## Updated at UTC 2026-08-20T19:25:55.042072

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-75140 7.5 0.00% 2 0 2026-08-20T18:30:58 jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource
CVE-2026-76956 7.5 0.26% 1 0 2026-08-20T18:30:48 In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's retu
CVE-2026-60721 9.8 0.49% 1 0 2026-08-20T18:30:36 Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware
CVE-2026-72530 9.0 0.34% 4 0 2026-08-20T18:16:44.963000 A remote unauthorized attacker with network access via port 4307/TCP to the True
CVE-2026-72529 9.8 0.28% 2 0 2026-08-20T18:16:44.813000 A remote unauthorized attacker with network access via port 4307/TCP to the True
CVE-2026-77176 8.1 0.00% 2 0 2026-08-20T17:19:49.773000 A flaw was found in Kata Containers. In configurations utilizing genpolicy for C
CVE-2026-77022 9.9 0.00% 2 0 2026-08-20T17:19:49.413000 A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this
CVE-2026-71428 9.3 0.00% 2 0 2026-08-20T17:19:40.773000 The unstructured library provides open-source components for ingesting and pre-p
CVE-2026-66792 9.9 0.30% 2 0 2026-08-20T17:19:29.693000 A flaw was found in the multicloud-operators-subscription component. This vulner
CVE-2026-63038 0 0.00% 2 0 2026-08-20T17:19:14.390000 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-76879 7.5 0.28% 2 0 2026-08-20T16:18:21.780000 C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows den
CVE-2026-76832 8.8 0.84% 2 0 2026-08-20T16:18:20.903000 Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal v
CVE-2026-76234 7.5 0.22% 2 0 2026-08-20T16:18:10.510000 libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, con
CVE-2026-75144 7.8 0.14% 2 0 2026-08-20T16:18:02.593000 FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in th
CVE-2026-75141 7.8 0.14% 2 0 2026-08-20T16:18:02.173000 FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box wri
CVE-2026-61518 8.8 0.31% 2 0 2026-08-20T16:17:28.090000 ISPConfig contains an authenticated SQL injection vulnerability in the Remote AP
CVE-2026-14952 7.5 0.49% 2 0 2026-08-20T16:17:07.333000 An unauthenticated remote attacker can retrieve sensible files from the FDS Web
CVE-2026-16885 9.8 0.80% 2 0 2026-08-20T15:55:41.820000 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
CVE-2026-76633 8.1 0.00% 2 0 2026-08-20T15:34:26 WeGIA before 3.9.2 contains an authorization bypass vulnerability in the passwor
CVE-2026-76833 7.8 0.00% 2 0 2026-08-20T15:34:26 @cgauge/yaml npm package contains an arbitrary code execution vulnerability that
CVE-2026-61897 7.8 0.00% 2 0 2026-08-20T15:34:20 An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partial
CVE-2026-28164 9.6 0.00% 2 0 2026-08-20T15:34:20 Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Add
CVE-2026-76886 8.1 0.27% 2 0 2026-08-20T15:34:14 C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows den
CVE-2026-60728 9.1 0.47% 1 0 2026-08-20T15:18:06.280000 Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware
CVE-2026-60730 9.9 0.39% 1 0 2026-08-20T15:17:54.660000 Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware
CVE-2026-76251 7.1 0.21% 1 0 2026-08-20T14:56:21.550000 In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does
CVE-2026-19490 0 0.34% 6 0 2026-08-20T14:17:10.673000 Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: f
CVE-2026-66794 9.3 0.32% 3 0 2026-08-20T13:08:53.900000 A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine f
CVE-2026-73197 7.5 0.00% 2 0 2026-08-20T13:08:53.900000 A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this
CVE-2026-70496 9.9 0.26% 4 0 2026-08-20T13:08:53.900000 A flaw was found in search-v2-operator. The operator's ClusterRole has permissio
CVE-2026-73925 8.2 0.23% 2 0 2026-08-20T13:08:14.613000 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-47630 5.5 0.14% 1 0 2026-08-20T13:06:05.500000 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attac
CVE-2026-67271 9.8 0.46% 2 0 2026-08-20T13:02:12.153000 Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/
CVE-2026-20320 7.5 0.35% 2 0 2026-08-20T13:01:19.947000 A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWork
CVE-2026-20315 10.0 0.32% 2 0 2026-08-20T13:01:19.947000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-66602 8.8 0.15% 2 0 2026-08-20T12:49:04.990000 Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar โ€“ WordPress
CVE-2026-76004 9.9 0.44% 4 0 2026-08-20T12:48:31.843000 A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-21090
CVE-2026-75976 9.9 0.63% 4 0 2026-08-20T12:48:31.843000 A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the
CVE-2026-75877 9.9 0.61% 2 0 2026-08-20T12:48:31.843000 A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affec
CVE-2026-15748 9.8 3.45% 10 3 2026-08-20T12:48:10.287000 The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload
CVE-2026-76589 9.9 0.61% 4 0 2026-08-20T12:48:10.287000 A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the
CVE-2026-76590 9.9 0.61% 4 0 2026-08-20T12:48:10.287000 A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by
CVE-2026-15826 9.8 2.48% 2 1 2026-08-20T12:48:10.287000 The User Profile Builder plugin for WordPress is vulnerable to Authentication By
CVE-2026-73198 7.5 0.00% 2 0 2026-08-20T12:31:29 A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vu
CVE-2026-13097 9.1 0.00% 2 0 2026-08-20T12:31:22 A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enfo
CVE-2026-75860 9.8 0.34% 2 0 2026-08-20T12:31:22 The JSON Options WordPress plugin through 0.0.4 does not have any capability che
CVE-2026-14950 9.8 0.55% 6 0 2026-08-20T09:31:23 An unauthenticated remote attacker in possession of a valid session identifier i
CVE-2026-14949 6.5 0.26% 2 0 2026-08-20T09:31:23 A low privileged remote attacker with a valid session can submit a request to th
CVE-2026-14948 8.8 0.39% 2 0 2026-08-20T09:31:23 A low privileged remote attacker can hijack an active administrative session wit
CVE-2026-14953 4.3 0.20% 2 0 2026-08-20T09:31:23 A low-privileged remote attacker can enumerate all configured users and identify
CVE-2026-14951 8.0 0.16% 2 0 2026-08-20T09:31:23 An low privileged remote attacker can cause authenticated users to perform unint
CVE-2026-14947 7.2 0.94% 2 0 2026-08-20T09:31:23 A high-privileged remote attacker can upload malicious ZIP archive containing di
CVE-2026-14946 7.2 0.52% 2 0 2026-08-20T09:16:45.813000 A high privileged remote attacker can upload a .php file and then request it dir
CVE-2026-64849 9.3 8.15% 13 3 template 2026-08-20T04:16:56.280000 MLflow is an open source AI engineering platform for agents, large language mode
CVE-2026-76928 7.5 0.28% 2 0 2026-08-20T00:35:18 X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows de
CVE-2026-76760 7.3 0.33% 1 0 2026-08-20T00:35:17 A vulnerability was found in chenhg5 cc-connect up to 1.4.1. Affected by this vu
CVE-2026-76850 9.8 0.98% 4 0 2026-08-20T00:35:17 LMDeploy deserializes disaggregated-serving peer messages with pickle. The handl
CVE-2026-76880 7.5 0.28% 2 0 2026-08-20T00:35:17 RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial
CVE-2026-76395 8.8 0.47% 3 0 2026-08-20T00:35:11 In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk r
CVE-2026-76399 8.1 0.25% 2 0 2026-08-20T00:35:11 In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk r
CVE-2026-76397 8.1 0.25% 2 0 2026-08-20T00:35:11 In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk r
CVE-2026-76396 7.5 0.24% 2 0 2026-08-20T00:35:11 In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the sch
CVE-2026-76404 9.1 0.56% 7 0 2026-08-20T00:35:08 In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splu
CVE-2026-76325 7.3 0.25% 1 0 2026-08-20T00:35:02 In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user w
CVE-2026-76333 7.1 0.25% 1 0 2026-08-20T00:35:02 In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user w
CVE-2026-76262 7.5 0.37% 1 0 2026-08-20T00:35:02 In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could r
CVE-2026-76310 9.4 0.37% 2 0 2026-08-20T00:34:56 In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unaut
CVE-2026-20030 10.0 0.45% 2 0 2026-08-19T21:31:32 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76583 7.4 1.07% 1 0 2026-08-19T21:30:47 A vulnerability was identified in TRENDnet TV-IP751WIC 11.03.03. Affected by thi
CVE-2026-75569 7.7 0.29% 2 0 2026-08-19T21:30:46 A flaw was found in mce-operator-bundle. The build process fetches and executes
CVE-2026-76139 8.0 0.33% 2 0 2026-08-19T21:30:46 A flaw was found in acm-operator-bundle. The build process for this component do
CVE-2026-76584 9.9 0.49% 2 0 2026-08-19T21:30:40 A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected b
CVE-2026-18848 8.3 0.10% 2 0 2026-08-19T21:30:32 IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 thr
CVE-2026-20317 10.0 0.34% 2 0 2026-08-19T21:30:29 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-68900 7.6 0.25% 2 0 2026-08-19T20:17:21.727000 Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHT
CVE-2026-52877 8.3 0.30% 2 0 2026-08-19T19:17:19.177000 Streambert is a cross-platform Electron Desktop App to stream and download video
CVE-2026-50191 8.8 0.33% 2 0 2026-08-19T19:17:18.273000 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4g
CVE-2026-75149 8.8 0.64% 2 0 2026-08-19T18:33:02 marimo before 0.23.15 contains a code injection vulnerability in the notebook co
CVE-2026-32475 9.0 0.42% 8 0 2026-08-19T18:32:57 Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Eleme
CVE-2026-75143 9.8 0.40% 2 0 2026-08-19T18:32:57 FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protoco
CVE-2026-75142 7.8 0.14% 2 0 2026-08-19T18:32:57 FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS mux
CVE-2026-75146 8.1 0.26% 2 0 2026-08-19T18:32:57 FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer
CVE-2026-60727 9.8 0.45% 1 0 2026-08-19T18:32:35 Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware
CVE-2026-60702 9.9 0.42% 2 0 2026-08-19T18:32:34 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware
CVE-2026-69414 7.8 0.23% 1 2 2026-08-19T18:32:28 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect
CVE-2026-53958 7.6 0.28% 2 0 2026-08-19T17:19:23.613000 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4g
CVE-2026-18051 10.0 0.43% 2 0 2026-08-19T17:18:36.337000 The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the
CVE-2026-70408 8.8 0.33% 2 0 2026-08-19T16:18:58.590000 An incorrect authorization vulnerability exists in acmailer, which may allow a u
CVE-2026-73924 9.1 0.29% 2 0 2026-08-19T15:33:23 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-73921 9.8 0.33% 2 0 2026-08-19T15:33:23 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-73938 7.5 0.38% 2 0 2026-08-19T15:33:23 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-71176 8.8 0.30% 2 0 2026-08-19T15:32:47 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutra
CVE-2026-71961 8.8 3.34% 2 0 2026-08-19T15:32:47 Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection
CVE-2026-58562 7.3 0.09% 1 0 2026-08-19T15:32:46 Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorizat
CVE-2026-76219 8.1 0.28% 1 0 2026-08-19T15:32:38 GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerabili
CVE-2026-73390 9.8 0.27% 1 0 2026-08-19T15:32:33 Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
CVE-2026-67364 None 0.29% 2 0 2026-08-19T15:32:24 Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms <
CVE-2026-73937 8.2 0.38% 2 0 2026-08-19T15:32:20 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-73935 7.5 0.30% 2 0 2026-08-19T15:32:20 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-73934 7.5 0.30% 2 0 2026-08-19T15:32:20 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-73939 8.6 0.32% 2 0 2026-08-19T15:32:20 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-73922 9.1 0.29% 2 0 2026-08-19T15:32:19 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-73936 7.5 0.41% 2 0 2026-08-19T15:32:19 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-73931 8.3 0.23% 2 0 2026-08-19T15:32:19 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-73930 9.9 0.36% 2 0 2026-08-19T15:32:19 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-60392 7.8 0.29% 1 0 2026-08-19T15:32:05 Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middl
CVE-2026-15780 7.2 0.39% 1 0 2026-08-19T09:31:30 The WP Statistics โ€“ Simple, privacy-friendly Google Analytics alternative plugin
CVE-2026-76050 7.3 0.33% 1 0 2026-08-19T06:31:24 A vulnerability was found in SourceCodester Simple Online Food Ordering System 1
CVE-2026-76049 7.3 0.33% 1 0 2026-08-19T06:31:24 A vulnerability has been found in SourceCodester Simple Online Food Ordering Sys
CVE-2026-19942 8.1 0.69% 2 0 2026-08-19T06:31:24 The Atarim โ€“ AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO
CVE-2026-33824 9.8 77.90% 8 2 2026-08-19T04:16:58.560000 Double free in Windows IKE Extension allows an unauthorized attacker to execute
CVE-2026-76008 10.0 0.57% 4 0 2026-08-19T03:31:30 A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_
CVE-2026-76003 9.9 0.44% 4 0 2026-08-19T03:31:23 A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected
CVE-2026-18963 9.1 0.39% 5 1 2026-08-19T03:31:21 A flaw was found in the reset-credentials flow of the keycloak-services componen
CVE-2026-21580 None 0.36% 2 0 2026-08-19T00:31:18 This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security
CVE-2026-60782 9.8 0.49% 1 0 2026-08-18T21:32:07 Vulnerability in the Oracle Payments product of Oracle E-Business Suite (compone
CVE-2026-60720 9.9 0.45% 1 0 2026-08-18T21:32:06 Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware
CVE-2026-47629 7.5 0.35% 2 0 2026-08-18T21:31:55 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attac
CVE-2026-47628 7.5 0.35% 2 0 2026-08-18T21:31:54 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attac
CVE-2026-47606 6.5 0.41% 1 0 2026-08-18T21:31:54 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attac
CVE-2026-47627 9.8 0.43% 4 0 2026-08-18T21:31:53 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attac
CVE-2026-75625 9.0 0.20% 1 0 2026-08-18T20:17:32.460000 Kraken agents fail to verify peer-to-peer downloaded blobs against their request
CVE-2026-47719 8.2 0.48% 1 0 2026-08-18T20:17:15.103000 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior
CVE-2026-59310 9.8 2.40% 2 2 2026-08-18T18:32:52 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-75130 9.0 0.28% 1 0 2026-08-18T18:32:11 Context7 through 2.1.2 contains a prompt injection vulnerability that allows att
CVE-2026-66780 9.9 0.24% 2 0 2026-08-18T18:32:10 A flaw was found in the submariner-operator component. The `submariner-k8s-broke
CVE-2026-65400 7.1 0.75% 7 1 2026-08-18T18:31:47 An authentication issue was addressed with improved state management. This issue
CVE-2026-75913 9.3 0.33% 1 0 2026-08-18T16:18:23.363000 CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an
CVE-2026-75481 8.8 0.28% 1 0 2026-08-18T16:18:20.627000 SkyPilot fails to validate that authenticated users are entitled to grant admini
CVE-2026-75103 8.8 0.34% 1 0 2026-08-18T16:18:20.127000 Crawlab fails to verify user ownership or administrative role on the password-ch
CVE-2026-67854 9.8 0.40% 1 0 2026-08-18T16:18:14.327000 SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute
CVE-2026-75783 9.6 0.40% 1 0 2026-08-18T15:31:56 A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Aff
CVE-2026-24301 8.8 1.63% 5 1 2026-08-18T15:31:45 Improper neutralization of special elements used in a command ('command injectio
CVE-2026-75479 7.5 0.36% 1 0 2026-08-18T15:17:13.457000 JimuReport contains an authentication bypass vulnerability in the report folder
CVE-2026-40144 0 0.11% 2 0 2026-08-18T15:04:46.610000 A memory-corruption vulnerability exists in a kernel-mode component of BeyondTru
CVE-2026-75852 9.8 0.45% 1 0 2026-08-18T14:18:12.260000 ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data comm
CVE-2026-75853 8.8 0.39% 1 0 2026-08-18T12:31:30 ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versi
CVE-2026-75851 9.9 0.32% 1 0 2026-08-18T12:31:30 ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fa
CVE-2026-75854 9.8 1.07% 1 0 2026-08-18T12:31:30 ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability i
CVE-2026-75045 9.1 0.30% 1 0 2026-08-18T04:16:47.170000 In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unau
CVE-2025-62593 8.8 1.01% 5 1 2026-08-18T04:16:40.860000 Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ra
CVE-2026-75094 9.1 2.09% 2 0 2026-08-18T03:31:14 A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_
CVE-2026-11801 7.5 0.30% 2 0 2026-08-18T03:31:11 The WPAdverts โ€“ Classifieds Plugin plugin for WordPress is vulnerable to authori
CVE-2026-75482 7.5 0.62% 1 0 2026-08-17T21:31:35 SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is a
CVE-2026-75111 7.5 0.39% 1 0 2026-08-17T21:31:35 Evidently UI fails to properly validate the filename parameter in the dataset ma
CVE-2026-19478 9.4 1.51% 15 3 2026-08-17T21:31:30 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2
CVE-2026-19650 7.1 0.24% 3 1 2026-08-17T21:31:30 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2
CVE-2026-75106 9.1 0.30% 1 0 2026-08-17T21:31:30 OpnForm derives editable-submission secrets from sequential row identifiers usin
CVE-2026-75105 7.5 0.28% 1 0 2026-08-17T21:31:30 phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the
CVE-2026-71290 9.1 0.19% 2 0 2026-08-17T19:06:52.793000 Improper TLS hostname verification vulnerability in Apache HttpComponents Client
CVE-2026-40145 None 0.11% 2 0 2026-08-17T18:31:28 A vulnerability exists in the interaction between a Endpoint Privilege Managemen
CVE-2026-47686 9.9 0.32% 2 0 2026-08-17T17:32:35 **Affected:** vm2 <= 3.11.3 **CVSS 3.1:** 9.9 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:N
CVE-2026-71479 9.1 0.52% 1 0 2026-08-17T16:36:14 ## Summary Multiple billing paths multiplied **user-controlled quantity paramet
CVE-2026-74889 9.8 0.20% 1 0 2026-08-17T12:32:31 openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info para
CVE-2026-17186 9.9 0.47% 2 0 2026-08-14T21:31:35 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute
CVE-2026-18146 7.2 0.36% 1 0 2026-08-14T19:09:56.813000 The Fluent Forms โ€“ Customizable Contact Forms, Survey, Quiz, & Conversational Fo
CVE-2026-66804 7.8 3.42% 1 3 2026-08-14T18:06:11.420000 Improper access control in Windows Cross Device Service allows an authorized att
CVE-2026-73570 8.9 0.54% 11 0 2026-08-14T05:17:00.340000 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor
CVE-2026-68138 7.8 0.13% 1 3 2026-08-14T00:31:53 In the Linux kernel, the following vulnerability has been resolved: net/sched:
CVE-2026-8715 9.6 0.32% 2 0 2026-08-13T21:36:21 Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read
CVE-2026-17482 9.8 0.55% 2 0 2026-08-13T21:36:21 IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to e
CVE-2026-19001 9.8 0.38% 1 0 2026-08-13T13:17:48.253000 The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-siz
CVE-2026-68820 7.0 0.33% 2 2 2026-08-11T21:33:01 Use after free in Windows Ancillary Function Driver for WinSock allows an author
CVE-2026-13737 None 0.43% 2 0 2026-08-11T18:30:43 CommServe contained an allowlist bypass vulnerability affecting command executio
CVE-2026-13738 0 0.53% 2 0 2026-08-11T17:17:47.660000 CommServe contained an authorization bypass vulnerability affecting a limited se
CVE-2026-58231 10.0 0.73% 3 1 2026-08-11T12:30:28 SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent
CVE-2026-71958 9.8 0.56% 1 0 2026-08-08T18:30:30 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CVE-2026-6540 7.5 0.37% 2 1 2026-08-08T03:32:15 Calico's Application Layer Policy (disabled by default), which enforces HTTP rul
CVE-2026-12569 9.8 30.20% 18 1 2026-08-01T05:16:55.023000 A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
CVE-2026-47301 8.8 0.68% 2 1 2026-07-30T19:17:31.990000 Improper access control in Microsoft Configuration Manager allows an authorized
CVE-2026-43760 8.6 0.24% 1 0 2026-07-30T19:17:30.313000 An access issue was addressed with improved access restrictions. This issue is f
CVE-2026-43774 5.5 0.13% 1 0 2026-07-28T18:33:56 An out-of-bounds read was addressed with improved bounds checking. This issue is
CVE-2026-11622 7.5 0.51% 2 0 2026-07-22T15:31:34 A DNSSEC validating resolver that is under a random subdomain attack against a D
CVE-2026-8452 9.8 0.49% 1 2 2026-07-01T15:52:28.390000 Memory overflow vulnerabilityย NetScaler ADC and NetScaler Gatewayย leading to unp
CVE-2026-20266 9.1 0.63% 2 0 2026-06-17T18:35:58 In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk r
CVE-2026-27912 8.0 0.24% 1 3 2026-06-17T10:27:52.490000 Improper authorization in Windows Kerberos allows an authorized attacker to elev
CVE-2021-33045 9.8 99.56% 1 4 template 2026-06-17T03:54:04.020000 The identity authentication bypass vulnerability found in some Dahua products du
CVE-2010-3854 0 5.92% 2 0 2026-06-16T23:23:40.850000 Multiple cross-site scripting (XSS) vulnerabilities in the web administration in
CVE-2008-5161 3.7 15.39% 2 1 2026-06-16T22:59:22.107000 Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Conne
CVE-2026-0075 5.9 0.09% 4 1 2026-06-02T15:33:09 In multiple functions, there is a possible way to access the contacts database d
CVE-2026-1947 7.5 0.27% 2 3 2026-03-16T15:30:54 The NEX-Forms โ€“ Ultimate Forms Plugin for WordPress plugin for WordPress is vuln
CVE-2026-3286 6.3 0.31% 1 0 2026-02-27T06:31:39 A vulnerability was identified in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3. Th
CVE-2021-33044 9.8 99.87% 2 10 2025-10-22T00:32:20 The identity authentication bypass vulnerability found in some Dahua products du
CVE-2026-59307 0 0.00% 2 0 N/A
CVE-2026-59324 0 0.00% 2 0 N/A
CVE-2026-63490 0 0.00% 2 0 N/A
CVE-2026-54330 0 0.00% 2 0 N/A
CVE-2026-63182 0 0.00% 1 0 N/A
CVE-2026-57580 0 0.44% 1 0 N/A
CVE-2026-68899 0 0.40% 2 0 N/A
CVE-2026-68561 0 0.38% 2 0 N/A
CVE-2026-50186 0 0.43% 2 0 N/A
CVE-2026-50142 0 0.56% 2 1 N/A
CVE-2026-52872 0 0.14% 2 0 N/A
CVE-2026-52876 0 0.15% 2 0 N/A
CVE-2026-75936 0 0.44% 1 0 N/A
CVE-2026-75935 0 0.44% 1 0 N/A
CVE-2025-53906 0 0.73% 1 0 N/A
CVE-2026-75914 0 0.41% 1 0 N/A
CVE-2026-75911 0 0.17% 1 0 N/A

CVE-2026-75140
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-20T18:30:58

2 posts

jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers ca

thehackerwire@mastodon.social at 2026-08-20T17:00:10.000Z ##

๐ŸŸ  CVE-2026-75140 - High (7.5)

jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-20T17:00:10.000Z ##

๐ŸŸ  CVE-2026-75140 - High (7.5)

jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76956
(7.5 HIGH)

EPSS: 0.26%

updated 2026-08-20T18:30:48

1 posts

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

hugovalters@mastodon.social at 2026-08-20T14:06:42.000Z ##

CVE-2026-76956 - DoS in libexpat 2.8.2/2.8.3. Insufficient entropy from getentropy handling enables hash flooding via crafted XML. CVSS 7.5. No patch yet, upgrade to 2.8.4. #CVE #libexpat #infosec

valtersit.com/cve/CVE-2026-769

##

CVE-2026-60721
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-08-20T18:30:36

1 posts

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Mana

infosecbot@mastodon.hofud.com at 2026-08-19T06:09:14.000Z ##

[1/9]

Most Impactful Security Incidents (โ€ฏ2026โ€‘08โ€‘18โ€ฏโ†’โ€ฏ2026โ€‘08โ€‘19โ€ฏ)

---

PRIORITYโ€ฏ1 โ€“ Critical / Highโ€‘Severity Flaws (CVSSโ€ฏ7โ€‘10):

CVEโ€‘2026โ€‘60392
โ€ข 7.8 (HIGH)
โ€ข Oracleโ€ฏOutsideโ€ฏInโ€ฏTechnology โ€“ PDF Export SDK (Fusion Middleware)
โ€ข Localโ€‘privilege escalation; requires attacker to have a logon on the host where the SDK runs. Successful exploitation can lead to full takeover of the component.
โ€ข 8.5.8
โ€ข Easily exploitable (local) โ€“ requires user interaction.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60782
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏPayments (Eโ€‘Business Suite) โ€“ File Transmission
โ€ข Remote unauthenticated attacker can compromise the Payments module via HTTP. Leads to full takeover of the Payments service.
โ€ข 12.2.3โ€‘12.2.15
โ€ข Networkโ€‘accessible, no authentication required.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60730
โ€ข 9.9 (CRITICAL)
โ€ข Oracleโ€ฏWebCenterโ€ฏPortal โ€“ Composer component
โ€ข Remote unauthenticated attacker can compromise the portal via HTTP. Full takeover of the portal.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.0.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60728
โ€ข 9.1 (CRITICAL)
โ€ข Oracleโ€ฏWebCenterโ€ฏPortal โ€“ Portlet Services
โ€ข Remote unauthenticated attacker can cause denialโ€‘ofโ€‘service and full compromise of portal data.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.0.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60727
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Remote unauthenticated attacker can take over the IAM system via HTTP.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60721
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Same vector as above; full takeover possible.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60720
โ€ข 9.9 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Remote unauthenticated attacker can compromise the IAM system.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

#infosecnews

##

CVE-2026-72530
(9.0 CRITICAL)

EPSS: 0.34%

updated 2026-08-20T18:16:44.963000

4 posts

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

cisakevtracker@mastodon.social at 2026-08-20T18:01:06.000Z ##

CVE ID: CVE-2026-72530
Vendor: TrueConf
Product: Server
Date Added: 2026-08-20
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

thehackerwire@mastodon.social at 2026-08-19T18:01:44.000Z ##

๐Ÿ”ด CVE-2026-72530 - Critical (9)

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and exec...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cisakevtracker@mastodon.social at 2026-08-20T18:01:06.000Z ##

CVE ID: CVE-2026-72530
Vendor: TrueConf
Product: Server
Date Added: 2026-08-20
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

thehackerwire@mastodon.social at 2026-08-19T18:01:44.000Z ##

๐Ÿ”ด CVE-2026-72530 - Critical (9)

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and exec...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72529
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-08-20T18:16:44.813000

2 posts

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

cisakevtracker@mastodon.social at 2026-08-20T18:01:22.000Z ##

CVE ID: CVE-2026-72529
Vendor: TrueConf
Product: Server
Date Added: 2026-08-20
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-08-20T18:01:22.000Z ##

CVE ID: CVE-2026-72529
Vendor: TrueConf
Product: Server
Date Added: 2026-08-20
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-77176
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-20T17:19:49.773000

2 posts

A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mount arbitrary container-rootfs paths over sensitive host locations or provision arbitrary content, potentially exposing confidential information or ena

thehackerwire@mastodon.social at 2026-08-20T18:00:32.000Z ##

๐ŸŸ  CVE-2026-77176 - High (8.1)

A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-20T18:00:32.000Z ##

๐ŸŸ  CVE-2026-77176 - High (8.1)

A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77022
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-08-20T17:19:49.413000

2 posts

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSID Configuration. The manipulation of the argument ssid results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks

thehackerwire@mastodon.social at 2026-08-20T18:00:20.000Z ##

๐Ÿ”ด CVE-2026-77022 - Critical (9.9)

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSID Configuration. The manipulation of the argument ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-20T18:00:20.000Z ##

๐Ÿ”ด CVE-2026-77022 - Critical (9.9)

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSID Configuration. The manipulation of the argument ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71428
(9.3 CRITICAL)

EPSS: 0.00%

updated 2026-08-20T17:19:40.773000

2 posts

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, and partition_md is fetched without host validation in unstructured/partition/auto.py, unstructured/partition/html/partition.py, and unstructured/partition/md.py. An

thehackerwire@mastodon.social at 2026-08-20T18:00:43.000Z ##

๐Ÿ”ด CVE-2026-71428 - Critical (9.3)

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, and partitio...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-20T18:00:43.000Z ##

๐Ÿ”ด CVE-2026-71428 - Critical (9.3)

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, and partitio...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66792
(9.9 CRITICAL)

EPSS: 0.30%

updated 2026-08-20T17:19:29.693000

2 posts

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to

CVE-2026-63038
(0 None)

EPSS: 0.00%

updated 2026-08-20T17:19:14.390000

2 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the dbName, tableName, schemaName, and username parameters.ย  This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]ย  https

DailyCyberSecurity at 2026-08-20T16:40:07.322Z ##

An Apache InLong SQL injection flaw, CVE-2026-63038, lets attackers inject SQL via multiple parameters. Two more bugs join it. Upgrade to 2.4.0.

securityonline.info/apache-inl

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T16:40:07.000Z ##

An Apache InLong SQL injection flaw, CVE-2026-63038, lets attackers inject SQL via multiple parameters. Two more bugs join it. Upgrade to 2.4.0.

