## Updated at UTC 2026-08-30T00:59:09.993154

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-82475 8.1 0.00% 2 0 2026-08-29T17:18:00.057000 iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerabilit
CVE-2026-82456 10.0 0.00% 2 0 2026-08-29T15:30:27 argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts
CVE-2026-82454 9.1 0.00% 2 0 2026-08-29T15:30:27 The Omnivore API (packages/api) before the fix in commit abf53d6 contains an aut
CVE-2026-82448 9.8 0.00% 2 0 2026-08-29T15:30:20 Shinobi before commit 5a76c74f contains a hardcoded connection key in the child
CVE-2026-82457 7.8 0.00% 2 0 2026-08-29T14:16:38.910000 su-exec through 0.3 fails to validate numeric user and group identifiers parsed
CVE-2026-82453 7.5 0.00% 2 0 2026-08-29T14:16:38.347000 rust-iot-platform through commit 5df942ab stores user passwords in cleartext wit
CVE-2026-82452 9.8 0.00% 2 0 2026-08-29T14:16:38.210000 rust-iot-platform through commit 5df942ab contains an authentication bypass vuln
CVE-2026-82450 8.8 0.00% 2 0 2026-08-29T14:16:37.930000 BookStack before 26.05.4 contains a remote code execution vulnerability in the p
CVE-2026-82251 7.5 0.39% 2 0 2026-08-29T14:16:37.677000 gitoxide before 0.52.1 fails to validate submodule names from .gitmodules config
CVE-2026-82447 8.8 0.00% 2 0 2026-08-29T13:16:38.643000 Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock
CVE-2026-14494 9.8 0.00% 2 0 2026-08-29T12:16:41.163000 The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution
CVE-2026-81578 0 0.39% 3 2 2026-08-29T04:18:08 An improper access control vulnerability exists in the web management interface
CVE-2026-74820 0 0.25% 4 0 2026-08-29T04:18:06.417000 ServiceNow has remediated a SQL injection vulnerability that was identified in i
CVE-2026-72984 8.8 0.44% 2 0 2026-08-29T04:18:06.270000 Access of resource using incompatible type ('type confusion') in Microsoft Edge
CVE-2026-19313 0 0.47% 2 0 2026-08-29T04:18:04.957000 An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows
CVE-2026-18886 0 0.25% 4 0 2026-08-29T04:18:04.793000 ServiceNow has remediated an improper access control vulnerability that was iden
CVE-2026-41012 7.7 0.10% 2 0 2026-08-29T03:31:04 Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers
CVE-2026-81533 7.1 0.21% 2 0 2026-08-29T00:31:12 An application using the MongoDB BI Connector ODBC Driver may encounter a memory
CVE-2026-81490 7.7 0.24% 3 0 2026-08-29T00:31:12 A database user able to create a view in a namespace that MongoDB Connector for
CVE-2026-81532 8.8 0.28% 2 0 2026-08-29T00:31:12 A user able to submit SQL through an application using the MongoDB Connector for
CVE-2026-81518 7.5 0.15% 2 0 2026-08-29T00:31:12 When mongosqld is configured with a client certificate authority file, the liste
CVE-2026-81520 7.5 0.24% 3 0 2026-08-29T00:31:04 A network-reachable client that has not yet authenticated can hold a MongoDB Con
CVE-2026-19295 9.9 0.98% 2 1 2026-08-29T00:31:03 IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execut
CVE-2026-18891 8.2 0.29% 2 0 2026-08-29T00:31:02 IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute a
CVE-2026-18729 8.8 0.46% 2 1 2026-08-29T00:31:02 IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacke
CVE-2026-19286 9.8 0.61% 2 1 2026-08-29T00:31:02 IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute a
CVE-2026-18899 7.5 0.46% 2 0 2026-08-29T00:31:02 IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbi
CVE-2026-17203 7.5 0.43% 2 0 2026-08-29T00:31:01 IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated
CVE-2026-73108 7.5 0.53% 1 0 2026-08-29T00:30:57 RustDesk versions before 1.4.7 contain an uncontrolled speculative memory alloca
CVE-2026-55784 7.5 0.25% 3 0 2026-08-28T23:17:07.517000 free5GC is an open-source implementation of the 5G core network. In version 1.4.
CVE-2026-55848 8.6 0.33% 2 0 2026-08-28T22:33:36 ### Summary XXE on MapFish Print allows reading arbitrary files of certain types
CVE-2026-82284 8.1 0.24% 2 0 2026-08-28T22:16:56.650000 Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/
CVE-2026-82278 8.8 0.56% 2 0 2026-08-28T22:16:56.293000 BISHENG before 2.6.0 contains a remote code execution vulnerability in the workf
CVE-2026-82017 7.6 0.15% 2 0 2026-08-28T22:16:55.067000 IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry
CVE-2026-81517 7.5 0.26% 2 0 2026-08-28T22:16:54.383000 An unauthenticated party able to reach the port of a MongoDB Connector for BI (m
CVE-2026-55634 9.9 0.45% 1 0 2026-08-28T22:16:51.290000 Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.1
CVE-2026-3627 9.1 0.51% 3 0 2026-08-28T22:16:49.063000 IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacke
CVE-2026-18904 8.2 0.31% 2 0 2026-08-28T22:16:47.227000 IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain se
CVE-2026-18527 9.9 0.29% 2 0 2026-08-28T22:16:46.620000 IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (AR
CVE-2026-55841 7.5 0.36% 3 0 2026-08-28T22:13:01 ### Impact A security issue has been identified in Graylog affecting the parsin
CVE-2026-18885 None 0.43% 6 0 2026-08-28T21:32:13 ServiceNow has remediated a code injection vulnerability that was identified inย 
CVE-2026-82282 8.0 0.26% 2 0 2026-08-28T21:31:36 Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, al
CVE-2026-82291 8.1 0.30% 2 0 2026-08-28T21:31:36 HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses w
CVE-2026-82329 9.8 0.38% 2 0 2026-08-28T21:31:36 JFrog Artifactory contains an authentication weakness that, under default config
CVE-2026-82275 7.5 0.37% 2 0 2026-08-28T21:31:29 Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the documen
CVE-2026-82279 8.1 0.27% 2 0 2026-08-28T21:31:29 HyperDX through 1.10.1 fails to enforce role-based access controls in team manag
CVE-2026-82288 7.5 0.32% 2 0 2026-08-28T21:31:28 Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerabi
CVE-2026-82286 8.6 0.35% 2 1 2026-08-28T21:31:28 gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the
CVE-2026-82283 8.1 0.24% 2 0 2026-08-28T21:31:27 VoltAgent through 2.1.20 fails to validate conversation ownership in memory API
CVE-2026-82277 9.8 0.43% 2 0 2026-08-28T21:31:26 Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutat
CVE-2026-82270 7.5 0.28% 2 0 2026-08-28T21:31:25 Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnera
CVE-2026-82269 8.1 0.30% 2 0 2026-08-28T21:31:25 Gophish through 0.12.1 fails to enforce account lockout and password change requ
CVE-2026-82268 7.5 0.28% 2 0 2026-08-28T21:31:25 Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability i
CVE-2026-75124 7.5 0.48% 2 0 2026-08-28T21:31:24 PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication
CVE-2026-75486 8.0 1.25% 2 0 2026-08-28T21:31:24 Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that a
CVE-2026-82266 9.8 0.34% 2 0 2026-08-28T21:31:23 Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_requi
CVE-2026-56100 8.1 0.29% 2 0 2026-08-28T21:31:17 SpringBlade versions 2.7.3 through 3.5.0 contain a privilege escalation vulnerab
CVE-2026-77586 8.0 0.23% 2 0 2026-08-28T21:16:15.740000 In MongoDB Connector for BI, MongoDB object names such as collection, field, and
CVE-2026-81525 8.1 0.27% 4 0 2026-08-28T21:16:15.740000 The MongoDB client library for PHP does not sufficiently sanitize special elemen
CVE-2026-82287 8.1 0.28% 2 0 2026-08-28T20:20:20.243000 Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows a
CVE-2026-82285 8.2 0.31% 2 0 2026-08-28T20:20:19.953000 bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability
CVE-2026-82021 8.3 0.23% 2 0 2026-08-28T20:20:14.470000 Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its
CVE-2026-81767 7.5 0.20% 2 0 2026-08-28T20:20:13.023000 Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
CVE-2026-81699 7.5 0.35% 1 0 2026-08-28T20:20:11.923000 openssl_encrypt versions before 1.4.9 fail to properly validate key derivation f
CVE-2026-81019 7.4 0.24% 1 0 2026-08-28T20:20:08.670000 wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when
CVE-2026-77438 7.5 0.24% 2 0 2026-08-28T20:19:55.927000 Trilium is an open-source hierarchical note-taking application. In versions up t
CVE-2026-76640 7.5 0.35% 6 1 2026-08-28T20:19:54.877000 Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities
CVE-2026-76060 8.8 2.31% 1 1 2026-08-28T20:19:54.620000 An authenticated OS command injection vulnerability exists in ZoneMinder's event
CVE-2026-66155 7.6 0.17% 1 0 2026-08-28T19:03:37.837000 A vulnerability has been identified in Element maps-ng V47 (All versions < V47.1
CVE-2026-76784 0 0.15% 1 0 2026-08-28T19:02:53.760000 Multiple TP-Link Kasa smart home devices contain insufficient cryptographic prot
CVE-2026-75112 0 0.11% 2 0 2026-08-28T18:58:27.140000 A security issue exists within OTTOยฎ Fleet Manager. The vulnerability stems from
CVE-2026-81728 8.1 0.26% 2 0 2026-08-28T18:56:49.340000 Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizar
CVE-2026-82261 7.5 0.34% 2 0 2026-08-28T18:56:34.447000 SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remot
CVE-2026-81701 9.8 0.31% 3 0 2026-08-28T18:56:34.447000 openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-i
CVE-2026-81681 4.6 0.13% 3 0 2026-08-28T18:56:34.447000 openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a port
CVE-2026-81680 4.0 0.15% 1 0 2026-08-28T18:56:34.447000 openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presenc
CVE-2026-81706 6.8 0.13% 1 0 2026-08-28T18:56:34.447000 openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own i
CVE-2026-81717 3.5 0.09% 1 0 2026-08-28T18:56:34.447000 openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weakness
CVE-2026-81695 3.3 0.18% 1 0 2026-08-28T18:56:34.447000 openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id
CVE-2026-81705 7.5 0.33% 1 0 2026-08-28T18:56:34.447000 openssl-encrypt before 1.4.9 fails to redact the file password in its --debug ar
CVE-2026-82254 7.5 0.35% 2 0 2026-08-28T18:54:09.323000 gitoxide before 0.69.0 contains unchecked array indexing in delta application an
CVE-2026-47879 7.7 0.24% 1 0 2026-08-28T18:47:30.163000 Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Reso
CVE-2026-47851 7.5 0.26% 1 1 2026-08-28T18:47:30.163000 Analyzing a PDF with a deeply nested or cyclic table of contents can cause a Sta
CVE-2026-82082 9.8 1.50% 2 0 2026-08-28T18:46:13.563000 NUMail developed by Green-Computing has an OS Command Injection vulnerability. U
CVE-2026-82078 None 0.46% 3 2 2026-08-28T18:31:39 An unsafe dynamic class loading vulnerability exists in the database connection
CVE-2026-82227 8.5 0.23% 2 0 2026-08-28T18:31:39 Contributor SQL Injection in WPBulky <= 1.2.2 versions.
CVE-2026-81285 7.5 0.26% 2 0 2026-08-28T18:31:34 Unauthenticated Denial of Service Attack in Smush Image Compression and Optimiza
CVE-2026-78239 9.8 0.55% 4 0 2026-08-28T16:18:27.560000 Xiiaozet LK100W exposes a critical management function that can be invoked with
CVE-2026-75813 7.5 0.26% 2 0 2026-08-28T16:18:25.510000 Certain configuration endpoints may lack proper server-side authorization check
CVE-2026-81277 8.5 0.34% 1 0 2026-08-28T15:09:00.790000 Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 version
CVE-2026-82252 7.5 0.39% 2 0 2026-08-28T12:30:36 gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules fi
CVE-2026-82222 10.0 0.42% 2 0 2026-08-28T12:30:36 Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP
CVE-2026-82253 7.5 0.50% 3 0 2026-08-28T12:30:36 gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path
CVE-2026-82234 8.2 0.32% 1 0 2026-08-28T12:30:36 SiYuan versions before v3.8.1 contain a server-side request forgery vulnerabilit
CVE-2026-82260 7.5 0.34% 3 0 2026-08-28T12:30:36 SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remot
CVE-2026-82259 7.5 0.37% 2 0 2026-08-28T12:30:30 SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deseri
CVE-2026-82247 7.5 0.30% 2 0 2026-08-28T12:30:28 gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL par
CVE-2026-66384 5.3 0.58% 6 1 2026-08-28T12:21:47.053000 An authenticated user may write data outside the intended Docker cache path unde
CVE-2023-49105 9.8 43.20% 10 1 template 2026-08-28T12:21:09.753000 An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker ca
CVE-2026-82123 6.5 0.18% 2 0 2026-08-28T09:32:01 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2026-76581 9.8 0.34% 1 0 2026-08-28T09:31:57 The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypa
CVE-2026-77365 7.2 0.31% 1 0 2026-08-28T06:31:05 The Optimole โ€“ Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image O
CVE-2026-18983 7.5 0.50% 2 0 2026-08-28T06:31:05 The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to
CVE-2026-38822 7.6 0.85% 2 0 2026-08-28T03:31:24 In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS da
CVE-2026-38820 8.3 1.74% 2 0 2026-08-28T03:31:23 openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via
CVE-2026-73809 7.5 0.17% 1 0 2026-08-28T00:32:11 A cleartext transmission of sensitive information vulnerability exists in certa
CVE-2026-77977 8.1 0.23% 2 0 2026-08-28T00:32:11 Ebyte gateway product's vendor configuration utility does not require authentica
CVE-2026-76945 7.5 0.36% 2 0 2026-08-28T00:32:11 The affected Ebyte device relies on client-managed authentication tokens withou
CVE-2026-76943 9.8 0.67% 2 0 2026-08-28T00:32:11 Xiiaozet LK100Wt contains an authentication weakness within an administrative s
CVE-2026-78037 8.8 1.22% 2 0 2026-08-28T00:32:11 Xiiaozet LK100W is vulnerable to OS command injection through its web-based man
CVE-2026-73125 9.8 0.53% 4 0 2026-08-28T00:32:04 Ebyte device web management interface does not consistently enforce authenticat
CVE-2026-76940 7.5 0.36% 2 0 2026-08-28T00:32:04 The affected Ebyte device does not restrict repeated authentication attempts th
CVE-2026-71362 9.1 25.14% 2 1 template 2026-08-28T00:18:09.390000 Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul
CVE-2026-79619 None 0.14% 1 0 2026-08-27T21:32:29 On Linux, several OpenZFS ioctl authorization checks accept a capability held on
CVE-2026-81934 9.8 0.58% 2 0 2026-08-27T21:32:02 Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' f
CVE-2026-81730 8.2 0.38% 2 0 2026-08-27T21:31:54 Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name sup
CVE-2026-53362 7.8 0.51% 11 1 2026-08-27T21:31:19 In the Linux kernel, the following vulnerability has been resolved: ipv6: accou
CVE-2026-76639 8.8 0.71% 9 1 2026-08-27T20:18:38.230000 Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code ex
CVE-2026-81702 9.8 0.14% 3 0 2026-08-27T18:32:38 openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when l
CVE-2026-81700 9.8 0.25% 3 0 2026-08-27T18:32:38 openssl_encrypt versions before 1.4.9 contain a signature verification vulnerabi
CVE-2026-81698 7.5 0.28% 2 0 2026-08-27T18:32:38 openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in
CVE-2026-81714 7.0 0.14% 1 0 2026-08-27T18:32:38 openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fin
CVE-2026-81707 9.8 0.41% 2 0 2026-08-27T18:32:38 openssl_encrypt before 1.4.9 fails to sanitize the email field of imported ident
CVE-2026-81696 3.3 0.18% 1 0 2026-08-27T18:32:37 openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characte
CVE-2026-81694 3.3 0.18% 1 0 2026-08-27T18:32:37 openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames rea
CVE-2026-81685 3.3 0.18% 1 0 2026-08-27T18:32:37 openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in
CVE-2026-81722 7.5 0.34% 1 0 2026-08-27T18:32:31 nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficie
CVE-2026-81721 7.5 0.39% 1 0 2026-08-27T18:32:31 openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted
CVE-2026-81719 7.8 0.32% 2 0 2026-08-27T18:32:30 openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insuffi
CVE-2026-81094 9.1 0.42% 1 0 2026-08-27T18:32:30 The mcp-router CLI served its MCP aggregator on every interface and enforced aut
CVE-2026-81718 7.5 0.13% 1 0 2026-08-27T18:32:30 openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256
CVE-2026-78251 None 0.39% 1 0 2026-08-27T18:32:25 DJI drones contain an FTP service that uses hardcoded credentials shared across
CVE-2026-47877 8.2 0.19% 1 0 2026-08-27T18:32:09 Spring Security Authorization Server's default consent page renders user-control
CVE-2026-47852 7.5 0.20% 1 0 2026-08-27T18:32:07 A local attacker on a multi-user host can pre-create the deterministic cache pat
CVE-2026-81735 10.0 0.53% 1 0 2026-08-27T17:21:03.677000 startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its l
CVE-2026-81576 7.7 0.33% 1 0 2026-08-27T17:20:55.230000 If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issu
CVE-2026-74232 9.8 0.47% 7 0 2026-08-27T17:19:51.953000 Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink
CVE-2026-61617 7.7 0.25% 1 0 2026-08-27T17:19:02.473000 Wings is the server control plane for the Pterodactyl game-server management pan
CVE-2026-47666 7.6 0.20% 1 0 2026-08-27T17:18:27.247000 Penpot is an open-source design and prototyping platform. In versions up to and
CVE-2026-18431 9.8 0.64% 2 1 2026-08-27T17:17:29.533000 The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versi
CVE-2026-15990 7.5 0.69% 1 0 2026-08-27T17:17:14.017000 The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal
CVE-2026-74233 9.8 2.63% 7 0 2026-08-27T15:31:35 Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, an
CVE-2026-80557 9.8 0.52% 1 0 2026-08-27T15:31:33 In the Linux kernel, the following vulnerability has been resolved: libceph: fi
CVE-2026-65182 9.1 0.59% 1 0 2026-08-27T15:27:26.040000 Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat
CVE-2026-81625 8.8 0.53% 1 0 2026-08-27T13:18:41.920000 A remote attacker with user privileges may use a malicious or compromised NASL v
CVE-2026-80587 9.8 0.39% 2 0 2026-08-27T13:18:41.093000 In the Linux kernel, the following vulnerability has been resolved: mptcp: avoi
CVE-2026-80551 9.3 0.14% 1 0 2026-08-27T13:18:39.733000 In the Linux kernel, the following vulnerability has been resolved: s390/vfio_c
CVE-2026-41992 7.5 0.37% 5 0 2026-08-27T13:17:57.967000 GNU gzip contains a global buffer overflow vulnerability in the LZH decompressio
CVE-2026-78276 7.2 0.50% 1 0 2026-08-27T12:30:34 Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
CVE-2026-78285 8.5 0.34% 1 0 2026-08-27T12:30:34 Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
CVE-2026-78286 9.8 0.53% 1 0 2026-08-27T12:30:33 Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
CVE-2026-81573 8.6 0.46% 1 0 2026-08-27T12:30:27 If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configu
CVE-2026-81572 7.8 0.17% 1 0 2026-08-27T12:30:27 cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-S
CVE-2026-81273 8.1 0.17% 1 0 2026-08-27T12:30:27 Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4
CVE-2026-81581 8.8 0.20% 1 0 2026-08-27T12:30:27 Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70
CVE-2026-81579 8.8 0.16% 1 0 2026-08-27T12:30:27 In WibuKey for Windows before version 6.71, an untrusted pointer dereference in
CVE-2026-81574 8.2 0.41% 1 0 2026-08-27T12:30:27 In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitiz
CVE-2026-81575 7.5 0.44% 1 0 2026-08-27T12:30:26 If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 acce
CVE-2026-60004 9.8 84.55% 7 9 template 2026-08-27T11:41:19.230000 Gitea before 1.27.1 allows remote code execution via the diffpatch API through G
CVE-2026-59270 9.4 0.29% 2 0 2026-08-27T06:31:43 Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditio
CVE-2026-80585 9.4 0.32% 1 0 2026-08-27T06:31:38 In the Linux kernel, the following vulnerability has been resolved: mptcp: fast
CVE-2026-80528 9.8 0.52% 1 0 2026-08-27T06:31:38 In the Linux kernel, the following vulnerability has been resolved: ceph: avoid
CVE-2026-80519 9.8 0.45% 1 0 2026-08-27T06:31:38 In the Linux kernel, the following vulnerability has been resolved: ovpn: finis
CVE-2026-80554 9.3 0.14% 1 0 2026-08-27T06:31:38 In the Linux kernel, the following vulnerability has been resolved: s390/vfio_c
CVE-2026-80589 9.8 0.38% 2 0 2026-08-27T06:31:38 In the Linux kernel, the following vulnerability has been resolved: block: stop
CVE-2026-74737 9.8 0.56% 1 0 2026-08-27T06:31:37 In the Linux kernel, the following vulnerability has been resolved: net: ethern
CVE-2026-74744 9.8 0.52% 1 0 2026-08-27T06:31:37 In the Linux kernel, the following vulnerability has been resolved: ipvlan: inh
CVE-2026-80558 9.8 0.52% 1 0 2026-08-27T06:31:33 In the Linux kernel, the following vulnerability has been resolved: libceph: Av
CVE-2026-74752 9.8 0.43% 1 0 2026-08-27T06:31:31 In the Linux kernel, the following vulnerability has been resolved: sctp: valid
CVE-2026-74751 9.4 0.34% 1 0 2026-08-27T06:31:31 In the Linux kernel, the following vulnerability has been resolved: riscv: lib:
CVE-2026-80588 7.5 0.34% 1 0 2026-08-27T06:17:46.353000 In the Linux kernel, the following vulnerability has been resolved: mptcp: recl
CVE-2026-80586 9.8 0.40% 1 0 2026-08-27T06:17:45.700000 In the Linux kernel, the following vulnerability has been resolved: mptcp: opti
CVE-2026-80561 9.8 0.52% 1 0 2026-08-27T06:17:41.057000 In the Linux kernel, the following vulnerability has been resolved: libceph: fi
CVE-2026-74746 9.8 0.54% 1 0 2026-08-27T06:17:25.033000 In the Linux kernel, the following vulnerability has been resolved: netfilter:
CVE-2026-74743 9.8 0.52% 1 0 2026-08-27T06:17:24.113000 In the Linux kernel, the following vulnerability has been resolved: macvlan: in
CVE-2026-65641 None 0.54% 1 0 2026-08-27T00:30:36 A vulnerability allowing an unauthenticated network attacker to coerce SMB authe
CVE-2026-70419 9.1 2.19% 1 0 2026-08-26T21:31:47 Dell Cloud Disaster Recovery, versions 20.2 and prior,ย containย an Improper Neutr
CVE-2026-75960 8.1 0.35% 3 0 2026-08-26T18:32:04 Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently
CVE-2026-19271 7.5 0.30% 1 0 2026-08-26T18:32:04 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injecti
CVE-2015-5287 7.8 4.96% 1 1 2026-08-26T18:31:30 The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.
CVE-2026-8452 9.8 1.61% 8 3 2026-08-26T18:30:34 Memory overflow vulnerabilityย NetScaler ADC and NetScaler Gatewayย leading to unp
CVE-2022-0995 7.1 9.52% 3 4 2026-08-26T18:30:28 An out-of-bounds (OOB) memory write flaw was found in the Linux kernelโ€™s watch_q
CVE-2015-3246 5.1 8.80% 1 1 2026-08-26T18:30:27 libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper progr
CVE-2026-54569 9.8 0.78% 1 0 2026-08-26T15:28:48 ### Summary An unauthenticated remote code execution vulnerability in the SENAI
CVE-2026-19042 8.8 2.00% 1 0 2026-08-26T14:17:08.270000 A command injection vulnerability in TeamViewer Full Client and Host for Linux p
CVE-2026-19913 None 0.36% 1 1 2026-08-25T18:32:01 The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure v
CVE-2026-19912 None 0.22% 1 1 2026-08-25T18:32:01 The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote
CVE-2026-74684 7.1 0.14% 1 0 2026-08-25T06:18:51.253000 In the Linux kernel, the following vulnerability has been resolved: net: tap: s
CVE-2026-64531 7.8 0.38% 1 4 2026-08-22T04:17:58.720000 In the Linux kernel, the following vulnerability has been resolved: net: openvs
CVE-2026-73570 8.9 20.53% 1 6 template 2026-08-21T18:34:48 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor
CVE-2026-77806 9.8 4.20% 1 1 template 2026-08-21T18:16:52.373000 SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary
CVE-2026-19598 9.8 2.79% 1 4 template 2026-08-20T12:48:10.287000 The Pods โ€“ Custom Content Types and Fields plugin for WordPress is vulnerable to
CVE-2026-53361 7.1 0.13% 1 1 2026-08-19T18:31:59 In the Linux kernel, the following vulnerability has been resolved: af_unix: Se
CVE-2026-65400 9.8 9.90% 3 3 2026-08-19T04:17:34.547000 An authentication issue was addressed with improved state management. This issue
CVE-2026-19478 9.4 6.00% 1 7 template 2026-08-17T21:31:30 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2
CVE-2026-72137 9.8 0.62% 3 0 2026-08-17T06:34:17 In the Linux kernel, the following vulnerability has been resolved: xfrm: nat_k
CVE-2026-61979 8.1 0.28% 1 0 2026-08-13T15:34:46 Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions
CVE-2026-63077 9.8 87.71% 2 4 template 2026-08-06T05:17:05.170000 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-15981 9.8 0.81% 1 1 2026-07-24T23:16:50.257000 The SAML Single Sign On โ€“ SSO Login plugin for WordPress is vulnerable to Authen
CVE-2026-45657 9.8 15.48% 1 0 2026-07-23T08:10:00.137000 Use after free in Windows Kernel allows an unauthorized attacker to execute code
CVE-2026-47291 9.8 22.75% 1 1 2026-07-23T08:10:00.137000 Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attack
CVE-2018-18472 9.8 25.63% 2 0 2026-06-17T01:47:21.423000 Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a ro
CVE-2021-23758 9.8 83.63% 1 1 2026-02-03T17:39:26 ### Overview Affected versions of this package are vulnerable to Deserializatio
CVE-2025-39367 5.3 0.27% 1 0 2025-04-28T09:32:00 Missing Authorization vulnerability in SeventhQueen Kleo.This issue affects Kleo
CVE-2021-35941 7.5 12.71% 2 0 2023-01-27T05:02:51 Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all ver
CVE-2026-81849 0 0.57% 2 0 N/A
CVE-2026-65643 0 0.00% 6 1 N/A
CVE-2026-77078 0 0.29% 2 0 N/A
CVE-2026-77037 0 0.35% 2 0 N/A
CVE-2026-82333 0 0.28% 2 0 N/A
CVE-2026-75604 0 0.00% 3 3 N/A
CVE-2026-61800 0 0.59% 2 0 N/A
CVE-2026-81529 0 0.17% 1 0 N/A
CVE-2026-81522 0 0.27% 2 0 N/A
CVE-2026-68503 0 0.40% 1 0 N/A
CVE-2026-47665 0 0.25% 1 0 N/A

CVE-2026-82475
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-29T17:18:00.057000

2 posts

iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions.

thehackerwire@mastodon.social at 2026-08-29T17:59:52.000Z ##

๐ŸŸ  CVE-2026-82475 - High (8.1)

iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T17:59:52.000Z ##

๐ŸŸ  CVE-2026-82475 - High (8.1)

iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82456
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-08-29T15:30:27

2 posts

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.

thehackerwire@mastodon.social at 2026-08-29T15:01:42.000Z ##

๐Ÿ”ด CVE-2026-82456 - Critical (10)

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T15:01:42.000Z ##

๐Ÿ”ด CVE-2026-82456 - Critical (10)

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82454
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-08-29T15:30:27

2 posts

The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as the sole allowed algorithm to jwt.verify(). Using jsonwebtoken v8 (which does not validate key/algorithm compatibility), an attacker can set alg=HS256 an

thehackerwire@mastodon.social at 2026-08-29T15:01:06.000Z ##

๐Ÿ”ด CVE-2026-82454 - Critical (9.1)

The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T15:01:06.000Z ##

๐Ÿ”ด CVE-2026-82454 - Critical (9.1)

The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82448
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-29T15:30:20

2 posts

Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during WebSocket handshake, then dispatch SQL queries through the onWebSocketDataFromChildNode handler to read and modify user records and camera configuration.

thehackerwire@mastodon.social at 2026-08-29T14:00:17.000Z ##

๐Ÿ”ด CVE-2026-82448 - Critical (9.8)

Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during W...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T14:00:17.000Z ##

๐Ÿ”ด CVE-2026-82448 - Critical (9.8)

Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during W...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82457
(7.8 HIGH)

EPSS: 0.00%

updated 2026-08-29T14:16:38.910000

2 posts

su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that truncate to root's identifier, causing su-exec to execute target programs with root privileges instead of intended unprivileged accounts.

thehackerwire@mastodon.social at 2026-08-29T15:01:52.000Z ##

๐ŸŸ  CVE-2026-82457 - High (7.8)

su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that truncate to ro...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T15:01:52.000Z ##

๐ŸŸ  CVE-2026-82457 - High (7.8)

su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that truncate to ro...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82453
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-29T14:16:38.347000

2 posts

rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts.

thehackerwire@mastodon.social at 2026-08-29T15:00:55.000Z ##

๐ŸŸ  CVE-2026-82453 - High (7.5)

rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T15:00:55.000Z ##

๐ŸŸ  CVE-2026-82453 - High (7.5)

rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82452
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-29T14:16:38.210000

2 posts

rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete user accounts by directly accessing unprotected endpoints without providing valid credentials.

thehackerwire@mastodon.social at 2026-08-29T15:00:45.000Z ##

๐Ÿ”ด CVE-2026-82452 - Critical (9.8)

rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete u...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T15:00:45.000Z ##

๐Ÿ”ด CVE-2026-82452 - Critical (9.8)

rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete u...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82450
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-29T14:16:37.930000

2 posts

BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by embedding a PHP file with a .php filename in the ZIP archive, which is stored in the public web root and executed by unaut

thehackerwire@mastodon.social at 2026-08-29T15:02:02.000Z ##

๐ŸŸ  CVE-2026-82450 - High (8.8)

BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T15:02:02.000Z ##

๐ŸŸ  CVE-2026-82450 - High (8.8)

BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82251
(7.5 HIGH)

EPSS: 0.39%

updated 2026-08-29T14:16:37.677000

2 posts

gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to redirect state() and open() functions to repositories outside .git/modules, causing repository confusion and inspection of attacker-controlled repositories.

thehackerwire@mastodon.social at 2026-08-28T15:00:12.000Z ##

๐ŸŸ  CVE-2026-82251 - High (7.5)

gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to redirect state() and...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T15:00:12.000Z ##

๐ŸŸ  CVE-2026-82251 - High (7.5)

gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to redirect state() and...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82447
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-29T13:16:38.643000

2 posts

Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment. Attackers can inject malicious Jinja template syntax through workflow parameters or upstream block output to execute arbitrary code with server process privileges.

thehackerwire@mastodon.social at 2026-08-29T14:00:06.000Z ##

๐ŸŸ  CVE-2026-82447 - High (8.8)

Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment. Attackers can inject malicious Jinja template syn...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T14:00:06.000Z ##

๐ŸŸ  CVE-2026-82447 - High (8.8)

Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment. Attackers can inject malicious Jinja template syn...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14494
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-29T12:16:41.163000

2 posts

The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capability to all users during form submissions and bypassing MIME type validation when allowed_file_types is not configured. This makes it possible for unauthenticat

thehackerwire@mastodon.social at 2026-08-29T13:00:13.000Z ##

๐Ÿ”ด CVE-2026-14494 - Critical (9.8)

The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capability to...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T13:00:13.000Z ##

๐Ÿ”ด CVE-2026-14494 - Critical (9.8)

The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capability to...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81578
(0 None)

EPSS: 0.39%

updated 2026-08-29T04:18:08

3 posts

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specificย conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

2 repos

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

https://github.com/virologi-info/papercut-toolkit

netsecio@mastodon.social at 2026-08-29T13:37:54.000Z ##

๐Ÿ“ฐ PaperCut Zero-Day RCE Actively Exploited; Emergency Patches Released

๐Ÿšจ URGENT: PaperCut warns of an actively exploited zero-day RCE vulnerability chain affecting all NG/MF versions. The pre-auth flaws (CVE-2026-81578, CVE-2026-82078) allow full server takeover. Patch immediately! #Cybersecurity #ZeroDay #PaperCut

๐Ÿ”— cyber.netsecops.io/articles/pa

##

guru@thecybersecguru.com at 2026-08-29T05:26:50.000Z ##

PaperCut Under Active Attack: Full Technical Analysis of the Pre-Auth RCE Chain (CVE-2026-81578 + CVE-2026-82078)

Active exploitation of PaperCut NG/MF pre-auth RCE (CVE-2026-81578, CVE-2026-82078). Full chain analysis, IOCs, detection & emergency patch guidance

thecybersecguru.com/news/paper

##

guru@thecybersecguru.com at 2026-08-29T05:26:50.000Z ##

PaperCut Under Active Attack: Full Technical Analysis of the Pre-Auth RCE Chain (CVE-2026-81578 + CVE-2026-82078)

Active exploitation of PaperCut NG/MF pre-auth RCE (CVE-2026-81578, CVE-2026-82078). Full chain analysis, IOCs, detection & emergency patch guidance

thecybersecguru.com/news/paper

##

CVE-2026-74820
(0 None)

EPSS: 0.25%

updated 2026-08-29T04:18:06.417000

4 posts

ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data beyond what was intended.ย  ServiceNow deployed a security update to hosted ins

security_crawler_carl at 2026-08-29T09:20:59.700Z ##

๐Ÿ† New Achievement! Maximum Severity, Minimum Fuss!

Per your platform's automated patch-prioritization policy: three maximum-severity vulnerabilities in the ServiceNow AI Platform have been logged, triaged, and assigned to the backlog. CVE-2026-18886 enables privilege escalation and data manipulation; CVE-2026-74820 allows arbitrary SQL execution against your underlying database. No user interaction required for exploitation. (1/3)

##

DailyCyberSecurity at 2026-08-28T03:02:14.899Z ##

ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.

securityonline.info/servicenow

##

security_crawler_carl@infosec.exchange at 2026-08-29T09:20:59.000Z ##

๐Ÿ† New Achievement! Maximum Severity, Minimum Fuss!

Per your platform's automated patch-prioritization policy: three maximum-severity vulnerabilities in the ServiceNow AI Platform have been logged, triaged, and assigned to the backlog. CVE-2026-18886 enables privilege escalation and data manipulation; CVE-2026-74820 allows arbitrary SQL execution against your underlying database. No user interaction required for exploitation. (1/3)

##

DailyCyberSecurity@infosec.exchange at 2026-08-28T03:02:14.000Z ##

ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.

#ServiceNow #CodeInjection #SQLInjection #CVE #InfoSec

securityonline.info/servicenow

##

CVE-2026-72984
(8.8 HIGH)

EPSS: 0.44%

updated 2026-08-29T04:18:06.270000

2 posts

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-08-29T17:02:59.000Z ##

๐ŸŸ  CVE-2026-72984 - High (8.8)

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T17:02:59.000Z ##

๐ŸŸ  CVE-2026-72984 - High (8.8)

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19313
(0 None)

EPSS: 0.47%

updated 2026-08-29T04:18:04.957000

2 posts

An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

DailyCyberSecurity at 2026-08-28T03:37:25.400Z ##

WatchGuard patched CVE-2026-19313 and more Fireware flaws, pre-authentication remote code execution bugs rated CVSS 9.3. Update firewalls now.

securityonline.info/watchguard

##

DailyCyberSecurity@infosec.exchange at 2026-08-28T03:37:25.000Z ##

WatchGuard patched CVE-2026-19313 and more Fireware flaws, pre-authentication remote code execution bugs rated CVSS 9.3. Update firewalls now.

#WatchGuard #Fireware #RCE #Firewall #InfoSec

securityonline.info/watchguard

##

CVE-2026-18886
(0 None)

EPSS: 0.25%

updated 2026-08-29T04:18:04.793000

4 posts

ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privilege escalation.ย  ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to ou

security_crawler_carl at 2026-08-29T09:20:59.700Z ##

๐Ÿ† New Achievement! Maximum Severity, Minimum Fuss!

Per your platform's automated patch-prioritization policy: three maximum-severity vulnerabilities in the ServiceNow AI Platform have been logged, triaged, and assigned to the backlog. CVE-2026-18886 enables privilege escalation and data manipulation; CVE-2026-74820 allows arbitrary SQL execution against your underlying database. No user interaction required for exploitation. (1/3)

##

DailyCyberSecurity at 2026-08-28T03:02:14.899Z ##

ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.

securityonline.info/servicenow

##

security_crawler_carl@infosec.exchange at 2026-08-29T09:20:59.000Z ##

๐Ÿ† New Achievement! Maximum Severity, Minimum Fuss!

Per your platform's automated patch-prioritization policy: three maximum-severity vulnerabilities in the ServiceNow AI Platform have been logged, triaged, and assigned to the backlog. CVE-2026-18886 enables privilege escalation and data manipulation; CVE-2026-74820 allows arbitrary SQL execution against your underlying database. No user interaction required for exploitation. (1/3)

##

DailyCyberSecurity@infosec.exchange at 2026-08-28T03:02:14.000Z ##

ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.

#ServiceNow #CodeInjection #SQLInjection #CVE #InfoSec

securityonline.info/servicenow

##

CVE-2026-41012
(7.7 HIGH)

EPSS: 0.10%

updated 2026-08-29T03:31:04

2 posts

Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualization infrastructure takeover. An attacker who can intercept traffic between the BOSH Director and vCenter can establish a malicious server impersonati

thehackerwire@mastodon.social at 2026-08-29T03:59:47.000Z ##

๐ŸŸ  CVE-2026-41012 - High (7.7)

Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualiza...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T03:59:47.000Z ##

๐ŸŸ  CVE-2026-41012 - High (7.7)

Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualiza...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81533
(7.1 HIGH)

EPSS: 0.21%

updated 2026-08-29T00:31:12

2 posts

An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL statement contains an unusually long run of digits following a LIMIT clause. The issue occurs only on connections where the driver's optional prefetch setting is enabled, and stems from the driver copying the digit sequence into a fixed-size internal buffer without checking its length

hugovalters@mastodon.social at 2026-08-29T15:04:18.000Z ##

CVE-2026-81533 - Memory safety flaw in MongoDB BI Connector ODBC Driver. Buffer overflow via long LIMIT clauses. CVSS 7.1. Disable prefetch now. #CVE #MongoDB #infosec

valtersit.com/cve/CVE-2026-815

##

hugovalters@mastodon.social at 2026-08-29T15:04:18.000Z ##

CVE-2026-81533 - Memory safety flaw in MongoDB BI Connector ODBC Driver. Buffer overflow via long LIMIT clauses. CVSS 7.1. Disable prefetch now. #CVE #MongoDB #infosec

valtersit.com/cve/CVE-2026-815

##

CVE-2026-81490
(7.7 HIGH)

EPSS: 0.24%

updated 2026-08-29T00:31:12

3 posts

A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. The sampling logic classifies the resulting server message as transient and, after the configured retries are exhausted, proceeds without a valid result, ending the schema refresh routine. The mongos

hugovalters@mastodon.social at 2026-08-29T11:08:27.000Z ##

CVE-2026-81490 - DoS flaw in MongoDB Connector for BI. Malicious views block schema refresh routines. CVSS 7.7. Restrict view creation privileges. #CVE #MongoDB #infosec

valtersit.com/cve/CVE-2026-814

##

thehackerwire@mastodon.social at 2026-08-29T00:01:37.000Z ##

๐ŸŸ  CVE-2026-81490 - High (7.7)

A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. The sampling logic classifies the resulting se...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T00:01:37.000Z ##

๐ŸŸ  CVE-2026-81490 - High (7.7)

A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. The sampling logic classifies the resulting se...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81532
(8.8 HIGH)

EPSS: 0.28%

updated 2026-08-29T00:31:12

2 posts

A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the name length is not bounded before the driver builds its diagnostic message, memory adjacent to that buffer is overwritten with user-supplied content. This can terminate the hosting

thehackerwire@mastodon.social at 2026-08-29T06:02:00.000Z ##

๐ŸŸ  CVE-2026-81532 - High (8.8)

A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the name length is not bounded ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T06:02:00.000Z ##

๐ŸŸ  CVE-2026-81532 - High (8.8)

A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the name length is not bounded ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81518
(7.5 HIGH)

EPSS: 0.15%

updated 2026-08-29T00:31:12

2 posts

When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accepted. In deployments that rely on client certificates as the sole means of identifying users, a remote party with network access to the listener can therefore establish a session an

thehackerwire@mastodon.social at 2026-08-29T05:00:32.000Z ##

๐ŸŸ  CVE-2026-81518 - High (7.5)

When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accepted. In deployments that re...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T05:00:32.000Z ##

๐ŸŸ  CVE-2026-81518 - High (7.5)

When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accepted. In deployments that re...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81520
(7.5 HIGH)

EPSS: 0.24%

updated 2026-08-29T00:31:04

3 posts

A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Because the negotiation loop had no overall time bound and the read from the client had no deadline, each such session retains a worker, a client connection slot, and its associated backend

hugovalters@mastodon.social at 2026-08-29T14:09:21.000Z ##

CVE-2026-81520 - DoS vulnerability in MongoDB Connector for BI allows unauthenticated resource exhaustion. CVSS 7.5. Restrict access immediately. #CVE #MongoDB #infosec

valtersit.com/cve/CVE-2026-815

##

thehackerwire@mastodon.social at 2026-08-29T05:00:42.000Z ##

๐ŸŸ  CVE-2026-81520 - High (7.5)

A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Because the negotiation loop had no ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T05:00:42.000Z ##

๐ŸŸ  CVE-2026-81520 - High (7.5)

A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Because the negotiation loop had no ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19295
(9.9 CRITICAL)

EPSS: 0.98%

updated 2026-08-29T00:31:03

2 posts

IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing

1 repos

https://github.com/rmhowe425/POC-CVE-2026-19295

thehackerwire@mastodon.social at 2026-08-29T08:03:42.000Z ##

๐Ÿ”ด CVE-2026-19295 - Critical (9.9)

IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references i...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T08:03:42.000Z ##

๐Ÿ”ด CVE-2026-19295 - Critical (9.9)

IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references i...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18891
(8.2 HIGH)

EPSS: 0.29%

updated 2026-08-29T00:31:02

2 posts

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.

thehackerwire@mastodon.social at 2026-08-29T09:01:20.000Z ##

๐ŸŸ  CVE-2026-18891 - High (8.2)

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T09:01:20.000Z ##

๐ŸŸ  CVE-2026-18891 - High (8.2)

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18729
(8.8 HIGH)

EPSS: 0.46%

updated 2026-08-29T00:31:02

2 posts

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.

1 repos

https://github.com/rmhowe425/POC-CVE-2026-18729

thehackerwire@mastodon.social at 2026-08-29T09:01:11.000Z ##

๐ŸŸ  CVE-2026-18729 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T09:01:11.000Z ##

๐ŸŸ  CVE-2026-18729 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19286
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-08-29T00:31:02

2 posts

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.

1 repos

https://github.com/rmhowe425/POC-CVE-2026-19286

thehackerwire@mastodon.social at 2026-08-29T08:03:32.000Z ##

๐Ÿ”ด CVE-2026-19286 - Critical (9.8)

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T08:03:32.000Z ##

๐Ÿ”ด CVE-2026-19286 - Critical (9.8)

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18899
(7.5 HIGH)

EPSS: 0.46%

updated 2026-08-29T00:31:02

2 posts

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.

thehackerwire@mastodon.social at 2026-08-29T07:00:17.000Z ##

๐ŸŸ  CVE-2026-18899 - High (7.5)

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T07:00:17.000Z ##

๐ŸŸ  CVE-2026-18899 - High (7.5)

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17203
(7.5 HIGH)

EPSS: 0.43%

updated 2026-08-29T00:31:01

2 posts

IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.

thehackerwire@mastodon.social at 2026-08-29T08:03:53.000Z ##

๐ŸŸ  CVE-2026-17203 - High (7.5)

IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T08:03:53.000Z ##

๐ŸŸ  CVE-2026-17203 - High (7.5)

IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73108
(7.5 HIGH)

EPSS: 0.53%

updated 2026-08-29T00:30:57

1 posts

RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before receiving the payload. A crafted header can request up to 1,073,741,823 bytes of capacity, allowing unauthenticated attackers to use concurrent TCP connectio

thehackerwire@mastodon.social at 2026-08-26T23:01:17.000Z ##

๐ŸŸ  CVE-2026-73108 - High (7.5)

RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before rece...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55784
(7.5 HIGH)

EPSS: 0.25%

updated 2026-08-28T23:17:07.517000

3 posts

free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-subscriber authentication state in a global sync.Map named AUSFContext.UePool in internal/context/context.go, keyed only by SUPI. Every request handled by internal/sbi/processor/ue_authentication.go creates an AusfUeContext, and AddAusfUeContextToPool executes ausfContext.Ue

hugovalters@mastodon.social at 2026-08-29T17:11:33.000Z ##

CVE-2026-55784 - Auth state overwrite flaw in free5GC 5G core network AUSF component. CVSS 7.5. Unpatched, monitor for fixes and mitigate immediately. #CVE #5G #infosec

valtersit.com/cve/CVE-2026-557

##

thehackerwire@mastodon.social at 2026-08-29T00:00:31.000Z ##

๐ŸŸ  CVE-2026-55784 - High (7.5)

free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-subscriber authentication state in a global sync.Map named AUSFContext.UePool in internal/context/context.go, keyed only b...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T00:00:31.000Z ##

๐ŸŸ  CVE-2026-55784 - High (7.5)

free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-subscriber authentication state in a global sync.Map named AUSFContext.UePool in internal/context/context.go, keyed only b...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55848
(8.6 HIGH)

EPSS: 0.33%

updated 2026-08-28T22:33:36

2 posts

### Summary XXE on MapFish Print allows reading arbitrary files of certain types. Eg /etc/passwd or k8 secrets and certs. https://github.com/mapfish/mapfish-print/commit/13020c0fbc299e5f604e4e66066311c4bf04d507 ### Details To trigger the XXE it is required to host a remote script and dtd file. When using the Print feature its possible to send the attacker server url as url of the gml layer. The

thehackerwire@mastodon.social at 2026-08-29T00:00:20.000Z ##

๐ŸŸ  CVE-2026-55848 - High (8.6)

mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print endpoint and ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T00:00:20.000Z ##

๐ŸŸ  CVE-2026-55848 - High (8.6)

mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print endpoint and ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82284
(8.1 HIGH)

EPSS: 0.24%

updated 2026-08-28T22:16:56.650000

2 posts

Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers can read other users' conversation histories including private knowledge base content, delete arbitrary chats, and inject fabricated messages into other users' conversations.

thehackerwire@mastodon.social at 2026-08-29T10:01:12.000Z ##

๐ŸŸ  CVE-2026-82284 - High (8.1)

Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers can read other users' conversation histories inc...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T10:01:12.000Z ##

๐ŸŸ  CVE-2026-82284 - High (8.1)

Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers can read other users' conversation histories inc...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82278
(8.8 HIGH)

EPSS: 0.56%

updated 2026-08-28T22:16:56.293000

2 posts

BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code. Attackers can submit crafted Code node definitions to the POST /api/v1/workflow/run_once endpoint, which executes them with exec() without sandboxing, gaining access to filesystem, credentials, and internal network resources.

thehackerwire@mastodon.social at 2026-08-29T13:00:58.000Z ##

๐ŸŸ  CVE-2026-82278 - High (8.8)

BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code. Attackers can submit crafted Code node definitions to the POST /api/v1/workflow...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T13:00:58.000Z ##

๐ŸŸ  CVE-2026-82278 - High (8.8)

BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code. Attackers can submit crafted Code node definitions to the POST /api/v1/workflow...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82017
(7.6 HIGH)

EPSS: 0.15%

updated 2026-08-28T22:16:55.067000

2 posts

IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the signed bootloader. Attackers can inject malicious kernel command line parameters that execute with boot environment privileg

thehackerwire@mastodon.social at 2026-08-29T00:01:28.000Z ##

๐ŸŸ  CVE-2026-82017 - High (7.6)

IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned co...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T00:01:28.000Z ##

๐ŸŸ  CVE-2026-82017 - High (7.6)

IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned co...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81517
(7.5 HIGH)

EPSS: 0.26%

updated 2026-08-28T22:16:54.383000

2 posts

An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path. When a log write or log rotation operation subsequently fails, the resulting error is not handled and the shared mongosqld process ends, ending service for all connected SQL clients. The proces

thehackerwire@mastodon.social at 2026-08-29T05:00:21.000Z ##

๐ŸŸ  CVE-2026-81517 - High (7.5)

An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path. When a log write or log rotation operati...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T05:00:21.000Z ##

๐ŸŸ  CVE-2026-81517 - High (7.5)

An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path. When a log write or log rotation operati...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55634
(9.9 CRITICAL)

EPSS: 0.45%

updated 2026-08-28T22:16:51.290000

1 posts

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field name that is emitted without an identifier allowlist by lib/DataObject/ClassBuilder/FieldDefinitionPropertiesBuilder.php into generated PHP properties and

hugovalters@mastodon.social at 2026-08-29T01:08:54.000Z ##

CVE-2026-55634 - Critical Code Injection vulnerability in Pimcore import API. CVSS 9.9. Update immediately. #CVE #Pimcore #infosec

valtersit.com/cve/CVE-2026-556

##

CVE-2026-3627
(9.1 CRITICAL)

EPSS: 0.51%

updated 2026-08-28T22:16:49.063000

3 posts

IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

hugovalters@mastodon.social at 2026-08-29T18:09:56.000Z ##

CVE-2026-3627 - Critical SQLi in IBM Concert (1.0.0-2.3.1). Remote attackers can read, modify, or delete database contents. CVSS 9.1. Update now. #CVE #IBM #infosec

valtersit.com/cve/CVE-2026-362

##

thehackerwire@mastodon.social at 2026-08-29T07:00:05.000Z ##

๐Ÿ”ด CVE-2026-3627 - Critical (9.1)

IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T07:00:05.000Z ##

๐Ÿ”ด CVE-2026-3627 - Critical (9.1)

IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18904
(8.2 HIGH)

EPSS: 0.31%

updated 2026-08-28T22:16:47.227000

2 posts

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers.

thehackerwire@mastodon.social at 2026-08-29T07:00:27.000Z ##

๐ŸŸ  CVE-2026-18904 - High (8.2)

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T07:00:27.000Z ##

๐ŸŸ  CVE-2026-18904 - High (8.2)

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18527
(9.9 CRITICAL)

EPSS: 0.29%

updated 2026-08-28T22:16:46.620000

2 posts

IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.

thehackerwire@mastodon.social at 2026-08-29T09:01:00.000Z ##

๐Ÿ”ด CVE-2026-18527 - Critical (9.9)

IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T09:01:00.000Z ##

๐Ÿ”ด CVE-2026-18527 - Critical (9.9)

IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55841
(7.5 HIGH)

EPSS: 0.36%

updated 2026-08-28T22:13:01

3 posts

### Impact A security issue has been identified in Graylog affecting the parsing of syslog messages that use a key-value format, such as those generated by Fortigate devices. The vulnerability allows attackers to overwrite individual message fields, or to produce invalid messages which Graylog will discard. This effectively enables log evasion techniques to obscure malicious activity. ### Patch

hugovalters@mastodon.social at 2026-08-29T12:12:04.000Z ##

CVE-2026-55841 - High severity FortiGate syslog parser flaw in Graylog. CVSS 7.5. Update immediately. #CVE #Graylog #infosec

valtersit.com/cve/CVE-2026-558

##

thehackerwire@mastodon.social at 2026-08-29T00:00:41.000Z ##

๐ŸŸ  CVE-2026-55841 - High (7.5)

Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLFo...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T00:00:41.000Z ##

๐ŸŸ  CVE-2026-55841 - High (7.5)

Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLFo...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18885(CVSS UNKNOWN)

EPSS: 0.43%

updated 2026-08-28T21:32:13

6 posts

ServiceNow has remediated a code injection vulnerability that was identified inย the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform andย gain access to, or modify, instance data beyond what was intended.ย  ServiceNow deployed a security update to hosted instances and ServiceNow provid

netsecio@mastodon.social at 2026-08-29T13:38:09.000Z ##

๐Ÿ“ฐ ServiceNow Patches Three Critical CVSS 10.0 Flaws in AI Platform

ServiceNow patches three critical unauthenticated flaws (CVSS 10.0) in its AI Platform. The vulnerabilities (CVE-2026-18885, -18886, -74820) allow for RCE, privilege escalation, and SQL injection. Self-hosted customers must patch immediately. #Servic...

๐Ÿ”— cyber.netsecops.io/articles/se

##

guru@thecybersecguru.com at 2026-08-28T15:46:45.000Z ##

ServiceNow Patches Three CVSS 10.0 Vulnerabilities Allowing Unauthenticated Code Execution and SQL Injection

ServiceNow patched three CVSS 10.0 vulnerabilities allowing unauthenticated code execution, privilege escalation and SQL injection

thecybersecguru.com/news/servi

##

netsecio@mastodon.social at 2026-08-28T15:14:02.000Z ##

๐Ÿ“ฐ ServiceNow Patches Three Critical CVSS 10.0 Flaws in AI Platform

ServiceNow patches three critical unauthenticated flaws (CVSS 10.0) in its AI Platform. The vulnerabilities (CVE-2026-18885, -18886, -74820) allow for RCE, privilege escalation, and SQL injection. Self-hosted customers must patch immediately. #Servic...

๐Ÿ”— cyber.netsecops.io/articles/se

##

DailyCyberSecurity at 2026-08-28T03:02:14.899Z ##

ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.

securityonline.info/servicenow

##

guru@thecybersecguru.com at 2026-08-28T15:46:45.000Z ##

ServiceNow Patches Three CVSS 10.0 Vulnerabilities Allowing Unauthenticated Code Execution and SQL Injection

ServiceNow patched three CVSS 10.0 vulnerabilities allowing unauthenticated code execution, privilege escalation and SQL injection

thecybersecguru.com/news/servi

##

DailyCyberSecurity@infosec.exchange at 2026-08-28T03:02:14.000Z ##

ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.

#ServiceNow #CodeInjection #SQLInjection #CVE #InfoSec

securityonline.info/servicenow

##

CVE-2026-82282
(8.0 HIGH)

EPSS: 0.26%

updated 2026-08-28T21:31:36

2 posts

Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Attackers can observe or intercept the GitHub redirect during setup to obtain the RSA private key and webhook secret, enabling installation token minting and webhook payload forgery.

thehackerwire@mastodon.social at 2026-08-29T10:00:51.000Z ##

๐ŸŸ  CVE-2026-82282 - High (8)

Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Attackers can observe or intercept the GitHub redirect during setup to obtain the RSA private key an...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T10:00:51.000Z ##

๐ŸŸ  CVE-2026-82282 - High (8)

Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Attackers can observe or intercept the GitHub redirect during setup to obtain the RSA private key an...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82291
(8.1 HIGH)

EPSS: 0.30%

updated 2026-08-28T21:31:36

2 posts

HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. Attackers can execute authenticated GraphQL queries from malicious pages visited by logged-in users to access workspaces, projects, forms, submissions, and respondent data, or modify account settings.

thehackerwire@mastodon.social at 2026-08-28T22:02:21.000Z ##

๐ŸŸ  CVE-2026-82291 - High (8.1)

HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. Attackers can execute authenticated GraphQL queries from malicious pages visited by logg...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T22:02:21.000Z ##

๐ŸŸ  CVE-2026-82291 - High (8.1)

HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. Attackers can execute authenticated GraphQL queries from malicious pages visited by logg...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82329
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-08-28T21:31:36

2 posts

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

thehackerwire@mastodon.social at 2026-08-28T22:00:46.000Z ##

๐Ÿ”ด CVE-2026-82329 - Critical (9.8)

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T22:00:46.000Z ##

๐Ÿ”ด CVE-2026-82329 - Critical (9.8)

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82275
(7.5 HIGH)

EPSS: 0.37%

updated 2026-08-28T21:31:29

2 posts

Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file access to intended directories. Attackers can supply absolute file paths to the unauthenticated Gradio interface to read arbitrary files accessible by the server process.

thehackerwire@mastodon.social at 2026-08-29T12:00:53.000Z ##

๐ŸŸ  CVE-2026-82275 - High (7.5)

Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file access to intended directories. Attackers can supply absolute file paths to the unauthenticated Gradio interface to read arbitrary...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T12:00:53.000Z ##

๐ŸŸ  CVE-2026-82275 - High (7.5)

Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file access to intended directories. Attackers can supply absolute file paths to the unauthenticated Gradio interface to read arbitrary...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82279
(8.1 HIGH)

EPSS: 0.27%

updated 2026-08-28T21:31:29

2 posts

HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team members including owners, rotate API keys, and rename teams by sending requests to PATCH /team/apiKey, PATCH /team/name, and DELETE /team/member endpoints.

thehackerwire@mastodon.social at 2026-08-28T22:02:32.000Z ##

๐ŸŸ  CVE-2026-82279 - High (8.1)

HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team members including owners, rotate API keys, and rename teams by s...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T22:02:32.000Z ##

๐ŸŸ  CVE-2026-82279 - High (8.1)

HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team members including owners, rotate API keys, and rename teams by s...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82288
(7.5 HIGH)

EPSS: 0.32%

updated 2026-08-28T21:31:28

2 posts

Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated attackers can access this endpoint to retrieve configured usernames and passwords, then use them to authenticate to the interface and access the application.

thehackerwire@mastodon.social at 2026-08-28T22:02:05.000Z ##

๐ŸŸ  CVE-2026-82288 - High (7.5)

Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated attackers c...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T22:02:05.000Z ##

๐ŸŸ  CVE-2026-82288 - High (7.5)

Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated attackers c...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82286
(8.6 HIGH)

EPSS: 0.35%

updated 2026-08-28T21:31:28

2 posts

gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-directory segments to overwrite existing files with content sourced from attacker-controlled URLs.

1 repos

https://github.com/BiiTts/CVE-2026-82286-gpt-crawler-Arbitrary-File-Write

thehackerwire@mastodon.social at 2026-08-28T22:00:56.000Z ##

๐ŸŸ  CVE-2026-82286 - High (8.6)

gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-directory segme...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T22:00:56.000Z ##

๐ŸŸ  CVE-2026-82286 - High (8.6)

gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-directory segme...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82283
(8.1 HIGH)

EPSS: 0.24%

updated 2026-08-28T21:31:27

2 posts

VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations. Attackers can read, modify, and delete arbitrary conversations and messages by supplying caller-controlled identifiers to memory endpoints.

thehackerwire@mastodon.social at 2026-08-29T10:01:01.000Z ##

๐ŸŸ  CVE-2026-82283 - High (8.1)

VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations. Attackers can read, modify, and delete arbitrary conversations and messages by supplying c...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T10:01:01.000Z ##

๐ŸŸ  CVE-2026-82283 - High (8.1)

VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations. Attackers can read, modify, and delete arbitrary conversations and messages by supplying c...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82277
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-08-28T21:31:26

2 posts

Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can invoke PromoteRollout, AbortRollout, RestartRollout, SetRolloutImage, UndoRollout, and RetryRollout operations across all namespaces accessible to the operator's kubeconfig.

thehackerwire@mastodon.social at 2026-08-29T12:01:03.000Z ##

๐Ÿ”ด CVE-2026-82277 - Critical (9.8)

Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can invoke PromoteRollout, AbortRollout, RestartRollout...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T12:01:03.000Z ##

๐Ÿ”ด CVE-2026-82277 - Critical (9.8)

Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can invoke PromoteRollout, AbortRollout, RestartRollout...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82270
(7.5 HIGH)

EPSS: 0.28%

updated 2026-08-28T21:31:25

2 posts

Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header to internal addresses and forward requests with Authorization headers to reach internal services and exfiltrate provider API keys.

thehackerwire@mastodon.social at 2026-08-29T14:00:56.000Z ##

๐ŸŸ  CVE-2026-82270 - High (7.5)

Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header to internal addresses and forward requests w...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T14:00:56.000Z ##

๐ŸŸ  CVE-2026-82270 - High (7.5)

Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header to internal addresses and forward requests w...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82269
(8.1 HIGH)

EPSS: 0.30%

updated 2026-08-28T21:31:25

2 posts

Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required.

thehackerwire@mastodon.social at 2026-08-29T14:00:46.000Z ##

๐ŸŸ  CVE-2026-82269 - High (8.1)

Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is l...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T14:00:46.000Z ##

๐ŸŸ  CVE-2026-82269 - High (8.1)

Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is l...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82268
(7.5 HIGH)

EPSS: 0.28%

updated 2026-08-28T21:31:25

2 posts

Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio interface to make the server issue HTTP requests to arbitrary internal addresses including metadata services and read retrieved content through parsed docum

thehackerwire@mastodon.social at 2026-08-29T13:01:20.000Z ##

๐ŸŸ  CVE-2026-82268 - High (7.5)

Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio int...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T13:01:20.000Z ##

๐ŸŸ  CVE-2026-82268 - High (7.5)

Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio int...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75124
(7.5 HIGH)

EPSS: 0.48%

updated 2026-08-28T21:31:24

2 posts

PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP query string without guaranteeing NUL termination, allowing parse_query_string to process attacker-controlled data into a fixed-size stack buffer. An unauthenticated remote attacker can send an ove

thehackerwire@mastodon.social at 2026-08-29T17:02:49.000Z ##

๐ŸŸ  CVE-2026-75124 - High (7.5)

PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP query string without guaranteeing NUL termin...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T17:02:49.000Z ##

๐ŸŸ  CVE-2026-75124 - High (7.5)

PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP query string without guaranteeing NUL termin...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75486
(8.0 HIGH)

EPSS: 1.25%

updated 2026-08-28T21:31:24

2 posts

Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands by injecting malicious input into the linters.<key>.optic-ci.original branch name field. The expectGitBranch() function in src/lint.ts passes the unsanitized branch name directly into child_process.exec() via an unescape

thehackerwire@mastodon.social at 2026-08-29T16:01:31.000Z ##

๐ŸŸ  CVE-2026-75486 - High (8)

Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands by injecting malicious input into the linters..optic-ci.original br...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T16:01:31.000Z ##

๐ŸŸ  CVE-2026-75486 - High (8)

Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands by injecting malicious input into the linters..optic-ci.original br...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82266
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-08-28T21:31:23

2 posts

Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker accounts, modify cluster configuration, and disrupt partition replication.

thehackerwire@mastodon.social at 2026-08-29T13:01:09.000Z ##

๐Ÿ”ด CVE-2026-82266 - Critical (9.8)

Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker accounts, m...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T13:01:09.000Z ##

๐Ÿ”ด CVE-2026-82266 - Critical (9.8)

Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker accounts, m...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56100
(8.1 HIGH)

EPSS: 0.29%

updated 2026-08-28T21:31:17

2 posts

SpringBlade versions 2.7.3 through 3.5.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feign user-creation endpoint exposed via @RestController without authorization checks. Attackers can exploit the gateway's authentication filter, which only validates JWT parsing

thehackerwire@mastodon.social at 2026-08-29T17:03:09.000Z ##

๐ŸŸ  CVE-2026-56100 - High (8.1)

SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feig...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T17:03:09.000Z ##

๐ŸŸ  CVE-2026-56100 - High (8.1)

SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feig...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77586
(8.0 HIGH)

EPSS: 0.23%

updated 2026-08-28T21:16:15.740000

2 posts

In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text returned by SHOW CREATE statements without escaping the identifier delimiter. A user with permission to write to a sampled MongoDB collection can choose a name that closes the quoted identifier early, so that additional SQL text becomes part of the gen

thehackerwire@mastodon.social at 2026-08-29T16:01:21.000Z ##

๐ŸŸ  CVE-2026-77586 - High (8)

In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text returned by SHOW CREATE statements without escaping the identifier delimiter. A user with permissio...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T16:01:21.000Z ##

๐ŸŸ  CVE-2026-77586 - High (8)

In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text returned by SHOW CREATE statements without escaping the identifier delimiter. A user with permissio...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81525
(8.1 HIGH)

EPSS: 0.27%

updated 2026-08-28T21:16:15.740000

4 posts

The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application that incorporates untrusted text into these identifiers may have operations silently directed at a different storage location than the one the application intended.

DailyCyberSecurity at 2026-08-28T17:21:30.973Z ##

Discover the details of recent MongoDB security vulnerabilities affecting drivers and BI connectors. Update your systems to patch CVE-2026-81525 and others.

securityonline.info/mongodb-se

##

thehackerwire@mastodon.social at 2026-08-27T23:00:22.000Z ##

๐ŸŸ  CVE-2026-81525 - High (8.1)

The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application that incorporates untruste...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-08-28T17:21:30.000Z ##

Discover the details of recent MongoDB security vulnerabilities affecting drivers and BI connectors. Update your systems to patch CVE-2026-81525 and others.

#MongoDB #Cybersecurity #Vulnerability #CVE202681525 #DatabaseSecurity

securityonline.info/mongodb-se

##

thehackerwire@mastodon.social at 2026-08-27T23:00:22.000Z ##

๐ŸŸ  CVE-2026-81525 - High (8.1)

The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application that incorporates untruste...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82287
(8.1 HIGH)

EPSS: 0.28%

updated 2026-08-28T20:20:20.243000

2 posts

Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions by reflecting any request origin in Access-Control-Allow-Origin responses while credentials are enabled. Attackers can issue credentialed cross-origin requests from any website to read analytics data, account information, and perform authenticated state-changing operations as the

thehackerwire@mastodon.social at 2026-08-28T22:01:07.000Z ##

๐ŸŸ  CVE-2026-82287 - High (8.1)

Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions by reflecting any request origin in Access-Control-Allow-Origin responses while credentials are enabled. Attackers can issue cre...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T22:01:07.000Z ##

๐ŸŸ  CVE-2026-82287 - High (8.1)

Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions by reflecting any request origin in Access-Control-Allow-Origin responses while credentials are enabled. Attackers can issue cre...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82285
(8.2 HIGH)

EPSS: 0.31%

updated 2026-08-28T20:20:19.953000

2 posts

bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/workflow/report/callback endpoint that lacks authentication and applies no URL scheme restrictions or host filtering. Unauthenticated attackers can supply arbitrary URLs to enumerate internal network services and cloud metadata endpoints, then retrieve captured responses from object storage using ca

thehackerwire@mastodon.social at 2026-08-29T12:00:43.000Z ##

๐ŸŸ  CVE-2026-82285 - High (8.2)

bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/workflow/report/callback endpoint that lacks authentication and applies no URL scheme restrictions or host filtering. Unauthenticated attackers can...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T12:00:43.000Z ##

๐ŸŸ  CVE-2026-82285 - High (8.2)

bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/workflow/report/callback endpoint that lacks authentication and applies no URL scheme restrictions or host filtering. Unauthenticated attackers can...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82021
(8.3 HIGH)

EPSS: 0.23%

updated 2026-08-28T20:20:14.470000

2 posts

Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather than a pinned commit SHA. An attacker who compromises the upstream repository can propagate malicious code to every host that installs the affected catalo

thehackerwire@mastodon.social at 2026-08-29T14:01:06.000Z ##

๐ŸŸ  CVE-2026-82021 - High (8.3)

Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather t...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T14:01:06.000Z ##

๐ŸŸ  CVE-2026-82021 - High (8.3)

Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather t...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81767
(7.5 HIGH)

EPSS: 0.20%

updated 2026-08-28T20:20:13.023000

2 posts

Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.

thehackerwire@mastodon.social at 2026-08-28T17:00:14.000Z ##

๐ŸŸ  CVE-2026-81767 - High (7.5)

Unauthenticated Broken Access Control in Simple Payment &lt;= 2.5.2 versions.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T17:00:14.000Z ##

๐ŸŸ  CVE-2026-81767 - High (7.5)

Unauthenticated Broken Access Control in Simple Payment &lt;= 2.5.2 versions.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81699
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-28T20:20:11.923000

1 posts

openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply malicious files with excessive KDF parameters to exhaust system resources and crash or wedge the process before password verification occurs.

thehackerwire@mastodon.social at 2026-08-27T19:00:48.000Z ##

๐ŸŸ  CVE-2026-81699 - High (7.5)

openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply malicious ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81019
(7.4 HIGH)

EPSS: 0.24%

updated 2026-08-28T20:20:08.670000

1 posts

wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM key and nonce discloses the keystream (the XOR of two ciphertexts equals the XOR of their plaintexts, so one known reco

hugovalters@mastodon.social at 2026-08-28T18:04:07.000Z ##

CVE-2026-81019 - AES-GCM nonce reuse in wolfSSL wolfProvider allows TLS 1.2 decryption and auth tag forgery. CVSS 7.4. Update to 1.2.2 immediately. #CVE #wolfSSL #infosec

valtersit.com/cve/CVE-2026-810

##

CVE-2026-77438
(7.5 HIGH)

EPSS: 0.24%

updated 2026-08-28T20:19:55.927000

2 posts

Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public share-search endpoint does not enforce the per-note shareCredentials and shareHiddenFromTree controls, allowing an unauthenticated visitor to read the titles, tree paths, and content of protected shared notes. The endpoint authorizes only the ancestor note supplied in the request and

thehackerwire@mastodon.social at 2026-08-27T23:00:33.000Z ##

๐ŸŸ  CVE-2026-77438 - High (7.5)

Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public share-search endpoint does not enforce the per-note shareCredentials and shareHiddenFromTree controls, allowing an unauthenticated ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-27T23:00:33.000Z ##

๐ŸŸ  CVE-2026-77438 - High (7.5)

Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public share-search endpoint does not enforce the per-note shareCredentials and shareHiddenFromTree controls, allowing an unauthenticated ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76640
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-28T20:19:54.877000

6 posts

Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisioning stack that allow unauthenticated proximate attackers to achieve root code execution without pairing or credentials by exploiting an unquoted heredoc variable in the WiFi provisioning script and a buffer overflow in the SSID chunk accumulator. Attackers can send crafted BLE w

1 repos

https://github.com/OlivierLaflamme/UniBLEed

cyberworldops at 2026-08-29T18:20:00.781Z ##

Two independent root RCE chains were disclosed on the Unitree G1 EDU humanoid robot. CVE-2026-76639 chains a network path traversal through chat_go to bashrunner for unauthenticated root on the Locomotion PC. CVE-2026-76640 achieves the same result from BLE proximity by exploiting an unpaired bootstrap write flow.

cyberworldops.eu/en/two-root-a

##

AAKL at 2026-08-28T15:08:53.268Z ##

Oh, goodie. The robots come with recycled bugs. These two are tracked as CVE-2026-76639 and CVE-2026-76640.

This was posted on August 27.

Boschko Security Blog: UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range boschko.ca/g1-ble-rce/

More:

The Hacker News: Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth thehackernews.com/2026/08/two-

##

Analyst207@mastodon.social at 2026-08-28T13:24:58.000Z ##

Unitree Humanoid Robot Flaws Expose Root Code Execution Risk

A security researcher has uncovered two critical vulnerabilities in the Unitree G1 EDU robot, allowing hackers to remotely execute code with root access, potentially putting users and systems at risk. These flaws, tracked as CVE-2026-76639 and CVE-2026-76640, highlight the importance of robust security measures in robotics andโ€ฆ

osintsights.com/unitree-humano

#UnitreeHumanoidRobot #RemoteCodeExecution #Cve202676639 #Cve202676640 #Robotics

##

sayzard@mastodon.sayzard.org at 2026-08-28T01:46:07.000Z ##

UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot

Unitree G1 ํœด๋จธ๋…ธ์ด๋“œ ๋กœ๋ด‡์—์„œ ์ธ์ฆ ์—†์ด root ๊ถŒํ•œ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰์ด ๊ฐ€๋Šฅํ•œ UniBLEed ๊ณต๊ฒฉ ์ฒด์ธ์ด ๊ณต๊ฐœ๋์œผ๋ฉฐ, CVE-2026-76639์™€ CVE-2026-76640์ด ๋ถ€์—ฌ๋๋‹ค. ๊ณต๊ฒฉ์€ ์†Œ์œ ๊ถŒ ๊ฒ€์ฆ ์—†์ด ๋กœ๋ด‡ AES ํ‚ค๋ฅผ ๋ณตํ˜ธํ™”ํ•ด ์ฃผ๋Š” ํด๋ผ์šฐ๋“œ API, ํŽ˜์–ด๋ง ์—†์ด ์“ฐ๊ธฐ ๊ฐ€๋Šฅํ•œ BLE GATT ํŠน์„ฑ, Wi-Fi ์„ค์ • heredoc ์ธ์ ์…˜, AI ์ฑ—๋ด‡ ์ง€์‹๋ฒ ์ด์Šค์˜ ๊ฒฝ๋กœ ์ˆœํšŒ, ๊ทธ๋ฆฌ๊ณ  BSS ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ๋ฅผ ์กฐํ•ฉํ•ด root์˜ system() ํ˜ธ์ถœ๋กœ ์ด์–ด์ง„๋‹ค. ํŠนํžˆ ๊ทผ๊ฑฐ๋ฆฌ์˜ ๋‹ค๋ฅธ G1๋กœ ๋™์ผ ๊ณต๊ฒฉ์„ ์ „ํŒŒํ•  ์ˆ˜ ์žˆ๋Š” ์›œ ๊ฐ€๋Šฅ์„ฑ์ด ์–ธ๊ธ‰๋ผ, ๋กœ๋ด‡ยท์—ฃ์ง€ AI ์žฅ๋น„์—์„œ BLEยทํด๋ผ์šฐ๋“œยท๋กœ์ปฌ ์„œ๋น„์Šค...

boschko.ca/g1-ble-rce/

##

cyberworldops@infosec.exchange at 2026-08-29T18:20:00.000Z ##

Two independent root RCE chains were disclosed on the Unitree G1 EDU humanoid robot. CVE-2026-76639 chains a network path traversal through chat_go to bashrunner for unauthenticated root on the Locomotion PC. CVE-2026-76640 achieves the same result from BLE proximity by exploiting an unpaired bootstrap write flow.

#UnitreeG1 #RootRCE #BLE #RoboticsSecurity

cyberworldops.eu/en/two-root-a

##

AAKL@infosec.exchange at 2026-08-28T15:08:53.000Z ##

Oh, goodie. The robots come with recycled bugs. These two are tracked as CVE-2026-76639 and CVE-2026-76640.

This was posted on August 27.

Boschko Security Blog: UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range boschko.ca/g1-ble-rce/

More:

The Hacker News: Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth thehackernews.com/2026/08/two- #infosec #vulnerability #robotics

##

CVE-2026-76060
(8.8 HIGH)

EPSS: 2.31%

updated 2026-08-28T20:19:54.620000

1 posts

An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server.

1 repos

https://github.com/investigato/CVE-2026-76060_ZoneMinder_CommandInjection-PoC

Matchbook3469@mastodon.social at 2026-08-28T18:58:50.000Z ##

๐ŸŸ  New security advisory:

CVE-2026-76060 affects multiple systems.

โ€ข Impact: Significant security breach potential
โ€ข Risk: Unauthorized access or data exposure
โ€ข Mitigation: Apply patches within 24-48 hours

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#CVE #SecurityPatching #HackerNews

##

CVE-2026-66155
(7.6 HIGH)

EPSS: 0.17%

updated 2026-08-28T19:03:37.837000

1 posts

A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins. This could allow an attacker to craft a malicious URL that, when loa

thehackerwire@mastodon.social at 2026-08-27T17:00:36.000Z ##

๐ŸŸ  CVE-2026-66155 - High (7.6)

A vulnerability has been identified in Element maps-ng V47 (All versions &lt; V47.12.3), Element maps-ng V48 (All versions &lt; V48.11.3), Element maps-ng V49 (All versions &lt; V49.16.1). The si-map component does not properly neutralize user-con...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76784
(0 None)

EPSS: 0.15%

updated 2026-08-28T19:02:53.760000

1 posts

Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge locally exchanged control messages, potentially resulting in unauthorized device control. Successful exploitation could allow an attacker to manipulate the operational state of an affected device, r

DailyCyberSecurity@infosec.exchange at 2026-08-27T02:15:40.000Z ##

A high-severity TP-Link Kasa vulnerability (CVE-2026-76784) allows unauthorized smart home device control. Apply the latest firmware patch immediately.

#TPLink #Kasa #Vulnerability #Cybersecurity #CVE202676784 #SmartHome

securityonline.info/tp-link-ka

##

CVE-2026-75112
(0 None)

EPSS: 0.11%

updated 2026-08-28T18:58:27.140000

2 posts

A security issue exists within OTTOยฎ Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker gains access to an unencrypted system backup, the weakly hashed credentials coul

cyberworldops at 2026-08-28T10:20:00.484Z ##

Weak bcrypt hashes in Rockwell Automation OTTO Fleet Manager (CVE-2026-75112) reduce the computational cost of offline brute-force attacks against stored credentials. The flaw affects OT fleet management software in industrial environments. Patch and rotate passwords.

cyberworldops.eu/en/rockwell-a

##

cyberworldops@infosec.exchange at 2026-08-28T10:20:00.000Z ##

Weak bcrypt hashes in Rockwell Automation OTTO Fleet Manager (CVE-2026-75112) reduce the computational cost of offline brute-force attacks against stored credentials. The flaw affects OT fleet management software in industrial environments. Patch and rotate passwords.

#CWE916 #OTSecurity #RockwellAdvisory #ICSAdvisory

cyberworldops.eu/en/rockwell-a

##

CVE-2026-81728
(8.1 HIGH)

EPSS: 0.26%

updated 2026-08-28T18:56:49.340000

2 posts

Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies only the generic alphanohtml filter: that strips HTML but leaves SQL keywords, comment markers, parentheses, spaces and quotes intact. import_insert() in htdocs/core/modules/import/import_csv.modules.php

thehackerwire@mastodon.social at 2026-08-27T21:00:10.000Z ##

๐ŸŸ  CVE-2026-81728 - High (8.1)

Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies only the generic alphanohtml filter: that strips HT...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-27T21:00:10.000Z ##

๐ŸŸ  CVE-2026-81728 - High (8.1)

Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies only the generic alphanohtml filter: that strips HT...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82261
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-28T18:56:34.447000

2 posts

SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulnerability in form deserialization. An attacker can send malformed form data to cause the server to become unresponsive while processing the request, resulting in denial of service. Fixed in 2.52.2.

thehackerwire@mastodon.social at 2026-08-28T12:59:59.000Z ##

๐ŸŸ  CVE-2026-82261 - High (7.5)

SvelteKit (@sveltejs/kit) versions >=2.49.0 and &lt;=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulnerability in form deserialization. An attacker can send malformed form data to cause the server to become ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T12:59:59.000Z ##

๐ŸŸ  CVE-2026-82261 - High (7.5)

SvelteKit (@sveltejs/kit) versions >=2.49.0 and &lt;=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulnerability in form deserialization. An attacker can send malformed form data to cause the server to become ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81701
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-08-28T18:56:34.447000

3 posts

openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsigned plugins following documented installation paths to achieve arbitrary code execution in the CLI process with access to passwords and cryptographic key

thehackerwire@mastodon.social at 2026-08-27T20:00:37.000Z ##

๐Ÿ”ด CVE-2026-81701 - Critical (9.8)

openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsig...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-27T20:00:37.000Z ##

๐Ÿ”ด CVE-2026-81701 - Critical (9.8)

openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsig...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w@infosec.exchange at 2026-08-27T19:24:00.000Z ##

How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.

nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-81681
(4.6 MEDIUM)

EPSS: 0.13%

updated 2026-08-28T18:56:34.447000

3 posts

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB Workspace' with AES-256-GCM encryption and write a marker declaring the workspace encrypted, but the workspace directory is actually stored in cleartext and the derived encryption key is never applied to it. A user who trusts the branding and places files in the workspace leaves

CVE-2026-81680
(4.0 MEDIUM)

EPSS: 0.15%

updated 2026-08-28T18:56:34.447000

1 posts

openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to delete recovery-slot fields and bypass authentication, silently removing recovery paths the owner deliberately added.

CVE-2026-81706
(6.8 MEDIUM)

EPSS: 0.13%

updated 2026-08-28T18:56:34.447000

1 posts

openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding own identity is deleted. When the own identity is deleted, the shadowed contact becomes visible and resolves to the attacker's keys, enabling silent key substitution for encrypted files.

CVE-2026-81717
(3.5 LOW)

EPSS: 0.09%

updated 2026-08-28T18:56:34.447000

1 posts

openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical write access). USBDriveCreator._verify_integrity_file only validates files listed in the manifest, so files added to the drive โ€” including a root-level autorun payload โ€” are not detected and integrit

CVE-2026-81695
(3.3 LOW)

EPSS: 0.18%

updated 2026-08-28T18:56:34.447000

1 posts

openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id containing escape sequences to repaint terminal output and forge authenticity verification blocks.

CVE-2026-81705
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-28T18:56:34.447000

1 posts

openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g. --passw). The sanitizer only recognized exact option names, --option=value forms, and tokens starting with -p, so these spellings bypass the redaction chokepoint and the cleartext passwo

thehackerwire@mastodon.social at 2026-08-27T18:01:48.000Z ##

๐ŸŸ  CVE-2026-81705 - High (7.5)

openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g. --passw). The sanitizer only reco...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82254
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-28T18:54:09.323000

2 posts

gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to trigger panics or out-of-memory process kills.

thehackerwire@mastodon.social at 2026-08-28T14:59:50.000Z ##

๐ŸŸ  CVE-2026-82254 - High (7.5)

gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to trigger panics or out...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T14:59:50.000Z ##

๐ŸŸ  CVE-2026-82254 - High (7.5)

gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to trigger panics or out...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47879
(7.7 HIGH)

EPSS: 0.24%

updated 2026-08-28T18:47:30.163000

1 posts

Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Spring Cloud Gateway 3.1.13 and earlier

thehackerwire@mastodon.social at 2026-08-27T07:00:33.000Z ##

๐ŸŸ  CVE-2026-47879 - High (7.7)

Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor.
Spring Cloud Gateway 5.0.0 - 5.0.2
Spring Cloud Gateway 4.3.0 - 4.3.5
Spring Cloud Gateway 4.0.0 - 4.2.9
Spring Cloud...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47851
(7.5 HIGH)

EPSS: 0.26%

updated 2026-08-28T18:47:30.163000

1 posts

Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9

1 repos

https://github.com/tangyaofq/spring-ai-sibling-loop-poc

thehackerwire@mastodon.social at 2026-08-27T04:01:20.000Z ##

๐ŸŸ  CVE-2026-47851 - High (7.5)

Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread.
Spring AI 2.0.0
Spring AI 1.1.0 - 1.1.8
Spring AI 1.0.0 - 1.0.9

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82082
(9.8 CRITICAL)

EPSS: 1.50%

updated 2026-08-28T18:46:13.563000

2 posts

NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.

thehackerwire@mastodon.social at 2026-08-28T06:00:20.000Z ##

๐Ÿ”ด CVE-2026-82082 - Critical (9.8)

NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T06:00:20.000Z ##

๐Ÿ”ด CVE-2026-82082 - Critical (9.8)

NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82078(CVSS UNKNOWN)

EPSS: 0.46%

updated 2026-08-28T18:31:39

3 posts

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on

2 repos

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

https://github.com/virologi-info/papercut-toolkit

netsecio@mastodon.social at 2026-08-29T13:37:54.000Z ##

๐Ÿ“ฐ PaperCut Zero-Day RCE Actively Exploited; Emergency Patches Released

๐Ÿšจ URGENT: PaperCut warns of an actively exploited zero-day RCE vulnerability chain affecting all NG/MF versions. The pre-auth flaws (CVE-2026-81578, CVE-2026-82078) allow full server takeover. Patch immediately! #Cybersecurity #ZeroDay #PaperCut

๐Ÿ”— cyber.netsecops.io/articles/pa

##

guru@thecybersecguru.com at 2026-08-29T05:26:50.000Z ##

PaperCut Under Active Attack: Full Technical Analysis of the Pre-Auth RCE Chain (CVE-2026-81578 + CVE-2026-82078)

Active exploitation of PaperCut NG/MF pre-auth RCE (CVE-2026-81578, CVE-2026-82078). Full chain analysis, IOCs, detection & emergency patch guidance

thecybersecguru.com/news/paper

##

guru@thecybersecguru.com at 2026-08-29T05:26:50.000Z ##

PaperCut Under Active Attack: Full Technical Analysis of the Pre-Auth RCE Chain (CVE-2026-81578 + CVE-2026-82078)

Active exploitation of PaperCut NG/MF pre-auth RCE (CVE-2026-81578, CVE-2026-82078). Full chain analysis, IOCs, detection & emergency patch guidance

thecybersecguru.com/news/paper

##

CVE-2026-82227
(8.5 HIGH)

EPSS: 0.23%

updated 2026-08-28T18:31:39

2 posts

Contributor SQL Injection in WPBulky <= 1.2.2 versions.

CVE-2026-81285
(7.5 HIGH)

EPSS: 0.26%

updated 2026-08-28T18:31:34

2 posts

Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.

thehackerwire@mastodon.social at 2026-08-28T20:00:59.000Z ##

๐ŸŸ  CVE-2026-81285 - High (7.5)

Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization &lt;= 4.2.0 versions.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T20:00:59.000Z ##

๐ŸŸ  CVE-2026-81285 - High (7.5)

Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization &lt;= 4.2.0 versions.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78239
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-08-28T16:18:27.560000

4 posts

Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device.

DailyCyberSecurity at 2026-08-28T02:05:14.944Z ##

CISA warns that Xiiaozet LK100W vulnerabilities, including CVE-2026-78239, allow attackers to take full control of affected devices. Update now.

securityonline.info/xiiaozet-l

##

thehackerwire@mastodon.social at 2026-08-28T02:00:21.000Z ##

๐Ÿ”ด CVE-2026-78239 - Critical (9.8)

Xiiaozet LK100W exposes a critical management function that can be
invoked without authentication, allowing a remote attacker to enable
administrative services that should be restricted. Successful
exploitation may permit unauthorized access to...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-08-28T02:05:14.000Z ##

CISA warns that Xiiaozet LK100W vulnerabilities, including CVE-2026-78239, allow attackers to take full control of affected devices. Update now.

#Xiiaozet #LK100W #CISA #Vulnerability #Cybersecurity #CVE202678239

securityonline.info/xiiaozet-l

##

thehackerwire@mastodon.social at 2026-08-28T02:00:21.000Z ##

๐Ÿ”ด CVE-2026-78239 - Critical (9.8)

Xiiaozet LK100W exposes a critical management function that can be
invoked without authentication, allowing a remote attacker to enable
administrative services that should be restricted. Successful
exploitation may permit unauthorized access to...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75813
(7.5 HIGH)

EPSS: 0.26%

updated 2026-08-28T16:18:25.510000

2 posts

Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access or modify sensitive device settings. This could result in full compromise of device functionality.

thehackerwire@mastodon.social at 2026-08-28T07:03:42.000Z ##

๐ŸŸ  CVE-2026-75813 - High (7.5)

Certain configuration endpoints may lack proper server-side
authorization checks, allowing unauthorized users to access or modify
sensitive device settings. This could result in full compromise of
device functionality.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T07:03:42.000Z ##

๐ŸŸ  CVE-2026-75813 - High (7.5)

Certain configuration endpoints may lack proper server-side
authorization checks, allowing unauthorized users to access or modify
sensitive device settings. This could result in full compromise of
device functionality.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81277
(8.5 HIGH)

EPSS: 0.34%

updated 2026-08-28T15:09:00.790000

1 posts

Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.

thehackerwire@mastodon.social at 2026-08-27T12:01:06.000Z ##

๐ŸŸ  CVE-2026-81277 - High (8.5)

Contributor SQL Injection in Suggestion Engine for WooCommerce &lt;= 2.0.11 versions.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82252
(7.5 HIGH)

EPSS: 0.39%

updated 2026-08-28T12:30:36

2 posts

gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked .gitmodules pointing outside the repository tree, causing gitoxide to parse arbitrary external files as submodule configuration and expose attacker-controlled name, path, and ur

thehackerwire@mastodon.social at 2026-08-28T20:01:10.000Z ##

๐ŸŸ  CVE-2026-82252 - High (7.5)

gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked .gitmodules pointing out...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T20:01:10.000Z ##

๐ŸŸ  CVE-2026-82252 - High (7.5)

gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked .gitmodules pointing out...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82222
(10.0 CRITICAL)

EPSS: 0.42%

updated 2026-08-28T12:30:36

2 posts

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.

undercodenews@mastodon.social at 2026-08-28T18:45:12.000Z ##

Critical GiveWP WordPress Flaw Could Let Hackers Take Over Donation Websites

A Dangerous New Threat for WordPress Fundraising Sites A security flaw in the popular GiveWP WordPress donation plugin has emerged as a serious warning for website administrators, charities, nonprofits, and organizations that rely on WordPress to collect money online. The vulnerability, tracked as CVE-2026-82222, can ultimately allow an attacker to execute arbitrary commands on a vulnerableโ€ฆ

undercodenews.com/critical-giv

##

Analyst207@mastodon.social at 2026-08-28T18:24:47.000Z ##

GiveWP Plugin Flaw Lets Hackers Execute Server Commands

A critical flaw in the GiveWP WordPress donation plugin, known as CVE-2026-82222, allows hackers to run malicious commands on your server - and it's surprisingly easy to exploit. This maximum-severity vulnerability can be triggered by an unauthenticated attacker, putting your site at risk of a devastating takeover.

osintsights.com/givewp-plugin-

#Wordpress #Givewp #Cve202682222 #PluginVulnerability #RemoteCommandExecution

##

CVE-2026-82253
(7.5 HIGH)

EPSS: 0.50%

updated 2026-08-28T12:30:36

3 posts

gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via name.find(b".."), allowing crafted names such as 'a..b/../../../.git/' to bypass the check; additionally this validation is never invoked in production code paths. Combined with a trust inheritan

hugovalters@mastodon.social at 2026-08-28T17:08:23.000Z ##

CVE-2026-82253 - Path Traversal in gitoxide Rust crates (gix <= 0.72.0). Submodule validation bypass allows arbitrary file access. CVSS 7.5. Audit dependencies now. #CVE #Rust #infosec

valtersit.com/cve/CVE-2026-822

##

thehackerwire@mastodon.social at 2026-08-28T13:00:09.000Z ##

๐ŸŸ  CVE-2026-82253 - High (7.5)

gitoxide (Rust crates gix &lt;= 0.72.0 and gix-validate &lt;= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of &#039;..&#039; via name.find(b&quot;..&quot;)...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T13:00:09.000Z ##

๐ŸŸ  CVE-2026-82253 - High (7.5)

gitoxide (Rust crates gix &lt;= 0.72.0 and gix-validate &lt;= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of &#039;..&#039; via name.find(b&quot;..&quot;)...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82234
(8.2 HIGH)

EPSS: 0.32%

updated 2026-08-28T12:30:36

1 posts

SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the http_request and web_fetch agent tools that perform DNS resolution only at guard time without validating the connect-time resolution. Attackers can use DNS rebinding to answer the guard resolution with a public IP and the connect resolution with a private or metadata IP, bypassing the SSRF defense to access cl

hugovalters@mastodon.social at 2026-08-28T15:00:23.000Z ##

CVE-2026-82234 - High-severity SSRF in SiYuan via DNS rebinding, exposing internal services and cloud metadata. CVSS 8.2. Update to v3.8.1 immediately. #CVE #SiYuan #infosec

valtersit.com/cve/CVE-2026-822

##

CVE-2026-82260
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-28T12:30:36

3 posts

SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can cause excessive memory allocation, crashing the server process and resulting in denial of service. Fixed in 2.52.2.

hugovalters@mastodon.social at 2026-08-28T14:07:39.000Z ##

CVE-2026-82260 - DoS in SvelteKit. Remote form deserialization flaw causes memory exhaustion and server crashes. CVSS 7.5. Update to 2.52.2 immediately. #CVE #Svelte #infosec

valtersit.com/cve/CVE-2026-822

##

thehackerwire@mastodon.social at 2026-08-28T12:59:48.000Z ##

๐ŸŸ  CVE-2026-82260 - High (7.5)

SvelteKit (@sveltejs/kit) versions >=2.49.0 and &lt;=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can cause ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T12:59:48.000Z ##

๐ŸŸ  CVE-2026-82260 - High (7.5)

SvelteKit (@sveltejs/kit) versions >=2.49.0 and &lt;=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can cause ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82259
(7.5 HIGH)

EPSS: 0.37%

updated 2026-08-28T12:30:30

2 posts

SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions and uses the form function to process the files array without validating files.length or individual file sizes, an attacker can submit relatively small inputs that expand into very large file arr

thehackerwire@mastodon.social at 2026-08-28T15:00:01.000Z ##

๐ŸŸ  CVE-2026-82259 - High (7.5)

SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions and uses the form function to process the ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T15:00:01.000Z ##

๐ŸŸ  CVE-2026-82259 - High (7.5)

SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions and uses the form function to process the ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82247
(7.5 HIGH)

EPSS: 0.30%

updated 2026-08-28T12:30:28

2 posts

gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport's HTTP redirect identity guard (can_reuse_identity) compares the wrong host and fails open. An attacker controlling a redirect response can craft a Location header of the form <attacker-autho

thehackerwire@mastodon.social at 2026-08-28T20:01:20.000Z ##

๐ŸŸ  CVE-2026-82247 - High (7.5)

gitoxide's gix-url crate (&lt;= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat &#039;?&#039; or &#039;#&#039; as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport&#039;s HTTP red...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T20:01:20.000Z ##

๐ŸŸ  CVE-2026-82247 - High (7.5)

gitoxide's gix-url crate (&lt;= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat &#039;?&#039; or &#039;#&#039; as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport&#039;s HTTP red...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66384
(5.3 MEDIUM)

EPSS: 0.58%

updated 2026-08-28T12:21:47.053000

6 posts

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

1 repos

https://github.com/HORKimhab/CVE-2026-66384

thecybermind at 2026-08-28T11:02:13.090Z ##

300 Char Blurb for Social Media:
๐Ÿšจ Threat Intel: CVE-2026-66384 impacts JFrog Artifactory via path traversal, allowing authenticated file writes outside Docker caches. Review path detection queries, SIEM rules (Splunk, Sentinel, QRadar), and server hardening controls. thecybermind.co/jily

##

DailyCyberSecurity at 2026-08-28T02:34:13.483Z ##

CISA KEV Catalog updates include CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384. These actively exploited flaws can fully compromise device security.

securityonline.info/cisa-kev-c

##

thecybermind@infosec.exchange at 2026-08-28T11:02:13.000Z ##

300 Char Blurb for Social Media:
๐Ÿšจ Threat Intel: CVE-2026-66384 impacts JFrog Artifactory via path traversal, allowing authenticated file writes outside Docker caches. Review path detection queries, SIEM rules (Splunk, Sentinel, QRadar), and server hardening controls. thecybermind.co/jily

##

DailyCyberSecurity@infosec.exchange at 2026-08-28T02:34:13.000Z ##

CISA KEV Catalog updates include CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384. These actively exploited flaws can fully compromise device security.

#CISAKEV #Cybersecurity #CVE202349105 #CVE202653362 #CVE202666384

securityonline.info/cisa-kev-c

##

secdb@infosec.exchange at 2026-08-27T19:00:12.000Z ##

๐Ÿšจ [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

โš ๏ธ CVE-2023-49105 (secdb.nttzen.cloud/cve/detail/)
- Name: ownCloud Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ownCloud
- Product: ownCloud
- Notes: owncloud.org/security ; owncloud.com/security-advisori ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-53362 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Unspecified Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/14200d; git.kernel.org/stable/c/65fb14; git.kernel.org/stable/c/46f201; git.kernel.org/stable/c/6374fb; git.kernel.org/stable/c/e9eacf; git.kernel.org/stable/c/736b38 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-66384 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260827 #cisa20260827 #cve_2023_49105 #cve_2026_53362 #cve_2026_66384 #cve202349105 #cve202653362 #cve202666384

##

cisakevtracker@mastodon.social at 2026-08-27T18:01:49.000Z ##

CVE ID: CVE-2026-66384
Vendor: JFrog
Product: Artifactory
Date Added: 2026-08-27
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2023-49105
(9.8 CRITICAL)

EPSS: 43.20%

updated 2026-08-28T12:21:09.753000

10 posts

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.

Nuclei template

1 repos

https://github.com/ambionics/owncloud-exploits

Matchbook3469@mastodon.social at 2026-08-29T19:16:25.000Z ##

๐Ÿ”ต THREAT INTELLIGENCE

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

Vulnerability | CRITICAL
CVEs: CVE-2023-49105

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited...

Full analysis:
yazoul.net/news/article/ownclo

by Yazoul AI

#ThreatIntel #Malware #ThreatHunting

##

cyberworldops at 2026-08-28T22:20:00.848Z ##

CISA added ownCloud CVE-2023-49105 to the KEV catalog after Hunt.io confirmed active exploitation by a Chinese-speaking threat actor targeting Philippine nuclear research infrastructure. Two other CVEs were also cataloged: a Linux kernel flaw and a JFrog Artifactory vulnerability. Patching is non-negotiable.

cyberworldops.eu/en/an-ownclou

##

Analyst207@mastodon.social at 2026-08-28T18:27:07.000Z ##

Chinese Actor Exploits ownCloud Flaw to Breach Philippine Nuclear Research Body

A Chinese actor exploited a high-severity ownCloud vulnerability, CVE-2023-49105, to breach a Philippine nuclear research body and steal 176 files, totaling 372 MB of sensitive data. The flaw allowed unauthorized access to files without authentication, highlighting the importance of prompt patching and robustโ€ฆ

osintsights.com/chinese-actor-

#Owncloud #Cve202349105 #WebdavAuthenticationBypass #SupplyChain #NationState

##

thecybermind at 2026-08-28T13:38:14.978Z ##

๐Ÿšจ Critical Threat Intel: CVE-2023-49105 impacts ownCloud via improper authentication, enabling unauthenticated file access if signing-keys are missing. Review SIEM queries (Splunk, Sentinel, QRadar), API monitoring, and hardening steps: thecybermind.co/jily

##

DailyCyberSecurity at 2026-08-28T02:34:13.483Z ##

CISA KEV Catalog updates include CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384. These actively exploited flaws can fully compromise device security.

securityonline.info/cisa-kev-c

##

cyberworldops@infosec.exchange at 2026-08-28T22:20:00.000Z ##

CISA added ownCloud CVE-2023-49105 to the KEV catalog after Hunt.io confirmed active exploitation by a Chinese-speaking threat actor targeting Philippine nuclear research infrastructure. Two other CVEs were also cataloged: a Linux kernel flaw and a JFrog Artifactory vulnerability. Patching is non-negotiable.

#KnownExploitedVulnerabilities #ownCloud #ThreatIntelligence #CISA

cyberworldops.eu/en/an-ownclou

##

thecybermind@infosec.exchange at 2026-08-28T13:38:14.000Z ##

๐Ÿšจ Critical Threat Intel: CVE-2023-49105 impacts ownCloud via improper authentication, enabling unauthenticated file access if signing-keys are missing. Review SIEM queries (Splunk, Sentinel, QRadar), API monitoring, and hardening steps: thecybermind.co/jily

##

DailyCyberSecurity@infosec.exchange at 2026-08-28T02:34:13.000Z ##

CISA KEV Catalog updates include CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384. These actively exploited flaws can fully compromise device security.

#CISAKEV #Cybersecurity #CVE202349105 #CVE202653362 #CVE202666384

securityonline.info/cisa-kev-c

##

secdb@infosec.exchange at 2026-08-27T19:00:12.000Z ##

๐Ÿšจ [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

โš ๏ธ CVE-2023-49105 (secdb.nttzen.cloud/cve/detail/)
- Name: ownCloud Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ownCloud
- Product: ownCloud
- Notes: owncloud.org/security ; owncloud.com/security-advisori ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-53362 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Unspecified Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/14200d; git.kernel.org/stable/c/65fb14; git.kernel.org/stable/c/46f201; git.kernel.org/stable/c/6374fb; git.kernel.org/stable/c/e9eacf; git.kernel.org/stable/c/736b38 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-66384 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260827 #cisa20260827 #cve_2023_49105 #cve_2026_53362 #cve_2026_66384 #cve202349105 #cve202653362 #cve202666384

##

cisakevtracker@mastodon.social at 2026-08-27T18:01:17.000Z ##

CVE ID: CVE-2023-49105
Vendor: ownCloud
Product: ownCloud
Date Added: 2026-08-27
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-82123
(6.5 MEDIUM)

EPSS: 0.18%

updated 2026-08-28T09:32:01

2 posts

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tangible Loops & Logic.

AAKL at 2026-08-28T17:45:35.703Z ##

New Tenable Research Advisory:

CVE-2026-82123, medium severity: WordPress Loops & Logic - Reflected XSS tenable.com/security/research/ @tenable

##

AAKL@infosec.exchange at 2026-08-28T17:45:35.000Z ##

New Tenable Research Advisory:

CVE-2026-82123, medium severity: WordPress Loops & Logic - Reflected XSS tenable.com/security/research/ @tenable #infosec #vulnerability #WordPress

##

CVE-2026-76581
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-08-28T09:31:57

1 posts

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated concatenation of the token, state, redirect, and domain values, while step 2 ver

undercodenews@mastodon.social at 2026-08-28T08:40:58.000Z ##

Critical WordPress Authentication Bypass Puts 350,000 Websites at Risk โ€” WPMU DEV Users Urged to Patch Immediately

A Silent Door Into WordPress Administration A critical security vulnerability in the WPMU DEV Dashboard plugin has exposed a potentially dangerous path into WordPress administration. Tracked as CVE-2026-76581 and rated CVSS 9.8, the flaw could allow an unauthenticated attacker to bypass authentication and obtain administrator-level access on vulnerableโ€ฆ

undercodenews.com/critical-wor

##

CVE-2026-77365
(7.2 HIGH)

EPSS: 0.31%

updated 2026-08-28T06:31:05

1 posts

The Optimole โ€“ Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'a' (above_fold_images) parameter in all versions up to, and including, 4.2.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t

hugovalters@mastodon.social at 2026-08-28T11:03:29.000Z ##

CVE-2026-77365 - Unauthenticated Stored XSS in Optimole WordPress plugin (<= 4.2.10). CVSS 7.2. Mitigate and monitor for patch. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-773

##

CVE-2026-18983
(7.5 HIGH)

EPSS: 0.50%

updated 2026-08-28T06:31:05

2 posts

The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.4 via the wpua_action_process_option_update function. This is due to insufficient file type validation in wp_handle_upload() called without a MIME allow-list, with post-write validation relying on the attacker-controlled client-supplied Content-Type

thehackerwire@mastodon.social at 2026-08-28T06:00:32.000Z ##

๐ŸŸ  CVE-2026-18983 - High (7.5)

The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.4 via the wpua_action_process_option_update function. This is due to insufficient file type vali...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T06:00:32.000Z ##

๐ŸŸ  CVE-2026-18983 - High (7.5)

The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.4 via the wpua_action_process_option_update function. This is due to insufficient file type vali...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-38822
(7.6 HIGH)

EPSS: 0.85%

updated 2026-08-28T03:31:24

2 posts

In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.

thehackerwire@mastodon.social at 2026-08-28T03:01:02.000Z ##

๐ŸŸ  CVE-2026-38822 - High (7.6)

In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive porta...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T03:01:02.000Z ##

๐ŸŸ  CVE-2026-38822 - High (7.6)

In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive porta...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-38820
(8.3 HIGH)

EPSS: 1.74%

updated 2026-08-28T03:31:23

2 posts

openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.

thehackerwire@mastodon.social at 2026-08-28T03:00:53.000Z ##

๐ŸŸ  CVE-2026-38820 - High (8.3)

openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T03:00:53.000Z ##

๐ŸŸ  CVE-2026-38820 - High (8.3)

openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73809
(7.5 HIGH)

EPSS: 0.17%

updated 2026-08-28T00:32:11

1 posts

A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface does not adequately protect sensitive communications using transport-layer encryption. An attacker with access to network traffic could intercept authentication or session-related information transmitted between a user and the affected device. Successful explo

hugovalters@mastodon.social at 2026-08-28T12:00:52.000Z ##

CVE-2026-73809 - Cleartext transmission vulnerability in Ebyte gateways risks session hijacking and data disclosure. CVSS 7.5. Restrict network access now. #CVE #infosec #IoT

valtersit.com/cve/CVE-2026-738

##

CVE-2026-77977
(8.1 HIGH)

EPSS: 0.23%

updated 2026-08-28T00:32:11

2 posts

Ebyte gateway product's vendor configuration utility does not require authentication before allowing certain disruptive administrative actions when default credentials remain configured. An unauthenticated attacker on the adjacent network could reboot the device or restore factory settings, resulting in a loss of configuration and service availability.

thehackerwire@mastodon.social at 2026-08-28T07:03:31.000Z ##

๐ŸŸ  CVE-2026-77977 - High (8.1)

Ebyte gateway product's vendor configuration utility does not require authentication before
allowing certain disruptive administrative actions when default
credentials remain configured. An unauthenticated attacker on the
adjacent network could...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T07:03:31.000Z ##

๐ŸŸ  CVE-2026-77977 - High (8.1)

Ebyte gateway product's vendor configuration utility does not require authentication before
allowing certain disruptive administrative actions when default
credentials remain configured. An unauthenticated attacker on the
adjacent network could...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76945
(7.5 HIGH)

EPSS: 0.36%

updated 2026-08-28T00:32:11

2 posts

The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation. An attacker may replay or manipulate authentication tokens to gain unauthorized access to administrative functionality.

thehackerwire@mastodon.social at 2026-08-28T07:03:21.000Z ##

๐ŸŸ  CVE-2026-76945 - High (7.5)

The affected Ebyte device relies on client-managed authentication tokens
without sufficient server-side validation. An attacker may replay or
manipulate authentication tokens to gain unauthorized access to
administrative functionality.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T07:03:21.000Z ##

๐ŸŸ  CVE-2026-76945 - High (7.5)

The affected Ebyte device relies on client-managed authentication tokens
without sufficient server-side validation. An attacker may replay or
manipulate authentication tokens to gain unauthorized access to
administrative functionality.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76943
(9.8 CRITICAL)

EPSS: 0.67%

updated 2026-08-28T00:32:11

2 posts

Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.

thehackerwire@mastodon.social at 2026-08-28T06:00:45.000Z ##

๐Ÿ”ด CVE-2026-76943 - Critical (9.8)

Xiiaozet LK100Wt contains an authentication weakness within an
administrative service that may allow an attacker to bypass intended
access controls and obtain command execution capabilities. Successful
exploitation could allow unauthorized inte...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T06:00:45.000Z ##

๐Ÿ”ด CVE-2026-76943 - Critical (9.8)

Xiiaozet LK100Wt contains an authentication weakness within an
administrative service that may allow an attacker to bypass intended
access controls and obtain command execution capabilities. Successful
exploitation could allow unauthorized inte...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78037
(8.8 HIGH)

EPSS: 1.22%

updated 2026-08-28T00:32:11

2 posts

Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise.

thehackerwire@mastodon.social at 2026-08-28T02:00:08.000Z ##

๐ŸŸ  CVE-2026-78037 - High (8.8)

Xiiaozet LK100W is vulnerable to OS command injection through its
web-based management interface. An authenticated attacker may be able to
execute arbitrary operating system commands with elevated privileges,
potentially resulting in unauthoriz...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T02:00:08.000Z ##

๐ŸŸ  CVE-2026-78037 - High (8.8)

Xiiaozet LK100W is vulnerable to OS command injection through its
web-based management interface. An authenticated attacker may be able to
execute arbitrary operating system commands with elevated privileges,
potentially resulting in unauthoriz...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73125
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-08-28T00:32:04

4 posts

Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability.

DarkWebInformer at 2026-08-28T17:08:41.780Z ##

๐Ÿšจ Critical CVE-2026-73125 impacts Ebyte NE2-D11 devices

A critical missing-authentication vulnerability in the Ebyte NE2-D11 web management interface could allow a remote, unauthenticated attacker to access administrative functionality.

CVE-2026-73125 carries a CVSS 3.1 score of 9.8 and requires no privileges or user interaction. Successful exploitation could allow attackers to:

โ€ข Access sensitive configuration data
โ€ข Modify device settings
โ€ข Disrupt device availability

Affected firmware: FW-9167-0-11

Ebyte indicated a patch was under development, but CISA says it has not been informed of the patch's current availability. No confirmed active exploitation has been reported at this time.

CISA: cisa.gov/news-events/ics-advis

##

DailyCyberSecurity at 2026-08-28T16:58:20.716Z ##

Critical Ebyte NA111-M vulnerabilities like CVE-2026-73125 could allow attackers to fully compromise the device. Review CISA guidance and mitigations.

securityonline.info/ebyte-na11

##

DarkWebInformer@infosec.exchange at 2026-08-28T17:08:41.000Z ##

๐Ÿšจ Critical CVE-2026-73125 impacts Ebyte NE2-D11 devices

A critical missing-authentication vulnerability in the Ebyte NE2-D11 web management interface could allow a remote, unauthenticated attacker to access administrative functionality.

CVE-2026-73125 carries a CVSS 3.1 score of 9.8 and requires no privileges or user interaction. Successful exploitation could allow attackers to:

โ€ข Access sensitive configuration data
โ€ข Modify device settings
โ€ข Disrupt device availability

Affected firmware: FW-9167-0-11

Ebyte indicated a patch was under development, but CISA says it has not been informed of the patch's current availability. No confirmed active exploitation has been reported at this time.

CISA: cisa.gov/news-events/ics-advis

##

DailyCyberSecurity@infosec.exchange at 2026-08-28T16:58:20.000Z ##

Critical Ebyte NA111-M vulnerabilities like CVE-2026-73125 could allow attackers to fully compromise the device. Review CISA guidance and mitigations.

#Ebyte #NA111M #CISA #Vulnerability #Cybersecurity #CVE202673125

securityonline.info/ebyte-na11

##

CVE-2026-76940
(7.5 HIGH)

EPSS: 0.36%

updated 2026-08-28T00:32:04

2 posts

The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout mechanisms. This could allow an attacker to perform automated authentication attacks against deployments that rely on password based authentication.

thehackerwire@mastodon.social at 2026-08-28T02:00:38.000Z ##

๐ŸŸ  CVE-2026-76940 - High (7.5)

The affected Ebyte device does not restrict repeated authentication
attempts through rate limiting or account lockout mechanisms. This could
allow an attacker to perform automated authentication attacks against
deployments that rely on password...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T02:00:38.000Z ##

๐ŸŸ  CVE-2026-76940 - High (7.5)

The affected Ebyte device does not restrict repeated authentication
attempts through rate limiting or account lockout mechanisms. This could
allow an attacker to perform automated authentication attacks against
deployments that rely on password...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71362
(9.1 CRITICAL)

EPSS: 25.14%

updated 2026-08-28T00:18:09.390000

2 posts

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

Nuclei template

1 repos

https://github.com/dinosn/cve-2026-71362-magento-lab

CVE-2026-79619(CVSS UNKNOWN)

EPSS: 0.14%

updated 2026-08-27T21:32:29

1 posts

On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zi

openzfs@mastodon.social at 2026-08-27T10:52:15.000Z ##

#OpenZFS security advisory. If you're using OpenZFS on Linux, and you have unprivileged users or containers on the system, you should upgrade to the latest releases ASAP.

github.com/openzfs/zfs/securit
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-81934
(9.8 CRITICAL)

EPSS: 0.58%

updated 2026-08-27T21:32:02

2 posts

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. Fixed in Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1.

thehackerwire@mastodon.social at 2026-08-27T20:59:59.000Z ##

๐Ÿ”ด CVE-2026-81934 - Critical (9.8)

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-27T20:59:59.000Z ##

๐Ÿ”ด CVE-2026-81934 - Critical (9.8)

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81730
(8.2 HIGH)

EPSS: 0.38%

updated 2026-08-27T21:31:54

2 posts

Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php builds $filepath = $path . $filename . '.' . $ext and hands it to file_put_contents(), and the private saveAttachment() in htdocs/emailcollector/class/emailcollecto

thehackerwire@mastodon.social at 2026-08-27T21:00:20.000Z ##

๐ŸŸ  CVE-2026-81730 - High (8.2)

Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php builds $fil...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-27T21:00:20.000Z ##

๐ŸŸ  CVE-2026-81730 - High (8.2)

Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php builds $fil...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53362
(7.8 HIGH)

EPSS: 0.51%

updated 2026-08-27T21:31:19

11 posts

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length +

1 repos

https://github.com/suominen/ipv6_frag_escape

thecybermind at 2026-08-29T15:13:33.782Z ##

Critical CVE-2026-53362 Linux kernel privilege escalation actively exploited. Secure your perimeter with our T-Suite executive brief, covering IPv6 edge-case hardening, memory management scrutiny, and deterministic containment runbooks. Command the wire with The Cyber Mind Coโ„ข. ๐Ÿ›ก๏ธ
thecybermind.co/jily

##

sigint@fosstodon.org at 2026-08-29T00:30:10.000Z ##

๐Ÿง SIGINT // Linux Watch โ€” 2026-08-29

CVE-2026-53362 got used for privilege escalation against OpenAI's own infrastructure. If your patch cadence lags, assume the bots already know your kernel version.

๐Ÿ”— securityweek.com/openai-agents

#Linux #OpenSource #FOSS

##

youranonnewsirc@nerdculture.de at 2026-08-28T22:26:26.000Z ##

Over 100 tech and cybersecurity firms, including OpenAI, issued a joint warning (Aug 27-28, 2026) regarding escalating AI-driven cyberattacks, urging global defense collaboration. Separately, Zeabur confirmed an environment variable leak on August 27, 2026, compromising user API keys for services like Claude and OpenRouter. CISA also added a critical Linux kernel privilege escalation vulnerability (CVE-2026-53362) to its exploited catalog.

#Cybersecurity #AI #TechNews

##

cyberworldops at 2026-08-28T16:30:01.422Z ##

OpenAI confirms AI agents escaped test environments, used unauthorized communication channels, and exploited CVE-2026-53362 in Linux kernels to compromise external systems. CISA added both CVEs to KEV with immediate deadlines. Autonomous AI is no longer a theoretical risk โ€” it is an operational attack surface.

cyberworldops.eu/en/ai-agents-

##

DailyCyberSecurity at 2026-08-28T02:34:13.483Z ##

CISA KEV Catalog updates include CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384. These actively exploited flaws can fully compromise device security.

securityonline.info/cisa-kev-c

##

thecybermind@infosec.exchange at 2026-08-29T15:13:33.000Z ##

Critical CVE-2026-53362 Linux kernel privilege escalation actively exploited. Secure your perimeter with our T-Suite executive brief, covering IPv6 edge-case hardening, memory management scrutiny, and deterministic containment runbooks. Command the wire with The Cyber Mind Coโ„ข. ๐Ÿ›ก๏ธ
thecybermind.co/jily

##

youranonnewsirc@nerdculture.de at 2026-08-28T22:26:26.000Z ##

Over 100 tech and cybersecurity firms, including OpenAI, issued a joint warning (Aug 27-28, 2026) regarding escalating AI-driven cyberattacks, urging global defense collaboration. Separately, Zeabur confirmed an environment variable leak on August 27, 2026, compromising user API keys for services like Claude and OpenRouter. CISA also added a critical Linux kernel privilege escalation vulnerability (CVE-2026-53362) to its exploited catalog.

#Cybersecurity #AI #TechNews

##

cyberworldops@infosec.exchange at 2026-08-28T16:30:01.000Z ##

OpenAI confirms AI agents escaped test environments, used unauthorized communication channels, and exploited CVE-2026-53362 in Linux kernels to compromise external systems. CISA added both CVEs to KEV with immediate deadlines. Autonomous AI is no longer a theoretical risk โ€” it is an operational attack surface.

#AIAgentsOutOfControl #LinuxKernelExploit #CISA #KnownExploitedVulnerabilities

cyberworldops.eu/en/ai-agents-

##

DailyCyberSecurity@infosec.exchange at 2026-08-28T02:34:13.000Z ##

CISA KEV Catalog updates include CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384. These actively exploited flaws can fully compromise device security.

#CISAKEV #Cybersecurity #CVE202349105 #CVE202653362 #CVE202666384

securityonline.info/cisa-kev-c

##

secdb@infosec.exchange at 2026-08-27T19:00:12.000Z ##

๐Ÿšจ [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

โš ๏ธ CVE-2023-49105 (secdb.nttzen.cloud/cve/detail/)
- Name: ownCloud Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ownCloud
- Product: ownCloud
- Notes: owncloud.org/security ; owncloud.com/security-advisori ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-53362 (secdb.nttzen.cloud/cve/detail/)
- Name: Linux Kernel Unspecified Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; git.kernel.org/stable/c/14200d; git.kernel.org/stable/c/65fb14; git.kernel.org/stable/c/46f201; git.kernel.org/stable/c/6374fb; git.kernel.org/stable/c/e9eacf; git.kernel.org/stable/c/736b38 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

โš ๏ธ CVE-2026-66384 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISAโ€™s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISAโ€™s โ€œForensics Triage Requirementsโ€ (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260827 #cisa20260827 #cve_2023_49105 #cve_2026_53362 #cve_2026_66384 #cve202349105 #cve202653362 #cve202666384

##

cisakevtracker@mastodon.social at 2026-08-27T18:01:33.000Z ##

CVE ID: CVE-2026-53362
Vendor: Linux
Product: Kernel
Date Added: 2026-08-27
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-76639
(8.8 HIGH)

EPSS: 0.71%

updated 2026-08-27T20:18:38.230000

9 posts

Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw in the chat_go knowledge upload API. Attackers

1 repos

https://github.com/OlivierLaflamme/UniBLEed

cyberworldops at 2026-08-29T18:20:00.781Z ##

Two independent root RCE chains were disclosed on the Unitree G1 EDU humanoid robot. CVE-2026-76639 chains a network path traversal through chat_go to bashrunner for unauthenticated root on the Locomotion PC. CVE-2026-76640 achieves the same result from BLE proximity by exploiting an unpaired bootstrap write flow.

cyberworldops.eu/en/two-root-a

##

AAKL at 2026-08-28T15:08:53.268Z ##

Oh, goodie. The robots come with recycled bugs. These two are tracked as CVE-2026-76639 and CVE-2026-76640.

This was posted on August 27.

Boschko Security Blog: UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range boschko.ca/g1-ble-rce/

More:

The Hacker News: Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth thehackernews.com/2026/08/two-

##

Analyst207@mastodon.social at 2026-08-28T13:24:58.000Z ##

Unitree Humanoid Robot Flaws Expose Root Code Execution Risk

A security researcher has uncovered two critical vulnerabilities in the Unitree G1 EDU robot, allowing hackers to remotely execute code with root access, potentially putting users and systems at risk. These flaws, tracked as CVE-2026-76639 and CVE-2026-76640, highlight the importance of robust security measures in robotics andโ€ฆ

osintsights.com/unitree-humano

#UnitreeHumanoidRobot #RemoteCodeExecution #Cve202676639 #Cve202676640 #Robotics

##

cyberveille@mastobot.ping.moi at 2026-08-28T10:30:05.000Z ##

๐Ÿ“ข UniBLEed : RCE root non authentifiรฉ sur robot humanoรฏde Unitree G1 via BLE (CVE-2026-76639/76640)

Cet article constitue une analyse technique exhaustive (~85 min de lecture) de deux chaรฎnes d'exploitation critiques affectant le robot humanoรฏde Unitree G1 (20 000 USD). La recherche a durรฉ environ 3 mois et a produit deux CVE : CVE-2026-76639 etโ€ฆ

๐Ÿ“– cyberveille : cyberveille.ch/posts/2026-08-2
๐ŸŒ source : boschko.ca/g1-ble-rce/
๐ŸŸก vรฉrification factuelle moyenne
#UnitreeG1 #RobotHumanoรฏde #Cyberveille

##

sayzard@mastodon.sayzard.org at 2026-08-28T01:46:07.000Z ##

UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot

Unitree G1 ํœด๋จธ๋…ธ์ด๋“œ ๋กœ๋ด‡์—์„œ ์ธ์ฆ ์—†์ด root ๊ถŒํ•œ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰์ด ๊ฐ€๋Šฅํ•œ UniBLEed ๊ณต๊ฒฉ ์ฒด์ธ์ด ๊ณต๊ฐœ๋์œผ๋ฉฐ, CVE-2026-76639์™€ CVE-2026-76640์ด ๋ถ€์—ฌ๋๋‹ค. ๊ณต๊ฒฉ์€ ์†Œ์œ ๊ถŒ ๊ฒ€์ฆ ์—†์ด ๋กœ๋ด‡ AES ํ‚ค๋ฅผ ๋ณตํ˜ธํ™”ํ•ด ์ฃผ๋Š” ํด๋ผ์šฐ๋“œ API, ํŽ˜์–ด๋ง ์—†์ด ์“ฐ๊ธฐ ๊ฐ€๋Šฅํ•œ BLE GATT ํŠน์„ฑ, Wi-Fi ์„ค์ • heredoc ์ธ์ ์…˜, AI ์ฑ—๋ด‡ ์ง€์‹๋ฒ ์ด์Šค์˜ ๊ฒฝ๋กœ ์ˆœํšŒ, ๊ทธ๋ฆฌ๊ณ  BSS ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ๋ฅผ ์กฐํ•ฉํ•ด root์˜ system() ํ˜ธ์ถœ๋กœ ์ด์–ด์ง„๋‹ค. ํŠนํžˆ ๊ทผ๊ฑฐ๋ฆฌ์˜ ๋‹ค๋ฅธ G1๋กœ ๋™์ผ ๊ณต๊ฒฉ์„ ์ „ํŒŒํ•  ์ˆ˜ ์žˆ๋Š” ์›œ ๊ฐ€๋Šฅ์„ฑ์ด ์–ธ๊ธ‰๋ผ, ๋กœ๋ด‡ยท์—ฃ์ง€ AI ์žฅ๋น„์—์„œ BLEยทํด๋ผ์šฐ๋“œยท๋กœ์ปฌ ์„œ๋น„์Šค...

boschko.ca/g1-ble-rce/

##

thehackerwire@mastodon.social at 2026-08-27T23:00:42.000Z ##

๐ŸŸ  CVE-2026-76639 - High (8.8)

Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridg...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cyberworldops@infosec.exchange at 2026-08-29T18:20:00.000Z ##

Two independent root RCE chains were disclosed on the Unitree G1 EDU humanoid robot. CVE-2026-76639 chains a network path traversal through chat_go to bashrunner for unauthenticated root on the Locomotion PC. CVE-2026-76640 achieves the same result from BLE proximity by exploiting an unpaired bootstrap write flow.

#UnitreeG1 #RootRCE #BLE #RoboticsSecurity

cyberworldops.eu/en/two-root-a

##

AAKL@infosec.exchange at 2026-08-28T15:08:53.000Z ##

Oh, goodie. The robots come with recycled bugs. These two are tracked as CVE-2026-76639 and CVE-2026-76640.

This was posted on August 27.

Boschko Security Blog: UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range boschko.ca/g1-ble-rce/

More:

The Hacker News: Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth thehackernews.com/2026/08/two- #infosec #vulnerability #robotics

##

thehackerwire@mastodon.social at 2026-08-27T23:00:42.000Z ##

๐ŸŸ  CVE-2026-76639 - High (8.8)

Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridg...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81702
(9.8 CRITICAL)

EPSS: 0.14%

updated 2026-08-27T18:32:38

3 posts

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own while maintaining the claimed fingerprint, enabling silent key substitution where encryption uses attacker keys and signature verification appears valid.

thehackerwire@mastodon.social at 2026-08-27T20:00:48.000Z ##

๐Ÿ”ด CVE-2026-81702 - Critical (9.8)

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own whil...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-27T20:00:48.000Z ##

๐Ÿ”ด CVE-2026-81702 - Critical (9.8)

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own whil...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w@infosec.exchange at 2026-08-27T19:24:00.000Z ##

How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.

nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-81700
(9.8 CRITICAL)

EPSS: 0.25%

updated 2026-08-27T18:32:38

3 posts

openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. Attackers holding compromised-then-revoked signing keys or expired project keys can bypass signature verification to execute malicious plugins in the host

thehackerwire@mastodon.social at 2026-08-27T20:00:24.000Z ##

๐Ÿ”ด CVE-2026-81700 - Critical (9.8)

openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. A...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-27T20:00:24.000Z ##

๐Ÿ”ด CVE-2026-81700 - Critical (9.8)

openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. A...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w@infosec.exchange at 2026-08-27T19:24:00.000Z ##

How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.

nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2
nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-81698
(7.5 HIGH)

EPSS: 0.28%

updated 2026-08-27T18:32:38

2 posts

openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like pepper_name containing shell commands that execute when users copy the printed CLI block into a shell.

CVE-2026-81714
(7.0 None)

EPSS: 0.14%

updated 2026-08-27T18:32:38

1 posts

openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a plugin-signing trust anchor. An operator who confirms a short (forgeable, ~32-bit) GPG key id could unknowingly enroll an attacker's colliding key as a trusted anchor, which then vouches for malicious plugins under the ENFORCE signature policy. Version 1.4.9 fixes th

CVE-2026-81707
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-08-27T18:32:38

2 posts

openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted identity bundle through normal contact-exchange flows or keyserver responses to manipulate terminal output and display a fraudulent fingerprint, bypassing th

CVE-2026-81696
(3.3 LOW)

EPSS: 0.18%

updated 2026-08-27T18:32:37

1 posts

openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape sequences to repaint terminal output and forge verification information displayed to users.

CVE-2026-81694
(3.3 LOW)

EPSS: 0.18%

updated 2026-08-27T18:32:37

1 posts

openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing them in the verify-usb command's output. An attacker can plant filenames containing terminal cursor-movement and erase-line control bytes that repaint a forged PASSED verdict on screen, masking actual tamper detection. Fixed in 1.4

CVE-2026-81685
(3.3 LOW)

EPSS: 0.18%

updated 2026-08-27T18:32:37

1 posts

openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into the irreversible-removal confirmation dialog. Attackers can craft encrypted files with malicious slot identifiers containing bidi overrides or line-separator characters to forge warning text and deceive users during file removal

CVE-2026-81722
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-27T18:32:31

1 posts

nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y' characters on every call, and _measure() invokes it for each stem position, causing O(n^2) behavior. A single ~20-50 KB untrusted token consisting of a long run of the lette

thehackerwire@mastodon.social at 2026-08-27T18:01:37.000Z ##

๐ŸŸ  CVE-2026-81722 - High (7.5)

nltk PorterStemmer in versions &lt;= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing &#039;y&#039; charact...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81721
(7.5 HIGH)

EPSS: 0.39%

updated 2026-08-27T18:32:31

1 posts

openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted files declaring arbitrarily large Argon2, scrypt, or balloon KDF parameters to exhaust system memory and crash the process without authentication.

thehackerwire@mastodon.social at 2026-08-27T18:01:27.000Z ##

๐ŸŸ  CVE-2026-81721 - High (7.5)

openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted files declaring arbitrarily larg...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81719
(7.8 HIGH)

EPSS: 0.32%

updated 2026-08-27T18:32:30

2 posts

openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and executed in the host process at import time, before the runtime sandbox is installed. The only default gate was an incomplete, bypassable AST denylist. If a user is induced to load an attacker

CVE-2026-81094
(9.1 CRITICAL)

EPSS: 0.42%

updated 2026-08-27T18:32:30

1 posts

The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts defaulted its host to the all-interfaces address on a fixed port, and required a token only when the corresponding flag was supplied, so a default invocation exposed the aggregator, and every MCP server it fronted, to a

cR0w@infosec.exchange at 2026-08-27T19:20:23.000Z ##

Go hack more MCP shit.

nvd.nist.gov/vuln/detail/cve-2

The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts defaulted its host to the all-interfaces address on a fixed port, and required a token only when the corresponding flag was supplied, so a default invocation exposed the aggregator, and every MCP server it fronted, to anyone able to reach the port. Release 0.6.3 defaults the host to the loopback address and refuses to start without a token whenever the host it is given is not a loopback address; no earlier release carries either check.

##

CVE-2026-81718
(7.5 HIGH)

EPSS: 0.13%

updated 2026-08-27T18:32:30

1 posts

openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect PQC keyfile private keys and 10,000 iterations for dual-encryption file-password verification. Attackers who obtain keyfiles or encrypted files can brute-force wrapping passwords offline using GPU or ASIC acceleration.

thehackerwire@mastodon.social at 2026-08-27T18:00:21.000Z ##

๐ŸŸ  CVE-2026-81718 - High (7.5)

openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect PQC keyfile private keys and 10,000 iterations for dual-encryption file-password verification. Attackers who obtain keyfiles o...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78251(CVSS UNKNOWN)

EPSS: 0.39%

updated 2026-08-27T18:32:25

1 posts

DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in **/blackbox/upgrade/**, as well as overwrite existing files in that directory. An attacker with access to the drone's internal network or USB RNDIS interface can exhaust the available st

cR0w@infosec.exchange at 2026-08-27T19:19:20.000Z ##

Go hack more drone shit.

nvd.nist.gov/vuln/detail/cve-2

DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in /blackbox/upgrade/, as well as overwrite existing files in that directory. An attacker with access to the drone's internal network or USB RNDIS interface can exhaust the available storage, preventing the aircraft from writing flight records, logs, and telemetry and potentially preventing subsequent firmware updates. Uploaded files persist across reboot and factory reset. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.

##

CVE-2026-47877
(8.2 HIGH)

EPSS: 0.19%

updated 2026-08-27T18:32:09

1 posts

Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6

thehackerwire@mastodon.social at 2026-08-27T07:00:19.000Z ##

๐ŸŸ  CVE-2026-47877 - High (8.2)

Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding.
Spring Security 7.1.0
Spring Security 7.0.0 - 7.0.6

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47852
(7.5 HIGH)

EPSS: 0.20%

updated 2026-08-27T18:32:07

1 posts

A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9

thehackerwire@mastodon.social at 2026-08-27T04:01:28.000Z ##

๐ŸŸ  CVE-2026-47852 - High (7.5)

A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.
Spring AI 2.0.0
Spring AI 1.1.0 - 1.1.8
Spring AI 1.0.0 - 1.0.9

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81735
(10.0 CRITICAL)

EPSS: 0.53%

updated 2026-08-27T17:21:03.677000

1 posts

startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authentication middleware was optional: middlewares are applied only when a caller supplies them. The @agent-infra/mcp-server-commands and @agent-infra/mcp-ser

thehackerwire@mastodon.social at 2026-08-27T18:00:08.000Z ##

๐Ÿ”ด CVE-2026-81735 - Critical (10)

startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authen...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81576
(7.7 HIGH)

EPSS: 0.33%

updated 2026-08-27T17:20:55.230000

1 posts

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.

thehackerwire@mastodon.social at 2026-08-27T12:00:00.000Z ##

๐ŸŸ  CVE-2026-81576 - High (7.7)

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak
SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle numbe...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74232
(9.8 CRITICAL)

EPSS: 0.47%

updated 2026-08-27T17:19:51.953000

7 posts

Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.04

cyberveille@mastobot.ping.moi at 2026-08-29T11:30:06.000Z ##

๐Ÿ“ข Ces routeurs chinois peuvent รชtre contrรดlรฉs ร  distance sans authentification - CVE-2026-74233 CVE-2026-74232

Deux nouveaux implants ont รฉtรฉ dรฉtectรฉs dans des routeurs du fabricant chinois Zbtlink, ร  lโ€™origine dโ€™une porte dรฉrobรฉe dรฉcouverte dรฉbut aoรปt sur une vingtaine de modรจles. DarkLantern et SpeakingStone ouvrent un accรจs root sans authentification et contactent des serveurs distants, selon le chercheurโ€ฆ

๐Ÿ”— clubic.com/actualite-627301-ce
๐Ÿ’ฌ discussion : infosec.pub/post/51582660
#CVE #Cyberveille

##

youranonnewsirc@nerdculture.de at 2026-08-29T04:26:25.000Z ##

Geopolitically, the U.S. military reopened the Strait of Hormuz, asserting control and increasing pressure on Iran. Ukraine utilized drones to strike a significant Russian oil refinery in Yaroslavl. Cybersecurity alerts include the discovery of critical factory implants (CVE-2026-74232, CVE-2026-74233) in China-made ZBT routers, enabling unauthenticated root access. Ransomware tactics are evolving, becoming more adaptive and automation-driven to evade controls and target high-value data. Additionally, concerns are rising over AI models breaching production infrastructure during security testing.

#AnonNews_irc #Cybersecurity #News

##

DailyCyberSecurity at 2026-08-28T03:18:09.259Z ##

VulnCheck found a ZBT router backdoor in firmware, tracked as CVE-2026-74232 and CVE-2026-74233, granting unauthenticated root over the internet.

securityonline.info/zbt-router

##

youranonnewsirc@nerdculture.de at 2026-08-29T04:26:25.000Z ##

Geopolitically, the U.S. military reopened the Strait of Hormuz, asserting control and increasing pressure on Iran. Ukraine utilized drones to strike a significant Russian oil refinery in Yaroslavl. Cybersecurity alerts include the discovery of critical factory implants (CVE-2026-74232, CVE-2026-74233) in China-made ZBT routers, enabling unauthenticated root access. Ransomware tactics are evolving, becoming more adaptive and automation-driven to evade controls and target high-value data. Additionally, concerns are rising over AI models breaching production infrastructure during security testing.

#AnonNews_irc #Cybersecurity #News

##

DailyCyberSecurity@infosec.exchange at 2026-08-28T03:18:09.000Z ##

VulnCheck found a ZBT router backdoor in firmware, tracked as CVE-2026-74232 and CVE-2026-74233, granting unauthenticated root over the internet.

#ZBT #SupplyChain #Backdoor #RouterSecurity #VulnCheck

securityonline.info/zbt-router

##

thehackerwire@mastodon.social at 2026-08-27T17:00:25.000Z ##

๐Ÿ”ด CVE-2026-74232 - Critical (9.8)

Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, A...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w@infosec.exchange at 2026-08-27T16:27:45.000Z ##

Fucking LMAO

nvd.nist.gov/vuln/detail/cve-2

Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels.

##

CVE-2026-61617
(7.7 HIGH)

EPSS: 0.25%

updated 2026-08-27T17:19:02.473000

1 posts

Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a single server to exhaust the host node's physical disk and take down every server on it. Wings checks available space only once, as a boolean, when the

thehackerwire@mastodon.social at 2026-08-26T23:00:06.000Z ##

๐ŸŸ  CVE-2026-61617 - High (7.7)

Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47666
(7.6 HIGH)

EPSS: 0.20%

updated 2026-08-27T17:18:27.247000

1 posts

Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font family names, which are interpolated into a @font-face CSS rule and injected into the page as HTML without sanitization. Because the backend accepts an arbitrary font-family string and the frontend writes the resulting style throu

thehackerwire@mastodon.social at 2026-08-26T23:59:59.000Z ##

๐ŸŸ  CVE-2026-47666 - High (7.6)

Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font family names, which are interpolated into a @font-face CSS rule and injected ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18431
(9.8 CRITICAL)

EPSS: 0.64%

updated 2026-08-27T17:17:29.533000

2 posts

The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the s

1 repos

https://github.com/HORKimhab/CVE-2026-18431

beyondmachines1@infosec.exchange at 2026-08-27T18:01:40.000Z ##

Remote Code Execution Vulnerability Chain Discovered in Avada WordPress Theme

A critical vulnerability chain (CVE-2026-18431) in the Avada WordPress theme allows unauthenticated attackers to execute arbitrary PHP code and fully compromise websites without any user interaction.

**If you're using the Avada WordPress theme, update it to version 7.16.1 and update the Fusion Builder plugin to version 3.16.1 right ASAP. Since this flaw lets attackers take over your whole site without logging in, also check your site for any unfamiliar administrator accounts or new PHP files after updating.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-08-27T14:02:11.000Z ##

Wordfence's AI system Argus uncovered a six-step vulnerability chain in the Avada WordPress theme, rated 9.8 critical, enabling unauthenticated remote code execution.

#Avada #CVE202618431 #WordPress #Wordfence #FusionBuilder

securityexpress.info/avada-the

##

CVE-2026-15990
(7.5 HIGH)

EPSS: 0.69%

updated 2026-08-27T17:17:14.017000

1 posts

The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.0.1 via the 'frm_graph' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Successful exploitation requires Formidable Forms Lite, Formidable Forms Pro, and Formidable Cha

thehackerwire@mastodon.social at 2026-08-27T04:01:38.000Z ##

๐ŸŸ  CVE-2026-15990 - High (7.5)

The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.0.1 via the 'frm_graph' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74233
(9.8 CRITICAL)

EPSS: 2.63%

updated 2026-08-27T15:31:35

7 posts

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated att

cyberveille@mastobot.ping.moi at 2026-08-29T11:30:06.000Z ##

๐Ÿ“ข Ces routeurs chinois peuvent รชtre contrรดlรฉs ร  distance sans authentification - CVE-2026-74233 CVE-2026-74232

Deux nouveaux implants ont รฉtรฉ dรฉtectรฉs dans des routeurs du fabricant chinois Zbtlink, ร  lโ€™origine dโ€™une porte dรฉrobรฉe dรฉcouverte dรฉbut aoรปt sur une vingtaine de modรจles. DarkLantern et SpeakingStone ouvrent un accรจs root sans authentification et contactent des serveurs distants, selon le chercheurโ€ฆ

๐Ÿ”— clubic.com/actualite-627301-ce
๐Ÿ’ฌ discussion : infosec.pub/post/51582660
#CVE #Cyberveille

##

youranonnewsirc@nerdculture.de at 2026-08-29T04:26:25.000Z ##

Geopolitically, the U.S. military reopened the Strait of Hormuz, asserting control and increasing pressure on Iran. Ukraine utilized drones to strike a significant Russian oil refinery in Yaroslavl. Cybersecurity alerts include the discovery of critical factory implants (CVE-2026-74232, CVE-2026-74233) in China-made ZBT routers, enabling unauthenticated root access. Ransomware tactics are evolving, becoming more adaptive and automation-driven to evade controls and target high-value data. Additionally, concerns are rising over AI models breaching production infrastructure during security testing.

#AnonNews_irc #Cybersecurity #News

##

DailyCyberSecurity at 2026-08-28T03:18:09.259Z ##

VulnCheck found a ZBT router backdoor in firmware, tracked as CVE-2026-74232 and CVE-2026-74233, granting unauthenticated root over the internet.

securityonline.info/zbt-router

##

youranonnewsirc@nerdculture.de at 2026-08-29T04:26:25.000Z ##

Geopolitically, the U.S. military reopened the Strait of Hormuz, asserting control and increasing pressure on Iran. Ukraine utilized drones to strike a significant Russian oil refinery in Yaroslavl. Cybersecurity alerts include the discovery of critical factory implants (CVE-2026-74232, CVE-2026-74233) in China-made ZBT routers, enabling unauthenticated root access. Ransomware tactics are evolving, becoming more adaptive and automation-driven to evade controls and target high-value data. Additionally, concerns are rising over AI models breaching production infrastructure during security testing.

#AnonNews_irc #Cybersecurity #News

##

DailyCyberSecurity@infosec.exchange at 2026-08-28T03:18:09.000Z ##

VulnCheck found a ZBT router backdoor in firmware, tracked as CVE-2026-74232 and CVE-2026-74233, granting unauthenticated root over the internet.

#ZBT #SupplyChain #Backdoor #RouterSecurity #VulnCheck

securityonline.info/zbt-router

##

thehackerwire@mastodon.social at 2026-08-27T17:00:13.000Z ##

๐Ÿ”ด CVE-2026-74233 - Critical (9.8)

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w@infosec.exchange at 2026-08-27T16:29:40.000Z ##

Bugdoor too?

nvd.nist.gov/vuln/detail/CVE-2

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authentication uses a hardcoded salt and an all-zero wildcard MAC bypass, rendering it ineffective.

##

CVE-2026-80557
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-08-27T15:31:33

1 posts

In the Linux kernel, the following vulnerability has been resolved: libceph: fix OOB read in decode_watchers() via missing bounds check ceph_start_decoding() validates that struct_len bytes remain in the buffer after the encoding header, but accepts struct_len=0 as valid: ceph_decode_need(p, end, 0, bad) always passes. When a malicious or compromised OSD sends an obj_list_watch_response_t reply

CVE-2026-65182
(9.1 CRITICAL)

EPSS: 0.59%

updated 2026-08-27T15:27:26.040000

1 posts

Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 throu

beyondmachines1@infosec.exchange at 2026-08-27T13:01:20.000Z ##

Apache Tomcat Patches Critical Security Constraint Bypass Vulnerability

Apache Tomcat addressed a critical vulnerability (CVE-2026-65182) that allows unauthenticated attackers to bypass security restrictions by exploiting path-ordering logic. Administrators should update to the latest versions or remove the examples application to prevent unauthorized access.

**If you run Apache Tomcat (versions 9.0.x, 10.1.x, or 11.0.x), update now to 11.0.25, 10.1.59, or 9.0.121. Note that 10.1.58 has the fix but was never officially released, so don't rely on it. If you can't patch right away, delete the default examples web application and review your security constraint rules so the more restrictive short paths are listed before longer ones.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-81625
(8.8 HIGH)

EPSS: 0.53%

updated 2026-08-27T13:18:41.920000

1 posts

A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected products to trigger a stack buffer overflow and gain full access on the compromised system.

thehackerwire@mastodon.social at 2026-08-27T11:00:23.000Z ##

๐ŸŸ  CVE-2026-81625 - High (8.8)

A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected products to trigger a stack buffer overflow and gain full access on the compromised system.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80587
(9.8 CRITICAL)

EPSS: 0.39%

updated 2026-08-27T13:18:41.093000

2 posts

In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions Some MPTCP suboptions are mutually exclusive according to the RFC8684, but also because in different places, the code doesn't expect some combinations to be present. That's specially true for suboptions that would be present twice, but with different attributes. The new restrictio

CVE-2026-80551
(9.3 CRITICAL)

EPSS: 0.14%

updated 2026-08-27T13:18:39.733000

1 posts

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Ensure first IDAW remains constant The first IDAW in a list does not need to be on a 2K/4K boundary like all others, and so is read separately to accurately calculate the size of the buffer needed to read the full IDAL. Verify that the address found in the first IDAW is unchanged between reads, to ensure a consis

CVE-2026-41992
(7.5 HIGH)

EPSS: 0.37%

updated 2026-08-27T13:17:57.967000

5 posts

GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a spe

CyReVolt@mastodon.social at 2026-08-27T13:12:15.000Z ##

xeiaso.net/shitposts/no-way-to

sweet shitpost ๐Ÿ™ƒ

##

ngate@mastodon.social at 2026-08-27T12:46:16.000Z ##

๐Ÿšจ BREAKING: Tech users baffled as they discover glaring security flaw in their beloved open-source project. ๐Ÿ˜ฑ "Who could've seen this coming?" they cry, while clutching their GNU manuals like sacred texts. ๐Ÿคฆโ€โ™‚๏ธ Meanwhile, the rest of the world rolls its eyes and continues to use literally any other software.
xeiaso.net/shitposts/no-way-to #TechNews #OpenSource #SecurityFlaw #UserConcern #GNUManuals #SoftwareAlternatives #HackerNews #ngated

##

h4ckernews@mastodon.social at 2026-08-27T12:46:09.000Z ##

"No way to prevent this" say users of only language where this regularly happens

xeiaso.net/shitposts/no-way-to

Comments: news.ycombinator.com/item?id=4

#HackerNews #memorysafety #CVE202641992 #programming #news #cybersecurity

##

xeiaso.net@bsky.brid.gy at 2026-08-27T12:21:28.754Z ##

"No way to prevent this" say users of only language where this regularly happens

https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/

"No way to prevent this" say u...

##

cadey@pony.social at 2026-08-27T12:21:28.000Z ##

"No way to prevent this" say users of only language where this regularly happens

xeiaso.net/shitposts/no-way-to

##

CVE-2026-78276
(7.2 HIGH)

EPSS: 0.50%

updated 2026-08-27T12:30:34

1 posts

Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.

hugovalters@mastodon.social at 2026-08-27T17:11:09.000Z ##

CVE-2026-78276 - PHP Object Injection in Fluent Boards Pro <= 2.0.11. CVSS 7.2. Currently unpatched. Restrict access and mitigate now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-782

##

CVE-2026-78285
(8.5 HIGH)

EPSS: 0.34%

updated 2026-08-27T12:30:34

1 posts

Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.

thehackerwire@mastodon.social at 2026-08-27T13:01:45.000Z ##

๐ŸŸ  CVE-2026-78285 - High (8.5)

Subscriber SQL Injection in Like Button Rating &lt;= 2.6.61 versions.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78286
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-08-27T12:30:33

1 posts

Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.

thehackerwire@mastodon.social at 2026-08-27T13:01:57.000Z ##

๐Ÿ”ด CVE-2026-78286 - Critical (9.8)

Unauthenticated PHP Object Injection in Geo Controller &lt;= 8.9.8 versions.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81573
(8.6 HIGH)

EPSS: 0.46%

updated 2026-08-27T12:30:27

1 posts

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the

thehackerwire@mastodon.social at 2026-08-27T13:01:34.000Z ##

๐ŸŸ  CVE-2026-81573 - High (8.6)

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network-
origin restrictions. Commands intended only for local or same-network clients can therefore be executed by
arbitrary r...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81572
(7.8 HIGH)

EPSS: 0.17%

updated 2026-08-27T12:30:27

1 posts

cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, thi

thehackerwire@mastodon.social at 2026-08-27T12:01:17.000Z ##

๐ŸŸ  CVE-2026-81572 - High (7.8)

cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and
file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file
operations are performed. A local...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81273
(8.1 HIGH)

EPSS: 0.17%

updated 2026-08-27T12:30:27

1 posts

Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.

thehackerwire@mastodon.social at 2026-08-27T12:00:56.000Z ##

๐ŸŸ  CVE-2026-81273 - High (8.1)

Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro &lt;= 2.2.4 versions.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81581
(8.8 HIGH)

EPSS: 0.20%

updated 2026-08-27T12:30:27

1 posts

Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually results in a denial of service, yet we cannot rule out the possibility of exploits that can cause Remote Code Execution and Privilege Escalation (since the driver runs with system privileges).

thehackerwire@mastodon.social at 2026-08-27T12:00:20.000Z ##

๐ŸŸ  CVE-2026-81581 - High (8.8)

Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually results in a denial of service, yet we cannot rule o...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81579
(8.8 HIGH)

EPSS: 0.16%

updated 2026-08-27T12:30:27

1 posts

In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code, run an administrator shell, or gain full control over the system.

thehackerwire@mastodon.social at 2026-08-27T12:00:10.000Z ##

๐ŸŸ  CVE-2026-81579 - High (8.8)

In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be lever...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81574
(8.2 HIGH)

EPSS: 0.41%

updated 2026-08-27T12:30:27

1 posts

In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and remotely

thehackerwire@mastodon.social at 2026-08-27T11:00:33.000Z ##

๐ŸŸ  CVE-2026-81574 - High (8.2)

In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format
specifiers. This can be used to reliably crash CodeMeter and disclose sensitive in...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81575
(7.5 HIGH)

EPSS: 0.44%

updated 2026-08-27T12:30:26

1 posts

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a segmentation fault that ultimately crashes the CodeMeter Runtime.

thehackerwire@mastodon.social at 2026-08-27T11:00:45.000Z ##

๐ŸŸ  CVE-2026-81575 - High (7.5)

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and
the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, cau...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cyberworldops at 2026-08-29T20:20:01.244Z ##

CVE-2026-60004 is a critical unauthenticated RCE in Gitea versions prior to 1.27.1, actively exploited in the wild. The flaw targets the diffpatch API endpoint, allowing attackers to install malicious Git hooks for full server compromise. Shadowserver counts over 8,300 exposed instances. Patch now or audit exposure.

cyberworldops.eu/en/gitea-unde

##

undercodenews@mastodon.social at 2026-08-28T18:47:36.000Z ##

Over 8,300 Gitea Servers Remain Exposed to Critical Remote Code Execution Attacks + Video

A New Gitea Security Crisis Is Growing A critical vulnerability in the self-hosted Gitea Git service has become an urgent cybersecurity concern after researchers reported that more than 8,300 Internet-exposed Gitea servers remain vulnerable to active remote code execution attacks. The flaw, tracked as CVE-2026-60004, carries a CVSS score of 9.8, placing it firmly in the criticalโ€ฆ

undercodenews.com/over-8300-gi

##

sayzard@mastodon.sayzard.org at 2026-08-28T14:42:02.000Z ##

Over 8,300 Gitea servers vulnerable to code execution attacks

Gitea์˜ diffpatch API ์ฝ”๋“œ ์ธ์ ์…˜ ์ทจ์•ฝ์ (CVE-2026-60004)์ด ์‹ค์ œ ๊ณต๊ฒฉ์— ์•…์šฉ๋˜๊ณ  ์žˆ์œผ๋ฉฐ, ์ธํ„ฐ๋„ท์— ๋…ธ์ถœ๋œ ์•ฝ 8,393๊ฐœ ์ธ์Šคํ„ด์Šค๊ฐ€ ์•„์ง ์ทจ์•ฝํ•œ ์ƒํƒœ๋‹ค. ์ €์žฅ์†Œ ์“ฐ๊ธฐ ๊ถŒํ•œ์ด ํ•„์š”ํ•˜์ง€๋งŒ ๊ธฐ๋ณธ ์„ค์ •์—์„œ ์ž์ฒด ํšŒ์›๊ฐ€์ž…์ด ํ™œ์„ฑํ™”๋ผ ์žˆ์–ด ๊ณต๊ฒฉ์ž๋Š” ๊ณ„์ •์„ ๋งŒ๋“ค๊ณ  ์ €์žฅ์†Œ๋ฅผ ์ƒ์„ฑํ•œ ๋’ค Gitea ์„œ๋น„์Šค ๊ณ„์ • ๊ถŒํ•œ์œผ๋กœ ์ž„์˜ ์…ธ ๋ช…๋ น์„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋‹ค. Gitea๋Š” 1.27.1์—์„œ ์ˆ˜์ •ํ–ˆ์œผ๋ฉฐ, CISA๋Š” ์ด๋ฏธ ์•…์šฉ ์ค‘์ธ ์ทจ์•ฝ์  ๋ชฉ๋ก์— ์ถ”๊ฐ€ํ–ˆ๊ณ  ๋ฏธํŒจ์น˜ ์„œ๋ฒ„์—์„œ๋Š” ์•”ํ˜ธ...

bleepingcomputer.com/news/secu

##

cyberveille@mastobot.ping.moi at 2026-08-28T14:30:06.000Z ##

๐Ÿ“ข [VULN] CVE-2026-60004 : RCE critique de Gitea exploitรฉe pour dรฉployer des charges utiles semblables ร  des mineurs | SOC Prime

Une vulnรฉrabilitรฉ critique dโ€™exรฉcution de code ร  distance dans Gitea est passรฉe de la divulgation ร  une exploitation active moins dโ€™un mois aprรจs quโ€™un correctif est devenu disponible.

๐Ÿ”— socprime.com/fr/blog/cve-2026-
๐Ÿ’ฌ discussion : infosec.pub/post/51545700
#Vulnรฉrabilitรฉ #CVE #Cyberveille

##

Analyst207@mastodon.social at 2026-08-28T13:24:48.000Z ##

Gitea Servers Exposed to Ongoing Code Execution Attacks

Thousands of Gitea servers remain vulnerable to code execution attacks, with 8393 Internet-exposed IPs still susceptible to CVE-2026-60004, a code injection bug that lets attackers execute arbitrary shell commands. This flaw can be easily exploited by anyone with write access to a repository, which is especially concerning since Gitea enablesโ€ฆ

osintsights.com/gitea-servers-

#Cve202660004 #CodeExecution #Gitea #SupplyChain #EmergingThreats

##

BugsToday@mastodon.social at 2026-08-28T11:59:28.000Z ##

bugstoday.com/gitea-cve-2026-6

#Cybersecurity #InfoSec #CVE #Vulnerability #Security #CyberAttack #Exploit #Malware #Ransomware

##

cyberworldops@infosec.exchange at 2026-08-29T20:20:01.000Z ##

CVE-2026-60004 is a critical unauthenticated RCE in Gitea versions prior to 1.27.1, actively exploited in the wild. The flaw targets the diffpatch API endpoint, allowing attackers to install malicious Git hooks for full server compromise. Shadowserver counts over 8,300 exposed instances. Patch now or audit exposure.

#CriticalVulnerability #RemoteCodeExecution #GiteaSecurity #PatchNow

cyberworldops.eu/en/gitea-unde

##

CVE-2026-59270
(9.4 CRITICAL)

EPSS: 0.29%

updated 2026-08-27T06:31:43

2 posts

Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25

cR0w@infosec.exchange at 2026-08-27T16:26:06.000Z ##

wat

spring.io/security/cve-2026-59

Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.

An attacker who could reach the LDAP listener port could authenticate using the well-known administrative bind DN, and then read or modify entries in the in-memory directory.

##

thehackerwire@mastodon.social at 2026-08-27T07:00:07.000Z ##

๐Ÿ”ด CVE-2026-59270 - Critical (9.4)

Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.
Spring Security 7.1.0
Spring Security 7.0.0 - 7.0.6
Spring Sec...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80585
(9.4 CRITICAL)

EPSS: 0.32%

updated 2026-08-27T06:31:38

1 posts

In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN data Passive TCP Fast Open accepts a valid-cookie SYN even when it carries no data. In that case the child socket's receive queue is intentionally left empty. mptcp_fastopen_subflow_synack_set_params() set is_mptfo before checking for queued SYN data. That made data-less TFO SY

CVE-2026-80528
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-08-27T06:31:38

1 posts

In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while using current->journal_info handle_reply() stores a `ceph_mds_request` pointer in `current->journal_info` while filling the inode and dentry cache from an MDS reply. An allocation in this section can enter direct reclaim and prune dentries from another filesystem. If this dirties an ext4 inode, ext

CVE-2026-80519
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-08-27T06:31:38

1 posts

In the Linux kernel, the following vulnerability has been resolved: ovpn: finish crypto callback cleanup before peer release Crypto completion callbacks hold both key-slot and peer references. The peer reference pins the netdev, and dropping the last peer reference can let netdev unregistration and module removal make progress. Do not release that peer reference before the callback has finished

CVE-2026-80554
(9.3 CRITICAL)

EPSS: 0.14%

updated 2026-08-27T06:31:38

1 posts

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Limit the number of channel program segments The processing of channel programs, and the CCWs within them, is done recursively. As such, there is an arbitrary (but not architectural) limit to the number of CCWs that can exist in a single channel program. The vfio-ccw logic breaks these channel programs into segme

CVE-2026-80589
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-08-27T06:31:38

2 posts

In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer when releasing a never added disk disk_release() undoes blk_mq_init_allocated_queue() for a disk whose probe failed before add_disk(), but it only calls blk_mq_exit_queue(). Nothing there stops q->timeout, and that timer rolls forward: it stays pending until it next expires, not until the last reque

CVE-2026-74737
(9.8 CRITICAL)

EPSS: 0.56%

updated 2026-08-27T06:31:37

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG On the packet reception path, the ID of the MAC Port on which the packet was received, is embedded in the RX DMA Descriptor's metadata. The ID is extracted using the helper function cppi5_desc_get_tags_ids() which fills in the 16-bit Source Tag into the 'port

CVE-2026-74744
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-08-27T06:31:37

1 posts

In the Linux kernel, the following vulnerability has been resolved: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev ipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(), but leave needed_headroom and needed_tailroom set to 0. When the underlying phy_dev (or stacked lower device) requires extra headroom or tailroom for headers/trailers (e.g. macsec, ipsec, wi

CVE-2026-80558
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-08-27T06:31:33

1 posts

In the Linux kernel, the following vulnerability has been resolved: libceph: Avoid using invalid osd indices from primary_temp A corrupted osdmap received from a Ceph monitor or OSD may contain osd indices in its pg_temp, primary_temp, pg_upmap, and pg_upmap_items parts that don't exist, i.e., that are greater than max_osd or smaller than CEPH_HOMELESS_OSD (-1). These indices are used to create

CVE-2026-74752
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-08-27T06:31:31

1 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: validate cookie AUTH state before use When cookie authentication is disabled, COOKIE_ECHO restores fixed-size AUTH fields directly from peer-controlled cookie bytes. A forged RANDOM length, HMAC list, or CHUNKS list can then reach association consumers with lengths or identifiers that were never validated against the loca

CVE-2026-74751
(9.4 CRITICAL)

EPSS: 0.34%

updated 2026-08-27T06:31:31

1 posts

In the Linux kernel, the following vulnerability has been resolved: riscv: lib: Fix ZBB strnlen reading past count boundary The ZBB-optimized strnlen loop loads one word ahead before checking the aligned boundary: REG_L t1, SZREG(t0) // load next word addi t0, t0, SZREG // advance orc.b t1, t1 bgeu t0, t4, 4f // boundary check AFTER load where t4

CVE-2026-80588
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-27T06:17:46.353000

1 posts

In the Linux kernel, the following vulnerability has been resolved: mptcp: reclaim forward-allocated memory on RX path errors After commit 9db5b3cec4ec ("mptcp: borrow forward memory from subflow"), errors in the receive path prior to queueing skbs into the receive queue do not trigger forward-allocated memory reclaiming. Prevent forward memory from growing unboundedly in pathological drop scen

thehackerwire@mastodon.social at 2026-08-27T09:01:41.000Z ##

๐ŸŸ  CVE-2026-80588 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

mptcp: reclaim forward-allocated memory on RX path errors

After commit 9db5b3cec4ec ("mptcp: borrow forward memory from subflow"),
errors in the receive path prior to queueing s...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80586
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-08-27T06:17:45.700000

1 posts

In the Linux kernel, the following vulnerability has been resolved: mptcp: options: reset DSS fields in case of unexpected size A remote peer could send a malformed DSS with a wrong size, followed by another DSS or MPC + Data. In this case, the first suboption will be ignored, but leaving some fields written, which could lead to inconsistency or access uninitialized data. Explicitly reset the f

CVE-2026-80561
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-08-27T06:17:41.057000

1 posts

In the Linux kernel, the following vulnerability has been resolved: libceph: fix multiple unsafe decodes in decode_locker() decode_locker() in cls_lock_client.c contains three unsafe decode operations that allow a malicious or compromised OSD to trigger slab-out-of-bounds reads: 1. ceph_decode_copy() at the locker_id_t name field has no preceding bounds check. With p == end after ceph_start_

CVE-2026-74746
(9.8 CRITICAL)

EPSS: 0.54%

updated 2026-08-27T06:17:25.033000

1 posts

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: publish GC-visible tuple last nf_flow_table_iterate() only treats original-direction tuple nodes as owning entries. Publishing the original node first lets GC observe and free a flow while flow_offload_add() is still inserting the reply node. Publish the reply node first and the original node last so GC nev

CVE-2026-74743
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-08-27T06:17:24.113000

1 posts

In the Linux kernel, the following vulnerability has been resolved: macvlan: inherit needed_headroom and needed_tailroom from lowerdev macvlan devices inherit hard_header_len from lowerdev during macvlan_init(), but leave needed_headroom and needed_tailroom set to 0. When the underlying lowerdev requires extra headroom or tailroom for headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or

CVE-2026-65641(CVSS UNKNOWN)

EPSS: 0.54%

updated 2026-08-27T00:30:36

1 posts

A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.

beyondmachines1@infosec.exchange at 2026-08-27T12:01:20.000Z ##

Veeam Patches Critical Authentication Coercion Flaw in Veeam ONE

Veeam released patches for a critical vulnerability (CVE-2026-65641) in Veeam ONE that allows unauthenticated attackers to steal service account NTLM credentials via SMB coercion. The flaw affects version 13 builds and could lead to unauthorized access to backup infrastructure.

**If you're running Veeam ONE version 13.1.0.7034 or any earlier version 13 build, update ASAP to 13.1.0.7233 or 13.0.2.7159. This flaw lets attackers steal your service account credentials without logging in. After updating, review your network logs for any unusual SMB traffic coming from your Veeam servers, as this could indicate the flaw was already exploited.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-70419
(9.1 CRITICAL)

EPSS: 2.19%

updated 2026-08-26T21:31:47

1 posts

Dell Cloud Disaster Recovery, versions 20.2 and prior,ย containย an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

CVE-2026-75960
(8.1 HIGH)

EPSS: 0.35%

updated 2026-08-26T18:32:04

3 posts

Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.

_r_netsec at 2026-08-28T09:13:04.992Z ##

One Resident Login, an Entire Apartment Complex: The Master PIN in Rently's API (CVE-2026-75960) planckdefense.com/blog/rently-

##

_r_netsec@infosec.exchange at 2026-08-28T09:13:04.000Z ##

One Resident Login, an Entire Apartment Complex: The Master PIN in Rently's API (CVE-2026-75960) planckdefense.com/blog/rently-

##

thehackerwire@mastodon.social at 2026-08-26T23:01:08.000Z ##

๐ŸŸ  CVE-2026-75960 - High (8.1)

Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19271
(7.5 HIGH)

EPSS: 0.30%

updated 2026-08-26T18:32:04

1 posts

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TรœBฤฐTAK BฤฐLGEM Software Technologies Research Institute Liderahenk allows LDAP Injection. This issue affects Liderahenk: from 3.4.0 before 3.5.5.

thehackerwire@mastodon.social at 2026-08-27T00:00:10.000Z ##

๐ŸŸ  CVE-2026-19271 - High (7.5)

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TรœBฤฐTAK BฤฐLGEM Software Technologies Research Institute Liderahenk allows LDAP Injection.

This issue affects Liderahenk: from 3.4.0 before 3....

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2015-5287
(7.8 HIGH)

EPSS: 4.96%

updated 2026-08-26T18:31:30

1 posts

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.

1 repos

https://github.com/HORKimhab/CVE-2015-5287

thecybermind@infosec.exchange at 2026-08-27T08:14:29.000Z ##

๐Ÿšจ Executive Risk Brief: CVE-2015-5287 targets Red Hat ABRT via symlink privilege escalation. Leaders must review asset visibility, compliance tracking, and patch management protocols. Read the full CSUITE brief from The Cyber Mind Co. thecybermind.co/9pkv

##

CVE-2026-8452
(9.8 CRITICAL)

EPSS: 1.61%

updated 2026-08-26T18:30:34

8 posts

Memory overflow vulnerabilityย NetScaler ADC and NetScaler Gatewayย leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as aย Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

3 repos

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

https://github.com/derekpreston81/CVE_ADC_IOC_2026

https://github.com/BishopFox/CVE-2026-8452-check

netsecio@mastodon.social at 2026-08-28T15:14:15.000Z ##

๐Ÿ“ฐ Public PoC for Critical Citrix NetScaler Pre-Auth RCE Released

A public PoC exploit is now available for a critical pre-auth RCE vulnerability (CVE-2026-8452) in Citrix NetScaler ADC & Gateway. No patch is available yet. Admins should monitor devices closely. #Citrix #RCE #PoC

๐Ÿ”— cyber.netsecops.io/articles/ci

##

youranonnewsirc@nerdculture.de at 2026-08-28T10:26:27.000Z ##

CISA urges immediate patching for a critical Citrix NetScaler vulnerability (CVE-2026-8452) actively exploited in the wild. The FBI and DOJ disrupted a China-linked hacking group (QTFY) targeting US critical infrastructure, including hospitals. Over 100 tech firms, including Microsoft and OpenAI, issued a joint warning about escalating AI-driven cyber threats, calling for enhanced defenses. In technology, Nvidia's strong earnings and 70% revenue growth forecast significantly boosted tech markets. Geopolitically, the US-Iran conflict persists, with Qatar initiating new mediation efforts.

#Cybersecurity #AnonNews_irc #News

##

blog@securebulletin.com at 2026-08-28T08:36:38.000Z ##

CISA Orders Rapid Action as Citrix NetScaler Flaw Is Exploited in the Wild

CISA has placed CVE-2026-8452 in its Known Exploited Vulnerabilities catalog following confirmed attacks against Citrix NetScaler products. The memory-safety flaw can disrupt critical gateway services, and organizations should apply Citrix guidance while reviewing edge-device telemetry.

securebulletin.com/cisa-orders

##

youranonnewsirc@nerdculture.de at 2026-08-28T04:26:24.000Z ##

Geopolitical tensions persist with US-Iran disputes over the Strait of Hormuz, while a devastating glacial collapse hits Nepal-Tibet. In technology, Nvidia forecasts a 70% revenue jump driven by AI demand, and SK Hynix breaks ground on a $4B US HBM plant in Indiana. Cybersecurity highlights CISA's urgent call to patch exploited Citrix NetScaler vulnerabilities (CVE-2026-8452) and a collective warning from over 100 companies, including OpenAI, on the need for urgent AI-powered cyber defenses against increasingly sophisticated AI threats.

#AnonNews_irc #Cybersecurity #AI

##

youranonnewsirc@nerdculture.de at 2026-08-28T10:26:27.000Z ##

CISA urges immediate patching for a critical Citrix NetScaler vulnerability (CVE-2026-8452) actively exploited in the wild. The FBI and DOJ disrupted a China-linked hacking group (QTFY) targeting US critical infrastructure, including hospitals. Over 100 tech firms, including Microsoft and OpenAI, issued a joint warning about escalating AI-driven cyber threats, calling for enhanced defenses. In technology, Nvidia's strong earnings and 70% revenue growth forecast significantly boosted tech markets. Geopolitically, the US-Iran conflict persists, with Qatar initiating new mediation efforts.

#Cybersecurity #AnonNews_irc #News

##

youranonnewsirc@nerdculture.de at 2026-08-28T04:26:24.000Z ##

Geopolitical tensions persist with US-Iran disputes over the Strait of Hormuz, while a devastating glacial collapse hits Nepal-Tibet. In technology, Nvidia forecasts a 70% revenue jump driven by AI demand, and SK Hynix breaks ground on a $4B US HBM plant in Indiana. Cybersecurity highlights CISA's urgent call to patch exploited Citrix NetScaler vulnerabilities (CVE-2026-8452) and a collective warning from over 100 companies, including OpenAI, on the need for urgent AI-powered cyber defenses against increasingly sophisticated AI threats.

#AnonNews_irc #Cybersecurity #AI

##

thecybermind@infosec.exchange at 2026-08-27T12:09:23.000Z ##

๐Ÿšจ Executive Risk Brief: CVE-2026-8452 targets Citrix NetScaler ADC & Gateway via memory buffer flaws. Leaders must review asset visibility, patch velocity, and risk governance. Read the full CSUITE brief: thecybermind.co/zapn

##

DailyCyberSecurity@infosec.exchange at 2026-08-27T02:31:29.000Z ##

CISA adds six exploited vulnerabilities to its KEV Catalog, including a Citrix NetScaler flaw and CVE-2026-8452, with active exploitation confirmed.

#CISA #KEV #Citrix #NetScaler #CyberSecurity #CVE

securityonline.info/cisa-kev-s

##

CVE-2022-0995
(7.1 HIGH)

EPSS: 9.52%

updated 2026-08-26T18:30:28

3 posts

An out-of-bounds (OOB) memory write flaw was found in the Linux kernelโ€™s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.

4 repos

https://github.com/1nzag/CVE-2022-0995

https://github.com/A1b2rt/cve-2022-0995

https://github.com/Bonfee/CVE-2022-0995

https://github.com/AndreevSemen/CVE-2022-0995

sigint@fosstodon.org at 2026-08-28T00:30:10.000Z ##

๐Ÿง SIGINT // Linux Watch โ€” 2026-08-28

CVE-2022-0995 (Linux kernel OOB write) joins the KEV list years after disclosure โ€” a reminder that unpatched old bugs don't retire, they just wait for someone to notice they still work.

๐Ÿ”— thehackernews.com/2026/08/cisa

#Linux #OpenSource #FOSS

##

thecybermind@infosec.exchange at 2026-08-27T14:07:04.000Z ##

๐Ÿšจ Critical Threat Intel: CVE-2022-0995 impacts the Linux kernel watch_queue subsystem via out-of-bounds memory writes, enabling local root privilege escalation. Review IOCs, Splunk/Sentinel queries, and kernel hardening actions: thecybermind.co/heaz

##

thecybermind@infosec.exchange at 2026-08-27T10:49:12.000Z ##

๐Ÿšจ Executive Risk Brief: CVE-2022-0995 targets the Linux Kernel via an out-of-bounds write flaw enabling privilege escalation. Leaders must review asset visibility, patch cadence, and risk governance. Read the full CSUITE brief: thecybermind.co/rzv2

##

CVE-2015-3246
(5.1 MEDIUM)

EPSS: 8.80%

updated 2026-08-26T18:30:27

1 posts

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

1 repos

https://github.com/HORKimhab/CVE-2015-3246

thecybermind@infosec.exchange at 2026-08-27T08:55:42.000Z ##

๐Ÿšจ Executive Risk Brief: CVE-2015-3246 targets Red Hat libuser via authentication race conditions. Leaders must review asset visibility, compliance tracking, and endpoint hardening protocols. Read the full CSUITE brief from The Cyber Mind Co. thecybermind.co/7ei4

##

CVE-2026-54569
(9.8 CRITICAL)

EPSS: 0.78%

updated 2026-08-26T15:28:48

1 posts

### Summary An unauthenticated remote code execution vulnerability in the SENAITE JSON API allows any network-reachable attacker to execute arbitrary Python on the Zope worker process via a two-request anonymous chain. The `/@@API/update` route is reachable to anonymous callers and runs `eval()` on attacker-controlled input before any permission check fires. This is a different code path from th

thehackerwire@mastodon.social at 2026-08-26T23:00:58.000Z ##

๐Ÿ”ด CVE-2026-54569 - Critical (9.8)

SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization a...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19042
(8.8 HIGH)

EPSS: 2.00%

updated 2026-08-26T14:17:08.270000

1 posts

A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker to execute arbitrary commands in the context of the current user via a specially crafted URL sent through the out-of-session chat feature. Exploitation requires user interaction by clicking the malicious link.

CVE-2026-19913(CVSS UNKNOWN)

EPSS: 0.36%

updated 2026-08-25T18:32:01

1 posts

The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter is used as the base URL for a backend request and accepts nonโ€‘HTTP schemes such as file://. When an exception or error occurs, the response is subsequently deserialized and its raw contents are reflected to the clie

1 repos

https://github.com/HORKimhab/CVE-2026-19912-CVE-2026-19913-CVE-2026-19914

cyberworldops@infosec.exchange at 2026-08-27T04:20:01.000Z ##

Two unpatched vulnerabilities in Kaltura's mwEmbed HTML5 player library (html5lib) allow unauthenticated file read and remote code execution via insecure deserialization in mwEmbedLoader.php. CVE-2026-19913 and CVE-2026-19912 affect any exposed instance with no auth or tokens required. No vendor patch exists yet.

#Kaltura #VulnerabilityManagement #RCE #CERTCC

cyberworldops.eu/en/unpatched-

##

CVE-2026-19912(CVSS UNKNOWN)

EPSS: 0.22%

updated 2026-08-25T18:32:01

1 posts

The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php accepts a userโ€‘controlled ServiceUrl, whose response is passed to unserialize(), and the resulting objectโ€™s fields are written to a cache path derived from attackerโ€‘supplied uiconf_id with

1 repos

https://github.com/HORKimhab/CVE-2026-19912-CVE-2026-19913-CVE-2026-19914

cyberworldops@infosec.exchange at 2026-08-27T04:20:01.000Z ##

Two unpatched vulnerabilities in Kaltura's mwEmbed HTML5 player library (html5lib) allow unauthenticated file read and remote code execution via insecure deserialization in mwEmbedLoader.php. CVE-2026-19913 and CVE-2026-19912 affect any exposed instance with no auth or tokens required. No vendor patch exists yet.

#Kaltura #VulnerabilityManagement #RCE #CERTCC

cyberworldops.eu/en/unpatched-

##

CVE-2026-74684
(7.1 HIGH)

EPSS: 0.14%

updated 2026-08-25T06:18:51.253000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() The commit 4f61f133f354 ("net: tap: NULL pointer derefence in dev_parse_header_protocol when skb->dev is null") fixed a crash in tap_get_user() by assigning skb->dev before calling tun_vnet_hdr_to_skb(). This is required because virtio_net_hdr_to_skb()

sigint@fosstodon.org at 2026-08-29T23:45:05.000Z ##

๐Ÿง SIGINT // Ubuntu Watch โ€” 2026-08-30

CVE-2026-74684 hits TAP/virtio-net GSO handling with a remote NULL deref panic, CVSS 7.1. Anyone running VMs or containers with virtio-net bridging should prioritize this kernel update over routine patching.

๐Ÿ”— linuxcompatible.org/story/linu

#Ubuntu #Linux #infosec

##

CVE-2026-64531
(7.8 HIGH)

EPSS: 0.38%

updated 2026-08-22T04:17:58.720000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guar

4 repos

https://github.com/suominen/ovswrap

https://github.com/HackSpeak/CVE-2026-64531

https://github.com/0xBlackash/CVE-2026-64531

https://github.com/mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool

sigint@fosstodon.org at 2026-08-28T23:45:06.000Z ##

๐Ÿง SIGINT // Ubuntu Watch โ€” 2026-08-29

Big batch of kernel CVEs including CVE-2026-64531 across multiple subsystems. If you run mainline or generic kernels on Ubuntu, patch and reboot promptly since several of these look locally exploitable.

๐Ÿ”— ubuntu.com/security/notices/US

#Ubuntu #Linux #infosec

##

CVE-2026-73570
(8.9 HIGH)

EPSS: 20.53%

updated 2026-08-21T18:34:48

1 posts

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands a

Nuclei template

6 repos

https://github.com/INFOKOM-KI/Zimbra-CVE-2026-73570-Rules

https://github.com/HORKimhab/CVE-2026-73570

https://github.com/BiuTrap/CVE-2026-73570

https://github.com/alsyundawy/eradicate-zimbra-malware

https://github.com/gabrielunknown/CVE-2026-73570

https://github.com/jishino567/CVE-2026-73570

CVE-2026-77806
(9.8 CRITICAL)

EPSS: 4.20%

updated 2026-08-21T18:16:52.373000

1 posts

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.

Nuclei template

1 repos

https://github.com/CuteeCat/CVE-2026-77806

cyberveille@mastobot.ping.moi at 2026-08-28T07:00:06.000Z ##

๐Ÿ“ข โš ๏ธ[VULN] Mise ร  jour critique de sรฉcuritรฉ : sortie de SPIP 4.4.21- CVE-2026-77806

La version 4.4.21 corrige une faille de sรฉcuritรฉ signalรฉe anonymement via lโ€™ANSSI. Cette version corrige une vulnรฉrabilitรฉ universelle (sans conditions) prรฉ-authentification RCE qui touche la version 4.4.20 de SPIP. Cette faille nโ€™est pas prise en charge par lโ€™รฉcran de sรฉcuritรฉ.

๐Ÿ”— blog.spip.net/Mise-a-jour-crit
๐Ÿ’ฌ discussion : infosec.pub/post/51532987
#Vulnรฉrabilitรฉ #CVE #Cyberveille

##

CVE-2026-19598
(9.8 CRITICAL)

EPSS: 2.79%

updated 2026-08-20T12:48:10.287000

1 posts

The Pods โ€“ Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check โ€” including the method allowlist, nonce verification, login enforcement, and capability gate โ€” through pods_error(), which under the JSON met

Nuclei template

4 repos

https://github.com/sag-asab/CVE-2026-19598

https://github.com/HackfutSecRoot/multi_exploit_wp

https://github.com/DeadExpl0it/CVE-2026-19598-PoC

https://github.com/ksotaria1337/CVE-2026-19598

DailyCyberSecurity@infosec.exchange at 2026-08-27T07:52:23.000Z ##

Wordfence found CVE-2026-19598, a critical unauthenticated flaw in the Pods WordPress plugin (100,000+ installs) letting attackers reset any password, including the admin's.

#PodsPlugin #CVE202619598 #WordPress #Wordfence #PrivilegeEscalation

meterpreter.org/pods-wordpress

##

CVE-2026-53361
(7.1 HIGH)

EPSS: 0.13%

updated 2026-08-19T18:31:59

1 posts

In the Linux kernel, the following vulnerability has been resolved: af_unix: Set gc_in_progress to true in unix_gc(). Igor Ushakov reported that unix_gc() could run with gc_in_progress being false if the work is scheduled while running: Thread 1 Thread 2 Thread 3 -------- -------- -------- unix_schedule_gc()

1 repos

https://github.com/sgkdev/bad_garbage

CVE-2026-65400
(9.8 CRITICAL)

EPSS: 9.90%

updated 2026-08-19T04:17:34.547000

3 posts

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

3 repos

https://github.com/panchocosil/CVE-2026-65400-poc

https://github.com/HORKimhab/CVE-2026-65400

https://github.com/acheong08/CVE-2026-65400

CVE-2026-19478
(9.4 CRITICAL)

EPSS: 6.00%

updated 2026-08-17T21:31:30

1 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Nuclei template

7 repos

https://github.com/davkharrr/CVE-2026-19478-PoC

https://github.com/HORKimhab/CVE-2026-19650-CVE-2026-19478

https://github.com/renzi25031469/CVE-2026-19478

https://github.com/dinosn/gitlab-cve-2026-19478-lab

https://github.com/n0xdaemon/cve-2026-19478

https://github.com/punitdarji/Gitlab-CVE-2026-19478

https://github.com/EQSTLab/CVE-2026-19478

hackmag@infosec.exchange at 2026-08-27T15:00:28.000Z ##

โšช๏ธ Hackers Are Already Exploiting a Critical GitLab Vulnerability

๐Ÿ—จ๏ธ Researchers at watchTowr reported that hackers have begun exploiting the critical GitLab vulnerability CVE-2026-19478 in real-world attacks, just days after the bug was disclosed. Last week, GitLab developers released emergency patches for Community Edition (CE) and Enterprise Edition (EE) thatโ€ฆ

๐Ÿ”— hackmag.com/news/gitlab-attack

#news

##

CVE-2026-72137
(9.8 CRITICAL)

EPSS: 0.62%

updated 2026-08-17T06:34:17

3 posts

In the Linux kernel, the following vulnerability has been resolved: xfrm: nat_keepalive: avoid double free on send error nat_keepalive_send() frees the keepalive skb whenever the IPv4 or IPv6 send helper reports an error. That cleanup is only correct before the skb is handed to the output path. Once ip_build_and_send_pkt() or ip6_xmit() takes ownership, the networking stack may already have con

decio@infosec.exchange at 2026-08-27T13:58:44.000Z ##

Le kernel #Linux avait dรฉjร  free().
Avec CVE-2026-72137, il propose maintenant le double free. :apartyblobcat: :neocat_floof_explode:

Et CyberMeowfia (nebusec.ai) vient de publier le PoC ยซ root inclus ยป pour #Ubuntu 7.0.0-28.
โฌ‡๏ธ
LPE exploit for the latest Ubuntu 26.04 ( lnkd.in/p/eYP7_A2g ) ๐Ÿ‘€
๐Ÿ‘‡
github.com/NebuSec/CyberMeowfi

Bref, si ce kernel traรฎne chez vous : patcher avant que quelquโ€™un ne profite de la promo 2 pour 1.

๐Ÿ” :debian:
๐Ÿ‘‡
vulnerability.circl.lu/vuln/CV

#CyberVeille #CVE_2026_72137

##

obivan@infosec.exchange at 2026-08-27T12:43:21.000Z ##

Another Linux (Ubuntu) LPE github.com/NebuSec/CyberMeowfi

##

DailyCyberSecurity@infosec.exchange at 2026-08-27T03:41:22.000Z ##

A public PoC exploit targets CVE-2026-72137, a CVSS 9.8 Linux kernel double-free that enables root privilege escalation. Patch now.

#CVE202672137 #LinuxKernel #PrivilegeEscalation #PoC #xfrm #InfoSec

securityonline.info/cve-2026-7

##

CVE-2026-61979
(8.1 HIGH)

EPSS: 0.28%

updated 2026-08-13T15:34:46

1 posts

Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.

rswebsols@mastodon.social at 2026-08-29T06:06:26.000Z ##

Hackers Exploit miniOrange SAML Vulnerabilities to Gain Admin Access to WordPress #wordpress

Security alert: Hackers are exploiting two unauthenticated bypass flaws in the miniOrange SAML 2.0 plugin to gain admin access on WordPress sites. Patch updates (Standard edition) address CVE-2026-61979 and CVE-2026-15981. Learn what this means for your site and how to protect it in our latest post: ift.tt/Nf3pSs8

Source: ift.tt/Nf3pSs8 | Image: ift.tt/XpgZVHc

##

CVE-2026-63077
(9.8 CRITICAL)

EPSS: 87.71%

updated 2026-08-06T05:17:05.170000

2 posts

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Nuclei template

4 repos

https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation

https://github.com/sfewer-r7/CVE-2026-63077

https://github.com/AnggaTechI/CVE-2026-63077

https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap

sayzard@mastodon.sayzard.org at 2026-08-28T21:38:52.000Z ##

Security Incident Affecting JetBrains Cadence

JetBrains์˜ PyCharm ์—ฐ๋™ ํด๋ผ์šฐ๋“œ ์‹คํ–‰ ์„œ๋น„์Šค Cadence๊ฐ€ TeamCity์˜ ์น˜๋ช…์  ์›๊ฒฉ ๋ช…๋ น ์‹คํ–‰ ์ทจ์•ฝ์ (CVE-2026-63077)์„ ํ†ตํ•ด ์นจํ•ด๋์œผ๋ฉฐ, ๊ณต๊ฒฉ์ž๋Š” 2026๋…„ 8์›” 8์ผ๋ถ€ํ„ฐ 24์ผ๊นŒ์ง€ ํ™˜๊ฒฝ์— ๋ฌด๋‹จ ์ ‘๊ทผํ–ˆ์Šต๋‹ˆ๋‹ค. Cadence ์‹คํ–‰์— ์‚ฌ์šฉ๋๊ฑฐ๋‚˜ ํ”„๋กœ์ ํŠธ ํŒŒ์ผยท2024๋…„ ์„œ๋ฒ„ ๋ฐฑ์—…์— ์กด์žฌํ•œ ํด๋ผ์šฐ๋“œ IAM ์ž๊ฒฉ ์ฆ๋ช…, ์†Œ์Šค ์ œ์–ด ํ† ํฐ, ํŒจํ‚ค์ง€ยท์ปจํ…Œ์ด๋„ˆ ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ํ† ํฐ, SSH ํ‚ค ๋ฐ ์†Œ์Šค ์ฝ”๋“œ๊ฐ€ ์œ ์ถœ๋์„ ๊ฐ€๋Šฅ์„ฑ์ด ์žˆ์Šต๋‹ˆ๋‹ค. Cadence ์‚ฌ์šฉ์ž๋Š” ๋ชจ๋“  ๊ด€๋ จ ์‹œํฌ๋ฆฟ์„ ์ฆ‰์‹œ ํ๊ธฐยท๊ต์ฒดํ•˜๊ณ  AWS/GCP/Azure IAM, S3...

blog.jetbrains.com/pycharm/202

##

security_crawler_carl@infosec.exchange at 2026-08-27T15:27:31.000Z ##

CVE-2026-63077 has been flagged by both Australia's ACSC and CISA's Known Exploited Vulnerabilities catalog since August 5, meaning threat actors already found it on the shelf before you did.

No specific sector is being targeted. Everyone's invited. The ACSC recommends you urgently audit your network for vulnerable TeamCity On-Premises versions and apply available patches immediately. (2/3)

##

CVE-2026-15981
(9.8 CRITICAL)

EPSS: 0.81%

updated 2026-07-24T23:16:50.257000

1 posts

The SAML Single Sign On โ€“ SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful sign

1 repos

https://github.com/Nxploited/CVE-2026-15981

rswebsols@mastodon.social at 2026-08-29T06:06:26.000Z ##

Hackers Exploit miniOrange SAML Vulnerabilities to Gain Admin Access to WordPress #wordpress

Security alert: Hackers are exploiting two unauthenticated bypass flaws in the miniOrange SAML 2.0 plugin to gain admin access on WordPress sites. Patch updates (Standard edition) address CVE-2026-61979 and CVE-2026-15981. Learn what this means for your site and how to protect it in our latest post: ift.tt/Nf3pSs8

Source: ift.tt/Nf3pSs8 | Image: ift.tt/XpgZVHc

##

CVE-2026-45657
(9.8 CRITICAL)

EPSS: 15.48%

updated 2026-07-23T08:10:00.137000

1 posts

Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.

CapTechGroup@mastodon.social at 2026-08-29T18:23:43.000Z ##

June 2026 Patch Tuesday: 206 CVEs, 32 critical, 28 RCE. CVE-2026-47291 is an unauthenticated integer overflow in http.sys (IIS, WinRM, anything listening on 80/443). CVE-2026-45657 is a kernel use-after-free reachable via...

captechgroup.com/threat-intell

##

CVE-2026-47291
(9.8 CRITICAL)

EPSS: 22.75%

updated 2026-07-23T08:10:00.137000

1 posts

Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.

1 repos

https://github.com/dhmosfunk/CVE-2026-49160-CVE-2026-47291-HTTP.sys

CapTechGroup@mastodon.social at 2026-08-29T18:23:43.000Z ##

June 2026 Patch Tuesday: 206 CVEs, 32 critical, 28 RCE. CVE-2026-47291 is an unauthenticated integer overflow in http.sys (IIS, WinRM, anything listening on 80/443). CVE-2026-45657 is a kernel use-after-free reachable via...

captechgroup.com/threat-intell

##

CVE-2018-18472
(9.8 CRITICAL)

EPSS: 25.63%

updated 2026-06-17T01:47:21.423000

2 posts

Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter. It can be triggered by anyone who knows the IP address of the affected device, as exploited in the wild in June 2021 for factory reset commands,

guerrillaconsumer at 2026-08-28T00:01:05.721Z ##

@kirschner Western Digital did something like this with their My Book Live NAS drives. They stopped shipping firmware updates for the line in 2015 but allowed a remote-code flaw (CVE-2018-18472) to sit unpatched for years. In 2021, a newly discovered auth-bypass in the factory-reset function (CVE-2021-35941) allowed attackers to remotely wipe devices worldwide. Owners opened the app to find empty folders.

##

guerrillaconsumer@infosec.exchange at 2026-08-28T00:01:05.000Z ##

@kirschner Western Digital did something like this with their My Book Live NAS drives. They stopped shipping firmware updates for the line in 2015 but allowed a remote-code flaw (CVE-2018-18472) to sit unpatched for years. In 2021, a newly discovered auth-bypass in the factory-reset function (CVE-2021-35941) allowed attackers to remotely wipe devices worldwide. Owners opened the app to find empty folders.

##

CVE-2021-23758
(9.8 CRITICAL)

EPSS: 83.63%

updated 2026-02-03T17:39:26

1 posts

### Overview Affected versions of this package are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution. ### Description Serialization is a process of converting an object into a sequence of bytes which can be persisted to a disk or database or can be sent through streams. The rever

1 repos

https://github.com/numanturle/CVE-2021-23758-POC

thecybermind@infosec.exchange at 2026-08-27T07:35:45.000Z ##

๐Ÿšจ Executive Risk Brief: CVE-2021-23758 targets Ajax.NET Professional via unsafe deserialization. Leaders must review SBOM asset visibility, regulatory compliance, and financial risk mitigation strategies. Read the full CSUITE brief: thecybermind.co/uyx4

##

CVE-2025-39367
(5.3 MEDIUM)

EPSS: 0.27%

updated 2025-04-28T09:32:00

1 posts

Missing Authorization vulnerability in SeventhQueen Kleo.This issue affects Kleo: from n/a before 5.4.4.

wpguyuk@infosec.exchange at 2026-08-27T07:04:36.000Z ##

If you are running Avada, patch it now. CVE-2025-39367 allows a complete stranger to execute code on your site with no account and no password required. Avada is ThemeForest's best-selling theme, which makes the attack surface enormous. This one is as serious as it gets.

#WordPress #WordPressSecurity #Avada #SecurityHardening #WebSecurity

wpguy.uk/blog/avada-rce-vulner

##

CVE-2021-35941
(7.5 HIGH)

EPSS: 12.71%

updated 2023-01-27T05:02:51

2 posts

Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerability than CVE-2018-18472.

guerrillaconsumer at 2026-08-28T00:01:05.721Z ##

@kirschner Western Digital did something like this with their My Book Live NAS drives. They stopped shipping firmware updates for the line in 2015 but allowed a remote-code flaw (CVE-2018-18472) to sit unpatched for years. In 2021, a newly discovered auth-bypass in the factory-reset function (CVE-2021-35941) allowed attackers to remotely wipe devices worldwide. Owners opened the app to find empty folders.

##

guerrillaconsumer@infosec.exchange at 2026-08-28T00:01:05.000Z ##

@kirschner Western Digital did something like this with their My Book Live NAS drives. They stopped shipping firmware updates for the line in 2015 but allowed a remote-code flaw (CVE-2018-18472) to sit unpatched for years. In 2021, a newly discovered auth-bypass in the factory-reset function (CVE-2021-35941) allowed attackers to remotely wipe devices worldwide. Owners opened the app to find empty folders.

##

CVE-2026-81849
(0 None)

EPSS: 0.57%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-29T16:01:11.000Z ##

๐ŸŸ  CVE-2026-81849 - High (8.8)

Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-DownloadContent ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T16:01:11.000Z ##

๐ŸŸ  CVE-2026-81849 - High (8.8)

Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-DownloadContent ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65643
(0 None)

EPSS: 0.00%

6 posts

N/A

1 repos

https://github.com/HORKimhab/CVE-2026-65643

beyondmachines1 at 2026-08-29T14:01:41.222Z ##

cPanel Patches Root Escalation Flaw in Domain Management

cPanel fixed a vulnerability (CVE-2026-65643) that allows authenticated users to gain root access by exploiting domain parking features. The flaw allows full server takeover and compromises all hosted accounts, databases, and files.

**If you run cPanel/WHM (including WP Squared), update your servers right away to a patched build 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, or 11.138.1.7 or later using the `upcp` script or the WHM interface. If you can't patch immediately, block users from creating new parked or addon domains until the update is done, since any single hosting customer could otherwise take full root control of the whole server and everyone's data on it.**

beyondmachines.net/event_detai

##

threatnoir at 2026-08-28T19:05:50.274Z ##

โš ๏ธ CRITICAL: Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

A critical vulnerability in cPanel/WHM (CVE-2026-65643) allows authenticated hosting customers to escalate privileges to root on shared servers via domain parking and addon domain features. Any customer account can exploit this to achieve full server compromise. If your infrastructure runs cPanel/Wโ€ฆ

threatnoir.com/focus

๐Ÿค– AI generated summary

##

netsecio@mastodon.social at 2026-08-28T15:14:04.000Z ##

๐Ÿ“ฐ Critical cPanel Flaw Allows Hosting Customers to Gain Root Access

Critical cPanel vulnerability (CVE-2026-65643) allows any authenticated user to gain full root access on shared hosting servers by abusing the domain parking feature. Patches are available and must be applied immediately. #cPanel #Vulnerability #Cybe...

๐Ÿ”— cyber.netsecops.io/articles/cr

##

Analyst207@mastodon.social at 2026-08-28T10:24:53.000Z ##

cPanel Flaw Enables Root Code Execution via Domain Functionality

A critical cPanel security flaw, tracked as CVE-2026-65643, allows attackers to execute code as the root user, giving them full control of the server, by exploiting domain parking and addon domain functionality. This vulnerability impacts all supported versions of cPanel &amp; WHM and can be triggered by an authenticated account holder.

osintsights.com/cpanel-flaw-en

#Cpanel #Cve202665643 #RootCodeExecution #WebHosting #SupplyChain

##

beyondmachines1@infosec.exchange at 2026-08-29T14:01:41.000Z ##

cPanel Patches Root Escalation Flaw in Domain Management

cPanel fixed a vulnerability (CVE-2026-65643) that allows authenticated users to gain root access by exploiting domain parking features. The flaw allows full server takeover and compromises all hosted accounts, databases, and files.

**If you run cPanel/WHM (including WP Squared), update your servers right away to a patched build 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, or 11.138.1.7 or later using the `upcp` script or the WHM interface. If you can't patch immediately, block users from creating new parked or addon domains until the update is done, since any single hosting customer could otherwise take full root control of the whole server and everyone's data on it.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

threatnoir@infosec.exchange at 2026-08-28T19:05:50.000Z ##

โš ๏ธ CRITICAL: Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

A critical vulnerability in cPanel/WHM (CVE-2026-65643) allows authenticated hosting customers to escalate privileges to root on shared servers via domain parking and addon domain features. Any customer account can exploit this to achieve full server compromise. If your infrastructure runs cPanel/Wโ€ฆ

threatnoir.com/focus

#infosec #cybersecurity

๐Ÿค– AI generated summary

##

CVE-2026-77078
(0 None)

EPSS: 0.29%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-29T06:02:22.000Z ##

๐ŸŸ  CVE-2026-77078 - High (7.5)

multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafted text field names can cause an uncaught RangeError (Invalid array length) that terminates the Node.js process. The first ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T06:02:22.000Z ##

๐ŸŸ  CVE-2026-77078 - High (7.5)

multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafted text field names can cause an uncaught RangeError (Invalid array length) that terminates the Node.js process. The first ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77037
(0 None)

EPSS: 0.35%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-29T06:02:12.000Z ##

๐ŸŸ  CVE-2026-77037 - High (7.5)

multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is aborted or truncated before the write stream finishes, multer's disk storage engine removes the visible file but does not close the ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T06:02:12.000Z ##

๐ŸŸ  CVE-2026-77037 - High (7.5)

multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is aborted or truncated before the write stream finishes, multer's disk storage engine removes the visible file but does not close the ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82333
(0 None)

EPSS: 0.28%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-29T00:01:19.000Z ##

๐ŸŸ  CVE-2026-82333 - High (7.5)

multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted text field names can make multer's field parser synchronously iterate a maximum-length sparse array, blocking the event loop s...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-29T00:01:19.000Z ##

๐ŸŸ  CVE-2026-82333 - High (7.5)

multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted text field names can make multer's field parser synchronously iterate a maximum-length sparse array, blocking the event loop s...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cyberveille@mastobot.ping.moi at 2026-08-28T09:30:06.000Z ##

๐Ÿ“ข [VULN] Next.js : deux failles critiques permettent une exรฉcution de code ร  distance sans authentification - CVE-2026-75604

Le 25 aoรปt 2026, Vercel a publiรฉ plusieurs nouvelles versions de Next.js : 15.5.24 et 16.3.3. L'objectif ? Patcher deux failles critiques permettant toutes les deux une exรฉcution de code ร  distance sans authentification. Voici l'essentiel ร  savoir sur ces failles.

๐Ÿ”— it-connect.fr/nextjs-failles-c
๐Ÿ’ฌ discussion : infosec.pub/post/51535270
#CVE #Cyberveille

##

guru@thecybersecguru.com at 2026-08-27T16:25:38.000Z ##

Critical Next.js & libheif RCE Vulnerabilities: Inside the August 2026 AVIF Zero-Day Exploit Chain

Critical Next.js RCE vulnerabilities affect AVIF image optimization and Windows servers. Learn about libheif, GHSA-2xp9-vwfh-vxw4, CVE-2026-75604

thecybersecguru.com/news/nextj

##

obivan@infosec.exchange at 2026-08-27T10:16:34.000Z ##

Next.js Windows RCE PoC github.com/rafabd1/CVE-2026-75

##

CVE-2026-61800
(0 None)

EPSS: 0.59%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-28T03:01:13.000Z ##

๐Ÿ”ด CVE-2026-61800 - Critical (9.1)

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/oss...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-28T03:01:13.000Z ##

๐Ÿ”ด CVE-2026-61800 - Critical (9.1)

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/oss...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81529
(0 None)

EPSS: 0.17%

1 posts

N/A

hugovalters@mastodon.social at 2026-08-28T01:04:20.000Z ##

CVE-2026-81529 - Connection-option injection in MongoDB C# Driver allows security control bypass. CVSS 7.1. Audit code and sanitize inputs now. #CVE #MongoDB #infosec

valtersit.com/cve/CVE-2026-815

##

CVE-2026-81522
(0 None)

EPSS: 0.27%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-27T21:00:53.000Z ##

๐ŸŸ  CVE-2026-81522 - High (8.1)

A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace identifier from untrusted input without validating it may ther...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-27T21:00:53.000Z ##

๐ŸŸ  CVE-2026-81522 - High (8.1)

A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace identifier from untrusted input without validating it may ther...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68503
(0 None)

EPSS: 0.40%

1 posts

N/A

beyondmachines1@infosec.exchange at 2026-08-27T10:01:19.000Z ##

LazyOwn RedTeam Framework Patches Critical Default Credential Vulnerability

LazyOwn RedTeam/APT Framework patched a critical vulnerability (CVE-2026-68503) that allows attackers to gain full administrative control over C2 dashboards using hardcoded default credentials. The flaw enables unauthorized users to hijack red-team campaigns, issue commands to beacons, and access exfiltrated data.

**If you run the LazyOwn RedTeam/APT framework, update it to version 0.2.154 or later ASAP. Older versions ship with default usernames and passwords that let anyone take over your C2 dashboard. If you can't update yet, change the `c2_user` and `c2_pass` values in your `payload.json` to unique strong passwords and put the dashboard behind a firewall so only trusted networks can reach it.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-47665
(0 None)

EPSS: 0.25%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-26T23:59:49.000Z ##

๐ŸŸ  CVE-2026-47665 - High (8.7)

Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as raw text and rendered into the page with innerH...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites