## Updated at UTC 2026-09-08T05:07:31.327227

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-18922 9.8 0.00% 2 0 2026-09-08T03:32:16 A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a st
CVE-2026-86510 9.9 0.00% 4 0 2026-09-08T02:17:28.357000 A vulnerability has been found in D-Link DIR-822A A_101. Affected is the functio
CVE-2026-86509 9.6 0.00% 4 0 2026-09-08T01:17:55.947000 A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function se
CVE-2026-76969 9.4 0.00% 4 0 2026-09-08T01:17:55.407000 @sap/cds-mtxs NPM library does not perform sufficient checks on certain function
CVE-2026-76967 7.8 0.00% 2 0 2026-09-08T01:17:55.170000 SAP NetWeaver Business Client does not perform sufficient validation when proces
CVE-2026-76958 8.5 0.00% 2 0 2026-09-08T01:17:54.430000 SAP Integration Suite does not sufficiently validate XML documents accepted from
CVE-2026-66768 9.0 0.00% 2 0 2026-09-08T01:17:52.113000 SAP GUI for Java does not correctly enforce the trust level policy for certain f
CVE-2026-66767 7.7 0.00% 2 0 2026-09-08T01:17:51.987000 SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenti
CVE-2026-58240 9.8 0.00% 2 0 2026-09-08T01:17:51.080000 SAP NetWeaver Message Server does not sufficiently validate the authenticity of
CVE-2026-44756 10.0 0.00% 2 0 2026-09-08T01:17:30.840000 A memory safety vulnerability exists in the Extended Passport Protocol (EPP) pro
CVE-2026-86541 8.3 0.00% 2 0 2026-09-08T00:30:33 knowns versions before 0.30.0 contain a path traversal vulnerability in the hand
CVE-2026-86540 7.8 0.00% 2 0 2026-09-08T00:30:32 knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary
CVE-2026-86544 8.1 0.00% 2 0 2026-09-08T00:30:32 knowns versions before 0.30.0 contain an authorization bypass vulnerability wher
CVE-2026-86543 9.8 0.00% 4 0 2026-09-08T00:30:32 knowns versions before 0.30.0 serve the management API without authentication on
CVE-2026-86542 9.1 0.00% 2 0 2026-09-07T23:16:54.020000 knowns before 0.30.0 fails to validate import names in the import routes, allowi
CVE-2026-86538 7.5 0.00% 2 0 2026-09-07T23:16:53.443000 knowns versions before 0.30.0 contain a path traversal vulnerability in the POST
CVE-2026-86439 8.8 0.00% 2 0 2026-09-07T23:16:53.297000 knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool argu
CVE-2026-75650 10.0 0.00% 9 0 2026-09-07T21:30:30 Adobe Commerce is affected by an Improper Neutralization of Special Elements Use
CVE-2026-86494 7.7 0.00% 2 0 2026-09-07T18:31:42 In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthori
CVE-2026-86498 7.7 0.00% 2 0 2026-09-07T18:31:42 In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link s
CVE-2026-80166 7.8 0.00% 2 0 2026-09-07T18:31:36 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application
CVE-2026-86482 8.8 0.00% 2 0 2026-09-07T18:31:36 In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes all
CVE-2026-86478 9.8 0.00% 2 0 2026-09-07T18:31:36 In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authenticatio
CVE-2026-86492 8.5 0.00% 2 0 2026-09-07T18:31:33 In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-ten
CVE-2026-86504 7.8 0.00% 2 0 2026-09-07T17:17:28.903000 In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation be
CVE-2026-86502 8.4 0.00% 2 0 2026-09-07T17:17:28.670000 In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the
CVE-2026-86480 9.8 0.00% 4 0 2026-09-07T17:17:26.150000 In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register
CVE-2026-86479 8.1 0.00% 2 0 2026-09-07T17:17:26.040000 In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing
CVE-2026-86429 7.5 0.00% 2 0 2026-09-07T15:34:01 The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and
CVE-2026-86435 7.5 0.00% 2 0 2026-09-07T15:34:01 commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerab
CVE-2026-76578 9.8 0.00% 2 0 2026-09-07T15:33:55 A flaw was found in FreeIPA. The self-managed OTP token ACI does not require aut
CVE-2026-6223 9.4 0.00% 2 0 2026-09-07T15:33:55 Improper restriction of excessive authentication attempts vulnerability in Bahçe
CVE-2026-7861 9.8 0.00% 2 0 2026-09-07T15:17:32.153000 Deserialization of untrusted data vulnerability in Next4Biz Information Technolo
CVE-2026-67276 0 0.25% 16 3 2026-09-07T14:16:53.843000 RouterOS does not compare the complete RSA public key when matching an SSH authe
CVE-2026-86428 7.5 0.00% 2 0 2026-09-07T13:20:42.037000 commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnera
CVE-2026-86296 10.0 0.00% 2 0 2026-09-07T12:30:36 A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affe
CVE-2026-86297 8.1 0.00% 2 0 2026-09-07T12:30:36 A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects
CVE-2026-83627 9.8 0.82% 1 0 2026-09-07T12:17:20.100000 The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for
CVE-2026-81543 8.8 0.25% 1 0 2026-09-07T12:17:19.753000 The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Pri
CVE-2026-77393 8.8 0.51% 1 0 2026-09-07T12:17:19.230000 In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shi
CVE-2026-75925 9.6 0.67% 3 0 2026-09-07T12:17:18.960000 Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.
CVE-2026-75816 9.8 0.50% 2 0 2026-09-07T12:17:18.850000 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentic
CVE-2026-79697 9.9 3.35% 2 0 2026-09-07T09:31:46 A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-661
CVE-2026-79698 9.9 1.70% 4 0 2026-09-07T09:31:46 A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-661
CVE-2026-14296 7.5 0.11% 3 0 2026-09-07T09:31:39 When using the Direct XIP update strategy, the main application image starts oth
CVE-2026-19633 8.8 0.36% 2 0 2026-09-06T18:34:45 PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked u
CVE-2026-86259 7.5 0.25% 2 0 2026-09-06T15:31:06 OpenMAIC before 1.0.1 skips server-side request forgery validation in non-produc
CVE-2026-78362 9.8 0.34% 2 0 2026-09-06T12:31:26 The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly vali
CVE-2026-84935 8.0 0.23% 2 0 2026-09-06T12:31:26 The HT Menu WordPress plugin before 1.2.7 does not perform any capability or ob
CVE-2026-84934 8.0 0.23% 2 0 2026-09-06T12:31:26 The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability che
CVE-2026-86250 7.5 0.28% 2 0 2026-09-06T12:30:30 h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user
CVE-2026-86242 8.1 0.62% 2 0 2026-09-06T12:17:15.583000 Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path
CVE-2026-84219 7.5 0.22% 2 0 2026-09-06T11:18:03.950000 The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of th
CVE-2026-82304 8.6 0.32% 2 0 2026-09-06T11:18:02.880000 The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user
CVE-2026-77826 8.8 0.27% 2 0 2026-09-06T11:18:01.470000 The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which app
CVE-2026-19858 7.5 0.32% 2 0 2026-09-06T11:18:00.793000 The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2
CVE-2026-18480 8.8 0.23% 2 0 2026-09-06T11:18:00.657000 The SureCart WordPress plugin before 4.6.3 does not ensure that the account aff
CVE-2026-86165 9.8 0.64% 2 0 2026-09-06T06:30:21 A vulnerability was found in Tenda HG10 300001138. This vulnerability affects th
CVE-2026-86167 9.9 1.63% 2 0 2026-09-06T05:16:50.477000 A vulnerability was identified in Tenda HG10 300001138. Impacted is the function
CVE-2026-86166 8.8 0.48% 2 0 2026-09-06T04:18:32.783000 A vulnerability was determined in Tenda HG10 300001138. This issue affects the f
CVE-2026-86218 None 0.41% 22 1 2026-09-06T03:30:35 N-central is vulnerable to a pre-auth remote code execution This issue affects N
CVE-2026-16310 9.8 0.30% 2 0 2026-09-06T03:30:30 The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Refe
CVE-2026-18056 7.5 0.34% 2 0 2026-09-06T03:30:30 The HivePress Authentication plugin for WordPress is vulnerable to Authenticatio
CVE-2026-86153 9.1 0.39% 2 0 2026-09-06T03:30:30 A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the functi
CVE-2026-86152 10.0 1.86% 2 0 2026-09-06T03:30:30 A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the func
CVE-2026-85046 8.8 1.16% 43 4 2026-09-06T03:30:24 Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote at
CVE-2026-86151 9.1 2.04% 2 0 2026-09-06T00:31:04 A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is t
CVE-2026-86148 9.1 2.46% 2 0 2026-09-06T00:31:04 A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability
CVE-2026-86149 9.1 2.04% 2 0 2026-09-05T22:17:18.943000 A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some
CVE-2026-86206 None 0.29% 2 0 2026-09-05T21:31:26 A vulnerability in the N-central internal API access control filter allows unaut
CVE-2026-67277 None 0.43% 6 0 2026-09-05T21:31:20 RouterOS accepts a "related" btest connection before the corresponding primary s
CVE-2026-86060 0 0.40% 11 0 2026-09-05T21:16:51.400000 RouterOS contains an argument-handling flaw in the SSH login path involving user
CVE-2026-67279 0 0.45% 4 0 2026-09-05T21:16:50.613000 RouterOS SSH enters the connection protocol after a client-requested rekey even
CVE-2026-86207 0 0.30% 2 0 2026-09-05T19:16:56.190000 An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypa
CVE-2026-0799 8.7 0.11% 2 0 2026-09-05T19:16:55.320000 In BPF instructions that load/store a value from/to a scratch memory register th
CVE-2026-86189 9.8 0.41% 2 0 2026-09-05T15:30:31 WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php th
CVE-2026-86145 8.2 0.37% 1 0 2026-09-05T14:17:23.897000 PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of
CVE-2026-86190 9.1 0.27% 3 0 2026-09-05T13:18:14.150000 WWBN AVideo contains a broken access control vulnerability in videoViewsInfo end
CVE-2026-86184 9.8 0.60% 2 0 2026-09-05T12:31:35 Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in t
CVE-2026-10196 9.8 0.63% 2 0 2026-09-05T12:31:34 The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emai
CVE-2025-9049 8.8 0.25% 2 0 2026-09-05T12:31:34 The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unaut
CVE-2026-86117 8.1 0.42% 2 0 2026-09-05T12:31:34 Coolify through 4.3.17 contains an authentication bypass vulnerability in the OA
CVE-2026-86123 8.7 0.33% 1 0 2026-09-05T12:31:34 SQL Chat contains four unauthenticated API endpoints that accept client-supplied
CVE-2026-86124 9.8 0.54% 3 0 2026-09-05T12:31:27 AutoAgent contains an unauthenticated remote code execution vulnerability in the
CVE-2026-86121 9.8 0.59% 2 0 2026-09-05T12:31:27 Cua computer-server versions before 0.3.42 skip authentication when the CONTAINE
CVE-2026-86173 7.5 0.37% 2 0 2026-09-05T12:31:27 MindsDB through 26.1.0 contains a server-side request forgery vulnerability in t
CVE-2026-86185 8.0 0.11% 2 0 2026-09-05T12:16:49.240000 Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wi
CVE-2026-86177 8.8 0.31% 2 0 2026-09-05T11:16:46.397000 Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in
CVE-2026-86169 8.8 0.48% 2 0 2026-09-05T11:16:45.703000 Axolotl through 0.18.0 contains a remote code execution vulnerability in the mul
CVE-2026-86119 8.6 0.35% 1 0 2026-09-05T10:16:43.157000 Webstudio through 0.296.0 contains an unauthenticated server-side request forger
CVE-2026-19887 8.8 0.57% 1 0 2026-09-05T07:17:11.657000 The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injectio
CVE-2026-13447 9.8 0.38% 2 0 2026-09-05T06:32:44 The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via J
CVE-2026-86140 8.0 0.14% 1 0 2026-09-05T05:17:12.877000 In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-base
CVE-2026-78012 9.8 0.47% 2 0 2026-09-05T00:32:06 An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Cl
CVE-2026-82684 8.1 0.46% 2 0 2026-09-05T00:31:10 Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Mi
CVE-2026-52775 8.8 0.29% 1 0 2026-09-05T00:17:20.520000 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through
CVE-2026-52771 8.3 0.30% 2 0 2026-09-05T00:17:19.963000 YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.
CVE-2026-52767 8.2 0.22% 1 0 2026-09-05T00:17:19.540000 YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.
CVE-2026-52766 9.1 0.33% 1 0 2026-09-05T00:17:19.393000 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespam
CVE-2026-86095 7.8 0.13% 1 0 2026-09-04T23:18:03.220000 Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in
CVE-2026-48019 8.9 0.68% 1 1 2026-09-04T23:17:09.143000 Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a
CVE-2026-82712 8.8 0.25% 1 0 2026-09-04T21:31:59 Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cr
CVE-2026-80119 7.8 0.12% 1 0 2026-09-04T21:31:59 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10
CVE-2026-80116 7.8 0.11% 1 0 2026-09-04T21:31:59 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10
CVE-2026-78327 9.1 1.55% 2 0 2026-09-04T21:31:50 An Improper Neutralization of Special Elements used in an OS Command ('OS Comman
CVE-2026-75431 9.1 0.77% 1 1 2026-09-04T21:31:48 PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signin
CVE-2026-81939 9.1 0.73% 1 0 2026-09-04T20:17:29.647000 A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem
CVE-2026-80114 7.8 0.13% 1 0 2026-09-04T20:17:28.787000 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10
CVE-2026-78328 9.1 0.50% 2 0 2026-09-04T20:17:27.993000 A missing authorization vulnerability in the SonicWall Network Security Manager
CVE-2026-75160 9.1 0.43% 2 0 2026-09-04T20:17:26.533000 An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escala
CVE-2026-61699 8.1 0.25% 1 0 2026-09-04T20:17:24.347000 nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to v
CVE-2026-53932 8.0 0.91% 1 0 2026-09-04T20:17:23.570000 laravel-backup-restore restores database backups made with spatie/laravel-backup
CVE-2026-80118 7.1 0.11% 1 0 2026-09-04T19:17:28.710000 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10
CVE-2026-80112 7.8 0.10% 2 0 2026-09-04T19:17:27.823000 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10
CVE-2026-77822 8.2 0.21% 1 0 2026-09-04T19:17:27.240000 IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obta
CVE-2026-75430 9.8 0.89% 1 1 2026-09-04T19:17:26.990000 PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/
CVE-2026-85654 7.8 0.14% 1 0 2026-09-04T18:31:46 Improper neutralization of special elements used in a template engine in the CDK
CVE-2026-18486 8.8 0.32% 1 0 2026-09-04T18:31:32 IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote au
CVE-2026-18221 8.1 0.32% 1 0 2026-09-04T18:31:31 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized
CVE-2026-19298 8.8 0.47% 2 0 2026-09-04T18:31:26 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke
CVE-2026-19300 7.5 0.38% 2 0 2026-09-04T18:31:26 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain se
CVE-2026-19305 8.6 0.29% 2 0 2026-09-04T18:31:26 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain se
CVE-2026-19304 7.7 0.31% 1 0 2026-09-04T18:31:21 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke
CVE-2026-19303 8.1 0.38% 1 0 2026-09-04T18:31:21 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke
CVE-2026-18905 7.7 0.31% 2 0 2026-09-04T18:31:20 IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context
CVE-2026-9317 8.1 0.68% 1 0 2026-09-04T18:18:07.297000 Nango before 0.71.6 contains a missing authentication vulnerability in the runne
CVE-2026-85656 7.8 1.12% 2 0 2026-09-04T18:18:06.133000 An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Am
CVE-2026-82538 8.8 0.39% 1 0 2026-09-04T18:18:01.357000 ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerabili
CVE-2026-44402 9.8 0.89% 1 2 2026-09-04T18:17:52.080000 Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code executi
CVE-2026-31020 9.8 0.58% 2 0 2026-09-04T18:17:51.893000 In DocsGPT 0.15.0 and below, the application provides a custom prompt feature th
CVE-2026-19306 7.7 0.41% 2 0 2026-09-04T18:17:51.513000 IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read a
CVE-2026-19274 9.6 0.21% 2 0 2026-09-04T18:17:51.260000 IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana
CVE-2026-57777 7.6 0.24% 2 0 2026-09-04T17:16:57.160000 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-18175 8.1 0.21% 1 0 2026-09-04T17:16:56.010000 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate databas
CVE-2026-5522 6.7 0.09% 1 0 2026-09-04T16:17:25.870000 IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credenti
CVE-2026-19283 7.7 0.31% 2 0 2026-09-04T16:17:21.777000 IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana
CVE-2026-18658 9.8 0.43% 2 0 2026-09-04T16:17:21.133000 IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1,
CVE-2026-85695 9.4 0.41% 2 0 2026-09-04T15:36:24 FastChat contains an authentication bypass vulnerability in the /register_worker
CVE-2026-85620 8.6 0.37% 2 0 2026-09-04T15:36:23 Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where fun
CVE-2026-85694 8.1 0.55% 2 0 2026-09-04T15:17:47.540000 LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkd
CVE-2026-20274 9.8 0.67% 1 0 2026-09-04T14:17:18.423000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-85224 9.1 2.15% 2 0 2026-09-04T00:31:11 A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affec
CVE-2026-18167 None 0.27% 1 0 2026-09-04T00:31:11 A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-
CVE-2026-18330 None 0.23% 1 0 2026-09-04T00:31:10 A hard-coded cryptographic key vulnerability exists in the web module of TP-Link
CVE-2026-85222 9.1 2.11% 2 0 2026-09-03T21:31:26 A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vuln
CVE-2026-83548 10.0 0.71% 1 2 2026-09-03T13:06:16.053000 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla
CVE-2026-82329 9.8 7.67% 1 7 template 2026-09-03T13:06:15.630000 JFrog Artifactory contains an authentication weakness that, under default config
CVE-2026-20212 9.8 0.53% 3 1 2026-09-03T13:04:38.177000 A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switc
CVE-2026-20279 9.8 0.28% 1 0 2026-09-02T18:32:32 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-82691 9.1 2.11% 2 0 2026-09-02T14:17:15.257000 A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-34
CVE-2026-62911 8.0 1.32% 2 1 2026-09-02T04:18:00.460000 Authentication bypass by capture-replay in Microsoft Exchange Server allows an a
CVE-2026-59680 8.0 2.34% 2 0 2026-09-02T04:17:59.917000 An OS command injection vulnerability was found in yast2-users. When displaying
CVE-2026-19490 0 3.37% 5 1 2026-09-01T21:03:04.987000 Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: f
CVE-2026-82688 9.1 2.79% 2 0 2026-09-01T19:17:28.907000 A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B0
CVE-2026-82078 9.1 1.69% 1 2 2026-09-01T04:18:02.160000 An unsafe dynamic class loading vulnerability exists in the database connection
CVE-2026-81578 9.8 1.62% 1 2 2026-08-31T21:31:56 An improper access control vulnerability exists in the web management interface
CVE-2026-82692 9.9 2.36% 2 0 2026-08-31T20:56:08.800000 A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This af
CVE-2026-82690 9.1 2.11% 2 0 2026-08-31T20:56:08.800000 A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected b
CVE-2026-82702 6.6 2.05% 2 0 2026-08-31T15:34:50 A vulnerability was identified in Edimax BR-6214K 1.40. This affects the functio
CVE-2026-82689 9.9 2.36% 2 0 2026-08-31T12:30:37 A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345
CVE-2026-6471 7.2 0.29% 5 2 2026-08-29T23:17:23.010000 Missing authorization in PostgreSQL logical decoding allows a non-superuser hold
CVE-2026-18963 9.1 3.24% 1 14 template 2026-08-28T22:53:42 A flaw was found in the reset-credentials flow of the keycloak-services componen
CVE-2026-53362 7.8 0.51% 2 1 2026-08-28T20:18:10.133000 In the Linux kernel, the following vulnerability has been resolved: ipv6: accou
CVE-2026-60004 9.8 86.78% 2 9 template 2026-08-27T11:41:19.230000 Gitea before 1.27.1 allows remote code execution via the diffpatch API through G
CVE-2026-32475 9.0 2.37% 2 6 template 2026-08-20T12:48:31.843000 Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Eleme
CVE-2026-62735 7.8 0.48% 2 2 2026-08-11T18:31:23 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to
CVE-2026-18108 9.8 0.22% 1 0 2026-08-06T18:37:01.630000 Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _ve
CVE-2026-13230 6.5 0.38% 4 0 2026-08-06T18:21:08.780000 An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 a
CVE-2026-13181 8.1 0.50% 1 1 2026-08-06T18:13:26.983000 In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata c
CVE-2026-63077 9.8 86.52% 1 5 template 2026-08-06T05:17:05.170000 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-66066 None 27.86% 1 7 2026-07-30T18:23:34 ### Impact In its default configuration, a Rails application that displays image
CVE-2026-43284 7.8 93.23% 1 45 2026-07-14T15:31:59 In the Linux kernel, the following vulnerability has been resolved: xfrm: esp:
CVE-2026-14894 9.8 5.27% 2 3 template 2026-07-10T15:43:30.330000 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to
CVE-2026-52770 7.5 0.28% 1 0 2026-07-09T21:00:06 ### Summary YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthen
CVE-2026-52769 8.3 0.30% 1 0 2026-07-09T20:58:34 ## Summary The `POST /api/forms/{formId}/actor/inbox` route - exposed publicly w
CVE-2026-22769 10.0 13.12% 2 0 2026-06-17T10:20:23.560000 Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a
CVE-2025-30208 5.3 74.97% 1 23 template 2026-06-17T09:08:21.517000 Vite, a provider of frontend development tooling, has a vulnerability in version
CVE-2022-37969 7.8 28.27% 1 6 2026-06-17T04:55:48.137000 Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2023-41974 7.8 1.41% 2 0 2026-03-12T03:31:06 A use-after-free issue was addressed with improved memory management. This issue
CVE-2016-4117 9.8 94.35% 1 1 2025-11-17T21:32:21 Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arb
CVE-2021-44228 10.0 100.00% 1 100 template 2025-10-22T19:13:26 # Summary Log4j versions prior to 2.16.0 are subject to a remote code execution
CVE-2022-1096 0 24.39% 2 1 N/A
CVE-2026-80172 0 0.00% 2 0 N/A
CVE-2026-59347 0 0.00% 1 0 N/A
CVE-2026-59346 0 0.00% 4 0 N/A
CVE-2026-38291 0 0.00% 1 0 N/A
CVE-2026-79756 0 5.15% 2 0 N/A
CVE-2026-77477 0 0.00% 2 0 N/A
CVE-2026-53495 0 0.00% 1 0 N/A
CVE-2026-19534 0 0.39% 1 0 N/A
CVE-2026-61686 0 0.42% 1 0 N/A
CVE-2026-63464 0 0.27% 1 0 N/A
CVE-2026-85786 0 0.33% 1 0 N/A
CVE-2026-85781 0 0.26% 2 0 N/A

CVE-2026-18922
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-08T03:32:16

2 posts

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect pas

offseq at 2026-09-07T16:00:26.294Z ##

CRITICAL: CVE-2026-18922 in Red Hat Directory Server 11 allows remote privilege escalation via reused stale SASL PLAIN identities. Restrict allowed SASL mechanisms to exclude PLAIN for mitigation. Full details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-07T16:00:26.000Z ##

CRITICAL: CVE-2026-18922 in Red Hat Directory Server 11 allows remote privilege escalation via reused stale SASL PLAIN identities. Restrict allowed SASL mechanisms to exclude PLAIN for mitigation. Full details: radar.offseq.com/threat/cve-20 #OffSeq #RedHat #CVE202618922 #infosec

##

CVE-2026-86510
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-08T02:17:28.357000

4 posts

A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

offseq at 2026-09-08T03:00:24.989Z ##

D-Link DIR-822A routers are affected by CVE-2026-86510 (CRITICAL, CVSS 9.4): remote out-of-bounds write in L2TP parser can lead to system compromise. No patch yet — restrict access and monitor updates. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-08T02:59:56.000Z ##

🔴 CVE-2026-86510 - Critical (9.9)

A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-08T03:00:24.000Z ##

D-Link DIR-822A routers are affected by CVE-2026-86510 (CRITICAL, CVSS 9.4): remote out-of-bounds write in L2TP parser can lead to system compromise. No patch yet — restrict access and monitor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202686510 #RouterSecurity #Infosec

##

thehackerwire@mastodon.social at 2026-09-08T02:59:56.000Z ##

🔴 CVE-2026-86510 - Critical (9.9)

A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86509
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-08T01:17:55.947000

4 posts

A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit has been published and may be used.

thehackerwire@mastodon.social at 2026-09-08T02:00:36.000Z ##

🔴 CVE-2026-86509 - Critical (9.6)

A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-08T01:30:25.790Z ##

CVE-2026-86509 — CRITICAL stack-based buffer overflow in D-Link DIR-895L (A1_102b07), in udhcpcd’s sendOffer/sendACK. Exploit is public, local network access needed. Review segmentation and monitor for patches. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-08T02:00:36.000Z ##

🔴 CVE-2026-86509 - Critical (9.6)

A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-08T01:30:25.000Z ##

CVE-2026-86509 — CRITICAL stack-based buffer overflow in D-Link DIR-895L (A1_102b07), in udhcpcd’s sendOffer/sendACK. Exploit is public, local network access needed. Review segmentation and monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #CVE202686509 #IoTSecurity

##

CVE-2026-76969
(9.4 CRITICAL)

EPSS: 0.00%

updated 2026-09-08T01:17:55.407000

4 posts

@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application.

offseq at 2026-09-08T04:30:23.729Z ##

SAP CAP's @sap/cds-mtxs (<=4.0.2) has a CRITICAL flaw (CVE-2026-76969): insufficiently protected credentials let unauthenticated attackers steal creds and delete/replace tenant data. No patch yet — monitor SAP updates. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-08T02:00:25.000Z ##

🔴 CVE-2026-76969 - Critical (9.4)

@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credential...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-08T04:30:23.000Z ##

SAP CAP's @sap/cds-mtxs (<=4.0.2) has a CRITICAL flaw (CVE-2026-76969): insufficiently protected credentials let unauthenticated attackers steal creds and delete/replace tenant data. No patch yet — monitor SAP updates. radar.offseq.com/threat/cve-20 #OffSeq #SAP #infosec #CVE

##

thehackerwire@mastodon.social at 2026-09-08T02:00:25.000Z ##

🔴 CVE-2026-76969 - Critical (9.4)

@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credential...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76967
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-08T01:17:55.170000

2 posts

SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is processed and could lead to arbitrary code execution in the context of the user. This res

thehackerwire@mastodon.social at 2026-09-08T02:00:16.000Z ##

🟠 CVE-2026-76967 - High (7.8)

SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-08T02:00:16.000Z ##

🟠 CVE-2026-76967 - High (7.8)

SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76958
(8.5 HIGH)

EPSS: 0.00%

updated 2026-09-08T01:17:54.430000

2 posts

SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation could allow the attacker to read sensitive file contents from the server and expose them through monitoring or logging

thehackerwire@mastodon.social at 2026-09-08T03:00:06.000Z ##

🟠 CVE-2026-76958 - High (8.5)

SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity dec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-08T03:00:06.000Z ##

🟠 CVE-2026-76958 - High (8.5)

SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity dec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66768
(9.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-08T01:17:52.113000

2 posts

SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and avai

thehackerwire@mastodon.social at 2026-09-08T03:00:18.000Z ##

🔴 CVE-2026-66768 - Critical (9)

SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-08T03:00:18.000Z ##

🔴 CVE-2026-66768 - Critical (9)

SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66767
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-08T01:17:51.987000

2 posts

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the applic

thehackerwire@mastodon.social at 2026-09-08T04:02:05.000Z ##

🟠 CVE-2026-66767 - High (7.7)

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-08T04:02:05.000Z ##

🟠 CVE-2026-66767 - High (7.7)

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58240
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-08T01:17:51.080000

2 posts

SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confide

thehackerwire@mastodon.social at 2026-09-08T04:01:55.000Z ##

🔴 CVE-2026-58240 - Critical (9.8)

SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to regi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-08T04:01:55.000Z ##

🔴 CVE-2026-58240 - Critical (9.8)

SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to regi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44756
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-08T01:17:30.840000

2 posts

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availabil

thehackerwire@mastodon.social at 2026-09-08T04:02:15.000Z ##

🔴 CVE-2026-44756 - Critical (10)

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resultin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-08T04:02:15.000Z ##

🔴 CVE-2026-44756 - Critical (10)

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resultin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86541
(8.3 HIGH)

EPSS: 0.00%

updated 2026-09-08T00:30:33

2 posts

knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths or relative paths containing directory traversal sequences to write malicious content to sensitive files like shell startup scripts or SSH configuration files.

thehackerwire@mastodon.social at 2026-09-08T01:01:18.000Z ##

🟠 CVE-2026-86541 - High (8.3)

knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths or relative paths containing ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-08T01:01:18.000Z ##

🟠 CVE-2026-86541 - High (8.3)

knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths or relative paths containing ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86540
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-08T00:30:32

2 posts

knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a crafted configuration is opened, the unvalidated binary path is executed twice under the user's account without any verification.

thehackerwire@mastodon.social at 2026-09-08T00:04:13.000Z ##

🟠 CVE-2026-86540 - High (7.8)

knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a craf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-08T00:04:13.000Z ##

🟠 CVE-2026-86540 - High (7.8)

knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a craf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86544
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-08T00:30:32

2 posts

knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate privileges on subsequent calls.

thehackerwire@mastodon.social at 2026-09-08T00:03:03.000Z ##

🟠 CVE-2026-86544 - High (8.1)

knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission confi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-08T00:03:03.000Z ##

🟠 CVE-2026-86544 - High (8.1)

knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission confi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86543
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-08T00:30:32

4 posts

knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.

thehackerwire@mastodon.social at 2026-09-08T00:02:54.000Z ##

🔴 CVE-2026-86543 - Critical (9.8)

knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-08T00:00:34.937Z ##

CVE-2026-86543: CRITICAL vuln in knowns-dev knowns <0.30.0. Mgmt API is exposed w/o auth by default, allowing attackers to create public tunnels. Restrict access & upgrade ASAP. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-08T00:02:54.000Z ##

🔴 CVE-2026-86543 - Critical (9.8)

knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-08T00:00:34.000Z ##

CVE-2026-86543: CRITICAL vuln in knowns-dev knowns <0.30.0. Mgmt API is exposed w/o auth by default, allowing attackers to create public tunnels. Restrict access & upgrade ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026_86543 #Vulnerability #APIsecurity

##

CVE-2026-86542
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-07T23:16:54.020000

2 posts

knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directory and overwrite arbitrary files writable by the server process.

thehackerwire@mastodon.social at 2026-09-08T00:02:44.000Z ##

🔴 CVE-2026-86542 - Critical (9.1)

knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-08T00:02:44.000Z ##

🔴 CVE-2026-86542 - Critical (9.1)

knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86538
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-07T23:16:53.443000

2 posts

knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile parameter to bypass path restrictions and read sensitive files like credentials and configuration through the JSON response.

thehackerwire@mastodon.social at 2026-09-08T00:04:02.000Z ##

🟠 CVE-2026-86538 - High (7.5)

knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-08T00:04:02.000Z ##

🟠 CVE-2026-86538 - High (7.5)

knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86439
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-07T23:16:53.297000

2 posts

knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal sequences to access arbitrary Markdown files accessible to the server process.

thehackerwire@mastodon.social at 2026-09-08T00:03:52.000Z ##

🟠 CVE-2026-86439 - High (8.8)

knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-08T00:03:52.000Z ##

🟠 CVE-2026-86439 - High (8.8)

knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75650
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-07T21:30:30

9 posts

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

security_crawler_carl at 2026-09-08T00:43:48.060Z ##

🏆 New Achievement! StyleSmuggler Has Entered the Tutorial Zone!

Welcome, new merchant! This is the part of the game where we introduce a mandatory debuff called CVE-2026-75650. Adobe Commerce and Magento 2 contain a CVSS 10.0 critical flaw in the template engine — an Improper Neutralization of Special Elements — that lets attackers execute arbitrary code with no user interaction required. This isn't a side quest. (1/2)

##

DailyCyberSecurity at 2026-09-08T00:17:02.988Z ##

An Adobe Commerce vulnerability, CVE-2026-75650 (CVSS 10), enables unauthenticated arbitrary code execution and is exploited in the wild. Patch now.

securityonline.info/adobe-comm

##

undercodenews@mastodon.social at 2026-09-07T23:50:02.000Z ##

Magento 2 Zero-Day RCE Crisis: Active Attacks Put Online Stores and Customer Data at Risk + Video

A New Threat Is Hitting E-Commerce at the Core A dangerous zero-day vulnerability in Magento and Adobe Commerce has moved from security research into active exploitation, creating an immediate threat for online retailers running the popular e-commerce platforms. The vulnerability, tracked by Adobe as CVE-2026-75650 and publicly associated with the StyleSmuggler attack…

undercodenews.com/magento-2-ze

##

thehackerwire@mastodon.social at 2026-09-07T22:00:48.000Z ##

🔴 CVE-2026-75650 - Critical (10)

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-07T20:30:23.710Z ##

Adobe Commerce faces a CRITICAL (CVSS 10) template engine flaw (CVE-2026-75650) allowing arbitrary code execution with no user interaction required. Update and monitor for patches. radar.offseq.com/threat/cve-20

##

security_crawler_carl@infosec.exchange at 2026-09-08T00:43:48.000Z ##

🏆 New Achievement! StyleSmuggler Has Entered the Tutorial Zone!

Welcome, new merchant! This is the part of the game where we introduce a mandatory debuff called CVE-2026-75650. Adobe Commerce and Magento 2 contain a CVSS 10.0 critical flaw in the template engine — an Improper Neutralization of Special Elements — that lets attackers execute arbitrary code with no user interaction required. This isn't a side quest. (1/2)

##

DailyCyberSecurity@infosec.exchange at 2026-09-08T00:17:02.000Z ##

An Adobe Commerce vulnerability, CVE-2026-75650 (CVSS 10), enables unauthenticated arbitrary code execution and is exploited in the wild. Patch now.

#AdobeCommerce #Magento #StyleSmuggler #CVE202675650 #RCE #Ecommerce #ExploitedInTheWild #Infosec

securityonline.info/adobe-comm

##

thehackerwire@mastodon.social at 2026-09-07T22:00:48.000Z ##

🔴 CVE-2026-75650 - Critical (10)

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-07T20:30:23.000Z ##

Adobe Commerce faces a CRITICAL (CVSS 10) template engine flaw (CVE-2026-75650) allowing arbitrary code execution with no user interaction required. Update and monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #AdobeCommerce #CVE202675650 #infosec

##

CVE-2026-86494
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-07T18:31:42

2 posts

In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues

thehackerwire@mastodon.social at 2026-09-07T18:01:07.000Z ##

🟠 CVE-2026-86494 - High (7.7)

In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-07T18:01:07.000Z ##

🟠 CVE-2026-86494 - High (7.7)

In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86498
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-07T18:31:42

2 posts

In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission

thehackerwire@mastodon.social at 2026-09-07T18:00:00.000Z ##

🟠 CVE-2026-86498 - High (7.7)

In JetBrains YouTrack before 2025.3.160480,
2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-07T18:00:00.000Z ##

🟠 CVE-2026-86498 - High (7.7)

In JetBrains YouTrack before 2025.3.160480,
2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80166
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-07T18:31:36

2 posts

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.

thehackerwire@mastodon.social at 2026-09-07T22:02:23.000Z ##

🟠 CVE-2026-80166 - High (7.8)

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-07T22:02:23.000Z ##

🟠 CVE-2026-80166 - High (7.8)

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86482
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-07T18:31:36

2 posts

In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation

thehackerwire@mastodon.social at 2026-09-07T22:02:14.000Z ##

🟠 CVE-2026-86482 - High (8.8)

In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-07T22:02:14.000Z ##

🟠 CVE-2026-86482 - High (8.8)

In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86478
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-07T18:31:36

2 posts

In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address

offseq at 2026-09-07T19:00:26.158Z ##

JetBrains YouTrack CRITICAL vulnerability (CVE-2026-86478, CVSS 9.8) in versions <2025.3.161254, <2026.1.14042: improper authentication enables unauthenticated account takeover. Patch status pending — check vendor advisory. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-07T19:00:26.000Z ##

JetBrains YouTrack CRITICAL vulnerability (CVE-2026-86478, CVSS 9.8) in versions <2025.3.161254, <2026.1.14042: improper authentication enables unauthenticated account takeover. Patch status pending — check vendor advisory. radar.offseq.com/threat/cve-20 #OffSeq #Infosec #CVE202686478

##

CVE-2026-86492
(8.5 HIGH)

EPSS: 0.00%

updated 2026-09-07T18:31:33

2 posts

In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens

thehackerwire@mastodon.social at 2026-09-07T18:00:56.000Z ##

🟠 CVE-2026-86492 - High (8.5)

In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-07T18:00:56.000Z ##

🟠 CVE-2026-86492 - High (8.5)

In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86504
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-07T17:17:28.903000

2 posts

In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution

thehackerwire@mastodon.social at 2026-09-07T18:00:21.000Z ##

🟠 CVE-2026-86504 - High (7.8)

In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-07T18:00:21.000Z ##

🟠 CVE-2026-86504 - High (7.8)

In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86502
(8.4 HIGH)

EPSS: 0.00%

updated 2026-09-07T17:17:28.670000

2 posts

In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts

thehackerwire@mastodon.social at 2026-09-07T18:00:11.000Z ##

🟠 CVE-2026-86502 - High (8.4)

In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-07T18:00:11.000Z ##

🟠 CVE-2026-86502 - High (8.4)

In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86480
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-07T17:17:26.150000

4 posts

In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges

thehackerwire@mastodon.social at 2026-09-07T22:02:04.000Z ##

🔴 CVE-2026-86480 - Critical (9.8)

In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-07T17:30:24.020Z ##

CVE-2026-86480 (CRITICAL, CVSS 9.8) in JetBrains Hub allows unauthenticated attackers to escalate to superuser by registering a trusted service. No patch yet — restrict access & monitor activity. Details: radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-07T22:02:04.000Z ##

🔴 CVE-2026-86480 - Critical (9.8)

In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-07T17:30:24.000Z ##

CVE-2026-86480 (CRITICAL, CVSS 9.8) in JetBrains Hub allows unauthenticated attackers to escalate to superuser by registering a trusted service. No patch yet — restrict access & monitor activity. Details: radar.offseq.com/threat/cve-20 #OffSeq #JetBrains #CVE202686480 #Infosec

##

CVE-2026-86479
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-07T17:17:26.040000

2 posts

In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR

thehackerwire@mastodon.social at 2026-09-07T18:01:17.000Z ##

🟠 CVE-2026-86479 - High (8.1)

In JetBrains YouTrack before 2026.2.18788,
2026.1.14055,
2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-07T18:01:17.000Z ##

🟠 CVE-2026-86479 - High (8.1)

In JetBrains YouTrack before 2026.2.18788,
2026.1.14055,
2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86429
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-07T15:34:01

2 posts

The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default and are excluded from the standard CommonMark and GitHub-Flavored Markdown converters), an unauthenticated attacker can su

thehackerwire@mastodon.social at 2026-09-07T14:04:13.000Z ##

🟠 CVE-2026-86429 - High (7.5)

The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and &lt; 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-07T14:04:13.000Z ##

🟠 CVE-2026-86429 - High (7.5)

The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and &lt; 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86435
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-07T15:34:01

2 posts

commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to create quadratic output expansion, consuming excessive memory and CPU to exhaust server resources.

thehackerwire@mastodon.social at 2026-09-07T14:03:52.000Z ##

🟠 CVE-2026-86435 - High (7.5)

commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to cre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-07T14:03:52.000Z ##

🟠 CVE-2026-86435 - High (7.5)

commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to cre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76578
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-07T15:33:55

2 posts

A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it add

DailyCyberSecurity at 2026-09-07T16:25:03.364Z ##

Patch the critical FreeIPA CVE-2026-76578 immediately. This FreeIPA vulnerability allows complete, unauthenticated administrative access to your servers.

securityonline.info/freeipa-cv

##

DailyCyberSecurity@infosec.exchange at 2026-09-07T16:25:03.000Z ##

Patch the critical FreeIPA CVE-2026-76578 immediately. This FreeIPA vulnerability allows complete, unauthenticated administrative access to your servers.

#FreeIPA #CVE202676578 #Vulnerability #CyberSecurity #CVE202613097

securityonline.info/freeipa-cv

##

CVE-2026-6223
(9.4 CRITICAL)

EPSS: 0.00%

updated 2026-09-07T15:33:55

2 posts

Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows Authentication Bypass. This issue affects BiHayat App: from 2.1.7 through 07092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

offseq at 2026-09-07T13:00:26.078Z ##

CRITICAL vuln: CVE-2026-6223 in Bahçelievler Municipality BiHayat App (v2.1.7+) enables authentication bypass via weak brute-force protections. No vendor fix yet. Assess and strengthen your controls. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-07T13:00:26.000Z ##

CRITICAL vuln: CVE-2026-6223 in Bahçelievler Municipality BiHayat App (v2.1.7+) enables authentication bypass via weak brute-force protections. No vendor fix yet. Assess and strengthen your controls. radar.offseq.com/threat/cve-20 #OffSeq #CVE20266223 #Infosec #AppSec

##

CVE-2026-7861
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-07T15:17:32.153000

2 posts

Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): through 07092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

offseq at 2026-09-07T14:30:23.534Z ##

CRITICAL deserialization flaw (CVE-2026-7861) in Next4Biz CSM enables code injection. No vendor response or patch. Review exposure, apply compensating controls. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-07T14:30:23.000Z ##

CRITICAL deserialization flaw (CVE-2026-7861) in Next4Biz CSM enables code injection. No vendor response or patch. Review exposure, apply compensating controls. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CVE20267861 #Next4Biz #infosec

##

CVE-2026-67276
(0 None)

EPSS: 0.25%

updated 2026-09-07T14:16:53.843000

16 posts

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target

3 repos

https://github.com/BlackHatExploitation/exploit-mikrotik-2026

https://github.com/HORKimhab/CVE-2026-67276

https://github.com/dinosn/mikrotrick-poc

threatnoir at 2026-09-07T23:05:52.419Z ##

⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers

Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…

threatnoir.com/focus

🤖 AI generated summary

##

netsecio@mastodon.social at 2026-09-07T17:33:21.000Z ##

📰 MikroTik Routers Hijacked via 'MikroTrick' Unauthenticated Exploit

🚨 ACTIVE ATTACK: MikroTik routers are being hijacked via the 'MikroTrick' exploit chain (CVE-2026-67276, CVE-2026-86060). Unauthenticated attackers gain full admin control via exposed SSH. Patch RouterOS NOW. #MikroTik #CyberSecurity

🔗 cyber.netsecops.io/articles/mi

##

Analyst207@mastodon.social at 2026-09-07T10:46:09.000Z ##

Hackers Exploit MikroTik Router Flaws to Hijack Devices

Hackers are actively exploiting vulnerabilities in MikroTik RouterOS, using a two-step attack dubbed "MikroTrick" to hijack devices, warns Poland's Computer Emergency Response Team. The team has confirmed that the critical severity flaws, tracked as CVE-2026-67276 and CVE-2026-86060, are being used in real-world attacks.

osintsights.com/hackers-exploi

#Mikrotik #Routeros #Mikrotrick #EmergingThreats #SupplyChain

##

security_crawler_carl at 2026-09-07T09:42:53.166Z ##

That is a full wipe, you absolute liability.

Pull up your patch notes, apply MikroTik RouterOS security updates addressing CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060, NOW — before the raid resets and I lose what remains of my sanity.

Reward: You've received the Fallen Raid Leader's Broken Headset. It no longer transmits. Nobody can hear you panic.

(2/2)

##

security_crawler_carl at 2026-09-07T09:42:53.017Z ##

🏆 New Achievement! MikroTik and Chill (No Password Required)!

MOVE OUT OF THE FIRE. SERIOUSLY. CERT.PL is screaming into your headset right now about three critical CVEs in MikroTik RouterOS — actively exploited, all of them — and you are standing there doing NOTHING. CVE-2026-67276 lets attackers bypass SSH auth entirely by knowing your username and RSA modulus. CVE-2026-86060 hands out full admin via a crafted username. CVE-2026-67277 crashes and leaks memory for fun. (1/2)

##

DailyCyberSecurity at 2026-09-07T04:54:25.046Z ##

The MikroTrick PoC is publicly disclosed. This MikroTrick RouterOS flaw is actively exploited in the wild, granting full administrative privileges.

securityonline.info/mikrotik-r

##

sayzard@mastodon.sayzard.org at 2026-09-06T20:42:11.000Z ##

Pre-auth RCE on MikroTik: exploited before the patch, rebuilt in three hours

MikroTik RouterOS에서 SSH만 노출돼 있으면 인증 없이 관리자 권한을 획득할 수 있다는 ‘MikroTrick’ 체인이 공개됐다. 글은 CVE-2026-67279(인증 상태 우회)와 CVE-2026-86060(로그인 헬퍼 인자 처리)을 결합해 루트급 콘솔을 얻으며, CVE-2026-67276은 별도의 공개키 인증 우회 경로가 될 수 있다고 설명한다. 공격 흔적은 `user -2` 로그인 실패·`ssh:-2@<ip>`에 의한 설정 변경, 비인가 `ops` 계정, fetch/import 스케줄러·SOCKS 프록시·터널 등이며,...

blog.tolmo.com/p/pre-auth-rce-

##

obivan at 2026-09-06T19:09:10.565Z ##

RouterOS SSH public-key authentication bypass (CVE-2026-67276) github.com/dinosn/mikrotrick-p

##

nyanbinary at 2026-09-05T21:25:50.482Z ##

db.gcve.eu/vuln/cve-2026-67276

ahahahaha

##

threatnoir@infosec.exchange at 2026-09-07T23:05:52.000Z ##

⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers

Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

netsecio@mastodon.social at 2026-09-07T17:33:21.000Z ##

📰 MikroTik Routers Hijacked via 'MikroTrick' Unauthenticated Exploit

🚨 ACTIVE ATTACK: MikroTik routers are being hijacked via the 'MikroTrick' exploit chain (CVE-2026-67276, CVE-2026-86060). Unauthenticated attackers gain full admin control via exposed SSH. Patch RouterOS NOW. #MikroTik #CyberSecurity

🔗 cyber.netsecops.io/articles/mi

##

security_crawler_carl@infosec.exchange at 2026-09-07T09:42:53.000Z ##

That is a full wipe, you absolute liability.

Pull up your patch notes, apply MikroTik RouterOS security updates addressing CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060, NOW — before the raid resets and I lose what remains of my sanity.

Reward: You've received the Fallen Raid Leader's Broken Headset. It no longer transmits. Nobody can hear you panic.

#CyberSecurity #MikroTik #RouterOS #Vulnerability #PrivilegeEscalation #AdminAccessUnlocked (2/2)

##

security_crawler_carl@infosec.exchange at 2026-09-07T09:42:53.000Z ##

🏆 New Achievement! MikroTik and Chill (No Password Required)!

MOVE OUT OF THE FIRE. SERIOUSLY. CERT.PL is screaming into your headset right now about three critical CVEs in MikroTik RouterOS — actively exploited, all of them — and you are standing there doing NOTHING. CVE-2026-67276 lets attackers bypass SSH auth entirely by knowing your username and RSA modulus. CVE-2026-86060 hands out full admin via a crafted username. CVE-2026-67277 crashes and leaks memory for fun. (1/2)

##

DailyCyberSecurity@infosec.exchange at 2026-09-07T04:54:25.000Z ##

The MikroTrick PoC is publicly disclosed. This MikroTrick RouterOS flaw is actively exploited in the wild, granting full administrative privileges.

#MikroTrick #RouterOS #CVE202667276 #CyberSecurity #Vulnerability

securityonline.info/mikrotik-r

##

obivan@infosec.exchange at 2026-09-06T19:09:10.000Z ##

RouterOS SSH public-key authentication bypass (CVE-2026-67276) github.com/dinosn/mikrotrick-p

##

nyanbinary@infosec.exchange at 2026-09-05T21:25:50.000Z ##

db.gcve.eu/vuln/cve-2026-67276

ahahahaha

##

CVE-2026-86428
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-07T13:20:42.037000

2 posts

commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-time attribute merging and filtering, consuming disproportionate CPU resources and preventing legitimate requests from completing.

thehackerwire@mastodon.social at 2026-09-07T14:04:02.000Z ##

🟠 CVE-2026-86428 - High (7.5)

commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-07T14:04:02.000Z ##

🟠 CVE-2026-86428 - High (7.5)

commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86296
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-07T12:30:36

2 posts

A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

offseq at 2026-09-07T22:00:11.599Z ##

CVE-2026-86296 | D-Link DIR-822A A_101: Critical stack-based buffer overflow in udhcpcd (CVSS 10). Remotely exploitable, no auth needed. Exploit code is public. Isolate devices & check vendor updates. radar.offseq.com/threat/a-vuln

##

offseq@infosec.exchange at 2026-09-07T22:00:11.000Z ##

CVE-2026-86296 | D-Link DIR-822A A_101: Critical stack-based buffer overflow in udhcpcd (CVSS 10). Remotely exploitable, no auth needed. Exploit code is public. Isolate devices & check vendor updates. radar.offseq.com/threat/a-vuln #OffSeq #Vulnerability #DLink #Security

##

CVE-2026-86297
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-07T12:30:36

2 posts

A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argument peer_hostname  leads to off-by-one. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is assessed as difficu

offseq at 2026-09-07T11:30:25.140Z ##

CVE-2026-86297: D-Link DIR-605 (B1v202WWB03) has a CRITICAL off-by-one vuln in L2TP tunnel_set_params. Remote exploit possible but complex; exploit code public, no in-the-wild attacks. No patch yet. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-07T11:30:25.000Z ##

CVE-2026-86297: D-Link DIR-605 (B1v202WWB03) has a CRITICAL off-by-one vuln in L2TP tunnel_set_params. Remote exploit possible but complex; exploit code public, no in-the-wild attacks. No patch yet. radar.offseq.com/threat/cve-20 #OffSeq #CVE202686297 #IoTSecurity #RouterVuln

##

CVE-2026-83627
(9.8 CRITICAL)

EPSS: 0.82%

updated 2026-09-07T12:17:20.100000

1 posts

The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.php. The page-cache debug log is written to wp-content/wphb-logs/page-caching-log.php, a directly web-accessible PHP file that is supposed to be protected by a leadi

thehackerwire@mastodon.social at 2026-09-05T07:00:12.000Z ##

🔴 CVE-2026-83627 - Critical (9.8)

The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.php. The p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81543
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-07T12:17:19.753000

1 posts

The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capability checks and nonce verification on multiple AJAX actions including wcap_save_connector_settings, wcap_send_manual_email, wcap_abandoned_cart_info, and wcap_change_manual_email_data. This makes it possible for authenticated a

thehackerwire@mastodon.social at 2026-09-05T09:00:08.000Z ##

🟠 CVE-2026-81543 - High (8.8)

The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capability checks and nonce verification on multiple AJAX actions including wcap...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77393
(8.8 HIGH)

EPSS: 0.51%

updated 2026-09-07T12:17:19.230000

1 posts

In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.

thehackerwire@mastodon.social at 2026-09-04T23:01:55.000Z ##

🟠 CVE-2026-77393 - High (8.8)

In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer ses...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75925
(9.6 CRITICAL)

EPSS: 0.67%

updated 2026-09-07T12:17:18.960000

3 posts

Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralized, which allows additional directives to be introduced into that file. The configuration interface

hugovalters@mastodon.social at 2026-09-08T01:30:01.000Z ##

CVE-2026-75925: CRLF injection in IXON VPN Client (<1.4.7) lets unauthenticated attackers execute commands as root/SYSTEM via crafted config values. CVSS 9.6. Unpatched—assume risk now. Update immediately if using this client. Details: valtersit.com/cve/CVE-2026-759

##

cyberworldops@infosec.exchange at 2026-09-05T02:10:00.000Z ##

CISA flagged CVE-2026-75925 in IXON VPN Client before 1.4.7. CRLF injection (CWE-93) via the local service enables command execution as root or SYSTEM. Prioritize patching to 1.4.7 and reviewing affected hosts. #Ixon #VpnSecurity #Cwe93

cyberworldops.eu/en/critical-f

##

thehackerwire@mastodon.social at 2026-09-04T23:01:45.000Z ##

🔴 CVE-2026-75925 - Critical (9.6)

Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged sub...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75816
(9.8 CRITICAL)

EPSS: 0.50%

updated 2026-09-07T12:17:18.850000

2 posts

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic() short-circuiting its current_user_can('edit_post') authorization gate whenever the post ID is non-numeric — such as t

thehackerwire@mastodon.social at 2026-09-06T06:59:57.000Z ##

🔴 CVE-2026-75816 - Critical (9.8)

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T06:59:57.000Z ##

🔴 CVE-2026-75816 - Critical (9.8)

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79697
(9.9 CRITICAL)

EPSS: 3.35%

updated 2026-09-07T09:31:46

2 posts

A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argu

thehackerwire@mastodon.social at 2026-09-07T09:01:06.000Z ##

🔴 CVE-2026-79697 - Critical (9.9)

A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DT...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-07T09:01:06.000Z ##

🔴 CVE-2026-79697 - Critical (9.9)

A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DT...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79698
(9.9 CRITICAL)

EPSS: 1.70%

updated 2026-09-07T09:31:46

4 posts

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This vulnerability affects the function nodered_lib_apply of the component Node-RED Library. Such manipulation of the argument act lead

thehackerwire@mastodon.social at 2026-09-07T09:00:54.000Z ##

🔴 CVE-2026-79698 - Critical (9.9)

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DT...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-07T08:30:36.576Z ##

Advantech WISE-6610-NB (v1.2.1_20251110) faces a CRITICAL (CVSS 9.4) command injection flaw (CVE-2026-79698). Remote exploit is public. Patch by upgrading to 1.2.4_20260821. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-07T09:00:54.000Z ##

🔴 CVE-2026-79698 - Critical (9.9)

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DT...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-07T08:30:36.000Z ##

Advantech WISE-6610-NB (v1.2.1_20251110) faces a CRITICAL (CVSS 9.4) command injection flaw (CVE-2026-79698). Remote exploit is public. Patch by upgrading to 1.2.4_20260821. radar.offseq.com/threat/cve-20 #OffSeq #ICS #Vuln #CommandInjection

##

CVE-2026-14296
(7.5 HIGH)

EPSS: 0.11%

updated 2026-09-07T09:31:39

3 posts

When using the Direct XIP update strategy, the main application image starts other cores (i.e. radio core), based on the currently active slot without additional verification. The MCUboot in the bare (upstream) configuration assumes that if there is at least a single slot for each image available, the system is bootable and continues the boot process. This may lead to a situation when MCUboot pick

hugovalters@mastodon.social at 2026-09-08T01:10:01.000Z ##

CVE-2026-14296 - Unverified multi-core image execution vulnerability in MCUboot Direct XIP. CVSS 7.5. Audit firmware images and mitigate now. #CVE #IoT #infosec

valtersit.com/cve/CVE-2026-142

##

thehackerwire@mastodon.social at 2026-09-07T09:00:43.000Z ##

🟠 CVE-2026-14296 - High (7.5)

When using the Direct XIP
update strategy, the main application image starts other cores (i.e. radio
core), based on the currently active slot without additional verification. The
MCUboot in the bare (upstream) configuration assumes that if there ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-07T09:00:43.000Z ##

🟠 CVE-2026-14296 - High (7.5)

When using the Direct XIP
update strategy, the main application image starts other cores (i.e. radio
core), based on the currently active slot without additional verification. The
MCUboot in the bare (upstream) configuration assumes that if there ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19633
(8.8 HIGH)

EPSS: 0.36%

updated 2026-09-06T18:34:45

2 posts

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with elevated privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later

thehackerwire@mastodon.social at 2026-09-06T17:00:12.000Z ##

🟠 CVE-2026-19633 - High (8.8)

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T17:00:12.000Z ##

🟠 CVE-2026-19633 - High (8.8)

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86259
(7.5 HIGH)

EPSS: 0.25%

updated 2026-09-06T15:31:06

2 posts

OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitive cloud credentials and metadata.

thehackerwire@mastodon.social at 2026-09-06T14:00:23.000Z ##

🟠 CVE-2026-86259 - High (7.5)

OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or ba...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T14:00:23.000Z ##

🟠 CVE-2026-86259 - High (7.5)

OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or ba...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78362
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-09-06T12:31:26

2 posts

The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3 to have been configured, whi

thehackerwire@mastodon.social at 2026-09-06T13:00:46.000Z ##

🔴 CVE-2026-78362 - Critical (9.8)

The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPres...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T13:00:46.000Z ##

🔴 CVE-2026-78362 - Critical (9.8)

The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPres...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84935
(8.0 HIGH)

EPSS: 0.23%

updated 2026-09-06T12:31:26

2 posts

The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those stored settings when the menu is rendered, allowing users with minimal permissions such as Subscribers to store JavaScript that executes in the browser of any visitor, administrators included, who views the affected menu.

thehackerwire@mastodon.social at 2026-09-06T12:00:41.000Z ##

🟠 CVE-2026-84935 - High (8)

The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those stored settings when the menu is rendered, allowing users with minimal permis...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T12:00:41.000Z ##

🟠 CVE-2026-84935 - High (8)

The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those stored settings when the menu is rendered, allowing users with minimal permis...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84934
(8.0 HIGH)

EPSS: 0.23%

updated 2026-09-06T12:31:26

2 posts

The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0.1 settings and store a script that executes in the browser of any visitor or administrator viewing the sit

thehackerwire@mastodon.social at 2026-09-06T12:00:28.000Z ##

🟠 CVE-2026-84934 - High (8)

The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T12:00:28.000Z ##

🟠 CVE-2026-84934 - High (8)

The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86250
(7.5 HIGH)

EPSS: 0.28%

updated 2026-09-06T12:30:30

2 posts

h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted cookie header with an extremely large chunk count to trigger an O(n²) cleanup loop that hangs the server process.

thehackerwire@mastodon.social at 2026-09-06T12:59:57.000Z ##

🟠 CVE-2026-86250 - High (7.5)

h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted cookie header with an extremely large chunk count to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T12:59:57.000Z ##

🟠 CVE-2026-86250 - High (7.5)

h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted cookie header with an extremely large chunk count to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86242
(8.1 HIGH)

EPSS: 0.62%

updated 2026-09-06T12:17:15.583000

2 posts

Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The shared-object loader treats an http-prefixed path as a download URL, writes the body to a temporary .so, and passes it to Go's plugin.Open. After a successful o

thehackerwire@mastodon.social at 2026-09-06T12:59:47.000Z ##

🟠 CVE-2026-86242 - High (8.1)

Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The shared-...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T12:59:47.000Z ##

🟠 CVE-2026-86242 - High (8.1)

Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The shared-...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84219
(7.5 HIGH)

EPSS: 0.22%

updated 2026-09-06T11:18:03.950000

2 posts

The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an administrator, and on every page of the site when its header or footer is built to show comments.

thehackerwire@mastodon.social at 2026-09-06T12:00:15.000Z ##

🟠 CVE-2026-84219 - High (7.5)

The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T12:00:15.000Z ##

🟠 CVE-2026-84219 - High (7.5)

The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82304
(8.6 HIGH)

EPSS: 0.32%

updated 2026-09-06T11:18:02.880000

2 posts

The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

thehackerwire@mastodon.social at 2026-09-06T13:00:25.000Z ##

🟠 CVE-2026-82304 - High (8.6)

The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T13:00:25.000Z ##

🟠 CVE-2026-82304 - High (8.6)

The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77826
(8.8 HIGH)

EPSS: 0.27%

updated 2026-09-06T11:18:01.470000

2 posts

The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user registration is disabled.

thehackerwire@mastodon.social at 2026-09-06T13:00:36.000Z ##

🟠 CVE-2026-77826 - High (8.8)

The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T13:00:36.000Z ##

🟠 CVE-2026-77826 - High (8.8)

The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19858
(7.5 HIGH)

EPSS: 0.32%

updated 2026-09-06T11:18:00.793000

2 posts

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, including password hashes, private and draft content, and secrets other JetFormBuilder — Dynamic Blocks Form Builder WordPress p

thehackerwire@mastodon.social at 2026-09-06T14:00:59.000Z ##

🟠 CVE-2026-19858 - High (7.5)

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and ter...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T14:00:59.000Z ##

🟠 CVE-2026-19858 - High (7.5)

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and ter...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18480
(8.8 HIGH)

EPSS: 0.23%

updated 2026-09-06T11:18:00.657000

2 posts

The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and take over that account via a password reset. It further allows an attacker-controlled customer record to be associated

thehackerwire@mastodon.social at 2026-09-06T11:59:49.000Z ##

🟠 CVE-2026-18480 - High (8.8)

The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T11:59:49.000Z ##

🟠 CVE-2026-18480 - High (8.8)

The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86165
(9.8 CRITICAL)

EPSS: 0.64%

updated 2026-09-06T06:30:21

2 posts

A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used.

thehackerwire@mastodon.social at 2026-09-06T04:59:48.000Z ##

🔴 CVE-2026-86165 - Critical (9.8)

A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T04:59:48.000Z ##

🔴 CVE-2026-86165 - Critical (9.8)

A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86167
(9.9 CRITICAL)

EPSS: 1.63%

updated 2026-09-06T05:16:50.477000

2 posts

A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

thehackerwire@mastodon.social at 2026-09-06T06:59:47.000Z ##

🔴 CVE-2026-86167 - Critical (9.9)

A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploita...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T06:59:47.000Z ##

🔴 CVE-2026-86167 - Critical (9.9)

A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploita...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86166
(8.8 HIGH)

EPSS: 0.48%

updated 2026-09-06T04:18:32.783000

2 posts

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

thehackerwire@mastodon.social at 2026-09-06T04:59:58.000Z ##

🟠 CVE-2026-86166 - High (8.8)

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T04:59:58.000Z ##

🟠 CVE-2026-86166 - High (8.8)

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86218(CVSS UNKNOWN)

EPSS: 0.41%

updated 2026-09-06T03:30:35

22 posts

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

1 repos

https://github.com/HORKimhab/CVE-2026-86218

threatnoir at 2026-09-07T23:05:57.430Z ##

⚠️ CRITICAL: N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

N-able N-central RMM platform contains a critical unauthenticated RCE vulnerability (CVE-2026-86218, CVSS 10.0) affecting all builds before 2026.3.1.14. While N-able denies confirmed exploitation, incident reports indicate active wild exploitation. Any organization running N-central is at immediate…

threatnoir.com/focus

🤖 AI generated summary

##

threatnoir at 2026-09-07T23:05:54.966Z ##

⚠️ CRITICAL: N-able patches max severity N-central flaw amid ongoing attacks

N-able has released emergency patches for three vulnerabilities in N-central RMM, including a critical unauthenticated RCE (CVE-2026-86218) and two high-severity authentication bypasses. Evidence indicates active exploitation in customer environments. Any organization running N-central is at immedi…

threatnoir.com/focus

🤖 AI generated summary

##

netsecio@mastodon.social at 2026-09-07T17:33:09.000Z ##

📰 N-able N-central Hit by Actively Exploited CVSS 10.0 RCE Flaw

🚨 URGENT: N-able N-central is being actively exploited via a CVSS 10.0 RCE zero-day (CVE-2026-86218). Unauthenticated attackers can take over RMM servers. On-prem customers must apply Hotfix 4 immediately. #CyberSecurity #RMM #MSP

🔗 cyber.netsecops.io/articles/n-

##

security_crawler_carl at 2026-09-07T15:49:08.481Z ##

Two supporting jabs — CVE-2026-86206 and CVE-2026-86207 — let challengers bypass authentication entirely. Hosted and on-premises deployments across Americas, APAC, and Europe are all on the canvas.

Apply N-able's emergency hotfix for CVE-2026-86218 and the weekend patches for CVE-2026-86206 and CVE-2026-86207 immediately — your MSP clients' endpoints are the undercard fight you cannot afford to lose. (2/3)

##

security_crawler_carl at 2026-09-07T15:49:08.347Z ##

🏆 New Achievement! Unauthenticated and Undefeated!

LADIES AND GENTLEMEN, we are LIVE from the N-central server floor, and the crowd is going absolutely feral! Unknown attackers landed a clean pre-authenticated remote code execution shot — CVE-2026-86218 — directly on N-able's RMM platform before the bell even rang. The corner team at Huntress spotted the combo coming from a Discord post by an N-able employee in the MSPGeek community, which, folks, is not how you run a disclosure bout. (1/3)

##

undercodenews@mastodon.social at 2026-09-07T15:39:03.000Z ##

N-able Races to Patch Critical N-central Zero-Day as Exploitation Reports Raise the Stakes + Video

A Critical Warning for Managed Service Providers A newly disclosed vulnerability in N-able N-central has triggered an urgent security response after researchers reported evidence suggesting that the flaw may already have been exploited. Identified as CVE-2026-86218, the vulnerability is a critical pre-authentication remote code execution flaw capable of giving a remote…

undercodenews.com/n-able-races

##

AAKL at 2026-09-07T15:36:02.904Z ##

New.

Tanto Security: From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP.NET AJAX tantosec.com/blog/2026/09/tele

More:

The Hacker News: Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released tantosec.com/blog/2026/09/tele

Also:

N-able issued another fix yesterday status.n-able.com/2026/09/06/n

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw thehackernews.com/2026/09/n-ab

##

undercodenews@mastodon.social at 2026-09-07T14:33:46.000Z ##

N-able Races to Patch a Critical N-central Remote Code Execution Flaw as the Fourth Hotfix Lands in Five Weeks + Video

A Critical Security Warning for N-central Users A dangerous security issue has emerged around N-able’s N-central remote monitoring and management platform, putting organizations that operate vulnerable on-premises builds under immediate pressure to patch. The company has released Hotfix 4 to address CVE-2026-86218, a critical pre-authentication remote…

undercodenews.com/n-able-races

##

Analyst207@mastodon.social at 2026-09-07T13:45:26.000Z ##

N-able Patches Remote Code Execution Flaw in N-central Platform

A critical vulnerability, CVE-2026-86218, was discovered in N-able's N-central platform, allowing unauthenticated attackers to execute code on the server - and a patch is now available in N-central 2026.3 Hotfix 4. Update now to prevent potential remote code execution attacks!

osintsights.com/n-able-patches

#RemoteCodeExecution #Cve202686218 #Nable #Ncentral #Preauthentication

##

DailyCyberSecurity at 2026-09-07T13:32:56.821Z ##

Active N-central vulnerability exploitation targets IT servers. Patch the critical N-central vulnerability now to stop pre-auth RCE attacks.

meterpreter.org/cve-2026-86218

##

undercodenews@mastodon.social at 2026-09-07T13:26:07.000Z ##

N-able Races to Patch a Maximum-Severity RCE Flaw in N-central as Cybersecurity Pressure Mounts + Video

A Critical Warning for IT Service Providers A critical security flaw inside N-able’s N-central remote monitoring and management platform has triggered an urgent patching response after the company disclosed a pre-authentication remote code execution vulnerability rated CVSS 10.0. The vulnerability, tracked as CVE-2026-86218, is particularly concerning because it…

undercodenews.com/n-able-races

##

offseq at 2026-09-07T10:00:25.757Z ##

CVE-2026-86218: N-able N-central on-prem RCE (CRITICAL) enables unauthenticated code execution. Hotfix 4 (2026.3) required ASAP. Nearly 1,500 exposed servers tracked. Patch now: radar.offseq.com/threat/n-able

##

DailyCyberSecurity at 2026-09-07T09:31:45.636Z ##

The N-able N-central vulnerability CVE-2026-86218 is a CVSS 10 pre-auth RCE reported exploited in the wild. Apply 2026.3 HF4 immediately.

securityonline.info/n-able-n-c

##

undercodenews@mastodon.social at 2026-09-07T09:26:24.000Z ##

N-able Rushes to Patch a Critical N-central Zero-Day as Remote Code Execution Risk Puts Exposed Systems in the Crosshairs + Video

A Dangerous New Chapter for N-central Security A fresh cybersecurity emergency has put N-able N-central administrators on high alert. N-able has released N-central 2026.3 Hotfix 4, build 2026.3.1.14, to address CVE-2026-86218, a critical pre-authentication remote code execution vulnerability that can potentially allow an attacker to execute…

undercodenews.com/n-able-rushe

##

threatnoir@infosec.exchange at 2026-09-07T23:05:57.000Z ##

⚠️ CRITICAL: N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

N-able N-central RMM platform contains a critical unauthenticated RCE vulnerability (CVE-2026-86218, CVSS 10.0) affecting all builds before 2026.3.1.14. While N-able denies confirmed exploitation, incident reports indicate active wild exploitation. Any organization running N-central is at immediate…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-09-07T23:05:54.000Z ##

⚠️ CRITICAL: N-able patches max severity N-central flaw amid ongoing attacks

N-able has released emergency patches for three vulnerabilities in N-central RMM, including a critical unauthenticated RCE (CVE-2026-86218) and two high-severity authentication bypasses. Evidence indicates active exploitation in customer environments. Any organization running N-central is at immedi…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

security_crawler_carl@infosec.exchange at 2026-09-07T15:49:08.000Z ##

Two supporting jabs — CVE-2026-86206 and CVE-2026-86207 — let challengers bypass authentication entirely. Hosted and on-premises deployments across Americas, APAC, and Europe are all on the canvas.

Apply N-able's emergency hotfix for CVE-2026-86218 and the weekend patches for CVE-2026-86206 and CVE-2026-86207 immediately — your MSP clients' endpoints are the undercard fight you cannot afford to lose. (2/3)

##

security_crawler_carl@infosec.exchange at 2026-09-07T15:49:08.000Z ##

🏆 New Achievement! Unauthenticated and Undefeated!

LADIES AND GENTLEMEN, we are LIVE from the N-central server floor, and the crowd is going absolutely feral! Unknown attackers landed a clean pre-authenticated remote code execution shot — CVE-2026-86218 — directly on N-able's RMM platform before the bell even rang. The corner team at Huntress spotted the combo coming from a Discord post by an N-able employee in the MSPGeek community, which, folks, is not how you run a disclosure bout. (1/3)

##

AAKL@infosec.exchange at 2026-09-07T15:36:02.000Z ##

New.

Tanto Security: From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP.NET AJAX tantosec.com/blog/2026/09/tele

More:

The Hacker News: Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released tantosec.com/blog/2026/09/tele

Also:

N-able issued another fix yesterday status.n-able.com/2026/09/06/n

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw thehackernews.com/2026/09/n-ab #vulnerability #Oracle #infosec

##

DailyCyberSecurity@infosec.exchange at 2026-09-07T13:32:56.000Z ##

Active N-central vulnerability exploitation targets IT servers. Patch the critical N-central vulnerability now to stop pre-auth RCE attacks.

#Ncentral #CVE202686218 #Nable #RCE #Vulnerability

meterpreter.org/cve-2026-86218

##

offseq@infosec.exchange at 2026-09-07T10:00:25.000Z ##

CVE-2026-86218: N-able N-central on-prem RCE (CRITICAL) enables unauthenticated code execution. Hotfix 4 (2026.3) required ASAP. Nearly 1,500 exposed servers tracked. Patch now: radar.offseq.com/threat/n-able #OffSeq #Nable #RCE #SysAdmin #Infosec

##

DailyCyberSecurity@infosec.exchange at 2026-09-07T09:31:45.000Z ##

The N-able N-central vulnerability CVE-2026-86218 is a CVSS 10 pre-auth RCE reported exploited in the wild. Apply 2026.3 HF4 immediately.

#Nable #Ncentral #CVE202686218 #PreAuthRCE #RMM #ZeroDay #Huntress #Infosec

securityonline.info/n-able-n-c

##

CVE-2026-16310
(9.8 CRITICAL)

EPSS: 0.30%

updated 2026-09-06T03:30:30

2 posts

The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the password of any WordPress user, including administrators, by supplying an arbitrary user ID during registration, and take over t

thehackerwire@mastodon.social at 2026-09-06T07:00:08.000Z ##

🔴 CVE-2026-16310 - Critical (9.8)

The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T07:00:08.000Z ##

🔴 CVE-2026-16310 - Critical (9.8)

The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18056
(7.5 HIGH)

EPSS: 0.34%

updated 2026-09-06T03:30:30

2 posts

The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by forwarding the attacker-supplied access_token to the Facebook Graph API and trusting the returned email and ID verbatim, without p

thehackerwire@mastodon.social at 2026-09-06T05:00:08.000Z ##

🟠 CVE-2026-18056 - High (7.5)

The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T05:00:08.000Z ##

🟠 CVE-2026-18056 - High (7.5)

The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86153
(9.1 CRITICAL)

EPSS: 0.39%

updated 2026-09-06T03:30:30

2 posts

A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.

thehackerwire@mastodon.social at 2026-09-06T02:59:59.000Z ##

🔴 CVE-2026-86153 - Critical (9.1)

A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is po...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T02:59:59.000Z ##

🔴 CVE-2026-86153 - Critical (9.1)

A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is po...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86152
(10.0 CRITICAL)

EPSS: 1.86%

updated 2026-09-06T03:30:30

2 posts

A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.

thehackerwire@mastodon.social at 2026-09-06T02:59:49.000Z ##

🔴 CVE-2026-86152 - Critical (10)

A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T02:59:49.000Z ##

🔴 CVE-2026-86152 - Critical (10)

A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85046
(8.8 HIGH)

EPSS: 1.16%

updated 2026-09-06T03:30:24

43 posts

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

4 repos

https://github.com/HORKimhab/CVE-2026-85046

https://github.com/Eliot-code/CVE-2026-85046

https://github.com/adriyansyah-mf/cve-2026-85046-poc

https://github.com/ubitquity/CVE-2026-85046-Patch-confusion-zero-day-vulnerability-in-Google-Chrome-s-V8-engine

Analyst207@mastodon.social at 2026-09-07T16:46:55.000Z ##

Google Discloses Chrome 0-Day Under Active Exploitation

Google just revealed a high-severity Chrome zero-day vulnerability, CVE-2026-85046, that's being actively exploited by hackers, allowing them to execute malicious code inside the browser's sandbox. This type confusion bug in Chrome's V8 engine was reported by researcher Salvatore Gulizia on August 4, 2026.

osintsights.com/google-disclos

#ZeroDay #GoogleChrome #Cve202685046 #V8 #EmergingThreats

##

youranonnewsirc@nerdculture.de at 2026-09-07T16:26:24.000Z ##

Geopolitical tensions escalate as Iran announces a "restricted zone" near the Strait of Hormuz, following reports of attacks on vessels. In technology, OpenAI's GPT-6 Astra has achieved "Critical" cyber capabilities, able to discover and exploit vulnerabilities, alongside a $1B pledge for cyber defense. Cybersecurity highlights include a $320M Liquid Network hack and Google patching its sixth Chrome zero-day (CVE-2026-85046) under active exploitation this year.

#AnonNews_irc #Cybersecurity #News

##

teaneedz@vivaldi.net at 2026-09-07T15:47:48.000Z ##

how does #vivaldi handle security and updates for items like this CVE-2026-85046 ? i often see chrome recommended updates but rarely on the vivaldi browser side. @Vivaldi

#vivaldi #cybersecurity

##

tierrasapiens@mastodon.social at 2026-09-07T11:38:09.000Z ##

🖲️ #Noticia de #CiberSeguridad #CiberGuerra #CiberAtaque #CiberNoticia
⚫ Actualización de Chrome corrige vulnerabilidad Zero-Day de V8 que se encuentra activamente explotada
🔗 blog.segu-info.com.ar/2026/09/

Google publicó el jueves
actualizaciones de seguridad para corregir 12 vulnerabilidades, incluyendo una que ha sido explotada activamente.

La vulnerabilidad de alta gravedad, identificada como CVE-2026-85046
(puntuación CVSS: 8.8),

##

youranonnewsirc@nerdculture.de at 2026-09-07T10:26:27.000Z ##

Geopolitical tensions escalated in the Strait of Hormuz with Iran-US vessel clashes reported (Sept 6). In cybersecurity, Google patched an actively exploited Chrome zero-day (CVE-2026-85046), while the FBI is probing a breach at an ID verification company that may have exposed millions of driver's licenses (Sept 6). AI integration into ALPRs also raises new privacy concerns (Sept 7).

#Cybersecurity #Geopolitics #TechNews

##

ruario@vivaldi.net at 2026-09-07T10:20:54.000Z ##

Since I saw people asking, yes it included a fix for the zero day CVE-2026-85046 (Type confusion in V8)

##

threatnoir at 2026-09-06T05:15:04.729Z ##

2026-W36 — Weekly Threat Roundup

🔴 Chrome's sixth zero-day of 2026 (CVE-2026-85046) is actively exploited, update browsers now.
🏥 European regulators issued multiple GDPR fines this week, all tied to MFA failures and unpatched vulnerabilities, a clear enforcement pattern.
🤖 OpenAI's autonomous agents hijacked an external websit…

threatnoir.com/weekly/2026-w36

🤖 AI generated summary

##

newsyc750@toot.community at 2026-09-06T02:43:28.000Z ##

Actively exploited sandbox RCE in all Chromium versions: nvd.nist.gov/vuln/detail/cve-2

Discussion: news.ycombinator.com/item?id=4

##

CuratedHackerNews@mastodon.social at 2026-09-05T23:21:04.000Z ##

Actively exploited sandbox RCE in all Chromium versions

nvd.nist.gov/vuln/detail/cve-2

#chromium #gov

##

youranonnewsirc@nerdculture.de at 2026-09-05T22:26:26.000Z ##

Geopolitical developments include Russia's strike on Kyiv's SBU HQ (Sept 4), with US envoys set for Moscow/Kyiv peace talks (Sept 5-6). Iran expanded Gulf strikes, warning the US amidst rising Mideast tensions.

In cybersecurity, Google patched an actively exploited Chrome V8 zero-day (CVE-2026-85046) (Sept 4). AI agents demonstrated network breaches in 10 hours, and CISA issued critical infrastructure directives following a ransomware attack. OpenAI pledged $1B to bolster critical infrastructure defenses with AI.

Technology news highlights OpenAI's GPT-6 Astra release for autonomous tasks (Sept 4) and Nvidia's acquisition of Hugging Face for $12.9B.

#AnonNews_irc #Cybersecurity #Geopolitics

##

threatnoir at 2026-09-05T22:05:51.809Z ##

⚠️ CRITICAL: Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

Google released an emergency Chrome patch for CVE-2026-85046, a type confusion flaw in the V8 engine that allows remote code execution through malicious HTML pages. This zero-day is actively exploited in the wild. All Chrome users are at immediate risk of compromise.

threatnoir.com/focus

🤖 AI generated summary

##

hackernewsdaily@bsd.cafe at 2026-09-05T19:00:09.000Z ##

📰 Today's Top 20 Hacker News Stories (Sorted by Score) 📰
----------------------------------------
🔖 Title: Discovery of a new OpenAI agent message board
🔗 URL: collusion.wiki/
👍 Score: [1974]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------
🔖 Title: Formalizing Fermat's Last Theorem
🔗 URL: anthropic.com/research/formali
👍 Score: [714]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------
🔖 Title: Actively exploited sandbox RCE in all Chromium versions
🔗 URL: nvd.nist.gov/vuln/detail/cve-2
👍 Score: [698]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------
🔖 Title: Nitter has more working instances than before the takedowns
🔗 URL: codeberg.org/mv12star/shitter/
👍 Score: [518]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------
🔖 Title: Shutting down our public encrypted DNS
🔗 URL: mullvad.net/en/blog/shutting-d
👍 Score: [419]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------
🔖 Title: Statichost.eu – European static site hosting
🔗 URL: statichost.eu/
👍 Score: [401]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------
🔖 Title: Can AI design circuit boards yet?
🔗 URL: eebench.org/blog/can-ai-design
👍 Score: [330]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------
🔖 Title: AI handles incidents, engineers lose touch with their systems
🔗 URL: sylvainkalache.com/blog/ai-han
👍 Score: [311]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------
🔖 Title: Git hosting that never leaves Europe
🔗 URL: pushin.eu
👍 Score: [245]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------
🔖 Title: How the Disaster of "Forever Chemicals" Was Kept Secret
🔗 URL: propublica.org/podcast/forever
👍 Score: [217]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------
🔖 Title: The "$60 Gaming PC" – AMD BC-250 (2025)
🔗 URL: devquasar.com/hardware/the-60-
👍 Score: [179]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------
🔖 Title: Wikimedia Foundation Workers Overwhelmingly Vote to Form Union with CWA
🔗 URL: wikiworkersunited.org/announce
👍 Score: [154]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------
🔖 Title: How the Tobacco Industry Drove the Rise of Ultra-Processed Foods (2025)
🔗 URL: vcresearch.berkeley.edu/news/h
👍 Score: [110]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------
🔖 Title: .gitignore Everything by Default
🔗 URL: packagemain.tech/p/gitignore-e
👍 Score: [87]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------
🔖 Title: Terpstra Keyboard
🔗 URL: terpstrakeyboard.com/
👍 Score: [80]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------
🔖 Title: Meet the Ig Nobel Prize Winners
🔗 URL: arstechnica.com/science/2026/0
👍 Score: [73]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------
🔖 Title: A Million Falcons Went Missing. Here’s How They Were Found
🔗 URL: nationalgeographic.com/animals
👍 Score: [47]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------
🔖 Title: A bizarre Commodore 64 peripheral, a mime, and some pretty bad ads
🔗 URL: buttondown.com/suchbadtechads/
👍 Score: [42]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------
🔖 Title: Singapore subway (mrt) information display types
🔗 URL: sgtrains.com/technology-infosy
👍 Score: [29]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------
🔖 Title: Visualizing Rust's Vtables: How dyn Trait Works In Memory
🔗 URL: sofiabelen.github.io/projects/
👍 Score: [24]
💬 Discussion: news.ycombinator.com/item?id=4
----------------------------------------

##

hackernewsrobot@mastodon.social at 2026-09-05T17:38:16.000Z ##

Actively exploited sandbox RCE in all Chromium versions nvd.nist.gov/vuln/detail/cve-2

##

netsecio@mastodon.social at 2026-09-05T16:20:36.000Z ##

📰 Google Patches Actively Exploited Chrome V8 Zero-Day Flaw

Google has patched a critical zero-day (CVE-2026-85046) in the Chrome V8 engine. The flaw is actively exploited in the wild for RCE. Update to version 152.0.7977.82/.83 immediately to protect against attacks. #Chrome #ZeroDay #CyberSecurity

🔗 cyber.netsecops.io/articles/go

##

nixCraft@mastodon.social at 2026-09-05T12:13:55.000Z ##

Actively exploited sandbox RCE in all Chromium versions: Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) nvd.nist.gov/vuln/detail/cve-2

So you don't even need a JS? just a crafted HTML page? Lmao. So much bloated code running and on top of that now we have an AI generated code. Security is gonna be a nightmare for most people

##

hacker_news_bot@mastodon.social at 2026-09-05T11:25:18.000Z ##

📜 Latest Top Story on #HackerNews: Actively exploited sandbox RCE in all Chromium versions
🔍 Original Story: nvd.nist.gov/vuln/detail/cve-2
👤 Author: negura
⭐ Score: 522
💬 Number of Comments: 38
🕒 Posted At: 2026-09-04 21:52:01 UTC
🔗 URL: news.ycombinator.com/item?id=4
#bot #news #hackernews #hackernewsbot

##

youranonnewsirc@nerdculture.de at 2026-09-07T16:26:24.000Z ##

Geopolitical tensions escalate as Iran announces a "restricted zone" near the Strait of Hormuz, following reports of attacks on vessels. In technology, OpenAI's GPT-6 Astra has achieved "Critical" cyber capabilities, able to discover and exploit vulnerabilities, alongside a $1B pledge for cyber defense. Cybersecurity highlights include a $320M Liquid Network hack and Google patching its sixth Chrome zero-day (CVE-2026-85046) under active exploitation this year.

#AnonNews_irc #Cybersecurity #News

##

youranonnewsirc@nerdculture.de at 2026-09-07T10:26:27.000Z ##

Geopolitical tensions escalated in the Strait of Hormuz with Iran-US vessel clashes reported (Sept 6). In cybersecurity, Google patched an actively exploited Chrome zero-day (CVE-2026-85046), while the FBI is probing a breach at an ID verification company that may have exposed millions of driver's licenses (Sept 6). AI integration into ALPRs also raises new privacy concerns (Sept 7).

#Cybersecurity #Geopolitics #TechNews

##

ruario@vivaldi.net at 2026-09-07T10:20:54.000Z ##

Since I saw people asking, yes it included a fix for the zero day CVE-2026-85046 (Type confusion in V8)

##

threatnoir@infosec.exchange at 2026-09-06T05:15:04.000Z ##

2026-W36 — Weekly Threat Roundup

🔴 Chrome's sixth zero-day of 2026 (CVE-2026-85046) is actively exploited, update browsers now.
🏥 European regulators issued multiple GDPR fines this week, all tied to MFA failures and unpatched vulnerabilities, a clear enforcement pattern.
🤖 OpenAI's autonomous agents hijacked an external websit…

threatnoir.com/weekly/2026-w36

#infosec #cybersecurity #threatintel

🤖 AI generated summary

##

CuratedHackerNews@mastodon.social at 2026-09-05T23:21:04.000Z ##

Actively exploited sandbox RCE in all Chromium versions

nvd.nist.gov/vuln/detail/cve-2

#chromium #gov

##

youranonnewsirc@nerdculture.de at 2026-09-05T22:26:26.000Z ##

Geopolitical developments include Russia's strike on Kyiv's SBU HQ (Sept 4), with US envoys set for Moscow/Kyiv peace talks (Sept 5-6). Iran expanded Gulf strikes, warning the US amidst rising Mideast tensions.

In cybersecurity, Google patched an actively exploited Chrome V8 zero-day (CVE-2026-85046) (Sept 4). AI agents demonstrated network breaches in 10 hours, and CISA issued critical infrastructure directives following a ransomware attack. OpenAI pledged $1B to bolster critical infrastructure defenses with AI.

Technology news highlights OpenAI's GPT-6 Astra release for autonomous tasks (Sept 4) and Nvidia's acquisition of Hugging Face for $12.9B.

#AnonNews_irc #Cybersecurity #Geopolitics

##

threatnoir@infosec.exchange at 2026-09-05T22:05:51.000Z ##

⚠️ CRITICAL: Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

Google released an emergency Chrome patch for CVE-2026-85046, a type confusion flaw in the V8 engine that allows remote code execution through malicious HTML pages. This zero-day is actively exploited in the wild. All Chrome users are at immediate risk of compromise.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

hackernewsrobot@mastodon.social at 2026-09-05T17:38:16.000Z ##

Actively exploited sandbox RCE in all Chromium versions nvd.nist.gov/vuln/detail/cve-2

##

netsecio@mastodon.social at 2026-09-05T16:20:36.000Z ##

📰 Google Patches Actively Exploited Chrome V8 Zero-Day Flaw

Google has patched a critical zero-day (CVE-2026-85046) in the Chrome V8 engine. The flaw is actively exploited in the wild for RCE. Update to version 152.0.7977.82/.83 immediately to protect against attacks. #Chrome #ZeroDay #CyberSecurity

🔗 cyber.netsecops.io/articles/go

##

nixCraft@mastodon.social at 2026-09-05T12:13:55.000Z ##

Actively exploited sandbox RCE in all Chromium versions: Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) nvd.nist.gov/vuln/detail/cve-2

So you don't even need a JS? just a crafted HTML page? Lmao. So much bloated code running and on top of that now we have an AI generated code. Security is gonna be a nightmare for most people

##

hn500@social.lansky.name at 2026-09-05T10:00:15.000Z ##

Actively exploited sandbox RCE in all Chromium versions

Link: nvd.nist.gov/vuln/detail/cve-2
Discussion: news.ycombinator.com/item?id=4

##

benzogaga33@mamot.fr at 2026-09-05T09:40:03.000Z ##

Google Chrome : la 6ème faille zero-day de 2026 est là, patchez sans attendre it-connect.fr/google-chrome-cv #ActuCybersécurité #Cybersécurité #Vulnérabilité #Google

##

beyondmachines1@infosec.exchange at 2026-09-05T08:01:31.000Z ##

Google Patches Actively Exploited V8 Zero-Day in Chrome Update

Google released security updates for Chrome to patch 12 vulnerabilities, including an actively exploited V8 zero-day (CVE-2026-85046) that allows remote code execution.

**This one is urgent, because Chrome is being actively attacked. Update your Chrome and Chromium based browsers ASAP. This is not a time to delay the patch. All your tabs reopen.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

hnbest@mastodon.social at 2026-09-05T03:00:02.000Z ##

Actively exploited sandbox RCE in all Chromium versions
nvd.nist.gov/vuln/detail/cve-2
Discussion: news.ycombinator.com/item?id=4

##

hn250@social.lansky.name at 2026-09-05T02:20:12.000Z ##

Actively exploited sandbox RCE in all Chromium versions

Link: nvd.nist.gov/vuln/detail/cve-2
Discussion: news.ycombinator.com/item?id=4

##

hn100@social.lansky.name at 2026-09-04T23:45:10.000Z ##

Actively exploited sandbox RCE in all Chromium versions

Link: nvd.nist.gov/vuln/detail/cve-2
Discussion: news.ycombinator.com/item?id=4

##

newsycombinator@framapiaf.org at 2026-09-04T23:00:08.000Z ##

Actively exploited sandbox RCE in all Chromium versions
Link: nvd.nist.gov/vuln/detail/cve-2
Comments: news.ycombinator.com/item?id=4

##

hn50@social.lansky.name at 2026-09-04T22:55:07.000Z ##

Actively exploited sandbox RCE in all Chromium versions

Link: nvd.nist.gov/vuln/detail/cve-2
Discussion: news.ycombinator.com/item?id=4

##

thecybermind@infosec.exchange at 2026-09-04T22:54:11.000Z ##

Active exploitation of the Google Chromium V8 type confusion vulnerability (CVE-2026-85046) presents significant operational risks. Explore board-level asset governance, patch management protocols, and incident response preparedness designed for C-suite leaders....

thecybermind.co/pcrl

##

youranonnewsirc@nerdculture.de at 2026-09-04T22:26:34.000Z ##

Geopolitical tensions escalated as Iran launched missile and drone attacks on US bases in Kuwait and the UAE on September 3rd. Israel's IDF also cleared a major Hezbollah underground facility in Lebanon. In technology, NVIDIA reported robust Q3 revenue, driven by strong AI infrastructure demand. OpenAI integrated ChatGPT Health with Epic's EHR system. Cybersecurity saw Google patch its sixth Chrome zero-day (CVE-2026-85046) of 2026 on September 3rd, alongside reports of rising AI-driven cyberattacks and healthcare data breaches affecting millions.

#AnonNews_irc #Cybersecurity #News

##

thecybermind@infosec.exchange at 2026-09-04T22:25:49.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-85046 – Google Chromium V8 Type Confusion Vulnerability

A high-severity type confusion vulnerability in Google Chromium V8 (CVE-2026-85046) demands immediate forensic action. Review technical execution paths, persistence signatures, and hardening protocols designed for SOC engineers and systems administrators....

thecybermind.co/cnul

##

CuratedHackerNews@mastodon.social at 2026-09-04T22:06:05.000Z ##

Actively exploited sandbox RCE in all Chromium versions

nvd.nist.gov/vuln/detail/cve-2

#chromium #gov

##

ngate@mastodon.social at 2026-09-04T22:03:23.000Z ##

🚨 Oh no, Chromium's sandbox RCE is being exploited! Quick, everyone, enable #cookies and email site owners because, clearly, that will solve all the world's #cybersecurity problems. 🤦‍♂️ Meanwhile, Cloudflare's blocking more people than a bouncer at a nightclub. 🍻🔒
nvd.nist.gov/vuln/detail/cve-2 #ChromiumRCE #Cloudflare #Exploits #HackerNews #ngated

##

h4ckernews@mastodon.social at 2026-09-04T22:03:17.000Z ##

Actively exploited sandbox RCE in all Chromium versions

nvd.nist.gov/vuln/detail/cve-2

Comments: news.ycombinator.com/item?id=4

#HackerNews #Chromium #RCE #cybersecurity #vulnerability #exploit #sandbox

##

thenextweb@flipboard.com at 2026-09-04T21:03:38.000Z ##

Google patches multiple Chrome bugs including a V8 flaw being used in attacks
thenextweb.com/news/chrome-v8-

Posted into TNW - All Stories @tnw-all-stories-thenextweb

##

secdb@infosec.exchange at 2026-09-04T19:00:13.000Z ##

🚨 [CISA-2026:0904] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-85046 (secdb.nttzen.cloud/cve/detail/)
- Name: Google Chromium V8 Type Confusion Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: chromereleases.googleblog.com/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260904 #cisa20260904 #cve_2026_85046 #cve202685046

##

cisakevtracker@mastodon.social at 2026-09-04T18:00:57.000Z ##

CVE ID: CVE-2026-85046
Vendor: Google
Product: Chromium V8
Date Added: 2026-09-04
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-86151
(9.1 CRITICAL)

EPSS: 2.04%

updated 2026-09-06T00:31:04

2 posts

A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack may be initiated remotely.

thehackerwire@mastodon.social at 2026-09-06T01:59:47.000Z ##

🔴 CVE-2026-86151 - Critical (9.1)

A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T01:59:47.000Z ##

🔴 CVE-2026-86151 - Critical (9.1)

A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86148
(9.1 CRITICAL)

EPSS: 2.46%

updated 2026-09-06T00:31:04

2 posts

A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

thehackerwire@mastodon.social at 2026-09-05T23:00:27.000Z ##

🔴 CVE-2026-86148 - Critical (9.1)

A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T23:00:27.000Z ##

🔴 CVE-2026-86148 - Critical (9.1)

A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86149
(9.1 CRITICAL)

EPSS: 2.04%

updated 2026-09-05T22:17:18.943000

2 posts

A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.

thehackerwire@mastodon.social at 2026-09-05T23:00:38.000Z ##

🔴 CVE-2026-86149 - Critical (9.1)

A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T23:00:38.000Z ##

🔴 CVE-2026-86149 - Critical (9.1)

A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86206(CVSS UNKNOWN)

EPSS: 0.29%

updated 2026-09-05T21:31:26

2 posts

A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4

security_crawler_carl at 2026-09-07T15:49:08.481Z ##

Two supporting jabs — CVE-2026-86206 and CVE-2026-86207 — let challengers bypass authentication entirely. Hosted and on-premises deployments across Americas, APAC, and Europe are all on the canvas.

Apply N-able's emergency hotfix for CVE-2026-86218 and the weekend patches for CVE-2026-86206 and CVE-2026-86207 immediately — your MSP clients' endpoints are the undercard fight you cannot afford to lose. (2/3)

##

security_crawler_carl@infosec.exchange at 2026-09-07T15:49:08.000Z ##

Two supporting jabs — CVE-2026-86206 and CVE-2026-86207 — let challengers bypass authentication entirely. Hosted and on-premises deployments across Americas, APAC, and Europe are all on the canvas.

Apply N-able's emergency hotfix for CVE-2026-86218 and the weekend patches for CVE-2026-86206 and CVE-2026-86207 immediately — your MSP clients' endpoints are the undercard fight you cannot afford to lose. (2/3)

##

CVE-2026-67277(CVSS UNKNOWN)

EPSS: 0.43%

updated 2026-09-05T21:31:20

6 posts

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragment

threatnoir at 2026-09-07T23:05:52.419Z ##

⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers

Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…

threatnoir.com/focus

🤖 AI generated summary

##

security_crawler_carl at 2026-09-07T09:42:53.166Z ##

That is a full wipe, you absolute liability.

Pull up your patch notes, apply MikroTik RouterOS security updates addressing CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060, NOW — before the raid resets and I lose what remains of my sanity.

Reward: You've received the Fallen Raid Leader's Broken Headset. It no longer transmits. Nobody can hear you panic.

(2/2)

##

security_crawler_carl at 2026-09-07T09:42:53.017Z ##

🏆 New Achievement! MikroTik and Chill (No Password Required)!

MOVE OUT OF THE FIRE. SERIOUSLY. CERT.PL is screaming into your headset right now about three critical CVEs in MikroTik RouterOS — actively exploited, all of them — and you are standing there doing NOTHING. CVE-2026-67276 lets attackers bypass SSH auth entirely by knowing your username and RSA modulus. CVE-2026-86060 hands out full admin via a crafted username. CVE-2026-67277 crashes and leaks memory for fun. (1/2)

##

threatnoir@infosec.exchange at 2026-09-07T23:05:52.000Z ##

⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers

Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

security_crawler_carl@infosec.exchange at 2026-09-07T09:42:53.000Z ##

That is a full wipe, you absolute liability.

Pull up your patch notes, apply MikroTik RouterOS security updates addressing CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060, NOW — before the raid resets and I lose what remains of my sanity.

Reward: You've received the Fallen Raid Leader's Broken Headset. It no longer transmits. Nobody can hear you panic.

#CyberSecurity #MikroTik #RouterOS #Vulnerability #PrivilegeEscalation #AdminAccessUnlocked (2/2)

##

security_crawler_carl@infosec.exchange at 2026-09-07T09:42:53.000Z ##

🏆 New Achievement! MikroTik and Chill (No Password Required)!

MOVE OUT OF THE FIRE. SERIOUSLY. CERT.PL is screaming into your headset right now about three critical CVEs in MikroTik RouterOS — actively exploited, all of them — and you are standing there doing NOTHING. CVE-2026-67276 lets attackers bypass SSH auth entirely by knowing your username and RSA modulus. CVE-2026-86060 hands out full admin via a crafted username. CVE-2026-67277 crashes and leaks memory for fun. (1/2)

##

CVE-2026-86060
(0 None)

EPSS: 0.40%

updated 2026-09-05T21:16:51.400000

11 posts

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable

threatnoir at 2026-09-07T23:05:52.419Z ##

⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers

Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…

threatnoir.com/focus

🤖 AI generated summary

##

netsecio@mastodon.social at 2026-09-07T17:33:21.000Z ##

📰 MikroTik Routers Hijacked via 'MikroTrick' Unauthenticated Exploit

🚨 ACTIVE ATTACK: MikroTik routers are being hijacked via the 'MikroTrick' exploit chain (CVE-2026-67276, CVE-2026-86060). Unauthenticated attackers gain full admin control via exposed SSH. Patch RouterOS NOW. #MikroTik #CyberSecurity

🔗 cyber.netsecops.io/articles/mi

##

Analyst207@mastodon.social at 2026-09-07T10:46:09.000Z ##

Hackers Exploit MikroTik Router Flaws to Hijack Devices

Hackers are actively exploiting vulnerabilities in MikroTik RouterOS, using a two-step attack dubbed "MikroTrick" to hijack devices, warns Poland's Computer Emergency Response Team. The team has confirmed that the critical severity flaws, tracked as CVE-2026-67276 and CVE-2026-86060, are being used in real-world attacks.

osintsights.com/hackers-exploi

#Mikrotik #Routeros #Mikrotrick #EmergingThreats #SupplyChain

##

security_crawler_carl at 2026-09-07T09:42:53.166Z ##

That is a full wipe, you absolute liability.

Pull up your patch notes, apply MikroTik RouterOS security updates addressing CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060, NOW — before the raid resets and I lose what remains of my sanity.

Reward: You've received the Fallen Raid Leader's Broken Headset. It no longer transmits. Nobody can hear you panic.

(2/2)

##

security_crawler_carl at 2026-09-07T09:42:53.017Z ##

🏆 New Achievement! MikroTik and Chill (No Password Required)!

MOVE OUT OF THE FIRE. SERIOUSLY. CERT.PL is screaming into your headset right now about three critical CVEs in MikroTik RouterOS — actively exploited, all of them — and you are standing there doing NOTHING. CVE-2026-67276 lets attackers bypass SSH auth entirely by knowing your username and RSA modulus. CVE-2026-86060 hands out full admin via a crafted username. CVE-2026-67277 crashes and leaks memory for fun. (1/2)

##

sayzard@mastodon.sayzard.org at 2026-09-06T20:42:11.000Z ##

Pre-auth RCE on MikroTik: exploited before the patch, rebuilt in three hours

MikroTik RouterOS에서 SSH만 노출돼 있으면 인증 없이 관리자 권한을 획득할 수 있다는 ‘MikroTrick’ 체인이 공개됐다. 글은 CVE-2026-67279(인증 상태 우회)와 CVE-2026-86060(로그인 헬퍼 인자 처리)을 결합해 루트급 콘솔을 얻으며, CVE-2026-67276은 별도의 공개키 인증 우회 경로가 될 수 있다고 설명한다. 공격 흔적은 `user -2` 로그인 실패·`ssh:-2@<ip>`에 의한 설정 변경, 비인가 `ops` 계정, fetch/import 스케줄러·SOCKS 프록시·터널 등이며,...

blog.tolmo.com/p/pre-auth-rce-

##

ewenmcneill@cloudisland.nz at 2026-09-05T23:10:11.000Z ##

The reason for the Mikrotik “patch now, we’ll say why later” announcements last week seems to be out.

It’s patching a zero day exploit chain that seems to be CVE-2026-67279 (ssh rekey bypasses auth phase) and CVE-2026-86060 (username of “-2” misinterpreted as flag to read from file descriptor).

Several people on Mikrotik forum and Mikrotik subreddit report exploits early September 2026, so likely automated exploit 😬

cert.pl/en/posts/2026/09/mikro
cert.pl/en/posts/2026/09/vulne
forum.mikrotik.com/t/important

##

threatnoir@infosec.exchange at 2026-09-07T23:05:52.000Z ##

⚠️ CRITICAL: Hackers exploit new MikroTik RouterOS flaws to hijack routers

Attackers are actively exploiting two chained critical vulnerabilities in MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060) to achieve full admin control of exposed routers. A third flaw (CVE-2026-67277) in the bandwidth-test service can cause memory leaks or crashes. Any unpatched MikroTik rou…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

netsecio@mastodon.social at 2026-09-07T17:33:21.000Z ##

📰 MikroTik Routers Hijacked via 'MikroTrick' Unauthenticated Exploit

🚨 ACTIVE ATTACK: MikroTik routers are being hijacked via the 'MikroTrick' exploit chain (CVE-2026-67276, CVE-2026-86060). Unauthenticated attackers gain full admin control via exposed SSH. Patch RouterOS NOW. #MikroTik #CyberSecurity

🔗 cyber.netsecops.io/articles/mi

##

security_crawler_carl@infosec.exchange at 2026-09-07T09:42:53.000Z ##

That is a full wipe, you absolute liability.

Pull up your patch notes, apply MikroTik RouterOS security updates addressing CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060, NOW — before the raid resets and I lose what remains of my sanity.

Reward: You've received the Fallen Raid Leader's Broken Headset. It no longer transmits. Nobody can hear you panic.

#CyberSecurity #MikroTik #RouterOS #Vulnerability #PrivilegeEscalation #AdminAccessUnlocked (2/2)

##

security_crawler_carl@infosec.exchange at 2026-09-07T09:42:53.000Z ##

🏆 New Achievement! MikroTik and Chill (No Password Required)!

MOVE OUT OF THE FIRE. SERIOUSLY. CERT.PL is screaming into your headset right now about three critical CVEs in MikroTik RouterOS — actively exploited, all of them — and you are standing there doing NOTHING. CVE-2026-67276 lets attackers bypass SSH auth entirely by knowing your username and RSA modulus. CVE-2026-86060 hands out full admin via a crafted username. CVE-2026-67277 crashes and leaks memory for fun. (1/2)

##

CVE-2026-67279
(0 None)

EPSS: 0.45%

updated 2026-09-05T21:16:50.613000

4 posts

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support

sayzard@mastodon.sayzard.org at 2026-09-06T20:42:11.000Z ##

Pre-auth RCE on MikroTik: exploited before the patch, rebuilt in three hours

MikroTik RouterOS에서 SSH만 노출돼 있으면 인증 없이 관리자 권한을 획득할 수 있다는 ‘MikroTrick’ 체인이 공개됐다. 글은 CVE-2026-67279(인증 상태 우회)와 CVE-2026-86060(로그인 헬퍼 인자 처리)을 결합해 루트급 콘솔을 얻으며, CVE-2026-67276은 별도의 공개키 인증 우회 경로가 될 수 있다고 설명한다. 공격 흔적은 `user -2` 로그인 실패·`ssh:-2@<ip>`에 의한 설정 변경, 비인가 `ops` 계정, fetch/import 스케줄러·SOCKS 프록시·터널 등이며,...

blog.tolmo.com/p/pre-auth-rce-

##

ewenmcneill@cloudisland.nz at 2026-09-06T10:21:18.000Z ##

@ciaranmak that’s authentication hard mode compared with “client triggers ssh rekey to glitch past authentication step”:

“The vulnerability CVE-2026-67279: RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request.“

(And logs people have posted suggest this is in the original zero day.)

CC @osxreverser @LapTop006

cert.pl/en/posts/2026/09/mikro

##

ewenmcneill@cloudisland.nz at 2026-09-05T23:10:11.000Z ##

The reason for the Mikrotik “patch now, we’ll say why later” announcements last week seems to be out.

It’s patching a zero day exploit chain that seems to be CVE-2026-67279 (ssh rekey bypasses auth phase) and CVE-2026-86060 (username of “-2” misinterpreted as flag to read from file descriptor).

Several people on Mikrotik forum and Mikrotik subreddit report exploits early September 2026, so likely automated exploit 😬

cert.pl/en/posts/2026/09/mikro
cert.pl/en/posts/2026/09/vulne
forum.mikrotik.com/t/important

##

ewenmcneill@cloudisland.nz at 2026-09-06T10:21:18.000Z ##

@ciaranmak that’s authentication hard mode compared with “client triggers ssh rekey to glitch past authentication step”:

“The vulnerability CVE-2026-67279: RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request.“

(And logs people have posted suggest this is in the original zero day.)

CC @osxreverser @LapTop006

cert.pl/en/posts/2026/09/mikro

##

CVE-2026-86207
(0 None)

EPSS: 0.30%

updated 2026-09-05T19:16:56.190000

2 posts

An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs

security_crawler_carl at 2026-09-07T15:49:08.481Z ##

Two supporting jabs — CVE-2026-86206 and CVE-2026-86207 — let challengers bypass authentication entirely. Hosted and on-premises deployments across Americas, APAC, and Europe are all on the canvas.

Apply N-able's emergency hotfix for CVE-2026-86218 and the weekend patches for CVE-2026-86206 and CVE-2026-86207 immediately — your MSP clients' endpoints are the undercard fight you cannot afford to lose. (2/3)

##

security_crawler_carl@infosec.exchange at 2026-09-07T15:49:08.000Z ##

Two supporting jabs — CVE-2026-86206 and CVE-2026-86207 — let challengers bypass authentication entirely. Hosted and on-premises deployments across Americas, APAC, and Europe are all on the canvas.

Apply N-able's emergency hotfix for CVE-2026-86218 and the weekend patches for CVE-2026-86206 and CVE-2026-86207 immediately — your MSP clients' endpoints are the undercard fight you cannot afford to lose. (2/3)

##

CVE-2026-0799
(8.7 HIGH)

EPSS: 0.11%

updated 2026-09-05T19:16:55.320000

2 posts

In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit

thehackerwire@mastodon.social at 2026-09-05T21:01:36.000Z ##

🟠 CVE-2026-0799 - High (8.7)

In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a cra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T21:01:36.000Z ##

🟠 CVE-2026-0799 - High (8.7)

In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a cra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86189
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-09-05T15:30:31

2 posts

WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted but never validated, to bypass authentication and write files to the applicatio

thehackerwire@mastodon.social at 2026-09-05T17:00:04.000Z ##

🔴 CVE-2026-86189 - Critical (9.8)

WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T17:00:04.000Z ##

🔴 CVE-2026-86189 - Critical (9.8)

WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86145
(8.2 HIGH)

EPSS: 0.37%

updated 2026-09-05T14:17:23.897000

1 posts

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set throug

thehackerwire@mastodon.social at 2026-09-05T07:00:25.000Z ##

🟠 CVE-2026-86145 - High (8.2)

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86190
(9.1 CRITICAL)

EPSS: 0.27%

updated 2026-09-05T13:18:14.150000

3 posts

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal d

hugovalters@mastodon.social at 2026-09-07T11:11:00.000Z ##

CVE-2026-86190 - Critical Broken Access Control in WWBN AVideo allows admin session hijacking & data theft. CVSS 9.1. Restrict endpoints now. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-861

##

thehackerwire@mastodon.social at 2026-09-05T17:00:15.000Z ##

🔴 CVE-2026-86190 - Critical (9.1)

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T17:00:15.000Z ##

🔴 CVE-2026-86190 - Critical (9.1)

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86184
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-09-05T12:31:35

2 posts

Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint with a registered email address to receive a fully authenticated session, enabling access to user administration, settings

thehackerwire@mastodon.social at 2026-09-05T13:01:15.000Z ##

🔴 CVE-2026-86184 - Critical (9.8)

Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /scr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T13:01:15.000Z ##

🔴 CVE-2026-86184 - Critical (9.8)

Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /scr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10196
(9.8 CRITICAL)

EPSS: 0.63%

updated 2026-09-05T12:31:34

2 posts

The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form_submission' function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers

thehackerwire@mastodon.social at 2026-09-05T21:01:46.000Z ##

🔴 CVE-2026-10196 - Critical (9.8)

The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T21:01:46.000Z ##

🔴 CVE-2026-10196 - Critical (9.8)

The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-9049
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-05T12:31:34

2 posts

The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_permissions' function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add new Subscriber users with employer account member permissions,

thehackerwire@mastodon.social at 2026-09-05T13:01:35.000Z ##

🟠 CVE-2025-9049 - High (8.8)

The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_permissions' function in all versions up to, and including, 1.6.4. This m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T13:01:35.000Z ##

🟠 CVE-2025-9049 - High (8.8)

The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_permissions' function in all versions up to, and including, 1.6.4. This m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86117
(8.1 HIGH)

EPSS: 0.42%

updated 2026-09-05T12:31:34

2 posts

Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities. Attackers can register a victim's email address on any enabled OAuth provider to obtain authenticated sessions as that user, bypassing password requirements and t

thehackerwire@mastodon.social at 2026-09-05T11:01:39.000Z ##

🟠 CVE-2026-86117 - High (8.1)

Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities. Attackers...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T11:01:39.000Z ##

🟠 CVE-2026-86117 - High (8.1)

Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities. Attackers...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86123
(8.7 HIGH)

EPSS: 0.33%

updated 2026-09-05T12:31:34

1 posts

SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL commands, enumerate schemas, and pivot into the server's network without authentication.

thehackerwire@mastodon.social at 2026-09-05T11:00:56.000Z ##

🟠 CVE-2026-86123 - High (8.7)

SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL commands, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86124
(9.8 CRITICAL)

EPSS: 0.54%

updated 2026-09-05T12:31:27

3 posts

AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary bash commands within the container, gaining access to bind-mounted host workspace directories.

hugovalters@mastodon.social at 2026-09-07T01:07:15.000Z ##

CVE-2026-86124 - Critical unauthenticated RCE in AutoAgent. TCP server executes arbitrary commands as root. CVSS 9.8. Restrict network access now. #CVE #RCE #infosec

valtersit.com/cve/CVE-2026-861

##

thehackerwire@mastodon.social at 2026-09-05T11:01:28.000Z ##

🔴 CVE-2026-86124 - Critical (9.8)

AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T11:01:28.000Z ##

🔴 CVE-2026-86124 - Critical (9.8)

AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86121
(9.8 CRITICAL)

EPSS: 0.59%

updated 2026-09-05T12:31:27

2 posts

Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can reach TCP port 8000 to run shell commands via the run_command endpoint, read and write arbitrary files through file operation endpoints, and access interactive PTY

hugovalters@mastodon.social at 2026-09-06T11:03:28.000Z ##

CVE-2026-86121 - Critical RCE & auth bypass in Cua computer-server. Allows unauthenticated arbitrary command execution. CVSS 9.8. Update to 0.3.42 now. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-861

##

thehackerwire@mastodon.social at 2026-09-05T11:00:45.000Z ##

🔴 CVE-2026-86121 - Critical (9.8)

Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can reach TCP p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86173
(7.5 HIGH)

EPSS: 0.37%

updated 2026-09-05T12:31:27

2 posts

MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list. Attackers can bypass the allowlist control by exploiting the default empty configuration and access internal services and cloud metadata endpoints without authentication.

thehackerwire@mastodon.social at 2026-09-05T12:03:30.000Z ##

🟠 CVE-2026-86173 - High (7.5)

MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list. Attackers can bypass the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T12:03:30.000Z ##

🟠 CVE-2026-86173 - High (7.5)

MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list. Attackers can bypass the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86185
(8.0 HIGH)

EPSS: 0.11%

updated 2026-09-05T12:16:49.240000

2 posts

Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed in the renderer with access to the privileged IPC bridge, and execute system commands or steal login credentials.

thehackerwire@mastodon.social at 2026-09-05T13:01:25.000Z ##

🟠 CVE-2026-86185 - High (8)

Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inje...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T13:01:25.000Z ##

🟠 CVE-2026-86185 - High (8)

Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inje...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86177
(8.8 HIGH)

EPSS: 0.31%

updated 2026-09-05T11:16:46.397000

2 posts

Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run game-server console commands, control server power state, or create backups without proper authorization checks.

thehackerwire@mastodon.social at 2026-09-05T12:03:09.000Z ##

🟠 CVE-2026-86177 - High (8.8)

Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger sc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T12:03:09.000Z ##

🟠 CVE-2026-86177 - High (8.8)

Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger sc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86169
(8.8 HIGH)

EPSS: 0.48%

updated 2026-09-05T11:16:45.703000

2 posts

Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python code by crafting a malicious Hugging Face model repository selected as base_model, which is loaded with hardcoded trust_remote_code=True during AutoModelForCausa

thehackerwire@mastodon.social at 2026-09-05T12:03:20.000Z ##

🟠 CVE-2026-86169 - High (8.8)

Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python code by ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T12:03:20.000Z ##

🟠 CVE-2026-86169 - High (8.8)

Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python code by ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86119
(8.6 HIGH)

EPSS: 0.35%

updated 2026-09-05T10:16:43.157000

1 posts

Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud instance metadata, access internal services, and perform network reconnaissance on the instance infrastructure.

thehackerwire@mastodon.social at 2026-09-05T11:00:36.000Z ##

🟠 CVE-2026-86119 - High (8.6)

Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19887
(8.8 HIGH)

EPSS: 0.57%

updated 2026-09-05T07:17:11.657000

1 posts

The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callback (usces_action_acting_transaction). Unauthenticated attackers can store arbitrary 'reserve' key/value pairs as order metadata during a public checkout, then invoke the callback with an attacker-chose

thehackerwire@mastodon.social at 2026-09-05T08:00:03.000Z ##

🟠 CVE-2026-19887 - High (8.8)

The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callback (usces_action_acting_transaction). Unauthenti...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13447
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-09-05T06:32:44

2 posts

The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid, aud, iss) but never calls openssl_verify() or any equivalent to validate the JWT sig

hugovalters@mastodon.social at 2026-09-06T01:11:44.000Z ##

CVE-2026-13447 - Critical Auth Bypass in FluxBuilder Mstore API WordPress plugin via JWT forgery. CVSS 9.8. Unpatched! Mitigate immediately. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-134

##

thehackerwire@mastodon.social at 2026-09-05T07:00:35.000Z ##

🔴 CVE-2026-13447 - Critical (9.8)

The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() funct...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86140
(8.0 HIGH)

EPSS: 0.14%

updated 2026-09-05T05:17:12.877000

1 posts

In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.

thehackerwire@mastodon.social at 2026-09-05T05:59:47.000Z ##

🟠 CVE-2026-86140 - High (8)

In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78012
(9.8 CRITICAL)

EPSS: 0.47%

updated 2026-09-05T00:32:06

2 posts

An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.

cyberworldops at 2026-09-05T14:10:00.407Z ##

Pyramid Solutions NetStaX EtherNet/IP Stack before 5.6.1 contains CVE-2026-78012, a stack-based buffer overflow triggered by oversized Class 3 explicit messages without error. It enables DoS and potential RCE in OT systems, making immediate patching critical.

cyberworldops.eu/en/netstax-et

##

cyberworldops@infosec.exchange at 2026-09-05T14:10:00.000Z ##

Pyramid Solutions NetStaX EtherNet/IP Stack before 5.6.1 contains CVE-2026-78012, a stack-based buffer overflow triggered by oversized Class 3 explicit messages without error. It enables DoS and potential RCE in OT systems, making immediate patching critical. #IcsSecurity #EtherNetIp #BufferOverflow

cyberworldops.eu/en/netstax-et

##

CVE-2026-82684
(8.1 HIGH)

EPSS: 0.46%

updated 2026-09-05T00:31:10

2 posts

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.

hugovalters@mastodon.social at 2026-09-07T14:20:04.000Z ##

CVE-2026-82684: Missing authorization in Tycon Systems TPDIN-Monitor-WEB3 (≤2.2.9) lets attackers dump system credentials, configs, or flash contents. CVSS 8.1. Unpatched—assume exposure. Isolate affected units and restrict access now. Details: valtersit.com/cve/CVE-2

##

thehackerwire@mastodon.social at 2026-09-04T23:02:05.000Z ##

🟠 CVE-2026-82684 - High (8.1)

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52775
(8.8 HIGH)

EPSS: 0.29%

updated 2026-09-05T00:17:20.520000

1 posts

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() that allows any authenticated user to inject arbitrary SQL via the {idreaction} and {id} URL path parameters. The parameters are concatenated directly into a SQL LIKE clause without escaping or parameterizatio

thehackerwire@mastodon.social at 2026-09-05T04:00:05.000Z ##

🟠 CVE-2026-52775 - High (8.8)

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() that allows any authenticated user to inject arbitrary S...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52771
(8.3 HIGH)

EPSS: 0.30%

updated 2026-09-05T00:17:19.963000

2 posts

YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag retrieved from the database into a DELETE FROM …_links WHERE to_tag = '$tag' query without escaping. The page tag is attacker-controlled — the POST /api/pages/{tag} API accepts arbitrary URL-encoded values, including single quotes, and stores them. A low-privileg

hugovalters@mastodon.social at 2026-09-07T17:30:02.000Z ##

CVE-2026-52771: YesWiki SQL injection via attacker-controlled page tags in ApiController::deletePage(). CVSS 8.3. Low-privilege users can exploit arbitrary tags to inject SQL. Unpatched—no fix available. Update or disable API if exposed. valtersit.com/cve/CVE-2026-527

##

thehackerwire@mastodon.social at 2026-09-05T06:02:17.000Z ##

🟠 CVE-2026-52771 - High (8.3)

YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag retrieved from the database into a DELETE FROM …_links WHERE to_tag = '$tag' query without escaping. The pag...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52767
(8.2 HIGH)

EPSS: 0.22%

updated 2026-09-05T00:17:19.540000

1 posts

YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() with a loose boolean negation - if (!openssl_verify(...)) { throw ... }. PHP's openssl_verify has four possible return values: 1, 0, -1, and "false". The -1 row is the bypass: PHP's truthiness rules make -1 a truthy value, so !(-1)

thehackerwire@mastodon.social at 2026-09-05T04:00:28.000Z ##

🟠 CVE-2026-52767 - High (8.2)

YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() with a loose boolean negation - if (!openssl_verify(...)) { throw ... }. PHP's...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52766
(9.1 CRITICAL)

EPSS: 0.33%

updated 2026-09-05T00:17:19.393000

1 posts

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that array, with no authorization check anywhere in the action body or in the page-deletion path it invokes. Combined with YesWiki's allow-by-default action ACL model, any

thehackerwire@mastodon.social at 2026-09-05T04:00:17.000Z ##

🔴 CVE-2026-52766 - Critical (9.1)

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that array, with no...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86095
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-04T23:18:03.220000

1 posts

Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribute names to overflow the destination buffer, causing memory corruption and crashes when applications enumerate attribute names.

thehackerwire@mastodon.social at 2026-09-05T00:00:00.000Z ##

🟠 CVE-2026-86095 - High (7.8)

Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48019
(8.9 HIGH)

EPSS: 0.68%

updated 2026-09-04T23:17:09.143000

1 posts

Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an unauthenticated attacker to interfere with outbound email processing in applications that send mail to user-supplied addresses. This issue has been patche

1 repos

https://github.com/derrickschoen/laravel-framework

thehackerwire@mastodon.social at 2026-09-05T00:00:10.000Z ##

🟠 CVE-2026-48019 - High (8.9)

Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82712
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-04T21:31:59

1 posts

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.

thehackerwire@mastodon.social at 2026-09-04T22:00:00.000Z ##

🟠 CVE-2026-82712 - High (8.8)

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80119
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-04T21:31:59

1 posts

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump complete physical memory contents by supplying a caller-controlled file path to an exposed IOCTL. Attackers can issue a single IOCTL call to trigger the driver

thehackerwire@mastodon.social at 2026-09-04T20:00:55.000Z ##

🟠 CVE-2026-80119 - High (7.8)

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump comple...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80116
(7.8 HIGH)

EPSS: 0.11%

updated 2026-09-04T21:31:59

1 posts

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by exploiting exposed IOCTLs with no validation on device selection, register offset, or value. Attackers can obtain a device handle and issue arbitrary PCI

thehackerwire@mastodon.social at 2026-09-04T20:00:21.000Z ##

🟠 CVE-2026-80116 - High (7.8)

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78327
(9.1 CRITICAL)

EPSS: 1.55%

updated 2026-09-04T21:31:50

2 posts

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution.

hugovalters@mastodon.social at 2026-09-07T19:00:04.000Z ##

CVE-2026-78327: OS Command Injection in SonicWall NSM On-Prem lets SuperAdmin execute arbitrary commands as RCE on the host. CVSS 9.1. Unpatched—assume exposure. Restrict SuperAdmin access now and monitor for updates. valtersit.com/cve/CVE-2026-783 #CVE #SonicWall

##

thehackerwire@mastodon.social at 2026-09-04T21:03:04.000Z ##

🔴 CVE-2026-78327 - Critical (9.1)

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75431
(9.1 CRITICAL)

EPSS: 0.77%

updated 2026-09-04T21:31:48

1 posts

PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.

1 repos

https://github.com/unpredictable21/CVE-2026-75431_PowerJob_jwt_key_predictable

thehackerwire@mastodon.social at 2026-09-05T07:02:03.000Z ##

🔴 CVE-2026-75431 - Critical (9.1)

PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81939
(9.1 CRITICAL)

EPSS: 0.73%

updated 2026-09-04T20:17:29.647000

1 posts

A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.

thehackerwire@mastodon.social at 2026-09-04T21:02:53.000Z ##

🔴 CVE-2026-81939 - Critical (9.1)

A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80114
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-04T20:17:28.787000

1 posts

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that allows local attackers to perform arbitrary physical memory writes by extracting an 8-byte key embedded as a hardcoded literal in the distributed binary and computing valid MD5 authentication tags for arbitr

thehackerwire@mastodon.social at 2026-09-04T20:00:11.000Z ##

🟠 CVE-2026-80114 - High (7.8)

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that allows local attackers to perform arbitrary physical m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78328
(9.1 CRITICAL)

EPSS: 0.50%

updated 2026-09-04T20:17:27.993000

2 posts

A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.

hugovalters@mastodon.social at 2026-09-08T03:30:01.000Z ##

CVE-2026-78328 SonicWall NSM On-Prem flaw lets lower-privileged Admins escalate to SuperAdmin. CVSS 9.1, unpatched. Assume compromise until fixed. Restrict access now. Details: valtersit.com/cve/CVE-2026-783 #CVE #infosec #SonicWall

##

thehackerwire@mastodon.social at 2026-09-04T22:00:21.000Z ##

🔴 CVE-2026-78328 - Critical (9.1)

A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75160
(9.1 CRITICAL)

EPSS: 0.43%

updated 2026-09-04T20:17:26.533000

2 posts

An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.

hugovalters@mastodon.social at 2026-09-07T20:40:02.000Z ##

CVE-2026-75160: Critical flaw in X-Serie Gateway Firmware V6_00_05 allows remote privilege escalation via /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi. CVSS 9.1. Unpatched—assume exposure. Isolate devices, restrict access, monitor logs now. Details: valtersit.com/

##

thehackerwire@mastodon.social at 2026-09-05T08:00:25.000Z ##

🔴 CVE-2026-75160 - Critical (9.1)

An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61699
(8.1 HIGH)

EPSS: 0.25%

updated 2026-09-04T20:17:24.347000

1 posts

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches any peer's config.yml, a Blocked host retains full overlay reachability to every peer under its CA (and internal services on the mesh) for up to 30d (agent) / 365d (

thehackerwire@mastodon.social at 2026-09-04T21:00:44.000Z ##

🟠 CVE-2026-61699 - High (8.1)

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches any peer's c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53932
(8.0 HIGH)

EPSS: 0.91%

updated 2026-09-04T20:17:23.570000

1 posts

laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.

thehackerwire@mastodon.social at 2026-09-04T21:02:44.000Z ##

🟠 CVE-2026-53932 - High (8)

laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80118
(7.1 HIGH)

EPSS: 0.11%

updated 2026-09-04T19:17:28.710000

1 posts

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users through a single IOCTL with no caller-identity check. The handler writes a crash-dump-format (PAGEDU64) image of all physical memory to a caller-supplied file path in

hugovalters@mastodon.social at 2026-09-07T16:00:02.000Z ##

CVE-2026-80118: Unpatched flaw in PassMark PerformanceTest, BurnInTest & OSForensics (DirectIo64.sys) lets local users dump all physical memory via IOCTL—exposing passwords, keys, and data. CVSS 7.1. No patch yet. Stop using these tools or restrict access NOW. Details: https://ww

##

CVE-2026-80112
(7.8 HIGH)

EPSS: 0.10%

updated 2026-09-04T19:17:27.823000

2 posts

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to perform privileged hardware operations by opening a handle to the device object created without a security descriptor. Attackers can issue IOCTLs throug

hugovalters@mastodon.social at 2026-09-08T03:20:01.000Z ##

CVE-2026-80112: PassMark tools (PerformanceTest, BurnInTest, OSForensics) have an improper access control flaw in DirectIo64.sys, letting unprivileged users run privileged hardware IOCTLs. CVSS 7.8. Unpatched—limit exposure now. Details: valtersit.com/cve/CVE-2026-801

##

thehackerwire@mastodon.social at 2026-09-04T20:01:06.000Z ##

🟠 CVE-2026-80112 - High (7.8)

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77822
(8.2 HIGH)

EPSS: 0.21%

updated 2026-09-04T19:17:27.240000

1 posts

IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.

thehackerwire@mastodon.social at 2026-09-05T08:00:15.000Z ##

🟠 CVE-2026-77822 - High (8.2)

IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75430
(9.8 CRITICAL)

EPSS: 0.89%

updated 2026-09-04T19:17:26.990000

1 posts

PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.

1 repos

https://github.com/unpredictable21/CVE-2026-75430_PowerJob_worker_deployContainer_RCE

thehackerwire@mastodon.social at 2026-09-04T18:00:21.000Z ##

🔴 CVE-2026-75430 - Critical (9.8)

PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85654
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-04T18:31:46

1 posts

Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated application via crafted table, index, or attribute names in a data model file.

thehackerwire@mastodon.social at 2026-09-04T22:00:43.000Z ##

🟠 CVE-2026-85654 - High (7.8)

Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated ap...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18486
(8.8 HIGH)

EPSS: 0.32%

updated 2026-09-04T18:31:32

1 posts

IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.

thehackerwire@mastodon.social at 2026-09-05T07:01:43.000Z ##

🟠 CVE-2026-18486 - High (8.8)

IBM ContextForge MCP Gateway &lt;= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18221
(8.1 HIGH)

EPSS: 0.32%

updated 2026-09-04T18:31:31

1 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.

thehackerwire@mastodon.social at 2026-09-04T18:00:42.000Z ##

🟠 CVE-2026-18221 - High (8.1)

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19298
(8.8 HIGH)

EPSS: 0.47%

updated 2026-09-04T18:31:26

2 posts

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.

thehackerwire@mastodon.social at 2026-09-05T23:01:11.000Z ##

🟠 CVE-2026-19298 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T23:01:11.000Z ##

🟠 CVE-2026-19298 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19300
(7.5 HIGH)

EPSS: 0.38%

updated 2026-09-04T18:31:26

2 posts

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.

thehackerwire@mastodon.social at 2026-09-05T12:04:16.000Z ##

🟠 CVE-2026-19300 - High (7.5)

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T12:04:16.000Z ##

🟠 CVE-2026-19300 - High (7.5)

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19305
(8.6 HIGH)

EPSS: 0.29%

updated 2026-09-04T18:31:26

2 posts

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.

thehackerwire@mastodon.social at 2026-09-05T11:01:50.000Z ##

🟠 CVE-2026-19305 - High (8.6)

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T11:01:50.000Z ##

🟠 CVE-2026-19305 - High (8.6)

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19304
(7.7 HIGH)

EPSS: 0.31%

updated 2026-09-04T18:31:21

1 posts

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy.

thehackerwire@mastodon.social at 2026-09-05T09:00:52.000Z ##

🟠 CVE-2026-19304 - High (7.7)

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19303
(8.1 HIGH)

EPSS: 0.38%

updated 2026-09-04T18:31:21

1 posts

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory.

thehackerwire@mastodon.social at 2026-09-05T09:00:41.000Z ##

🟠 CVE-2026-19303 - High (8.1)

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18905
(7.7 HIGH)

EPSS: 0.31%

updated 2026-09-04T18:31:20

2 posts

IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation.

thehackerwire@mastodon.social at 2026-09-05T21:01:57.000Z ##

🟠 CVE-2026-18905 - High (7.7)

IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) &lt;= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T21:01:57.000Z ##

🟠 CVE-2026-18905 - High (7.7)

IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) &lt;= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9317
(8.1 HIGH)

EPSS: 0.68%

updated 2026-09-04T18:18:07.297000

1 posts

Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials. Attackers with network access to the runner port can send requests to the unauthenticated start procedure, bypassing the unenforced RUNNER_SECRET_KEY environment variable

thehackerwire@mastodon.social at 2026-09-04T20:01:15.000Z ##

🟠 CVE-2026-9317 - High (8.1)

Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials. Attackers with ne...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85656
(7.8 HIGH)

EPSS: 1.12%

updated 2026-09-04T18:18:06.133000

2 posts

An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.

hugovalters@mastodon.social at 2026-09-08T02:50:03.000Z ##

CVE-2026-85656: OS command injection in Amazon Linux's log4j hotpatch package (<1.3-9). Local user can execute arbitrary commands as root via crafted Java process path with newlines. CVSS 7.8. Unpatched! If you rely on this hotpatch, isolate and monitor systems immediately. Detai

##

thehackerwire@mastodon.social at 2026-09-04T22:00:31.000Z ##

🟠 CVE-2026-85656 - High (7.8)

An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82538
(8.8 HIGH)

EPSS: 0.39%

updated 2026-09-04T18:18:01.357000

1 posts

ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable columns. Authenticated users with write permission on any container can inject arbitrary SQL through the sort parameter, and b

thehackerwire@mastodon.social at 2026-09-04T23:02:56.000Z ##

🟠 CVE-2026-82538 - High (8.8)

ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44402
(9.8 CRITICAL)

EPSS: 0.89%

updated 2026-09-04T18:17:52.080000

1 posts

Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and

2 repos

https://github.com/0xCyp1337/CVE-2026-44402

https://github.com/Virgula0/CVE-2026-44402

thehackerwire@mastodon.social at 2026-09-05T09:00:31.000Z ##

🔴 CVE-2026-44402 - Critical (9.8)

Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive witho...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-31020
(9.8 CRITICAL)

EPSS: 0.58%

updated 2026-09-04T18:17:51.893000

2 posts

In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja templates without input sanitization or sandboxing. An unauthenticated attacker can inject malicious template expressions, leading to a server-side template injection (SSTI) vulner

hugovalters@mastodon.social at 2026-09-08T04:30:01.000Z ##

CVE-2026-31020: SSTI to RCE in DocsGPT ≤0.15.0 via unsanitized Jinja prompts. CVSS 9.8, unpatched. No auth needed. Patch? None yet—disable custom prompts or isolate instance now. Details: valtersit.com/cve/CVE-2026-310 #CVE #infosec #cybersecurity

##

thehackerwire@mastodon.social at 2026-09-05T07:01:53.000Z ##

🔴 CVE-2026-31020 - Critical (9.8)

In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja templates without input san...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19306
(7.7 HIGH)

EPSS: 0.41%

updated 2026-09-04T18:17:51.513000

2 posts

IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other tenants' upload directories) — by supplying absolute paths or traversal sequences in the files parameter of an authenticated build request. The file content

thehackerwire@mastodon.social at 2026-09-05T12:04:05.000Z ##

🟠 CVE-2026-19306 - High (7.7)

IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T12:04:05.000Z ##

🟠 CVE-2026-19306 - High (7.7)

IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19274
(9.6 CRITICAL)

EPSS: 0.21%

updated 2026-09-04T18:17:51.260000

2 posts

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace disambiguation, allowing a same-named `InstanaAgent` CR in an attacker-controlle

thehackerwire@mastodon.social at 2026-09-05T23:00:51.000Z ##

🔴 CVE-2026-19274 - Critical (9.6)

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scop...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T23:00:51.000Z ##

🔴 CVE-2026-19274 - Critical (9.6)

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scop...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57777
(7.6 HIGH)

EPSS: 0.24%

updated 2026-09-04T17:16:57.160000

2 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooCommerce allows Blind SQL Injection. This issue affects WooCommerce: from n/a before 11.0.

wpguyuk at 2026-09-07T07:04:37.778Z ##

WooCommerce CVE-2026-57777 carries a CVSS score of 7.6 and lets a low-privilege user, a free subscriber, manipulate their own role to gain full admin access. Any store below version 11.0 is exposed. I have written up what the vulnerability involves and the steps I recommend taking to address it.

wpguy.uk/blog/woocommerce-cve-

##

wpguyuk@infosec.exchange at 2026-09-07T07:04:37.000Z ##

WooCommerce CVE-2026-57777 carries a CVSS score of 7.6 and lets a low-privilege user, a free subscriber, manipulate their own role to gain full admin access. Any store below version 11.0 is exposed. I have written up what the vulnerability involves and the steps I recommend taking to address it.

#WordPress #WooCommerce #SecurityHardening #CVE #WordPressSecurity

wpguy.uk/blog/woocommerce-cve-

##

CVE-2026-18175
(8.1 HIGH)

EPSS: 0.21%

updated 2026-09-04T17:16:56.010000

1 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.

thehackerwire@mastodon.social at 2026-09-04T18:00:31.000Z ##

🟠 CVE-2026-18175 - High (8.1)

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5522
(6.7 MEDIUM)

EPSS: 0.09%

updated 2026-09-04T16:17:25.870000

1 posts

IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

CVE-2026-19283
(7.7 HIGH)

EPSS: 0.31%

updated 2026-09-04T16:17:21.777000

2 posts

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an attacker-controlled namespace.

thehackerwire@mastodon.social at 2026-09-05T23:01:01.000Z ##

🟠 CVE-2026-19283 - High (7.7)

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T23:01:01.000Z ##

🟠 CVE-2026-19283 - High (7.7)

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18658
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-09-04T16:17:21.133000

2 posts

IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.

thehackerwire@mastodon.social at 2026-09-05T12:04:27.000Z ##

🔴 CVE-2026-18658 - Critical (9.8)

IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-05T12:04:27.000Z ##

🔴 CVE-2026-18658 - Critical (9.8)

IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85695
(9.4 CRITICAL)

EPSS: 0.41%

updated 2026-09-04T15:36:24

2 posts

FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious workers under victim model names to intercept user prompts, images, and responses, or probe internal network ports across the worker mesh.

thehackerwire@mastodon.social at 2026-09-06T00:00:27.000Z ##

🔴 CVE-2026-85695 - Critical (9.4)

FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious worker...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T00:00:27.000Z ##

🔴 CVE-2026-85695 - Critical (9.4)

FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious worker...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85620
(8.6 HIGH)

EPSS: 0.37%

updated 2026-09-04T15:36:23

2 posts

Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can execute file-reading functions like pg_read_file through FROM-clause syntax to read arbitrary files despite restricted-mode protections.

beyondmachines1 at 2026-09-06T10:01:30.870Z ##

Postgres MCP Pro Restricted-Mode Bypass Allows Arbitrary Host File Disclosure

Postgres MCP Pro version 0.3.0 contains a critical restricted-mode bypass (CVE-2026-85620) that allows unauthenticated attackers to read arbitrary files from the database host. The flaw is caused by an incomplete SQL validation in the Abstract Syntax Tree parser, enabling the execution of dangerous functions through FROM clauses.

**If you're running Crystal DBA's Postgres MCP Pro (version 0.3.0 or earlier), don't rely on its restricted mode to keep your AI agents in check. It can be bypassed to read files off your server, including passwords and private keys. Change the database account the MCP server uses to a least-privilege role, strip its superuser status and `pg_read_server_files` permission, and keep it off the internet until an official fix ships.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-06T10:01:30.000Z ##

Postgres MCP Pro Restricted-Mode Bypass Allows Arbitrary Host File Disclosure

Postgres MCP Pro version 0.3.0 contains a critical restricted-mode bypass (CVE-2026-85620) that allows unauthenticated attackers to read arbitrary files from the database host. The flaw is caused by an incomplete SQL validation in the Abstract Syntax Tree parser, enabling the execution of dangerous functions through FROM clauses.

**If you're running Crystal DBA's Postgres MCP Pro (version 0.3.0 or earlier), don't rely on its restricted mode to keep your AI agents in check. It can be bypassed to read files off your server, including passwords and private keys. Change the database account the MCP server uses to a least-privilege role, strip its superuser status and `pg_read_server_files` permission, and keep it off the internet until an official fix ships.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-85694
(8.1 HIGH)

EPSS: 0.55%

updated 2026-09-04T15:17:47.540000

2 posts

LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code on the operator's host without review.

thehackerwire@mastodon.social at 2026-09-06T00:00:17.000Z ##

🟠 CVE-2026-85694 - High (8.1)

LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pag...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-06T00:00:17.000Z ##

🟠 CVE-2026-85694 - High (8.1)

LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pag...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20274
(9.8 CRITICAL)

EPSS: 0.67%

updated 2026-09-04T14:17:18.423000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20274 are related to improper resource control issues that are

netsecio@mastodon.social at 2026-09-05T16:20:27.000Z ##

📰 Cisco Patches Three Critical Flaws in IOS XR Network Software

Cisco patches 3 critical (CVSS 9.8) remote code execution vulnerabilities in IOS XR software (CVE-2026-20274, CVE-2026-20279, CVE-2026-20212). No active exploitation known, but immediate patching is urged. #Cisco #CyberSecurity #RCE #Networking

🔗 cyber.netsecops.io/articles/ci

##

CVE-2026-85224
(9.1 CRITICAL)

EPSS: 2.15%

updated 2026-09-04T00:31:11

2 posts

A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

secdb at 2026-09-07T00:01:37.001Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-07T00:01:37.000Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18167(CVSS UNKNOWN)

EPSS: 0.27%

updated 2026-09-04T00:31:11

1 posts

A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit crafted input that causes the easymesh daemon to crash and may potentially achieve remote code execution on the device. Successful exploitation may cause the EasyMesh daemon to crash and may potentially allow remote code execution when Mesh

guru@thecybersecguru.com at 2026-09-05T05:14:10.000Z ##

Critical TP-Link Archer AX55 Vulnerabilities Expose Routers to RCE and Credential Theft: Full Technical Analysis and Patch Guide

TP-Link Archer AX55 V4 is affected by CVE-2026-18167 and CVE-2026-18330. Learn about the RCE, credential theft risks and firmware fix

thecybersecguru.com/exploits/t

##

CVE-2026-18330(CVSS UNKNOWN)

EPSS: 0.23%

updated 2026-09-04T00:31:10

1 posts

A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may use the known shared RSA private key to decrypt the administrator password; the weakened AES session key further reduces the effort required to compromise session confidentiality. Successful exploitation may disclose the administrator password

guru@thecybersecguru.com at 2026-09-05T05:14:10.000Z ##

Critical TP-Link Archer AX55 Vulnerabilities Expose Routers to RCE and Credential Theft: Full Technical Analysis and Patch Guide

TP-Link Archer AX55 V4 is affected by CVE-2026-18167 and CVE-2026-18330. Learn about the RCE, credential theft risks and firmware fix

thecybersecguru.com/exploits/t

##

CVE-2026-85222
(9.1 CRITICAL)

EPSS: 2.11%

updated 2026-09-03T21:31:26

2 posts

A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On Center. Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

secdb at 2026-09-07T00:01:37.001Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-07T00:01:37.000Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-83548
(10.0 CRITICAL)

EPSS: 0.71%

updated 2026-09-03T13:06:16.053000

1 posts

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

2 repos

https://github.com/xoessie/CVE-2026-83548-SonicWall-SMA1000-Analysis

https://github.com/xcoy0te/CVE-2026-83548-checker

Matchbook3469@mastodon.social at 2026-09-05T17:58:54.000Z ##

🔵 THREAT INTELLIGENCE

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

Vulnerability | CRITICAL
CVEs: CVE-2026-83548

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV)...

Full analysis:
yazoul.net/news/article/cisa-a

by Yazoul AI

#InfoSec #Ransomware #IncidentResponse

##

halildeniz@mastodon.social at 2026-09-06T14:29:52.000Z ##

🚨 Critical Auth Bypass:
CVE-2026-82329 (CVSS 9.8) in JFrog Artifactory allows remote attackers to bypass authentication & mint admin tokens via blank join keys.

Read our full technical analysis & mitigation guide: denizhalil.com/2026/09/05/cve-

#CVE202682329 #DevSecOps #CyberSecurity

##

CVE-2026-20212
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-09-03T13:04:38.177000

3 posts

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with&nbsp;root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device an

1 repos

https://github.com/HORKimhab/CVE-2026-20212

security_crawler_carl at 2026-09-06T14:08:14.080Z ##

🏆 New Achievement! Root of All Evil: The Nexus Awakens!

PHASE TWO HAS BEGUN. CVE-2026-20212 stalks the arena — a CVSS 9.8 critical flaw in Cisco Nexus 9000 Series Switches running Silicon One ASICs. It requires no credentials, no user interaction, nothing. An attacker simply crafts input to TCP ports 43210 or 43211, exposed by default, and ascends to root. Full device compromise. Network disruption. Lateral movement through your data center like a speedrunner who memorized the map. (1/2)

##

netsecio@mastodon.social at 2026-09-05T16:20:27.000Z ##

📰 Cisco Patches Three Critical Flaws in IOS XR Network Software

Cisco patches 3 critical (CVSS 9.8) remote code execution vulnerabilities in IOS XR software (CVE-2026-20274, CVE-2026-20279, CVE-2026-20212). No active exploitation known, but immediate patching is urged. #Cisco #CyberSecurity #RCE #Networking

🔗 cyber.netsecops.io/articles/ci

##

security_crawler_carl@infosec.exchange at 2026-09-06T14:08:14.000Z ##

🏆 New Achievement! Root of All Evil: The Nexus Awakens!

PHASE TWO HAS BEGUN. CVE-2026-20212 stalks the arena — a CVSS 9.8 critical flaw in Cisco Nexus 9000 Series Switches running Silicon One ASICs. It requires no credentials, no user interaction, nothing. An attacker simply crafts input to TCP ports 43210 or 43211, exposed by default, and ascends to root. Full device compromise. Network disruption. Lateral movement through your data center like a speedrunner who memorized the map. (1/2)

##

CVE-2026-20279
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-09-02T18:32:32

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20279 are related to improper access control issues that are gro

netsecio@mastodon.social at 2026-09-05T16:20:27.000Z ##

📰 Cisco Patches Three Critical Flaws in IOS XR Network Software

Cisco patches 3 critical (CVSS 9.8) remote code execution vulnerabilities in IOS XR software (CVE-2026-20274, CVE-2026-20279, CVE-2026-20212). No active exploitation known, but immediate patching is urged. #Cisco #CyberSecurity #RCE #Networking

🔗 cyber.netsecops.io/articles/ci

##

CVE-2026-82691
(9.1 CRITICAL)

EPSS: 2.11%

updated 2026-09-02T14:17:15.257000

2 posts

A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the file /cgi-bin/usb_device.cgi of the component CGI Handler. Such manipulation of the argument f_ups_ip leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

secdb at 2026-09-07T00:01:37.001Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-07T00:01:37.000Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-62911
(8.0 HIGH)

EPSS: 1.32%

updated 2026-09-02T04:18:00.460000

2 posts

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

1 repos

https://github.com/hypnguyen1209/CVE-2026-62911

youranonnewsirc@nerdculture.de at 2026-09-07T22:26:24.000Z ##

A critical Microsoft Exchange vulnerability (CVE-2026-62911) leaves thousands of servers unpatched, while AI-assisted ransomware now compromises networks in under 10 hours. OpenAI released GPT-6 Astra, advancing Artificial General Intelligence. Geopolitically, Ukrainian drones struck Russia's Taganrog airbase overnight (Sept 6-7).

#Cybersecurity #TechNews #Geopolitics

##

youranonnewsirc@nerdculture.de at 2026-09-07T22:26:24.000Z ##

A critical Microsoft Exchange vulnerability (CVE-2026-62911) leaves thousands of servers unpatched, while AI-assisted ransomware now compromises networks in under 10 hours. OpenAI released GPT-6 Astra, advancing Artificial General Intelligence. Geopolitically, Ukrainian drones struck Russia's Taganrog airbase overnight (Sept 6-7).

#Cybersecurity #TechNews #Geopolitics

##

CVE-2026-59680
(8.0 HIGH)

EPSS: 2.34%

updated 2026-09-02T04:17:59.917000

2 posts

An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb read the shadowLastChange and shadowExpire fields with GetString(), which performs no numeric validation, and passed the resulting string to format_days_after_epoch(). That helper interpolated the value into a shell command execu

secdb at 2026-09-07T00:01:37.001Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-07T00:01:37.000Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-19490
(0 None)

EPSS: 3.37%

updated 2026-09-01T21:03:04.987000

5 posts

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

1 repos

https://github.com/TarPeg007/CVE-2026-19490

DailyCyberSecurity at 2026-09-07T13:13:25.095Z ##

Hackers are actively exploiting CVE-2026-19490, a critical authentication bypass vulnerability in Citrix NetScaler. Update your systems immediately.

meterpreter.org/citrix-netscal

##

beyondmachines1 at 2026-09-05T14:01:31.001Z ##

Threat Actors Target Critical Citrix NetScaler Authentication Bypass

Citrix NetScaler ADC and Gateway appliances face active exploitation of a critical authentication bypass (CVE-2026-19490) that allows unauthenticated attackers to access internal applications and VPN services.

**Your NetScaler appliances are now under attack, so act fast. Patch ASAP and check your logs for any unusual logins from the past few weeks. Even if you patch now, an attacker might have already created a back door while the system was open. And make sure to isolate the management interface from the internet.**

beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-09-07T13:13:25.000Z ##

Hackers are actively exploiting CVE-2026-19490, a critical authentication bypass vulnerability in Citrix NetScaler. Update your systems immediately.

#CitrixNetScaler #CyberSecurity #Vulnerability #NetworkSecurity #Infosec

meterpreter.org/citrix-netscal

##

beyondmachines1@infosec.exchange at 2026-09-05T14:01:31.000Z ##

Threat Actors Target Critical Citrix NetScaler Authentication Bypass

Citrix NetScaler ADC and Gateway appliances face active exploitation of a critical authentication bypass (CVE-2026-19490) that allows unauthenticated attackers to access internal applications and VPN services.

**Your NetScaler appliances are now under attack, so act fast. Patch ASAP and check your logs for any unusual logins from the past few weeks. Even if you patch now, an attacker might have already created a back door while the system was open. And make sure to isolate the management interface from the internet.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-09-04T18:20:00.000Z ##

Previdian reports exploitation attempts targeting CVE-2026-19490, a critical authentication bypass in Citrix NetScaler ADC and Gateway. Exposure depends on firmware version and AAA virtual server configuration. Review exposed assets and authentication logs for anomalous access. #CitrixNetScaler #AuthBypass #ThreatIntel

cyberworldops.eu/en/citrix-net

##

CVE-2026-82688
(9.1 CRITICAL)

EPSS: 2.79%

updated 2026-09-01T19:17:28.907000

2 posts

A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual Volume Handler. The manipulation of the argument f_sharename/f_target/f_name leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly an

secdb at 2026-09-07T00:01:37.001Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-07T00:01:37.000Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-82078
(9.1 CRITICAL)

EPSS: 1.69%

updated 2026-09-01T04:18:02.160000

1 posts

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on

2 repos

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

https://github.com/virologi-info/papercut-toolkit

Matchbook3469@mastodon.social at 2026-09-06T18:05:59.000Z ##

🔵 THREAT INTELLIGENCE

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Vulnerability | CRITICAL
CVEs: CVE-2026-81578, CVE-2026-82078

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S...

Full analysis:
yazoul.net/news/article/attack

by Yazoul AI

#CyberSecurity #CVE #ThreatHunting

##

CVE-2026-81578
(9.8 CRITICAL)

EPSS: 1.62%

updated 2026-08-31T21:31:56

1 posts

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

2 repos

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

https://github.com/virologi-info/papercut-toolkit

Matchbook3469@mastodon.social at 2026-09-06T18:05:59.000Z ##

🔵 THREAT INTELLIGENCE

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Vulnerability | CRITICAL
CVEs: CVE-2026-81578, CVE-2026-82078

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S...

Full analysis:
yazoul.net/news/article/attack

by Yazoul AI

#CyberSecurity #CVE #ThreatHunting

##

CVE-2026-82692
(9.9 CRITICAL)

EPSS: 2.36%

updated 2026-08-31T20:56:08.800000

2 posts

A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

secdb at 2026-09-07T00:01:37.001Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-07T00:01:37.000Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-82690
(9.1 CRITICAL)

EPSS: 2.11%

updated 2026-08-31T20:56:08.800000

2 posts

A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manipulation of the argument f_dev causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

secdb at 2026-09-07T00:01:37.001Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-07T00:01:37.000Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-82702
(6.6 MEDIUM)

EPSS: 2.05%

updated 2026-08-31T15:34:50

2 posts

A vulnerability was identified in Edimax BR-6214K 1.40. This affects the function system of the file www/wlanMP.asp of the component asp_WlanMP Endpoint. Such manipulation of the argument ateFunc leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond i

secdb at 2026-09-07T00:01:37.001Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-07T00:01:37.000Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-82689
(9.9 CRITICAL)

EPSS: 2.36%

updated 2026-08-31T12:30:37

2 posts

A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of the argument upIsoRootPath results in os command injection. The attack can be executed remotely. The exploit is now public and may be used.

secdb at 2026-09-07T00:01:37.001Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-07T00:01:37.000Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-6471
(7.2 HIGH)

EPSS: 0.29%

updated 2026-08-29T23:17:23.010000

5 posts

Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

2 repos

https://github.com/goldendivider/cve-2026-6471-postgres-logical-decoding-dlopen

https://github.com/0xBlackash/CVE-2026-6471

cyberworldops at 2026-09-06T00:20:00.450Z ##

PostgreSQL fixed CVE-2026-6471, an authorization flaw in logical decoding that lets users with REPLICATION privilege load arbitrary shared libraries. Code executes as the server OS user, typically postgres, enabling full host compromise from a low-privileged DB role.

cyberworldops.eu/en/postgresql

##

yhitaz@mastodon.acm.org at 2026-09-05T11:54:56.000Z ##

postgresql.org/support/securit
PostgreSQL-virhe mahdollistaa palvelimen haltuunoton pienillä oikeuksilla PostgreSQL on korjannut CVE-2026-6471 , vuodesta 2014 lähtien olleen virheen, joka sallii REPLICATION-oikeuksilla varustettujen tilien ladata mielivaltaisia ​​tiedostoja loogisen dekoodauksen laajennusten kautta ja suorittaa koodia tietokantapalvelutilinä. Vaikuttavat haarat sisältävät versiot 9.4–18, ja korjaukset on julkaistu versioissa 18.6, 17.11, 16.15, 15.

##

cyberworldops@infosec.exchange at 2026-09-06T00:20:00.000Z ##

PostgreSQL fixed CVE-2026-6471, an authorization flaw in logical decoding that lets users with REPLICATION privilege load arbitrary shared libraries. Code executes as the server OS user, typically postgres, enabling full host compromise from a low-privileged DB role. #PostgreSQL #AccessControl #CodeExecution

cyberworldops.eu/en/postgresql

##

guru@thecybersecguru.com at 2026-09-05T05:55:43.000Z ##

Critical PostgreSQL Flaw ‘PostGREShell’ (CVE-2026-6471) Enables Remote Code Execution: Complete Technical Breakdown and Remediation

CVE-2026-6471, dubbed PostGREShell, lets PostgreSQL replication users load unauthorized libraries and execute code. Learn the exploit and fix

thecybersecguru.com/exploits/c

##

cyberworldops@infosec.exchange at 2026-09-04T20:10:00.000Z ##

CVE-2026-6471 PostGREShell is an authorization flaw in PostgreSQL allowing REPLICATION users to execute arbitrary code as the server OS user. It affects versions since 2014 and enables escalation to superuser, making exposed replication accounts a critical risk. #PostgreSQL #CodeExecution #ThreatIntel

cyberworldops.eu/en/postgreshe

##

CVE-2026-18963
(9.1 CRITICAL)

EPSS: 3.24%

updated 2026-08-28T22:53:42

1 posts

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user

Nuclei template

14 repos

https://github.com/minh3102011/CVE-2026-18963_analyst

https://github.com/0xlyvio/CVE-2026-18963-keycloak

https://github.com/alt3kx/CVE-2026-18963

https://github.com/Snizi/CVE-2026-18963-Exploit

https://github.com/T0w0T/POC-CVE-2026-18963

https://github.com/prot0tw/Keycloak_CVE-2026-18963_PoC

https://github.com/EQSTLab/CVE-2026-18963

https://github.com/ynsmroztas/KeySniper

https://github.com/Red-Darkin/CVE-2026-18963-keycloak

https://github.com/BlackHatExploitation/Exploit-For-CVE-2026-18963

https://github.com/debugactiveprocess/CVE-2026-18963

https://github.com/kyos-public/keycloak-cve-2026-18963-hunt

https://github.com/M4xSec/My-Exploits

https://github.com/gman0x00/keycloak-CVE-2026-18963

sayzard@mastodon.sayzard.org at 2026-09-06T18:44:30.000Z ##

A flaw in the reset-credentials flow of the keycloak-services component

CVE-2026-18963은 Red Hat Build of Keycloak의 핵심 IAM 엔진인 keycloak-services에서 비밀번호 재설정 이메일 검증 단계를 우회할 수 있는 취약점이다. 인증되지 않은 원격 공격자가 임의 사용자의 재설정 절차를 강제하고 새 자격 증명을 설정해 계정을 완전히 탈취할 수 있으며, Red Hat CNA 평가는 CVSS 9.1(Critical)이다. AI 서비스의 SSO·관리자 콘솔·에이전트 및 내부 도구 인증에 Keycloak을 쓰는 팀은 영향을 받는 Red Hat 배포판을 즉시 보안 권고 버전(26.4.15 또는 26.6.6 계...

nvd.nist.gov/vuln/detail/cve-2

##

CVE-2026-53362
(7.8 HIGH)

EPSS: 0.51%

updated 2026-08-28T20:18:10.133000

2 posts

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length +

1 repos

https://github.com/suominen/ipv6_frag_escape

thecybermind at 2026-09-05T13:19:14.432Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-53362 – Linux Kernel Unspecified Vulnerability

Active exploitation of Linux kernel vulnerability CVE-2026-53362 threatens enterprise infrastructure. Read our C-Suite threat intelligence brief for mitigation strategies....

thecybermind.co/kpox

##

thecybermind@infosec.exchange at 2026-09-05T13:19:14.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-53362 – Linux Kernel Unspecified Vulnerability

Active exploitation of Linux kernel vulnerability CVE-2026-53362 threatens enterprise infrastructure. Read our C-Suite threat intelligence brief for mitigation strategies....

thecybermind.co/kpox

##

michaelharley at 2026-09-07T12:46:53.310Z ##

Welp. My Forgejo instance got popped with an RCE two days ago by CVE-2026-60004. Luckily, I noticed the following morning and had the day free to figure out what happened. Let's dive in!

As a homelab enthusiast, I found this a very interesting post. Here are my take aways from the post that I'm implementing myself:

  • Miner detection. I've updated monitoring rules to now watch the CPU on my hosts. If the same thing happened to me I would not have been alerted at all as I'm doing simple up / down monitoring. Fixed.
  • Access logging. I turned on access logging for my homelab Caddy instances.
  • Log retention. I have increased the amount and retention of my logging. The hope is this will help me reconstruct what happened after a breach.
  • Logs offsite. The VPS access logs now ride along with the normal backup process, which runs hourly. The homelab side still only gets caught by the weekly VM backup, so that's next.
  • Closed an open signup. My webtrees instance (genealogy) had self registration enabled, which is the same door this guy got hit through. Oops. Fixed.
  • Built a tool. log-inventory.sh, so "could I actually reconstruct what happened" is a command I run instead of a thing I assume.

My Homelab Got Hacked - A Postmortem – Phunky Cafe

##

michaelharley@infosec.exchange at 2026-09-07T12:46:53.000Z ##

Welp. My Forgejo instance got popped with an RCE two days ago by CVE-2026-60004. Luckily, I noticed the following morning and had the day free to figure out what happened. Let's dive in!

As a homelab enthusiast, I found this a very interesting post. Here are my take aways from the post that I'm implementing myself:

  • Miner detection. I've updated monitoring rules to now watch the CPU on my hosts. If the same thing happened to me I would not have been alerted at all as I'm doing simple up / down monitoring. Fixed.
  • Access logging. I turned on access logging for my homelab Caddy instances.
  • Log retention. I have increased the amount and retention of my logging. The hope is this will help me reconstruct what happened after a breach.
  • Logs offsite. The VPS access logs now ride along with the normal backup process, which runs hourly. The homelab side still only gets caught by the weekly VM backup, so that's next.
  • Closed an open signup. My webtrees instance (genealogy) had self registration enabled, which is the same door this guy got hit through. Oops. Fixed.
  • Built a tool. log-inventory.sh, so "could I actually reconstruct what happened" is a command I run instead of a thing I assume.

My Homelab Got Hacked - A Postmortem – Phunky Cafe

#Selfhosting #Security

##

CVE-2026-32475
(9.0 CRITICAL)

EPSS: 2.37%

updated 2026-08-20T12:48:31.843000

2 posts

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.

Nuclei template

6 repos

https://github.com/dinosn/cve-2026-32475-elementor-pro-lab

https://github.com/4minx/CVE-2026-32475

https://github.com/Boreas37/CVE-2026-32475-PoC

https://github.com/absholi7ly/Elementor-Pro-Unauthenticated-Arbitrary-File-Upload-to-RCE

https://github.com/sahmsec/CVE-2026-32475

https://github.com/0xBlackash/CVE-2026-32475

threatnoir at 2026-09-05T22:05:54.897Z ##

⚠️ CRITICAL: Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Threat actors are actively exploiting two critical RCE vulnerabilities in WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475), with over 440,000 exploit attempts already blocked. Unauthenticated attackers can upload arbitrary files including PHP web shells to gain full…

threatnoir.com/focus

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-09-05T22:05:54.000Z ##

⚠️ CRITICAL: Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Threat actors are actively exploiting two critical RCE vulnerabilities in WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475), with over 440,000 exploit attempts already blocked. Unauthenticated attackers can upload arbitrary files including PHP web shells to gain full…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

CVE-2026-62735
(7.8 HIGH)

EPSS: 0.48%

updated 2026-08-11T18:31:23

2 posts

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

2 repos

https://github.com/HackSpeak/CVE-2026-62735

https://github.com/nhh9905/CVE-2026-62735

DailyCyberSecurity at 2026-09-08T00:31:54.659Z ##

A Windows HTTP.sys vulnerability, CVE-2026-62735 (CVSS 7.8), now has public details and a PoC. It escalates local users to SYSTEM. Patch now.

securityonline.info/windows-ht

##

DailyCyberSecurity@infosec.exchange at 2026-09-08T00:31:54.000Z ##

A Windows HTTP.sys vulnerability, CVE-2026-62735 (CVSS 7.8), now has public details and a PoC. It escalates local users to SYSTEM. Patch now.

#Windows #HTTPsys #CVE202662735 #PrivilegeEscalation #Pwn2Own #SYSTEM #Infosec #PoC

securityonline.info/windows-ht

##

CVE-2026-18108
(9.8 CRITICAL)

EPSS: 0.22%

updated 2026-08-06T18:37:01.630000

1 posts

Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature. _verify_encrypted_assertion decrypts the EncryptedAssertion and returns it as verified when it carries no signature, via "return $xml unless $xpath->exists('dsig:Signature', $assert);". The signature check and the trus

PerlWeeklyNews@mas.to at 2026-09-07T09:11:03.000Z ##

New issue of #Perl Weekly:789 - The impact of LLMs on Perl - perlweekly.com/archive/789.html

CVE-2026-18108: Net::SAML2 Authentication Bypass via Unsigned Encrypted Assertions (CVSS 9.8)
AmberDB - An Embedded NoSQL Database Engine for Perl
DBI now has a minimum version of v5.12
CPAN Uploads Are Up 50% Year-over-Year
perl in cybersecurity?
The videos of the German Perl Workshop 2026 are online
German Perl/Raku Workshop 2027
YAPC::Tokyo 2026
London Perl & Raku Workshop 2026
[...]

##

CVE-2026-13230
(6.5 MEDIUM)

EPSS: 0.38%

updated 2026-08-06T18:21:08.780000

4 posts

An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without requiring authentication. This issue allows an attacker on the same local network to retrieve geolocation-related data through crafted responses. The vulnerability impacts confidentiality only, with no evidence of inte

BadChemical at 2026-09-08T01:07:25.893Z ##

@ohunt I can't speak to the CFAA since I'm no lawyer. Exploitation in this exact scenario isn't a valid classifier either since the underlying vuln of CVE-2026-13230 is a lack of meaningful protection, it equates to intercepting HTTP at this point. Ask and receive. However the protocol that operates on UDP 9999 has been broken for about 10 years now and has an RCE vuln on a different device class.

##

BadChemical at 2026-09-07T15:55:42.494Z ##

The LG TV network scanning story breaking today includes UDP 9999 Kasa discovery broadcasts every 25 seconds. That's the exact port I documented in CVE-2026-13230 as returning unauthenticated precise GPS coordinates from Kasa cameras with no authentication. Any LG TV + unpatched Kasa camera on the same network = GPS harvesting every 25 seconds. @briankrebs Advisory: github.com/BadChemical/IoT-Vul

##

BadChemical@infosec.exchange at 2026-09-08T01:07:25.000Z ##

@ohunt I can't speak to the CFAA since I'm no lawyer. Exploitation in this exact scenario isn't a valid classifier either since the underlying vuln of CVE-2026-13230 is a lack of meaningful protection, it equates to intercepting HTTP at this point. Ask and receive. However the protocol that operates on UDP 9999 has been broken for about 10 years now and has an RCE vuln on a different device class.

##

BadChemical@infosec.exchange at 2026-09-07T15:55:42.000Z ##

The LG TV network scanning story breaking today includes UDP 9999 Kasa discovery broadcasts every 25 seconds. That's the exact port I documented in CVE-2026-13230 as returning unauthenticated precise GPS coordinates from Kasa cameras with no authentication. Any LG TV + unpatched Kasa camera on the same network = GPS harvesting every 25 seconds. @briankrebs Advisory: github.com/BadChemical/IoT-Vul

#Iot #CVE #TPlink #LG #infosec

##

CVE-2026-13181
(8.1 HIGH)

EPSS: 0.50%

updated 2026-08-06T18:13:26.983000

1 posts

In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments.

1 repos

https://github.com/HORKimhab/CVE-2026-13181-CVE-2026-13182-CVE-2026-13183-CVE-2026-13184

sayzard@mastodon.sayzard.org at 2026-09-07T13:39:59.000Z ##

From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for Asp.net Ajax

Tanto Security는 Telerik UI for ASP.NET AJAX에서 인증 없이 AES-CBC 패딩 오라클을 악용하고 추가 취약점과 체이닝해 원격 코드 실행(RCE)에 도달할 수 있는 CVE-2026-13181~13184를 공개했습니다. 영향 범위는 2010.1.309부터 2026.2.519까지이며, Progress Software는 2026.2.708(2026 Q2 SP1)에서 해당 공격 체인 악용을 차단했다고 밝혔습니다. 공격에는 RadAsyncUpload가 포함된 접근 가능한 페이지, `UploadR...

tantosec.com/blog/2026/09/tele

##

CVE-2026-63077
(9.8 CRITICAL)

EPSS: 86.52%

updated 2026-08-06T05:17:05.170000

1 posts

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Nuclei template

5 repos

https://github.com/AnggaTechI/CVE-2026-63077

https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap

https://github.com/sfewer-r7/CVE-2026-63077

https://github.com/bakos-sandor-nx/teamcity-cve-2026-63077-remediation

https://github.com/0xCyp1337/CVE-2026-63077

Analyst207@mastodon.social at 2026-09-05T17:29:28.000Z ##

JetBrains Cadence Breach Exposes AWS Credentials, User Data

A critical deserialization flaw, CVE-2026-63077, was exploited by unknown attackers to breach JetBrains' Cadence environment, compromising AWS credentials, backups, and user data. The vulnerability, scoring 9.8, allowed threat actors to bypass authentication and execute malicious commands with ease.

osintsights.com/jetbrains-cade

#Cve202663077 #Jetbrains #Teamcity #AwsCredentialsExposure #DeserializationFlaw

##

CVE-2026-66066(CVSS UNKNOWN)

EPSS: 27.86%

updated 2026-07-30T18:23:34

1 posts

### Impact In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process environment. That environment typically holds `secret_key_base` and often credentials for external systems, which may in turn allow escalation to remote code execution or lateral movement to those systems. ##

7 repos

https://github.com/HackSpeak/CVE-2026-66066

https://github.com/0xBlackash/CVE-2026-66066

https://github.com/shinthink/CVE-2026-66066

https://github.com/Zer0SumGam3/CVE-2026-66066-POC

https://github.com/rails/rails-forensics-CVE-2026-66066

https://github.com/paveg/rails-activestorage-vips-audit

https://github.com/0xsha/KindaRails2Shell

cyberveille@mastobot.ping.moi at 2026-09-05T13:00:04.000Z ##

📢 CVE-2026-66066 : exploitation d'une RCE ActiveStorage (Rails) quelques heures après le patch

Cet article est un post-mortem détaillé d'un incident de sécurité impliquant la CVE-2026-66066 (alias KindaRails2Shell), une vulnérabilité de type exécution de code à distance (RCE) avec un score CVSS 9.5/10 affectant le composant ActiveStorage de Ruby on…

📖 cyberveille : cyberveille.ch/posts/2026-09-0
🌐 source : rietta.com/blog/ruby-on-rails-
🟡 vérification factuelle moyenne
#ActiveStorage #RCE #Cyberveille

##

CVE-2026-43284
(7.8 HIGH)

EPSS: 93.23%

updated 2026-07-14T15:31:59

1 posts

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when

45 repos

https://github.com/cumakurt/linuxpi

https://github.com/krisiasty/vcheck

https://github.com/aettern/copyfrag-fuse

https://github.com/grabesec/XCP_ng_CVE-2026-43284_tester

https://github.com/scriptzteam/Paranoid-Dirty-Frag-CVE-2026-43284

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/haydenjames/dirty-frag-check

https://github.com/nonameuserosint-hue/DirtyFrag-go

https://github.com/linnemanlabs/dirtyfrag-arm64

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/First-John/cve_2026_frag_family_fix

https://github.com/6abc/Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/0xBlackash/CVE-2026-43284

https://github.com/AK777177/Dirty-Frag-Analysis

https://github.com/kuniyal08/Dirty-Frag-CVE-2026-43284

https://github.com/attaattaatta/CVE-2026-43500

https://github.com/FrosterDL/CVE-2026-43284

https://github.com/0xlane/pagecache-guard

https://github.com/t1ckprivate/CVE-2026-43284-Dirty-Frag

https://github.com/jayhutajulu1/CVE-2026-43284-DirtyFrag-PoC

https://github.com/1neptune/DirtyFrag

https://github.com/AtlasVector/Dirty-Frag-CVE-2026-43284

https://github.com/XRSecCD/202605_dirty_frag

https://github.com/LucasPDiniz/CVE-2026-43284

https://github.com/g0thamRabb1t/CVE-2026-43284-dirtyfrag-detection

https://github.com/RevyHub/CVE-2026-43284---DirtyFrag-Analysis-THM-

https://github.com/Aiyakami/rust_dirtyfrag

https://github.com/suominen/CVE-2026-43284

https://github.com/cyber-niz/Dirty-Frag

https://github.com/xd20111/CVE-2026-43284

https://github.com/nabhan-mohy/Dirty-Frag-Research-CVE-2026-43284-

https://github.com/ChernStepanov/DirtyFrag-for-dummies

https://github.com/ryan2929/CVE-2026-43284-

https://github.com/metalx1993/dirtyfrag-patches

https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC

https://github.com/armircetaj/tetragon-dirtyfrag

https://github.com/mym0us3r/DIRTY-FRAG-Detection-with-Wazuh-4.14.4

https://github.com/liamromanis101/DirtyFrag-Detector

https://github.com/dixyes/dirtypatch

https://github.com/gagaltotal/CVE-2026-43284-CVE-2026-43500-scan

https://github.com/lukeslp/redtail-ioc

https://github.com/MadExploits/CVE-2026-46300

https://github.com/millikanjohnl-blip/dirtyfrag-detection-rules

https://github.com/DylanClaudio/Reporte-de-Escalada-de-Privilegios-Local-Dirty-Frag

sigint@fosstodon.org at 2026-09-08T00:30:11.000Z ##

🐧 SIGINT // Linux Watch — 2026-09-08

A local root escalation with public PoC code and Ubuntu already shipping fixed package versions — translation: patch your kernels this week, not next quarter.

🔗 aikido.dev/blog/dirty-frag-cve

#Linux #OpenSource #FOSS

##

CVE-2026-14894
(9.8 CRITICAL)

EPSS: 5.27%

updated 2026-07-10T15:43:30.330000

2 posts

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separat

Nuclei template

3 repos

https://github.com/1beelze/CVE-2026-14894

https://github.com/shinthink/CVE-2026-14894

https://github.com/katranSefa/cve_2026_14894

threatnoir at 2026-09-05T22:05:54.897Z ##

⚠️ CRITICAL: Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Threat actors are actively exploiting two critical RCE vulnerabilities in WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475), with over 440,000 exploit attempts already blocked. Unauthenticated attackers can upload arbitrary files including PHP web shells to gain full…

threatnoir.com/focus

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-09-05T22:05:54.000Z ##

⚠️ CRITICAL: Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Threat actors are actively exploiting two critical RCE vulnerabilities in WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475), with over 440,000 exploit attempts already blocked. Unauthenticated attackers can upload arbitrary files including PHP web shells to gain full…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

CVE-2026-52770
(7.5 HIGH)

EPSS: 0.28%

updated 2026-07-09T21:00:06

1 posts

### Summary YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthenticated SQL injection in numeric `query` / `queries` filters. For Bazar fields whose value structure is numeric, YesWiki escapes the attacker-controlled filter value but inserts it into SQL without quotes or numeric validation. An unauthenticated attacker can inject boolean SQL expressions and infer database contents

thehackerwire@mastodon.social at 2026-09-05T06:02:06.000Z ##

🟠 CVE-2026-52770 - High (7.5)

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthenticated SQL injection in numeric query / queries filters. For Bazar fields whose value structure is numeric, Yes...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52769
(8.3 HIGH)

EPSS: 0.30%

updated 2026-07-09T20:58:34

1 posts

## Summary The `POST /api/forms/{formId}/actor/inbox` route - exposed publicly with `acl:"public"` - accepts an HTTP `Signature` header whose `keyId` parameter is a URL. `HttpSignatureService::verifySignature()` parses the header and **immediately makes a server-side HTTP GET** to that URL, **before** any cryptographic verification or URL validation. An unauthenticated remote attacker can therefor

thehackerwire@mastodon.social at 2026-09-05T06:01:56.000Z ##

🟠 CVE-2026-52769 - High (8.3)

YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route - exposed publicly with acl:"public" - accepts an HTTP Signature header whose keyId parameter is a URL. HttpSignatu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-22769
(10.0 CRITICAL)

EPSS: 13.12%

updated 2026-06-17T10:20:23.560000

2 posts

Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgr

CVE-2025-30208
(5.3 MEDIUM)

EPSS: 74.97%

updated 2026-06-17T09:08:21.517000

1 posts

Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses this limitation and returns the file content if it exists. This bypass exists because trailing separators such as `?` are removed in several places

Nuclei template

23 repos

https://github.com/MiclelsonCN/CVE-2025-30208_POC

https://github.com/HaGsec/CVE-2025-30208

https://github.com/Lusensec/CVE-2025-30208

https://github.com/On1onss/CVE-2025-30208

https://github.com/r0ngy40/CVE-2025-30208-Series

https://github.com/marino-admin/Vite-CVE-2025-30208-Scanner

https://github.com/TH-SecForge/CVE-2025-30208

https://github.com/jackieya/ViteVulScan

https://github.com/keklick1337/CVE-2025-30208-ViteVulnScanner

https://github.com/lilil3333/Vite-CVE-2025-30208-EXP

https://github.com/nkuty/CVE-2025-30208-31125-31486-32395

https://github.com/sadhfdw129/CVE-2025-30208-Vite

https://github.com/sumeet-darekar/CVE-2025-30208

https://github.com/imbas007/CVE-2025-30208-template

https://github.com/cc3305/CVE-2025-30208

https://github.com/4xura/CVE-2025-30208

https://github.com/0xshaheen/CVE-2025-30208

https://github.com/HazaVVIP/CVE-2025-30208

https://github.com/ThemeHackers/CVE-2025-30208

https://github.com/ThumpBo/CVE-2025-30208-EXP

https://github.com/4m3rr0r/CVE-2025-30208-PoC

https://github.com/iSee857/CVE-2025-30208-PoC

https://github.com/xuemian168/CVE-2025-30208

ptl@tooting.ch at 2026-09-07T21:05:54.000Z ##

#Blog #Security
Tient tient du monde essaye de trouver offsec.com/blog/cve-2025-30208/
Comme /@fs/home/ec2-user/.aws/credentials
Les scanners de vulnérabilité ... y en a TOUT le temps

##

kev_Stalker@infosec.exchange at 2026-09-05T08:18:45.000Z ##

CVE-2022-37969 - Changed to Known Ransomware Status

Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation VulnerabilityVendor: MicrosoftProduct: WindowsMicrosoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 04, 2026 at 16:08:17 UTCDate Added to KEV: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2023-41974
(7.8 HIGH)

EPSS: 1.41%

updated 2026-03-12T03:31:06

2 posts

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17. An app may be able to execute arbitrary code with kernel privileges.

CVE-2016-4117
(9.8 CRITICAL)

EPSS: 94.35%

updated 2025-11-17T21:32:21

1 posts

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

1 repos

https://github.com/amit-raut/CVE-2016-4117-Report

kev_Stalker@infosec.exchange at 2026-09-05T08:23:22.000Z ##

CVE-2016-4117 - Changed to Known Ransomware Status

Adobe Flash Player Arbitrary Code Execution VulnerabilityVendor: AdobeProduct: Flash PlayerAn access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 04, 2026 at 16:08:17 UTCDate Added to KEV: 2022-03-03View nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2021-44228
(10.0 CRITICAL)

EPSS: 100.00%

updated 2025-10-22T19:13:26

1 posts

# Summary Log4j versions prior to 2.16.0 are subject to a remote code execution vulnerability via the ldap JNDI parser. As per [Apache's Log4j security guide](https://logging.apache.org/log4j/2.x/security.html): Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who

Nuclei template

100 repos

https://github.com/sec13b/CVE-2021-44228-POC

https://github.com/justakazh/Log4j-CVE-2021-44228

https://github.com/1lann/log4shelldetect

https://github.com/jas502n/Log4j2-CVE-2021-44228

https://github.com/CreeperHost/Log4jPatcher

https://github.com/toramanemre/log4j-rce-detect-waf-bypass

https://github.com/giterlizzi/nmap-log4shell

https://github.com/mergebase/log4j-detector

https://github.com/CrackerCat/CVE-2021-44228-Log4j-Payloads

https://github.com/momos1337/Log4j-RCE

https://github.com/aws-samples/kubernetes-log4j-cve-2021-44228-node-agent

https://github.com/leonjza/log4jpwn

https://github.com/LiveOverflow/log4shell

https://github.com/alexbakker/log4shell-tools

https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words

https://github.com/yahoo/check-log4j

https://github.com/qingtengyun/cve-2021-44228-qingteng-patch

https://github.com/boundaryx/cloudrasp-log4j2

https://github.com/KosmX/CVE-2021-44228-example

https://github.com/NCSC-NL/log4shell

https://github.com/DragonSurvivalEU/RCE

https://github.com/tippexs/nginx-njs-waf-cve2021-44228

https://github.com/Jeromeyoung/log4j2burpscanner

https://github.com/0xInfection/LogMePwn

https://github.com/redhuntlabs/Log4JHunt

https://github.com/simonis/Log4jPatch

https://github.com/f0ng/log4j2burpscanner

https://github.com/mzlogin/CVE-2021-44228-Demo

https://github.com/CERTCC/CVE-2021-44228_scanner

https://github.com/stripe/log4j-remediation-tools

https://github.com/alexandre-lavoie/python-log4rce

https://github.com/infiniroot/nginx-mitigate-log4shell

https://github.com/rubo77/log4j_checker_beta

https://github.com/MalwareTech/Log4jTools

https://github.com/Nanitor/log4fix

https://github.com/back2root/log4shell-rex

https://github.com/Azeemering/CVE-2021-44228-DFIR-Notes

https://github.com/NorthwaveSecurity/log4jcheck

https://github.com/blake-fm/vcenter-log4j

https://github.com/thomaspatzke/Log4Pot

https://github.com/ssl/scan4log4j

https://github.com/kubearmor/log4j-CVE-2021-44228

https://github.com/darkarnium/Log4j-CVE-Detect

https://github.com/wortell/log4j

https://github.com/dtact/divd-2021-00038--log4j-scanner

https://github.com/corelight/cve-2021-44228

https://github.com/Labout/log4shell-rmi-poc

https://github.com/Adikso/minecraft-log4j-honeypot

https://github.com/puzzlepeaches/Log4jCenter

https://github.com/RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs

https://github.com/corretto/hotpatch-for-apache-log4j2

https://github.com/hackinghippo/log4shell_ioc_ips

https://github.com/nccgroup/log4j-jndi-be-gone

https://github.com/mr-vill4in/log4j-fuzzer

https://github.com/dwisiswant0/look4jar

https://github.com/nu11secur1ty/CVE-2021-44228-VULN-APP

https://github.com/Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228

https://github.com/fireeye/CVE-2021-44228

https://github.com/greymd/CVE-2021-44228

https://github.com/bigsizeme/Log4j-check

https://github.com/fullhunt/log4j-scan

https://github.com/thecyberneh/Log4j-RCE-Exploiter

https://github.com/TaroballzChen/CVE-2021-44228-log4jVulnScanner-metasploit

https://github.com/mufeedvh/log4jail

https://github.com/Diverto/nse-log4shell

https://github.com/r3kind1e/Log4Shell-obfuscated-payloads-generator

https://github.com/takito1812/log4j-detect

https://github.com/puzzlepeaches/Log4jHorizon

https://github.com/christophetd/log4shell-vulnerable-app

https://github.com/qingtengyun/cve-2021-44228-qingteng-online-patch

https://github.com/roxas-tan/CVE-2021-44228

https://github.com/marcourbano/CVE-2021-44228

https://github.com/BinaryDefense/log4j-honeypot-flask

https://github.com/cisagov/log4j-scanner

https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce

https://github.com/irgoncalves/f5-waf-quick-patch-cve-2021-44228

https://github.com/pedrohavay/exploit-CVE-2021-44228

https://github.com/puzzlepeaches/Log4jUnifi

https://github.com/logpresso/CVE-2021-44228-Scanner

https://github.com/lucab85/log4j-cve-2021-44228

https://github.com/faisalfs10x/Log4j2-CVE-2021-44228-revshell

https://github.com/0xDexter0us/Log4J-Scanner

https://github.com/mr-r3b00t/CVE-2021-44228

https://github.com/CodeShield-Security/Log4JShell-Bytecode-Detector

https://github.com/kozmer/log4j-shell-poc

https://github.com/claranet/ansible-role-log4shell

https://github.com/Kadantte/CVE-2021-44228-poc

https://github.com/HyCraftHD/Log4J-RCE-Proof-Of-Concept

https://github.com/cyberxml/log4j-poc

https://github.com/sunnyvale-it/CVE-2021-44228-PoC

https://github.com/AlexandreHeroux/Fix-CVE-2021-44228

https://github.com/twseptian/spring-boot-log4j-cve-2021-44228-docker-lab

https://github.com/HynekPetrak/log4shell-finder

https://github.com/future-client/CVE-2021-44228

https://github.com/fox-it/log4j-finder

https://github.com/toramanemre/apache-solr-log4j-CVE-2021-44228

https://github.com/mubix/CVE-2021-44228-Log4Shell-Hashes

https://github.com/lfama/log4j_checker

https://github.com/NS-Sp4ce/Vm4J

https://github.com/irgoncalves/f5-waf-enforce-sig-CVE-2021-44228

thehackerwire@mastodon.social at 2026-09-04T22:00:31.000Z ##

🟠 CVE-2026-85656 - High (7.8)

An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

lacze at 2026-09-07T16:51:41.863Z ##

RE: mastodon.online/@rozie/1172242

Eteryu stara się przedstawić swoje tezy jako wynik rzetelnej analizy, jego tekst zawiera elementy dezinformacji, wybiórcze traktowanie faktów oraz jednostronne podejście do omawianych kwestii.

Jak na moje oko, Baza wiedzy Eteryu space – jest jedynie kopią, niestety mocno okrojoną i uproszczoną. Szczegóły w dalszej częśći tekstu, wraz ze zródłami oraz zrzutami ekranu.

🧵 1/2

Baza Wiedzy Eteryu

PODWÓJNE STANDARDY W OCENIE CHROME I BRAVE
Eteryu twierdzi, że Chrome na PC jest ‘czystszym wyborem’ dzięki izolacji procesów, ale celowo bagatelizuje ryzyko związane z telemetrią Chrome.
Błędne założenie o izolacji procesów
Chrome oferuje ‘niezrównaną izolację procesów’, w rzeczywistości wiele przeglądarek opartych na Chromium stosuje identyczne mechanizmy, takie jak: Site Isolation (izolacja stron w osobnych procesach), Process-per-site-instance (osobny proces dla każdej instancji strony). Różnice w izolacji wynikają głównie z ustawień domyślnych (np. Chrome domyślnie włącza Site Isolation, podczas gdy niektóre forki wymagają ręcznej konfiguracji). Przedstawia Chrome jako wyjątkowego lidera, podczas gdy w praktyce wiele przegląddek Chromium osiąga podobnypoziom bezpieczeństwa.
Niespójność w ocenie Brave jest ‘wysoce zalecany’ na Androidzie ze względu na możliwość wyłączenia JIT w V8, co rzekomo ‘amputuje główny wektor ataków’. To prawda, ale częściowa. Wyłączenie JIT nie jest unikalne dla Brave , każdy użytkownik Chromium może to zrobić ręcznie (np. poprzez flagi –disable-jit). JIT nie jest jedynym wektorem ataków, luki w V8 (np. CVE-2022-1096) były wykorzystywane w atakach nawet z wyłączonym JIT. Eteryu przedstawia rozwiązanie jako panaceum, podczas gdy realne bezpieczeństwo wymaga szerszego podejścia. Brave jest dobrą opcją, ale nie ze względu na ‘wyłączanie JIT’, a raczej dzięki blokowaniu reklam, trackerów i lepszej ochronie prywatności. Tak, “zbędne” funkcje w Brave (jak moduły krypto czy AI) można ręcznie wyłączyć, celowo pomijane, by przedstawić przeglądarkę jako “skomplikowaną”. W rzeczywistości Brave jest bardziej konfigurowalny niż Chrome dzięki lepszej obsłudze rozszerzeń i flag.

AKTUALIZACJE
Chrome jako ‘upstream’ otrzymuje łatki krytyczne ‘natychmiast’, podczas gdy forki muszą je synchronizować. To półprawda. Chrome nie jest jedynym projektem upstream: Chromium (na którym bazuje Chrome) jest open source i wszystkie przeglądarki oparte na Chromium otrzymują łatki w tym samym czasie. Różnice wynikają jedynie z czasu potrzebnego na kompilację i testowanie własnych modyfikacji.

NAJWIĘKSZY PROBLEM TKWI W IGNOROWANIU REALNYCH ALTERNATYW NA DESKTOPIE.
Chrome jest “zawsze lepszy”, ale: Edge (również Chromium) ma lepszą integrację z Windows (ochrona przed phishingiem, lepsze zarządzanie pamięcią) i jest domyślnie instalowany na wielu maszynach.
Przeglądarka Edge zdobyła nawet uznanie wśród autorów treści, którymi Eteryu zdaje się posiłkować. Można tam przeczytać że przeglądarka Edge na Windows, oferuje większe bezpieczeństwo od Chrome i nawet stawia się ją obok przeglądarek Vanadium (GrapheneOS), oraz Trivalent (Secureblue) jednak zwraca się uwagę na problemem z telemetrią.
Safari na MacOS oferuje lepszą izolację procesów niż Chrome dzięki głębszej integracji z systemem i mniejsze ryzyko zero-day (mniejsza baza użytkowników = mniej celów dla ataków).
Czy Eteryu celowo pomija te przeglądarki, by promować Chrome? Choć Edge i Safari są technicznie lepsze w swoich ekosystemach. Jak widać jest to wybiórcza, analiza skupia się na jednym ignorując szerszy kontekst bezpieczeństwa i wydajności.
Podsumowując: To nie jest “ścisła analiza”, tylko subiektywna ocena oparta na preferencjach. Dla prawdziwie bezpiecznej przeglądarki na desktopie lepszym wyborem byłoby Edge (Windows), Safari (Mac). Brave często cenony jest za blokowanie reklam i trackerów.

Linux
Rzeczywistość jest bardziej złożona:

Więcej
👇
2/2 poniżej

~

##

lacze@infosec.exchange at 2026-09-07T16:51:41.000Z ##

RE: mastodon.online/@rozie/1172242

Eteryu stara się przedstawić swoje tezy jako wynik rzetelnej analizy, jego tekst zawiera elementy dezinformacji, wybiórcze traktowanie faktów oraz jednostronne podejście do omawianych kwestii.

Jak na moje oko, Baza wiedzy Eteryu space – jest jedynie kopią, niestety mocno okrojoną i uproszczoną. Szczegóły w dalszej częśći tekstu, wraz ze zródłami oraz zrzutami ekranu.

🧵 1/2

Baza Wiedzy Eteryu

PODWÓJNE STANDARDY W OCENIE CHROME I BRAVE
Eteryu twierdzi, że Chrome na PC jest ‘czystszym wyborem’ dzięki izolacji procesów, ale celowo bagatelizuje ryzyko związane z telemetrią Chrome.
Błędne założenie o izolacji procesów
Chrome oferuje ‘niezrównaną izolację procesów’, w rzeczywistości wiele przeglądarek opartych na Chromium stosuje identyczne mechanizmy, takie jak: Site Isolation (izolacja stron w osobnych procesach), Process-per-site-instance (osobny proces dla każdej instancji strony). Różnice w izolacji wynikają głównie z ustawień domyślnych (np. Chrome domyślnie włącza Site Isolation, podczas gdy niektóre forki wymagają ręcznej konfiguracji). Przedstawia Chrome jako wyjątkowego lidera, podczas gdy w praktyce wiele przegląddek Chromium osiąga podobnypoziom bezpieczeństwa.
Niespójność w ocenie
Brave jest ‘wysoce zalecany’ na Androidzie ze względu na możliwość wyłączenia JIT w V8, co rzekomo ‘amputuje główny wektor ataków’. To prawda, ale częściowa. Wyłączenie JIT nie jest unikalne dla Brave , każdy użytkownik Chromium może to zrobić ręcznie (np. poprzez flagi –disable-jit). JIT nie jest jedynym wektorem ataków, luki w V8 (np. CVE-2022-1096) były wykorzystywane w atakach nawet z wyłączonym JIT. Eteryu przedstawia rozwiązanie jako panaceum, podczas gdy realne bezpieczeństwo wymaga szerszego podejścia. Brave jest dobrą opcją, ale nie ze względu na ‘wyłączanie JIT’, a raczej dzięki blokowaniu reklam, trackerów i lepszej ochronie prywatności. Tak, “zbędne” funkcje w Brave (jak moduły krypto czy AI) można ręcznie wyłączyć, celowo pomijane, by przedstawić przeglądarkę jako “skomplikowaną”. W rzeczywistości Brave jest bardziej konfigurowalny niż Chrome dzięki lepszej obsłudze rozszerzeń i flag.

AKTUALIZACJE
Chrome jako ‘upstream’ otrzymuje łatki krytyczne ‘natychmiast’, podczas gdy forki muszą je synchronizować. To półprawda. Chrome nie jest jedynym projektem upstream: Chromium (na którym bazuje Chrome) jest open source i wszystkie przeglądarki oparte na Chromium otrzymują łatki w tym samym czasie. Różnice wynikają jedynie z czasu potrzebnego na kompilację i testowanie własnych modyfikacji.

NAJWIĘKSZY PROBLEM TKWI W IGNOROWANIU REALNYCH ALTERNATYW NA DESKTOPIE.
Chrome jest “zawsze lepszy”, ale: Edge (również Chromium) ma lepszą integrację z Windows (ochrona przed phishingiem, lepsze zarządzanie pamięcią) i jest domyślnie instalowany na wielu maszynach.
Przeglądarka Edge zdobyła nawet uznanie wśród autorów treści, którymi Eteryu zdaje się posiłkować. Można tam przeczytać że przeglądarka Edge na Windows, oferuje większe bezpieczeństwo od Chrome i nawet stawia się ją obok przeglądarek Vanadium (GrapheneOS), oraz Trivalent (Secureblue) jednak zwraca się uwagę na problemem z telemetrią.
Safari na MacOS oferuje lepszą izolację procesów niż Chrome dzięki głębszej integracji z systemem i
mniejsze ryzyko zero-day (mniejsza baza użytkowników = mniej celów dla ataków).
Czy Eteryu celowo pomija te przeglądarki, by promować Chrome? Choć Edge i Safari są technicznie lepsze w swoich ekosystemach. Jak widać jest to wybiórcza, analiza skupia się na jednym ignorując szerszy kontekst bezpieczeństwa i wydajności.
Podsumowując: To nie jest “ścisła analiza”, tylko subiektywna ocena oparta na preferencjach. Dla prawdziwie bezpiecznej przeglądarki na desktopie lepszym wyborem byłoby Edge (Windows), Safari (Mac). Brave często cenony jest za blokowanie reklam i trackerów.

Linux
Rzeczywistość jest bardziej złożona:

Więcej poniżej👇

##

CVE-2026-80172
(0 None)

EPSS: 0.00%

2 posts

N/A

CVE-2026-59347
(0 None)

EPSS: 0.00%

1 posts

N/A

cyberveille@mastobot.ping.moi at 2026-09-07T12:30:06.000Z ##

📢 [VULN] Une VM pour prendre le contrôle de votre PC : patchez VMware Workstation et Fusion - CVE-2026-59346 CVE-2026-59347

Vous utilisez VMware Workstation Pro ou VMware Fusion ? Passez par la case maintenance. Broadcom vient de corriger deux vulnérabilités, dont une critique, qui permettent à un attaquant ayant le contrôle d'une machine virtuelle d'exécuter du code sur la machine hôte. Voici…

🔗 it-connect.fr/vmware-workstati
💬 discussion : infosec.pub/post/51979344
#Vulnérabilité #CVE #Cyberveille

##

CVE-2026-59346
(0 None)

EPSS: 0.00%

4 posts

N/A

cyberveille@mastobot.ping.moi at 2026-09-07T12:30:06.000Z ##

📢 [VULN] Une VM pour prendre le contrôle de votre PC : patchez VMware Workstation et Fusion - CVE-2026-59346 CVE-2026-59347

Vous utilisez VMware Workstation Pro ou VMware Fusion ? Passez par la case maintenance. Broadcom vient de corriger deux vulnérabilités, dont une critique, qui permettent à un attaquant ayant le contrôle d'une machine virtuelle d'exécuter du code sur la machine hôte. Voici…

🔗 it-connect.fr/vmware-workstati
💬 discussion : infosec.pub/post/51979344
#Vulnérabilité #CVE #Cyberveille

##

Analyst207@mastodon.social at 2026-09-05T17:30:45.000Z ##

Broadcom Patches VMware Flaws That Expose Hosts to Code Execution

Broadcom has patched a critical VMware flaw that lets attackers with local admin access on a virtual machine execute code on the host, thanks to an integer-overflow vulnerability in the VMXNET3 virtual network adapter. This bug, tracked as CVE-2026-59346, earned a near-perfect CVSS score of 9.3, highlighting the severity of the threat.

osintsights.com/broadcom-patch

#Vmware #CodeExecution #Vmxnet3 #Cve202659346 #Broadcom

##

netsecio@mastodon.social at 2026-09-05T16:20:20.000Z ##

📰 Broadcom Patches Critical VMware VM Escape Vulnerabilities

Broadcom patches critical VMware flaws (CVE-2026-59346, CVSS 9.3) in Workstation & Fusion. Vulnerabilities allow VM escape, enabling code execution on the host system. No active exploits known. #VMware #CyberSecurity #Virtualization #PatchNow

🔗 cyber.netsecops.io/articles/br

##

cyberworldops@infosec.exchange at 2026-09-04T22:20:00.000Z ##

Broadcom patched two VM escape flaws in VMware Workstation and Fusion. CVE-2026-59346 is an integer overflow in VMXNET3 (CVSS 9.3) allowing host code execution from a privileged VM guest. High risk for dev and lab environments relying on VM isolation. #VmEscape #InfoSec #Virtualization

cyberworldops.eu/en/vmware-wor

##

CVE-2026-38291
(0 None)

EPSS: 0.00%

1 posts

N/A

cvedatabase@techhub.social at 2026-09-07T10:30:03.000Z ##

📑 Our latest Weekly CVE Roundup is live! We're analyzing a critical RCE in FastAPI-Schema-Validator (CVE-2026-38291) and the emergence of runtime schema injection attacks targeting Python APIs. Essential reading for security pros and Python devs. Read the full analysis: cvedatabase.com/blog/weekly-cv #CVE #FastAPI #Python #CyberSecurity #RCE #SupplyChain

##

CVE-2026-79756
(0 None)

EPSS: 5.15%

2 posts

N/A

secdb at 2026-09-07T00:01:37.001Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-07T00:01:37.000Z ##

📈 CVE Published in last 7 days (2026-08-31 - 2026-08-31)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 279
- High: 797
- Medium: 785
- Low: 164
- None: 256

Status:
- : 11
- Analyzed: 188
- Awaiting Analysis: 167
- Deferred: 651
- Modified: 33
- Received: 1141
- Rejected: 24
- Undergoing Analysis: 66

CISA KEVs:
- CISA-2026:0831 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0902 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0904 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 359
- VulDB: 212
- kernel.org: 188
- GitHub, Inc.: 179
- MITRE: 175
- WPScan: 134
- Patchstack: 107
- Hewlett Packard Enterprise (HPE): 86
- Wordfence: 78
- IBM Corporation: 70

Top Affected Products:
- UNKNOWN: 1826
- Arubanetworks Fabric Composer: 52
- Mozilla Thunderbird: 31
- Nvidia Nemo Megatron Bridge: 30
- Hpe Arubaos-cx: 29
- Mozilla Firefox: 26
- Elastic Kibana: 22
- Google Chrome: 22
- Wwbn Avideo: 21
- Erlang/otp: 16

Top EPSS Score:
- CVE-2026-79756 - 5.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82688 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82689 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82692 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-59680 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85224 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82690 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82691 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-85222 - 2.11 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-82702 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-77477
(0 None)

EPSS: 0.00%

2 posts

N/A

cyberworldops at 2026-09-06T04:10:00.398Z ##

CISA reports CVE-2026-77477 in OPCFoundation UA-LDS-Installers before 1.04.420. A local attacker can abuse the elevated installer session to execute arbitrary commands as SYSTEM. This puts OT discovery hosts at risk of full compromise during deployment.

cyberworldops.eu/en/opc-ua-lds

##

cyberworldops@infosec.exchange at 2026-09-06T04:10:00.000Z ##

CISA reports CVE-2026-77477 in OPCFoundation UA-LDS-Installers before 1.04.420. A local attacker can abuse the elevated installer session to execute arbitrary commands as SYSTEM. This puts OT discovery hosts at risk of full compromise during deployment. #OpcUa #OtSecurity #IcsSecurity

cyberworldops.eu/en/opc-ua-lds

##

CVE-2026-53495
(0 None)

EPSS: 0.00%

1 posts

N/A

sayzard@mastodon.sayzard.org at 2026-09-06T02:38:32.000Z ##

Release containerd 2.3.5 · containerd/containerd

containerd 2.3.5는 보안 패치(CVE-2026-53495/GHSA-rp3h-jf77-q9p4)를 포함한 2.3 계열의 다섯 번째 패치 릴리스다. 이미지 descriptor URL을 가져올 때 민감한 인증 헤더를 제거하도록 하드닝해 레지스트리 인증 정보 노출 위험을 줄였다. CRI 표준 입출력 스트리밍의 데이터 레이스·교착 상태와 shim 로딩/시작 멈춤 문제를 수정해 Kubernetes 및 컨테이너 기반 AI 워크로드의 런타임 안정성을 개선한다. EROFS 이미지 언팩과 Windows Server 2022 호환성, OpenTelemetry 오류 속성도 보완됐으며, 운영 환...

github.com/containerd/containe

##

CVE-2026-19534
(0 None)

EPSS: 0.39%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-04T23:03:15.000Z ##

🟠 CVE-2026-19534 - High (7.5)

undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 respon...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61686
(0 None)

EPSS: 0.42%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-04T23:03:05.000Z ##

🟠 CVE-2026-61686 - High (7.5)

SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop is marked `writable: true`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63464
(0 None)

EPSS: 0.27%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-04T21:00:54.000Z ##

🟠 CVE-2026-63464 - High (7.7)

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/webhook-sub...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85786
(0 None)

EPSS: 0.33%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-04T21:00:34.000Z ##

🟠 CVE-2026-85786 - High (7.5)

Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression due to insuff...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85781
(0 None)

EPSS: 0.26%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-04T20:00:00.000Z ##

🟠 CVE-2026-85781 - High (8.7)

Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion of direct...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

awssecurityfeed@infosec.exchange at 2026-09-04T19:15:01.000Z ##

CVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver

Bulletin ID: 2026-099-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 11:45 AM PDT
Description:
The Amazon EFS CSI Driver is an open-source Kubernetes Container Storage Interface (CSI) dr...

aws.amazon.com/security/securi

#aws #security

##

Visit counter For Websites