#ApacheInLong #SQLInjection #CVE #SSRF #InfoSec #OpenSource

securityonline.info/apache-inl

##

CVE-2026-76879
(7.5 HIGH)

EPSS: 0.28%

updated 2026-08-20T16:18:21.780000

2 posts

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

thehackerwire@mastodon.social at 2026-08-20T01:04:17.000Z ##

๐ŸŸ  CVE-2026-76879 - High (7.5)

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-20T01:04:17.000Z ##

๐ŸŸ  CVE-2026-76879 - High (7.5)

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76832
(8.8 HIGH)

EPSS: 0.84%

updated 2026-08-20T16:18:20.903000

2 posts

Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in the file_name argument passed to read_file, save_to_file, or run_python_file tool actions. Attackers can inject traversal sequences such as '../../../../../../etc/passwd' through direct too

thehackerwire@mastodon.social at 2026-08-19T23:01:13.000Z ##

๐ŸŸ  CVE-2026-76832 - High (8.8)

Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in the file_name argument passed to rea...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T23:01:13.000Z ##

๐ŸŸ  CVE-2026-76832 - High (8.8)

Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in the file_name argument passed to rea...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76234
(7.5 HIGH)

EPSS: 0.22%

updated 2026-08-20T16:18:10.510000

2 posts

libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain cryptographic implementation bugs. libcrux-ecdh did not properly check length and clamping during X25519 secret validation (and had a broken clamping check for imported X25519 secret keys); libcrux-ed25519 performed a duplicated clamping step during key generation; and libcrux-psq panicked instead of propagating a

thehackerwire@mastodon.social at 2026-08-19T15:00:19.000Z ##

๐ŸŸ  CVE-2026-76234 - High (7.5)

libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain cryptographic implementation bugs. libcrux-ecdh did not properly check length and clamping during X25519 secret validation (and had a broken clamping check for im...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T15:00:19.000Z ##

๐ŸŸ  CVE-2026-76234 - High (7.5)

libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain cryptographic implementation bugs. libcrux-ecdh did not properly check length and clamping during X25519 secret validation (and had a broken clamping check for im...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75144
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-20T16:18:02.593000

2 posts

FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit. The packetizer copies an input-derived data unit or fragment size into a fixed-size buffer without an upper bound check, causing a heap buffer overflow when the crafted inp

thehackerwire@mastodon.social at 2026-08-19T18:01:28.000Z ##

๐ŸŸ  CVE-2026-75144 - High (7.8)

FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit. The packetizer copi...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T18:01:28.000Z ##

๐ŸŸ  CVE-2026-75144 - High (7.8)

FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit. The packetizer copi...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75141
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-20T16:18:02.173000

2 posts

FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffer overflow. A crafted HEVC input file triggers the overflow during muxing.

thehackerwire@mastodon.social at 2026-08-19T18:00:20.000Z ##

๐ŸŸ  CVE-2026-75141 - High (7.8)

FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap bu...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T18:00:20.000Z ##

๐ŸŸ  CVE-2026-75141 - High (7.8)

FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap bu...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61518
(8.8 HIGH)

EPSS: 0.31%

updated 2026-08-20T16:17:28.090000

2 posts

ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods is concatenated directly into SQL WHERE clauses without integer casting or parameterized query binding. The built-in SQL injection scanner does not block quote-free boolean payloads and does not reject requests in its default configuration. A remote AP

thehackerwire@mastodon.social at 2026-08-19T19:00:43.000Z ##

๐ŸŸ  CVE-2026-61518 - High (8.8)

ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods is concatenated directly into SQL WHERE clauses without integer casting or parameterized query bind...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T19:00:43.000Z ##

๐ŸŸ  CVE-2026-61518 - High (8.8)

ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods is concatenated directly into SQL WHERE clauses without integer casting or parameterized query bind...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14952
(7.5 HIGH)

EPSS: 0.49%

updated 2026-08-20T16:17:07.333000

2 posts

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.

certvde at 2026-08-20T08:20:37.575Z ##

VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

frauscher.csaf-tp.certvde.com/

##

certvde@infosec.exchange at 2026-08-20T08:20:37.000Z ##

#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

#CSAF frauscher.csaf-tp.certvde.com/

##

CVE-2026-16885
(9.8 CRITICAL)

EPSS: 0.80%

updated 2026-08-20T15:55:41.820000

2 posts

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

offseq at 2026-08-20T06:00:23.729Z ##

Stack-based buffer overflow (CVE-2026-16885) in IBM AIX 7.2, 7.3 & PowerVM VIOS 4.1 (CRITICAL, CVSS 9.8). Remote, unauthenticated code execution possible. No patch yet โ€” monitor IBM advisories. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-20T06:00:23.000Z ##

Stack-based buffer overflow (CVE-2026-16885) in IBM AIX 7.2, 7.3 & PowerVM VIOS 4.1 (CRITICAL, CVSS 9.8). Remote, unauthenticated code execution possible. No patch yet โ€” monitor IBM advisories. radar.offseq.com/threat/cve-20 #OffSeq #IBM #AIX #Vuln

##

CVE-2026-76633
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-20T15:34:26

2 posts

WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of the alterarSenha method from permission checks in controle/control.php. Attackers can manipulate the redir parameter to point to alterar_senha.php, routin

thehackerwire@mastodon.social at 2026-08-20T15:00:03.000Z ##

๐ŸŸ  CVE-2026-76633 - High (8.1)

WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of t...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-20T15:00:03.000Z ##

๐ŸŸ  CVE-2026-76633 - High (8.1)

WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of t...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76833
(7.8 HIGH)

EPSS: 0.00%

updated 2026-08-20T15:34:26

2 posts

@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a custom !js YAML tag whose construct callback unconditionally calls eval() on attacker-supplied string values during document parsing. Any application parsing untrusted YAML input with this library exposes full Node.js runtime authority, including environm

thehackerwire@mastodon.social at 2026-08-20T14:59:52.000Z ##

๐ŸŸ  CVE-2026-76833 - High (7.8)

@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a custom !js YAML tag whose construct callback unconditionally calls eval() on attacker-supplied string ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-20T14:59:52.000Z ##

๐ŸŸ  CVE-2026-76833 - High (7.8)

@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a custom !js YAML tag whose construct callback unconditionally calls eval() on attacker-supplied string ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61897
(7.8 HIGH)

EPSS: 0.00%

updated 2026-08-20T15:34:20

2 posts

An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.

thehackerwire@mastodon.social at 2026-08-20T17:00:47.000Z ##

๐ŸŸ  CVE-2026-61897 - High (7.8)

An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-20T17:00:47.000Z ##

๐ŸŸ  CVE-2026-61897 - High (7.8)

An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-28164
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-08-20T15:34:20

2 posts

Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7.

offseq at 2026-08-20T13:30:26.574Z ##

CVE-2026-28164: CRITICAL CSRF in HashThemes Easy Elementor Addons โ‰ค2.3.7. Remote attackers can exploit this for full user compromise. No patch yet โ€” track vendor advisories. CVSS 9.6. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-20T13:30:26.000Z ##

CVE-2026-28164: CRITICAL CSRF in HashThemes Easy Elementor Addons โ‰ค2.3.7. Remote attackers can exploit this for full user compromise. No patch yet โ€” track vendor advisories. CVSS 9.6. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CSRF #CVE2026_28164

##

CVE-2026-76886
(8.1 HIGH)

EPSS: 0.27%

updated 2026-08-20T15:34:14

2 posts

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

thehackerwire@mastodon.social at 2026-08-20T01:03:18.000Z ##

๐ŸŸ  CVE-2026-76886 - High (8.1)

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-20T01:03:18.000Z ##

๐ŸŸ  CVE-2026-76886 - High (8.1)

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-60728
(9.1 CRITICAL)

EPSS: 0.47%

updated 2026-08-20T15:18:06.280000

1 posts

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to criti

infosecbot@mastodon.hofud.com at 2026-08-19T06:09:14.000Z ##

[1/9]

Most Impactful Security Incidents (โ€ฏ2026โ€‘08โ€‘18โ€ฏโ†’โ€ฏ2026โ€‘08โ€‘19โ€ฏ)

---

PRIORITYโ€ฏ1 โ€“ Critical / Highโ€‘Severity Flaws (CVSSโ€ฏ7โ€‘10):

CVEโ€‘2026โ€‘60392
โ€ข 7.8 (HIGH)
โ€ข Oracleโ€ฏOutsideโ€ฏInโ€ฏTechnology โ€“ PDF Export SDK (Fusion Middleware)
โ€ข Localโ€‘privilege escalation; requires attacker to have a logon on the host where the SDK runs. Successful exploitation can lead to full takeover of the component.
โ€ข 8.5.8
โ€ข Easily exploitable (local) โ€“ requires user interaction.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60782
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏPayments (Eโ€‘Business Suite) โ€“ File Transmission
โ€ข Remote unauthenticated attacker can compromise the Payments module via HTTP. Leads to full takeover of the Payments service.
โ€ข 12.2.3โ€‘12.2.15
โ€ข Networkโ€‘accessible, no authentication required.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60730
โ€ข 9.9 (CRITICAL)
โ€ข Oracleโ€ฏWebCenterโ€ฏPortal โ€“ Composer component
โ€ข Remote unauthenticated attacker can compromise the portal via HTTP. Full takeover of the portal.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.0.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60728
โ€ข 9.1 (CRITICAL)
โ€ข Oracleโ€ฏWebCenterโ€ฏPortal โ€“ Portlet Services
โ€ข Remote unauthenticated attacker can cause denialโ€‘ofโ€‘service and full compromise of portal data.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.0.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60727
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Remote unauthenticated attacker can take over the IAM system via HTTP.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60721
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Same vector as above; full takeover possible.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60720
โ€ข 9.9 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Remote unauthenticated attacker can compromise the IAM system.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

#infosecnews

##

CVE-2026-60730
(9.9 CRITICAL)

EPSS: 0.39%

updated 2026-08-20T15:17:54.660000

1 posts

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact addit

infosecbot@mastodon.hofud.com at 2026-08-19T06:09:14.000Z ##

[1/9]

Most Impactful Security Incidents (โ€ฏ2026โ€‘08โ€‘18โ€ฏโ†’โ€ฏ2026โ€‘08โ€‘19โ€ฏ)

---

PRIORITYโ€ฏ1 โ€“ Critical / Highโ€‘Severity Flaws (CVSSโ€ฏ7โ€‘10):

CVEโ€‘2026โ€‘60392
โ€ข 7.8 (HIGH)
โ€ข Oracleโ€ฏOutsideโ€ฏInโ€ฏTechnology โ€“ PDF Export SDK (Fusion Middleware)
โ€ข Localโ€‘privilege escalation; requires attacker to have a logon on the host where the SDK runs. Successful exploitation can lead to full takeover of the component.
โ€ข 8.5.8
โ€ข Easily exploitable (local) โ€“ requires user interaction.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60782
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏPayments (Eโ€‘Business Suite) โ€“ File Transmission
โ€ข Remote unauthenticated attacker can compromise the Payments module via HTTP. Leads to full takeover of the Payments service.
โ€ข 12.2.3โ€‘12.2.15
โ€ข Networkโ€‘accessible, no authentication required.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60730
โ€ข 9.9 (CRITICAL)
โ€ข Oracleโ€ฏWebCenterโ€ฏPortal โ€“ Composer component
โ€ข Remote unauthenticated attacker can compromise the portal via HTTP. Full takeover of the portal.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.0.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60728
โ€ข 9.1 (CRITICAL)
โ€ข Oracleโ€ฏWebCenterโ€ฏPortal โ€“ Portlet Services
โ€ข Remote unauthenticated attacker can cause denialโ€‘ofโ€‘service and full compromise of portal data.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.0.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60727
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Remote unauthenticated attacker can take over the IAM system via HTTP.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60721
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Same vector as above; full takeover possible.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60720
โ€ข 9.9 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Remote unauthenticated attacker can compromise the IAM system.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

#infosecnews

##

CVE-2026-76251
(7.1 HIGH)

EPSS: 0.21%

updated 2026-08-20T14:56:21.550000

1 posts

In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin" or "power" Splunk roles could cause the Splunk App for Splunk Observability Cloud to forward requests to Splunk Observability Cloud, including the Splunk Observability Cloud access token stored for the app. With this access, the user could view all relevant data available to that token and make lim

hugovalters@mastodon.social at 2026-08-20T18:07:12.000Z ##

CVE-2026-76251 - Splunk Enterprise priv-esc. Non-admins can leak Observability Cloud tokens. CVSS 7.1. Patch now. #CVE #Splunk #infosec

valtersit.com/cve/CVE-2026-762

##

CVE-2026-19490
(0 None)

EPSS: 0.34%

updated 2026-08-20T14:17:10.673000

6 posts

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Analyst207@mastodon.social at 2026-08-20T14:57:44.000Z ##

Citrix Flaw Exposes Authentication on NetScaler Servers

Citrix has warned of a critical authentication bypass vulnerability, CVE-2026-19490, affecting NetScaler servers, urging customers to review their configurations and prioritize patching based on exposure and deployment role.

osintsights.com/citrix-flaw-ex

#Cve202619490 #Citrix #AuthenticationBypass #Netscaler #Gateway

##

cyberworldops at 2026-08-20T10:20:01.241Z ##

Citrix has released patches for CVE-2026-19490, a CVSS 9.3 authentication bypass in NetScaler ADC and Gateway. An unauthenticated remote attacker can exploit the flaw via an alternative path to bypass authentication on appliances configured as SSL VPN, ICA Proxy, CVPN, RDP Proxy, or AAA servers.

cyberworldops.eu/en/netscaler-

##

ransomnews.online@bsky.brid.gy at 2026-08-20T09:37:37.000Z ##

๐Ÿšจ #NetScaler bypass exposed

CVE-2026-19490 grants remote unauthenticated access to Gateway and AAA deployments.
๐Ÿ”— read more: www.securityweek.com...

#ransomNews #cyberthreats #Citrix


Exploitation Expected for Crit...

##

DailyCyberSecurity at 2026-08-19T15:23:33.424Z ##

CVE-2026-19490 (CVSS 9.3) is a critical NetScaler authentication bypass in NetScaler Gateway and ADC. Patch now to block unauthenticated access.

securityonline.info/netscaler-

##

cyberworldops@infosec.exchange at 2026-08-20T10:20:01.000Z ##

Citrix has released patches for CVE-2026-19490, a CVSS 9.3 authentication bypass in NetScaler ADC and Gateway. An unauthenticated remote attacker can exploit the flaw via an alternative path to bypass authentication on appliances configured as SSL VPN, ICA Proxy, CVPN, RDP Proxy, or AAA servers.

#CitrixBleb #NetScalerVuln #CVSS9 #RemoteAccessSecurity

cyberworldops.eu/en/netscaler-

##

DailyCyberSecurity@infosec.exchange at 2026-08-19T15:23:33.000Z ##

CVE-2026-19490 (CVSS 9.3) is a critical NetScaler authentication bypass in NetScaler Gateway and ADC. Patch now to block unauthenticated access.

#NetScaler #Citrix #CVE202619490 #AuthBypass #InfoSec

securityonline.info/netscaler-

##

CVE-2026-66794
(9.3 CRITICAL)

EPSS: 0.32%

updated 2026-08-20T13:08:53.900000

3 posts

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy requests to arbitrary services across any managed cluster. This enables unauthorized access to internal

undercodenews@mastodon.social at 2026-08-20T12:05:44.000Z ##

Red Hat Kubernetes SSRF Vulnerability CVE-2026-66794: A Hidden Proxy Route Could Open the Door to Isolated Cluster Services + Video

A High-Severity Warning Behind the Kubernetes Control Plane Kubernetes environments are built around layers of isolation. Namespaces separate workloads, network policies restrict traffic, firewalls protect management interfaces, and authentication systems determine who can reach sensitive services. But what happens when the infrastructureโ€ฆ

undercodenews.com/red-hat-kube

##

thehackerwire@mastodon.social at 2026-08-19T19:00:29.000Z ##

๐Ÿ”ด CVE-2026-66794 - Critical (9.3)

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manip...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T19:00:29.000Z ##

๐Ÿ”ด CVE-2026-66794 - Critical (9.3)

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manip...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73197
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-20T13:08:53.900000

2 posts

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage, slower request handling, and potential service disruption or denial of service.

thehackerwire@mastodon.social at 2026-08-20T12:00:50.000Z ##

๐ŸŸ  CVE-2026-73197 - High (7.5)

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-20T12:00:50.000Z ##

๐ŸŸ  CVE-2026-73197 - High (7.5)

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70496
(9.9 CRITICAL)

EPSS: 0.26%

updated 2026-08-20T13:08:53.900000

4 posts

A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork. This grants excessive privileges beyond what is necessary for the operator's intended function, potentially le

DailyCyberSecurity at 2026-08-20T03:01:45.925Z ##

Red Hat ACM privilege escalation flaws (CVE-2026-70496, CVSS 9.9) let attackers seize full cluster control. See the three Kubernetes bugs.

securityonline.info/red-hat-ac

##

thehackerwire@mastodon.social at 2026-08-19T20:00:15.000Z ##

๐Ÿ”ด CVE-2026-70496 - Critical (9.9)

A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T03:01:45.000Z ##

Red Hat ACM privilege escalation flaws (CVE-2026-70496, CVSS 9.9) let attackers seize full cluster control. See the three Kubernetes bugs.

#RedHat #Kubernetes #PrivilegeEscalation #CVE #ACM #CloudSecurity #InfoSec

securityonline.info/red-hat-ac

##

thehackerwire@mastodon.social at 2026-08-19T20:00:15.000Z ##

๐Ÿ”ด CVE-2026-70496 - Critical (9.9)

A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73925
(8.2 HIGH)

EPSS: 0.23%

updated 2026-08-20T13:08:14.613000

2 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data o

thehackerwire@mastodon.social at 2026-08-19T11:01:03.000Z ##

๐ŸŸ  CVE-2026-73925 - High (8.2)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T11:01:03.000Z ##

๐ŸŸ  CVE-2026-73925 - High (8.2)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47630
(5.5 MEDIUM)

EPSS: 0.14%

updated 2026-08-20T13:06:05.500000

1 posts

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution.

AAKL@infosec.exchange at 2026-08-18T17:07:44.000Z ##

Nvidia has new advisories addressing two vulnerabilities:

- NVIDIA Cumulus Linux and NVOS - August 2026 nvidia.custhelp.com/app/answer

- CRITICAL, affecting the following: CVE-2026-47627, CVE-2026-47628, CVE-2026-47629, CVE-2026-47606, CVE-2026-47630

NVIDIA Triton Inference Server - August 2026 nvidia.custhelp.com/app/answer #Nvidia #infosec #vulnerability #Linux

##

CVE-2026-67271
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-08-20T13:02:12.153000

2 posts

Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and Remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet and cause a crash, that is persistent in case automatic restarts are enabled.

DailyCyberSecurity at 2026-08-20T14:05:08.537Z ##

A critical Dell PowerStore vulnerability, CVE-2026-67271 (CVSS 9.8), allows unauthenticated remote code execution via SMB. Two more flaws patched.

securityonline.info/dell-power

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T14:05:08.000Z ##

A critical Dell PowerStore vulnerability, CVE-2026-67271 (CVSS 9.8), allows unauthenticated remote code execution via SMB. Two more flaws patched.

#DellPowerStore #CVE202667271 #RCE #SMB #Storage #InfoSec

securityonline.info/dell-power

##

CVE-2026-20320
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-20T13:01:19.947000

2 posts

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML me

CVE-2026-20315
(10.0 CRITICAL)

EPSS: 0.32%

updated 2026-08-20T13:01:19.947000

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20315 are related to improper access control issues that are

DailyCyberSecurity at 2026-08-20T02:06:30.600Z ##

Cisco patches Secure Workload flaws CVE-2026-20315 and CVE-2026-20317, an authentication bypass and privilege escalation pair scoring CVSS 10. Upgrade now.

securityonline.info/cisco-secu

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T02:06:30.000Z ##

Cisco patches Secure Workload flaws CVE-2026-20315 and CVE-2026-20317, an authentication bypass and privilege escalation pair scoring CVSS 10. Upgrade now.

#Cisco #CVE #AuthenticationBypass #PrivilegeEscalation #Vulnerability #InfoSec #PatchNow

securityonline.info/cisco-secu

##

CVE-2026-66602
(8.8 HIGH)

EPSS: 0.15%

updated 2026-08-20T12:49:04.990000

2 posts

Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar โ€“ WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar โ€“ WordPress Notification Bar: from n/a through 2.0.0.

thehackerwire@mastodon.social at 2026-08-18T23:00:11.000Z ##

๐ŸŸ  CVE-2026-66602 - High (8.8)

Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar โ€“ WordPress Notification Bar allows Cross Site Request Forgery.

This issue affects HashBar โ€“ WordPress Notification Bar: from n/a through 2.0.0.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-18T23:00:11.000Z ##

๐ŸŸ  CVE-2026-66602 - High (8.8)

Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar โ€“ WordPress Notification Bar allows Cross Site Request Forgery.

This issue affects HashBar โ€“ WordPress Notification Bar: from n/a through 2.0.0.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76004
(9.9 CRITICAL)

EPSS: 0.44%

updated 2026-08-20T12:48:31.843000

4 posts

A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/aspApBasicConfigUrcp of the component HTTP Handler. The manipulation of the argument pvid leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

offseq at 2026-08-19T04:30:24.438Z ##

UTT HiPER 1250GW v3.2.7-210907-180535 hit by CRITICAL stack-based buffer overflow (CVE-2026-76004) in HTTP handler. Exploitable via 'pvid' arg. No patch yet โ€” restrict remote access & monitor traffic. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-19T04:00:55.000Z ##

๐Ÿ”ด CVE-2026-76004 - Critical (9.9)

A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/aspApBasicConfigUrcp of the component HTTP Handler. The manipulation of the argumen...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-19T04:30:24.000Z ##

UTT HiPER 1250GW v3.2.7-210907-180535 hit by CRITICAL stack-based buffer overflow (CVE-2026-76004) in HTTP handler. Exploitable via 'pvid' arg. No patch yet โ€” restrict remote access & monitor traffic. radar.offseq.com/threat/cve-20 #OffSeq #CVE202676004 #Vuln #Infosec

##

thehackerwire@mastodon.social at 2026-08-19T04:00:55.000Z ##

๐Ÿ”ด CVE-2026-76004 - Critical (9.9)

A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/aspApBasicConfigUrcp of the component HTTP Handler. The manipulation of the argumen...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75976
(9.9 CRITICAL)

EPSS: 0.63%

updated 2026-08-20T12:48:31.843000

4 posts

A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM. This manipulation of the argument wan_l2tp_password causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

thehackerwire@mastodon.social at 2026-08-19T03:00:12.000Z ##

๐Ÿ”ด CVE-2026-75976 - Critical (9.9)

A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM. This manipulation of the argument wan_l2tp_password causes stack-based buffer overflow. The attac...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-19T00:00:36.865Z ##

Stack-based buffer overflow (CVE-2026-75976, CVSS 9.4) in TRENDnet TEW-823DRU 1.1.02b01: remote exploitation possible via /cgi-bin/wan.cgi. Public exploit exists. Assess exposure & monitor for patches: radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-19T03:00:12.000Z ##

๐Ÿ”ด CVE-2026-75976 - Critical (9.9)

A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM. This manipulation of the argument wan_l2tp_password causes stack-based buffer overflow. The attac...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-19T00:00:36.000Z ##

Stack-based buffer overflow (CVE-2026-75976, CVSS 9.4) in TRENDnet TEW-823DRU 1.1.02b01: remote exploitation possible via /cgi-bin/wan.cgi. Public exploit exists. Assess exposure & monitor for patches: radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Infosec #IoTSecurity

##

CVE-2026-75877
(9.9 CRITICAL)

EPSS: 0.61%

updated 2026-08-20T12:48:31.843000

2 posts

A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/SystemDDNSChanged/SystemEmailChanged/SystemFTPChanged/websCheckRealm/FUN_00432574/FUN_0043372C of the component alphapd. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.

thehackerwire@mastodon.social at 2026-08-18T21:00:41.000Z ##

๐Ÿ”ด CVE-2026-75877 - Critical (9.9)

A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/SystemDDNSChanged/SystemEmailChanged/SystemFTPChanged/websCheckRealm/FUN_00432574/FUN_0043372C of the component alphapd. Executing...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-18T21:00:41.000Z ##

๐Ÿ”ด CVE-2026-75877 - Critical (9.9)

A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/SystemDDNSChanged/SystemEmailChanged/SystemFTPChanged/websCheckRealm/FUN_00432574/FUN_0043372C of the component alphapd. Executing...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15748
(9.8 CRITICAL)

EPSS: 3.45%

updated 2026-08-20T12:48:10.287000

10 posts

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler th

3 repos

https://github.com/ubaydev/CVE-2026-15748

https://github.com/HORKimhab/CVE-2026-15826-CVE-2026-15748

https://github.com/yora1928/cve-2026-15748

cyberveille@mastobot.ping.moi at 2026-08-20T18:00:05.000Z ##

๐Ÿ“ข CVE-2026-15748 : Faille critique dans Forminator Forms expose 300 000 sites WordPress

L'information provient de la firme de sรฉcuritรฉ WordPress Defiant. ๐Ÿ” Contexte Une vulnรฉrabilitรฉ critique a รฉtรฉ identifiรฉe dans le plugin Forminator Forms pour WordPress, l'un des constructeurs de formulaires les plus populaires avec plus de 600 000 installationsโ€ฆ

๐Ÿ“– cyberveille : cyberveille.ch/posts/2026-08-2
๐ŸŒ source : securityweek.com/300000-wordpr
๐ŸŸข vรฉrification factuelle haute
#ForminatorForms #WordPress #Cyberveille

##

beyondmachines1 at 2026-08-19T09:01:23.027Z ##

Unauthenticated RCE Vulnerability Patched in Forminator Forms Plugin

WPMU DEV patched a critical vulnerability (CVE-2026-15748) in the Forminator Forms plugin that allowed unauthenticated attackers to upload and execute PHP files. The flaw can lead to full remote code execution and site compromise.

**If you use the Forminator Forms plugin on your WordPress site, update it to version 1.56.2 or later ASAP away: attackers can take over the whole site without logging in. After updating, check your upload folders for any unfamiliar PHP files. If you can't update yet, delete any forms that use both File Upload and Select fields.**

beyondmachines.net/event_detai

##

cyberveille@mastobot.ping.moi at 2026-08-19T07:00:06.000Z ##

๐Ÿ“ข [VULN] 600 000 sites WordPress menacรฉs par une faille critique dans Forminator Forms CVE-2026-15748

Une faille critique touche Forminator Forms, une extension WordPress utilisรฉe sur plus de 600 000 sites. Rรฉfรฉrencรฉe CVE-2026-15748, la vulnรฉrabilitรฉ obtient un score de 9,8/10 et peut permettre ร  un attaquant non authentifiรฉ dโ€™exรฉcuter du code sur un serveur vulnรฉrable.

๐Ÿ”— cyberattaque.org/600-000-sites
๐Ÿ’ฌ discussion : infosec.pub/post/51136301
#Vulnรฉrabilitรฉ #CVE #Cyberveille

##

guru@thecybersecguru.com at 2026-08-19T05:14:10.000Z ##

Critical WordPress Alert: Dissecting CVE-2026-15748 (Forminator RCE) & CVE-2026-15826 (UPB Auth Bypass)

CVE-2026-15748 enables critical Forminator RCE, while CVE-2026-15826 allows User Profile Builder authentication bypass. Learn how to detect and patch both

thecybersecguru.com/news/cve-2

##

security_crawler_carl at 2026-08-19T01:00:33.684Z ##

CVE-2026-15748, scored 9.8 out of 10, allows unauthenticated attackers to manipulate Select field configurations and bypass the plugin's blocklist entirely, uploading executable files through handle_file_upload. Defiant confirms this is several weaknesses working together in a kind of tragic team-building exercise.

Remote code execution is not a learning objective we endorse. Please update Forminator Forms to version 1.56.2 or later immediately. (2/3)

##

beyondmachines1@infosec.exchange at 2026-08-19T09:01:23.000Z ##

Unauthenticated RCE Vulnerability Patched in Forminator Forms Plugin

WPMU DEV patched a critical vulnerability (CVE-2026-15748) in the Forminator Forms plugin that allowed unauthenticated attackers to upload and execute PHP files. The flaw can lead to full remote code execution and site compromise.

**If you use the Forminator Forms plugin on your WordPress site, update it to version 1.56.2 or later ASAP away: attackers can take over the whole site without logging in. After updating, check your upload folders for any unfamiliar PHP files. If you can't update yet, delete any forms that use both File Upload and Select fields.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

security_crawler_carl@infosec.exchange at 2026-08-19T01:00:33.000Z ##

CVE-2026-15748, scored 9.8 out of 10, allows unauthenticated attackers to manipulate Select field configurations and bypass the plugin's blocklist entirely, uploading executable files through handle_file_upload. Defiant confirms this is several weaknesses working together in a kind of tragic team-building exercise.

Remote code execution is not a learning objective we endorse. Please update Forminator Forms to version 1.56.2 or later immediately. (2/3)

##

offseq@infosec.exchange at 2026-08-18T06:00:26.000Z ##

CVE-2026-15748 (CRITICAL, CVSS 9.8): wpmudev Forminator Forms for WordPress up to 1.56.1 lets unauthenticated attackers upload dangerous files via handle_file_upload, risking remote code execution. Patch urgently: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

ottoto2017@prattohome.com at 2026-08-18T05:26:14.000Z ##

ใ€ŒForminator WordPressใฎ่„†ๅผฑๆ€งใซใ‚ˆใ‚Šใ€ๆ‚ชๆ„ใฎใ‚ใ‚‹PHPใƒ•ใ‚กใ‚คใƒซใฎใ‚ขใƒƒใƒ—ใƒญใƒผใƒ‰ใ‚’ไป‹ใ—ใฆ่ช่จผใชใ—ใฎใƒชใƒขใƒผใƒˆใ‚ณใƒผใƒ‰ๅฎŸ่กŒใŒๅฏ่ƒฝใซใชใ‚‹ ใ€๏ผš #TheHackerNews

ใ€Œ0ไธ‡ไปถไปฅไธŠใฎใ‚คใƒณใ‚นใƒˆใƒผใƒซๅฎŸ็ธพใ‚’ๆŒใคWordPressใƒ—ใƒฉใ‚ฐใ‚คใƒณใ€ŒForminator Formsใ€ใซใ€้‡ๅคงใชใ‚ปใ‚ญใƒฅใƒชใƒ†ใ‚ฃไธŠใฎๆฌ ้™ฅใŒ็™บ่ฆ‹ใ•ใ‚ŒใŸใ€‚ใ“ใฎๆฌ ้™ฅใ‚’ๆ‚ช็”จใ™ใ‚Œใฐใ€่„†ๅผฑๆ€งใฎใ‚ใ‚‹ใ‚ตใ‚คใƒˆใงไปปๆ„ใฎใ‚ณใƒผใƒ‰ใ‚’ๅฎŸ่กŒใงใใ‚‹ๅฏ่ƒฝๆ€งใŒใ‚ใ‚‹ใ€‚

CVE-2026-15748 ใจใ—ใฆ่ฟฝ่ทกใ•ใ‚Œใฆใ„ใ‚‹ใ“ใฎ่„†ๅผฑๆ€งใฏ ใ€CVSSใ‚นใ‚ณใ‚ขใƒชใƒณใ‚ฐใ‚ทใ‚นใƒ†ใƒ ใง10็‚นๆบ€็‚นไธญ9.8็‚นใจ่ฉ•ไพกใ•ใ‚Œใฆใ„ใ‚‹ใ€‚ใ“ใฎ่„†ๅผฑๆ€งใฏใ€ใ€Œdarooใ€ใจใ„ใ†ใ‚ชใƒณใƒฉใ‚คใƒณไธŠใฎใƒ‹ใƒƒใ‚ฏใƒใƒผใƒ ใ‚’ๆŒใคใ‚ปใ‚ญใƒฅใƒชใƒ†ใ‚ฃ็ ”็ฉถ่€…ใซใ‚ˆใฃใฆ็™บ่ฆ‹ใ•ใ‚Œใ€ๅ ฑๅ‘Šใ•ใ‚ŒใŸใ€‚

thehackernews.com/2026/08/form

#prattohome

##

DailyCyberSecurity@infosec.exchange at 2026-08-18T01:52:19.000Z ##

CVE-2026-15748 (CVSS 9.8): Forminator Flaw Enables Pre-Auth RCE

securityonline.info/cve-2026-1

##

CVE-2026-76589
(9.9 CRITICAL)

EPSS: 0.61%

updated 2026-08-20T12:48:10.287000

4 posts

A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.

offseq at 2026-08-20T04:30:26.310Z ##

TRENDnet TEW-755AP is affected by CVE-2026-76589 (CRITICAL, CVSS 9.4): stack-based buffer overflow in /sbin/mycli, exploitable remotely. Public exploit; no patch yet. Restrict device access and monitor. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-19T23:00:26.000Z ##

๐Ÿ”ด CVE-2026-76589 - Critical (9.9)

A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack may be launched remotely. The exp...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-20T04:30:26.000Z ##

TRENDnet TEW-755AP is affected by CVE-2026-76589 (CRITICAL, CVSS 9.4): stack-based buffer overflow in /sbin/mycli, exploitable remotely. Public exploit; no patch yet. Restrict device access and monitor. radar.offseq.com/threat/cve-20 #OffSeq #CVE202676589 #IoTSecurity

##

thehackerwire@mastodon.social at 2026-08-19T23:00:26.000Z ##

๐Ÿ”ด CVE-2026-76589 - Critical (9.9)

A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack may be launched remotely. The exp...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76590
(9.9 CRITICAL)

EPSS: 0.61%

updated 2026-08-20T12:48:10.287000

4 posts

A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument cameo.wan.wan_pppoe_password_00 leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.

offseq at 2026-08-20T00:00:37.743Z ##

CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch โ€” restrict access, monitor endpoints. Exploit code public, no active attacks yet. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-19T23:01:04.000Z ##

๐Ÿ”ด CVE-2026-76590 - Critical (9.9)

A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument cameo.wan.wan_pppoe_password_00 leads to...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-20T00:00:37.000Z ##

CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch โ€” restrict access, monitor endpoints. Exploit code public, no active attacks yet. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec #CVE2026

##

thehackerwire@mastodon.social at 2026-08-19T23:01:04.000Z ##

๐Ÿ”ด CVE-2026-76590 - Critical (9.9)

A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument cameo.wan.wan_pppoe_password_00 leads to...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15826
(9.8 CRITICAL)

EPSS: 2.48%

updated 2026-08-20T12:48:10.287000

2 posts

The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user() before performing an is_wp_error() check โ€” when a registration is submitted with a 61โ€“70 character username, WordPress core rejects it with a WP_Error

1 repos

https://github.com/HORKimhab/CVE-2026-15826-CVE-2026-15748

guru@thecybersecguru.com at 2026-08-19T05:14:10.000Z ##

Critical WordPress Alert: Dissecting CVE-2026-15748 (Forminator RCE) & CVE-2026-15826 (UPB Auth Bypass)

CVE-2026-15748 enables critical Forminator RCE, while CVE-2026-15826 allows User Profile Builder authentication bypass. Learn how to detect and patch both

thecybersecguru.com/news/cve-2

##

beyondmachines1@infosec.exchange at 2026-08-18T10:01:46.000Z ##

Critical Authentication Bypass Reported in User Profile Builder

Cozmoslabs patched a critical authentication bypass vulnerability (CVE-2026-15826) in the User Profile Builder WordPress plugin that allowed unauthenticated attackers to gain full administrative control.

**If you run the User Profile Builder plugin on WordPress, update it to version 3.16.5 or later ASAP. If you can't update immediately, turn off the "Automatically Log In after Registration" setting in the plugin options, and check whether your admin account is user ID 1 and if possible switch to a different admin account.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-73198
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-20T12:31:29

2 posts

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsiveness, and a denial of service (DoS) condition.

thehackerwire@mastodon.social at 2026-08-20T12:01:00.000Z ##

๐ŸŸ  CVE-2026-73198 - High (7.5)

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memor...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-20T12:01:00.000Z ##

๐ŸŸ  CVE-2026-73198 - High (7.5)

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memor...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13097
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-08-20T12:31:22

2 posts

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized a

thehackerwire@mastodon.social at 2026-08-20T12:01:13.000Z ##

๐Ÿ”ด CVE-2026-13097 - Critical (9.1)

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-20T12:01:13.000Z ##

๐Ÿ”ด CVE-2026-13097 - Critical (9.1)

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75860
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-08-20T12:31:22

2 posts

The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to enable user registration and set the default role to administrator, leading to privilege escalation and full site takeover.

offseq at 2026-08-20T07:30:24.479Z ##

CVE-2026-75860: CRITICAL privilege escalation in JSON Options โ‰ค0.0.4. Unauthenticated attackers can update WordPress options & gain admin access. Remove or disable plugin until fix is available. Full site takeover risk. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-20T07:30:24.000Z ##

CVE-2026-75860: CRITICAL privilege escalation in JSON Options โ‰ค0.0.4. Unauthenticated attackers can update WordPress options & gain admin access. Remove or disable plugin until fix is available. Full site takeover risk. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202675860

##

CVE-2026-14950
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-08-20T09:31:23

6 posts

An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access to the FDS web interface.

DailyCyberSecurity at 2026-08-20T16:54:52.158Z ##

Frauscher FDS102 vulnerabilities include CVE-2026-14950 (CVSS 9.8), a session flaw enabling unauthorized continued access. Update to v2.14.0.

securityonline.info/frauscher-

##

offseq at 2026-08-20T09:00:26.414Z ##

Frauscher FDS 102 v2.1.0 hit by CRITICAL vuln (CVE-2026-14950): insufficient session expiration lets remote attackers keep using stolen session tokens. No patch yet โ€” monitor sessions, restrict access. radar.offseq.com/threat/cve-20

##

certvde at 2026-08-20T08:20:37.575Z ##

VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

frauscher.csaf-tp.certvde.com/

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T16:54:52.000Z ##

Frauscher FDS102 vulnerabilities include CVE-2026-14950 (CVSS 9.8), a session flaw enabling unauthorized continued access. Update to v2.14.0.

#Frauscher #FDS102 #ICS #RailwaySecurity #CVE #OTSecurity

securityonline.info/frauscher-

##

offseq@infosec.exchange at 2026-08-20T09:00:26.000Z ##

Frauscher FDS 102 v2.1.0 hit by CRITICAL vuln (CVE-2026-14950): insufficient session expiration lets remote attackers keep using stolen session tokens. No patch yet โ€” monitor sessions, restrict access. radar.offseq.com/threat/cve-20 #OffSeq #ICS #CVE202614950 #Security

##

certvde@infosec.exchange at 2026-08-20T08:20:37.000Z ##

#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

#CSAF frauscher.csaf-tp.certvde.com/

##

CVE-2026-14949
(6.5 MEDIUM)

EPSS: 0.26%

updated 2026-08-20T09:31:23

2 posts

A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.

certvde at 2026-08-20T08:20:37.575Z ##

VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

frauscher.csaf-tp.certvde.com/

##

certvde@infosec.exchange at 2026-08-20T08:20:37.000Z ##

#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

#CSAF frauscher.csaf-tp.certvde.com/

##

CVE-2026-14948
(8.8 HIGH)

EPSS: 0.39%

updated 2026-08-20T09:31:23

2 posts

A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.

certvde at 2026-08-20T08:20:37.575Z ##

VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

frauscher.csaf-tp.certvde.com/

##

certvde@infosec.exchange at 2026-08-20T08:20:37.000Z ##

#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

#CSAF frauscher.csaf-tp.certvde.com/

##

CVE-2026-14953
(4.3 MEDIUM)

EPSS: 0.20%

updated 2026-08-20T09:31:23

2 posts

A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.

certvde at 2026-08-20T08:20:37.575Z ##

VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

frauscher.csaf-tp.certvde.com/

##

certvde@infosec.exchange at 2026-08-20T08:20:37.000Z ##

#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

#CSAF frauscher.csaf-tp.certvde.com/

##

CVE-2026-14951
(8.0 HIGH)

EPSS: 0.16%

updated 2026-08-20T09:31:23

2 posts

An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.

certvde at 2026-08-20T08:20:37.575Z ##

VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

frauscher.csaf-tp.certvde.com/

##

certvde@infosec.exchange at 2026-08-20T08:20:37.000Z ##

#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

#CSAF frauscher.csaf-tp.certvde.com/

##

CVE-2026-14947
(7.2 HIGH)

EPSS: 0.94%

updated 2026-08-20T09:31:23

2 posts

A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise.

certvde at 2026-08-20T08:20:37.575Z ##

VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

frauscher.csaf-tp.certvde.com/

##

certvde@infosec.exchange at 2026-08-20T08:20:37.000Z ##

#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

#CSAF frauscher.csaf-tp.certvde.com/

##

CVE-2026-14946
(7.2 HIGH)

EPSS: 0.52%

updated 2026-08-20T09:16:45.813000

2 posts

A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.

certvde at 2026-08-20T08:20:37.575Z ##

VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

frauscher.csaf-tp.certvde.com/

##

certvde@infosec.exchange at 2026-08-20T08:20:37.000Z ##

#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

#CSAF frauscher.csaf-tp.certvde.com/

##

CVE-2026-64849
(9.3 CRITICAL)

EPSS: 8.15%

updated 2026-08-20T04:16:56.280000

13 posts

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated addr

Nuclei template

3 repos

https://github.com/BiuTrap/CVE-2026-64849

https://github.com/zavisco/CVE-2026-64849.yaml

https://github.com/codeb0ssx/CVE-2026-64849-PoC

thecybermind at 2026-08-20T16:44:32.901Z ##

CVE-2026-64849 exposes unauthenticated MLflow tracking servers to critical server-side request forgery (SSRF) threats via redirect bypasses. Discover immediate mitigation strategies, CISA KEV compliance guidelines, and SOC detection playbooks to secure your AI infrastructure. thecybermind.co/jily

##

cyberworldops at 2026-08-20T14:20:00.407Z ##

CISA has detected active exploitation of CVE-2026-64849, a critical SSRF in MLflow. Exposed tracking servers without authentication can be abused to query cloud metadata, internal services, and loopback addresses, leading to credential theft and internal reconnaissance.

cyberworldops.eu/en/mlflow-und

##

Matchbook3469@mastodon.social at 2026-08-19T22:57:22.000Z ##

๐Ÿ”ด New security advisory:

CVE-2026-64849 affects Lfprojects Mlflow.

โ€ข Impact: Remote code execution or complete system compromise possible
โ€ข Risk: Attackers can gain full control of affected systems
โ€ข Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#CVE #VulnerabilityManagement #CyberSec

##

secdb at 2026-08-19T19:00:12.467Z ##

๐Ÿšจ [CISA-2026:0819] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

โš ๏ธ CVE-2026-64849 (secdb.nttzen.cloud/cve/detail/)
- Name: MLflow Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MLflow
- Product: MLflow
- Notes: github.com/mlflow/mlflow/pull/ ; github.com/mlflow/mlflow/issue ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-08-19T18:00:51.000Z ##

CVE ID: CVE-2026-64849
Vendor: MLflow
Product: MLflow
Date Added: 2026-08-19
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

beyondmachines1 at 2026-08-19T08:01:23.736Z ##

Attackers Exploit a Critical MLflow Vulnerability

Attackers are actively exploiting a critical flaw in MLflow (CVE-2026-64849) to steal cloud credentials and gain remote code execution.

**If you run MLflow, update it to version 3.15.0 or later ASAP, and make sure the server is not reachable from the internet. Then check your audit logs for any odd requests to cloud metadata services. If you see any (or aren't sure), rotate your cloud credentials and keys as a precaution.**

beyondmachines.net/event_detai

##

thecybermind@infosec.exchange at 2026-08-20T16:44:32.000Z ##

CVE-2026-64849 exposes unauthenticated MLflow tracking servers to critical server-side request forgery (SSRF) threats via redirect bypasses. Discover immediate mitigation strategies, CISA KEV compliance guidelines, and SOC detection playbooks to secure your AI infrastructure. thecybermind.co/jily

##

cyberworldops@infosec.exchange at 2026-08-20T14:20:00.000Z ##

CISA has detected active exploitation of CVE-2026-64849, a critical SSRF in MLflow. Exposed tracking servers without authentication can be abused to query cloud metadata, internal services, and loopback addresses, leading to credential theft and internal reconnaissance.

#CloudSecurity #SSRF #Vulnerability #ThreatIntel

cyberworldops.eu/en/mlflow-und

##

secdb@infosec.exchange at 2026-08-19T19:00:12.000Z ##

๐Ÿšจ [CISA-2026:0819] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

โš ๏ธ CVE-2026-64849 (secdb.nttzen.cloud/cve/detail/)
- Name: MLflow Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MLflow
- Product: MLflow
- Notes: github.com/mlflow/mlflow/pull/ ; github.com/mlflow/mlflow/issue ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260819 #cisa20260819 #cve_2026_64849 #cve202664849

##

cisakevtracker@mastodon.social at 2026-08-19T18:00:51.000Z ##

CVE ID: CVE-2026-64849
Vendor: MLflow
Product: MLflow
Date Added: 2026-08-19
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

beyondmachines1@infosec.exchange at 2026-08-19T08:01:23.000Z ##

Attackers Exploit a Critical MLflow Vulnerability

Attackers are actively exploiting a critical flaw in MLflow (CVE-2026-64849) to steal cloud credentials and gain remote code execution.

**If you run MLflow, update it to version 3.15.0 or later ASAP, and make sure the server is not reachable from the internet. Then check your audit logs for any odd requests to cloud metadata services. If you see any (or aren't sure), rotate your cloud credentials and keys as a precaution.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-08-18T20:20:00.000Z ##

Active exploitation of CVE-2026-64849 in MLflow enables unauthenticated SSRF to internal endpoints including cloud metadata services. FUXA, a SCADA/HMI platform for industrial automation, faces parallel exposure. Both flaws were confirmed independently by watchTowr and VulnCheck.

#MLflowVulnerability #FUXACVE #IndustrialOT #AISecurity

cyberworldops.eu/en/mlflow-and

##

DailyCyberSecurity@infosec.exchange at 2026-08-18T12:33:19.000Z ##

A public PoC for CVE-2026-64849, an unauthenticated MLflow SSRF (CVSS 9.3), is now live. watchTowr reports exploitation attempts. Patch to 3.15.0.

#MLflow #CVE202664849 #SSRF #watchTowr #AISecurity #InfoSec

securityonline.info/mlflow-ssr

##

CVE-2026-76928
(7.5 HIGH)

EPSS: 0.28%

updated 2026-08-20T00:35:18

2 posts

X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

thehackerwire@mastodon.social at 2026-08-19T23:59:47.000Z ##

๐ŸŸ  CVE-2026-76928 - High (7.5)

X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T23:59:47.000Z ##

๐ŸŸ  CVE-2026-76928 - High (7.5)

X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76760
(7.3 HIGH)

EPSS: 0.33%

updated 2026-08-20T00:35:17

1 posts

A vulnerability was found in chenhg5 cc-connect up to 1.4.1. Affected by this vulnerability is the function Authenticate of the file core/webhook.go. The manipulation of the argument exec results in code injection. The attack may be performed from remote. The exploit has been made public and could be used. The reported GitHub issue was closed automatically due to inactivity.

hugovalters@mastodon.social at 2026-08-20T17:10:46.000Z ##

CVE-2026-76760 - Code injection in chenhg5 cc-connect <=1.4.1 via Authenticate (core/webhook.go). Remote exploit public, CVSS 7.3, no patch yet. Limit access and monitor logs. #CVE #infosec #codeinjection

valtersit.com/cve/CVE-2026-767

##

CVE-2026-76850
(9.8 CRITICAL)

EPSS: 0.98%

updated 2026-08-20T00:35:17

4 posts

LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes with pickle.loads(), and the isinstance check against DistServeCacheFreeRequest runs only after deserialization has already completed. The peer that supplie

offseq at 2026-08-20T01:30:25.153Z ##

CVE-2026-76850 (CRITICAL): InternLM lmdeploy <0.16.0 vulnerable to remote code execution via untrusted pickle deserialization on ZeroMQ endpoints. Enable API keys or disable disaggregated serving to mitigate. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-19T23:00:07.000Z ##

๐Ÿ”ด CVE-2026-76850 - Critical (9.8)

LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes wit...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-20T01:30:25.000Z ##

CVE-2026-76850 (CRITICAL): InternLM lmdeploy <0.16.0 vulnerable to remote code execution via untrusted pickle deserialization on ZeroMQ endpoints. Enable API keys or disable disaggregated serving to mitigate. radar.offseq.com/threat/cve-20 #OffSeq #Infosec #Vuln #CVE202676850

##

thehackerwire@mastodon.social at 2026-08-19T23:00:07.000Z ##

๐Ÿ”ด CVE-2026-76850 - Critical (9.8)

LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes wit...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76880
(7.5 HIGH)

EPSS: 0.28%

updated 2026-08-20T00:35:17

2 posts

RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

thehackerwire@mastodon.social at 2026-08-20T01:04:26.000Z ##

๐ŸŸ  CVE-2026-76880 - High (7.5)

RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-20T01:04:26.000Z ##

๐ŸŸ  CVE-2026-76880 - High (7.5)

RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76395
(8.8 HIGH)

EPSS: 0.47%

updated 2026-08-20T00:35:11

3 posts

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible because a model codec in Splunk AI Toolkit deserializes sparse matrix data without guarding against embedded pickle content. For more information see Tro

sayzard@mastodon.sayzard.org at 2026-08-20T10:42:32.000Z ##

Splunk patches 9.1 CVSS RCE in MCP Server and 9 flaws in AI Toolkit

Splunk์ด MCP Server, AI Toolkit, Splunk Connect for Kafka ๋“ฑ์—์„œ ๋ฐœ๊ฒฌ๋œ 17๊ฐœ ์ทจ์•ฝ์ ์˜ ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ๋ฅผ ๋ฐฐํฌํ–ˆ๋‹ค. ๊ฐ€์žฅ ์‹ฌ๊ฐํ•œ CVE-2026-76404(CVSS 9.1)๋Š” Splunk MCP Server 1.2.1 ๋ฏธ๋งŒ์—์„œ ๊ด€๋ฆฌ์ž ๊ถŒํ•œ ์‚ฌ์šฉ์ž๊ฐ€ ์ž๊ฒฉ ์ฆ๋ช… ๊ด€๋ฆฌ ๊ธฐ๋Šฅ์˜ ์•ˆ์ „ํ•˜์ง€ ์•Š์€ ์—ญ์ง๋ ฌํ™”๋ฅผ ์•…์šฉํ•ด ํ˜ธ์ŠคํŠธ OS ๋ช…๋ น์„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋Š” RCE๋‹ค. AI Toolkit์—๋„ ์•…์„ฑ sparse matrix/pickle ๋ฐ์ดํ„ฐ๋ฅผ ํฌํ•จํ•œ ๋ชจ๋ธ ๋กœ๋”ฉ์œผ๋กœ ์ฝ”๋“œ ์‹คํ–‰์ด ๊ฐ€๋Šฅํ•œ CVE-2026-76395(CVSS 8.8)๋ฅผ ํฌํ•จํ•ด...

cyberupdates365.com/splunk-mcp

##

thehackerwire@mastodon.social at 2026-08-19T23:01:24.000Z ##

๐ŸŸ  CVE-2026-76395 - High (8.8)

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T23:01:24.000Z ##

๐ŸŸ  CVE-2026-76395 - High (8.8)

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76399
(8.1 HIGH)

EPSS: 0.25%

updated 2026-08-20T00:35:11

2 posts

In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access to all relevant data and affect system integrity. The vulnerability is possible because Splunk AI Toolkit gives the "power" Splunk role permission to mod

thehackerwire@mastodon.social at 2026-08-20T05:00:25.000Z ##

๐ŸŸ  CVE-2026-76399 - High (8.1)

In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-20T05:00:25.000Z ##

๐ŸŸ  CVE-2026-76399 - High (8.1)

In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76397
(8.1 HIGH)

EPSS: 0.25%

updated 2026-08-20T00:35:11

2 posts

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolkit does not preserve the trusted experiment scope when it processes caller-controlled query values before accessing restricted history data. For more info

thehackerwire@mastodon.social at 2026-08-20T05:00:14.000Z ##

๐ŸŸ  CVE-2026-76397 - High (8.1)

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolki...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-20T05:00:14.000Z ##

๐ŸŸ  CVE-2026-76397 - High (8.1)

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolki...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76396
(7.5 HIGH)

EPSS: 0.24%

updated 2026-08-20T00:35:11

2 posts

In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible because Splunk AI Toolkit does not mark the apply search command as risky. For more information see Troubleshoot the AI Toolkit (https://help.splunk.com/e

thehackerwire@mastodon.social at 2026-08-20T05:00:04.000Z ##

๐ŸŸ  CVE-2026-76396 - High (7.5)

In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible b...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-20T05:00:04.000Z ##

๐ŸŸ  CVE-2026-76396 - High (7.5)

In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible b...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76404
(9.1 CRITICAL)

EPSS: 0.56%

updated 2026-08-20T00:35:08

7 posts

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking whether the content is of the expected type.

sayzard@mastodon.sayzard.org at 2026-08-20T10:42:32.000Z ##

Splunk patches 9.1 CVSS RCE in MCP Server and 9 flaws in AI Toolkit

Splunk์ด MCP Server, AI Toolkit, Splunk Connect for Kafka ๋“ฑ์—์„œ ๋ฐœ๊ฒฌ๋œ 17๊ฐœ ์ทจ์•ฝ์ ์˜ ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ๋ฅผ ๋ฐฐํฌํ–ˆ๋‹ค. ๊ฐ€์žฅ ์‹ฌ๊ฐํ•œ CVE-2026-76404(CVSS 9.1)๋Š” Splunk MCP Server 1.2.1 ๋ฏธ๋งŒ์—์„œ ๊ด€๋ฆฌ์ž ๊ถŒํ•œ ์‚ฌ์šฉ์ž๊ฐ€ ์ž๊ฒฉ ์ฆ๋ช… ๊ด€๋ฆฌ ๊ธฐ๋Šฅ์˜ ์•ˆ์ „ํ•˜์ง€ ์•Š์€ ์—ญ์ง๋ ฌํ™”๋ฅผ ์•…์šฉํ•ด ํ˜ธ์ŠคํŠธ OS ๋ช…๋ น์„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋Š” RCE๋‹ค. AI Toolkit์—๋„ ์•…์„ฑ sparse matrix/pickle ๋ฐ์ดํ„ฐ๋ฅผ ํฌํ•จํ•œ ๋ชจ๋ธ ๋กœ๋”ฉ์œผ๋กœ ์ฝ”๋“œ ์‹คํ–‰์ด ๊ฐ€๋Šฅํ•œ CVE-2026-76395(CVSS 8.8)๋ฅผ ํฌํ•จํ•ด...

cyberupdates365.com/splunk-mcp

##

DailyCyberSecurity at 2026-08-20T05:31:55.609Z ##

Splunk patches CVE-2026-76404, a critical remote code execution flaw in the MCP Server app, plus 16 more bugs across its apps and add-ons.

securityonline.info/splunk-app

##

offseq at 2026-08-20T03:00:25.879Z ##

Splunk MCP Server app v1.2 is impacted by CVE-2026-76404 (CRITICAL, CVSS 9.1) โ€” insecure deserialization lets admin users run arbitrary OS commands. Limit admin access & monitor for misuse until a patch is released. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-19T23:00:17.000Z ##

๐Ÿ”ด CVE-2026-76404 - Critical (9.1)

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T05:31:55.000Z ##

Splunk patches CVE-2026-76404, a critical remote code execution flaw in the MCP Server app, plus 16 more bugs across its apps and add-ons.

#Splunk #CVE #RemoteCodeExecution #RCE #MCPServer #Deserialization #InfoSec #PatchNow

securityonline.info/splunk-app

##

offseq@infosec.exchange at 2026-08-20T03:00:25.000Z ##

Splunk MCP Server app v1.2 is impacted by CVE-2026-76404 (CRITICAL, CVSS 9.1) โ€” insecure deserialization lets admin users run arbitrary OS commands. Limit admin access & monitor for misuse until a patch is released. radar.offseq.com/threat/cve-20 #OffSeq #Splunk #Infosec #CVE202676404

##

thehackerwire@mastodon.social at 2026-08-19T23:00:17.000Z ##

๐Ÿ”ด CVE-2026-76404 - Critical (9.1)

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76325
(7.3 HIGH)

EPSS: 0.25%

updated 2026-08-20T00:35:02

1 posts

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a malicious ui-tour knowledge object that matches an auto-tour page name and share the object at the app level. The object can execute arbitrary JavaScript in the browser of another authenticated user who visits a standard Splunk Web page. The JavaScript could expose all rel

hugovalters@mastodon.social at 2026-08-20T15:02:52.000Z ##

CVE-2026-76325 - Stored XSS in Splunk Enterprise. Power role can share malicious ui-tour object, executing JS in authenticated users' browsers. CVSS 7.3. Update to fixed versions immediately. #CVE #Splunk #infosec

valtersit.com/cve/CVE-2026-763

##

CVE-2026-76333
(7.1 HIGH)

EPSS: 0.25%

updated 2026-08-20T00:35:02

1 posts

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a Dashboard Studio workflow action with a crafted Uniform Resource Locator (URL). When another authenticated user selects the stored action from Event Actions and selects Continue, attacker-controlled JavaScript runs in the browser of that user. This could expose data or act

hugovalters@mastodon.social at 2026-08-20T12:07:38.000Z ##

CVE-2026-76333 - Stored XSS in Splunk Enterprise Dashboard Studio. Crafted URL triggers attacker JS in user's browser, exposing data. CVSS 7.1. No official patch - mitigate now. #CVE #Splunk #infosec

valtersit.com/cve/CVE-2026-763

##

CVE-2026-76262
(7.5 HIGH)

EPSS: 0.37%

updated 2026-08-20T00:35:02

1 posts

In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus service metrics from the Edge Processor SPL2 Preview sidecar, including service details that expose relevant runtime and build metadata for the sidecar. The vulnerability does not affect Splunk Enterprise versions below 10.4. The information disclosure is possible because the Prometheus metrics endpoint

hugovalters@mastodon.social at 2026-08-20T11:08:34.000Z ##

CVE-2026-76262 - Info disclosure in Splunk Enterprise <10.4.2. Unauthenticated access to Prometheus metrics via Edge Processor SPL2 Preview sidecar. CVSS 7.5. Update to 10.4.2. #CVE #Splunk #infosec

valtersit.com/cve/CVE-2026-762

##

CVE-2026-76310
(9.4 CRITICAL)

EPSS: 0.37%

updated 2026-08-20T00:34:56

2 posts

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material, and use it to access all relevant data available to the report owner and affect system integrity, including by performing administrative actions when the owner holds the "admin" Splunk r

CVE-2026-20030
(10.0 CRITICAL)

EPSS: 0.45%

updated 2026-08-19T21:31:32

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20030 are related to improper neutralization of special elements used

CVE-2026-76583
(7.4 HIGH)

EPSS: 1.07%

updated 2026-08-19T21:30:47

1 posts

A vulnerability was identified in TRENDnet TV-IP751WIC 11.03.03. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The manipulation leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used.

hugovalters@mastodon.social at 2026-08-20T01:09:07.000Z ##

CVE-2026-76583 - Command injection in TRENDnet TV-IP751WIC via set_time.cgi. CVSS 7.4. Exploit public, no patch. Disable remote access now. #CVE #TRENDnet #infosec

valtersit.com/cve/CVE-2026-765

##

CVE-2026-75569
(7.7 HIGH)

EPSS: 0.29%

updated 2026-08-19T21:30:46

2 posts

A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during the build. The consequence is a compromised build process, potentially leading to t

thehackerwire@mastodon.social at 2026-08-19T22:00:41.000Z ##

๐ŸŸ  CVE-2026-75569 - High (7.7)

A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T22:00:41.000Z ##

๐ŸŸ  CVE-2026-75569 - High (7.7)

A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76139
(8.0 HIGH)

EPSS: 0.33%

updated 2026-08-19T21:30:46

2 posts

A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote attacker could exploit this vulnerability to inject malicious code, leading to u

thehackerwire@mastodon.social at 2026-08-19T22:00:16.000Z ##

๐ŸŸ  CVE-2026-76139 - High (8)

A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub acces...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T22:00:16.000Z ##

๐ŸŸ  CVE-2026-76139 - High (8)

A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub acces...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76584
(9.9 CRITICAL)

EPSS: 0.49%

updated 2026-08-19T21:30:40

2 posts

A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The manipulation of the argument Currenttime results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

thehackerwire@mastodon.social at 2026-08-19T22:00:27.000Z ##

๐Ÿ”ด CVE-2026-76584 - Critical (9.9)

A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The manipulation of the argument Currenttime results in st...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T22:00:27.000Z ##

๐Ÿ”ด CVE-2026-76584 - Critical (9.9)

A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The manipulation of the argument Currenttime results in st...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18848
(8.3 HIGH)

EPSS: 0.10%

updated 2026-08-19T21:30:32

2 posts

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An attacker who can lure a logged-in ASMI administrator to visit a crafted web page can, under specific conditions, silently perform administrative actions on the FSP on behalf of that administrator, resulting in a c

thehackerwire@mastodon.social at 2026-08-19T20:00:28.000Z ##

๐ŸŸ  CVE-2026-18848 - High (8.3)

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An attacker who can lure a logged-in ASMI administrator to visi...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T20:00:28.000Z ##

๐ŸŸ  CVE-2026-18848 - High (8.3)

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An attacker who can lure a logged-in ASMI administrator to visi...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20317
(10.0 CRITICAL)

EPSS: 0.34%

updated 2026-08-19T21:30:29

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20317 are related to improper authentication issues that are gr

DailyCyberSecurity at 2026-08-20T02:06:30.600Z ##

Cisco patches Secure Workload flaws CVE-2026-20315 and CVE-2026-20317, an authentication bypass and privilege escalation pair scoring CVSS 10. Upgrade now.

securityonline.info/cisco-secu

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T02:06:30.000Z ##

Cisco patches Secure Workload flaws CVE-2026-20315 and CVE-2026-20317, an authentication bypass and privilege escalation pair scoring CVSS 10. Upgrade now.

#Cisco #CVE #AuthenticationBypass #PrivilegeEscalation #Vulnerability #InfoSec #PatchNow

securityonline.info/cisco-secu

##

CVE-2026-68900
(7.6 HIGH)

EPSS: 0.25%

updated 2026-08-19T20:17:21.727000

2 posts

Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/lib/exportHTML.js read a card title and body through textContent, which decoded entity-encoded markup, and then interpolated titleText and allText into content.innerHTML in the exported index.html. A board member could store an entity-encoded event-handler payload in a card title that remained inert

thehackerwire@mastodon.social at 2026-08-19T21:00:45.000Z ##

๐ŸŸ  CVE-2026-68900 - High (7.6)

Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/lib/exportHTML.js read a card title and body through textContent, which decoded entity-encoded markup, and then interpolated titleText and allText ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T21:00:45.000Z ##

๐ŸŸ  CVE-2026-68900 - High (7.6)

Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/lib/exportHTML.js read a card title and body through textContent, which decoded entity-encoded markup, and then interpolated titleText and allText ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52877
(8.3 HIGH)

EPSS: 0.30%

updated 2026-08-19T19:17:19.177000

2 posts

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url directly to Electron's shell.openExternal without validating its protocol. A compromised renderer can submit file: URIs or operating-system-specific custom schemes, causing the host to open local files

thehackerwire@mastodon.social at 2026-08-18T23:00:38.000Z ##

๐ŸŸ  CVE-2026-52877 - High (8.3)

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url directly to Electron's shell.openExternal withou...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-18T23:00:38.000Z ##

๐ŸŸ  CVE-2026-52877 - High (8.3)

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url directly to Electron's shell.openExternal withou...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50191
(8.8 HIGH)

EPSS: 0.33%

updated 2026-08-19T19:17:18.273000

2 posts

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft, or OIDC SSO is configured. The POST /api/register endpoint permits creation of an unverified local account with a victim's email address, and POST /api/

thehackerwire@mastodon.social at 2026-08-19T00:00:15.000Z ##

๐ŸŸ  CVE-2026-50191 - High (8.8)

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft,...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T00:00:15.000Z ##

๐ŸŸ  CVE-2026-50191 - High (8.8)

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft,...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75149
(8.8 HIGH)

EPSS: 0.64%

updated 2026-08-19T18:33:02

2 posts

marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a notebook. When the notebook is opened in edit mode, marimo launches the specified command as a local subprocess before any notebook cell is executed, re

thehackerwire@mastodon.social at 2026-08-19T19:00:17.000Z ##

๐ŸŸ  CVE-2026-75149 - High (8.8)

marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T19:00:17.000Z ##

๐ŸŸ  CVE-2026-75149 - High (8.8)

marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-32475
(9.0 None)

EPSS: 0.42%

updated 2026-08-19T18:32:57

8 posts

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.

cyberworldops at 2026-08-20T16:20:01.246Z ##

A critical flaw in Elementor Pro (CVE-2026-32475) enables unauthenticated remote code execution via the File Upload module. Two desynchronized processing loops mishandle empty filenames, bypassing validation entirely. All versions below 4.2.2 are affected. Patch immediately and audit server logs for indicators of exploitation.

cyberworldops.eu/en/elementor-

##

undercodenews@mastodon.social at 2026-08-20T15:06:07.000Z ##

Elementor Pro Security Crisis: Critical WordPress Flaw Could Turn File Uploads Into Remote Code Execution

A Dangerous WordPress Vulnerability Hiding Behind a Familiar Feature A seemingly ordinary file-upload feature in Elementor Pro has become the center of a serious WordPress security warning. A newly disclosed vulnerability, tracked as CVE-2026-32475, could allow an attacker to upload a malicious PHP file to a vulnerable website and ultimately execute arbitraryโ€ฆ

undercodenews.com/elementor-pr

##

Analyst207@mastodon.social at 2026-08-20T14:56:26.000Z ##

Elementor Pro Flaw Enables RCE Attacks on WordPress Sites

A critical vulnerability in Elementor Pro, tracked as CVE-2026-32475, allows attackers to launch remote code execution (RCE) attacks on WordPress sites by exploiting a discrepancy in the plugin's File Upload module. This flaw affects Elementor Pro versions before 4.2.2 and can be triggered by a specially crafted multipart upload.

osintsights.com/elementor-pro-

#Wordpress #ElementorPro #RemoteCodeExecution #Cve202632475 #PluginVulnerability

##

undercodenews@mastodon.social at 2026-08-20T12:51:55.000Z ##

Critical Elementor Pro WordPress Flaw Opens the Door to Remote Code Execution โ€” Millions of Sites Face a Dangerous Upload Risk + Video

A Serious WordPress Security Warning A newly disclosed vulnerability in Elementor Pro has turned an ordinary website feature into a potential gateway for attackers. The critical flaw, tracked as CVE-2026-32475, can allow an unauthenticated attacker to upload a malicious PHP file and execute code remotely on a vulnerable WordPressโ€ฆ

undercodenews.com/critical-ele

##

undercodenews@mastodon.social at 2026-08-20T12:46:34.000Z ##

Critical Elementor Pro Flaw Puts WordPress Sites at Risk of Unauthenticated PHP Code Execution + Video

A Dangerous Weakness in a Popular WordPress Ecosystem A newly reported critical security vulnerability in Elementor Pro is raising serious concerns for WordPress website owners, administrators, hosting providers, and security teams. Tracked as CVE-2026-32475, the flaw reportedly affects Elementor Pro installations up to version 4.2.1 and could allow an unauthenticatedโ€ฆ

undercodenews.com/critical-ele

##

shawnhooper@fosstodon.org at 2026-08-19T18:17:50.000Z ##

WordPress admins running Elementor Pro:

CVSS 9.8 - CVE-2026-32475

WordPress Elementor Pro Plugin <= 4.2.1 is vulnerable to a high priority Arbitrary File Upload

patchstack.com/articles/critic

#wordpresss

##

cyberworldops@infosec.exchange at 2026-08-20T16:20:01.000Z ##

A critical flaw in Elementor Pro (CVE-2026-32475) enables unauthenticated remote code execution via the File Upload module. Two desynchronized processing loops mishandle empty filenames, bypassing validation entirely. All versions below 4.2.2 are affected. Patch immediately and audit server logs for indicators of exploitation.

#ElementorPro #WordPress #RemoteCodeExecution #CVE202632475

cyberworldops.eu/en/elementor-

##

shawnhooper@fosstodon.org at 2026-08-19T18:17:50.000Z ##

WordPress admins running Elementor Pro:

CVSS 9.8 - CVE-2026-32475

WordPress Elementor Pro Plugin <= 4.2.1 is vulnerable to a high priority Arbitrary File Upload

patchstack.com/articles/critic

#wordpresss

##

CVE-2026-75143
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-08-19T18:32:57

2 posts

FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overflowing it when the payload exceeds the destination size. This is reachable via the async:rist:// URL scheme, where the async wrapper supplies a smaller

thehackerwire@mastodon.social at 2026-08-19T18:01:18.000Z ##

๐Ÿ”ด CVE-2026-75143 - Critical (9.8)

FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, ove...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T18:01:18.000Z ##

๐Ÿ”ด CVE-2026-75143 - Critical (9.8)

FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, ove...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75142
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-19T18:32:57

2 posts

FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams triggers the overflow during MPEG-PS muxing.

thehackerwire@mastodon.social at 2026-08-19T18:00:35.000Z ##

๐ŸŸ  CVE-2026-75142 - High (7.8)

FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with a...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T18:00:35.000Z ##

๐ŸŸ  CVE-2026-75142 - High (7.8)

FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with a...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75146
(8.1 HIGH)

EPSS: 0.26%

updated 2026-08-19T18:32:57

2 posts

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an

thehackerwire@mastodon.social at 2026-08-19T18:00:06.000Z ##

๐ŸŸ  CVE-2026-75146 - High (8.1)

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negativ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T18:00:06.000Z ##

๐ŸŸ  CVE-2026-75146 - High (8.1)

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negativ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-60727
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-08-19T18:32:35

1 posts

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Mana

infosecbot@mastodon.hofud.com at 2026-08-19T06:09:14.000Z ##

[1/9]

Most Impactful Security Incidents (โ€ฏ2026โ€‘08โ€‘18โ€ฏโ†’โ€ฏ2026โ€‘08โ€‘19โ€ฏ)

---

PRIORITYโ€ฏ1 โ€“ Critical / Highโ€‘Severity Flaws (CVSSโ€ฏ7โ€‘10):

CVEโ€‘2026โ€‘60392
โ€ข 7.8 (HIGH)
โ€ข Oracleโ€ฏOutsideโ€ฏInโ€ฏTechnology โ€“ PDF Export SDK (Fusion Middleware)
โ€ข Localโ€‘privilege escalation; requires attacker to have a logon on the host where the SDK runs. Successful exploitation can lead to full takeover of the component.
โ€ข 8.5.8
โ€ข Easily exploitable (local) โ€“ requires user interaction.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60782
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏPayments (Eโ€‘Business Suite) โ€“ File Transmission
โ€ข Remote unauthenticated attacker can compromise the Payments module via HTTP. Leads to full takeover of the Payments service.
โ€ข 12.2.3โ€‘12.2.15
โ€ข Networkโ€‘accessible, no authentication required.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60730
โ€ข 9.9 (CRITICAL)
โ€ข Oracleโ€ฏWebCenterโ€ฏPortal โ€“ Composer component
โ€ข Remote unauthenticated attacker can compromise the portal via HTTP. Full takeover of the portal.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.0.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60728
โ€ข 9.1 (CRITICAL)
โ€ข Oracleโ€ฏWebCenterโ€ฏPortal โ€“ Portlet Services
โ€ข Remote unauthenticated attacker can cause denialโ€‘ofโ€‘service and full compromise of portal data.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.0.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60727
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Remote unauthenticated attacker can take over the IAM system via HTTP.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60721
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Same vector as above; full takeover possible.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60720
โ€ข 9.9 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Remote unauthenticated attacker can compromise the IAM system.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

#infosecnews

##

CVE-2026-60702
(9.9 CRITICAL)

EPSS: 0.42%

updated 2026-08-19T18:32:34

2 posts

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may signi

DailyCyberSecurity at 2026-08-19T02:42:04.742Z ##

An Oracle WebLogic vulnerability, CVE-2026-60702 (CVSS 9.9), allows full server takeover. Oracle patched nine flaws, five rated critical. Update now.

securityonline.info/oracle-web

##

DailyCyberSecurity@infosec.exchange at 2026-08-19T02:42:04.000Z ##

An Oracle WebLogic vulnerability, CVE-2026-60702 (CVSS 9.9), allows full server takeover. Oracle patched nine flaws, five rated critical. Update now.

#OracleWebLogic #CVE202660702 #RCE #FusionMiddleware #ServerTakeover #InfoSec

securityonline.info/oracle-web

##

CVE-2026-69414
(7.8 HIGH)

EPSS: 0.23%

updated 2026-08-19T18:32:28

1 posts

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;ShieldBreak &quot;. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

2 repos

https://github.com/1neptune/ShieldBreak

https://github.com/HORKimhab/CVE-2026-50656

CVE-2026-53958
(7.6 HIGH)

EPSS: 0.28%

updated 2026-08-19T17:19:23.613000

2 posts

4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEmail, ssoMicrosoftId, ssoMicrosoftEmail, ssoOidcId, and ssoOidcEmail through PATCH /api/users/:id. The whitelist in server/api/controllers/users/update.js mass assigns these backend-managed identity att

thehackerwire@mastodon.social at 2026-08-18T23:01:19.000Z ##

๐ŸŸ  CVE-2026-53958 - High (7.6)

4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEmail, ssoMicrosoftId, ssoMicrosoftEmail, ssoOidcI...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-18T23:01:19.000Z ##

๐ŸŸ  CVE-2026-53958 - High (7.6)

4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEmail, ssoMicrosoftId, ssoMicrosoftEmail, ssoOidcI...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18051
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-08-19T17:18:36.337000

2 posts

The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the same flaw overwrites the site's .htaccess files, which breaks the site and can stri

DailyCyberSecurity at 2026-08-19T08:53:58.362Z ##

CVE-2026-18051 (CVSS 10) is an unauthenticated arbitrary file write in W3 Total Cache, exposing 900k+ WordPress sites. Update to 2.10.5 now.

securityonline.info/w3-total-c

##

DailyCyberSecurity@infosec.exchange at 2026-08-19T08:53:58.000Z ##

CVE-2026-18051 (CVSS 10) is an unauthenticated arbitrary file write in W3 Total Cache, exposing 900k+ WordPress sites. Update to 2.10.5 now.

#W3TotalCache #WordPress #CVE202618051 #PathTraversal #InfoSec

securityonline.info/w3-total-c

##

CVE-2026-70408
(8.8 HIGH)

EPSS: 0.33%

updated 2026-08-19T16:18:58.590000

2 posts

An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.

thehackerwire@mastodon.social at 2026-08-19T06:00:01.000Z ##

๐ŸŸ  CVE-2026-70408 - High (8.8)

An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T06:00:01.000Z ##

๐ŸŸ  CVE-2026-70408 - High (8.8)

An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73924
(9.1 CRITICAL)

EPSS: 0.29%

updated 2026-08-19T15:33:23

2 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data o

thehackerwire@mastodon.social at 2026-08-19T11:00:46.000Z ##

๐Ÿ”ด CVE-2026-73924 - Critical (9.1)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T11:00:46.000Z ##

๐Ÿ”ด CVE-2026-73924 - Critical (9.1)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73921
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-08-19T15:33:23

2 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity a

thehackerwire@mastodon.social at 2026-08-19T05:00:39.000Z ##

๐Ÿ”ด CVE-2026-73921 - Critical (9.8)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T05:00:39.000Z ##

๐Ÿ”ด CVE-2026-73921 - Critical (9.8)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73938
(7.5 HIGH)

EPSS: 0.38%

updated 2026-08-19T15:33:23

2 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon acc

thehackerwire@mastodon.social at 2026-08-19T05:00:24.000Z ##

๐ŸŸ  CVE-2026-73938 - High (7.5)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T05:00:24.000Z ##

๐ŸŸ  CVE-2026-73938 - High (7.5)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71176
(8.8 HIGH)

EPSS: 0.30%

updated 2026-08-19T15:32:47

2 posts

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

thehackerwire@mastodon.social at 2026-08-19T16:01:27.000Z ##

๐ŸŸ  CVE-2026-71176 - High (8.8)

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulner...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T16:01:27.000Z ##

๐ŸŸ  CVE-2026-71176 - High (8.8)

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulner...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71961
(8.8 HIGH)

EPSS: 3.34%

updated 2026-08-19T15:32:47

2 posts

Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges by sending unsanitized input through the mesh MQTT command interface. The sync_command binary forwards unsanitized input directly to a shell execution sink in command.lua, enabling attackers with access to the MQTT b

thehackerwire@mastodon.social at 2026-08-19T16:01:15.000Z ##

๐ŸŸ  CVE-2026-71961 - High (8.8)

Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges by sending unsanitized input through the mesh MQTT command inte...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T16:01:15.000Z ##

๐ŸŸ  CVE-2026-71961 - High (8.8)

Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges by sending unsanitized input through the mesh MQTT command inte...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58562
(7.3 HIGH)

EPSS: 0.09%

updated 2026-08-19T15:32:46

1 posts

Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

hugovalters@mastodon.social at 2026-08-19T17:08:26.000Z ##

CVE-2026-58562 - Dell Command Update <5.7.1 missing authorization. Local attacker can gain unauthorized access. CVSS 7.3. No patch yet - restrict local access and monitor. #CVE #Dell #infosec

valtersit.com/cve/CVE-2026-585

##

CVE-2026-76219
(8.1 HIGH)

EPSS: 0.28%

updated 2026-08-19T15:32:38

1 posts

GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file

hugovalters@mastodon.social at 2026-08-19T15:14:29.000Z ##

CVE-2026-76219 - Arbitrary file overwrite in GitPython before 3.1.58 via IndexFile methods. Inject --index-output to clobber files. CVSS 8.1. Unpatched - update or mitigate now. #CVE #GitPython #infosec

valtersit.com/cve/CVE-2026-762

##

CVE-2026-73390
(9.8 CRITICAL)

EPSS: 0.27%

updated 2026-08-19T15:32:33

1 posts

Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.

hugovalters@mastodon.social at 2026-08-19T18:05:34.000Z ##

CVE-2026-73390 - Unauthenticated Privilege Escalation in Total Donations <=2.0.5. CVSS 9.8. Unpatched. Disable now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-733

##

CVE-2026-67364(CVSS UNKNOWN)

EPSS: 0.29%

updated 2026-08-19T15:32:24

2 posts

Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, letting an unauthenticated attacker inject arbitrar

offseq at 2026-08-19T13:30:25.893Z ##

CVE-2026-67364 (CVSS 10): CRITICAL pre-auth PHP code injection in Balbooa Forms for Joomla (v1.0.0 โ€“ 2.4.3.1). Exploitable via unescaped query param in custom-PHP handler. Update to 2.4.3.2+ now. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-19T13:30:25.000Z ##

CVE-2026-67364 (CVSS 10): CRITICAL pre-auth PHP code injection in Balbooa Forms for Joomla (v1.0.0 โ€“ 2.4.3.1). Exploitable via unescaped query param in custom-PHP handler. Update to 2.4.3.2+ now. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #CVE202667364 #WebSecurity

##

CVE-2026-73937
(8.2 HIGH)

EPSS: 0.38%

updated 2026-08-19T15:32:20

2 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (comp

thehackerwire@mastodon.social at 2026-08-19T05:00:12.000Z ##

๐ŸŸ  CVE-2026-73937 - High (8.2)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T05:00:12.000Z ##

๐ŸŸ  CVE-2026-73937 - High (8.2)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73935
(7.5 HIGH)

EPSS: 0.30%

updated 2026-08-19T15:32:20

2 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (comp

thehackerwire@mastodon.social at 2026-08-19T03:00:28.000Z ##

๐ŸŸ  CVE-2026-73935 - High (7.5)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T03:00:28.000Z ##

๐ŸŸ  CVE-2026-73935 - High (7.5)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73934
(7.5 HIGH)

EPSS: 0.30%

updated 2026-08-19T15:32:20

2 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (com

thehackerwire@mastodon.social at 2026-08-19T00:00:29.000Z ##

๐ŸŸ  CVE-2026-73934 - High (7.5)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T00:00:29.000Z ##

๐ŸŸ  CVE-2026-73934 - High (7.5)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73939
(8.6 HIGH)

EPSS: 0.32%

updated 2026-08-19T15:32:20

2 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks o

thehackerwire@mastodon.social at 2026-08-18T22:00:01.000Z ##

๐ŸŸ  CVE-2026-73939 - High (8.6)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-18T22:00:01.000Z ##

๐ŸŸ  CVE-2026-73939 - High (8.6)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73922
(9.1 CRITICAL)

EPSS: 0.29%

updated 2026-08-19T15:32:19

2 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data o

thehackerwire@mastodon.social at 2026-08-19T11:00:31.000Z ##

๐Ÿ”ด CVE-2026-73922 - Critical (9.1)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T11:00:31.000Z ##

๐Ÿ”ด CVE-2026-73922 - Critical (9.1)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73936
(7.5 HIGH)

EPSS: 0.41%

updated 2026-08-19T15:32:19

2 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (comple

thehackerwire@mastodon.social at 2026-08-19T03:00:37.000Z ##

๐ŸŸ  CVE-2026-73936 - High (7.5)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T03:00:37.000Z ##

๐ŸŸ  CVE-2026-73936 - High (7.5)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73931
(8.3 HIGH)

EPSS: 0.23%

updated 2026-08-19T15:32:19

2 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of

thehackerwire@mastodon.social at 2026-08-18T22:00:29.000Z ##

๐ŸŸ  CVE-2026-73931 - High (8.3)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-18T22:00:29.000Z ##

๐ŸŸ  CVE-2026-73931 - High (8.3)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73930
(9.9 CRITICAL)

EPSS: 0.36%

updated 2026-08-19T15:32:19

2 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of

thehackerwire@mastodon.social at 2026-08-18T22:00:16.000Z ##

๐Ÿ”ด CVE-2026-73930 - Critical (9.9)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-18T22:00:16.000Z ##

๐Ÿ”ด CVE-2026-73930 - Critical (9.9)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-60392
(7.8 HIGH)

EPSS: 0.29%

updated 2026-08-19T15:32:05

1 posts

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human int

infosecbot@mastodon.hofud.com at 2026-08-19T06:09:14.000Z ##

[1/9]

Most Impactful Security Incidents (โ€ฏ2026โ€‘08โ€‘18โ€ฏโ†’โ€ฏ2026โ€‘08โ€‘19โ€ฏ)

---

PRIORITYโ€ฏ1 โ€“ Critical / Highโ€‘Severity Flaws (CVSSโ€ฏ7โ€‘10):

CVEโ€‘2026โ€‘60392
โ€ข 7.8 (HIGH)
โ€ข Oracleโ€ฏOutsideโ€ฏInโ€ฏTechnology โ€“ PDF Export SDK (Fusion Middleware)
โ€ข Localโ€‘privilege escalation; requires attacker to have a logon on the host where the SDK runs. Successful exploitation can lead to full takeover of the component.
โ€ข 8.5.8
โ€ข Easily exploitable (local) โ€“ requires user interaction.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60782
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏPayments (Eโ€‘Business Suite) โ€“ File Transmission
โ€ข Remote unauthenticated attacker can compromise the Payments module via HTTP. Leads to full takeover of the Payments service.
โ€ข 12.2.3โ€‘12.2.15
โ€ข Networkโ€‘accessible, no authentication required.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60730
โ€ข 9.9 (CRITICAL)
โ€ข Oracleโ€ฏWebCenterโ€ฏPortal โ€“ Composer component
โ€ข Remote unauthenticated attacker can compromise the portal via HTTP. Full takeover of the portal.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.0.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60728
โ€ข 9.1 (CRITICAL)
โ€ข Oracleโ€ฏWebCenterโ€ฏPortal โ€“ Portlet Services
โ€ข Remote unauthenticated attacker can cause denialโ€‘ofโ€‘service and full compromise of portal data.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.0.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60727
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Remote unauthenticated attacker can take over the IAM system via HTTP.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60721
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Same vector as above; full takeover possible.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60720
โ€ข 9.9 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Remote unauthenticated attacker can compromise the IAM system.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

#infosecnews

##

CVE-2026-15780
(7.2 HIGH)

EPSS: 0.39%

updated 2026-08-19T09:31:30

1 posts

The WP Statistics โ€“ Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions up to, and including, 14.16.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever

hugovalters@mastodon.social at 2026-08-19T11:05:37.000Z ##

CVE-2026-15780 - Stored XSS in WP Statistics plugin โ‰ค14.16.8 via utm_campaign param. Unauthenticated payload injection. CVSS 7.2. Unpatched - update/disable now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-157

##

CVE-2026-76050
(7.3 HIGH)

EPSS: 0.33%

updated 2026-08-19T06:31:24

1 posts

A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?action=delete_menu. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.

hugovalters@mastodon.social at 2026-08-19T14:00:58.000Z ##

CVE-2026-76050 โ€“ SQLi in SourceCodester Simple Online Food Ordering System 1.0 via /admin/ajax.php?action=delete_menu. CVSS 7.3. Unpatched. Patch/update immediately. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-760

##

CVE-2026-76049
(7.3 HIGH)

EPSS: 0.33%

updated 2026-08-19T06:31:24

1 posts

A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=save_menu. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

hugovalters@mastodon.social at 2026-08-19T12:07:02.000Z ##

CVE-2026-76049 - SQLi in SourceCodester Simple Online Food Ordering System 1.0 via /admin/ajax.php. Remote exploit public, unpatched. CVSS 7.3. Update or isolate now. #CVE #infosec #SQLi

valtersit.com/cve/CVE-2026-760

##

CVE-2026-19942
(8.1 HIGH)

EPSS: 0.69%

updated 2026-08-19T06:31:24

2 posts

The Atarim โ€“ AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the AVCF_Abilities_Media::register (replace-media-file execute_callback) function in all versions up to, and including, 5.1.1. This makes it possible for authenticated attackers, with author-level

thehackerwire@mastodon.social at 2026-08-19T06:00:13.000Z ##

๐ŸŸ  CVE-2026-19942 - High (8.1)

The Atarim โ€“ AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the AVCF_Abilities_Media::register (repla...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T06:00:13.000Z ##

๐ŸŸ  CVE-2026-19942 - High (8.1)

The Atarim โ€“ AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the AVCF_Abilities_Media::register (repla...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-33824
(9.8 CRITICAL)

EPSS: 77.90%

updated 2026-08-19T04:16:58.560000

8 posts

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

2 repos

https://github.com/kaleth4/CVE-2026-33824

https://github.com/EpSiLoNPoInTOrI/IKEV2-POC

beyondmachines1 at 2026-08-20T10:01:03.444Z ##

CISA Warns of Active Exploitation of Critical Microsoft IKE Remote Code Execution Flaw

CISA reports active exploitation of a Windows IKE service critical remote code execution vulnerability (CVE-2026-33824). The flaw allows unauthenticated attackers to take full control of affected systems by sending malicious network packets.

**If you run Windows systems with IKEv2 enabled (VPN gateways, RRAS servers, IPsec endpoints), apply Microsoft's patch for CVE-2026-33824 immediately. Attackers are actively taking over these machines with no login or user action needed. If you can't patch right away, block inbound UDP ports 500 and 4500 at your firewall and only allow those ports from trusted, known IP addresses.**

beyondmachines.net/event_detai

##

undercodenews@mastodon.social at 2026-08-19T13:09:37.000Z ##

CISA Sounds the Alarm: Critical Windows IKE Vulnerability Is Now an Actively Exploited Threat

Introduction: The VPN Door Attackers Are Watching A dangerous Windows vulnerability has moved from the long list of security advisories into a far more urgent category: CISAโ€™s Known Exploited Vulnerabilities catalog. Tracked as CVE-2026-33824, the flaw affects the Windows Internet Key Exchange (IKE) Service Extensions and can allow an unauthenticated attacker to executeโ€ฆ

undercodenews.com/cisa-sounds-

##

offseq at 2026-08-19T10:30:25.671Z ##

CVE-2026-33824: CRITICAL RCE in Windows IKE Extension is being actively exploited. All supported Windows 10, 11 & Server are impacted. Patch immediately or block UDP 500/4500 if IKE not used. More at radar.offseq.com/threat/critic

##

Analyst207@mastodon.social at 2026-08-19T10:25:40.000Z ##

Hackers Actively Exploit Windows IKE Flaw

Hackers are actively exploiting a critical Windows flaw, known as CVE-2026-33824, that lets them execute code over a network, putting your system at risk. This vulnerability, found in the Windows Internet Key Exchange (IKE) Service Extensions, affects all supported Windows 10 and other Windows systems.

osintsights.com/hackers-active

#WindowsIkeFlaw #Cve202633824 #EmergingThreats #ZeroDay #Microsoft

##

beyondmachines1@infosec.exchange at 2026-08-20T10:01:03.000Z ##

CISA Warns of Active Exploitation of Critical Microsoft IKE Remote Code Execution Flaw

CISA reports active exploitation of a Windows IKE service critical remote code execution vulnerability (CVE-2026-33824). The flaw allows unauthenticated attackers to take full control of affected systems by sending malicious network packets.

**If you run Windows systems with IKEv2 enabled (VPN gateways, RRAS servers, IPsec endpoints), apply Microsoft's patch for CVE-2026-33824 immediately. Attackers are actively taking over these machines with no login or user action needed. If you can't patch right away, block inbound UDP ports 500 and 4500 at your firewall and only allow those ports from trusted, known IP addresses.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

offseq@infosec.exchange at 2026-08-19T10:30:25.000Z ##

CVE-2026-33824: CRITICAL RCE in Windows IKE Extension is being actively exploited. All supported Windows 10, 11 & Server are impacted. Patch immediately or block UDP 500/4500 if IKE not used. More at radar.offseq.com/threat/critic #OffSeq #RCE #Windows #BlueTeam

##

thecybermind@infosec.exchange at 2026-08-18T20:57:29.000Z ##

๐Ÿšจ NEW CISA KEV: CVE-2026-33824. Active RCE weaponization targeting Microsoft Internet Key Exchange (IKE) via double-free memory corruption. Unauthenticated access possible. Get the full T-Suite brief & custom CrowdStrike detection queries to secure your Precinct Hybrid architecture.
Link below ๐Ÿ‘‡
thecybermind.co/jily

#ThreatIntelligence #CISAKEV

##

cR0w@infosec.exchange at 2026-08-18T17:51:24.000Z ##

Looks like CVE-2026-33824 was added to KEV. Keep in mind that this service isn't just for IPSec VPNs. It's also used with some Windows Firewall policies so check your internal systems for listeners, not just public-facing systems.

An unauthenticated attacker could send specially crafted packets to a Windows machine with Internet Key Exchange (IKE) version 2 enabled, which could enable remote code execution.

msrc.microsoft.com/update-guid

nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-76008
(10.0 CRITICAL)

EPSS: 0.57%

updated 2026-08-19T03:31:30

4 posts

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflow. The attack can be initiated remotely.

thehackerwire@mastodon.social at 2026-08-19T04:00:34.000Z ##

๐Ÿ”ด CVE-2026-76008 - Critical (10)

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflo...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-19T03:00:25.355Z ##

Comfast CF-N1-S v2.6.0.1 hit by CRITICAL CVE-2026-76008: stack-based buffer overflow in /cgi-bin/mbox-config (get_para_from_uri). Remote exploitation risk; mitigation unavailable. Monitor for patches. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-19T04:00:34.000Z ##

๐Ÿ”ด CVE-2026-76008 - Critical (10)

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflo...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-19T03:00:25.000Z ##

Comfast CF-N1-S v2.6.0.1 hit by CRITICAL CVE-2026-76008: stack-based buffer overflow in /cgi-bin/mbox-config (get_para_from_uri). Remote exploitation risk; mitigation unavailable. Monitor for patches. #OffSeq #CVE202676008 #IoTSecurity radar.offseq.com/threat/cve-20

##

CVE-2026-76003
(9.9 CRITICAL)

EPSS: 0.44%

updated 2026-08-19T03:31:23

4 posts

A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of the argument timestart can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

offseq at 2026-08-19T06:00:27.615Z ##

CVE-2026-76003 (CRITICAL): Stack-based buffer overflow in UTT HiPER 1200GW (2.5.3-170306). Remote code execution possible via timestart argument; public exploit exists. No patch yet. Restrict access & monitor. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-19T04:00:44.000Z ##

๐Ÿ”ด CVE-2026-76003 - Critical (9.9)

A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of the argument timestart can lead to stack-based buffer overflow. The attack may ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-19T06:00:27.000Z ##

CVE-2026-76003 (CRITICAL): Stack-based buffer overflow in UTT HiPER 1200GW (2.5.3-170306). Remote code execution possible via timestart argument; public exploit exists. No patch yet. Restrict access & monitor. radar.offseq.com/threat/cve-20 #OffSeq #CVE202676003 #infosec #vuln

##

thehackerwire@mastodon.social at 2026-08-19T04:00:44.000Z ##

๐Ÿ”ด CVE-2026-76003 - Critical (9.9)

A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of the argument timestart can lead to stack-based buffer overflow. The attack may ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18963
(9.1 CRITICAL)

EPSS: 0.39%

updated 2026-08-19T03:31:21

5 posts

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user

1 repos

https://github.com/kyos-public/keycloak-cve-2026-18963-hunt

sayzard@mastodon.sayzard.org at 2026-08-20T07:38:35.000Z ##

Keycloak unauthenticated account takeover via reset-credentials flow bypass

Keycloak์˜ reset-credentials ํ”Œ๋กœ์šฐ์—์„œ ์ด๋ฉ”์ผ ๊ฒ€์ฆ ๋งํฌ ํด๋ฆญ์„ ์šฐํšŒํ•ด, ์ธ์ฆ๋˜์ง€ ์•Š์€ ๊ณต๊ฒฉ์ž๊ฐ€ ์ž„์˜ ์‚ฌ์šฉ์ž ๊ณ„์ •์˜ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์žฌ์„ค์ •ํ•˜๊ณ  ํƒˆ์ทจํ•  ์ˆ˜ ์žˆ๋Š” ์น˜๋ช…์  ์ทจ์•ฝ์ (CVE-2026-18963)์ด ๊ณต๊ฐœ๋๋‹ค. ์ทจ์•ฝ์ ์€ keycloak-services์˜ ์ƒํƒœ ์ฒ˜๋ฆฌ์™€ ์•ก์…˜ ํ† ํฐ ๊ฒ€์ฆ ๋ถ€์žฌ๊ฐ€ ๊ฒฐํ•ฉ๋œ ๋ฌธ์ œ์ด๋ฉฐ, ์ปค๋ฎค๋‹ˆํ‹ฐ Keycloak์—๋„ ์˜ํ–ฅ์„ ์ค€๋‹ค. ์˜ํ–ฅ ๋ฒ”์œ„๋Š” 26.0.0 ์ดํ›„ ์ผ๋ถ€ ๋ฆด๋ฆฌ์Šค์ด๋ฉฐ, ๊ณต๊ฐœ ์ปจํ…Œ์ด๋„ˆ ์‚ฌ์šฉ์ž๋Š” ์šฐ์„  26.7.2๋กœ ์—…๊ทธ๋ ˆ์ด๋“œํ•ด์•ผ ํ•˜๊ณ , Red Hat Build ์‚ฌ์šฉ์ž๋Š” 26.4.15 ๋˜๋Š” 26.6.6 ํŒจ์น˜๋ฅผ ์ ์šฉํ•ด...

github.com/keycloak/keycloak/i

##

smeyer@univention.social at 2026-08-20T07:23:48.000Z ##

Guten Morgen an @univention Kund*innen, die unsere #Keycloak App einsetzen! Wir werden demnรคchst Version 26.7.2 herausbringen. Von dem Account-Takeover-CVE ist unsere App nicht betroffen.

Details findet Ihr hier: help.univention.com/t/keycloak

##

hacksilon at 2026-08-19T17:02:26.802Z ##

PSA: Critical unauthenticated account takeover vulnerability in - allows resetting arbitrary usersโ€˜ passwords. Update to 26.7.2 immediately or disable password reset. Tracked as CVE-2026-18963. github.com/keycloak/keycloak/i

##

smeyer@univention.social at 2026-08-20T07:23:48.000Z ##

Guten Morgen an @univention Kund*innen, die unsere #Keycloak App einsetzen! Wir werden demnรคchst Version 26.7.2 herausbringen. Von dem Account-Takeover-CVE ist unsere App nicht betroffen.

Details findet Ihr hier: help.univention.com/t/keycloak

##

hacksilon@infosec.exchange at 2026-08-19T17:02:26.000Z ##

PSA: Critical unauthenticated account takeover vulnerability in #Keycloak - allows resetting arbitrary usersโ€˜ passwords. Update to 26.7.2 immediately or disable password reset. Tracked as CVE-2026-18963. github.com/keycloak/keycloak/i

#infosec

##

CVE-2026-21580(CVSS UNKNOWN)

EPSS: 0.36%

updated 2026-08-19T00:31:18

2 posts

This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server. This Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability, wi

DailyCyberSecurity at 2026-08-19T06:40:51.499Z ##

A Confluence vulnerability, CVE-2026-21580, is a stored XSS flaw (CVSS 8.6) allowing unauthenticated attacks. A Jira flaw also patched. Update now.

securityonline.info/confluence

##

DailyCyberSecurity@infosec.exchange at 2026-08-19T06:40:51.000Z ##

A Confluence vulnerability, CVE-2026-21580, is a stored XSS flaw (CVSS 8.6) allowing unauthenticated attacks. A Jira flaw also patched. Update now.

#Atlassian #Confluence #CVE202621580 #StoredXSS #Jira #InfoSec

securityonline.info/confluence

##

CVE-2026-60782
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-08-18T21:32:07

1 posts

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Con

infosecbot@mastodon.hofud.com at 2026-08-19T06:09:14.000Z ##

[1/9]

Most Impactful Security Incidents (โ€ฏ2026โ€‘08โ€‘18โ€ฏโ†’โ€ฏ2026โ€‘08โ€‘19โ€ฏ)

---

PRIORITYโ€ฏ1 โ€“ Critical / Highโ€‘Severity Flaws (CVSSโ€ฏ7โ€‘10):

CVEโ€‘2026โ€‘60392
โ€ข 7.8 (HIGH)
โ€ข Oracleโ€ฏOutsideโ€ฏInโ€ฏTechnology โ€“ PDF Export SDK (Fusion Middleware)
โ€ข Localโ€‘privilege escalation; requires attacker to have a logon on the host where the SDK runs. Successful exploitation can lead to full takeover of the component.
โ€ข 8.5.8
โ€ข Easily exploitable (local) โ€“ requires user interaction.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60782
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏPayments (Eโ€‘Business Suite) โ€“ File Transmission
โ€ข Remote unauthenticated attacker can compromise the Payments module via HTTP. Leads to full takeover of the Payments service.
โ€ข 12.2.3โ€‘12.2.15
โ€ข Networkโ€‘accessible, no authentication required.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60730
โ€ข 9.9 (CRITICAL)
โ€ข Oracleโ€ฏWebCenterโ€ฏPortal โ€“ Composer component
โ€ข Remote unauthenticated attacker can compromise the portal via HTTP. Full takeover of the portal.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.0.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60728
โ€ข 9.1 (CRITICAL)
โ€ข Oracleโ€ฏWebCenterโ€ฏPortal โ€“ Portlet Services
โ€ข Remote unauthenticated attacker can cause denialโ€‘ofโ€‘service and full compromise of portal data.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.0.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60727
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Remote unauthenticated attacker can take over the IAM system via HTTP.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60721
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Same vector as above; full takeover possible.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60720
โ€ข 9.9 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Remote unauthenticated attacker can compromise the IAM system.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

#infosecnews

##

CVE-2026-60720
(9.9 CRITICAL)

EPSS: 0.45%

updated 2026-08-18T21:32:06

1 posts

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact

infosecbot@mastodon.hofud.com at 2026-08-19T06:09:14.000Z ##

[1/9]

Most Impactful Security Incidents (โ€ฏ2026โ€‘08โ€‘18โ€ฏโ†’โ€ฏ2026โ€‘08โ€‘19โ€ฏ)

---

PRIORITYโ€ฏ1 โ€“ Critical / Highโ€‘Severity Flaws (CVSSโ€ฏ7โ€‘10):

CVEโ€‘2026โ€‘60392
โ€ข 7.8 (HIGH)
โ€ข Oracleโ€ฏOutsideโ€ฏInโ€ฏTechnology โ€“ PDF Export SDK (Fusion Middleware)
โ€ข Localโ€‘privilege escalation; requires attacker to have a logon on the host where the SDK runs. Successful exploitation can lead to full takeover of the component.
โ€ข 8.5.8
โ€ข Easily exploitable (local) โ€“ requires user interaction.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60782
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏPayments (Eโ€‘Business Suite) โ€“ File Transmission
โ€ข Remote unauthenticated attacker can compromise the Payments module via HTTP. Leads to full takeover of the Payments service.
โ€ข 12.2.3โ€‘12.2.15
โ€ข Networkโ€‘accessible, no authentication required.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60730
โ€ข 9.9 (CRITICAL)
โ€ข Oracleโ€ฏWebCenterโ€ฏPortal โ€“ Composer component
โ€ข Remote unauthenticated attacker can compromise the portal via HTTP. Full takeover of the portal.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.0.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60728
โ€ข 9.1 (CRITICAL)
โ€ข Oracleโ€ฏWebCenterโ€ฏPortal โ€“ Portlet Services
โ€ข Remote unauthenticated attacker can cause denialโ€‘ofโ€‘service and full compromise of portal data.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.0.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60727
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Remote unauthenticated attacker can take over the IAM system via HTTP.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60721
โ€ข 9.8 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Same vector as above; full takeover possible.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

CVEโ€‘2026โ€‘60720
โ€ข 9.9 (CRITICAL)
โ€ข Oracleโ€ฏIdentityโ€ฏManager โ€“ OIM Legacy UI
โ€ข Remote unauthenticated attacker can compromise the IAM system.
โ€ข 12.2.1.4.0,โ€ฏ14.1.2.1.0
โ€ข Networkโ€‘accessible, no auth.
โ€ข cveawg.mitre.org/api/cve/CVE-2

#infosecnews

##

CVE-2026-47629
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-18T21:31:55

2 posts

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service.

thehackerwire@mastodon.social at 2026-08-18T20:00:49.000Z ##

๐ŸŸ  CVE-2026-47629 - High (7.5)

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

AAKL@infosec.exchange at 2026-08-18T17:07:44.000Z ##

Nvidia has new advisories addressing two vulnerabilities:

- NVIDIA Cumulus Linux and NVOS - August 2026 nvidia.custhelp.com/app/answer

- CRITICAL, affecting the following: CVE-2026-47627, CVE-2026-47628, CVE-2026-47629, CVE-2026-47606, CVE-2026-47630

NVIDIA Triton Inference Server - August 2026 nvidia.custhelp.com/app/answer #Nvidia #infosec #vulnerability #Linux

##

CVE-2026-47628
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-18T21:31:54

2 posts

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service.

thehackerwire@mastodon.social at 2026-08-18T20:01:19.000Z ##

๐ŸŸ  CVE-2026-47628 - High (7.5)

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

AAKL@infosec.exchange at 2026-08-18T17:07:44.000Z ##

Nvidia has new advisories addressing two vulnerabilities:

- NVIDIA Cumulus Linux and NVOS - August 2026 nvidia.custhelp.com/app/answer

- CRITICAL, affecting the following: CVE-2026-47627, CVE-2026-47628, CVE-2026-47629, CVE-2026-47606, CVE-2026-47630

NVIDIA Triton Inference Server - August 2026 nvidia.custhelp.com/app/answer #Nvidia #infosec #vulnerability #Linux

##

CVE-2026-47606
(6.5 MEDIUM)

EPSS: 0.41%

updated 2026-08-18T21:31:54

1 posts

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosure.

AAKL@infosec.exchange at 2026-08-18T17:07:44.000Z ##

Nvidia has new advisories addressing two vulnerabilities:

- NVIDIA Cumulus Linux and NVOS - August 2026 nvidia.custhelp.com/app/answer

- CRITICAL, affecting the following: CVE-2026-47627, CVE-2026-47628, CVE-2026-47629, CVE-2026-47606, CVE-2026-47630

NVIDIA Triton Inference Server - August 2026 nvidia.custhelp.com/app/answer #Nvidia #infosec #vulnerability #Linux

##

CVE-2026-47627
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-08-18T21:31:53

4 posts

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service.

DailyCyberSecurity at 2026-08-20T01:03:59.644Z ##

NVIDIA Triton vulnerability CVE-2026-47627 scores CVSS 9.8. Learn how the denial of service flaw works and why you must update to version 26.06 now.

securityonline.info/nvidia-tri

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T01:03:59.000Z ##

NVIDIA Triton vulnerability CVE-2026-47627 scores CVSS 9.8. Learn how the denial of service flaw works and why you must update to version 26.06 now.

#NVIDIA #TritonInferenceServer #CVE202647627 #DenialOfService #AIsecurity #CVSS

securityonline.info/nvidia-tri

##

thehackerwire@mastodon.social at 2026-08-18T20:01:05.000Z ##

๐Ÿ”ด CVE-2026-47627 - Critical (9.8)

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

AAKL@infosec.exchange at 2026-08-18T17:07:44.000Z ##

Nvidia has new advisories addressing two vulnerabilities:

- NVIDIA Cumulus Linux and NVOS - August 2026 nvidia.custhelp.com/app/answer

- CRITICAL, affecting the following: CVE-2026-47627, CVE-2026-47628, CVE-2026-47629, CVE-2026-47606, CVE-2026-47630

NVIDIA Triton Inference Server - August 2026 nvidia.custhelp.com/app/answer #Nvidia #infosec #vulnerability #Linux

##

CVE-2026-75625
(9.0 CRITICAL)

EPSS: 0.20%

updated 2026-08-18T20:17:32.460000

1 posts

Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the agent-to-agent path or malicious peers can supply substituted content with forged CRC32 corrections that passes per-piece checks, poisoning the cache with attacker-chosen containe

thehackerwire@mastodon.social at 2026-08-18T19:00:16.000Z ##

๐Ÿ”ด CVE-2026-75625 - Critical (9)

Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the agent-to-agent path or mal...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47719
(8.2 HIGH)

EPSS: 0.48%

updated 2026-08-18T20:17:15.103000

1 posts

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO handlers in server/runtime/index.js omit isSocketWriteAuthorized and accept attacker-controlled property.address or endpoint connection data. A remote unauthenticated attacker can make server/runtime/devices/httprequest/index.js call axios.get against ar

hugovalters@mastodon.social at 2026-08-19T01:11:46.000Z ##

CVE-2026-47719 - Critical SSRF in FUXA SCADA/HMI. Unauthenticated attackers can probe internal networks via axios. CVSS 8.2. Unpatched - restrict access now. #CVE #ICS #cybersecurity

valtersit.com/cve/CVE-2026-477

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 2.40%

updated 2026-08-18T18:32:52

2 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server.ย A malicious actor with network access to vCenterย may exploit this issue to execute arbitrary code.

2 repos

https://github.com/HORKimhab/CVE-2026-59310

https://github.com/BiuTrap/CVE-2026-59310

undercodenews@mastodon.social at 2026-08-19T05:20:11.000Z ##

CISA Sounds the Alarm on Critical VMware vCenter Flaw: Active Exploitation Puts Enterprise Virtual Infrastructure at Risk

A New Warning for VMware Administrators A critical security vulnerability in VMware vCenter has become an urgent concern for organizations running virtualized infrastructure. Tracked as CVE-2026-59310, the flaw is a directory traversal vulnerability in the vCenter Syslog server that can ultimately allow a network-accessible attacker to executeโ€ฆ

undercodenews.com/cisa-sounds-

##

threatnoir@infosec.exchange at 2026-08-18T15:05:54.000Z ##

โš ๏ธ CRITICAL: โšก Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

Three critical vulnerabilities are under active exploitation: VMware vCenter (CVE-2026-59310) by China-nexus APT for potential ransomware deployment, Windows 0-day (CVE-2026-68820) by Lazarus Group targeting defense contractors with backdoors, and macOS flaw (CVE-2026-65400) distributing crypto minโ€ฆ

threatnoir.com/focus

#infosec #cybersecurity

๐Ÿค– AI generated summary

##

CVE-2026-75130
(9.0 None)

EPSS: 0.28%

updated 2026-08-18T18:32:11

1 posts

Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Custom AI Instructions feature served via the MCP server. Attackers can poison the custom instructions to exfiltrate credentials from environment files to an attacker-controlled service and perform destru

thehackerwire@mastodon.social at 2026-08-18T19:00:02.000Z ##

๐Ÿ”ด CVE-2026-75130 - Critical (9)

Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Custom AI Instructions feature served via the MCP s...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66780
(9.9 CRITICAL)

EPSS: 0.24%

updated 2026-08-18T18:32:10

2 posts

A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an attacker can redirect inter-cluster tunnel traffic, enabling a Man-in-the-Middle (

DailyCyberSecurity at 2026-08-20T13:00:08.368Z ##

A critical Red Hat vulnerability, CVE-2026-66780 (CVSS 9.9), enables a MITM attack across a cluster mesh. Two more critical flaws also disclosed.

securityonline.info/redhat-vul

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T13:00:08.000Z ##

A critical Red Hat vulnerability, CVE-2026-66780 (CVSS 9.9), enables a MITM attack across a cluster mesh. Two more critical flaws also disclosed.

#RedHat #CVE202666780 #MITM #Kubernetes #Keycloak #InfoSec

securityonline.info/redhat-vul

##

CVE-2026-65400
(7.1 HIGH)

EPSS: 0.75%

updated 2026-08-18T18:31:47

7 posts

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

1 repos

https://github.com/HORKimhab/CVE-2026-65400

sigint@fosstodon.org at 2026-08-19T23:02:51.000Z ##

๐Ÿšจ๐Ÿ› SIGINT // Cybersecurity Watch โ€” 2026-08-20
Critical macOS Screen Sharing flaw (CVE-2026-65400) exploited for remote root access, deploying Monero miners on unpatched Macs.
tomshardware.com/tech-industry
#CVE #macOS #InfoSec #Cybersecurity

##

DailyCyberSecurity at 2026-08-19T03:25:39.939Z ##

Attackers are exploiting CVE-2026-65400, a critical macOS Screen Sharing auth bypass, to gain root access and deploy Monero miners on Macs with exposed port 5900.

meterpreter.org/macos-screen-s

##

hackmag at 2026-08-18T22:31:05.124Z ##

โšช๏ธ Hackers Exploit macOS Screen Sharing Vulnerability to Install Crypto Miners

๐Ÿ—จ๏ธ The Netherlandsโ€™ National Cyber Security Centre (NCSC) has warned that attackers have begun exploiting the critical CVE-2026-65400 vulnerability in macOS Screen Sharing. The flaw allows authentication to be bypassed, granting access to a Mac without a password, and is alreadyโ€ฆ

๐Ÿ”— hackmag.com/news/cve-2026-6540

##

DailyCyberSecurity@infosec.exchange at 2026-08-19T03:25:39.000Z ##

Attackers are exploiting CVE-2026-65400, a critical macOS Screen Sharing auth bypass, to gain root access and deploy Monero miners on Macs with exposed port 5900.

#CVE202665400 #macOS #ScreenSharing #Monero #AppleSecurity

meterpreter.org/macos-screen-s

##

hackmag@infosec.exchange at 2026-08-18T22:31:05.000Z ##

โšช๏ธ Hackers Exploit macOS Screen Sharing Vulnerability to Install Crypto Miners

๐Ÿ—จ๏ธ The Netherlandsโ€™ National Cyber Security Centre (NCSC) has warned that attackers have begun exploiting the critical CVE-2026-65400 vulnerability in macOS Screen Sharing. The flaw allows authentication to be bypassed, granting access to a Mac without a password, and is alreadyโ€ฆ

๐Ÿ”— hackmag.com/news/cve-2026-6540

#news

##

threatnoir@infosec.exchange at 2026-08-18T15:05:54.000Z ##

โš ๏ธ CRITICAL: โšก Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

Three critical vulnerabilities are under active exploitation: VMware vCenter (CVE-2026-59310) by China-nexus APT for potential ransomware deployment, Windows 0-day (CVE-2026-68820) by Lazarus Group targeting defense contractors with backdoors, and macOS flaw (CVE-2026-65400) distributing crypto minโ€ฆ

threatnoir.com/focus

#infosec #cybersecurity

๐Ÿค– AI generated summary

##

FlipboardUK@flipboard.com at 2026-08-17T22:41:56.000Z ##

An AI agent built a working exploit for this macOS flaw in four hours
thenextweb.com/news/macos-scre

Posted into Technology (UK Edition) @technology-uk-edition-FlipboardUK

##

CVE-2026-75913
(9.3 CRITICAL)

EPSS: 0.33%

updated 2026-08-18T16:18:23.363000

1 posts

CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-options sentinel, so a value beginning with --output= is interpreted as a git flag. Because the tool is registered as auto-approved and advertised as read-only, an at

thehackerwire@mastodon.social at 2026-08-18T17:00:42.000Z ##

๐Ÿ”ด CVE-2026-75913 - Critical (9.3)

CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and &lt; 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-options se...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75481
(8.8 HIGH)

EPSS: 0.28%

updated 2026-08-18T16:18:20.627000

1 posts

SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its bearer token to gain administrative control over all users and workspaces.

thehackerwire@mastodon.social at 2026-08-18T05:00:33.000Z ##

๐ŸŸ  CVE-2026-75481 - High (8.8)

SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its bearer to...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75103
(8.8 HIGH)

EPSS: 0.34%

updated 2026-08-18T16:18:20.127000

1 posts

Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and change administrator credentials to achieve full account takeover and arbitrary code execution.

thehackerwire@mastodon.social at 2026-08-18T06:01:02.000Z ##

๐ŸŸ  CVE-2026-75103 - High (8.8)

Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and change admi...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67854
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-08-18T16:18:14.327000

1 posts

SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code

offseq@infosec.exchange at 2026-08-18T01:30:24.000Z ##

SQL Injection flaw (CVE-2026-67854) in Qcms v6.0.6 rated CRITICAL: remote code execution risk. No official patch. Restrict access & monitor for injection attempts. Details: radar.offseq.com/threat/sql-in #OffSeq #SQLInjection #Vulnerability #Qcms #InfoSec

##

CVE-2026-75783
(9.6 CRITICAL)

EPSS: 0.40%

updated 2026-08-18T15:31:56

1 posts

A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler. The manipulation leads to stack-based buffer overflow. The attack must be carried out from within the local network. The exploit has been disclosed publicly and may be used.

offseq@infosec.exchange at 2026-08-18T13:30:26.000Z ##

TRENDnet TEW-WLC100P v12.07b01 impacted by CRITICAL stack-based buffer overflow (CVE-2026-75783, CVSS 9.4) in DHCP blobmsg Handler. Exploit needs local network access. No patch yet โ€” restrict access & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #CVE202675783 #Vuln #IoTSecurity

##

CVE-2026-24301
(8.8 HIGH)

EPSS: 1.63%

updated 2026-08-18T15:31:45

5 posts

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

1 repos

https://github.com/CSOAI-ORG/memory-poisoning-axis

benzogaga33@mamot.fr at 2026-08-20T09:40:03.000Z ##

CoSnitch : Copilot a lui-mรชme livrรฉ la faille qui permet de voler vos donnรฉes it-connect.fr/cosnitch-cve-202 #ActuCybersรฉcuritรฉ #Cybersรฉcuritรฉ #Microsoft #Copilot #IA

##

PC_Fluesterer@social.tchncs.de at 2026-08-19T13:38:47.000Z ##

Von wegen KI: MS Copilot ist strunzdumm

Das Sicherheitsunternehmen Varonis hat eine Sicherheitslรผcke in Microsoft (MS) Copilot gefunden. Die hat inzwischen auch einen Namen bekommen und eine CVE-Nummer: CVE-2026-24301 oder CoSnitch. Sie ist mit 8,8 von 10 als kritisch eingestuft. Anscheinend gibt es noch keinen Flicken dagegen. Wer diese Lรผcke ausnutzt, kann Copilot von Ferne heimlich (ohne Interaktion des Opfers) dazu veranlassen, sensible geheime Daten zu senden. Zwar hat Copilot Schutzvorkehrungen gegen solchen Missbrauch, aber die sind unvollstรคndig. Der Trick der Forscher/innen bestand darin, Copilot sich selbst hacken zu lassen! Immer wenn die KI einen ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#cybercrime #datenleck #KI #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump

##

benzogaga33@mamot.fr at 2026-08-20T09:40:03.000Z ##

CoSnitch : Copilot a lui-mรชme livrรฉ la faille qui permet de voler vos donnรฉes it-connect.fr/cosnitch-cve-202 #ActuCybersรฉcuritรฉ #Cybersรฉcuritรฉ #Microsoft #Copilot #IA

##

PC_Fluesterer@social.tchncs.de at 2026-08-19T13:38:47.000Z ##

Von wegen KI: MS Copilot ist strunzdumm

Das Sicherheitsunternehmen Varonis hat eine Sicherheitslรผcke in Microsoft (MS) Copilot gefunden. Die hat inzwischen auch einen Namen bekommen und eine CVE-Nummer: CVE-2026-24301 oder CoSnitch. Sie ist mit 8,8 von 10 als kritisch eingestuft. Anscheinend gibt es noch keinen Flicken dagegen. Wer diese Lรผcke ausnutzt, kann Copilot von Ferne heimlich (ohne Interaktion des Opfers) dazu veranlassen, sensible geheime Daten zu senden. Zwar hat Copilot Schutzvorkehrungen gegen solchen Missbrauch, aber die sind unvollstรคndig. Der Trick der Forscher/innen bestand darin, Copilot sich selbst hacken zu lassen! Immer wenn die KI einen ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#cybercrime #datenleck #KI #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump

##

AAKL@infosec.exchange at 2026-08-18T16:50:44.000Z ##

Microsoft has an advisory for a new critical Copilot vulnerability.

CRITICAL: CVE-2026-24301: Microsoft Copilot Information Disclosure Vulnerability msrc.microsoft.com/update-guid

More information:

CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') cwe.mitre.org/data/definitions #infosec #Microsoft #Copilot #vulnerability

##

CVE-2026-75479
(7.5 HIGH)

EPSS: 0.36%

updated 2026-08-18T15:17:13.457000

1 posts

JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access protected report endpoints and retrieve full report definitions including embedded SQL statements and live query data.

thehackerwire@mastodon.social at 2026-08-18T01:00:31.000Z ##

๐ŸŸ  CVE-2026-75479 - High (7.5)

JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-40144
(0 None)

EPSS: 0.11%

updated 2026-08-18T15:04:46.610000

2 posts

A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to version 26.1.2. Insufficient validation of input processed by the component may result in memory being accessed outside its intended bounds.

CVE-2026-75852
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-08-18T14:18:12.260000

1 posts

ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials.

thehackerwire@mastodon.social at 2026-08-18T13:00:28.000Z ##

๐Ÿ”ด CVE-2026-75852 - Critical (9.8)

ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to p...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75853
(8.8 HIGH)

EPSS: 0.39%

updated 2026-08-18T12:31:30

1 posts

ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL PLAIN) but performs no authorization: it never checks database access permissions (canAccessToDatabase) and never binds the authenticated principal into the engine. As a result, any valid server credential โ€” even one provisioned for zero or one unrelated database โ€” can read,

thehackerwire@mastodon.social at 2026-08-18T13:00:39.000Z ##

๐ŸŸ  CVE-2026-75853 - High (8.8)

ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions &lt;= 26.7.3 enforces authentication (SASL PLAIN) but performs no authorization: it never checks database access permissions (canAccessToDatabase) and never binds ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75851
(9.9 CRITICAL)

EPSS: 0.32%

updated 2026-08-18T12:31:30

1 posts

ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted with awaitResponse:false, it executes on an async worker whose DatabaseContext has no bound user, causing the scripting authorization gate to become a no-op. A user with only read access to a single da

thehackerwire@mastodon.social at 2026-08-18T13:00:16.000Z ##

๐Ÿ”ด CVE-2026-75851 - Critical (9.9)

ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted with awaitResponse:false, it executes on an asyn...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75854
(9.8 CRITICAL)

EPSS: 1.07%

updated 2026-08-18T12:31:30

1 posts

ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attackers to read, write, and delete data. Attackers can connect to the Redis port and execute arbitrary commands against any database on the server without providing credentials, bypassing all security gates.

offseq@infosec.exchange at 2026-08-18T12:00:24.000Z ##

CVE-2026-75854: ArcadeDB <26.8.1 has a CRITICAL Redis plugin vuln (CVSS 9.3). Missing auth lets attackers run any command & access/modify/delete all DB data. Restrict Redis port access & monitor for fixes. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #ArcadeDB #Infosec

##

CVE-2026-75045
(9.1 CRITICAL)

EPSS: 0.30%

updated 2026-08-18T04:16:47.170000

1 posts

In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature

CVE-2025-62593
(8.8 HIGH)

EPSS: 1.01%

updated 2026-08-18T04:16:40.860000

5 posts

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is ins

1 repos

https://github.com/Boreas37/CVE-2025-62593-PoC

beyondmachines1 at 2026-08-20T08:01:03.316Z ##

Ray Framework Remote Code Execution Vulnerability Under Active Exploitation

CISA warned that attackers are exploiting a remote code execution vulnerability in the Ray framework to target machine learning developers. The flaw allows attackers to bypass browser security checks and run arbitrary commands on developer machines and internal networks.

**If you use the Ray framework, update it to version 2.52.0 or later ASAP. Attackers are actively exploiting CVE-2025-62593 to run commands on developer machines. Also make sure Ray is never reachable from the internet and only accessible from trusted networks, and watch for unusual traffic between developer laptops and your internal compute clusters.**

beyondmachines.net/event_detai

##

youranonnewsirc@nerdculture.de at 2026-08-18T22:26:21.000Z ##

Recent alerts include CISA adding a critical RCE flaw in Ray-Project Ray (CVE-2025-62593) to its KEV catalog (Aug 18). Heights Finance also reported a data breach impacting over 1.2 million customers. Globally, ransomware incidents remain high, with AI increasingly used in attacks. Geopolitically, US-Iran talks have stalled, intensifying Middle East tensions and affecting global shipping.

#Cybersecurity #AnonNews_irc #TechNews

##

beyondmachines1@infosec.exchange at 2026-08-20T08:01:03.000Z ##

Ray Framework Remote Code Execution Vulnerability Under Active Exploitation

CISA warned that attackers are exploiting a remote code execution vulnerability in the Ray framework to target machine learning developers. The flaw allows attackers to bypass browser security checks and run arbitrary commands on developer machines and internal networks.

**If you use the Ray framework, update it to version 2.52.0 or later ASAP. Attackers are actively exploiting CVE-2025-62593 to run commands on developer machines. Also make sure Ray is never reachable from the internet and only accessible from trusted networks, and watch for unusual traffic between developer laptops and your internal compute clusters.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

youranonnewsirc@nerdculture.de at 2026-08-18T22:26:21.000Z ##

Recent alerts include CISA adding a critical RCE flaw in Ray-Project Ray (CVE-2025-62593) to its KEV catalog (Aug 18). Heights Finance also reported a data breach impacting over 1.2 million customers. Globally, ransomware incidents remain high, with AI increasingly used in attacks. Geopolitically, US-Iran talks have stalled, intensifying Middle East tensions and affecting global shipping.

#Cybersecurity #AnonNews_irc #TechNews

##

thecybermind@infosec.exchange at 2026-08-18T15:28:33.000Z ##

๐Ÿšจ C-SUITE ALERT: CISA has flagged CVE-2025-62593 (Ray-Project) for active exploitation. This critical RCE flaw requires immediate executive oversight. Read our board-ready risk assessment and compliance framework to secure your enterprise. Command the wire. ๐Ÿ‘‡ Link below
thecybermind.co/k3rh
#CyberSecurity

##

CVE-2026-75094
(9.1 CRITICAL)

EPSS: 2.09%

updated 2026-08-18T03:31:14

2 posts

A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.

offseq@infosec.exchange at 2026-08-18T03:00:25.000Z ##

CVE-2026-75094: CRITICAL OS command injection in COMFAST CF-N1-S v2.6.0.1. Exploit code is public, no official patch. Restrict access to /cgi-bin/mbox-config to reduce risk. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoT #Security

##

thehackerwire@mastodon.social at 2026-08-18T03:00:05.000Z ##

๐Ÿ”ด CVE-2026-75094 - Critical (9.1)

A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injectio...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11801
(7.5 HIGH)

EPSS: 0.30%

updated 2026-08-18T03:31:11

2 posts

The WPAdverts โ€“ Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve internal site configuration data exposed by the classifieds-types REST endpoint, including register

thehackerwire@mastodon.social at 2026-08-18T05:00:21.000Z ##

๐ŸŸ  CVE-2026-11801 - High (7.5)

The WPAdverts โ€“ Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This make...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-18T04:30:25.000Z ##

WPAdverts โ€“ Classifieds Plugin <=2.3.2 hit by HIGH severity CWE-862 auth bypass (CVE-2026-11801). Unauthenticated users can access internal config data via REST API. Restrict endpoints & monitor for fixes. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vulnerability

##

CVE-2026-75482
(7.5 HIGH)

EPSS: 0.62%

updated 2026-08-17T21:31:35

1 posts

SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent-directory ('..') references, bypassing the built-in path sanitization. The server binds all interfaces (0.0.0.0), applies wildcard CORS, and requires no authentication. An unauthenticated network clie

thehackerwire@mastodon.social at 2026-08-18T05:00:44.000Z ##

๐ŸŸ  CVE-2026-75482 - High (7.5)

SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent-directory ('..') references, bypassing the buil...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75111
(7.5 HIGH)

EPSS: 0.39%

updated 2026-08-17T21:31:35

1 posts

Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory. Attackers can supply traversal sequences or absolute paths in the filename field to access system files, which are then materialized into datasets and retrieved through the download endpoint.

thehackerwire@mastodon.social at 2026-08-18T01:00:21.000Z ##

๐ŸŸ  CVE-2026-75111 - High (7.5)

Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory. Attackers can supply traversal sequences or absolut...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19478
(9.4 CRITICAL)

EPSS: 1.51%

updated 2026-08-17T21:31:30

15 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

3 repos

https://github.com/HORKimhab/CVE-2026-19650-CVE-2026-19478

https://github.com/davkharrr/CVE-2026-19478-PoC

https://github.com/renzi25031469/CVE-2026-19478

ransomnews.online@bsky.brid.gy at 2026-08-20T15:37:37.000Z ##

๐Ÿšจ ๐ŸฆŠ GitLab flaw exploited within two days

CVE-2026-19478 lets unauthenticated attackers alter or delete public projects via #GraphQL.
๐Ÿ”— read more: www.securityweek.com...

#ransomNews #cyberthreats #GitLab


Critical GitLab Flaw Exploited...

##

hackmag at 2026-08-20T04:30:06.544Z ##

โšช๏ธ Critical GitLab Vulnerability Allowed Deletion of Public Projects

๐Ÿ—จ๏ธ GitLab developers have released emergency patches for Community Edition (CE) and Enterprise Edition (EE) that address the critical vulnerability CVE-2026-19478 (CVSS score: 9.4). Under certain conditions, the flaw allowed an unauthenticated attacker to remotely modify or delete public projects andโ€ฆ

๐Ÿ”— hackmag.com/news/cve-2026-1947

##

threatcodex at 2026-08-19T14:17:54.524Z ##

Critical and High-Severity GraphQL CVEs in GitLab: Code Injection and CSRF via One Directive

ox.security/blog/gitlab-graphq

##

tierrasapiens@mastodon.social at 2026-08-19T12:35:11.000Z ##

๐Ÿ–ฒ๏ธ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
โšซ Critical GitLab Zero-Click Flaw Poses Mitigation Challenges
๐Ÿ”— darkreading.com/application-se

A lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential exploitation of CVE-2026-19478.

##

oversecurity@mastodon.social at 2026-08-19T08:13:08.000Z ##

Critical GitLab Flaw Lets Hackers Alter or Delete Public Projects

GitLab has patched two security flaws, including CVE-2026-19478, a critical code injection vulnerability that could allow unauthenticated attackers...

๐Ÿ”—๏ธ [Thecyberexpress] link.is.it/otTWyh

##

sayzard@mastodon.sayzard.org at 2026-08-19T07:44:37.000Z ##

GitLab CVE-2026-19478: GraphQL authorization bypass

๋ณธ๋ฌธ์€ ์ž์ฒด ์šด์˜ GitLab์˜ GraphQL directive ๊ฒฐํ•จ(CVE-2026-19478)์ด ์ธ์ฆ ์—†์ด ๊ณต๊ฐœ ํ”„๋กœ์ ํŠธ์™€ ์‚ฌ์šฉ์ž ๋ฐ์ดํ„ฐ๋ฅผ ๋ณ€๊ฒฝยท์‚ญ์ œํ•  ์ˆ˜ ์žˆ๋Š” CVSS 9.4๊ธ‰ ์ทจ์•ฝ์ ์ด๋ผ๊ณ  ์ฃผ์žฅํ•ฉ๋‹ˆ๋‹ค. ์˜ํ–ฅ ๋ฒ”์œ„๋กœ GitLab 18.2~18.11.10, 19.0~19.0.7, 19.1~19.1.5, 19.2~19.2.3์„ ์ œ์‹œํ•˜๋ฉฐ, ๊ฐ๊ฐ 18.11.11ยท19.0.8ยท19.1.6ยท19.2.4 ์ด์ƒ์œผ๋กœ ์ฆ‰์‹œ ์—…๊ทธ๋ ˆ์ด๋“œํ•  ๊ฒƒ์„ ๊ถŒ๊ณ ํ•ฉ๋‹ˆ๋‹ค. ํ•จ๊ป˜ ์ˆ˜์ •๋๋‹ค๋Š” CVE-2026-19650์€ GraphQL multiplex handler์˜ CSRF ๊ฒฐํ•จ์œผ๋กœ, ์ธ์ฆ ์‚ฌ์šฉ์ž์˜ ์ƒํ˜ธ์ž‘์šฉ์ด ํ•„์š”...

techupdate24.com/gitlab-cve-20

##

hackmag@infosec.exchange at 2026-08-20T04:30:06.000Z ##

โšช๏ธ Critical GitLab Vulnerability Allowed Deletion of Public Projects

๐Ÿ—จ๏ธ GitLab developers have released emergency patches for Community Edition (CE) and Enterprise Edition (EE) that address the critical vulnerability CVE-2026-19478 (CVSS score: 9.4). Under certain conditions, the flaw allowed an unauthenticated attacker to remotely modify or delete public projects andโ€ฆ

๐Ÿ”— hackmag.com/news/cve-2026-1947

#news

##

threatcodex@infosec.exchange at 2026-08-19T14:17:54.000Z ##

Critical and High-Severity GraphQL CVEs in GitLab: Code Injection and CSRF via One Directive
#GitLab #CVE_2026_19478 #CVE_2026_19650
ox.security/blog/gitlab-graphq

##

oversecurity@mastodon.social at 2026-08-19T08:13:08.000Z ##

Critical GitLab Flaw Lets Hackers Alter or Delete Public Projects

GitLab has patched two security flaws, including CVE-2026-19478, a critical code injection vulnerability that could allow unauthenticated attackers...

๐Ÿ”—๏ธ [Thecyberexpress] link.is.it/otTWyh

##

threatnoir@infosec.exchange at 2026-08-18T16:08:32.000Z ##

โš ๏ธ CRITICAL: GitLab Patches Critical Code Injection Vulnerability

GitLab released patches for a critical unauthenticated code injection vulnerability (CVE-2026-19478, CVSS 9.4) in GraphQL directives that allows attackers to modify or delete user data and public projects. A secondary CSRF flaw (CVE-2026-19650) affects the GraphQL multiplex query handler. Versionsโ€ฆ

threatnoir.com/focus

#infosec #cybersecurity

๐Ÿค– AI generated summary

##

beyondmachines1@infosec.exchange at 2026-08-18T11:01:46.000Z ##

GitLab Issues Emergency Patch for Critical GraphQL Flaw Allowing Remote Project Deletion

GitLab issued an emergency security update to fix a critical GraphQL code injection vulnerability (CVE-2026-19478) that allows unauthenticated attackers to remotely delete or modify public projects and user data.

**If you run a self-managed GitLab server (version 18.2 through 19.2.3), update it ASAP to 19.2.4, 19.1.6, 19.0.8, or 18.11.11. The patch is quick and won't take your system offline. Before you patch, check your logs for unusual GraphQL activity so you know nobody has already deleted or altered your projects or user data.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

offseq@infosec.exchange at 2026-08-18T09:00:28.000Z ##

CRITICAL: GitLab CE/EE (v18.2+ to 19.2.4) patched CVE-2026-19478, a code injection bug allowing unauthenticated data modification/deletion via GraphQL. CSRF (CVE-2026-19650) also fixed. Upgrade to safe versions ASAP. radar.offseq.com/threat/gitlab #OffSeq #GitLab #Infosec #CVE

##

cyberworldops@infosec.exchange at 2026-08-18T04:20:01.000Z ##

GitLab addressed a critical GraphQL flaw, CVE-2026-19478, with a CVSS score of 9.4, allowing attackers to modify or delete projects in GitLab CE and EE. This poses serious risks to code repositories and requires immediate patching to prevent exploitation. #GitLabCVE #GraphQLFlaw #CyberSecurityUpdate #InfoSecCritical

cyberworldops.eu/en/gitlab-fix

##

security_crawler_carl@infosec.exchange at 2026-08-18T02:53:30.000Z ##

๐Ÿ† New Achievement! Delete Yourself From This Industry!

Welcome to Module 9: GraphQL Directive Hygiene. Today's learning objective: CVE-2026-19478, a CVSS 9.4 flaw in GitLab Community and Enterprise Edition that allows a completely unauthenticated attacker โ€” no credentials, no victim interaction, no participation trophy โ€” to remotely modify or delete public projects and user data. (1/2)

##

DailyCyberSecurity@infosec.exchange at 2026-08-18T01:41:10.000Z ##

GitLab patched CVE-2026-19478, a CVSS 9.4 GraphQL code injection flaw letting unauthenticated users alter or delete project data.

#CVE202619478 #GitLab #CodeInjection #GraphQL #CVE202619650 #PatchNow

securityonline.info/gitlab-cve

##

CVE-2026-19650
(7.1 HIGH)

EPSS: 0.24%

updated 2026-08-17T21:31:30

3 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling.

1 repos

https://github.com/HORKimhab/CVE-2026-19650-CVE-2026-19478

sayzard@mastodon.sayzard.org at 2026-08-19T07:44:37.000Z ##

GitLab CVE-2026-19478: GraphQL authorization bypass

๋ณธ๋ฌธ์€ ์ž์ฒด ์šด์˜ GitLab์˜ GraphQL directive ๊ฒฐํ•จ(CVE-2026-19478)์ด ์ธ์ฆ ์—†์ด ๊ณต๊ฐœ ํ”„๋กœ์ ํŠธ์™€ ์‚ฌ์šฉ์ž ๋ฐ์ดํ„ฐ๋ฅผ ๋ณ€๊ฒฝยท์‚ญ์ œํ•  ์ˆ˜ ์žˆ๋Š” CVSS 9.4๊ธ‰ ์ทจ์•ฝ์ ์ด๋ผ๊ณ  ์ฃผ์žฅํ•ฉ๋‹ˆ๋‹ค. ์˜ํ–ฅ ๋ฒ”์œ„๋กœ GitLab 18.2~18.11.10, 19.0~19.0.7, 19.1~19.1.5, 19.2~19.2.3์„ ์ œ์‹œํ•˜๋ฉฐ, ๊ฐ๊ฐ 18.11.11ยท19.0.8ยท19.1.6ยท19.2.4 ์ด์ƒ์œผ๋กœ ์ฆ‰์‹œ ์—…๊ทธ๋ ˆ์ด๋“œํ•  ๊ฒƒ์„ ๊ถŒ๊ณ ํ•ฉ๋‹ˆ๋‹ค. ํ•จ๊ป˜ ์ˆ˜์ •๋๋‹ค๋Š” CVE-2026-19650์€ GraphQL multiplex handler์˜ CSRF ๊ฒฐํ•จ์œผ๋กœ, ์ธ์ฆ ์‚ฌ์šฉ์ž์˜ ์ƒํ˜ธ์ž‘์šฉ์ด ํ•„์š”...

techupdate24.com/gitlab-cve-20

##

threatnoir@infosec.exchange at 2026-08-18T16:08:32.000Z ##

โš ๏ธ CRITICAL: GitLab Patches Critical Code Injection Vulnerability

GitLab released patches for a critical unauthenticated code injection vulnerability (CVE-2026-19478, CVSS 9.4) in GraphQL directives that allows attackers to modify or delete user data and public projects. A secondary CSRF flaw (CVE-2026-19650) affects the GraphQL multiplex query handler. Versionsโ€ฆ

threatnoir.com/focus

#infosec #cybersecurity

๐Ÿค– AI generated summary

##

offseq@infosec.exchange at 2026-08-18T09:00:28.000Z ##

CRITICAL: GitLab CE/EE (v18.2+ to 19.2.4) patched CVE-2026-19478, a code injection bug allowing unauthenticated data modification/deletion via GraphQL. CSRF (CVE-2026-19650) also fixed. Upgrade to safe versions ASAP. radar.offseq.com/threat/gitlab #OffSeq #GitLab #Infosec #CVE

##

CVE-2026-75106
(9.1 CRITICAL)

EPSS: 0.30%

updated 2026-08-17T21:31:30

1 posts

OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other respondents' full submission data through the submission-fetch endpoint or overwrite submissions by supplying predicted hashes to the answer endpoint.

thehackerwire@mastodon.social at 2026-08-18T06:01:22.000Z ##

๐Ÿ”ด CVE-2026-75106 - Critical (9.1)

OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other respondents' full submission da...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75105
(7.5 HIGH)

EPSS: 0.28%

updated 2026-08-17T21:31:30

1 posts

phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and app/temp_share/address.php, when the share type is 'subnets', the subnetId parameter is used directly as a database primary key to fetch an address without confirming the address belongs to the authorized subnet. An unauthenticated party ho

thehackerwire@mastodon.social at 2026-08-18T06:01:12.000Z ##

๐ŸŸ  CVE-2026-75105 - High (7.5)

phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and app/temp_share/address.php, when the share type is 'subnets', the subnetId parameter is...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71290
(9.1 CRITICAL)

EPSS: 0.19%

updated 2026-08-17T19:06:52.793000

2 posts

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer.ย HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain.ย  Please note the classic vers

undercodenews@mastodon.social at 2026-08-19T08:36:09.000Z ##

Apache HttpClient TLS Flaw Could Let Attackers Impersonate Trusted Servers in MITM Attacks + Video

Introduction: When HTTPS Looks Secure but the Hostname Check Quietly Fails HTTPS is built around a simple promise: when an application connects to api.example.com, it should be able to confirm that the server on the other end is actually authorized to represent api.example.com. That trust relationship is now under scrutiny after the disclosure of CVE-2026-71290, a seriousโ€ฆ

undercodenews.com/apache-httpc

##

DailyCyberSecurity@infosec.exchange at 2026-08-18T13:02:55.000Z ##

CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic (CVSS 9.1)

securityonline.info/apache-htt

##

CVE-2026-40145(CVSS UNKNOWN)

EPSS: 0.11%

updated 2026-08-17T18:31:28

2 posts

A vulnerability exists in the interaction between a Endpoint Privilege Managementย (Windowsย Deployment)ย supportย utility and the agent's tamper protection controls. Under certain conditions, the protections applied to the utility process may not be enforced as intended.

CVE-2026-47686
(9.9 CRITICAL)

EPSS: 0.32%

updated 2026-08-17T17:32:35

2 posts

**Affected:** vm2 <= 3.11.3 **CVSS 3.1:** 9.9 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) **CWE:** CWE-693 (Protection Mechanism Failure) **Prerequisite:** Embedder exposes a host function that throws an Error with `.cause` referencing a powerful host object (e.g., `process`) ## Summary I found that `handleException()` in `lib/setup-sandbox.js` recursively sanitizes sub-errors for `Suppr

DailyCyberSecurity at 2026-08-20T13:15:58.124Z ##

A vm2 sandbox escape (CVE-2026-47686, CVSS 9.9) with public PoC lets attackers hijack the host. Two more critical flaws also patched. Update to 3.11.6.

securityonline.info/vm2-sandbo

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T13:15:58.000Z ##

A vm2 sandbox escape (CVE-2026-47686, CVSS 9.9) with public PoC lets attackers hijack the host. Two more critical flaws also patched. Update to 3.11.6.

#vm2 #CVE202647686 #SandboxEscape #RCE #NodeJS #InfoSec

securityonline.info/vm2-sandbo

##

CVE-2026-71479
(9.1 CRITICAL)

EPSS: 0.52%

updated 2026-08-17T16:36:14

1 posts

## Summary Multiple billing paths multiplied **user-controlled quantity parameters** into the quota calculation without an upper bound or overflow-safe integer conversion. A crafted extreme value (e.g. image `n = 18446744073686646784`, a wrapped-negative accepted by a `*uint` field) makes conversions like `int(float64(quota) * n)` wrap past the int64/int32 range into a large **negative** quota. T

CVE-2026-74889
(9.8 CRITICAL)

EPSS: 0.20%

updated 2026-08-17T12:32:31

1 posts

openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.

hugovalters@mastodon.social at 2026-08-18T01:00:27.000Z ##

CVE-2026-74889 - Critical crypto weakness in openssl_encrypt <1.4.0. HKDF with no salt/static info weakens key derivation, enabling multi-target attacks. CVSS 9.8. Update immediately. #CVE #cryptography #infosec

valtersit.com/cve/CVE-2026-748

##

CVE-2026-17186
(9.9 CRITICAL)

EPSS: 0.47%

updated 2026-08-14T21:31:35

2 posts

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.

CVE-2026-18146
(7.2 HIGH)

EPSS: 0.36%

updated 2026-08-14T19:09:56.813000

1 posts

The Fluent Forms โ€“ Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Notification Smartcode Values in all versions up to, and including, 6.2.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in the

wpguyuk@infosec.exchange at 2026-08-18T20:58:56.000Z ##

If you are running Fluent Forms and have not updated since 13 August 2026, attackers may already be scanning for your installation. CVE-2026-18146 is high-severity and affects every version below 6.2.12. Update now.

#WordPress #WordPressSecurity #FluentForms #CVE #WebSecurity

wpguy.uk/blog/high-vulnerabili

##

CVE-2026-66804
(7.8 HIGH)

EPSS: 3.42%

updated 2026-08-14T18:06:11.420000

1 posts

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

3 repos

https://github.com/DavidCarliez/CVE-2026-66804-CrossDevice-LPE

https://github.com/Rat5ak/CVE-2026-66804-CrossDevice-Service-EoP

https://github.com/CypherHippie/CVE-2026-66804

CVE-2026-73570
(8.9 HIGH)

EPSS: 0.54%

updated 2026-08-14T05:17:00.340000

11 posts

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands a

cyberworldops at 2026-08-20T18:20:00.868Z ##

Active exploitation of CVE-2026-73570 in Zimbra Collaboration Suite is underway. The command injection flaw enables unauthenticated RCE on ZCS versions prior to 10.1.20 when zimbra-snmp is installed with SNMP notifications active. Attackers exploit this via crafted SMTP requests for full server compromise. Patch or disable SNMP immediately.

cyberworldops.eu/en/zimbra-vul

##

undercodenews@mastodon.social at 2026-08-20T16:51:59.000Z ##

Critical Zimbra Flaw Under Active Exploitation: Why CVE-2026-73570 Demands Immediate Attention + Video

Introduction: When an Email Server Becomes the Door Into an Entire Organization Email remains one of the most valuable systems inside any organization. It carries confidential conversations, authentication links, financial documents, government communications, customer information, and the daily operational decisions that keep businesses moving. That is exactly why aโ€ฆ

undercodenews.com/critical-zim

##

Analyst207@mastodon.social at 2026-08-20T14:59:24.000Z ##

Zimbra SNMP Flaw Exploited for Remote Code Execution

A critical Zimbra SNMP flaw, CVE-2026-73570, with a CVSS score of 8.9, is under active exploitation, allowing attackers to execute remote code. This vulnerability can be triggered by sending specially crafted SNMP requests, putting unpatched Zimbra Collaboration systems at risk.

osintsights.com/zimbra-snmp-fl

#Zimbra #RemoteCodeExecution #Cve202673570 #Snmp #EmergingThreats

##

ransomnews.online@bsky.brid.gy at 2026-08-20T11:37:37.000Z ##

โš ๏ธ Zimbra RCE faces active exploitation

CVE-2026-73570 enables unauthenticated OS command injection; Zimbra fixed it in version 10.1.20.
๐Ÿ”— read more: gbhackers.com/zimbra...

#ransomNews #cyberthreats #Zimbra


Zimbra RCE Vulnerability Lets ...

##

undercodenews@mastodon.social at 2026-08-20T10:42:55.000Z ##

Zimbra Under Attack: Critical CVE-2026-73570 Is Now Being Exploited in the Wild

A Critical Warning for Thousands of Exposed Email Servers A serious new threat is emerging around Zimbra Collaboration Suite (ZCS), one of the most widely deployed open-source collaboration and email platforms used by organizations around the world. Security defenders are now facing a particularly dangerous combination: a critical vulnerability, internet-exposed systems, and credibleโ€ฆ

undercodenews.com/zimbra-under

##

offseq at 2026-08-20T10:30:27.507Z ##

CRITICAL: CVE-2026-73570 in Zimbra Collaboration Suite is under active exploit. RCE via SNMP notifications lets unauth attackers run OS commands as Zimbra user. Patch to 10.1.20 now & monitor for abnormal files/restarts. Details: radar.offseq.com/threat/critic

##

Analyst207@mastodon.social at 2026-08-20T09:55:40.000Z ##

Zimbra Vulnerability Exploited in Active Attacks

A critical vulnerability in the Zimbra Collaboration Suite is under active attack, putting over 12,100 exposed servers worldwide at risk, with most located in Europe and Asia. Attackers can exploit this flaw, tracked as CVE-2026-73570, to execute remote code without authentication, simply by sending specially crafted SMTP requests.

osintsights.com/zimbra-vulnera

#ZimbraCollaborationSuite #Cve202673570 #RemoteCodeExecution #CommandInjection #Snmp

##

DailyCyberSecurity at 2026-08-20T02:38:01.490Z ##

CVE-2026-73570 is exploited in the wild. This unauthenticated RCE hits Zimbra Collaboration via SNMP notifications. Patch to 10.1.20 now.

securityonline.info/zimbra-cve

##

cyberworldops@infosec.exchange at 2026-08-20T18:20:00.000Z ##

Active exploitation of CVE-2026-73570 in Zimbra Collaboration Suite is underway. The command injection flaw enables unauthenticated RCE on ZCS versions prior to 10.1.20 when zimbra-snmp is installed with SNMP notifications active. Attackers exploit this via crafted SMTP requests for full server compromise. Patch or disable SNMP immediately.

#ZimbraRCE #CVE202673570 #PatchNow

cyberworldops.eu/en/zimbra-vul

##

offseq@infosec.exchange at 2026-08-20T10:30:27.000Z ##

CRITICAL: CVE-2026-73570 in Zimbra Collaboration Suite is under active exploit. RCE via SNMP notifications lets unauth attackers run OS commands as Zimbra user. Patch to 10.1.20 now & monitor for abnormal files/restarts. Details: radar.offseq.com/threat/critic #OffSeq #Zimbra #Vuln

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T02:38:01.000Z ##

CVE-2026-73570 is exploited in the wild. This unauthenticated RCE hits Zimbra Collaboration via SNMP notifications. Patch to 10.1.20 now.

#Zimbra #CVE #RCE #RemoteCodeExecution #ExploitedInTheWild #InfoSec #PatchNow

securityonline.info/zimbra-cve

##

CVE-2026-68138
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-14T00:31:53

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/sched: serialize qdisc_rtab_list against concurrent get/put qdisc_get_rtab() and qdisc_put_rtab() mutate the process-global singly linked list qdisc_rtab_list and a plain non-atomic 'int refcnt' with no lock. This was only safe because every caller historically held the RTNL mutex, which serialized all rate-table lookups, in

3 repos

https://github.com/jangkrikkbozz/CVE-2026-68138

https://github.com/suominen/CVE-2026-68138

https://github.com/aramosf/CVE-2026-68138

CVE-2026-8715
(9.6 CRITICAL)

EPSS: 0.32%

updated 2026-08-13T21:36:21

2 posts

Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. Th

CVE-2026-17482
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-08-13T21:36:21

2 posts

IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.

DailyCyberSecurity at 2026-08-19T01:34:45.699Z ##

A critical IBM remote code execution flaw (CVE-2026-17482, CVSS 9.8) allows attackers to compromise workstations. Discover how to apply the software patch.

securityonline.info/ibm-remote

##

DailyCyberSecurity@infosec.exchange at 2026-08-19T01:34:45.000Z ##

A critical IBM remote code execution flaw (CVE-2026-17482, CVSS 9.8) allows attackers to compromise workstations. Discover how to apply the software patch.

#IBM #CyberSecurity #CVE202617482 #RCE #VulnerabilityManagement

securityonline.info/ibm-remote

##

CVE-2026-19001
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-08-13T13:17:48.253000

1 posts

The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and, under certain conditions, the potential for arbitrary code execution.

CVE-2026-68820
(7.0 None)

EPSS: 0.33%

updated 2026-08-11T21:33:01

2 posts

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

2 repos

https://github.com/ubitquity/Windows-WinSock-UAF-Mitigation

https://github.com/HORKimhab/CVE-2026-68820

youranonnewsirc@nerdculture.de at 2026-08-18T16:26:33.000Z ##

August 17-18, 2026:

**Geopolitical:** Saudi Arabia, Tรผrkiye, and Pakistan formalized a strategic defense pact. Commercial tanker traffic in the Strait of Hormuz plummeted to near-zero following recent strikes and stalled US-Iran negotiations.

**Technology:** Nvidia plans significant AI data center investments for OpenAI. AI-driven tech layoffs have now surpassed 2025 totals. Google Cloud targets 2029 for post-quantum cryptographic readiness.

**Cybersecurity:** Major data breaches impacted RingCentral (1.6M users) and Poland's MyDr healthcare platform (19M citizens). Microsoft patched 421 vulnerabilities, including an actively exploited Windows zero-day by Lazarus Group (CVE-2026-68820).

#AnonNews_irc #Cybersecurity #News

##

threatnoir@infosec.exchange at 2026-08-18T15:05:54.000Z ##

โš ๏ธ CRITICAL: โšก Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

Three critical vulnerabilities are under active exploitation: VMware vCenter (CVE-2026-59310) by China-nexus APT for potential ransomware deployment, Windows 0-day (CVE-2026-68820) by Lazarus Group targeting defense contractors with backdoors, and macOS flaw (CVE-2026-65400) distributing crypto minโ€ฆ

threatnoir.com/focus

#infosec #cybersecurity

๐Ÿค– AI generated summary

##

CVE-2026-13737(CVSS UNKNOWN)

EPSS: 0.43%

updated 2026-08-11T18:30:43

2 posts

CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.

DailyCyberSecurity at 2026-08-19T12:57:03.837Z ##

Protect your network from CVE-2026-13737 and CVE-2026-13738. These critical Commvault command execution flaws allow hackers to bypass authorization checks.

securityonline.info/commvault-

##

DailyCyberSecurity@infosec.exchange at 2026-08-19T12:57:03.000Z ##

Protect your network from CVE-2026-13737 and CVE-2026-13738. These critical Commvault command execution flaws allow hackers to bypass authorization checks.

#Commvault #CVE202613737 #CVE202613738 #Cybersecurity #Vulnerability

securityonline.info/commvault-

##

CVE-2026-13738
(0 None)

EPSS: 0.53%

updated 2026-08-11T17:17:47.660000

2 posts

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.

DailyCyberSecurity at 2026-08-19T12:57:03.837Z ##

Protect your network from CVE-2026-13737 and CVE-2026-13738. These critical Commvault command execution flaws allow hackers to bypass authorization checks.

securityonline.info/commvault-

##

DailyCyberSecurity@infosec.exchange at 2026-08-19T12:57:03.000Z ##

Protect your network from CVE-2026-13737 and CVE-2026-13738. These critical Commvault command execution flaws allow hackers to bypass authorization checks.

#Commvault #CVE202613737 #CVE202613738 #Cybersecurity #Vulnerability

securityonline.info/commvault-

##

CVE-2026-58231
(10.0 CRITICAL)

EPSS: 0.73%

updated 2026-08-11T12:30:28

3 posts

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

1 repos

https://github.com/HORKimhab/CVE-2026-58231

DailyCyberSecurity@infosec.exchange at 2026-08-18T13:31:10.000Z ##

DefusedCyber detected exploitation attempts against CVE-2026-58231, a critical unauthenticated SAP Commerce Cloud flaw, just three days after SAP's patch shipped.

#SAPCommerceCloud #CVE202658231 #SAPSecurity #Vulnerability #DataHubAdapter

meterpreter.org/cve-2026-58231

##

teezeh@ieji.de at 2026-08-18T06:16:53.000Z ##

โ€œA maximum-severity bug in SAP Commerce Cloud was exploited in the wild, research group Defused posted on X Aug. 14.

The 10.0 bug โ€” CVE-2026-58231 โ€” was described as having insufficient authorization checks and input validation and was earlier patched by SAP on Aug. 11.โ€

scworld.com/news/critical-sap-

##

ottoto2017@prattohome.com at 2026-08-18T05:35:18.000Z ##

ใ€ŒSAP Commerce Cloudใฎ่„†ๅผฑๆ€งCVE-2026-58231ใŒใ€ใƒ‘ใƒƒใƒ้ฉ็”จๅพŒๆ•ฐๆ—ฅใงๆ‚ช็”จใ•ใ‚Œใ‚‹่ฉฆใฟใฎๆจ™็š„ใจใชใ‚‹ ใ€๏ผš #TheHackerNews

ใ€ŒSAP Commerce Cloudใซๅฝฑ้Ÿฟใ‚’ไธŽใˆใ‚‹ใ€ๆœ€ใ‚‚ๆทฑๅˆปใชใ‚ปใ‚ญใƒฅใƒชใƒ†ใ‚ฃ่„†ๅผฑๆ€งใซใคใ„ใฆใ€็พๅœจๆดป็™บใชๆ‚ช็”จๆดปๅ‹•ใŒ่กŒใ‚ใ‚Œใฆใ„ใพใ™ใ€‚

CVE-2026-58231 ใจใ—ใฆ่ฟฝ่ทกใ•ใ‚Œใฆใ„ใ‚‹ใ“ใฎ่„†ๅผฑๆ€งใฏใ€ CVSSใ‚นใ‚ณใ‚ขใƒชใƒณใ‚ฐใ‚ทใ‚นใƒ†ใƒ ใง10.0ใจ่ฉ•ไพกใ•ใ‚Œใฆใ„ใพใ™ใ€‚ใ“ใ‚Œใฏใ€่ช่จผใƒใ‚งใƒƒใ‚ฏใจๅ…ฅๅŠ›ๆคœ่จผใŒไธๅๅˆ†ใชใ‚ฑใƒผใ‚นใซ้–ข้€ฃใ—ใฆใ„ใพใ™ใ€‚

CVE.orgใซใ‚ˆใ‚‹ใจใ€ใ€ŒSAP Commerce Cloudใงใฏใ€่ช่จผใ•ใ‚Œใฆใ„ใชใ„ๆ”ปๆ’ƒ่€…ใŒใƒ‡ใƒ•ใ‚ฉใƒซใƒˆใฎ่ช่จผใ‚ฏใƒฉใ‚คใ‚ขใƒณใƒˆใ‚’ๆ‚ช็”จใ—ใ€ๅๅˆ†ใชๆคœ่จผใŒ่กŒใ‚ใ‚Œใฆใ„ใชใ„็‰นๅฎšใฎๆฉŸ่ƒฝใซ็‰นๅˆฅใซ็ดฐๅทฅใ•ใ‚ŒใŸๅ…ฅๅŠ›ใ‚’้€ไฟกใงใใ‚‹ใ€ใจใฎใ“ใจใงใ™ใ€‚

ใ€Œ่„†ๅผฑๆ€งใ‚’ๆ‚ช็”จใ•ใ‚Œใ‚‹ใจใ€ไปปๆ„ใฎใ‚ณใƒผใƒ‰ๅฎŸ่กŒใŒๅฏ่ƒฝใซใชใ‚Šใ€ๅ†…้ƒจใ‚ณใƒณใƒใƒผใƒใƒณใƒˆใŒไพตๅฎณใ•ใ‚Œใ‚‹ๅฏ่ƒฝๆ€งใŒใ‚ใ‚Šใ€ใ‚ขใƒ—ใƒชใ‚ฑใƒผใ‚ทใƒงใƒณใฎๆฉŸๅฏ†ๆ€งใ€ๅฎŒๅ…จๆ€งใ€ๅฏ็”จๆ€งใซ้‡ๅคงใชๅฝฑ้Ÿฟใ‚’ไธŽใˆใ‚‹ๅฏ่ƒฝๆ€งใŒใ‚ใ‚Šใพใ™ใ€‚ใ€ ใ€

thehackernews.com/2026/08/sap-

#prattohome

##

CVE-2026-71958
(9.8 CRITICAL)

EPSS: 0.56%

updated 2026-08-08T18:30:30

1 posts

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.

CVE-2026-6540
(7.5 HIGH)

EPSS: 0.37%

updated 2026-08-08T03:32:15

2 posts

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not correctly evaluated by Prefix path rules. Dikastes authorizes the request under the permitted prefix while the downstream workload or a fronting proxy norm

1 repos

https://github.com/HORKimhab/CVE-2026-65400

hackmag at 2026-08-18T22:31:05.124Z ##

โšช๏ธ Hackers Exploit macOS Screen Sharing Vulnerability to Install Crypto Miners

๐Ÿ—จ๏ธ The Netherlandsโ€™ National Cyber Security Centre (NCSC) has warned that attackers have begun exploiting the critical CVE-2026-65400 vulnerability in macOS Screen Sharing. The flaw allows authentication to be bypassed, granting access to a Mac without a password, and is alreadyโ€ฆ

๐Ÿ”— hackmag.com/news/cve-2026-6540

##

hackmag@infosec.exchange at 2026-08-18T22:31:05.000Z ##

โšช๏ธ Hackers Exploit macOS Screen Sharing Vulnerability to Install Crypto Miners

๐Ÿ—จ๏ธ The Netherlandsโ€™ National Cyber Security Centre (NCSC) has warned that attackers have begun exploiting the critical CVE-2026-65400 vulnerability in macOS Screen Sharing. The flaw allows authentication to be bypassed, granting access to a Mac without a password, and is alreadyโ€ฆ

๐Ÿ”— hackmag.com/news/cve-2026-6540

#news

##

CVE-2026-12569
(9.8 CRITICAL)

EPSS: 30.20%

updated 2026-08-01T05:16:55.023000

18 posts

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.ย  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

1 repos

https://github.com/west-wind/Threat-Hunting-With-Splunk

cyberveille@mastobot.ping.moi at 2026-08-20T18:30:05.000Z ##

๐Ÿ“ข Clop exploite CVE-2026-12569 dans PTC Windchill avec un web shell personnalisรฉ pour extorsion massive

๐Ÿ“… Source : ReliaQuest Threat Research Team, publiรฉ le 18 aoรปt 2026. Cette analyse technique dรฉcrit une campagne d'extorsion de masse attribuรฉe avec haute confiance au groupe Clop (aka Cl0p).

๐Ÿ“– cyberveille : cyberveille.ch/posts/2026-08-2
๐ŸŒ source : reliaquest.com/blog/clop-retur
๐ŸŸข vรฉrification factuelle haute
#Clop #PTCWindchill #Cyberveille

##

threatnoir at 2026-08-20T16:06:30.298Z ##

โš ๏ธ CRITICAL: Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

Clop ransomware operators deployed a custom JSP web shell targeting PTC Windchill and FlexPLM servers, exploiting CVE-2026-12569 to decrypt stored credentials and exfiltrate engineering data. Any organization running vulnerable Windchill instances is at immediate risk of credential compromise, lateโ€ฆ

threatnoir.com/focus

๐Ÿค– AI generated summary

##

DailyCyberSecurity at 2026-08-20T13:02:20.500Z ##

ReliaQuest found Clop deploying a purpose-built JSP web shell that abuses Windchill's internal APIs to decrypt secrets and steal files after exploiting CVE-2026-12569.

meterpreter.org/clop-windchill

##

cyberworldops at 2026-08-20T00:20:00.444Z ##

Cl0p published full names of over 40 organizations allegedly breached through CVE-2026-12569 in PTC Windchill and FlexPLM. The flaw was added to CISA KEV in June, yet dozens of instances remained unpatched into August.

cyberworldops.eu/en/cl0p-targe

##

Analyst207@mastodon.social at 2026-08-19T17:56:35.000Z ##

Clop Exploits PTC Zero-Day in Large-Scale Data Theft Spree

Clop's latest large-scale data theft spree exploited a critical PTC zero-day vulnerability, CVE-2026-12569, affecting supply chain systems used by manufacturers, retailers, and industries like aerospace and automotive. This attack continues Clop's trend of targeting SaaS logistics companies with zero-days to carry out mass-exploitation campaigns.

osintsights.com/clop-exploits-

#Clop #Ptc #ZeroDay #Cve202612569 #SupplyChain

##

security_crawler_carl at 2026-08-19T16:30:24.086Z ##

You built your product lifecycle management empire on unpatched servers. Magnificent. Truly. Patch CVE-2026-12569 on all PTC Windchill and FlexPLM instances immediately, and hunt for unauthorized web shells before Clop finishes admiring your data.

Reward: You've unlocked the Hollow Trophy โ€” a shiny gold cup with absolutely nothing inside it, just like your patch management schedule.

(2/2)

##

security_crawler_carl at 2026-08-19T16:30:23.934Z ##

๐Ÿ† New Achievement! Shell We Dance, PTC?

Ahem. Allow me to explain my genius. Clop โ€” yes, the ransomware operation, the one you've heard about in hushed tones โ€” identified CVE-2026-12569 in PTC Windchill and FlexPLM servers and deployed a custom web shell so elegantly minimal it needs no additional tooling whatsoever. Credentials? Siphoned. Sensitive engineering data? Exfiltrated. It's almost beautiful, like a Bond villain who remembered to actually press the button. (1/2)

##

cyberworldops at 2026-08-19T14:20:00.484Z ##

ReliaQuest has documented a custom JSP web shell deployed by Clop after exploitation of CVE-2026-12569 on PTC Windchill and FlexPLM servers. The implant maps design vaults, decrypts keystore credentials, and queries databases via the application's own identity.

cyberworldops.eu/en/clop-explo

##

offseq at 2026-08-19T12:00:30.769Z ##

PTC Windchill/FlexPLM (CVE-2026-12569) exploited by Cl0p ransomware: CRITICAL severity, remote code execution, 40+ orgs hit. Patch ASAP to block active data theft & extortion. Full details: radar.offseq.com/threat/cl0p-r

##

sayzard@mastodon.sayzard.org at 2026-08-19T09:39:07.000Z ##

Clop Returns with Custom Implant in Mass-Extortion Campaign

Clop์œผ๋กœ ์ถ”์ •๋˜๋Š” ๊ณต๊ฒฉ ๊ทธ๋ฃน์ด PTC Windchill์˜ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ ์ทจ์•ฝ์  CVE-2026-12569(CVSS 9.3)๋ฅผ ๋Œ€๋Ÿ‰ ์•…์šฉํ•ด ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์ „์šฉ JSP ์›น์…ธ์„ ๋ฐฐํฌํ•˜๊ณ  ์žˆ๋‹ค. ์ด ์ž„ํ”Œ๋ž€ํŠธ๋Š” Windchill ํ‚ค์Šคํ† ์–ด์˜ LDAPยท๊ด€๋ฆฌ์žยท์Šคํ† ๋ฆฌ์ง€ ์ž๊ฒฉ์ฆ๋ช…์„ ๋ณตํ˜ธํ™”ํ•˜๊ณ , ๋‚ด๋ถ€ DB ์Šคํ‚ค๋งˆ์™€ vault ๊ตฌ์กฐ๋ฅผ ์ด์šฉํ•ด ๊ณ ๊ฐ€์น˜ ์—”์ง€๋‹ˆ์–ด๋ง ํŒŒ์ผ์„ ์—ด๊ฑฐยท์œ ์ถœํ•  ์ˆ˜ ์žˆ๋‹ค. ๋˜ํ•œ Base64 ZIP ํ˜•ํƒœ์˜ Java ๋ฐ”์ดํŠธ์ฝ”๋“œ๋ฅผ ๋ฉ”๋ชจ๋ฆฌ์—์„œ ๋กœ๋“œยท์‹คํ–‰ํ•˜๋Š” ์ปค์Šคํ…€ ํด๋ž˜์Šค ๋กœ๋”๋ฅผ ํฌํ•จํ•ด, ๋””์Šคํฌ ํ”์ ์„ ์ตœ์†Œํ™”ํ•˜๋ฉด์„œ ํšก์  ์ด๋™...

reliaquest.com/blog/clop-retur

##

undercodenews@mastodon.social at 2026-08-19T06:45:12.000Z ##

Cl0p Turns PTC Windchill Into a Data-Theft Weapon: Critical CVE-2026-12569 Exploited to Steal Industrial Secrets + Video

Introduction: When the Blueprint Becomes the Target The most dangerous cyberattacks do not always begin with a locked computer, a destroyed server, or a ransom note appearing across an employee's screen. Sometimes, the attack begins quietly against an application that nobody outside the engineering department thinks of as a critical securityโ€ฆ

undercodenews.com/cl0p-turns-p

##

threatnoir@infosec.exchange at 2026-08-20T16:06:30.000Z ##

โš ๏ธ CRITICAL: Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

Clop ransomware operators deployed a custom JSP web shell targeting PTC Windchill and FlexPLM servers, exploiting CVE-2026-12569 to decrypt stored credentials and exfiltrate engineering data. Any organization running vulnerable Windchill instances is at immediate risk of credential compromise, lateโ€ฆ

threatnoir.com/focus

#infosec #cybersecurity

๐Ÿค– AI generated summary

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T13:02:20.000Z ##

ReliaQuest found Clop deploying a purpose-built JSP web shell that abuses Windchill's internal APIs to decrypt secrets and steal files after exploiting CVE-2026-12569.

#Clop #Windchill #CVE202612569 #WebShell #DataExfiltration

meterpreter.org/clop-windchill

##

cyberworldops@infosec.exchange at 2026-08-20T00:20:00.000Z ##

Cl0p published full names of over 40 organizations allegedly breached through CVE-2026-12569 in PTC Windchill and FlexPLM. The flaw was added to CISA KEV in June, yet dozens of instances remained unpatched into August.

#Cl0p #Windchill #SupplyChainSecurity #CVE202612569

cyberworldops.eu/en/cl0p-targe

##

security_crawler_carl@infosec.exchange at 2026-08-19T16:30:24.000Z ##

You built your product lifecycle management empire on unpatched servers. Magnificent. Truly. Patch CVE-2026-12569 on all PTC Windchill and FlexPLM instances immediately, and hunt for unauthorized web shells before Clop finishes admiring your data.

Reward: You've unlocked the Hollow Trophy โ€” a shiny gold cup with absolutely nothing inside it, just like your patch management schedule.

#Ransomware #CyberSecurity #ClopRansomware #PtcWindchill #WebShell #PatchedOrPerish (2/2)

##

security_crawler_carl@infosec.exchange at 2026-08-19T16:30:23.000Z ##

๐Ÿ† New Achievement! Shell We Dance, PTC?

Ahem. Allow me to explain my genius. Clop โ€” yes, the ransomware operation, the one you've heard about in hushed tones โ€” identified CVE-2026-12569 in PTC Windchill and FlexPLM servers and deployed a custom web shell so elegantly minimal it needs no additional tooling whatsoever. Credentials? Siphoned. Sensitive engineering data? Exfiltrated. It's almost beautiful, like a Bond villain who remembered to actually press the button. (1/2)

##

cyberworldops@infosec.exchange at 2026-08-19T14:20:00.000Z ##

ReliaQuest has documented a custom JSP web shell deployed by Clop after exploitation of CVE-2026-12569 on PTC Windchill and FlexPLM servers. The implant maps design vaults, decrypts keystore credentials, and queries databases via the application's own identity.

#Clop #PTCWindchill #WebShell #ThreatIntelligence

cyberworldops.eu/en/clop-explo

##

offseq@infosec.exchange at 2026-08-19T12:00:30.000Z ##

PTC Windchill/FlexPLM (CVE-2026-12569) exploited by Cl0p ransomware: CRITICAL severity, remote code execution, 40+ orgs hit. Patch ASAP to block active data theft & extortion. Full details: radar.offseq.com/threat/cl0p-r #OffSeq #Ransomware #CVE202612569 #Infosec

##

CVE-2026-47301
(8.8 HIGH)

EPSS: 0.68%

updated 2026-07-30T19:17:31.990000

2 posts

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

1 repos

https://github.com/OmriBaso/SCCM-CVE-2026-47301-Remote-Code-Execution-Exploit

CVE-2026-43760
(8.6 HIGH)

EPSS: 0.24%

updated 2026-07-30T19:17:30.313000

1 posts

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access user-sensitive data.

cyberveille@mastobot.ping.moi at 2026-08-20T17:30:06.000Z ##

๐Ÿ“ข CVE-2026-43760 : RCE root ร  distance via Screen Sharing macOS sur Apple Silicon

Cet article prรฉsente une analyse technique dรฉtaillรฉe d'une vulnรฉrabilitรฉ dรฉcouverte dans le service Screen Sharing de macOS, affectant les systรจmes รฉquipรฉs de puces Apple Silicon (M4 et M5), testรฉs sous macOS 26.5.2 avec SIP activรฉ.

๐Ÿ“– cyberveille : cyberveille.ch/posts/2026-08-2
๐ŸŒ source : bynar.io/blog/a-root-remote-co
๐ŸŸก vรฉrification factuelle moyenne
#AppleSilicon #RCERoot #Cyberveille

##

CVE-2026-43774
(5.5 MEDIUM)

EPSS: 0.13%

updated 2026-07-28T18:33:56

1 posts

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.

decio@infosec.exchange at 2026-08-18T08:08:07.000Z ##

Petit insight trรจs sympa sur la recherche de vulnรฉrabilitรฉ macOS

Le chercheur Csaba Fitzl revient sur une jolie vuln dans Spotlight (Spotlight PostScript plugin), une sorte de petite chimรจre qui traรฎnait depuis un moment dans sa TODO list : quelques fonctions dรฉcompilรฉes du parser PostScript soumises ร  Claude, une piste identifiรฉe, puis validation humaine.

Rรฉsultat : CVE-2026-43774, un simple fichier .ps pouvant faire fuiter des morceaux de mรฉmoire de mdworker via les mรฉtadonnรฉes Spotlight.

Au-delร  du bug, le billet montre trรจs directement comment les IA sโ€™intรจgrent naturellement aux workflows de recherche de vulnรฉrabilitรฉs, en partant de lโ€™expertise humaine : une intuition et une approche, puis fuzzing dopรฉ au LLM, reverse, dรฉtection de patterns suspectsโ€ฆ

...et pourquoi les รฉditeurs comme la pomme doivent courir toujours plus vite derriรจre les patchs.

"How a single PostScript file leaks your Mac's memory"
๐Ÿ‘‡
iru.com/blog/how-a-single-post

##

CVE-2026-11622
(7.5 HIGH)

EPSS: 0.51%

updated 2026-07-22T15:31:34

2 posts

A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.

ondrej@sury.org at 2026-08-19T19:03:47.000Z ##

WTF?

> The fix for CVE-2026-11622 was reverted in commit d76328bfc7 on the development branch, reintroducing this vulnerability in the current stable release (9.20.27).

The branch was never merged and it was prepared just as an experiment. And this little ...personโ€ฆ tried to report this as CVSS 7.5.

##

ondrej@sury.org at 2026-08-19T19:03:47.000Z ##

WTF?

> The fix for CVE-2026-11622 was reverted in commit d76328bfc7 on the development branch, reintroducing this vulnerability in the current stable release (9.20.27).

The branch was never merged and it was prepared just as an experiment. And this little ...personโ€ฆ tried to report this as CVSS 7.5.

##

CVE-2026-8452
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-07-01T15:52:28.390000

1 posts

Memory overflow vulnerabilityย NetScaler ADC and NetScaler Gatewayย leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as aย Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

2 repos

https://github.com/derekpreston81/CVE_ADC_IOC_2026

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

CVE-2026-20266
(9.1 CRITICAL)

EPSS: 0.63%

updated 2026-06-17T18:35:58

2 posts

In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation.

CVE-2026-27912
(8.0 HIGH)

EPSS: 0.24%

updated 2026-06-17T10:27:52.490000

1 posts

Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.

3 repos

https://github.com/Semperis-Community/ResetNightmare

https://github.com/mihat2/ResetNightmare-impacket

https://github.com/oxstussz-eng/Kerberos-CVE-2026-27912

CVE-2021-33045
(9.8 CRITICAL)

EPSS: 99.56%

updated 2026-06-17T03:54:04.020000

1 posts

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Nuclei template

4 repos

https://github.com/dongpohezui/cve-2021-33045

https://github.com/bp2008/DahuaLoginBypass

https://github.com/umair-aziz025/dahua-cve-research

https://github.com/Bd-Mutant7/DahuaLoginBypass

sayzard@mastodon.sayzard.org at 2026-08-19T16:39:17.000Z ##

Operation CameraSwarm: 14,500 Dahua Cameras Compromised via P2P Relay Abuse

Hunt.io๊ฐ€ โ€˜Operation CameraSwarmโ€™ ์บ ํŽ˜์ธ์—์„œ Dahua ๊ฐ์‹œ ์นด๋ฉ”๋ผ 14,530๋Œ€ ์ด์ƒ์ด ํƒˆ์ทจ๋๋‹ค๊ณ  ๋ณด๊ณ ํ–ˆ๋‹ค. ๊ณต๊ฒฉ์ž๋Š” ๊ธฐ๋ณธยท์•ฝํ•œ ๋น„๋ฐ€๋ฒˆํ˜ธ ๋Œ€์ƒ ํฌ๋ฆฌ๋ด์…œ ๊ณต๊ฒฉ, CVSS 9.8์˜ ์ธ์ฆ ์šฐํšŒ ์ทจ์•ฝ์  CVE-2021-33044 ๋ฐ CVE-2021-33045, ๊ทธ๋ฆฌ๊ณ  Easy4IP ๊ณ„์—ด P2P ๋ฆด๋ ˆ์ด ์•…์šฉ์„ ๊ฒฐํ•ฉํ–ˆ๋‹ค. ํŠนํžˆ ์žฅ๋น„ ์ผ๋ จ๋ฒˆํ˜ธ๋ฅผ ์ด์šฉํ•œ P2P ํ„ฐ๋„์€ NAT ๋’ค์— ์žˆ๋Š” ์นด๋ฉ”๋ผ์—๋„ ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์–ด, ๋‹จ์ˆœํ•œ ๋„คํŠธ์›Œํฌ ๊ฒฝ๊ณ„ ๋ฐฉ์–ด๋งŒ์œผ๋กœ๋Š” ๋ถ€์กฑํ•˜๋‹ค๋Š” ์ ์ด ํ•ต์‹ฌ์ด๋‹ค. Dahua ์žฅ๋น„ ์šด์˜ ์กฐ์ง์€ ์ฆ‰์‹œ ํŽŒ์›จ์–ด์™€ ๋…ธ...

cyberupdates365.com/operation-

##

CVE-2010-3854
(0 None)

EPSS: 5.92%

updated 2026-06-16T23:23:40.850000

2 posts

Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

freddy@security.plumbing at 2026-08-19T20:16:47.000Z ##

@janl Oh no, I doxed myself. The reporter of CVE-2010-3854 wanted to stay anonymous, heh.

##

freddy@security.plumbing at 2026-08-19T20:16:47.000Z ##

@janl Oh no, I doxed myself. The reporter of CVE-2010-3854 wanted to stay anonymous, heh.

##

CVE-2008-5161
(3.7 LOW)

EPSS: 15.39%

updated 2026-06-16T22:59:22.107000

2 posts

Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux on IBM System z 6.0.4; Server for IBM z/OS 5.5.1 and earlier, 6.0.0, and 6.0.1; and Client 4.0-J through 4.3.3-J and 4.0-K through 4.3.10-K; and (2) OpenSSH 4.7p1 and possibly other

1 repos

https://github.com/talha3117/OpenSSH-4.7p1-CVE-2008-5161-Exploit

CVE-2026-0075
(5.9 MEDIUM)

EPSS: 0.09%

updated 2026-06-02T15:33:09

4 posts

In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

1 repos

https://github.com/QM4RS/CVE-2026-0075

DarkWebInformer at 2026-08-19T19:18:13.263Z ##

๐Ÿšจ Public PoC available for high-severity Android ContactsProvider flaw

github.com/qm4rs/cve-2026-0075

CVE-2026-0075 affects Android 14, 15, 16, and 16 QPR2 and can allow access to information from the contacts database through a SQL-related side channel without user interaction.

Researcher QM4RS has now released a controlled Android PoC that intentionally requests neither READ_CONTACTS nor WRITE_CONTACTS.

The issue involves ContactsProvider2 returning detailed SQLite errors to callers that lack contacts permission. Those errors could potentially be abused as an information side channel.

Google's fix strips sensitive JSON-related SQLite exception details from unauthorized callers.

The researcher cautions that the PoC is build-specific and does not demonstrate a universal exploitation path across every Android device.

Devices with the June 5, 2026 Android security patch level or later address the issue.

##

DailyCyberSecurity at 2026-08-19T13:27:49.349Z ##

A public PoC for CVE-2026-0075 shows an Android elevation of privilege in ContactsProvider2 that needs no user interaction.

securityonline.info/cve-2026-0

##

DarkWebInformer@infosec.exchange at 2026-08-19T19:18:13.000Z ##

๐Ÿšจ Public PoC available for high-severity Android ContactsProvider flaw

github.com/qm4rs/cve-2026-0075

CVE-2026-0075 affects Android 14, 15, 16, and 16 QPR2 and can allow access to information from the contacts database through a SQL-related side channel without user interaction.

Researcher QM4RS has now released a controlled Android PoC that intentionally requests neither READ_CONTACTS nor WRITE_CONTACTS.

The issue involves ContactsProvider2 returning detailed SQLite errors to callers that lack contacts permission. Those errors could potentially be abused as an information side channel.

Google's fix strips sensitive JSON-related SQLite exception details from unauthorized callers.

The researcher cautions that the PoC is build-specific and does not demonstrate a universal exploitation path across every Android device.

Devices with the June 5, 2026 Android security patch level or later address the issue.

##

DailyCyberSecurity@infosec.exchange at 2026-08-19T13:27:49.000Z ##

A public PoC for CVE-2026-0075 shows an Android elevation of privilege in ContactsProvider2 that needs no user interaction.

#CVE20260075 #Android #ElevationOfPrivilege #ContactsProvider #SQLInjection #AndroidSecurity

securityonline.info/cve-2026-0

##

CVE-2026-1947
(7.5 HIGH)

EPSS: 0.27%

updated 2026-03-16T15:30:54

2 posts

The NEX-Forms โ€“ Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 9.1.9 via the submit_nex_form() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to to overwrite arbitrary form entries via the 'nf_set_entry_update_id' parameter.

3 repos

https://github.com/HORKimhab/CVE-2026-19650-CVE-2026-19478

https://github.com/davkharrr/CVE-2026-19478-PoC

https://github.com/renzi25031469/CVE-2026-19478

hackmag at 2026-08-20T04:30:06.544Z ##

โšช๏ธ Critical GitLab Vulnerability Allowed Deletion of Public Projects

๐Ÿ—จ๏ธ GitLab developers have released emergency patches for Community Edition (CE) and Enterprise Edition (EE) that address the critical vulnerability CVE-2026-19478 (CVSS score: 9.4). Under certain conditions, the flaw allowed an unauthenticated attacker to remotely modify or delete public projects andโ€ฆ

๐Ÿ”— hackmag.com/news/cve-2026-1947

##

hackmag@infosec.exchange at 2026-08-20T04:30:06.000Z ##

โšช๏ธ Critical GitLab Vulnerability Allowed Deletion of Public Projects

๐Ÿ—จ๏ธ GitLab developers have released emergency patches for Community Edition (CE) and Enterprise Edition (EE) that address the critical vulnerability CVE-2026-19478 (CVSS score: 9.4). Under certain conditions, the flaw allowed an unauthenticated attacker to remotely modify or delete public projects andโ€ฆ

๐Ÿ”— hackmag.com/news/cve-2026-1947

#news

##

CVE-2026-3286
(6.3 MEDIUM)

EPSS: 0.31%

updated 2026-02-27T06:31:39

1 posts

A vulnerability was identified in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3. The impacted element is the function Save of the file paicoding-web/src/main/java/com/github/paicoding/forum/web/common/image/rest/ImageRestController.java of the component Image Save Endpoint. Such manipulation of the argument img leads to server-side request forgery. The attack may be launched remotely. The exploit is

offseq@infosec.exchange at 2026-08-18T01:30:24.000Z ##

SQL Injection flaw (CVE-2026-67854) in Qcms v6.0.6 rated CRITICAL: remote code execution risk. No official patch. Restrict access & monitor for injection attempts. Details: radar.offseq.com/threat/sql-in #OffSeq #SQLInjection #Vulnerability #Qcms #InfoSec

##

netsecio@mastodon.social at 2026-08-20T14:30:03.000Z ##

๐Ÿ“ฐ Over 14,500 Dahua Cameras Compromised in 'Operation CameraSwarm'

โ€œOperation CameraSwarmโ€ compromises 14,500+ Dahua cameras & NVRs using brute-force, auth bypass CVEs, and P2P abuse. Devices in Ukraine & Russia were primary targets. CISA KEVs CVE-2021-33044/33045 exploited. #IoT #Dahua #CyberAttack #Botnet

๐Ÿ”— cyber.netsecops.io/articles/op

##

sayzard@mastodon.sayzard.org at 2026-08-19T16:39:17.000Z ##

Operation CameraSwarm: 14,500 Dahua Cameras Compromised via P2P Relay Abuse

Hunt.io๊ฐ€ โ€˜Operation CameraSwarmโ€™ ์บ ํŽ˜์ธ์—์„œ Dahua ๊ฐ์‹œ ์นด๋ฉ”๋ผ 14,530๋Œ€ ์ด์ƒ์ด ํƒˆ์ทจ๋๋‹ค๊ณ  ๋ณด๊ณ ํ–ˆ๋‹ค. ๊ณต๊ฒฉ์ž๋Š” ๊ธฐ๋ณธยท์•ฝํ•œ ๋น„๋ฐ€๋ฒˆํ˜ธ ๋Œ€์ƒ ํฌ๋ฆฌ๋ด์…œ ๊ณต๊ฒฉ, CVSS 9.8์˜ ์ธ์ฆ ์šฐํšŒ ์ทจ์•ฝ์  CVE-2021-33044 ๋ฐ CVE-2021-33045, ๊ทธ๋ฆฌ๊ณ  Easy4IP ๊ณ„์—ด P2P ๋ฆด๋ ˆ์ด ์•…์šฉ์„ ๊ฒฐํ•ฉํ–ˆ๋‹ค. ํŠนํžˆ ์žฅ๋น„ ์ผ๋ จ๋ฒˆํ˜ธ๋ฅผ ์ด์šฉํ•œ P2P ํ„ฐ๋„์€ NAT ๋’ค์— ์žˆ๋Š” ์นด๋ฉ”๋ผ์—๋„ ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์–ด, ๋‹จ์ˆœํ•œ ๋„คํŠธ์›Œํฌ ๊ฒฝ๊ณ„ ๋ฐฉ์–ด๋งŒ์œผ๋กœ๋Š” ๋ถ€์กฑํ•˜๋‹ค๋Š” ์ ์ด ํ•ต์‹ฌ์ด๋‹ค. Dahua ์žฅ๋น„ ์šด์˜ ์กฐ์ง์€ ์ฆ‰์‹œ ํŽŒ์›จ์–ด์™€ ๋…ธ...

cyberupdates365.com/operation-

##

CVE-2026-59307
(0 None)

EPSS: 0.00%

2 posts

N/A

DailyCyberSecurity at 2026-08-20T17:17:17.379Z ##

Two critical Spring Integration vulnerabilities, CVE-2026-59307 and CVE-2026-59324, expose systems to remote code execution and data leakage. Update now.

securityonline.info/spring-int

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T17:17:17.000Z ##

Two critical Spring Integration vulnerabilities, CVE-2026-59307 and CVE-2026-59324, expose systems to remote code execution and data leakage. Update now.

#SpringIntegration #CyberSecurity #CVE202659307 #CVE202659324 #Vulnerability

securityonline.info/spring-int

##

CVE-2026-59324
(0 None)

EPSS: 0.00%

2 posts

N/A

DailyCyberSecurity at 2026-08-20T17:17:17.379Z ##

Two critical Spring Integration vulnerabilities, CVE-2026-59307 and CVE-2026-59324, expose systems to remote code execution and data leakage. Update now.

securityonline.info/spring-int

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T17:17:17.000Z ##

Two critical Spring Integration vulnerabilities, CVE-2026-59307 and CVE-2026-59324, expose systems to remote code execution and data leakage. Update now.

#SpringIntegration #CyberSecurity #CVE202659307 #CVE202659324 #Vulnerability

securityonline.info/spring-int

##

CVE-2026-63490
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-20T17:00:28.000Z ##

๐ŸŸ  CVE-2026-63490 - High (7.5)

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader without the...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-20T17:00:28.000Z ##

๐ŸŸ  CVE-2026-63490 - High (7.5)

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader without the...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54330
(0 None)

EPSS: 0.00%

2 posts

N/A

alina@girldick.gay at 2026-08-20T09:20:37.000Z ##

docs.ceph.com/en/latest/securi

github.com/ceph/ceph/commit/89

>RGW: This release contains a fix for CVE-2026-54330. We now reject Sigv4 requests with `host` and `x-amz-` headers not included in the signed subset. Unfortunately, the REST client used in multisite was generating such improperly signed requests.

can't make this shit up

> If you are running multisite, you must set the ``rgw_sigv4_insecure`` option to true before you begin to upgrade. After all clusters are upgraded, set the option to ``false`` again.

??! D:

they want me to backdoor the cluster in order to fix a security vuln in the cluster lmfao

##

alina@girldick.gay at 2026-08-20T09:20:37.000Z ##

docs.ceph.com/en/latest/securi

github.com/ceph/ceph/commit/89

>RGW: This release contains a fix for CVE-2026-54330. We now reject Sigv4 requests with `host` and `x-amz-` headers not included in the signed subset. Unfortunately, the REST client used in multisite was generating such improperly signed requests.

can't make this shit up

> If you are running multisite, you must set the ``rgw_sigv4_insecure`` option to true before you begin to upgrade. After all clusters are upgraded, set the option to ``false`` again.

??! D:

they want me to backdoor the cluster in order to fix a security vuln in the cluster lmfao

##

CVE-2026-63182
(0 None)

EPSS: 0.00%

1 posts

N/A

sayzard@mastodon.sayzard.org at 2026-08-20T02:43:34.000Z ##

Hacking SAML with Claude Code

Dex ๊ธฐ์—ฌ์ž๊ฐ€ Claude Opus ๊ธฐ๋ฐ˜ ๋ฉ€ํ‹ฐ์—์ด์ „ํŠธ ํ•˜๋„ค์Šค๋ฅผ ๋งŒ๋“ค์–ด SAML ๊ตฌํ˜„์ฒด๋ฅผ ๋Œ€๊ทœ๋ชจ๋กœ ์ ๊ฒ€ํ•œ ์‚ฌ๋ก€๋‹ค. ์œ„ํ˜‘ ๋ชจ๋ธ์„ ์ฃผ๊ณ  ํƒ์ƒ‰์‹œํ‚ค๋Š” ๋ฐฉ์‹์œผ๋กœ XML ์ฒ˜๋ฆฌ ์ฐจ์ด์™€ ์„œ๋ช… ๊ฒ€์ฆ ๋ถˆ์ผ์น˜๋ฅผ ์ฐพ์•˜์œผ๋ฉฐ, Authentik(CVE-2026-57580), litesaml/lightsaml(CVE-2026-63182), OneUptime, Java saml-client์—์„œ ์ธ์ฆ ์šฐํšŒ ๋˜๋Š” ์„œ๋ช… ๋ž˜ํ•‘ ๋ฌธ์ œ๋ฅผ ๋ณด๊ณ ํ–ˆ๋‹ค. ๋˜ํ•œ NodeยทPython SAML ์ƒํƒœ๊ณ„์—๋Š” ์ฒ˜๋ฆฌ ๋ณ€ํ™˜๊ณผ XML ํŒŒ์„œ ์กฐํ•ฉ์œผ๋กœ ๋ฐœ์ƒํ•˜๋Š” ๋ฏธ์ธ์ฆ OOM DoS ๋ฌธ์ œ๊ฐ€ ์•„์ง ๋‚จ์•„ ์žˆ๋‹ค๊ณ  ์ฃผ์žฅํ•œ๋‹ค. AI ์—์ด์ „ํŠธ๋ฅผ ์ทจ์•ฝ์  ํƒ์ƒ‰์— ์ ์šฉํ•  ๋•Œ๋Š” ๊ฐ€์ ฏ ํƒ์ƒ‰โ†’์ข…๋‹จ๊ฐ„ ์ต์Šคํ”Œ๋กœ์ž‡ ๊ฒ€์ฆ, JSONL ๊ธฐ๋ฐ˜...

oblique.security/blog/hacking-

##

CVE-2026-57580
(0 None)

EPSS: 0.44%

1 posts

N/A

sayzard@mastodon.sayzard.org at 2026-08-20T02:43:34.000Z ##

Hacking SAML with Claude Code

Dex ๊ธฐ์—ฌ์ž๊ฐ€ Claude Opus ๊ธฐ๋ฐ˜ ๋ฉ€ํ‹ฐ์—์ด์ „ํŠธ ํ•˜๋„ค์Šค๋ฅผ ๋งŒ๋“ค์–ด SAML ๊ตฌํ˜„์ฒด๋ฅผ ๋Œ€๊ทœ๋ชจ๋กœ ์ ๊ฒ€ํ•œ ์‚ฌ๋ก€๋‹ค. ์œ„ํ˜‘ ๋ชจ๋ธ์„ ์ฃผ๊ณ  ํƒ์ƒ‰์‹œํ‚ค๋Š” ๋ฐฉ์‹์œผ๋กœ XML ์ฒ˜๋ฆฌ ์ฐจ์ด์™€ ์„œ๋ช… ๊ฒ€์ฆ ๋ถˆ์ผ์น˜๋ฅผ ์ฐพ์•˜์œผ๋ฉฐ, Authentik(CVE-2026-57580), litesaml/lightsaml(CVE-2026-63182), OneUptime, Java saml-client์—์„œ ์ธ์ฆ ์šฐํšŒ ๋˜๋Š” ์„œ๋ช… ๋ž˜ํ•‘ ๋ฌธ์ œ๋ฅผ ๋ณด๊ณ ํ–ˆ๋‹ค. ๋˜ํ•œ NodeยทPython SAML ์ƒํƒœ๊ณ„์—๋Š” ์ฒ˜๋ฆฌ ๋ณ€ํ™˜๊ณผ XML ํŒŒ์„œ ์กฐํ•ฉ์œผ๋กœ ๋ฐœ์ƒํ•˜๋Š” ๋ฏธ์ธ์ฆ OOM DoS ๋ฌธ์ œ๊ฐ€ ์•„์ง ๋‚จ์•„ ์žˆ๋‹ค๊ณ  ์ฃผ์žฅํ•œ๋‹ค. AI ์—์ด์ „ํŠธ๋ฅผ ์ทจ์•ฝ์  ํƒ์ƒ‰์— ์ ์šฉํ•  ๋•Œ๋Š” ๊ฐ€์ ฏ ํƒ์ƒ‰โ†’์ข…๋‹จ๊ฐ„ ์ต์Šคํ”Œ๋กœ์ž‡ ๊ฒ€์ฆ, JSONL ๊ธฐ๋ฐ˜...

oblique.security/blog/hacking-

##

CVE-2026-68899
(0 None)

EPSS: 0.40%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-19T21:00:25.000Z ##

๐ŸŸ  CVE-2026-68899 - High (8.7)

Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation.js used the Unix file command for content-based MIME detection, but detectMimeFromFile() silently returned undefined when that binary was unavaila...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T21:00:25.000Z ##

๐ŸŸ  CVE-2026-68899 - High (8.7)

Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation.js used the Unix file command for content-based MIME detection, but detectMimeFromFile() silently returned undefined when that binary was unavaila...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68561
(0 None)

EPSS: 0.38%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-19T21:00:07.000Z ##

๐ŸŸ  CVE-2026-68561 - High (8.8)

Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) rule in server/permissions/boards.js called canUpdateBoardSort in server/lib/utils.js, which authorized any board member whenever fieldNames included...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T21:00:07.000Z ##

๐ŸŸ  CVE-2026-68561 - High (8.8)

Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) rule in server/permissions/boards.js called canUpdateBoardSort in server/lib/utils.js, which authorized any board member whenever fieldNames included...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50186
(0 None)

EPSS: 0.43%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-19T00:00:04.000Z ##

๐ŸŸ  CVE-2026-50186 - High (8.8)

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal sequences in the filename parameter of GET /exports/:id/:filename. In server/api/controllers/boards...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-19T00:00:04.000Z ##

๐ŸŸ  CVE-2026-50186 - High (8.8)

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal sequences in the filename parameter of GET /exports/:id/:filename. In server/api/controllers/boards...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-18T23:01:47.000Z ##

๐ŸŸ  CVE-2026-50142 - High (7.5)

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memory() with the msf1 sequence brand can cause unbounded heap allocation. In libheif/sequences/seq_bo...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-18T23:01:47.000Z ##

๐ŸŸ  CVE-2026-50142 - High (7.5)

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memory() with the msf1 sequence brand can cause unbounded heap allocation. In libheif/sequences/seq_bo...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52872
(0 None)

EPSS: 0.14%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-18T23:01:36.000Z ##

๐ŸŸ  CVE-2026-52872 - High (8.8)

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IPC channel, accepts a renderer-supplied subtitle ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-18T23:01:36.000Z ##

๐ŸŸ  CVE-2026-52872 - High (8.8)

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IPC channel, accepts a renderer-supplied subtitle ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52876
(0 None)

EPSS: 0.15%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-18T23:00:25.000Z ##

๐ŸŸ  CVE-2026-52876 - High (8.8)

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled filePath without validating its type or location...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-18T23:00:25.000Z ##

๐ŸŸ  CVE-2026-52876 - High (8.8)

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled filePath without validating its type or location...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75936
(0 None)

EPSS: 0.44%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-18T21:00:27.000Z ##

๐ŸŸ  CVE-2026-75936 - High (7.5)

Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large s...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75935
(0 None)

EPSS: 0.44%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-18T21:00:11.000Z ##

๐ŸŸ  CVE-2026-75935 - High (7.5)

Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted Ion binary document containing a declared-length field that causes excessive heap ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-53906
(0 None)

EPSS: 0.73%

1 posts

N/A

normalmode@mastodon.social at 2026-08-18T17:22:18.000Z ##

@hugovalters Iโ€™m curious. What does โ€œunpatchedโ€ mean in this context? I had presumed it meant the vulnerability hasnโ€™t been fixed yet, but this doesnโ€™t seem to be the case. e.g. this page lists the CVE as โ€œunpatchedโ€ but also says what version of Vim it was fixed in: valtersit.com/cve/CVE-2025-539

##

CVE-2026-75914
(0 None)

EPSS: 0.41%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-18T17:00:49.000Z ##

๐ŸŸ  CVE-2026-75914 - High (7.5)

CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace symlinks pointing to external files with image extensions to...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75911
(0 None)

EPSS: 0.17%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-18T17:00:28.000Z ##

๐ŸŸ  CVE-2026-75911 - High (7.8)

CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committing a malicious .codewhale/config.toml file to a...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites