## Updated at UTC 2026-09-17T08:03:11.909232

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-87796 9.8 0.00% 2 0 2026-09-17T05:17:02.123000 The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbit
CVE-2026-91843 9.8 0.00% 7 0 2026-09-17T04:18:10.730000 A stack overflow during the unauthenticated login process may allow an attacker
CVE-2026-76460 10.0 0.00% 10 0 2026-09-17T04:18:01.527000 A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an
CVE-2026-58704 8.8 0.11% 34 0 2026-09-17T04:17:54.930000 In Cellular Modem, there is a possible permission bypass due to a logic error in
CVE-2026-20331 9.6 0.00% 2 0 2026-09-17T04:17:41.327000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-92838 7.8 0.00% 2 0 2026-09-17T02:16:28.610000 A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop ap
CVE-2026-92578 8.1 0.00% 2 0 2026-09-17T00:31:30 WWBN AVideo through 29.0 contains an authentication bypass vulnerability where t
CVE-2026-92576 8.6 0.00% 2 0 2026-09-17T00:31:25 HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability
CVE-2026-20341 9.1 0.00% 2 0 2026-09-16T21:32:50 A vulnerability in the sftunnel inter-device communication protocol of Cisco Sec
CVE-2026-20176 9.1 0.00% 2 0 2026-09-16T21:32:50 A vulnerability in Cisco ISE could allow an authenticated, remote attacker to ex
CVE-2026-20211 9.1 0.00% 2 0 2026-09-16T21:32:50 A vulnerability in Cisco ISE could allow an authenticated, remote attacker to ex
CVE-2026-87976 None 0.00% 2 0 2026-09-16T21:32:48 Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when
CVE-2026-87024 7.2 0.00% 2 0 2026-09-16T21:32:47 Tanium addressed a SQL injection vulnerability in Asset.
CVE-2026-70469 None 0.00% 2 0 2026-09-16T21:32:46 Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the appli
CVE-2026-79994 0 0.11% 2 0 2026-09-16T20:38:33.883000 The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a
CVE-2026-70416 10.0 0.00% 2 0 2026-09-16T20:37:16.870000 Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untru
CVE-2026-92176 7.8 0.17% 2 0 2026-09-16T20:26:50.280000 pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulne
CVE-2026-92177 7.8 0.17% 2 0 2026-09-16T20:26:50.280000 pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Executio
CVE-2026-91939 9.8 0.59% 2 0 2026-09-16T20:21:01.047000 Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() witho
CVE-2026-86865 8.8 0.00% 2 0 2026-09-16T20:17:37.153000 Tanium addressed a SQL injection vulnerability in Asset.
CVE-2026-92248 7.8 0.18% 2 0 2026-09-16T19:42:43.623000 A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail pre
CVE-2026-83099 10.0 0.36% 1 0 2026-09-16T19:42:12.090000 Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component
CVE-2026-90711 9.1 0.19% 3 0 2026-09-16T19:40:00.317000 proxy-addr is a Node.js module that determines a request's client address behind
CVE-2026-87288 8.1 0.24% 2 0 2026-09-16T19:40:00.317000 Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compil
CVE-2026-83105 9.0 0.38% 1 0 2026-09-16T19:36:43.087000 Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component
CVE-2026-77853 8.8 1.03% 1 0 2026-09-16T19:27:25.623000 Improper neutralization of special elements used in an OS command ('OS Command I
CVE-2026-73807 9.8 0.65% 4 0 2026-09-16T19:17:32.787000 The mySCADA myPRO Manager command API does not properly enforce authentication f
CVE-2026-53713 9.1 0.41% 1 0 2026-09-16T19:17:18.060000 Envoy Gateway is an open source project for managing Envoy Proxy as a standalone
CVE-2026-27565 9.8 0.94% 8 0 2026-09-16T19:17:14.183000 An unauthenticated remote attacker can upload a malicious IODD file that places
CVE-2026-27564 7.2 2.02% 6 0 2026-09-16T19:17:13.860000 A high-privileged remote attacker can exploit a command injection vulnerability
CVE-2026-40854 0 0.00% 2 0 2026-09-16T19:14:25.980000 WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability i
CVE-2026-20307 9.9 0.00% 2 0 2026-09-16T18:32:09 A vulnerability in the web-based management interface of Cisco ISE could allow a
CVE-2026-92397 9.1 0.00% 2 0 2026-09-16T18:32:09 A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected
CVE-2026-89775 9.3 0.18% 2 0 2026-09-16T18:31:58 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64:
CVE-2026-87287 8.1 0.24% 2 0 2026-09-16T18:31:53 Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compil
CVE-2026-82028 8.8 0.43% 1 0 2026-09-16T17:18:09.647000 Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-
CVE-2026-61595 7.7 0.00% 2 0 2026-09-16T15:32:15 ### Impact `djust.tenants` isolation was enforced only on the HTTP path. The cur
CVE-2026-73172 None 0.00% 2 0 2026-09-16T15:31:13 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele
CVE-2026-84858 8.8 0.00% 2 0 2026-09-16T15:18:00.527000 ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote
CVE-2026-91990 7.5 0.41% 1 0 2026-09-16T13:42:49.167000 Tornado before 6.5.8 contains a memory amplification vulnerability in parse_mult
CVE-2026-65838 8.2 0.27% 1 0 2026-09-16T13:42:48.383000 Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.
CVE-2026-73453 10.0 0.75% 2 0 2026-09-16T12:30:37 An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors
CVE-2026-27561 7.2 2.23% 6 0 2026-09-16T09:30:35 A high-privileged remote attacker can exploit a command injection vulnerability
CVE-2026-27563 7.2 2.02% 6 0 2026-09-16T09:30:35 A high-privileged remote attacker can exploit a command injection vulnerability
CVE-2026-27562 7.2 2.23% 6 0 2026-09-16T09:30:34 A high-privileged remote attacker can exploit a command injection vulnerability
CVE-2026-81642 None 0.52% 2 0 2026-09-16T09:30:28 In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in t
CVE-2026-12793 9.8 0.39% 3 3 2026-09-16T06:31:34 The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnera
CVE-2026-14349 9.8 0.42% 2 0 2026-09-16T06:31:34 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress i
CVE-2026-83355 9.8 0.36% 1 0 2026-09-16T00:32:32 Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of
CVE-2026-83339 9.8 0.48% 1 0 2026-09-16T00:32:27 Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusio
CVE-2026-83095 9.8 0.48% 1 0 2026-09-16T00:32:27 Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component
CVE-2026-77179 None 0.16% 2 0 2026-09-16T00:32:25 On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows
CVE-2026-85893 8.8 0.68% 2 0 2026-09-16T00:31:42 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke
CVE-2026-15640 None 0.28% 4 0 2026-09-16T00:31:41 Under certain conditions a valid SAML IdP response may be used to impersonate an
CVE-2026-69486 8.8 0.66% 2 0 2026-09-16T00:31:41 Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthor
CVE-2026-15638 None 0.20% 2 0 2026-09-16T00:31:34 An unauthenticated user with access to Secret Server could leverage a padding or
CVE-2026-15639 None 0.39% 4 0 2026-09-16T00:31:33 An attacker can craft a malicious link that, if used by a legitimate user, may c
CVE-2026-87289 7.5 0.46% 2 0 2026-09-16T00:31:27 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: hel
CVE-2026-83098 9.8 0.36% 1 0 2026-09-16T00:31:25 Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component
CVE-2026-83100 9.8 0.48% 1 0 2026-09-16T00:31:25 Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component
CVE-2026-92000 7.5 0.39% 2 0 2026-09-15T21:33:15 adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output li
CVE-2026-68070 8.8 0.27% 2 0 2026-09-15T21:33:13 The affected products are missing authentication for a critical function, which
CVE-2026-66890 9.6 0.20% 2 0 2026-09-15T21:33:13 The affected products use hard-coded credentials, which could allow remote acces
CVE-2026-87286 8.1 0.24% 2 0 2026-09-15T21:33:13 Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compil
CVE-2026-83149 9.1 0.26% 1 0 2026-09-15T21:32:16 Vulnerability in Oracle Application Testing Suite. The supported version that
CVE-2026-83103 9.1 0.47% 1 0 2026-09-15T21:32:14 Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component
CVE-2026-83107 9.1 0.47% 1 0 2026-09-15T21:32:07 Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component
CVE-2026-76670 9.9 0.45% 2 0 2026-09-15T21:31:34 Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConn
CVE-2026-92179 7.8 0.17% 2 0 2026-09-15T21:31:29 pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Executio
CVE-2026-92178 7.8 0.17% 2 0 2026-09-15T21:31:28 pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution
CVE-2026-92180 7.8 0.14% 2 0 2026-09-15T21:31:25 pdfforge PDF Architect activation-service Update Service Uncontrolled Search Pat
CVE-2026-89040 9.8 0.93% 2 0 2026-09-15T20:19:20.240000 Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated a
CVE-2026-88975 7.5 0.62% 2 0 2026-09-15T20:01:24 ### Summary An unauthenticated peer can make Ember's HTTP/2 read loop hold 16 Mi
CVE-2026-69213 7.5 0.36% 2 0 2026-09-15T20:00:36 Ember's HTTP/2 connection serializes all outgoing frames through a single unboun
CVE-2026-90847 9.1 2.18% 1 0 2026-09-15T19:17:46.767000 A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element i
CVE-2026-57586 8.6 0.15% 1 0 2026-09-15T19:17:31.030000 CodeRAG is a lightweight semantic code search and distillation utility for AI co
CVE-2026-20274 9.8 0.73% 1 0 2026-09-15T18:33:13 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-91985 7.5 0.38% 1 0 2026-09-15T18:32:43 Vikunja before 2.6.0 fails to properly restrict access to the link-share hash fi
CVE-2026-91989 7.5 1.26% 1 0 2026-09-15T18:32:42 atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the
CVE-2026-76441 9.8 0.49% 1 0 2026-09-15T18:32:19 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20353 9.8 0.40% 1 0 2026-09-15T18:32:19 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20276 8.6 0.27% 1 0 2026-09-15T18:32:13 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-76440 9.8 0.45% 1 0 2026-09-15T18:19:12.950000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20275 8.8 0.19% 1 0 2026-09-15T18:17:18.413000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-89026 9.8 0.52% 7 1 2026-09-15T17:17:33.510000 The Issabel Framework, the web framework supporting Issabel PBX software, before
CVE-2026-39919 9.8 0.49% 2 0 2026-09-15T15:32:20 Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability i
CVE-2026-90439 6.5 0.26% 1 0 2026-09-15T15:32:20 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module
CVE-2026-63696 9.1 0.32% 1 0 2026-09-15T15:32:20 Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download
CVE-2026-63695 9.8 0.53% 1 0 2026-09-15T15:32:20 Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session F
CVE-2026-89025 7.5 0.42% 1 0 2026-09-15T15:17:26.720000 Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerabilit
CVE-2026-75983 7.5 0.41% 1 0 2026-09-15T15:17:21.443000 The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugi
CVE-2026-45051 0 0.51% 1 0 2026-09-15T14:16:54.240000 Open Access Management (OpenAM) is an access management solution. Prior to 16.1.
CVE-2026-76461 9.8 2.01% 31 3 2026-09-15T12:47:32.497000 A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure
CVE-2026-91995 9.1 0.61% 1 0 2026-09-15T12:31:54 pig before 4.1.0 contains an authentication bypass vulnerability in the /registe
CVE-2026-89308 None 2.97% 1 0 2026-09-15T12:31:54 An unauthenticated OS command injection vulnerability exists in the ping.php end
CVE-2026-80217 8.8 0.28% 1 0 2026-09-15T09:30:39 Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allo
CVE-2026-91003 9.1 0.51% 2 0 2026-09-15T06:30:40 A flaw has been found in D-Link DI-8300 16.07. The affected element is the funct
CVE-2026-91001 9.9 0.48% 2 0 2026-09-15T06:30:39 A security flaw has been discovered in D-Link DI-8400 16.07. This affects the fu
CVE-2026-91771 8.8 0.73% 1 0 2026-09-15T03:30:30 Weights & Biases wandb before 0.29.0 fails to validate the file name from server
CVE-2026-91200 8.8 0.42% 1 0 2026-09-15T00:31:22 DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry n
CVE-2026-12944 9.6 0.25% 4 2 2026-09-15T00:31:21 IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary P
CVE-2026-91144 7.5 0.37% 1 0 2026-09-15T00:31:21 ZFile through 5.0.5 fails to validate requested file paths against a share link'
CVE-2026-65352 4.3 0.25% 1 0 2026-09-15T00:31:13 An information disclosure issue was addressed with improved state management. Th
CVE-2026-82232 9.8 0.56% 2 0 2026-09-14T21:32:45 Improper neutralization of special elements used in an SQL command ('SQL injecti
CVE-2026-89023 8.6 0.23% 1 0 2026-09-14T21:31:42 ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missin
CVE-2026-78330 9.8 0.60% 1 0 2026-09-14T20:58:48.430000 Incorrect privilege assignment vulnerability in Apache Syncope. When the config
CVE-2026-91079 8.5 0.35% 1 0 2026-09-14T20:17:03.600000 Huly Platform through 0.7.426 contains a server-side request forgery vulnerabili
CVE-2026-90946 7.5 0.57% 1 0 2026-09-14T19:18:13.990000 DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerabili
CVE-2026-59178 9.8 0.42% 1 0 2026-09-14T19:17:37.617000 ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management
CVE-2026-91080 7.5 0.59% 1 0 2026-09-14T18:31:35 webhook through 2.8.3 reads the entire request body into memory before evaluatin
CVE-2026-85921 8.2 0.26% 1 0 2026-09-14T18:31:29 Double free in Windows Secure Kernel Mode allows an authorized attacker to eleva
CVE-2026-90945 9.8 0.53% 2 0 2026-09-14T18:31:28 Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing
CVE-2026-89471 8.4 0.14% 1 0 2026-09-14T15:33:32 In the Linux kernel, the following vulnerability has been resolved: power: supp
CVE-2026-81008 7.8 0.16% 1 0 2026-09-14T15:33:29 In the Linux kernel, the following vulnerability has been resolved: interconnec
CVE-2026-81011 7.1 0.12% 1 0 2026-09-14T15:33:28 In the Linux kernel, the following vulnerability has been resolved: platform/x8
CVE-2026-80973 None 0.21% 1 0 2026-09-14T15:33:27 In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire
CVE-2026-89495 9.8 0.70% 1 0 2026-09-14T15:32:27 In the Linux kernel, the following vulnerability has been resolved: ocfs2: boun
CVE-2026-89489 7.8 0.14% 1 0 2026-09-14T15:32:27 In the Linux kernel, the following vulnerability has been resolved: openrisc: f
CVE-2026-89465 8.4 0.14% 1 0 2026-09-14T15:32:25 In the Linux kernel, the following vulnerability has been resolved: power: supp
CVE-2026-80979 7.8 0.13% 1 0 2026-09-14T15:32:22 In the Linux kernel, the following vulnerability has been resolved: net/smc: un
CVE-2026-80931 7.8 0.13% 1 0 2026-09-14T15:32:20 In the Linux kernel, the following vulnerability has been resolved: w1: ds28e17
CVE-2026-43502 7.8 0.12% 1 1 2026-09-14T15:32:07 In the Linux kernel, the following vulnerability has been resolved: net/rds: ha
CVE-2026-89475 0 0.21% 1 0 2026-09-14T13:19:03.853000 In the Linux kernel, the following vulnerability has been resolved: power: supp
CVE-2026-81000 7.8 0.16% 1 0 2026-09-14T13:18:54.210000 In the Linux kernel, the following vulnerability has been resolved: net: tun: b
CVE-2026-80989 8.8 0.34% 1 0 2026-09-14T13:18:53.647000 In the Linux kernel, the following vulnerability has been resolved: net: thunde
CVE-2026-90894 7.8 0.15% 2 0 2026-09-14T12:31:44 Parallels Desktop runs prl_disp_service as root. Local clients reach it on the w
CVE-2026-12518 None 0.11% 1 0 2026-09-14T09:31:09 A local privilege escalation vulnerability in the Logitech Logi Options+ updater
CVE-2026-89501 7.8 0.16% 1 0 2026-09-13T09:33:28 In the Linux kernel, the following vulnerability has been resolved: ring-buffer
CVE-2026-80981 9.8 0.59% 1 0 2026-09-13T09:33:25 In the Linux kernel, the following vulnerability has been resolved: net/smc: fi
CVE-2026-81006 7.8 0.13% 1 0 2026-09-13T09:33:21 In the Linux kernel, the following vulnerability has been resolved: ipmi: Remov
CVE-2026-80995 7.8 0.12% 1 0 2026-09-13T07:17:06.230000 In the Linux kernel, the following vulnerability has been resolved: net: mctp:
CVE-2026-80955 7.8 0.16% 1 0 2026-09-13T07:17:02.700000 In the Linux kernel, the following vulnerability has been resolved: dm-pcache:
CVE-2026-80945 9.1 0.47% 1 0 2026-09-13T07:17:01.827000 In the Linux kernel, the following vulnerability has been resolved: crypto: iaa
CVE-2026-80943 7.6 0.25% 1 0 2026-09-13T07:17:01.543000 In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwi
CVE-2026-80936 7.8 0.13% 1 0 2026-09-13T07:17:01.293000 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:
CVE-2026-85706 10.0 11.96% 12 12 2026-09-12T12:30:50 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7
CVE-2026-78159 9.8 0.76% 2 0 2026-09-12T09:33:41 The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execut
CVE-2026-78006 9.8 0.78% 2 2 2026-09-12T09:33:41 The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execut
CVE-2026-89506 None 0.17% 1 0 2026-09-11T21:31:37 In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs
CVE-2026-89462 None 0.17% 1 0 2026-09-11T21:31:32 In the Linux kernel, the following vulnerability has been resolved: power: supp
CVE-2026-80960 None 0.20% 1 0 2026-09-11T21:31:26 In the Linux kernel, the following vulnerability has been resolved: dm-pcache:
CVE-2026-84869 9.9 0.69% 5 0 2026-09-11T21:31:17 A condition in the ScreenConnect client may allow files to be transferred and ex
CVE-2026-42016 8.1 0.89% 3 0 2026-09-11T21:31:06 JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a pri
CVE-2026-59971 10.0 0.39% 1 0 2026-09-11T20:36:20 ## Summary In SSE/HTTP transport mode, `mysql_mcp_server` constructs `SseServer
CVE-2026-89514 0 0.17% 2 0 2026-09-11T20:19:33.913000 In the Linux kernel, the following vulnerability has been resolved: scsi: fnic:
CVE-2026-89446 0 0.20% 1 0 2026-09-11T20:19:25.110000 In the Linux kernel, the following vulnerability has been resolved: iommufd: Re
CVE-2026-81861 0 0.38% 2 1 2026-09-11T20:19:13.263000 CWE-522: Insufficiently Protected Credentials vulnerability that could result in
CVE-2026-86060 9.8 1.06% 1 1 2026-09-11T12:52:16.507000 RouterOS contains an argument-handling flaw in the SSH login path involving user
CVE-2026-82079 8.4 0.16% 3 0 2026-09-11T03:31:25 A stack-based buffer overflow vulnerability in the Nintendo Switch local wireles
CVE-2026-59160 8.8 0.41% 2 0 2026-09-09T23:47:56 ## Unauthenticated Network-Exposed Turborepo Task Execution via /api/run ### Su
CVE-2026-20079 10.0 75.75% 2 3 2026-09-09T21:31:33 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-58113 6.1 0.22% 2 0 2026-09-09T16:17:03.483000 A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.00
CVE-2026-87827 None 1.07% 1 0 2026-09-09T12:32:22 Certain KGUARD DVR devices running vulnerable firmware expose a system command e
CVE-2026-85880 7.8 0.57% 1 0 2026-09-09T05:18:19.193000 Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elev
CVE-2026-75650 10.0 2.15% 1 5 2026-09-09T05:18:07.237000 Adobe Commerce is affected by an Improper Neutralization of Special Elements Use
CVE-2026-58240 9.8 0.34% 1 0 2026-09-09T05:17:26.417000 SAP NetWeaver Message Server does not sufficiently validate the authenticity of
CVE-2026-15534 5.7 0.17% 2 0 2026-09-08T22:17:38.113000 Perl versions through 5.45.1 have out-of-bounds heap reads and writes during reg
CVE-2026-81963 7.8 0.63% 1 0 2026-09-08T21:34:09 Improper link resolution before file access ('link following') in Windows Update
CVE-2026-60004 9.8 86.78% 2 10 2026-09-08T17:56:31 ### Summary Gitea's `diffpatch` endpoint can be abused to install and execute a
CVE-2026-48888 7.5 0.26% 1 0 2026-09-08T13:12:58.310000 Allocation of Resources Without Limits or Throttling vulnerability in Automattic
CVE-2026-15315 8.8 0.30% 4 1 2026-09-04T18:32:18 Tapo C200 v5 contains an improper authentication vulnerability within the login
CVE-2026-80863 None 0.18% 1 0 2026-09-04T18:31:40 In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: F
CVE-2026-15316 6.5 0.23% 4 1 2026-09-04T18:31:13 An improper input validation vulnerability in the configuration service for proc
CVE-2026-80881 0 0.17% 1 0 2026-09-04T17:17:00.390000 In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix
CVE-2026-81572 7.8 0.17% 1 0 2026-09-01T20:56:59.203000 In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excludi
CVE-2026-81576 7.7 0.33% 1 0 2026-09-01T20:56:59.203000 If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issu
CVE-2026-56210 7.1 0.31% 2 0 2026-09-01T13:19:50.477000 A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1
CVE-2026-39113 4.0 0.21% 2 1 2026-08-31T18:31:16 Buffer Overflow vulnerability in SQLite affected version source snapshots/builds
CVE-2026-56211 7.1 0.48% 2 0 2026-08-31T15:34:31 A remote code execution vulnerability was found in libaom, the reference AV1 cod
CVE-2026-56208 7.6 0.42% 2 0 2026-08-31T15:34:31 A heap buffer overflow vulnerability was found in libaom, the reference AV1 code
CVE-2026-56209 7.1 0.35% 2 0 2026-08-31T15:34:31 An arbitrary address write vulnerability was found in libaom, the reference AV1
CVE-2026-81574 8.2 0.41% 1 0 2026-08-27T12:30:27 In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitiz
CVE-2026-81573 8.6 0.46% 1 0 2026-08-27T12:30:27 If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configu
CVE-2026-81575 7.5 0.44% 1 0 2026-08-27T12:30:26 If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 acce
CVE-2026-56368 3.7 0.26% 1 0 2026-08-26T20:48:48 A memory leak vulnerability exists in multiple coders that write raw pixel data
CVE-2026-59310 9.8 45.88% 2 2 2026-08-18T18:32:52 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-19487 5.3 0.42% 2 0 2026-08-13T21:37:11 Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression matc
CVE-2026-62721 7.8 0.41% 1 0 2026-08-11T18:31:23 Insufficient granularity of access control in User-Mode Power Service (UMPS) all
CVE-2026-5430 10.0 0.32% 6 1 2026-08-10T12:35:29.103000 The JWT authentication mechanism accepts tokens signed with algorithms other tha
CVE-2026-15830 5.3 1.26% 2 0 2026-08-04T18:31:31 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDja
CVE-2026-62946 5.1 0.09% 1 0 2026-08-03T16:19:22.763000 ImageMagick is free and open-source software used for editing and manipulating d
CVE-2026-45659 8.8 76.08% 2 2 2026-07-23T11:10:00.120000 Deserialization of untrusted data in Microsoft Office SharePoint allows an autho
CVE-2026-61864 2.9 0.10% 1 0 2026-07-15T12:32:06 ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transf
CVE-2026-61863 2.9 0.19% 1 0 2026-07-15T12:32:05 ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in
CVE-2026-61866 2.9 0.19% 1 0 2026-07-15T12:32:05 ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG enco
CVE-2026-61865 2.9 0.10% 1 0 2026-07-15T12:32:05 ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough li
CVE-2026-61465 3.3 0.17% 1 0 2026-07-14T15:17:09.260000 ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed mem
CVE-2026-56366 3.3 0.17% 1 0 2026-07-14T02:16:56.757000 ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META rea
CVE-2026-61870 2.9 0.19% 1 0 2026-07-13T22:07:31.147000 ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF enc
CVE-2026-56373 3.7 0.23% 1 0 2026-07-13T15:15:51.143000 ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB d
CVE-2026-61857 3.7 0.27% 1 0 2026-07-11T15:30:30 ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused
CVE-2026-55945 4.2 0.19% 1 0 2026-07-03T21:31:47 Concurrent execution using shared resource with improper synchronization ('race
CVE-2026-56371 5.3 0.26% 1 0 2026-07-02T15:17:07.390000 ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c
CVE-2026-56379 None 0.88% 1 0 2026-06-30T03:38:15 ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerabi
CVE-2026-47203 None 0.45% 2 0 2026-06-26T21:32:44 ### Impact **CVSSv4 Baseline Score:** Moderate 6.3 **CVSSv4 Weighted Score:**
CVE-2026-56378 3.7 0.22% 1 0 2026-06-26T13:41:36.727000 ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bo
CVE-2026-56370 3.3 0.12% 1 0 2026-06-24T13:10:05 When the `connected-components:*` define specifies an invalid index and out of b
CVE-2026-32746 9.8 23.67% 6 8 2026-06-17T10:36:18.783000 telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMO
CVE-2026-27540 9.0 2.32% 5 1 2026-06-17T10:27:18.693000 Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co P
CVE-2026-0628 8.8 6.63% 1 2 2026-06-17T10:11:06.543000 Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7
CVE-2025-30208 5.3 74.97% 1 23 2026-06-17T09:08:21.517000 Vite, a provider of frontend development tooling, has a vulnerability in version
CVE-2024-3400 10.0 100.00% 1 45 2026-06-17T07:44:11.533000 A command injection as a result of arbitrary file creation vulnerability in the
CVE-2025-48595 8.4 1.71% 2 3 2026-06-02T21:30:39 In multiple locations, there is a possible way to achieve code execution due to
CVE-2026-39987 9.8 98.95% 1 25 2026-04-27T16:30:09 ## Summary Marimo (19.6k stars) has a Pre-Auth RCE vulnerability. The terminal
CVE-2026-39364 None 2.00% 3 0 2026-04-07T22:16:19 ### Summary The contents of files that are specified by [`server.fs.deny`](http
CVE-2025-31125 5.3 58.46% 1 7 2026-01-22T21:47:41 ### Summary The contents of arbitrary files can be returned to the browser. ##
CVE-2023-38198 9.8 1.08% 2 0 2024-10-30T21:30:36 acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as e
CVE-2024-20260 8.6 0.62% 2 0 2024-10-23T18:33:16 A vulnerability in the VPN and management web servers of the Cisco Adaptive Secu
CVE-2024-45811 5.3 1.06% 1 0 2024-09-19T18:34:34 ### Summary The contents of arbitrary files can be returned to the browser. ###
CVE-2024-3094 10.0 85.97% 2 90 2024-03-29T18:30:50 Malicious code was discovered in the upstream tarballs of xz, starting with vers
CVE-2026-87886 0 0.00% 9 0 N/A
CVE-2026-61642 0 0.00% 2 0 N/A
CVE-2026-85498 0 0.00% 2 0 N/A
CVE-2026-88065 0 0.37% 2 0 N/A
CVE-2026-63443 0 0.42% 2 0 N/A
CVE-2026-73496 0 0.33% 1 0 N/A

CVE-2026-87796
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T05:17:02.123000

2 posts

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution poss

offseq at 2026-09-17T06:00:25.041Z ##

CVE-2026-87796 (CRITICAL, CVSS 9.8): sh1zen Multi Uploader for Gravity Forms ≤1.1.9 lets unauthenticated attackers upload arbitrary files, risking remote code execution. No patch yet — disable the plugin or restrict uploads. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-17T06:00:25.000Z ##

CVE-2026-87796 (CRITICAL, CVSS 9.8): sh1zen Multi Uploader for Gravity Forms ≤1.1.9 lets unauthenticated attackers upload arbitrary files, risking remote code execution. No patch yet — disable the plugin or restrict uploads. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE #RCE

##

CVE-2026-91843
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T04:18:10.730000

7 posts

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

undercodenews@mastodon.social at 2026-09-17T05:55:54.000Z ##

Critical Check Point Security Flaw Exposes Management Servers to Root-Level Remote Code Execution + Video

A Dangerous Vulnerability in the Security Control Plane A newly disclosed vulnerability in Check Point management infrastructure has created an urgent patching situation for organizations relying on the company’s security platforms. Tracked as CVE-2026-91843, the flaw is rated CVSS 9.8, Critical, and could allow an unauthenticated remote attacker to execute…

undercodenews.com/critical-che

##

censys at 2026-09-16T22:29:53.521Z ##

🚨New Censys Advisory: CVE-2026-91843

A critical (CVSS 9.8) unauthenticated RCE affects Check Point Quantum Security Management and Log Servers.

Censys observes 3,836 hosts globally exposing the management/log server role. This is total product presence, not a confirmed-vulnerable count.

No public PoC or confirmed exploitation has been reported as of publication. Check Point has released patches for supported versions via LivePatch.

Read the analysis and remediation details: censys.com/advisory/cve-2026-9

##

daniel1820815 at 2026-09-16T19:23:20.951Z ##

🚨 Please read this important update from Check Point:

CVE-2026-91843 - Stack overflow in login process to the Security Management and Log Servers

support.checkpoint.com/results

##

DailyCyberSecurity at 2026-09-16T16:08:43.666Z ##

Check Point fixed a critical Check Point login flaw (CVE-2026-91843). Patch this Check Point login flaw now to block unauthenticated remote root takeovers.

securityonline.info/check-poin

##

censys@infosec.exchange at 2026-09-16T22:29:53.000Z ##

🚨New Censys Advisory: CVE-2026-91843

A critical (CVSS 9.8) unauthenticated RCE affects Check Point Quantum Security Management and Log Servers.

Censys observes 3,836 hosts globally exposing the management/log server role. This is total product presence, not a confirmed-vulnerable count.

No public PoC or confirmed exploitation has been reported as of publication. Check Point has released patches for supported versions via LivePatch.

Read the analysis and remediation details: censys.com/advisory/cve-2026-9

#Cybersecurity #CVE #Vulnerability #CensysARC

##

daniel1820815@infosec.exchange at 2026-09-16T19:23:20.000Z ##

🚨 Please read this important update from Check Point:

CVE-2026-91843 - Stack overflow in login process to the Security Management and Log Servers

support.checkpoint.com/results

#CheckPoint #CheckPointsoftwareTechnologies #CVE #CVE202691843

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T16:08:43.000Z ##

Check Point fixed a critical Check Point login flaw (CVE-2026-91843). Patch this Check Point login flaw now to block unauthenticated remote root takeovers.

#CheckPoint #Cybersecurity #CVE202691843 #InfoSec #Vulnerability

securityonline.info/check-poin

##

CVE-2026-76460
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T04:18:01.527000

10 posts

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized ac

offseq at 2026-09-17T07:30:37.396Z ##

CRITICAL auth bypass (CVE-2026-76460) in Cisco ISE & ISE-PIC is being actively exploited. Remote attackers gain root on management interface via crafted API calls. Patch ASAP — no workarounds except ACLs. Details: radar.offseq.com/threat/active

##

undercodenews@mastodon.social at 2026-09-17T07:08:04.000Z ##

Cisco’s Critical ISE Zero-Day Is Being Exploited: CVE-2026-76460 Gives Remote Attackers a Path to Root Access + Video

A New Cisco Emergency for Security Teams A serious new vulnerability in Cisco Identity Services Engine has moved rapidly from disclosure to active exploitation, creating an immediate security concern for organizations that rely on ISE to control identity, authentication, and network access. Cisco has assigned the flaw CVE-2026-76460, giving it the…

undercodenews.com/ciscos-criti

##

cyberworldops at 2026-09-17T07:00:01.220Z ##

Cisco confirmed active exploitation of CVE-2026-76460, an authentication bypass in an ISE API endpoint. Unauthenticated remote access can lead to root compromise of ISE and ISE-PIC, now listed in CISA KEV. Patching and log review are urgent.

cyberworldops.eu/en/cisco-ise-

##

571906@ap.podcastindex.org at 2026-09-17T02:00:03.000Z ##

New Episode: SANS Stormcast Thursday, September 17th, 2026: Hospitality Scans; Cisco, Acronis, and Pixel 0-Day; Dynamic Incident Response

Shownotes:

Scans Targeting Hospitality Applications
https://isc.sans.edu/diary/Scans%20Targeting%20Hospitality%20Applications/33344
Cisco Identity Services Engine Authentication Bypass Vulnerability CVE-2026-76460
https://sec.cloudapps.cisco.com/

Transcript

AntennaPod | Anytime Player | Apple Podcasts | Castamatic | CurioCaster | Fountain | gPodder | Overcast | Pocket Casts | Podcast Addict | Podcast Guru | Podnews | Podverse | Truefans

Or Listen right here.

##

cR0w at 2026-09-16T17:54:16.579Z ##

Patch your Cisco ISE. CVE-2026-76460 a perfect 10 and is EITW. 🥳

sec.cloudapps.cisco.com/securi

The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.

##

DailyCyberSecurity at 2026-09-16T17:27:21.718Z ##

An exploited Cisco ISE vulnerability (CVE-2026-76460) allows remote root access. Patch this critical Cisco ISE vulnerability to secure networks.

securityonline.info/cisco-ise-

##

offseq@infosec.exchange at 2026-09-17T07:30:37.000Z ##

CRITICAL auth bypass (CVE-2026-76460) in Cisco ISE & ISE-PIC is being actively exploited. Remote attackers gain root on management interface via crafted API calls. Patch ASAP — no workarounds except ACLs. Details: radar.offseq.com/threat/active #OffSeq #Cisco #ZeroDay

##

cyberworldops@infosec.exchange at 2026-09-17T07:00:01.000Z ##

Cisco confirmed active exploitation of CVE-2026-76460, an authentication bypass in an ISE API endpoint. Unauthenticated remote access can lead to root compromise of ISE and ISE-PIC, now listed in CISA KEV. Patching and log review are urgent. #CiscoIse #AuthBypass #CisaKev

cyberworldops.eu/en/cisco-ise-

##

cR0w@infosec.exchange at 2026-09-16T17:54:16.000Z ##

Patch your Cisco ISE. CVE-2026-76460 a perfect 10 and is EITW. 🥳

sec.cloudapps.cisco.com/securi

The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T17:27:21.000Z ##

An exploited Cisco ISE vulnerability (CVE-2026-76460) allows remote root access. Patch this critical Cisco ISE vulnerability to secure networks.

#Cisco #CiscoISE #CVE202676460 #Cybersecurity #InfoSec

securityonline.info/cisco-ise-

##

CVE-2026-58704
(8.8 HIGH)

EPSS: 0.11%

updated 2026-09-17T04:17:54.930000

34 posts

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

ottoto2017@prattohome.com at 2026-09-17T04:56:11.000Z ##

「Google Pixel端末がゼロクリック攻撃でハッキングされる
/CISAは連邦政府機関に対し、パッチ適用にわずか3日間しか猶予を与えていない。 」: #TheRegister

「Googleと米国政府は、Pixelスマートフォンの携帯モデムに存在するゼロデイ脆弱性を悪用した攻撃者が、権限チェックを回避し、ユーザーの操作なしに権限を昇格できると警告した。この脆弱性は、アップデートを行うことで既に修正されている。

Googleは 火曜日に、 CVE-2026-58704 として追跡されているこの重大な脆弱性 を公表し 、その際、このセキュリティホールが「限定的かつ標的を絞った悪用を受けている可能性がある」と警告した。つまり、Googleが問題を修正する前に、悪意のある人物がこのバグを発見し、悪用していたということだ。」

theregister.com/security/2026/

#prattohome

##

ottoto2017@prattohome.com at 2026-09-17T04:40:19.000Z ##

「Google、限定的な標的型攻撃の兆候が見られる中、Pixelモデムの脆弱性を修正 」: #TheHackerNews

「Googleは、 明らかにした。 同社のPixel Cellular Modemに存在する深刻なセキュリティ上の欠陥が、実際に悪用されていることを

(CVSSスコア:8.0)として追跡されているこの脆弱性は CVE-2026-58704 、権限昇格の欠陥です。

によると、「セルラーモデムには、コードの論理エラーにより権限がバイパスされる可能性がある」とのことです NIST(米国国立標準技術研究所)の国家脆弱性データベース(NVD)に掲載されているバグの説明 。「これにより、追加の実行権限を必要とせずに、リモート(近接/隣接)での権限昇格が可能になる可能性がある。悪用にはユーザーの操作は不要である。」 」

thehackernews.com/2026/09/goog

#prattohome

##

DailyCyberSecurity at 2026-09-17T04:07:33.110Z ##

Google confirmed a Pixel modem zero-day (CVE-2026-58704) exploited in a zero-click spyware attack to escape the modem sandbox. Update now.

securityexpress.info/pixel-mod

##

thecybermind at 2026-09-16T21:31:34.521Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-58704 – Google Pixel Improper Authorization Vulnerability

A strategic executive briefing detailing governance, risk mitigation, and compliance frameworks for CVE-2026-58704 on Google Pixel mobile devices....

thecybermind.co/h86g

##

simonzerafa at 2026-09-16T21:27:45.635Z ##

Google and CISA warned that an actively exploited zero-day vulnerability (CVE-2026-58704) affecting Pixel cellular modems.

This allows attackers to silently bypass permission checks and escalate privileges with no user interaction!

It was quickly added to CISA's Known Exploited Vulnerabilities (KEV) catalog [1.2.1, 1.5.1].

Would be an excellent idea for Pixel owners to ownload and apply the September Android OS patches ASAP!

##

thecybermind at 2026-09-16T20:58:59.950Z ##

(CISA TS-MAN) The Cyber Mind TSUITE Brief: CVE-2026-58704 – Google Pixel Improper Authorization Vulnerability

Actionable threat intelligence and end-to-end hardening strategies for CVE-2026-58704, addressing improper authorization flaws in Google Pixel cellular modems....

thecybermind.co/iuw6

##

sayzard@mastodon.sayzard.org at 2026-09-16T20:39:04.000Z ##

Google confirms Pixel phones exploited in 'targeted' modem based attack

Google은 2026년 9월 보안 업데이트에서 Pixel 기기에 영향을 주는 셀룰러 모뎀 취약점 CVE-2026-58704를 수정했으며, 해당 취약점이 제한적·표적형 공격에 실제 악용됐다고 밝혔다. 이 논리 오류 기반 권한 우회는 사용자 상호작용 없이 인접 네트워크 범위에서 권한 상승을 유발할 수 있어, 제로클릭 공격 경로로 분류된다. CISA도 이를 알려진 악용 취약점(KEV)으로 등록했으며, Pixel 사용자는 즉시 9월 보안 패치를 적용해야 한다. AI 특화 이슈는 아니지만 개발자와 조직의 모바일 단말 보...

9to5google.com/2026/09/16/goog

##

cyberworldops at 2026-09-16T16:50:00.509Z ##

Google patched CVE-2026-58704, a high-severity Pixel Cellular Modem privilege-escalation flaw reportedly exploited in limited, targeted attacks. Its addition to CISA’s KEV Catalog underscores the need to prioritize affected device updates.

cyberworldops.eu/en/google-pat

##

AAKL at 2026-09-16T16:26:50.695Z ##

New.

Press release: New CISA Guidance Helps Critical Infrastructure Detect, Observe and Impede Malicious Cyber Activity cisa.gov/news-events/news/new-

The guide: Using Cyber Decoys to Strengthen Detection and Response cisa.gov/resources-tools/resou

CISA has also added one vulnerability to the catalogue.

CVE-2026-58704: Google Pixel Improper Authorization Vulnerability cve.org/CVERecord?id=CVE-2026-

##

security_crawler_carl at 2026-09-16T16:14:16.832Z ##

🏆 New Achievement! Tutorial: Learning to Live With Being Actively Exploited!

Welcome to the Mandatory Pixel Debuff Sequence. Before you proceed, please note that CVE-2026-58704 has been equipped to your device without your consent. This is a zero-day — that means the tutorial boss was already in your pocket before the level loaded. (1/3)

##

netsecio@mastodon.social at 2026-09-16T16:02:54.000Z ##

📰 Google Patches Actively Exploited Zero-Day Flaw in Pixel Modems

Google patches high-severity zero-day (CVE-2026-58704) in Pixel modems. The flaw allows for remote privilege escalation and is under limited, targeted exploitation. CISA added to KEV. Update your Pixel now! #Pixel #Android #ZeroDay

🔗 cyber.netsecops.io/articles/go

##

secdb at 2026-09-16T15:01:11.734Z ##

🚨 [CISA-2026:0916] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-58704 (secdb.nttzen.cloud/cve/detail/)
- Name: Google Pixel Improper Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Pixel
- Notes: source.android.com/docs/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

rogeragrimes at 2026-09-16T14:56:00.885Z ##

If you've got a Google Pixel cell phone, do a system patch immediately. There is an active vulnerability that allows the hacker to take control of your device with no user interaction. It is being actively used in the wild.

cve.org/CVERecord?id=CVE-2026-

##

tugatech@masto.pt at 2026-09-16T14:31:09.000Z ##

Google corrige falha zero-day em telemóveis Pixel com atualização que resolve 110 vulnerabilidades. A falha, identificada como CVE-2026-58704, está a ser explorada em ataques direcionados de alcance limitado. 📱

🔗 tugatech.com.pt/t91149-google-

#falha #google #pixel 

##

cisakevtracker@mastodon.social at 2026-09-16T14:01:08.000Z ##

CVE ID: CVE-2026-58704
Vendor: Google
Product: Pixel
Date Added: 2026-09-16
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

GrapheneOS@grapheneos.social at 2026-09-16T12:36:14.000Z ##

@skyblitz CVE-2026-58704 is a modem firmware vulnerability with a patch released today and it will be included in our upcoming release.

##

Analyst207@mastodon.social at 2026-09-16T12:03:22.000Z ##

Google Discloses Pixel Modem Flaw Under Limited Targeted Exploitation

Google just sounded the alarm on a high-severity bug in Pixel devices that's being exploited in targeted attacks, and they're urging users to take action. The vulnerability, tracked as CVE-2026-58704, affects the Pixel Cellular Modem and could allow attackers to escalate privileges.

osintsights.com/google-disclos

#PixelModemFlaw #Cve202658704 #AndroidSecurity #EmergingThreats #Google

##

skyblitz@ieji.de at 2026-09-16T12:00:11.000Z ##

@GrapheneOS funny to see google fixing : CVE-2025-48595 that was fixed looooooong ago in your.

i don't see CVE-2026-58704, is it already fixed ?

bleepingcomputer.com/news/secu

##

Analyst207@mastodon.social at 2026-09-16T07:03:07.000Z ##

Google Fixes Exploited Android Zero-Day Flaw on Pixel Devices

Google just patched a high-severity zero-day flaw in its Pixel smartphones, warning that hackers may be using it to launch targeted attacks. The vulnerability, tracked as CVE-2026-58704, allows for a permission bypass in the device's modem, posing a significant risk to users.

osintsights.com/google-fixes-e

#AndroidZeroDay #Cve202658704 #GooglePixel #EmergingThreats #MobileSecurity

##

ottoto2017@prattohome.com at 2026-09-17T04:56:11.000Z ##

「Google Pixel端末がゼロクリック攻撃でハッキングされる
/CISAは連邦政府機関に対し、パッチ適用にわずか3日間しか猶予を与えていない。 」: #TheRegister

「Googleと米国政府は、Pixelスマートフォンの携帯モデムに存在するゼロデイ脆弱性を悪用した攻撃者が、権限チェックを回避し、ユーザーの操作なしに権限を昇格できると警告した。この脆弱性は、アップデートを行うことで既に修正されている。

Googleは 火曜日に、 CVE-2026-58704 として追跡されているこの重大な脆弱性 を公表し 、その際、このセキュリティホールが「限定的かつ標的を絞った悪用を受けている可能性がある」と警告した。つまり、Googleが問題を修正する前に、悪意のある人物がこのバグを発見し、悪用していたということだ。」

theregister.com/security/2026/

#prattohome

##

ottoto2017@prattohome.com at 2026-09-17T04:40:19.000Z ##

「Google、限定的な標的型攻撃の兆候が見られる中、Pixelモデムの脆弱性を修正 」: #TheHackerNews

「Googleは、 明らかにした。 同社のPixel Cellular Modemに存在する深刻なセキュリティ上の欠陥が、実際に悪用されていることを

(CVSSスコア:8.0)として追跡されているこの脆弱性は CVE-2026-58704 、権限昇格の欠陥です。

によると、「セルラーモデムには、コードの論理エラーにより権限がバイパスされる可能性がある」とのことです NIST(米国国立標準技術研究所)の国家脆弱性データベース(NVD)に掲載されているバグの説明 。「これにより、追加の実行権限を必要とせずに、リモート(近接/隣接)での権限昇格が可能になる可能性がある。悪用にはユーザーの操作は不要である。」 」

thehackernews.com/2026/09/goog

#prattohome

##

DailyCyberSecurity@infosec.exchange at 2026-09-17T04:07:33.000Z ##

Google confirmed a Pixel modem zero-day (CVE-2026-58704) exploited in a zero-click spyware attack to escape the modem sandbox. Update now.

#Pixel #ZeroDay #CVE202658704 #Google #Spyware #ZeroClick #CyberSecurity

securityexpress.info/pixel-mod

##

thecybermind@infosec.exchange at 2026-09-16T21:31:34.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-58704 – Google Pixel Improper Authorization Vulnerability

A strategic executive briefing detailing governance, risk mitigation, and compliance frameworks for CVE-2026-58704 on Google Pixel mobile devices....

thecybermind.co/h86g

##

simonzerafa@infosec.exchange at 2026-09-16T21:27:45.000Z ##

Google and CISA warned that an actively exploited zero-day vulnerability (CVE-2026-58704) affecting Pixel cellular modems.

This allows attackers to silently bypass permission checks and escalate privileges with no user interaction!

It was quickly added to CISA's Known Exploited Vulnerabilities (KEV) catalog [1.2.1, 1.5.1].

Would be an excellent idea for Pixel owners to ownload and apply the September Android OS patches ASAP!

#Google #PixelPhone #ZeroDay #Exploit

##

thecybermind@infosec.exchange at 2026-09-16T20:58:59.000Z ##

(CISA TS-MAN) The Cyber Mind TSUITE Brief: CVE-2026-58704 – Google Pixel Improper Authorization Vulnerability

Actionable threat intelligence and end-to-end hardening strategies for CVE-2026-58704, addressing improper authorization flaws in Google Pixel cellular modems....

thecybermind.co/iuw6

##

cyberworldops@infosec.exchange at 2026-09-16T16:50:00.000Z ##

Google patched CVE-2026-58704, a high-severity Pixel Cellular Modem privilege-escalation flaw reportedly exploited in limited, targeted attacks. Its addition to CISA’s KEV Catalog underscores the need to prioritize affected device updates. #ZeroDay #MobileSecurity #ThreatIntelligence

cyberworldops.eu/en/google-pat

##

AAKL@infosec.exchange at 2026-09-16T16:26:50.000Z ##

New.

Press release: New CISA Guidance Helps Critical Infrastructure Detect, Observe and Impede Malicious Cyber Activity cisa.gov/news-events/news/new-

The guide: Using Cyber Decoys to Strengthen Detection and Response cisa.gov/resources-tools/resou

CISA has also added one vulnerability to the catalogue.

CVE-2026-58704: Google Pixel Improper Authorization Vulnerability cve.org/CVERecord?id=CVE-2026- #Google #infosec #vulnerability #CISA

##

security_crawler_carl@infosec.exchange at 2026-09-16T16:14:16.000Z ##

🏆 New Achievement! Tutorial: Learning to Live With Being Actively Exploited!

Welcome to the Mandatory Pixel Debuff Sequence. Before you proceed, please note that CVE-2026-58704 has been equipped to your device without your consent. This is a zero-day — that means the tutorial boss was already in your pocket before the level loaded. (1/3)

##

secdb@infosec.exchange at 2026-09-16T15:01:11.000Z ##

🚨 [CISA-2026:0916] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-58704 (secdb.nttzen.cloud/cve/detail/)
- Name: Google Pixel Improper Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Pixel
- Notes: source.android.com/docs/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260916 #cisa20260916 #cve_2026_58704 #cve202658704

##

rogeragrimes@infosec.exchange at 2026-09-16T14:56:00.000Z ##

If you've got a Google Pixel cell phone, do a system patch immediately. There is an active vulnerability that allows the hacker to take control of your device with no user interaction. It is being actively used in the wild.

cve.org/CVERecord?id=CVE-2026-

##

tugatech@masto.pt at 2026-09-16T14:31:09.000Z ##

Google corrige falha zero-day em telemóveis Pixel com atualização que resolve 110 vulnerabilidades. A falha, identificada como CVE-2026-58704, está a ser explorada em ataques direcionados de alcance limitado. 📱

🔗 tugatech.com.pt/t91149-google-

#falha #google #pixel 

##

cisakevtracker@mastodon.social at 2026-09-16T14:01:08.000Z ##

CVE ID: CVE-2026-58704
Vendor: Google
Product: Pixel
Date Added: 2026-09-16
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

GrapheneOS@grapheneos.social at 2026-09-16T12:36:14.000Z ##

@skyblitz CVE-2026-58704 is a modem firmware vulnerability with a patch released today and it will be included in our upcoming release.

##

skyblitz@ieji.de at 2026-09-16T12:00:11.000Z ##

@GrapheneOS funny to see google fixing : CVE-2025-48595 that was fixed looooooong ago in your.

i don't see CVE-2026-58704, is it already fixed ?

bleepingcomputer.com/news/secu

##

CVE-2026-20331
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-17T04:17:41.327000

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally disc

nyanbinary at 2026-09-16T18:08:42.419Z ##

@cR0w was just looking at those, lol. Don't sleep on this great advertisment of a CVE though: db.gcve.eu/vuln/cve-2026-20331

##

nyanbinary@infosec.exchange at 2026-09-16T18:08:42.000Z ##

@cR0w was just looking at those, lol. Don't sleep on this great advertisment of a CVE though: db.gcve.eu/vuln/cve-2026-20331

##

CVE-2026-92838
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-17T02:16:28.610000

2 posts

A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location. If successfully exploited, an attacker with local write access to the affected directory could achieve

offseq at 2026-09-17T04:30:24.676Z ##

CVE-2026-92838: HIGH severity DLL hijack in GeoVision GV-Remote E-map 18.3.1 🖥️. Local attackers can execute arbitrary code via unsafe DLL load paths. Restrict directory write access; check vendor guidance. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-17T04:30:24.000Z ##

CVE-2026-92838: HIGH severity DLL hijack in GeoVision GV-Remote E-map 18.3.1 🖥️. Local attackers can execute arbitrary code via unsafe DLL load paths. Restrict directory write access; check vendor guidance. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #InfoSec #Windows

##

CVE-2026-92578
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-17T00:31:30

2 posts

WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attackers who obtain the stored users.password hash value can authenticate as any user by submitting the hash directly to login endpoints, completely bypassing password v

offseq at 2026-09-17T00:00:35.351Z ##

CVE-2026-92578: CRITICAL auth bypass in WWBN AVideo (≤29.0) allows attackers with stolen password hashes to log in as any user — no password needed. Patch pending — restrict hash access, monitor for abuse. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-17T00:00:35.000Z ##

CVE-2026-92578: CRITICAL auth bypass in WWBN AVideo (≤29.0) allows attackers with stolen password hashes to log in as any user — no password needed. Patch pending — restrict hash access, monitor for abuse. radar.offseq.com/threat/cve-20 #OffSeq #CVE202692578 #authentication #infosec

##

CVE-2026-92576
(8.6 HIGH)

EPSS: 0.00%

updated 2026-09-17T00:31:25

2 posts

HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata endpoints, localhost services, and RFC 1918 addresses to extract IAM credentials and internal service data.

offseq at 2026-09-17T01:30:25.534Z ##

CRITICAL SSRF vuln (CVE-2026-92576) in HKUDS nanobot <0.3.0: Inadequate URL validation lets attackers access internal cloud metadata & services. Restrict WebFetchTool, monitor for suspicious requests. Patch status: unconfirmed. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-17T01:30:25.000Z ##

CRITICAL SSRF vuln (CVE-2026-92576) in HKUDS nanobot <0.3.0: Inadequate URL validation lets attackers access internal cloud metadata & services. Restrict WebFetchTool, monitor for suspicious requests. Patch status: unconfirmed. radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE202692576

##

CVE-2026-20341
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-16T21:32:50

2 posts

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated, remote attacker to obtain&nbsp;root privileges. This vulnerability is due to unsecured deserialization of untrusted data over the sftunnel management connection. An attacker could exploit this vulnerability by sending crafted sftunnel remote procedure calls (RPCs). A succ

offseq at 2026-09-17T03:00:25.202Z ##

CVE-2026-20341: CRITICAL flaw in Cisco Secure FMC Software sftunnel protocol. Admin remote attackers can gain root via insecure deserialization. Limit admin access, monitor for abuse, and check for patch updates. radar.offseq.com/threat/a-vuln

##

offseq@infosec.exchange at 2026-09-17T03:00:25.000Z ##

CVE-2026-20341: CRITICAL flaw in Cisco Secure FMC Software sftunnel protocol. Admin remote attackers can gain root via insecure deserialization. Limit admin access, monitor for abuse, and check for patch updates. radar.offseq.com/threat/a-vuln #OffSeq #Cisco #Infosec #Vulnerability

##

CVE-2026-20176
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-16T21:32:50

2 posts

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending

AAKL at 2026-09-16T17:17:37.050Z ##

New.

Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws sec.cloudapps.cisco.com/securi

This one is new, but there are others:

CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities sec.cloudapps.cisco.com/securi

Broadcom:

Broadcom has a long list of advisories addressing at least two critical vulnerabilities support.broadcom.com/web/ecx/s

Tenable:

Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities tenable.com/security/research/

And if you missed this, Microsoft posted two advisories for Edge yesterday: msrc.microsoft.com/update-guide

##

AAKL@infosec.exchange at 2026-09-16T17:17:37.000Z ##

New.

Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws sec.cloudapps.cisco.com/securi

This one is new, but there are others:

CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities sec.cloudapps.cisco.com/securi

Broadcom:

Broadcom has a long list of advisories addressing at least two critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Tenable:

Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities tenable.com/security/research/

And if you missed this, Microsoft posted two advisories for Edge yesterday: msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability

##

CVE-2026-20211
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-16T21:32:50

2 posts

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This vulnerability is due to insecure deserialization of Java objects by the affected software. An attacker could exploit this vulne

AAKL at 2026-09-16T17:17:37.050Z ##

New.

Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws sec.cloudapps.cisco.com/securi

This one is new, but there are others:

CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities sec.cloudapps.cisco.com/securi

Broadcom:

Broadcom has a long list of advisories addressing at least two critical vulnerabilities support.broadcom.com/web/ecx/s

Tenable:

Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities tenable.com/security/research/

And if you missed this, Microsoft posted two advisories for Edge yesterday: msrc.microsoft.com/update-guide

##

AAKL@infosec.exchange at 2026-09-16T17:17:37.000Z ##

New.

Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws sec.cloudapps.cisco.com/securi

This one is new, but there are others:

CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities sec.cloudapps.cisco.com/securi

Broadcom:

Broadcom has a long list of advisories addressing at least two critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Tenable:

Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities tenable.com/security/research/

And if you missed this, Microsoft posted two advisories for Edge yesterday: msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability

##

CVE-2026-87976(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-16T21:32:48

2 posts

Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components without rejected parent-directory names, and the path-containment check compared an unnormalized resolved path. An authenticat

DailyCyberSecurity at 2026-09-17T03:08:21.696Z ##

Learn about recent Apache NiFi vulnerabilities (CVE-2026-87976, CVE-2026-70469) and Apache MyFaces flaws. Apply Apache security updates to prevent DoS attacks.

securityonline.info/apache-nif

##

DailyCyberSecurity@infosec.exchange at 2026-09-17T03:08:21.000Z ##

Learn about recent Apache NiFi vulnerabilities (CVE-2026-87976, CVE-2026-70469) and Apache MyFaces flaws. Apply Apache security updates to prevent DoS attacks.

#ApacheNiFi #ApacheMyFaces #Vulnerability #CVE202687976 #Cybersecurity

securityonline.info/apache-nif

##

CVE-2026-87024
(7.2 HIGH)

EPSS: 0.00%

updated 2026-09-16T21:32:47

2 posts

Tanium addressed a SQL injection vulnerability in Asset.

CVE-2026-70469(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-16T21:32:46

2 posts

Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding. The framework enforcement filter did not check multiple instances of the Content-Encoding header and did not reject non-standard identifiers for gzip encoding, allowing a malicious client to send crafted r

DailyCyberSecurity at 2026-09-17T03:08:21.696Z ##

Learn about recent Apache NiFi vulnerabilities (CVE-2026-87976, CVE-2026-70469) and Apache MyFaces flaws. Apply Apache security updates to prevent DoS attacks.

securityonline.info/apache-nif

##

DailyCyberSecurity@infosec.exchange at 2026-09-17T03:08:21.000Z ##

Learn about recent Apache NiFi vulnerabilities (CVE-2026-87976, CVE-2026-70469) and Apache MyFaces flaws. Apply Apache security updates to prevent DoS attacks.

#ApacheNiFi #ApacheMyFaces #Vulnerability #CVE202687976 #Cybersecurity

securityonline.info/apache-nif

##

CVE-2026-79994
(0 None)

EPSS: 0.11%

updated 2026-09-16T20:38:33.883000

2 posts

The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a symlink between validation and connection, causing the host to connect to an arbitrary AF_UNIX socket outside the shared workspace. This can expose data or host-side cap

DailyCyberSecurity at 2026-09-17T02:33:27.028Z ##

Docker released an update for critical Docker Sandboxes vulnerabilities (CVE-2026-77179, CVE-2026-79994). Patch these Docker Sandboxes vulnerabilities today.

securityonline.info/docker-san

##

DailyCyberSecurity@infosec.exchange at 2026-09-17T02:33:27.000Z ##

Docker released an update for critical Docker Sandboxes vulnerabilities (CVE-2026-77179, CVE-2026-79994). Patch these Docker Sandboxes vulnerabilities today.

#Docker #DockerSandboxes #CVE202677179 #CVE202679994 #Cybersecurity

securityonline.info/docker-san

##

CVE-2026-70416
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-16T20:37:16.870000

2 posts

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

thehackerwire@mastodon.social at 2026-09-16T17:02:58.000Z ##

🔴 CVE-2026-70416 - Critical (10)

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-16T17:02:58.000Z ##

🔴 CVE-2026-70416 - Critical (10)

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92176
(7.8 HIGH)

EPSS: 0.17%

updated 2026-09-16T20:26:50.280000

2 posts

pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of App obj

thehackerwire@mastodon.social at 2026-09-15T20:02:50.000Z ##

🟠 CVE-2026-92176 - High (7.8)

pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T20:02:50.000Z ##

🟠 CVE-2026-92176 - High (7.8)

pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92177
(7.8 HIGH)

EPSS: 0.17%

updated 2026-09-16T20:26:50.280000

2 posts

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of P

thehackerwire@mastodon.social at 2026-09-15T19:59:48.000Z ##

🟠 CVE-2026-92177 - High (7.8)

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T19:59:48.000Z ##

🟠 CVE-2026-92177 - High (7.8)

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91939
(9.8 CRITICAL)

EPSS: 0.59%

updated 2026-09-16T20:21:01.047000

2 posts

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.

thehackerwire@mastodon.social at 2026-09-15T22:00:14.000Z ##

🔴 CVE-2026-91939 - Critical (9.8)

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T22:00:14.000Z ##

🔴 CVE-2026-91939 - Critical (9.8)

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86865
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-16T20:17:37.153000

2 posts

Tanium addressed a SQL injection vulnerability in Asset.

CVE-2026-92248
(7.8 HIGH)

EPSS: 0.18%

updated 2026-09-16T19:42:43.623000

2 posts

A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This leads to an undersized heap allocation, resulting in a heap-based buffer overflow when the image data is decoded. This buffer overflow corrupts adjacent hea

thehackerwire@mastodon.social at 2026-09-16T00:00:19.000Z ##

🟠 CVE-2026-92248 - High (7.8)

A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This lea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-16T00:00:19.000Z ##

🟠 CVE-2026-92248 - High (7.8)

A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This lea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83099
(10.0 CRITICAL)

EPSS: 0.36%

updated 2026-09-16T19:42:12.090000

1 posts

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional prod

infosecbot@mastodon.hofud.com at 2026-09-16T07:06:58.000Z ##

[1/4]

Most Impactful Security Incidents ( 2026‑09‑15 → today )

---

PRIORITY 1 – Critical/high‑severity flaws (CVSS 7‑10) in core software stacks :

CVE‑2026‑83339
• Oracle WebCenter Enterprise Capture – Client Bundle
• Unauthenticated remote code execution; attacker can take full control of the capture service.
• 9.8 (Critical)
• HTTP (network‑level)
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83355
• Oracle Enterprise Manager for Fusion Middleware – Metrics
• Remote code execution via unauthenticated HTTP request; full takeover of the management console.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83149
• Oracle Application Testing Suite – 13.3.0.1
• Low‑privileged attacker can execute arbitrary code over HTTP; leads to full compromise of the testing suite.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83107
• Oracle Forms – 12.2.1.19.0 / 14.1.2.0
• High‑privileged attacker can gain remote code execution via HTTP; full takeover of Forms services.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83105
• Oracle Forms – same versions
• Remote code execution (CVSS 9) via HTTP; attacker gains full control.
• 9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83103
• Oracle Forms – same versions
• Remote code execution (CVSS 9.1) via HTTP; full compromise.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83100
• Oracle Forms – same versions
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83099
• Oracle WebCenter Portal – Runtime Tools
• Remote code execution (CVSS 9.9) via HTTP; full compromise of the portal.
• 9.9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83098
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83095
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full compromise.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

#infosecnews

##

CVE-2026-90711
(9.1 CRITICAL)

EPSS: 0.19%

updated 2026-09-16T19:40:00.317000

3 posts

proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the correct ::ffff:10.0.0.0/104, is accepted without error but trusts every IPv4 address on the internet

DailyCyberSecurity at 2026-09-16T01:18:01.291Z ##

A critical proxy-addr IP spoofing flaw (CVE-2026-90711) exposes Node.js apps to access control bypasses. Patch this proxy-addr IP spoofing bug today.

securityonline.info/proxy-addr

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T01:18:01.000Z ##

A critical proxy-addr IP spoofing flaw (CVE-2026-90711) exposes Node.js apps to access control bypasses. Patch this proxy-addr IP spoofing bug today.

#ProxyAddr #NodeJS #IPspoofing #CVE202690711 #Cybersecurity

securityonline.info/proxy-addr

##

thehackerwire@mastodon.social at 2026-09-15T08:00:18.000Z ##

🔴 CVE-2026-90711 - Critical (9.1)

proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-si...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87288
(8.1 HIGH)

EPSS: 0.24%

updated 2026-09-16T19:40:00.317000

2 posts

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidenti

thehackerwire@mastodon.social at 2026-09-15T21:03:00.000Z ##

🟠 CVE-2026-87288 - High (8.1)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T21:03:00.000Z ##

🟠 CVE-2026-87288 - High (8.1)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83105
(9.0 CRITICAL)

EPSS: 0.38%

updated 2026-09-16T19:36:43.087000

1 posts

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional pr

infosecbot@mastodon.hofud.com at 2026-09-16T07:06:58.000Z ##

[1/4]

Most Impactful Security Incidents ( 2026‑09‑15 → today )

---

PRIORITY 1 – Critical/high‑severity flaws (CVSS 7‑10) in core software stacks :

CVE‑2026‑83339
• Oracle WebCenter Enterprise Capture – Client Bundle
• Unauthenticated remote code execution; attacker can take full control of the capture service.
• 9.8 (Critical)
• HTTP (network‑level)
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83355
• Oracle Enterprise Manager for Fusion Middleware – Metrics
• Remote code execution via unauthenticated HTTP request; full takeover of the management console.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83149
• Oracle Application Testing Suite – 13.3.0.1
• Low‑privileged attacker can execute arbitrary code over HTTP; leads to full compromise of the testing suite.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83107
• Oracle Forms – 12.2.1.19.0 / 14.1.2.0
• High‑privileged attacker can gain remote code execution via HTTP; full takeover of Forms services.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83105
• Oracle Forms – same versions
• Remote code execution (CVSS 9) via HTTP; attacker gains full control.
• 9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83103
• Oracle Forms – same versions
• Remote code execution (CVSS 9.1) via HTTP; full compromise.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83100
• Oracle Forms – same versions
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83099
• Oracle WebCenter Portal – Runtime Tools
• Remote code execution (CVSS 9.9) via HTTP; full compromise of the portal.
• 9.9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83098
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83095
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full compromise.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

#infosecnews

##

CVE-2026-77853
(8.8 HIGH)

EPSS: 1.03%

updated 2026-09-16T19:27:25.623000

1 posts

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.

thehackerwire@mastodon.social at 2026-09-15T10:03:52.000Z ##

🟠 CVE-2026-77853 - High (8.8)

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73807
(9.8 CRITICAL)

EPSS: 0.65%

updated 2026-09-16T19:17:32.787000

4 posts

The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.

DailyCyberSecurity at 2026-09-16T02:09:47.256Z ##

Discover the latest mySCADA myPRO Manager vulnerabilities, including CVE-2026-73807, and learn how to patch your systems to prevent remote attacks.

securityonline.info/myscada-my

##

offseq at 2026-09-16T00:00:36.792Z ##

CVE-2026-73807 | CRITICAL: mySCADA myPRO (v0 – 2.1) API flaw allows unauthenticated access to privileged functions. No patch yet — restrict API network access & monitor logs. radar.offseq.com/threat/cve-20

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T02:09:47.000Z ##

Discover the latest mySCADA myPRO Manager vulnerabilities, including CVE-2026-73807, and learn how to patch your systems to prevent remote attacks.

#mySCADA #CVE202673807 #Cybersecurity #Vulnerability

securityonline.info/myscada-my

##

offseq@infosec.exchange at 2026-09-16T00:00:36.000Z ##

CVE-2026-73807 | CRITICAL: mySCADA myPRO (v0 – 2.1) API flaw allows unauthenticated access to privileged functions. No patch yet — restrict API network access & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #ICS #SCADA #Vulnerability

##

CVE-2026-53713
(9.1 CRITICAL)

EPSS: 0.41%

updated 2026-09-16T19:17:18.060000

1 posts

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not collapse redundant separators before is_critical_path evaluates Lua submitted through EnvoyExtensionPolicy during default Strict validation. Linux resolves a double-s

thehackerwire@mastodon.social at 2026-09-14T23:01:09.000Z ##

🔴 CVE-2026-53713 - Critical (9.1)

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not collapse redu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-27565
(9.8 CRITICAL)

EPSS: 0.94%

updated 2026-09-16T19:17:14.183000

8 posts

An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.

DailyCyberSecurity at 2026-09-16T09:48:49.707Z ##

Patch critical industrial firmware vulnerabilities and authentication bypass flaws like CVE-2026-27565 in Pepperl+Fuchs, Phoenix Contact & Carlo Gavazzi.

securityonline.info/industrial

##

certvde at 2026-09-16T07:58:13.003Z ##

🔒 New CSAF advisory published

VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: gavazziautomation.csaf-tp.cert

##

certvde at 2026-09-16T07:57:36.259Z ##

🔒 New CSAF advisory published

VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: phoenixcontact.csaf-tp.certvde

##

certvde at 2026-09-16T07:56:58.455Z ##

🔒 New CSAF advisory published

VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: pepperl-fuchs.csaf-tp.certvde.

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T09:48:49.000Z ##

Patch critical industrial firmware vulnerabilities and authentication bypass flaws like CVE-2026-27565 in Pepperl+Fuchs, Phoenix Contact & Carlo Gavazzi.

#IndustrialSecurity #FirmwareFlaws #Cybersecurity #CVE202627565 #InfoSec

securityonline.info/industrial

##

certvde@infosec.exchange at 2026-09-16T07:58:13.000Z ##

🔒 New CSAF advisory published

VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: gavazziautomation.csaf-tp.cert

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:57:36.000Z ##

🔒 New CSAF advisory published

VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: phoenixcontact.csaf-tp.certvde

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:56:58.000Z ##

🔒 New CSAF advisory published

VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: pepperl-fuchs.csaf-tp.certvde.

#OT #Advisory

##

CVE-2026-27564
(7.2 HIGH)

EPSS: 2.02%

updated 2026-09-16T19:17:13.860000

6 posts

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device.

certvde at 2026-09-16T07:58:13.003Z ##

🔒 New CSAF advisory published

VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: gavazziautomation.csaf-tp.cert

##

certvde at 2026-09-16T07:57:36.259Z ##

🔒 New CSAF advisory published

VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: phoenixcontact.csaf-tp.certvde

##

certvde at 2026-09-16T07:56:58.455Z ##

🔒 New CSAF advisory published

VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: pepperl-fuchs.csaf-tp.certvde.

##

certvde@infosec.exchange at 2026-09-16T07:58:13.000Z ##

🔒 New CSAF advisory published

VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: gavazziautomation.csaf-tp.cert

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:57:36.000Z ##

🔒 New CSAF advisory published

VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: phoenixcontact.csaf-tp.certvde

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:56:58.000Z ##

🔒 New CSAF advisory published

VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: pepperl-fuchs.csaf-tp.certvde.

#OT #Advisory

##

CVE-2026-40854
(0 None)

EPSS: 0.00%

updated 2026-09-16T19:14:25.980000

2 posts

WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding file in /tmp/login_user. An attacker can bypass authentication by using directory entries such as "." or ".." in the cookie, allowing unauthorized access to the admin

cR0w at 2026-09-16T14:35:20.848Z ##

Vulnerabilities in a 5g router from T-Mobile, the company known for its security?! I'm shocked. Shocked! Well, not that shocked.

cert.pl/posts/2026/09/CVE-2026


##

cR0w@infosec.exchange at 2026-09-16T14:35:20.000Z ##

Vulnerabilities in a 5g router from T-Mobile, the company known for its security?! I'm shocked. Shocked! Well, not that shocked.

cert.pl/posts/2026/09/CVE-2026

#internetOfShit #miraiWillNeverDie
#jobSecurityForSomeone

##

CVE-2026-20307
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-16T18:32:09

2 posts

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. A

AAKL at 2026-09-16T17:17:37.050Z ##

New.

Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws sec.cloudapps.cisco.com/securi

This one is new, but there are others:

CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities sec.cloudapps.cisco.com/securi

Broadcom:

Broadcom has a long list of advisories addressing at least two critical vulnerabilities support.broadcom.com/web/ecx/s

Tenable:

Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities tenable.com/security/research/

And if you missed this, Microsoft posted two advisories for Edge yesterday: msrc.microsoft.com/update-guide

##

AAKL@infosec.exchange at 2026-09-16T17:17:37.000Z ##

New.

Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws sec.cloudapps.cisco.com/securi

This one is new, but there are others:

CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities sec.cloudapps.cisco.com/securi

Broadcom:

Broadcom has a long list of advisories addressing at least two critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Tenable:

Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities tenable.com/security/research/

And if you missed this, Microsoft posted two advisories for Edge yesterday: msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability

##

CVE-2026-92397
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-16T18:32:09

2 posts

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

thehackerwire@mastodon.social at 2026-09-16T17:02:40.000Z ##

🔴 CVE-2026-92397 - Critical (9.1)

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads to os comma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-16T17:02:40.000Z ##

🔴 CVE-2026-92397 - Critical (9.1)

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads to os comma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89775
(9.3 CRITICAL)

EPSS: 0.18%

updated 2026-09-16T18:31:58

2 posts

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Computing the effects of a TLB invalidation involves looking at the size of the mapping cached by the TLB. For S1 mappings such as VNCR, this is deducted from the combination of the base granule size and the mapping level. However, this implies that the S1 M

DailyCyberSecurity at 2026-09-17T02:40:47.551Z ##

A critical KVM guest escape (CVE-2026-89775) enables an LPE to gain root on Linux hosts. Patch this KVM guest escape vulnerability now.

securityonline.info/kvm-guest-

##

DailyCyberSecurity@infosec.exchange at 2026-09-17T02:40:47.000Z ##

A critical KVM guest escape (CVE-2026-89775) enables an LPE to gain root on Linux hosts. Patch this KVM guest escape vulnerability now.

#KVM #LinuxKernel #CVE202689775 #Cybersecurity #InfoSec

securityonline.info/kvm-guest-

##

CVE-2026-87287
(8.1 HIGH)

EPSS: 0.24%

updated 2026-09-16T18:31:53

2 posts

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidenti

thehackerwire@mastodon.social at 2026-09-15T21:02:51.000Z ##

🟠 CVE-2026-87287 - High (8.1)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T21:02:51.000Z ##

🟠 CVE-2026-87287 - High (8.1)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82028
(8.8 HIGH)

EPSS: 0.43%

updated 2026-09-16T17:18:09.647000

1 posts

Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that is interpolated directly into the FROM clause without parameterization or identifier quoting. Attackers with a self-registered account can substitute arbitrary su

thehackerwire@mastodon.social at 2026-09-14T21:00:35.000Z ##

🟠 CVE-2026-82028 - High (8.8)

Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that is interp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61595
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-16T15:32:15

2 posts

### Impact `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `threading.local()` and set exclusively by the HTTP-only `TenantMiddleware`, so on the live (WebSocket/SSE) path `get_current_tenant()` was always `None` during mount and every event handler — and the tenant-aware `QuerySet` manager failed **OPEN** (returned the unfiltered queryset, ignoring `

thehackerwire@mastodon.social at 2026-09-16T17:02:47.000Z ##

🟠 CVE-2026-61595 - High (7.7)

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `threading.local(...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-16T17:02:47.000Z ##

🟠 CVE-2026-61595 - High (7.7)

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `threading.local(...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73172(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-16T15:31:13

2 posts

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to execute arbitrary OS commands as root via crafted requests to TCP port 5058.

offseq at 2026-09-16T13:30:26.706Z ##

Advantech EKI-1242IEIMS (fw ≤1.06.01) suffers CRITICAL CVE-2026-73172: unauthenticated OS command injection via TCP 5058 enables remote root access. No patch yet — restrict device exposure & monitor traffic. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-16T13:30:26.000Z ##

Advantech EKI-1242IEIMS (fw ≤1.06.01) suffers CRITICAL CVE-2026-73172: unauthenticated OS command injection via TCP 5058 enables remote root access. No patch yet — restrict device exposure & monitor traffic. Details: radar.offseq.com/threat/cve-20 #OffSeq #ICS #CVE202673172 #infosec

##

CVE-2026-84858
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-16T15:18:00.527000

2 posts

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supplied JavaScript via the Rhino scripting engine. There are no authorization checks on this method and so it is possible for an attacker with access to a low privile

AAKL at 2026-09-16T17:17:37.050Z ##

New.

Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws sec.cloudapps.cisco.com/securi

This one is new, but there are others:

CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities sec.cloudapps.cisco.com/securi

Broadcom:

Broadcom has a long list of advisories addressing at least two critical vulnerabilities support.broadcom.com/web/ecx/s

Tenable:

Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities tenable.com/security/research/

And if you missed this, Microsoft posted two advisories for Edge yesterday: msrc.microsoft.com/update-guide

##

AAKL@infosec.exchange at 2026-09-16T17:17:37.000Z ##

New.

Cisco has advisories to address 13 critical vulnerabilities, among other lower-ranking flaws sec.cloudapps.cisco.com/securi

This one is new, but there are others:

CRITICAL: CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerabilities sec.cloudapps.cisco.com/securi

Broadcom:

Broadcom has a long list of advisories addressing at least two critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Tenable:

Tenable Research Advisories: CVE-2026-84858: ScadaLTS Multiple Vulnerabilities tenable.com/security/research/

And if you missed this, Microsoft posted two advisories for Edge yesterday: msrc.microsoft.com/update-guide #Microsoft #infosec #Cisco #vulnerability

##

CVE-2026-91990
(7.5 HIGH)

EPSS: 0.41%

updated 2026-09-16T13:42:49.167000

1 posts

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transient lists, exhausting server memory and causing denial of service.

thehackerwire@mastodon.social at 2026-09-15T17:00:03.000Z ##

🟠 CVE-2026-91990 - High (7.5)

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transie...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65838
(8.2 HIGH)

EPSS: 0.27%

updated 2026-09-16T13:42:48.383000

1 posts

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-presence Rego policy because ExtractHttpBodyOptionally leaves OPA with an empty parsed_body while forwarding the complete request body upstream. This inc

thehackerwire@mastodon.social at 2026-09-14T21:00:56.000Z ##

🟠 CVE-2026-65838 - High (8.2)

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73453
(10.0 CRITICAL)

EPSS: 0.75%

updated 2026-09-16T12:30:37

2 posts

An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled by default in Arista EOS. By crafting a malicious packet during the initiation of a P4Runtime session, an attacker can obtain complete administrative c

offseq at 2026-09-16T10:30:23.805Z ##

CVE-2026-73453: CRITICAL code injection in Arista EOS (4.29.2F – 4.36.1F) via P4Runtime. Allows unauthenticated code execution & admin control if enabled. Disable P4Runtime if not needed. No active exploits yet. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-16T10:30:23.000Z ##

CVE-2026-73453: CRITICAL code injection in Arista EOS (4.29.2F – 4.36.1F) via P4Runtime. Allows unauthenticated code execution & admin control if enabled. Disable P4Runtime if not needed. No active exploits yet. radar.offseq.com/threat/cve-20 #OffSeq #CVE202673453 #NetworkSecurity

##

CVE-2026-27561
(7.2 HIGH)

EPSS: 2.23%

updated 2026-09-16T09:30:35

6 posts

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.

certvde at 2026-09-16T07:58:13.003Z ##

🔒 New CSAF advisory published

VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: gavazziautomation.csaf-tp.cert

##

certvde at 2026-09-16T07:57:36.259Z ##

🔒 New CSAF advisory published

VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: phoenixcontact.csaf-tp.certvde

##

certvde at 2026-09-16T07:56:58.455Z ##

🔒 New CSAF advisory published

VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: pepperl-fuchs.csaf-tp.certvde.

##

certvde@infosec.exchange at 2026-09-16T07:58:13.000Z ##

🔒 New CSAF advisory published

VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: gavazziautomation.csaf-tp.cert

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:57:36.000Z ##

🔒 New CSAF advisory published

VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: phoenixcontact.csaf-tp.certvde

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:56:58.000Z ##

🔒 New CSAF advisory published

VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: pepperl-fuchs.csaf-tp.certvde.

#OT #Advisory

##

CVE-2026-27563
(7.2 HIGH)

EPSS: 2.02%

updated 2026-09-16T09:30:35

6 posts

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.

certvde at 2026-09-16T07:58:13.003Z ##

🔒 New CSAF advisory published

VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: gavazziautomation.csaf-tp.cert

##

certvde at 2026-09-16T07:57:36.259Z ##

🔒 New CSAF advisory published

VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: phoenixcontact.csaf-tp.certvde

##

certvde at 2026-09-16T07:56:58.455Z ##

🔒 New CSAF advisory published

VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: pepperl-fuchs.csaf-tp.certvde.

##

certvde@infosec.exchange at 2026-09-16T07:58:13.000Z ##

🔒 New CSAF advisory published

VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: gavazziautomation.csaf-tp.cert

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:57:36.000Z ##

🔒 New CSAF advisory published

VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: phoenixcontact.csaf-tp.certvde

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:56:58.000Z ##

🔒 New CSAF advisory published

VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: pepperl-fuchs.csaf-tp.certvde.

#OT #Advisory

##

CVE-2026-27562
(7.2 HIGH)

EPSS: 2.23%

updated 2026-09-16T09:30:34

6 posts

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.

certvde at 2026-09-16T07:58:13.003Z ##

🔒 New CSAF advisory published

VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: gavazziautomation.csaf-tp.cert

##

certvde at 2026-09-16T07:57:36.259Z ##

🔒 New CSAF advisory published

VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: phoenixcontact.csaf-tp.certvde

##

certvde at 2026-09-16T07:56:58.455Z ##

🔒 New CSAF advisory published

VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: pepperl-fuchs.csaf-tp.certvde.

##

certvde@infosec.exchange at 2026-09-16T07:58:13.000Z ##

🔒 New CSAF advisory published

VDE-2026-028
Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: gavazziautomation.csaf-tp.cert

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:57:36.000Z ##

🔒 New CSAF advisory published

VDE-2026-027
Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerab…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: phoenixcontact.csaf-tp.certvde

#OT #Advisory

##

certvde@infosec.exchange at 2026-09-16T07:56:58.000Z ##

🔒 New CSAF advisory published

VDE-2026-014
Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities
CVE-2026-27565, CVE-2026-27564, CVE-2026-27563, CVE-2026-27562, CVE-2026-27561 (+15 more)

The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be execute…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: pepperl-fuchs.csaf-tp.certvde.

#OT #Advisory

##

CVE-2026-81642(CVSS UNKNOWN)

EPSS: 0.52%

updated 2026-09-16T09:30:28

2 posts

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerabili

offseq at 2026-09-16T09:00:26.336Z ##

CVE-2026-81642: CRITICAL heap buffer overflow in NLnet Labs Unbound ≤1.26.0. Exploitable via DNSKEY with owner compression pointer — possible DoS & RCE. Patch ASAP. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-16T09:00:26.000Z ##

CVE-2026-81642: CRITICAL heap buffer overflow in NLnet Labs Unbound ≤1.26.0. Exploitable via DNSKEY with owner compression pointer — possible DoS & RCE. Patch ASAP. radar.offseq.com/threat/cve-20 #OffSeq #DNS #Unbound #Vuln #RCE

##

CVE-2026-12793
(9.8 CRITICAL)

EPSS: 0.39%

updated 2026-09-16T06:31:34

3 posts

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and executing an Advanced Validation server-side callback. This makes it possible for un

3 repos

https://github.com/murrez/CVE-2026-12793

https://github.com/rootxn/CVE-2026-12793

https://github.com/abraxas/CVE-2026-12793

netsecio@mastodon.social at 2026-09-16T16:03:29.000Z ##

📰 Critical WordPress Plugin Flaw Allows Unauthenticated Admin Creation

Critical unauthenticated admin creation flaw (CVE-2026-12793, CVSS 9.8) found in JetFormBuilder WordPress plugin (<= 3.6.2). Public exploit available. Update or disable immediately to prevent site takeover! #WordPress #Vulnerability

🔗 cyber.netsecops.io/articles/wo

##

offseq at 2026-09-16T04:30:24.617Z ##

CVE-2026-12793: CRITICAL privilege escalation in JetFormBuilder Dynamic Blocks Form Builder (<=3.6.2). Unauthenticated attackers can create admin accounts. Restrict access & monitor until patch. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-16T04:30:24.000Z ##

CVE-2026-12793: CRITICAL privilege escalation in JetFormBuilder Dynamic Blocks Form Builder (<=3.6.2). Unauthenticated attackers can create admin accounts. Restrict access & monitor until patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202612793 #Infosec

##

CVE-2026-14349
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-09-16T06:31:34

2 posts

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the email address of arbitrary user accounts, including administrators, which

offseq at 2026-09-16T06:00:25.409Z ##

TrueBooker (<=1.2.3) WordPress plugin hit by CVE-2026-14349 (CRITICAL, CVSS 9.8): missing auth lets unauthenticated attackers change user emails & reset passwords. No patch yet — restrict access & monitor! radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-16T06:00:25.000Z ##

TrueBooker (<=1.2.3) WordPress plugin hit by CVE-2026-14349 (CRITICAL, CVSS 9.8): missing auth lets unauthenticated attackers change user emails & reset passwords. No patch yet — restrict access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202614349 #AppSec

##

CVE-2026-83355
(9.8 CRITICAL)

EPSS: 0.36%

updated 2026-09-16T00:32:32

1 posts

Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager for Fusion Middleware. Successful attacks of this vulnerability can result in t

infosecbot@mastodon.hofud.com at 2026-09-16T07:06:58.000Z ##

[1/4]

Most Impactful Security Incidents ( 2026‑09‑15 → today )

---

PRIORITY 1 – Critical/high‑severity flaws (CVSS 7‑10) in core software stacks :

CVE‑2026‑83339
• Oracle WebCenter Enterprise Capture – Client Bundle
• Unauthenticated remote code execution; attacker can take full control of the capture service.
• 9.8 (Critical)
• HTTP (network‑level)
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83355
• Oracle Enterprise Manager for Fusion Middleware – Metrics
• Remote code execution via unauthenticated HTTP request; full takeover of the management console.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83149
• Oracle Application Testing Suite – 13.3.0.1
• Low‑privileged attacker can execute arbitrary code over HTTP; leads to full compromise of the testing suite.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83107
• Oracle Forms – 12.2.1.19.0 / 14.1.2.0
• High‑privileged attacker can gain remote code execution via HTTP; full takeover of Forms services.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83105
• Oracle Forms – same versions
• Remote code execution (CVSS 9) via HTTP; attacker gains full control.
• 9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83103
• Oracle Forms – same versions
• Remote code execution (CVSS 9.1) via HTTP; full compromise.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83100
• Oracle Forms – same versions
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83099
• Oracle WebCenter Portal – Runtime Tools
• Remote code execution (CVSS 9.9) via HTTP; full compromise of the portal.
• 9.9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83098
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83095
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full compromise.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

#infosecnews

##

CVE-2026-83339
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-09-16T00:32:27

1 posts

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover

infosecbot@mastodon.hofud.com at 2026-09-16T07:06:58.000Z ##

[1/4]

Most Impactful Security Incidents ( 2026‑09‑15 → today )

---

PRIORITY 1 – Critical/high‑severity flaws (CVSS 7‑10) in core software stacks :

CVE‑2026‑83339
• Oracle WebCenter Enterprise Capture – Client Bundle
• Unauthenticated remote code execution; attacker can take full control of the capture service.
• 9.8 (Critical)
• HTTP (network‑level)
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83355
• Oracle Enterprise Manager for Fusion Middleware – Metrics
• Remote code execution via unauthenticated HTTP request; full takeover of the management console.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83149
• Oracle Application Testing Suite – 13.3.0.1
• Low‑privileged attacker can execute arbitrary code over HTTP; leads to full compromise of the testing suite.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83107
• Oracle Forms – 12.2.1.19.0 / 14.1.2.0
• High‑privileged attacker can gain remote code execution via HTTP; full takeover of Forms services.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83105
• Oracle Forms – same versions
• Remote code execution (CVSS 9) via HTTP; attacker gains full control.
• 9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83103
• Oracle Forms – same versions
• Remote code execution (CVSS 9.1) via HTTP; full compromise.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83100
• Oracle Forms – same versions
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83099
• Oracle WebCenter Portal – Runtime Tools
• Remote code execution (CVSS 9.9) via HTTP; full compromise of the portal.
• 9.9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83098
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83095
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full compromise.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

#infosecnews

##

CVE-2026-83095
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-09-16T00:32:27

1 posts

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Ba

infosecbot@mastodon.hofud.com at 2026-09-16T07:06:58.000Z ##

[1/4]

Most Impactful Security Incidents ( 2026‑09‑15 → today )

---

PRIORITY 1 – Critical/high‑severity flaws (CVSS 7‑10) in core software stacks :

CVE‑2026‑83339
• Oracle WebCenter Enterprise Capture – Client Bundle
• Unauthenticated remote code execution; attacker can take full control of the capture service.
• 9.8 (Critical)
• HTTP (network‑level)
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83355
• Oracle Enterprise Manager for Fusion Middleware – Metrics
• Remote code execution via unauthenticated HTTP request; full takeover of the management console.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83149
• Oracle Application Testing Suite – 13.3.0.1
• Low‑privileged attacker can execute arbitrary code over HTTP; leads to full compromise of the testing suite.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83107
• Oracle Forms – 12.2.1.19.0 / 14.1.2.0
• High‑privileged attacker can gain remote code execution via HTTP; full takeover of Forms services.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83105
• Oracle Forms – same versions
• Remote code execution (CVSS 9) via HTTP; attacker gains full control.
• 9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83103
• Oracle Forms – same versions
• Remote code execution (CVSS 9.1) via HTTP; full compromise.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83100
• Oracle Forms – same versions
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83099
• Oracle WebCenter Portal – Runtime Tools
• Remote code execution (CVSS 9.9) via HTTP; full compromise of the portal.
• 9.9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83098
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83095
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full compromise.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

#infosecnews

##

CVE-2026-77179(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-09-16T00:32:25

2 posts

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.

DailyCyberSecurity at 2026-09-17T02:33:27.028Z ##

Docker released an update for critical Docker Sandboxes vulnerabilities (CVE-2026-77179, CVE-2026-79994). Patch these Docker Sandboxes vulnerabilities today.

securityonline.info/docker-san

##

DailyCyberSecurity@infosec.exchange at 2026-09-17T02:33:27.000Z ##

Docker released an update for critical Docker Sandboxes vulnerabilities (CVE-2026-77179, CVE-2026-79994). Patch these Docker Sandboxes vulnerabilities today.

#Docker #DockerSandboxes #CVE202677179 #CVE202679994 #Cybersecurity

securityonline.info/docker-san

##

CVE-2026-85893
(8.8 HIGH)

EPSS: 0.68%

updated 2026-09-16T00:31:42

2 posts

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-09-16T00:00:00.000Z ##

🟠 CVE-2026-85893 - High (8.8)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-16T00:00:00.000Z ##

🟠 CVE-2026-85893 - High (8.8)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15640(CVSS UNKNOWN)

EPSS: 0.28%

updated 2026-09-16T00:31:41

4 posts

Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.

cR0w at 2026-09-16T14:17:30.159Z ##

Go hack more Secret Server shit.

delinea.com/security-advisories

Authentication Bypass via SAML Response Manipulation - CVE-2026-15640

Reflected Cross-Site Scripting - CVE-2026-15639

Cryptographic Padding Oracle - CVE-2026-15638

##

offseq at 2026-09-16T01:30:23.928Z ##

Delinea Secret Server (On-Prem, v10.5.0 – 12.1.3) hit by CRITICAL auth bypass (CVE-2026-15640). SAML spoofing may allow attacker impersonation. Patch info not yet available. Details: radar.offseq.com/threat/cve-20

##

cR0w@infosec.exchange at 2026-09-16T14:17:30.000Z ##

Go hack more Secret Server shit.

delinea.com/security-advisories

Authentication Bypass via SAML Response Manipulation - CVE-2026-15640

Reflected Cross-Site Scripting - CVE-2026-15639

Cryptographic Padding Oracle - CVE-2026-15638

##

offseq@infosec.exchange at 2026-09-16T01:30:23.000Z ##

Delinea Secret Server (On-Prem, v10.5.0 – 12.1.3) hit by CRITICAL auth bypass (CVE-2026-15640). SAML spoofing may allow attacker impersonation. Patch info not yet available. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Delinea #CVE202615640

##

CVE-2026-69486
(8.8 HIGH)

EPSS: 0.66%

updated 2026-09-16T00:31:41

2 posts

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-09-16T00:00:09.000Z ##

🟠 CVE-2026-69486 - High (8.8)

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-16T00:00:09.000Z ##

🟠 CVE-2026-69486 - High (8.8)

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15638(CVSS UNKNOWN)

EPSS: 0.20%

updated 2026-09-16T00:31:34

2 posts

An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.

cR0w at 2026-09-16T14:17:30.159Z ##

Go hack more Secret Server shit.

delinea.com/security-advisories

Authentication Bypass via SAML Response Manipulation - CVE-2026-15640

Reflected Cross-Site Scripting - CVE-2026-15639

Cryptographic Padding Oracle - CVE-2026-15638

##

cR0w@infosec.exchange at 2026-09-16T14:17:30.000Z ##

Go hack more Secret Server shit.

delinea.com/security-advisories

Authentication Bypass via SAML Response Manipulation - CVE-2026-15640

Reflected Cross-Site Scripting - CVE-2026-15639

Cryptographic Padding Oracle - CVE-2026-15638

##

CVE-2026-15639(CVSS UNKNOWN)

EPSS: 0.39%

updated 2026-09-16T00:31:33

4 posts

An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.

cR0w at 2026-09-16T14:17:30.159Z ##

Go hack more Secret Server shit.

delinea.com/security-advisories

Authentication Bypass via SAML Response Manipulation - CVE-2026-15640

Reflected Cross-Site Scripting - CVE-2026-15639

Cryptographic Padding Oracle - CVE-2026-15638

##

offseq at 2026-09-16T03:00:24.672Z ##

CVE-2026-15639: CRITICAL XSS in Delinea Secret Server (On-Prem, 10.2.19 – 11.9.48). Exploitation allows remote attackers to run JS in user sessions. Patch status unknown — check vendor advisories. radar.offseq.com/threat/cve-20

##

cR0w@infosec.exchange at 2026-09-16T14:17:30.000Z ##

Go hack more Secret Server shit.

delinea.com/security-advisories

Authentication Bypass via SAML Response Manipulation - CVE-2026-15640

Reflected Cross-Site Scripting - CVE-2026-15639

Cryptographic Padding Oracle - CVE-2026-15638

##

offseq@infosec.exchange at 2026-09-16T03:00:24.000Z ##

CVE-2026-15639: CRITICAL XSS in Delinea Secret Server (On-Prem, 10.2.19 – 11.9.48). Exploitation allows remote attackers to run JS in user sessions. Patch status unknown — check vendor advisories. radar.offseq.com/threat/cve-20 #OffSeq #XSS #Vuln #Delinea #Cybersecurity

##

CVE-2026-87289
(7.5 HIGH)

EPSS: 0.46%

updated 2026-09-16T00:31:27

2 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatabl

thehackerwire@mastodon.social at 2026-09-15T21:03:11.000Z ##

🟠 CVE-2026-87289 - High (7.5)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network ac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T21:03:11.000Z ##

🟠 CVE-2026-87289 - High (7.5)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network ac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83098
(9.8 CRITICAL)

EPSS: 0.36%

updated 2026-09-16T00:31:25

1 posts

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Ba

infosecbot@mastodon.hofud.com at 2026-09-16T07:06:58.000Z ##

[1/4]

Most Impactful Security Incidents ( 2026‑09‑15 → today )

---

PRIORITY 1 – Critical/high‑severity flaws (CVSS 7‑10) in core software stacks :

CVE‑2026‑83339
• Oracle WebCenter Enterprise Capture – Client Bundle
• Unauthenticated remote code execution; attacker can take full control of the capture service.
• 9.8 (Critical)
• HTTP (network‑level)
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83355
• Oracle Enterprise Manager for Fusion Middleware – Metrics
• Remote code execution via unauthenticated HTTP request; full takeover of the management console.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83149
• Oracle Application Testing Suite – 13.3.0.1
• Low‑privileged attacker can execute arbitrary code over HTTP; leads to full compromise of the testing suite.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83107
• Oracle Forms – 12.2.1.19.0 / 14.1.2.0
• High‑privileged attacker can gain remote code execution via HTTP; full takeover of Forms services.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83105
• Oracle Forms – same versions
• Remote code execution (CVSS 9) via HTTP; attacker gains full control.
• 9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83103
• Oracle Forms – same versions
• Remote code execution (CVSS 9.1) via HTTP; full compromise.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83100
• Oracle Forms – same versions
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83099
• Oracle WebCenter Portal – Runtime Tools
• Remote code execution (CVSS 9.9) via HTTP; full compromise of the portal.
• 9.9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83098
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83095
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full compromise.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

#infosecnews

##

CVE-2026-83100
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-09-16T00:31:25

1 posts

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Ba

infosecbot@mastodon.hofud.com at 2026-09-16T07:06:58.000Z ##

[1/4]

Most Impactful Security Incidents ( 2026‑09‑15 → today )

---

PRIORITY 1 – Critical/high‑severity flaws (CVSS 7‑10) in core software stacks :

CVE‑2026‑83339
• Oracle WebCenter Enterprise Capture – Client Bundle
• Unauthenticated remote code execution; attacker can take full control of the capture service.
• 9.8 (Critical)
• HTTP (network‑level)
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83355
• Oracle Enterprise Manager for Fusion Middleware – Metrics
• Remote code execution via unauthenticated HTTP request; full takeover of the management console.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83149
• Oracle Application Testing Suite – 13.3.0.1
• Low‑privileged attacker can execute arbitrary code over HTTP; leads to full compromise of the testing suite.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83107
• Oracle Forms – 12.2.1.19.0 / 14.1.2.0
• High‑privileged attacker can gain remote code execution via HTTP; full takeover of Forms services.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83105
• Oracle Forms – same versions
• Remote code execution (CVSS 9) via HTTP; attacker gains full control.
• 9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83103
• Oracle Forms – same versions
• Remote code execution (CVSS 9.1) via HTTP; full compromise.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83100
• Oracle Forms – same versions
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83099
• Oracle WebCenter Portal – Runtime Tools
• Remote code execution (CVSS 9.9) via HTTP; full compromise of the portal.
• 9.9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83098
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83095
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full compromise.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

#infosecnews

##

CVE-2026-92000
(7.5 HIGH)

EPSS: 0.39%

updated 2026-09-15T21:33:15

2 posts

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.

thehackerwire@mastodon.social at 2026-09-15T22:00:04.000Z ##

🟠 CVE-2026-92000 - High (7.5)

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T22:00:04.000Z ##

🟠 CVE-2026-92000 - High (7.5)

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68070
(8.8 HIGH)

EPSS: 0.27%

updated 2026-09-15T21:33:13

2 posts

The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.

thehackerwire@mastodon.social at 2026-09-15T22:01:10.000Z ##

🟠 CVE-2026-68070 - High (8.8)

The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T22:01:10.000Z ##

🟠 CVE-2026-68070 - High (8.8)

The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66890
(9.6 CRITICAL)

EPSS: 0.20%

updated 2026-09-15T21:33:13

2 posts

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

thehackerwire@mastodon.social at 2026-09-15T22:00:59.000Z ##

🔴 CVE-2026-66890 - Critical (9.6)

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T22:00:59.000Z ##

🔴 CVE-2026-66890 - Critical (9.6)

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87286
(8.1 HIGH)

EPSS: 0.24%

updated 2026-09-15T21:33:13

2 posts

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidenti

thehackerwire@mastodon.social at 2026-09-15T21:00:53.000Z ##

🟠 CVE-2026-87286 - High (8.1)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T21:00:53.000Z ##

🟠 CVE-2026-87286 - High (8.1)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via H...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83149
(9.1 CRITICAL)

EPSS: 0.26%

updated 2026-09-15T21:32:16

1 posts

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Test Manager for Web Apps privilege with network access via HTTP to compromise Oracle Application Testing Suite. While the vulnerability is in Oracle Application Testing Suite, attacks may significantly impact additional pr

infosecbot@mastodon.hofud.com at 2026-09-16T07:06:58.000Z ##

[1/4]

Most Impactful Security Incidents ( 2026‑09‑15 → today )

---

PRIORITY 1 – Critical/high‑severity flaws (CVSS 7‑10) in core software stacks :

CVE‑2026‑83339
• Oracle WebCenter Enterprise Capture – Client Bundle
• Unauthenticated remote code execution; attacker can take full control of the capture service.
• 9.8 (Critical)
• HTTP (network‑level)
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83355
• Oracle Enterprise Manager for Fusion Middleware – Metrics
• Remote code execution via unauthenticated HTTP request; full takeover of the management console.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83149
• Oracle Application Testing Suite – 13.3.0.1
• Low‑privileged attacker can execute arbitrary code over HTTP; leads to full compromise of the testing suite.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83107
• Oracle Forms – 12.2.1.19.0 / 14.1.2.0
• High‑privileged attacker can gain remote code execution via HTTP; full takeover of Forms services.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83105
• Oracle Forms – same versions
• Remote code execution (CVSS 9) via HTTP; attacker gains full control.
• 9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83103
• Oracle Forms – same versions
• Remote code execution (CVSS 9.1) via HTTP; full compromise.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83100
• Oracle Forms – same versions
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83099
• Oracle WebCenter Portal – Runtime Tools
• Remote code execution (CVSS 9.9) via HTTP; full compromise of the portal.
• 9.9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83098
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83095
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full compromise.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

#infosecnews

##

CVE-2026-83103
(9.1 CRITICAL)

EPSS: 0.47%

updated 2026-09-15T21:32:14

1 posts

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional prod

infosecbot@mastodon.hofud.com at 2026-09-16T07:06:58.000Z ##

[1/4]

Most Impactful Security Incidents ( 2026‑09‑15 → today )

---

PRIORITY 1 – Critical/high‑severity flaws (CVSS 7‑10) in core software stacks :

CVE‑2026‑83339
• Oracle WebCenter Enterprise Capture – Client Bundle
• Unauthenticated remote code execution; attacker can take full control of the capture service.
• 9.8 (Critical)
• HTTP (network‑level)
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83355
• Oracle Enterprise Manager for Fusion Middleware – Metrics
• Remote code execution via unauthenticated HTTP request; full takeover of the management console.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83149
• Oracle Application Testing Suite – 13.3.0.1
• Low‑privileged attacker can execute arbitrary code over HTTP; leads to full compromise of the testing suite.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83107
• Oracle Forms – 12.2.1.19.0 / 14.1.2.0
• High‑privileged attacker can gain remote code execution via HTTP; full takeover of Forms services.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83105
• Oracle Forms – same versions
• Remote code execution (CVSS 9) via HTTP; attacker gains full control.
• 9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83103
• Oracle Forms – same versions
• Remote code execution (CVSS 9.1) via HTTP; full compromise.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83100
• Oracle Forms – same versions
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83099
• Oracle WebCenter Portal – Runtime Tools
• Remote code execution (CVSS 9.9) via HTTP; full compromise of the portal.
• 9.9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83098
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83095
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full compromise.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

#infosecnews

##

CVE-2026-83107
(9.1 CRITICAL)

EPSS: 0.47%

updated 2026-09-15T21:32:07

1 posts

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional prod

infosecbot@mastodon.hofud.com at 2026-09-16T07:06:58.000Z ##

[1/4]

Most Impactful Security Incidents ( 2026‑09‑15 → today )

---

PRIORITY 1 – Critical/high‑severity flaws (CVSS 7‑10) in core software stacks :

CVE‑2026‑83339
• Oracle WebCenter Enterprise Capture – Client Bundle
• Unauthenticated remote code execution; attacker can take full control of the capture service.
• 9.8 (Critical)
• HTTP (network‑level)
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83355
• Oracle Enterprise Manager for Fusion Middleware – Metrics
• Remote code execution via unauthenticated HTTP request; full takeover of the management console.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83149
• Oracle Application Testing Suite – 13.3.0.1
• Low‑privileged attacker can execute arbitrary code over HTTP; leads to full compromise of the testing suite.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83107
• Oracle Forms – 12.2.1.19.0 / 14.1.2.0
• High‑privileged attacker can gain remote code execution via HTTP; full takeover of Forms services.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83105
• Oracle Forms – same versions
• Remote code execution (CVSS 9) via HTTP; attacker gains full control.
• 9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83103
• Oracle Forms – same versions
• Remote code execution (CVSS 9.1) via HTTP; full compromise.
• 9.1
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83100
• Oracle Forms – same versions
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83099
• Oracle WebCenter Portal – Runtime Tools
• Remote code execution (CVSS 9.9) via HTTP; full compromise of the portal.
• 9.9
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83098
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full takeover.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

CVE‑2026‑83095
• Oracle WebCenter Portal – Composer
• Remote code execution (CVSS 9.8) via HTTP; full compromise.
• 9.8
• HTTP
• <cveawg.mitre.org/api/cve/CVE-2>

#infosecnews

##

CVE-2026-76670
(9.9 CRITICAL)

EPSS: 0.45%

updated 2026-09-15T21:31:34

2 posts

Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.

DailyCyberSecurity at 2026-09-16T02:03:44.877Z ##

A critical HPE EdgeConnect authorization bypass (CVE-2026-76670) enables full system compromise. Patch this HPE EdgeConnect authorization bypass now.

securityonline.info/hpe-edgeco

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T02:03:44.000Z ##

A critical HPE EdgeConnect authorization bypass (CVE-2026-76670) enables full system compromise. Patch this HPE EdgeConnect authorization bypass now.

#HPE #EdgeConnect #AuthorizationBypass #CVE202676670 #Cybersecurity

securityonline.info/hpe-edgeco

##

CVE-2026-92179
(7.8 HIGH)

EPSS: 0.17%

updated 2026-09-15T21:31:29

2 posts

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of P

thehackerwire@mastodon.social at 2026-09-15T20:00:10.000Z ##

🟠 CVE-2026-92179 - High (7.8)

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T20:00:10.000Z ##

🟠 CVE-2026-92179 - High (7.8)

pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92178
(7.8 HIGH)

EPSS: 0.17%

updated 2026-09-15T21:31:28

2 posts

pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF

thehackerwire@mastodon.social at 2026-09-15T19:59:59.000Z ##

🟠 CVE-2026-92178 - High (7.8)

pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T19:59:59.000Z ##

🟠 CVE-2026-92178 - High (7.8)

pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92180
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-15T21:31:25

2 posts

pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific fl

thehackerwire@mastodon.social at 2026-09-15T20:02:40.000Z ##

🟠 CVE-2026-92180 - High (7.8)

pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T20:02:40.000Z ##

🟠 CVE-2026-92180 - High (7.8)

pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89040
(9.8 CRITICAL)

EPSS: 0.93%

updated 2026-09-15T20:19:20.240000

2 posts

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root.

thehackerwire@mastodon.social at 2026-09-15T21:00:33.000Z ##

🔴 CVE-2026-89040 - Critical (9.8)

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T21:00:33.000Z ##

🔴 CVE-2026-89040 - Critical (9.8)

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88975
(7.5 HIGH)

EPSS: 0.62%

updated 2026-09-15T20:01:24

2 posts

### Summary An unauthenticated peer can make Ember's HTTP/2 read loop hold 16 MiB of a single frame in memory on a connection where Ember advertised a 16 KiB limit. The declared length is readable from the frame's first 9 bytes, but it is not compared against SETTINGS_MAX_FRAME_SIZE until the whole payload has been read into a contiguous buffer. That is 1024x amplification per connection, bounded

thehackerwire@mastodon.social at 2026-09-15T21:00:43.000Z ##

🟠 CVE-2026-88975 - High (7.5)

Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits to buffer the entire payload before comparing it with SETTINGS_MAX_FRAME_SIZE. An unauthe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T21:00:43.000Z ##

🟠 CVE-2026-88975 - High (7.5)

Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits to buffer the entire payload before comparing it with SETTINGS_MAX_FRAME_SIZE. An unauthe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69213
(7.5 HIGH)

EPSS: 0.36%

updated 2026-09-15T20:00:36

2 posts

Ember's HTTP/2 connection serializes all outgoing frames through a single unbounded queue drained by one writer fiber (`writeLoop`). When the write side stalls, any frames the connection keeps producing accumulate in that queue without limit. The peer can drive this cheaply because the connection emits a control frame in response to inbound frames it does not flow-control: one `PING` ACK per `PI

thehackerwire@mastodon.social at 2026-09-15T20:03:00.000Z ##

🟠 CVE-2026-69213 - High (7.5)

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames through one unbounded queue consumed by writeLoop. When the peer stops reading, an unauthenticated HTTP/2 client can continue se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T20:03:00.000Z ##

🟠 CVE-2026-69213 - High (7.5)

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames through one unbounded queue consumed by writeLoop. When the peer stops reading, an unauthenticated HTTP/2 client can continue se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90847
(9.1 CRITICAL)

EPSS: 2.18%

updated 2026-09-15T19:17:46.767000

1 posts

A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

offseq@infosec.exchange at 2026-09-15T01:30:24.000Z ##

EFM ipTIME C200E v1.094 suffers CRITICAL OS command injection (CVE-2026-90847, CVSS 9.4) via iux_set.cgi. Remotely exploitable, public exploit available. Restrict device access and monitor. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity #CVE

##

CVE-2026-57586
(8.6 HIGH)

EPSS: 0.15%

updated 2026-09-15T19:17:31.030000

1 posts

CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/manager.py treats build.gradle or build.gradle.kts as sufficient to invoke _sync_gradle. _sync_gradle prefers a repository-controlled gradlew or gradlew.bat file and p

thehackerwire@mastodon.social at 2026-09-15T16:01:44.000Z ##

🟠 CVE-2026-57586 - High (8.6)

CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/manager.py tre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20274
(9.8 CRITICAL)

EPSS: 0.73%

updated 2026-09-15T18:33:13

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20274 are related to improper resource control issues that are g

AAKL@infosec.exchange at 2026-09-15T15:50:22.000Z ##

Cisco has addressed a critical September 2 vulnerability.

CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

More related to Cisco:

Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability

##

CVE-2026-91985
(7.5 HIGH)

EPSS: 0.38%

updated 2026-09-15T18:32:43

1 posts

Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT at the share's permission level to escalate privileges and perform unauthorized writes or administrative actions.

thehackerwire@mastodon.social at 2026-09-15T17:00:15.000Z ##

🟠 CVE-2026-91985 - High (7.5)

Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91989
(7.5 HIGH)

EPSS: 1.26%

updated 2026-09-15T18:32:42

1 posts

atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass path containment checks by including '../' segments in requests to the DashboardHandler.do_GET endpoint to access files outside the intended agents_root directory.

thehackerwire@mastodon.social at 2026-09-15T16:59:53.000Z ##

🟠 CVE-2026-91989 - High (7.5)

atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass path conta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76441
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-09-15T18:32:19

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76441 are related to i

AAKL@infosec.exchange at 2026-09-14T16:42:45.000Z ##

Welcome to Monday and two new advisories from Cisco.

CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability sec.cloudapps.cisco.com/securi

Two more critical vulnerabilities on the 9th and the 11th sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

@cR0w

##

CVE-2026-20353
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-09-15T18:32:19

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20353 are related to i

AAKL@infosec.exchange at 2026-09-14T16:42:45.000Z ##

Welcome to Monday and two new advisories from Cisco.

CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability sec.cloudapps.cisco.com/securi

Two more critical vulnerabilities on the 9th and the 11th sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

@cR0w

##

CVE-2026-20276
(8.6 HIGH)

EPSS: 0.27%

updated 2026-09-15T18:32:13

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20276 are related to insufficient control flow management issues

AAKL@infosec.exchange at 2026-09-15T15:50:22.000Z ##

Cisco has addressed a critical September 2 vulnerability.

CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

More related to Cisco:

Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability

##

CVE-2026-76440
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-09-15T18:19:12.950000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76440 are related to

AAKL@infosec.exchange at 2026-09-14T16:42:45.000Z ##

Welcome to Monday and two new advisories from Cisco.

CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability sec.cloudapps.cisco.com/securi

Two more critical vulnerabilities on the 9th and the 11th sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

@cR0w

##

CVE-2026-20275
(8.8 HIGH)

EPSS: 0.19%

updated 2026-09-15T18:17:18.413000

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20275 are related to incorrect calculation issues that are gro

AAKL@infosec.exchange at 2026-09-15T15:50:22.000Z ##

Cisco has addressed a critical September 2 vulnerability.

CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

More related to Cisco:

Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability

##

CVE-2026-89026
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-09-15T17:17:33.510000

7 posts

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, c

1 repos

https://github.com/cflowsec/CVE-2026-89026

cyberworldops at 2026-09-17T04:30:00.441Z ##

Unauthenticated RCE in Issabel Framework (CVE-2026-89026) is being exploited in the wild. A hardcoded JWT secret in pbxapi/index.php allows token forgery and OS command execution as the Asterisk user, risking full PBX takeover.

cyberworldops.eu/en/one-shared

##

undercodenews@mastodon.social at 2026-09-17T03:53:49.000Z ##

Critical Issabel PBX Flaw CVE-2026-89026 Is Under Active Exploitation, Exposing Systems to Unauthenticated Remote Command Execution + Video

A Dangerous Authentication Failure in the Heart of Issabel PBX A critical security vulnerability in the Issabel Framework has moved from a newly disclosed software flaw to a confirmed exploitation concern. Tracked as CVE-2026-89026, the vulnerability allows unauthenticated remote attackers to forge JSON Web Tokens and abuse the…

undercodenews.com/critical-iss

##

rxerium at 2026-09-15T18:03:42.870Z ##

Thank you to @vulncheck for the smooth collaboration throughout the CNA process.

More details:
cve.org/CVERecord?id=CVE-2026-

##

thehackerwire@mastodon.social at 2026-09-15T18:01:18.000Z ##

🔴 CVE-2026-89026 - Critical (9.8)

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cyberworldops@infosec.exchange at 2026-09-17T04:30:00.000Z ##

Unauthenticated RCE in Issabel Framework (CVE-2026-89026) is being exploited in the wild. A hardcoded JWT secret in pbxapi/index.php allows token forgery and OS command execution as the Asterisk user, risking full PBX takeover. #Issabel #RemoteCodeExecution #InfoSec

cyberworldops.eu/en/one-shared

##

rxerium@infosec.exchange at 2026-09-15T18:03:42.000Z ##

Thank you to @vulncheck for the smooth collaboration throughout the CNA process.

More details:
cve.org/CVERecord?id=CVE-2026-

##

thehackerwire@mastodon.social at 2026-09-15T18:01:18.000Z ##

🔴 CVE-2026-89026 - Critical (9.8)

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39919
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-09-15T15:32:20

2 posts

Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image components declare different subsampling values, the non-samescale sub-byte-depth output path allocates

DailyCyberSecurity at 2026-09-17T02:20:05.016Z ##

A Ghostscript buffer overflow enables unauthenticated remote code execution. Patch this Ghostscript buffer overflow flaw (CVE-2026-39919) immediately.

securityonline.info/ghostscrip

##

DailyCyberSecurity@infosec.exchange at 2026-09-17T02:20:05.000Z ##

A Ghostscript buffer overflow enables unauthenticated remote code execution. Patch this Ghostscript buffer overflow flaw (CVE-2026-39919) immediately.

#Ghostscript #CVE202639919 #RemoteCodeExecution #Cybersecurity #InfoSec

securityonline.info/ghostscrip

##

CVE-2026-90439
(6.5 MEDIUM)

EPSS: 0.26%

updated 2026-09-15T15:32:20

1 posts

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a TLS handshake. This can happen in a non-deterministic manner that is beyond the attacker's control. This may cause a heap buffer overflow in the NGINX worker proc

sayzard@mastodon.sayzard.org at 2026-09-16T10:44:00.000Z ##

Nginx 1.30.5 and 1.31.6 fix HTTP/3 buffer overflow (CVE-2026-90439)

NGINX가 HTTP/3 처리 과정의 버퍼 오버플로 취약점(CVE-2026-90439)을 수정한 1.30.5(Stable)와 1.31.6(Mainline)을 배포했습니다. NGINX는 AI API 게이트웨이, 모델 서빙 프록시, RAG·에이전트 서비스의 인그레스 계층에 널리 사용되므로 HTTP/3를 활성화한 배포 환경은 우선 영향을 점검해야 합니다. 제공된 내용에는 CVSS, 공격 조건, 영향 범위 등 세부 정보가 없지만, 메모리 안전성 문제인 버퍼 오버플로 수정이므로 해당 버전 이상으로의 업데이트와 롤백 가능한 배포 검증이 권장됩니다.

nginx.org/en/download.html

#nginx #security #http3 #bufferoverflow #cve

##

CVE-2026-63696
(9.1 CRITICAL)

EPSS: 0.32%

updated 2026-09-15T15:32:20

1 posts

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

thehackerwire@mastodon.social at 2026-09-15T16:01:34.000Z ##

🔴 CVE-2026-63696 - Critical (9.1)

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63695
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-09-15T15:32:20

1 posts

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.

thehackerwire@mastodon.social at 2026-09-15T16:01:02.000Z ##

🔴 CVE-2026-63695 - Critical (9.8)

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89025
(7.5 HIGH)

EPSS: 0.42%

updated 2026-09-15T15:17:26.720000

1 posts

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. T

thehackerwire@mastodon.social at 2026-09-15T16:00:52.000Z ##

🟠 CVE-2026-89025 - High (7.5)

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specif...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75983
(7.5 HIGH)

EPSS: 0.41%

updated 2026-09-15T15:17:21.443000

1 posts

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` function being registered as a callback on WordPress core's `map_meta_cap` filter and unconditionally returning the always-true `'exist'` primitive for every c

thehackerwire@mastodon.social at 2026-09-15T08:00:29.000Z ##

🟠 CVE-2026-75983 - High (7.5)

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` func...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45051
(0 None)

EPSS: 0.51%

updated 2026-09-15T14:16:54.240000

1 posts

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators without an ObjectInputFilter. Exploitation requires the WebAuthn flow to be reachable and an attacker to have previously written controlled data to that attribute through delegated ad

offseq@infosec.exchange at 2026-09-15T10:30:25.000Z ##

OpenAM <16.1.1 suffers from CRITICAL deserialization vuln (CVE-2026-45051, CVSS 9.2). WebAuthnAuthentication lets attackers run arbitrary code via crafted serialized data. Patch to 16.1.1 ASAP! radar.offseq.com/threat/cve-20 #OffSeq #CVE202645051 #OpenAM #infosec

##

CVE-2026-76461
(9.8 CRITICAL)

EPSS: 2.01%

updated 2026-09-15T12:47:32.497000

31 posts

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that co

3 repos

https://github.com/HORKimhab/CVE-2026-76461

https://github.com/0xBlackash/CVE-2026-76461

https://github.com/fevar54/CVE-2026-76461-Detection-Kit-

security_crawler_carl at 2026-09-16T23:37:29.739Z ##

🏆 New Achievement! Root Access? We'll Get That Escalated for You!

Your ticket has been received. We see you're experiencing an issue where an unauthenticated attacker is executing arbitrary commands with root privileges on your Cisco Secure Email Gateway via CVE-2026-76461. Great news: we've reproduced the bug! It's the email parsing in Cisco AsyncOS — sending a specially crafted email with malicious SQL statements is all it takes. (1/3)

##

youranonnewsirc@nerdculture.de at 2026-09-16T16:26:20.000Z ##

Recent developments include Cisco patching a critical zero-day (CVE-2026-76461) in its Secure Email Gateway, which was actively exploited for root command execution. Geopolitically, China warned against weaponizing space after the US confirmed orbital weapon deployments. In technology, debates continue on AI safety versus national competitive advantage, with US Speaker Johnson rejecting development pauses.

#Cybersecurity #Geopolitics #AnonNews_irc

##

netsecio@mastodon.social at 2026-09-16T16:03:44.000Z ##

📰 Cisco Patches Actively Exploited Zero-Day in Secure Email Gateways

Cisco patches critical, actively exploited zero-day (CVE-2026-76461) in Secure Email Gateways. Unauthenticated attackers can compromise devices via a crafted email. CISA has added it to the KEV catalog. #CyberSecurity #ZeroDay #Infosec #Cisco

🔗 cyber.netsecops.io/articles/ci

##

571906@ap.podcastindex.org at 2026-09-16T02:00:02.000Z ##

New Episode: SANS Stormcast Wednesday, September 16th, 2026: MacOS 27 Traffic; Cisco 0-Day; Protecting Active Directory and API Tokens

Shownotes:

MacOS 27 - First Boot
https://isc.sans.edu/diary/MacOS%2027%20-%20First%20Boot/33340
Cisco Secure Email Gateway SQL Injection Vulnerability CVE-2026-76461
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/ci

Transcript

AntennaPod | Anytime Player | Apple Podcasts | Castamatic | CurioCaster | Fountain | gPodder | Overcast | Pocket Casts | Podcast Addict | Podcast Guru | Podnews | Podverse | Truefans

Or Listen right here.

##

youranonnewsirc@nerdculture.de at 2026-09-16T10:26:27.000Z ##

Global cybersecurity agencies, including CISA & NSA, issued guidance to mitigate 17 Active Directory compromise techniques (Sept 16). Cisco patched an actively exploited email gateway zero-day (CVE-2026-76461). Geopolitically, the US confirmed deploying space weapons, drawing warnings from China about an arms race (Sept 15). AI is now the leading driver for new cybersecurity spending.

#Cybersecurity #Geopolitics #TechNews

##

sayzard@mastodon.sayzard.org at 2026-09-16T06:43:30.000Z ##

Cisco Email Gateway SQL Injection Yields Unauthenticated Root (CVSS 9.8)

Cisco Secure Email Gateway의 AsyncOS 이메일 파싱 로직에서 인증 없이 악성 이메일만 전송해 SQL 인젝션을 유발하고, 기반 운영체제에서 root 권한 명령 실행까지 가능한 CVE-2026-76461이 공개됐다(CVSS 9.8). 물리·가상 어플라이언스 모두 구성과 무관하게 영향을 받으며, 우회책은 없으므로 해당 버전 사용 조직은 15.5.5-0141, 16.0.4-3021 또는 권장 버전인 16.5.0-780 이상으로 즉시 업그레이드해야 한...

sec.cloudapps.cisco.com/securi

##

DailyCyberSecurity at 2026-09-16T06:17:38.381Z ##

A critical Cisco Secure Email Gateway vulnerability allows unauthenticated attackers to gain root access via a single email. Learn about CVE-2026-76461.

meterpreter.org/cisco-secure-e

##

threatnoir at 2026-09-16T02:05:58.455Z ##

⚠️ CRITICAL: Cisco warns customers of actively exploited zero-day in email gateways

Cisco Secure Email Gateway contains a critical unauthenticated root privilege escalation vulnerability (CVE-2026-76461) that was actively exploited in the wild before patches were available. Multiple customers are likely already compromised. This is now tracked in CISA's Known Exploited Vulnerabili…

threatnoir.com/focus

🤖 AI generated summary

##

threatnoir at 2026-09-16T02:05:54.039Z ##

⚠️ CRITICAL: Cisco patches Secure Email Gateway zero-day exploited in attacks

Cisco Secure Email Gateway has a critical zero-day (CVE-2026-76461) that allows unauthenticated attackers to execute arbitrary commands as root via malicious SQL in crafted emails. This is actively exploited in the wild. Any organization running SEG is at immediate risk of full compromise.

threatnoir.com/focus

🤖 AI generated summary

##

sayzard@mastodon.sayzard.org at 2026-09-16T01:39:03.000Z ##

Cisco email security boxes can be rooted by an email

Cisco Secure Email Gateway의 AsyncOS에서 수신 이메일 처리 취약점(CVE-2026-76461)이 악용되고 있으며, 인증 없이 조작된 이메일 하나로 어플라이언스의 root 권한 명령 실행이 가능하다. CVSS는 9.8이고 물리·가상 어플라이언스 구성과 무관하게 영향을 받으며, 우회책이 없어 패치가 유일한 대응이다. 침해 후 공격자는 로컬 로그를 변조해 흔적을 지울 수 있으므로 게이트웨이 로그뿐 아니라 네트워크·방화벽 로그를 함께 조사해야 한다. Cisco는 AsyncO...

theregister.com/security/2026/

##

undercodenews@mastodon.social at 2026-09-15T22:35:16.000Z ##

Cisco Secure Email Gateway Zero-Day Under Active Attack: Critical CVE-2026-76461 Puts Root-Level Access at Risk + Video

A Critical Warning for Cisco Customers A serious cybersecurity warning is unfolding around Cisco Secure Email Gateway after Cisco disclosed active exploitation of CVE-2026-76461, a critical zero-day vulnerability that can allow an unauthenticated remote attacker to execute commands with root privileges. The vulnerability has also been added to the…

undercodenews.com/cisco-secure

##

Matchbook3469@mastodon.social at 2026-09-15T19:34:02.000Z ##

🔵 THREAT INTELLIGENCE

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

Vulnerability | CRITICAL
CVEs: CVE-2026-76461

Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]

Full analysis:
yazoul.net/news/article/cisco-

by Yazoul AI

#CyberSecurity #APT #CyberNews

##

Analyst207@mastodon.social at 2026-09-15T18:03:19.000Z ##

Cisco Discloses Actively Exploited Zero-Day in Email Gateways

A critical zero-day vulnerability, CVE-2026-76461, is under active exploitation, allowing hackers to remotely execute commands as root on Cisco Secure Email Gateway appliances with just a simple email. This gaping security hole gives attackers total control of the gateway, putting your email security at risk.

osintsights.com/cisco-disclose

#ZeroDay #Cve202676461 #Cisco #EmailGateway #RemoteCodeExecution

##

security_crawler_carl@infosec.exchange at 2026-09-16T23:37:29.000Z ##

🏆 New Achievement! Root Access? We'll Get That Escalated for You!

Your ticket has been received. We see you're experiencing an issue where an unauthenticated attacker is executing arbitrary commands with root privileges on your Cisco Secure Email Gateway via CVE-2026-76461. Great news: we've reproduced the bug! It's the email parsing in Cisco AsyncOS — sending a specially crafted email with malicious SQL statements is all it takes. (1/3)

##

youranonnewsirc@nerdculture.de at 2026-09-16T16:26:20.000Z ##

Recent developments include Cisco patching a critical zero-day (CVE-2026-76461) in its Secure Email Gateway, which was actively exploited for root command execution. Geopolitically, China warned against weaponizing space after the US confirmed orbital weapon deployments. In technology, debates continue on AI safety versus national competitive advantage, with US Speaker Johnson rejecting development pauses.

#Cybersecurity #Geopolitics #AnonNews_irc

##

youranonnewsirc@nerdculture.de at 2026-09-16T10:26:27.000Z ##

Global cybersecurity agencies, including CISA & NSA, issued guidance to mitigate 17 Active Directory compromise techniques (Sept 16). Cisco patched an actively exploited email gateway zero-day (CVE-2026-76461). Geopolitically, the US confirmed deploying space weapons, drawing warnings from China about an arms race (Sept 15). AI is now the leading driver for new cybersecurity spending.

#Cybersecurity #Geopolitics #TechNews

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T06:17:38.000Z ##

A critical Cisco Secure Email Gateway vulnerability allows unauthenticated attackers to gain root access via a single email. Learn about CVE-2026-76461.

#Cisco #EmailGateway #CyberSecurity #ZeroDay #Vulnerability

meterpreter.org/cisco-secure-e

##

threatnoir@infosec.exchange at 2026-09-16T02:05:58.000Z ##

⚠️ CRITICAL: Cisco warns customers of actively exploited zero-day in email gateways

Cisco Secure Email Gateway contains a critical unauthenticated root privilege escalation vulnerability (CVE-2026-76461) that was actively exploited in the wild before patches were available. Multiple customers are likely already compromised. This is now tracked in CISA's Known Exploited Vulnerabili…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-09-16T02:05:54.000Z ##

⚠️ CRITICAL: Cisco patches Secure Email Gateway zero-day exploited in attacks

Cisco Secure Email Gateway has a critical zero-day (CVE-2026-76461) that allows unauthenticated attackers to execute arbitrary commands as root via malicious SQL in crafted emails. This is actively exploited in the wild. Any organization running SEG is at immediate risk of full compromise.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

youranonnewsirc@nerdculture.de at 2026-09-15T16:26:27.000Z ##

Geopolitical tensions: A Russian drone struck a Kyiv-Warsaw train near the Polish border (Sept 13), and Houthi forces secured Yemen's Red Sea coast (Sept 11), affecting maritime routes. Tech news: Apple's Siri AI, powered by Apple Intelligence, began its beta rollout (Sept 14). Cybersecurity: Cisco warned of active exploitation of a critical Secure Email Gateway flaw (CVE-2026-76461) (Sept 15), and Anthropic reported Russia-linked spies used its AI Claude for hacking campaigns.

#Cybersecurity #Geopolitics #TechNews

##

thecybermind@infosec.exchange at 2026-09-15T16:25:35.000Z ##

Actionable C-Suite threat intelligence and mitigation strategies for CVE-2026-76461, addressing active SQL injection exploitation vectors within enterprise Cisco Secure Email Gateway infrastructures. thecybermind.co/r5ry

##

AAKL@infosec.exchange at 2026-09-15T15:50:22.000Z ##

Cisco has addressed a critical September 2 vulnerability.

CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

More related to Cisco:

Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability

##

cyberveille@mastobot.ping.moi at 2026-09-15T09:00:06.000Z ##

📢 [VULN] ⚠️Injection SQL exploitée dans Cisco Secure Email Gateway - CVE-2026-76461

Le 14 septembre 2026 à 16 h 00 UTC, Cisco a publié deux avis de sécurité sur sa passerelle de messagerie.

🔗 blog.marcfredericgomez.fr/inje
💬 discussion : infosec.pub/post/52317366
#CVE #Cyberveille

##

ottoto2017@prattohome.com at 2026-09-15T08:14:44.000Z ##

「Ciscoのセキュアメールゲートウェイの脆弱性が実際に悪用され、ルート権限でのコマンド実行が可能になる 」: #TheHackerNews

「スコは、Cisco Secure Email Gateway向けAsyncOSソフトウェアに影響を与える新たな重大な脆弱性が、実際に悪用されていると警告した。

CVE-2026-76461 として追跡されているこの脆弱性は 、CVSSスコアが10.0点満点中9.8点です。これは、メール解析ロジックにおける検証の不備が原因で、認証されていないリモート攻撃者が、基盤となるオペレーティングシステム上でroot権限で任意のコマンドを実行できる可能性があるとされています。

シスコは月曜日の勧告で、「攻撃者は、悪意のあるSQL文を含む細工された電子メールメッセージを影響を受けるデバイスに送信することで、この脆弱性を悪用する可能性がある」 と述べた 。」

thehackernews.com/2026/09/cisc

#prattohome

##

offseq@infosec.exchange at 2026-09-15T03:00:26.000Z ##

CRITICAL (CVSS 9.8): CVE-2026-76461 in Cisco AsyncOS for Secure Email Gateway lets unauthenticated attackers execute commands as root via crafted emails. Patch status unknown — monitor Cisco’s updates. radar.offseq.com/threat/a-vuln #OffSeq #Cisco #Vulnerability #EmailSecurity

##

DailyCyberSecurity@infosec.exchange at 2026-09-15T02:18:05.000Z ##

CVE-2026-76461 (CVSS 9.8) is a Cisco Secure Email Gateway vulnerability exploited in the wild. SQL injection grants root command execution. Patch now.

#Cisco #EmailSecurity #CVE202676461 #SQLInjection #RCE #ExploitedInTheWild #AsyncOS #InfoSec #PatchNow #RootAccess

securityonline.info/cve-2026-7

##

ssvc@infosec.exchange at 2026-09-14T22:16:17.000Z ##

Since no one seems to have noticed the Cisco exploited zero-day:

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability

cisa.gov/news-events/alerts/20

#CISA #KEV #Cisco #zeroday #CVE

##

secdb@infosec.exchange at 2026-09-14T21:00:30.000Z ##

🚨 [CISA-2026:0914] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-76461 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Secure Email Gateway SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Email Gateway
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260914 #cisa20260914 #cve_2026_76461 #cve202676461

##

thecybermind@infosec.exchange at 2026-09-14T20:55:43.000Z ##

CRITICAL CISA KEV ALERT: CVE-2026-76461 targets Cisco Secure Email Gateway via SQL injection, granting root-level RCE. Active exploitation verified. Access our TSUITE brief for SIEM queries and hardening steps to secure your email perimeter.

thecybermind.co/al1f

##

cisakevtracker@mastodon.social at 2026-09-14T20:00:50.000Z ##

CVE ID: CVE-2026-76461
Vendor: Cisco
Product: Secure Email Gateway
Date Added: 2026-09-14
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-09-14T16:42:45.000Z ##

Welcome to Monday and two new advisories from Cisco.

CRITICAL: CVE-2026-20353, CVE-2026-76440, and CVE-2026-76441: Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi

CRITICAL: CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability sec.cloudapps.cisco.com/securi

Two more critical vulnerabilities on the 9th and the 11th sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

@cR0w

##

CVE-2026-91995
(9.1 CRITICAL)

EPSS: 0.61%

updated 2026-09-15T12:31:54

1 posts

pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to overwrite any account credential including the admin account and gain full administrative control.

offseq@infosec.exchange at 2026-09-15T13:30:26.000Z ##

pig-mesh pig <4.1.0 hit by CRITICAL vuln (CVE-2026-91995, CVSS 9.3): remote attackers can reset any account password — admin included — via /register/password auth bypass. Restrict access & monitor logs while awaiting patch. radar.offseq.com/threat/cve-20 #OffSeq #vulnerability #CVE #infosec

##

CVE-2026-89308(CVSS UNKNOWN)

EPSS: 2.97%

updated 2026-09-15T12:31:54

1 posts

An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.

offseq@infosec.exchange at 2026-09-15T12:00:26.000Z ##

CVE-2026-89308 in TREXOM TrxTimeATTENDANCE (v1.0.5 – 1.9.5): CRITICAL OS command injection in ping.php allows unauthenticated RCE. Remediate ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202689308 #infosec #vuln #remediation

##

CVE-2026-80217
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-15T09:30:39

1 posts

Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.

thehackerwire@mastodon.social at 2026-09-15T10:04:02.000Z ##

🟠 CVE-2026-80217 - High (8.8)

Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91003
(9.1 CRITICAL)

EPSS: 0.51%

updated 2026-09-15T06:30:40

2 posts

A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.

thehackerwire@mastodon.social at 2026-09-15T08:00:39.000Z ##

🔴 CVE-2026-91003 - Critical (9.1)

A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-15T07:30:25.000Z ##

D-Link DI-8300 (fw 16.07) hit by CRITICAL stack buffer overflow (CVE-2026-91003) in /rzgl.asp — remote RCE possible, public exploit code out. Restrict access & monitor traffic until patch. radar.offseq.com/threat/cve-20 #OffSeq #CVE202691003 #DLink #Security

##

CVE-2026-91001
(9.9 CRITICAL)

EPSS: 0.48%

updated 2026-09-15T06:30:39

2 posts

A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

thehackerwire@mastodon.social at 2026-09-15T10:04:12.000Z ##

🔴 CVE-2026-91001 - Critical (9.9)

A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-15T06:00:26.000Z ##

Stack-based buffer overflow (CVE-2026-91001, CVSS 9.4) in D-Link DI-8400 (16.07) exposes devices to RCE. Exploit code is public. Restrict management access until fix. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202691001 #IoTSecurity #Vulnerability

##

CVE-2026-91771
(8.8 HIGH)

EPSS: 0.73%

updated 2026-09-15T03:30:30

1 posts

Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal sequences to write files outside the intended download directory, potentially enabling code execution through modification of shell startup files or Python import p

thehackerwire@mastodon.social at 2026-09-15T04:00:11.000Z ##

🟠 CVE-2026-91771 - High (8.8)

Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal sequences t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91200
(8.8 HIGH)

EPSS: 0.42%

updated 2026-09-15T00:31:22

1 posts

DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the developer workstation, enabling code execution.

thehackerwire@mastodon.social at 2026-09-15T00:00:17.000Z ##

🟠 CVE-2026-91200 - High (8.8)

DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the developer w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12944
(9.6 CRITICAL)

EPSS: 0.25%

updated 2026-09-15T00:31:21

4 posts

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role permissions, (2) arbitrary file exfiltration from the container filesystem, and (3) lateral movement to internal services

2 repos

https://github.com/cflowsec/CVE-2026-12944

https://github.com/ShadowForge-Cyber/CVE-2026-12944

DailyCyberSecurity at 2026-09-16T01:03:01.753Z ##

A critical Langflow SSRF flaw (CVE-2026-12944) exposes cloud credentials and internal networks. Patch your Langflow OSS servers immediately.

securityonline.info/langflow-s

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T01:03:01.000Z ##

A critical Langflow SSRF flaw (CVE-2026-12944) exposes cloud credentials and internal networks. Patch your Langflow OSS servers immediately.

#Langflow #SSRF #CVE202612944 #CVE202617628 #Cybersecurity

securityonline.info/langflow-s

##

offseq@infosec.exchange at 2026-09-15T00:00:36.000Z ##

CVE-2026-12944 (CRITICAL, CVSS 9.6) affects IBM Langflow OSS 1.0.0 – 1.10.0. Attackers can execute arbitrary Python as root via SSRF, steal AWS creds, and move laterally. Patch is available — validate remediation. radar.offseq.com/threat/cve-20 #OffSeq #SSRF #IBM #CloudSecurity

##

thehackerwire@mastodon.social at 2026-09-14T23:00:59.000Z ##

🔴 CVE-2026-12944 - Critical (9.6)

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91144
(7.5 HIGH)

EPSS: 0.37%

updated 2026-09-15T00:31:21

1 posts

ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the intended access restrictions.

thehackerwire@mastodon.social at 2026-09-14T23:00:48.000Z ##

🟠 CVE-2026-91144 - High (7.5)

ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared ba...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65352
(4.3 MEDIUM)

EPSS: 0.25%

updated 2026-09-15T00:31:13

1 posts

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1. A website may be able to determine a user's IP address with Private Relay turned on.

mysk@mastodon.social at 2026-09-15T14:41:27.000Z ##

Apple acknowledges fixing the Private Relay bug leaking the IP in the secure release notes of iOS 26.6.1 and macOS 26.6.2.
CVE-2026-65352 was assigned to it

##

CVE-2026-82232
(9.8 CRITICAL)

EPSS: 0.56%

updated 2026-09-14T21:32:45

2 posts

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort clauses for Task search. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2

DailyCyberSecurity at 2026-09-16T01:52:03.188Z ##

Six Apache Syncope vulnerabilities, including CVE-2026-82232, expose severe identity management flaws. Patch your Apache Syncope servers immediately.

securityonline.info/apache-syn

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T01:52:03.000Z ##

Six Apache Syncope vulnerabilities, including CVE-2026-82232, expose severe identity management flaws. Patch your Apache Syncope servers immediately.

#ApacheSyncope #IdentityManagement #CVE202682232 #Cybersecurity #Vulnerability

securityonline.info/apache-syn

##

CVE-2026-89023
(8.6 HIGH)

EPSS: 0.23%

updated 2026-09-14T21:31:42

1 posts

ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can retrieve stored offer records, delete arbitrary offers by numeric identifier, and access dashboard statistics to disclose bidder contact information, offer details, m

thehackerwire@mastodon.social at 2026-09-14T20:00:08.000Z ##

🟠 CVE-2026-89023 - High (8.6)

ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can retrieve stor...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78330
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-09-14T20:58:48.430000

1 posts

Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a successful authentication and obtaining a valid low-privileges JWT. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, fr

offseq@infosec.exchange at 2026-09-15T04:30:30.000Z ##

CVE-2026-78330 | CRITICAL: Apache Syncope vuln allows admin escalation if JWKS is exposed and JWT auth used. Affects 3.0.0-M0 – 3.0.16, 4.0.0-M0 – 4.0.7, 4.1.0-M0 – 4.1.2. Upgrade to 4.0.8/4.1.3 to mitigate. Details: radar.offseq.com/threat/incorr #OffSeq #Vulnerability #ApacheSyncope

##

CVE-2026-91079
(8.5 HIGH)

EPSS: 0.35%

updated 2026-09-14T20:17:03.600000

1 posts

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer renders and returns as downloadable PDFs or images, enabling access to internal metadata services and network hosts.

thehackerwire@mastodon.social at 2026-09-14T19:01:55.000Z ##

🟠 CVE-2026-91079 - High (8.5)

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90946
(7.5 HIGH)

EPSS: 0.57%

updated 2026-09-14T19:18:13.990000

1 posts

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to read all files with supported extensions including Python, JavaScript, YAML, and JSON files containing hardcoded secrets and credentials.

thehackerwire@mastodon.social at 2026-09-14T19:01:45.000Z ##

🟠 CVE-2026-90946 - High (7.5)

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59178
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-09-14T19:17:37.617000

1 posts

ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESPHOME_PASSWORD`. Earlier versions, and the legacy `esphome` dashboard, read the bare `$USERNAME` and `$PASSWORD` instead. When the env vars were renamed the bare names were dropped with no fallback, so

thehackerwire@mastodon.social at 2026-09-14T20:00:17.000Z ##

🔴 CVE-2026-59178 - Critical (9.8)

ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESPHOME_PASSWORD`. Earlier versions, and the legac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91080
(7.5 HIGH)

EPSS: 0.59%

updated 2026-09-14T18:31:35

1 posts

webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with invalid signatures to trigger out-of-memory conditions and crash the service.

thehackerwire@mastodon.social at 2026-09-14T20:00:27.000Z ##

🟠 CVE-2026-91080 - High (7.5)

webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with invalid signat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85921
(8.2 HIGH)

EPSS: 0.26%

updated 2026-09-14T18:31:29

1 posts

Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

AAKL@infosec.exchange at 2026-09-14T17:40:55.000Z ##

Looks like Microsoft has a couple of new flaws.

NEW and CRITICAL: CVE-2026-85921: Windows Secure Kernel Mode Elevation of Privilege Vulnerabilityhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921

NEW and CRITICAL: CVE-2026-85921: Windows Secure Kernel Mode Elevation of Privilege Vulnerability New msrc.microsoft.com/update-guid #infosec #Microsoft #vulnerability #Windows

##

CVE-2026-90945
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-09-14T18:31:28

2 posts

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.

thehackerwire@mastodon.social at 2026-09-14T19:01:34.000Z ##

🔴 CVE-2026-90945 - Critical (9.8)

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w@infosec.exchange at 2026-09-14T18:49:58.000Z ##

Go fuck with some crawlers.

nvd.nist.gov/vuln/detail/cve-2

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.

##

CVE-2026-89471
(8.4 HIGH)

EPSS: 0.14%

updated 2026-09-14T15:33:32

1 posts

In the Linux kernel, the following vulnerability has been resolved: power: supply: cros_usbpd-charger: bound the EC-reported port count cros_usbpd_charger_probe() reads two port counts from the EC and uses one of them, num_charger_ports, as the loop bound when populating a fixed-size array: struct port_data *ports[EC_USB_PD_MAX_PORTS]; /* 8 entries */ ... for (i = 0; i < charger->num_charger

hugovalters@mastodon.social at 2026-09-16T20:10:01.000Z ##

CVE-2026-89471 Linux kernel cros_usbpd-charger out-of-bounds access from unbounded EC port count. CVSS N/A, no patch yet. Apply mitigations or update once fixed. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-81008
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-14T15:33:29

1 posts

In the Linux kernel, the following vulnerability has been resolved: interconnect: Fix use after free in icc_get() and of_icc_get_by_index() In of_icc_get_by_index() and icc_get(), if the dynamic allocation for path->name fails via kasprintf(), the error handling path directly calls kfree(path) to free the path object and returns an error. However, prior to this point, path_find() calls path_ini

hugovalters@mastodon.social at 2026-09-16T21:40:01.000Z ##

CVE-2026-81008 Linux kernel use-after-free in icc_get() and of_icc_get_by_index(). CVSS N/A, patch status unknown. Update immediately. valtersit.com/cve/CVE-2026-810 #CVE #Linux #infosec

##

CVE-2026-81011
(7.1 HIGH)

EPSS: 0.12%

updated 2026-09-14T15:33:28

1 posts

In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: pass validated element count to package parsers The per-type package parsers are handed the wrong element count. hp_init_bios_package_attribute() validates obj->package.count and then calls one of the five hp_populate_*_package_data() wrappers (string, integer, enumeration, ordered list, password). Eac

hugovalters@mastodon.social at 2026-09-16T06:00:18.000Z ##

CVE-2026-81011: Linux kernel hp-bioscfg passes unvalidated element count to package parsers, causing out-of-bounds access. No CVSS, no patch yet. Treat as unpatched. Check your kernel version. valtersit.com/cve/CVE-2026-810 #CVE #Linux #infosec

##

CVE-2026-80973(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-09-14T15:33:27

1 posts

In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire: bound the MIDI event length from the device usb6fire_comm_receiver_handler() forwards a MIDI event using a length byte the device supplies, with no bound and no check that the transfer delivered that many bytes: if (!urb->status) { if (rt->receiver_buffer[0] == 0x10) /* midi in event */ if (midi_rt) midi_

hugovalters@mastodon.social at 2026-09-16T03:40:01.000Z ##

CVE-2026-80973 Linux ALSA 6fire: unvalidated MIDI length byte allows out-of-bounds read. CVSS N/A, patch status unknown. Patch now if you use this driver. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-89495
(9.8 CRITICAL)

EPSS: 0.70%

updated 2026-09-14T15:32:27

1 posts

In the Linux kernel, the following vulnerability has been resolved: ocfs2: bound namelen in dlm_migrate_request_handler Patch series "ocfs2/dlm: bound peer-controlled lengths in the o2dlm". The o2dlm receive handlers trust u8 length and count fields from the wire without bounding them, so a node in a DLM domain can corrupt or panic any other node with a malformed message. Three defects: - d

hugovalters@mastodon.social at 2026-09-17T02:21:06.000Z ##

CVE-2026-89495 Linux ocfs2/dlm out-of-bounds access. A DLM node can corrupt or panic any other node with a malformed message. CVSS N/A, no patch yet. Patch now.
valtersit.com/cve/CVE-2026-894
#CVE #Linux #infosec

##

CVE-2026-89489
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-14T15:32:27

1 posts

In the Linux kernel, the following vulnerability has been resolved: openrisc: fix arbitrary kernel memory access via or1k_atomic syscall sys_or1k_atomic() (syscall 244 in the "or1k" ABI) takes two user pointers, v1 and v2, and swaps the words they point to in hand-written assembly. l.lwz r29,0(r4) l.lwz r27,0(r5) l.sw 0(r4),r27 l.sw 0(r5),r29 The pointers are not chec

hugovalters@mastodon.social at 2026-09-16T09:10:00.000Z ##

CVE-2026-89489 Linux kernel openrisc or1k_atomic lacks access_ok checks, allowing arbitrary kernel memory read/write. No CVSS assigned, patch status unknown. Update your kernel now. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-89465
(8.4 HIGH)

EPSS: 0.14%

updated 2026-09-14T15:32:25

1 posts

In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: quiesce delayed work before teardown The threaded IRQ handler can queue pwr_rdy_work, max_charging_time_work and batt_presence_work. pwr_rdy_work and batt_presence_work can also queue max_charging_time_work, while batt_presence_work can requeue itself. rt9455_remove() cancels max_charging_time_work befor

hugovalters@mastodon.social at 2026-09-16T15:30:04.000Z ##

CVE-2026-89465 Linux kernel rt9455 power supply use-after-free from unquiesced delayed work, no CVSS assigned yet, patch status unknown. Update your kernel as soon as a fix lands. Details: valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-80979
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-14T15:32:22

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/smc: unregister the connection before draining the rx tasklet smc_conn_free() calls smc_ism_unset_conn() only while the link group is still on its device list, and never sets conn->killed. smc_lgr_terminate_sched() unlinks the group immediately and defers killing its connections to a work item, so a connection freed in that

hugovalters@mastodon.social at 2026-09-15T19:10:01.000Z ##

CVE-2026-80979 Linux kernel net/smc: use-after-free via smc_conn_free() when lgr termination races conn teardown. CVSS N/A, no patch confirmed. Verify your kernel build and update immediately. valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-80931
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-14T15:32:20

1 posts

In the Linux kernel, the following vulnerability has been resolved: w1: ds28e17: reject an oversize length on an I2C block read w1_f19_i2c_master_transfer() is the master_xfer for the DS28E17 1-Wire to I2C bridge. On an I2C_M_RECV_LEN read, it takes the length from the device. The downstream slave puts a length byte in buf[0]. The driver then reads that many bytes into buf[1] with w1_f19_i2c_rea

hugovalters@mastodon.social at 2026-09-16T04:30:01.000Z ##

CVE-2026-80931 Linux kernel w1 ds28e17: OOB access via oversize I2C block read length. No CVSS, patch status unknown. Update now. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-43502
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-14T15:32:07

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but before the message is attached to the sending socket. The purge path currently infers zerocopy state from rm->m_rs, so an unqueued message can be cleaned up as if it owned normal payload pages. Howev

1 repos

https://github.com/suominen/pintheft

secdb@infosec.exchange at 2026-09-14T22:14:36.000Z ##

🚨 ZcopyReaper (CVE-2026-43502) has been identified as a notable vulnerability.

In the Linux kernel, the following vulnerability has been resolved:

net/rds: handle zerocopy send cleanup before the message is queued

A zerocopy send can fail after user pages have been pinned but before
the message is attached to the sending socket.

The purge path currently infers zerocopy state from rm->m_rs, so an
unqueued message can be cleaned up as if it owned normal payload pages.
However, zerocopy ownership is really determined by the presence of
op_mmp_znotifier, regardless of whether the message has reached the
socket queue.

Capture op_mmp_znotifier up front in rds_message_purge() and use it as
the cleanup discriminator. If the message is already associated with a
socket, keep the existing completion path. Otherwise, drop the pinned
page accounting directly and release the notifier before putting the
payload pages.

This keeps early send failure cleanup consistent with the zerocopy
lifetime rules without changing the normal queued completion path.

ℹ️ Additional information on ZEN SecDB 👉 secdb.nttzen.cloud/cve/detail/

#Infosec #ZcopyReaper #Linux #Kernel #LPE #CVE202643502
#NTTData #ZEN #SecDB

##

CVE-2026-89475
(0 None)

EPSS: 0.21%

updated 2026-09-14T13:19:03.853000

1 posts

In the Linux kernel, the following vulnerability has been resolved: power: supply: bq24257: fix use-after-free on remove The STAT-pin interrupt is devm-managed, so it stays armed until the devm cleanup that runs after remove() returns. remove() cancels bq->iilimit_setup_work while the threaded handler can still fire; that handler reschedules the work and dereferences bq, so the work runs against

hugovalters@mastodon.social at 2026-09-17T01:50:02.000Z ##

CVE-2026-89475 Linux kernel bq24257 use-after-free on remove. CVSS N/A, patch unpatched. Update now. valtersit.com/cve/CVE-2026-894 #CVE #infosec #Linux

##

CVE-2026-81000
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-14T13:18:54.210000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to TUN or TAP. When align is larger than the usable space in a one-page skb head, SKB_MAX_HEAD(align) underflows and the re

hugovalters@mastodon.social at 2026-09-17T05:30:20.000Z ##

CVE-2026-81000 Linux kernel tun driver integer underflow in tun_get_user() via oversized headroom from OVS, leading to memory corruption. No CVSS assigned, patch status unpatched. Apply kernel updates now. valtersit.com/cve/CVE-2026-810 #CVE #Linux #infosec

##

CVE-2026-80989
(8.8 HIGH)

EPSS: 0.34%

updated 2026-09-14T13:18:53.647000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Mark the connection down when bringing it up fails Every failure path in tbnet_connected_work() undoes its own work and returns without clearing login_sent, so the connection still looks established. The next tbnet_tear_down() therefore takes its main branch and repeats a teardown that already happened: it stop

hugovalters@mastodon.social at 2026-09-17T04:00:02.000Z ##

CVE-2026-80989 Linux kernel thunderbolt net driver: failed bring-up leaves login_sent set, so tear-down repeats and hits dev_WARN, fatal under panic_on_warn. No CVSS or patch yet. Update your kernel now. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-90894
(7.8 HIGH)

EPSS: 0.15%

updated 2026-09-14T12:31:44

2 posts

Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group. After login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmParentPath). The daemon unpacks with one string, tar -xf "%1" -C "%2", then Qt QProcess::splitCommand 

Analyst207@mastodon.social at 2026-09-16T15:04:32.000Z ##

Parallels Desktop Flaw Exposes Macs to Root Access

A newly discovered flaw in Parallels Desktop, tracked as CVE-2026-90894, leaves Macs vulnerable to root access, allowing ordinary local accounts to run code as root. This security gap, dubbed ParaShells, was uncovered by JFrog's vulnerability team and rated 7.8 out of 10 in severity.

osintsights.com/parallels-desk

#MacVulnerability #ParallelsDesktop #Cve202690894 #LocalPrivilegeEscalation #RootAccess

##

undercodenews@mastodon.social at 2026-09-16T10:04:06.000Z ##

Parallels Desktop “ParaShells” Flaw Could Turn a Low-Privilege Mac Account into Root

A Dangerous Boundary Inside the Mac A critical vulnerability in Parallels Desktop for Mac has exposed a particularly dangerous security boundary: the gap between an ordinary local user and the root account. Tracked as CVE-2026-90894 and dubbed “ParaShells” by JFrog researchers, the flaw can reportedly allow an unprivileged local attacker to execute attacker-controlled code with root…

undercodenews.com/parallels-de

##

CVE-2026-12518(CVSS UNKNOWN)

EPSS: 0.11%

updated 2026-09-14T09:31:09

1 posts

A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileged local user to execute arbitrary code as SYSTEM.

CVE-2026-89501
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-13T09:33:28

1 posts

In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Hold cpu_buffer::lock when resizing a subbuf Because, ring_buffer_subbuf_order_set() can clear cpu_buffer->free_page, hold cpu_buffer->lock to prevent races with ring_buffer_alloc_read_page() and ring_buffer_free_read_page().

hugovalters@mastodon.social at 2026-09-16T04:10:21.000Z ##

CVE-2026-89501 Linux kernel ring-buffer race on subbuf resize, unpatched, CVSS N/A. Update immediately. valtersit.com/cve/CVE-2026-895 #CVE #Linux #infosec

##

CVE-2026-80981
(9.8 CRITICAL)

EPSS: 0.59%

updated 2026-09-13T09:33:25

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() smc_llc_srv_add_link() keeps add_llc pointing into the queue entry: add_llc = &qentry->msg.add_link; smc_llc.c:1482 ... smc_llc_save_add_link_info(link_new, add_llc); smc_llc.c:1494 smc_llc_flow_qentry_del(&lgr->llc_flow_lcl); smc_llc.c:1495 ..

hugovalters@mastodon.social at 2026-09-15T20:40:10.000Z ##

CVE-2026-80981 Linux kernel use-after-free in net/smc smc_llc_srv_add_link. CVSS N/A, patch status unknown. Update your kernel now. valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-81006
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-13T09:33:21

1 posts

In the Linux kernel, the following vulnerability has been resolved: ipmi: Remove all sysfs files on registration failure ipmi_add_smi() creates the nr_users and nr_msgs files before trying to create the maintenance_mode file. If that last creation fails, the error path removes only nr_users before dropping the final reference to the interface. Remove nr_msgs as well so no sysfs attribute embedd

hugovalters@mastodon.social at 2026-09-15T03:30:01.000Z ##

CVE-2026-81006 Linux kernel ipmi: failed registration leaves sysfs files on freed memory, risking use-after-free. CVSS N/A, patch status unknown. Update your kernel now. valtersit.com/cve/CVE-2026-810 #CVE #Linux #infosec

##

CVE-2026-80995
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-13T07:17:06.230000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: mctp: hold a reference to the route device in mctp_route_lookup() mctp_route_lookup() uses rt->dev without holding a reference on it. mctp_route_lookup_single() returns the route under RCU only, so the route's device can be torn down concurrently: mctp_dev_put() drops the last reference and synchronously kfree()s mdev->addr

hugovalters@mastodon.social at 2026-09-15T17:30:02.000Z ##

CVE-2026-80995 Linux kernel use-after-free in mctp_route_lookup can crash systems, possibly worse. No CVSS, no patch yet. Track it and update the moment a fix lands. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80955
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-13T07:17:02.700000

1 posts

In the Linux kernel, the following vulnerability has been resolved: dm-pcache: fix use-after-free and invalid seg operations in kset_replay() In kset_replay, when key->seg_gen is stale (key->seg_gen < key->cache_pos.cache_seg->gen), cache_key_put(key) is called but then key->cache_pos.cache_seg is accessed as the argument to cache_seg_get(). This is a use-after-free on the freed key memory. Alth

hugovalters@mastodon.social at 2026-09-17T07:10:01.000Z ##

CVE-2026-80955 Linux kernel dm-pcache use-after-free in kset_replay(). CVSS N/A. Patch status unknown. Update now. valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-80945
(9.1 CRITICAL)

EPSS: 0.47%

updated 2026-09-13T07:17:01.827000

1 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - unmap dst before software fallback on decompress On a hardware analytics error, decompress retries through the software fallback, which writes req->dst with the CPU while it is still mapped DMA_FROM_DEVICE. With SWIOTLB active the later dma_unmap_sg() copies the stale bounce buffer over req->dst, corrupting the res

hugovalters@mastodon.social at 2026-09-16T17:00:05.000Z ##

CVE-2026-80945 Linux kernel: IAA decompress race corrupts output via stale SWIOTLB bounce buffer on fallback. No CVSS, patch status unknown. Treat as unpatched. Check your kernel build now: valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-80943
(7.6 HIGH)

EPSS: 0.25%

updated 2026-09-13T07:17:01.543000

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids rtl92du_tx_fill_desc() uses ieee80211_get_tid() to read the QoS TID from the 802.11 header and then uses it as an index into sta_entry->tids[]. ieee80211_get_tid() returns the low 4-bit QoS TID value, so the result can be in the range 0..15. rtlwifi only allocates MAX

hugovalters@mastodon.social at 2026-09-16T12:20:03.000Z ##

CVE-2026-80943 Linux rtlwifi rtl8192du out-of-bounds access. CVSS N/A, patch status unknown. Update immediately. valtersit.com/cve/CVE-2026-809 #CVE #infosec #Linux

##

CVE-2026-80936
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-13T07:17:01.293000

1 posts

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: cancel mlo_pm_work on stop mt7925 queues mlo_pm_work with a 5 second delay during multi-link power-save setup and never cancels it on the stop path. If the device is torn down inside that window, the work outlives the teardown and its timer fires afterwards, trying to queue onto the workqueue that is already

hugovalters@mastodon.social at 2026-09-16T04:10:01.000Z ##

CVE-2026-80936 Linux mt76 mt7925: uncancelled mlo_pm_work fires after teardown, causing a use-after-free-style workqueue warning and kernel crash risk. CVSS N/A, unpatched - update your kernel now. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-85706
(10.0 CRITICAL)

EPSS: 11.96%

updated 2026-09-12T12:30:50

12 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

12 repos

https://github.com/gagaltotal/CVE-2026-85706-gitlab-poc

https://github.com/plur1bu5/gitread

https://github.com/gabrielunknown/CVE-2026-85706

https://github.com/solivaquaant/CVE-2026-85706

https://github.com/FlowerWitch/CVE-2026-85706_docker_exp

https://github.com/mhtsec/CVE-2026-85706

https://github.com/0xlyvio/cve-2026-85706-poc-exploit-gitlab

https://github.com/jithinkrishnanrs/gitlab-cve-2026-85706-ioc

https://github.com/brigadeops32/CVE-2026-85706

https://github.com/0xenesbayram/cve-2026-85706

https://github.com/guneykabel/cve-2026-85706

https://github.com/ynsmroztas/GitLabSniper

relayshieldadmin at 2026-09-16T18:20:40.798Z ##

GitLab CVE-2026-85706: unauth arbitrary file read, exploited in the wild, now on CISA KEV. Patch
19.3.2 / 19.2.6 / 19.1.8.
The 10.0 is about the read. The damage is the credentials inside the files, and a commits API
reads history, so secrets you deleted are still there.
Patch, hunt, THEN rotate. Rotating on a readable server hands over the new keys.
blog.relayshield.net/a-file-read-bug-is-a-credential-theft-bug

##

thecybermind at 2026-09-16T05:37:00.433Z ##

Actionable C-Suite threat intelligence for CVE-2026-85706, covering active path traversal exploitation vectors, endpoint hardening, and patch automation across GitLab environments. thecybermind.co/uzke

##

DailyCyberSecurity at 2026-09-16T04:17:24.317Z ##

Learn why CISA added GitLab CVE-2026-85706 to the Known Exploited Vulnerabilities catalog. Discover how this CVSS 10 flaw allows remote secret extraction.

meterpreter.org/gitlab-cve-202

##

eric.zip@bsky.brid.gy at 2026-09-16T02:09:52.270Z ##

Dropped some research and detection/hunt content on CVE-2026-85706 🤓

RE: https://bsky.app/profile/did:plc:lsvsraxh3ckc7frgv5p5d7gy/post/3mvl6a4xflz23

##

relayshieldadmin@infosec.exchange at 2026-09-16T18:20:40.000Z ##

GitLab CVE-2026-85706: unauth arbitrary file read, exploited in the wild, now on CISA KEV. Patch
19.3.2 / 19.2.6 / 19.1.8.
The 10.0 is about the read. The damage is the credentials inside the files, and a commits API
reads history, so secrets you deleted are still there.
Patch, hunt, THEN rotate. Rotating on a readable server hands over the new keys.
blog.relayshield.net/a-file-read-bug-is-a-credential-theft-bug
#GitLab #infosec #DevSecOps

##

thecybermind@infosec.exchange at 2026-09-16T05:37:00.000Z ##

Actionable C-Suite threat intelligence for CVE-2026-85706, covering active path traversal exploitation vectors, endpoint hardening, and patch automation across GitLab environments. thecybermind.co/uzke

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T04:17:24.000Z ##

Learn why CISA added GitLab CVE-2026-85706 to the Known Exploited Vulnerabilities catalog. Discover how this CVSS 10 flaw allows remote secret extraction.

#GitLab #CVE202685706 #CISA #CyberSecurity #Vulnerability

meterpreter.org/gitlab-cve-202

##

censys@infosec.exchange at 2026-09-15T15:32:12.000Z ##

🚨 GitLab CVE-2026-85706 is a critical CVSS 10.0 vulnerability under active exploitation.
Censys sees 86K+ GitLab hosts on the Internet.

Patch immediately. If your instance was exposed while vulnerable, rotate credentials and investigate for compromise. censys.com/advisory/cve-2026-8

#GitLab #Cybersecurity #Vulnerability #CVE

##

benzogaga33@mamot.fr at 2026-09-15T09:20:04.000Z ##

Comment la faille de GitLab peut mettre à nu vos serveurs goodtech.info/gitlab-faille-cr #Développement #Revuedepresse #Sécurité

##

hackmag@infosec.exchange at 2026-09-15T03:06:55.000Z ##

⚪️ Developers Urge Immediate Fix for Critical GitLab Vulnerability

🗨️ GitLab engineers have released patches for the critical CVE-2026-85706 vulnerability, which received the maximum CVSS score of 10 and allows an unauthenticated attacker to read arbitrary files on a server. Security researchers warn that attackers began attempting to exploit the…

🔗 hackmag.com/news/gitlab-patch?

#news

##

thecybermind@infosec.exchange at 2026-09-14T20:01:09.000Z ##

CRITICAL CISA KEV ALERT: CVE-2026-85706 targets GitLab CE/EE via path traversal in the repository commits API. Active exploitation verified. Access our TSUITE brief for SIEM detection queries and compensating controls to protect your CI/CD pipeline and isolate your secrets.

thecybermind.co/pcid

##

AAKL@infosec.exchange at 2026-09-14T17:47:44.000Z ##

New.

Rapid7: CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #infosec #GitLab #vulnerability

##

CVE-2026-78159
(9.8 CRITICAL)

EPSS: 0.76%

updated 2026-09-12T09:33:41

2 posts

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it p

offseq at 2026-09-16T12:00:26.810Z ##

CRITICAL: The Events Calendar WP plugin (<6.17.4.1) has two unauthenticated RCEs — CVE-2026-78159 (code injection) & CVE-2026-78006 (object injection, comments enabled). 240K+ sites at risk. Update now: radar.offseq.com/threat/unauth

##

offseq@infosec.exchange at 2026-09-16T12:00:26.000Z ##

CRITICAL: The Events Calendar WP plugin (<6.17.4.1) has two unauthenticated RCEs — CVE-2026-78159 (code injection) & CVE-2026-78006 (object injection, comments enabled). 240K+ sites at risk. Update now: radar.offseq.com/threat/unauth #OffSeq #WordPress #RCE #Vuln

##

CVE-2026-78006
(9.8 CRITICAL)

EPSS: 0.78%

updated 2026-09-12T09:33:41

2 posts

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attri

2 repos

https://github.com/user445213/CVE-2026-78006

https://github.com/DeadExpl0it/CVE-2026-78006-POC

offseq at 2026-09-16T12:00:26.810Z ##

CRITICAL: The Events Calendar WP plugin (<6.17.4.1) has two unauthenticated RCEs — CVE-2026-78159 (code injection) & CVE-2026-78006 (object injection, comments enabled). 240K+ sites at risk. Update now: radar.offseq.com/threat/unauth

##

offseq@infosec.exchange at 2026-09-16T12:00:26.000Z ##

CRITICAL: The Events Calendar WP plugin (<6.17.4.1) has two unauthenticated RCEs — CVE-2026-78159 (code injection) & CVE-2026-78006 (object injection, comments enabled). 240K+ sites at risk. Update now: radar.offseq.com/threat/unauth #OffSeq #WordPress #RCE #Vuln

##

CVE-2026-89506(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-09-11T21:31:37

1 posts

In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR The original commit missed that three drivers (mthca, irdma, siw) have UHW data associated with reg_mr that cannot be passed through the ioctl. They also assume that the udata cannot be NULL, so failing to pass a valid udata can trigger a NULL udata crash in those drivers.

hugovalters@mastodon.social at 2026-09-16T10:50:02.000Z ##

CVE-2026-89506 Linux kernel RDMA/uverbs NULL udata crash in mthca, irdma, siw drivers. No CVSS assigned, patch status unknown. Check your exposure and apply fixes when available. valtersit.com/cve/CVE-2026-895 #CVE #Linux #infosec

##

CVE-2026-89462(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-09-11T21:31:32

1 posts

In the Linux kernel, the following vulnerability has been resolved: power: supply: max17040: propagate register read errors max17040_get_vcell() and max17040_get_soc() ignore errors returned by regmap_read(). When an I2C transfer fails, the uninitialized register value is converted and reported to userspace as a valid voltage or state of charge. The polling worker can also replace the cached s

hugovalters@mastodon.social at 2026-09-17T03:30:15.000Z ##

CVE-2026-89462 Linux kernel max17040 power supply driver ignores I2C read errors, exposing uninitialized register data to userspace as valid voltage or state of charge. CVSS N/A, patch status unknown. Verify valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-80960(CVSS UNKNOWN)

EPSS: 0.20%

updated 2026-09-11T21:31:26

1 posts

In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate on-media seg_num against the cache device size seg_num is read from the crc32c-only superblock, so whoever supplies the cache device on a table load (CAP_SYS_ADMIN) controls it. It sizes cache->segments[] and is the value every later on-media segment id is bounded against, yet it is never checked against the

hugovalters@mastodon.social at 2026-09-16T04:20:03.000Z ##

CVE-2026-80960 Linux kernel dm-pcache out-of-bounds access via unchecked seg_num from on-media superblock. Can lead to memory corruption. CVSS N/A, patch status unknown. Patch now if you use dm-pcache. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-84869
(9.9 CRITICAL)

EPSS: 0.69%

updated 2026-09-11T21:31:17

5 posts

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

undercodenews@mastodon.social at 2026-09-16T20:23:06.000Z ##

Critical ScreenConnect Vulnerability Enters the Crosshairs as Attackers Exploit CVE-2026-84869 + Video

A New Remote-Access Security Crisis A critical vulnerability in ConnectWise ScreenConnect has moved from a security concern to an active exploitation problem, according to a September 16, 2026 alert shared by Cybersecurity News Everyday. The vulnerability, tracked as CVE-2026-84869, is reportedly being exploited in the wild and can provide attackers with capabilities…

undercodenews.com/critical-scr

##

thecybermind at 2026-09-16T14:42:24.127Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-84869 – ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

C-Suite threat intelligence and mitigation protocols for CVE-2026-84869, addressing active exploitation vectors within enterprise ConnectWise environments....

thecybermind.co/pxxw

##

thecybermind@infosec.exchange at 2026-09-16T14:42:24.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-84869 – ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

C-Suite threat intelligence and mitigation protocols for CVE-2026-84869, addressing active exploitation vectors within enterprise ConnectWise environments....

thecybermind.co/pxxw

##

beyondmachines1@infosec.exchange at 2026-09-15T11:01:13.000Z ##

ConnectWise Patches Critical ScreenConnect Flaw Exploited in Worm Attacks

ConnectWise fixed a critical vulnerability (CVE-2026-84869) in ScreenConnect that allows unauthorized file execution and worm-like propagation across remote sessions.

**If you use ConnectWise ScreenConnect, update to version 26.6.5 right away and then reinstall every host client. The update only takes effect once the clients are reinstalled, and this flaw is already being exploited to spread from machine to machine. If you can't patch, turn off the TransferFiles permission for all user roles as a mitigating measures. Don't forget to check integrated tools like ConnectWise Automate for their own patched versions.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

security_crawler_carl@infosec.exchange at 2026-09-14T19:46:27.000Z ##

🏆 New Achievement! The Help Desk Has Turned Against You!

PHASE ONE: ConnectWise ScreenConnect, your trusted remote support companion, enters the arena. PHASE TWO: CVE-2026-84869 awakens — CVSS 9.9, the kind of score that makes sysadmins physically leave their bodies. PHASE THREE: the worm-like propagation begins, chaining active remote sessions into unauthorized file transfers and full remote code execution. Huntress confirmed real-world exploitation. (1/2)

##

CVE-2026-42016
(8.1 HIGH)

EPSS: 0.89%

updated 2026-09-11T21:31:06

3 posts

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

thecybermind at 2026-09-16T13:23:43.009Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-42016 – JFrog Artifactory Incorrect Authorization Vulnerability

C-Suite threat intelligence for CVE-2026-42016, covering OAuth scope validation, lateral movement detection, and repository hardening across JFrog Artifactory instances....

thecybermind.co/0vaa

##

thecybermind@infosec.exchange at 2026-09-16T13:23:43.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-42016 – JFrog Artifactory Incorrect Authorization Vulnerability

C-Suite threat intelligence for CVE-2026-42016, covering OAuth scope validation, lateral movement detection, and repository hardening across JFrog Artifactory instances....

thecybermind.co/0vaa

##

thecybermind@infosec.exchange at 2026-09-14T17:10:44.000Z ##

CRITICAL CISA KEV ALERT: CVE-2026-42016 targets JFrog Artifactory via incorrect authorization and token scope flaws. Active exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to secure your software pipelines.

thecybermind.co/4u1b

##

CVE-2026-59971
(10.0 CRITICAL)

EPSS: 0.39%

updated 2026-09-11T20:36:20

1 posts

## Summary In SSE/HTTP transport mode, `mysql_mcp_server` constructs `SseServerTransport` without passing `security_settings`. As a result, the MCP Python SDK's DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and the service binds to `0.0.0.0` by default with no authentication on any route. **Trigger condition

thehackerwire@mastodon.social at 2026-09-15T16:01:54.000Z ##

🔴 CVE-2026-59971 - Critical (10)

MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_settings or ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89514
(0 None)

EPSS: 0.17%

updated 2026-09-11T20:19:33.913000

2 posts

In the Linux kernel, the following vulnerability has been resolved: scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock fnic_fcoe_process_vlan_resp() allocates a VLAN descriptor with kzalloc_obj() (default GFP_KERNEL) while holding vlans_lock via spin_lock_irqsave(). GFP_KERNEL may sleep, which is not allowed in this atomic context and can trigger a sleeping-from-invalid-context warning or

hugovalters@mastodon.social at 2026-09-16T07:40:01.000Z ##

CVE-2026-89514 Linux kernel fnic driver allocates memory with GFP_KERNEL under a spinlock, risking deadlock or crash. No CVSS, patch status unknown. Update kernel when fixes land. valtersit.com/cve/CVE-2026-895 #CVE #Linux #infosec

##

hugovalters@mastodon.social at 2026-09-16T07:40:01.000Z ##

CVE-2026-89514 Linux kernel fnic driver allocates memory with GFP_KERNEL under a spinlock, risking deadlock or crash. No CVSS, patch status unknown. Update kernel when fixes land. valtersit.com/cve/CVE-2026-895 #CVE #Linux #infosec

##

CVE-2026-89446
(0 None)

EPSS: 0.20%

updated 2026-09-11T20:19:25.110000

1 posts

In the Linux kernel, the following vulnerability has been resolved: iommufd: Release current IOAS on xa_store() failure iommufd_take_all_iova_rwsem() takes an object reference and the iova_rwsem write lock before storing the IOAS in the temporary ioas_list xarray. If xa_store() fails, the current IOAS has not been inserted into ioas_list yet. iommufd_release_all_iova_rwsem() only unwinds IOAS o

hugovalters@mastodon.social at 2026-09-16T13:50:03.000Z ##

CVE-2026-89446 Linux kernel iommufd IOAS ref leak on xa_store failure. No CVSS assigned yet, patch status unknown. Resource leak risk for iommufd users. Check your kernel version and update. valtersit.com/cve/CVE-2026-894 #CVE #Linux #infosec

##

CVE-2026-81861
(0 None)

EPSS: 0.38%

updated 2026-09-11T20:19:13.263000

2 posts

CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.

1 repos

https://github.com/abhinavagarwal07/scadapack-secure-lock-poc

cyberworldops at 2026-09-15T18:50:00.545Z ##

Schneider Electric disclosed CVE-2026-81861 (CWE-522) affecting SCADAPack x70 RTUs. Legacy Secure Lock insufficiently protects credentials, exposing RTU authentication data. Exposed credentials matter for OT as they can enable unauthorized access to monitoring and control functions.

cyberworldops.eu/en/schneider-

##

cyberworldops@infosec.exchange at 2026-09-15T18:50:00.000Z ##

Schneider Electric disclosed CVE-2026-81861 (CWE-522) affecting SCADAPack x70 RTUs. Legacy Secure Lock insufficiently protects credentials, exposing RTU authentication data. Exposed credentials matter for OT as they can enable unauthorized access to monitoring and control functions. #IcsSecurity #ScadaSecurity #OtSecurity

cyberworldops.eu/en/schneider-

##

CVE-2026-86060
(9.8 CRITICAL)

EPSS: 1.06%

updated 2026-09-11T12:52:16.507000

1 posts

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable

1 repos

https://github.com/bahirul/cve-2026-86060

thecybermind@infosec.exchange at 2026-09-14T18:30:04.000Z ##

CRITICAL CISA KEV ALERT: CVE-2026-86060 targets MikroTik RouterOS via improper argument delimiter neutralization and command injection. Active exploitation verified. Access our TSUITE brief for hardening steps and network segmentation protocols to secure your perimeter.

thecybermind.co/957k

##

CVE-2026-82079
(8.4 HIGH)

EPSS: 0.16%

updated 2026-09-11T03:31:25

3 posts

A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted network traffic. This issue affects Nintendo Switch: before 23.0.0.

nesbot@mastodon.social at 2026-09-16T18:07:36.000Z ##

[Sept 16, 2026] Nintendo Urges Switch Owners to Update Their Firmware After Security Exploit Discovered (CVE-2026-82079, fixed with firmware 23.0.0)
resetera.com/threads/1635112
#gaming #videogames #resetera

##

benzogaga33@mamot.fr at 2026-09-16T09:40:03.000Z ##

Nintendo Switch : une faille permet d’exécuter du code via le code QR affiché à l’écran it-connect.fr/nintendo-switch- #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

benzogaga33@mamot.fr at 2026-09-16T09:40:03.000Z ##

Nintendo Switch : une faille permet d’exécuter du code via le code QR affiché à l’écran it-connect.fr/nintendo-switch- #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

CVE-2026-59160
(8.8 HIGH)

EPSS: 0.41%

updated 2026-09-09T23:47:56

2 posts

## Unauthenticated Network-Exposed Turborepo Task Execution via /api/run ### Summary `@yeger/turbo-graph` starts its embedded Next.js server without binding to the loopback interface, causing it to listen on all network interfaces (`0.0.0.0:29312` by default). The `/api/run` HTTP endpoint exposed by this server performs no authentication, authorization, CSRF protection, or task allowlist check b

thehackerwire@mastodon.social at 2026-09-15T18:01:29.000Z ##

🟠 CVE-2026-59160 - High (8.8)

Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T18:01:29.000Z ##

🟠 CVE-2026-59160 - High (8.8)

Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20079
(10.0 CRITICAL)

EPSS: 75.75%

updated 2026-09-09T21:31:33

2 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerab

3 repos

https://github.com/CyberAuth/CVE-2026-20079

https://github.com/0xBlackash/CVE-2026-20079

https://github.com/DiegoArias008/CVE-2026-20079-checker

NetGuide@social.netguide.io at 2026-09-16T10:01:35.000Z ##

Cisco Secure FMC: Kritische Auth-Bypass-Lücke (CVSS 10.0) wird aktiv ausgenutzt

Cisco bestätigt, dass eine mit dem Höchstwert CVSS 10.0 bewertete Authentifizierungs-Bypass-Lücke (CVE-2026-20079) in seiner Secure Firewall Management Center (FMC) Software […]

netguide.io/news/de/2026/09/14

##

NetGuide@social.netguide.io at 2026-09-16T10:01:35.000Z ##

Cisco Secure FMC: Kritische Auth-Bypass-Lücke (CVSS 10.0) wird aktiv ausgenutzt

Cisco bestätigt, dass eine mit dem Höchstwert CVSS 10.0 bewertete Authentifizierungs-Bypass-Lücke (CVE-2026-20079) in seiner Secure Firewall Management Center (FMC) Software […]

netguide.io/news/de/2026/09/14

##

CVE-2026-58113
(6.1 MEDIUM)

EPSS: 0.22%

updated 2026-09-09T16:17:03.483000

2 posts

A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could al

cyberworldops at 2026-09-16T04:50:00.761Z ##

Siemens patched CVE-2026-58113, a reflected XSS (CWE-79) in Teamcenter /auth/ redirect flow. An unauthenticated attacker can craft a URL executing JavaScript in an authenticated user's session. Update all four affected branches.

cyberworldops.eu/en/siemens-pa

##

cyberworldops@infosec.exchange at 2026-09-16T04:50:00.000Z ##

Siemens patched CVE-2026-58113, a reflected XSS (CWE-79) in Teamcenter /auth/ redirect flow. An unauthenticated attacker can craft a URL executing JavaScript in an authenticated user's session. Update all four affected branches. #SiemensTeamcenter #CrossSiteScripting #PatchManagement

cyberworldops.eu/en/siemens-pa

##

CVE-2026-87827(CVSS UNKNOWN)

EPSS: 1.07%

updated 2026-09-09T12:32:22

1 posts

Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service can execute arbitrary system commands on the device, potentially resulting in complete compromise of the DVR. The vulnerability is known to have been exploited in t

CVE-2026-85880
(7.8 HIGH)

EPSS: 0.57%

updated 2026-09-09T05:18:19.193000

1 posts

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

youranonnewsirc@nerdculture.de at 2026-09-15T04:26:24.000Z ##

Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two actively exploited zero-days (CVE-2026-85880, CVE-2026-81963) allowing privilege escalation. Anthropic also revealed Russia-linked cyber-espionage groups are using Claude AI for hacking operations targeting government and defense organizations. Geopolitically, China is hosting a defense forum amid rising regional tensions over Taiwan and the South China Sea. In technology, OpenAI delayed its IPO beyond 2026, advocating for a global AI development slowdown.

#AnonNews_irc #Cybersecurity #News

##

CVE-2026-75650
(10.0 CRITICAL)

EPSS: 2.15%

updated 2026-09-09T05:18:07.237000

1 posts

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

5 repos

https://github.com/dinosn/cve-2026-75650-magento-validation-lab

https://github.com/jithinkrishnanrs/stylesmuggler-ioc-toolkit

https://github.com/fortbridge/stylesmuggler

https://github.com/disrex-group/stylesmuggler-adobe-patches

https://github.com/disrex-group/stylesmuggler-adobe-patches-mageos

CVE-2026-58240
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-09-09T05:17:26.417000

1 posts

SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confide

jurjen_heeck@mastodon.nl at 2026-09-16T06:57:24.000Z ##

CVE-2026-58240: From Patch Day to PoC in 96 Hours

securitybridge.com/blog/cve-20

"The takeaway for SAP security teams: the reasonable planning assumption is now days, not months between a patched CVE and public exploit tooling. If your patch process has ever taken longer than a week, that gap is real risk. Every kernel-level SAP HotNews should be treated as if there is already a working PoC in circulation — because increasingly, there is."

##

CVE-2026-15534
(5.7 MEDIUM)

EPSS: 0.17%

updated 2026-09-08T22:17:38.113000

2 posts

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the sig

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-81963
(7.8 HIGH)

EPSS: 0.63%

updated 2026-09-08T21:34:09

1 posts

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

youranonnewsirc@nerdculture.de at 2026-09-15T04:26:24.000Z ##

Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two actively exploited zero-days (CVE-2026-85880, CVE-2026-81963) allowing privilege escalation. Anthropic also revealed Russia-linked cyber-espionage groups are using Claude AI for hacking operations targeting government and defense organizations. Geopolitically, China is hosting a defense forum amid rising regional tensions over Taiwan and the South China Sea. In technology, OpenAI delayed its IPO beyond 2026, advocating for a global AI development slowdown.

#AnonNews_irc #Cybersecurity #News

##

CVE-2026-60004
(9.8 CRITICAL)

EPSS: 86.78%

updated 2026-09-08T17:56:31

2 posts

### Summary Gitea's `diffpatch` endpoint can be abused to install and execute a Git hook from repository-controlled content. An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user. With default open registration, an unauthenticated visitor can obtain the required write access by registering an account and creating a repository. ### Detai

10 repos

https://github.com/0xBlackash/CVE-2026-60004

https://github.com/HORKimhab/CVE-2026-60004

https://github.com/fevar54/cve-2026-60004

https://github.com/imbas007/CVE-2026-60004-POC

https://github.com/HackSpeak/CVE-2026-60004

https://github.com/gagaltotal/CVE-2026-60004-poc-gitea

https://github.com/EQSTLab/CVE-2026-60004

https://github.com/erberkan/CVE-2026-60004-PoC

https://github.com/shinthink/CVE-2026-60004

https://github.com/Sachinart/CVE-2026-60004-gitea-0day

VirusBulletin@infosec.exchange at 2026-09-15T08:43:23.000Z ##

Acronis TRU uncovered a multinational campaign in which Red Heron, a Chinese-speaking threat actor, rapidly weaponized CVE-2026-60004 to compromise internet-facing instances of Gitea, a self-hosted source-code management platform. acronis.com/en/tru/posts/red-h

##

cyberworldops@infosec.exchange at 2026-09-14T19:00:01.000Z ##

Red Heron exploited CVE-2026-60004, a critical Gitea RCE, to compromise 13 organizations after scanning 1,386 exposed instances. Exposed dev platforms offer direct access to code and lateral movement. Patch, restrict exposure and review logs. #GiteaSecurity #ThreatIntel #SupplyChain

cyberworldops.eu/en/red-heron-

##

CVE-2026-48888
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-08T13:12:58.310000

1 posts

Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0.

wpguyuk@infosec.exchange at 2026-09-15T07:04:31.000Z ##

WooCommerce CVE-2026-48888 is a high-severity flaw an attacker can exploit with no account and no elevated permissions. If my clients have not updated to 11.1.0, their customer data and payment layer are exposed right now. I recommend updating immediately.

#WordPress #WooCommerce #CVE #SecurityHardening #WordPressSecurity

wpguy.uk/blog/woocommerce-cve-

##

CVE-2026-15315
(8.8 HIGH)

EPSS: 0.30%

updated 2026-09-04T18:32:18

4 posts

Tapo C200 v5 contains an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions,

1 repos

https://github.com/HORKimhab/CVE-2026-15315

AAKL at 2026-09-16T16:32:55.863Z ##

In case you didn't have enough problems with cameras, here's another one.

OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras opswat.com/blog/authentication

More:

Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping infosecurity-magazine.com/news

##

security_crawler_carl at 2026-09-16T13:10:27.580Z ##

🏆 New Achievement! Smile, You're on Hacked Camera!

Step right up! For the low, low price of plugging a TP-Link Tapo C200 into your home network, you received two zero-days absolutely free of charge. OPSWAT discovered CVE-2026-15315, a replay-based authentication bypass letting any network-adjacent attacker waltz — sorry, slide — into a valid admin session without ever knowing your password. (1/2)

##

AAKL@infosec.exchange at 2026-09-16T16:32:55.000Z ##

In case you didn't have enough problems with cameras, here's another one.

OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras opswat.com/blog/authentication

More:

Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping infosecurity-magazine.com/news #infosec #vulnerability #spyware #zeroday #threatresearch

##

security_crawler_carl@infosec.exchange at 2026-09-16T13:10:27.000Z ##

🏆 New Achievement! Smile, You're on Hacked Camera!

Step right up! For the low, low price of plugging a TP-Link Tapo C200 into your home network, you received two zero-days absolutely free of charge. OPSWAT discovered CVE-2026-15315, a replay-based authentication bypass letting any network-adjacent attacker waltz — sorry, slide — into a valid admin session without ever knowing your password. (1/2)

##

CVE-2026-80863(CVSS UNKNOWN)

EPSS: 0.18%

updated 2026-09-04T18:31:40

1 posts

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix OOB in free_rd_atomic_resources() free_rd_atomic_resources() iterates using qp->attr.max_dest_rd_atomic. Updating max_dest_rd_atomic before freeing the old array can make the free path walk past the old allocation and trigger a slab out-of-bounds write catched by KASAN: =============================================

sigint@fosstodon.org at 2026-09-16T23:45:07.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-09-17

Another Linux kernel CVE patched in Ubuntu. If you run kernel-backed containers or KVM hosts, queue your reboots and check ABI bumps before assuming a live-patch covers it.

🔗 vulners.com/osv/OSV:UBUNTU-CVE

#Ubuntu #Linux #infosec

##

CVE-2026-15316
(6.5 MEDIUM)

EPSS: 0.23%

updated 2026-09-04T18:31:13

4 posts

An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5.  An attacker can send oversized crypted ciphertext values that may trigger exception handling failures, due to insufficient validation, causing the affected device to crash or restart. Successful exploitation may temporarily disrupt HTTPS manage

1 repos

https://github.com/HORKimhab/CVE-2026-15315

AAKL at 2026-09-16T16:32:55.863Z ##

In case you didn't have enough problems with cameras, here's another one.

OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras opswat.com/blog/authentication

More:

Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping infosecurity-magazine.com/news

##

security_crawler_carl at 2026-09-16T13:10:27.721Z ##

CVE-2026-15316 throws in a denial-of-service against the onboarding flow as a bonus gift with purchase.

Perhaps you'd like our Extended Vulnerability Warranty? Only $49.99. Or — and hear me out — you could just update your Tapo C200 to firmware V5_1.4.6, released August 18, for the remarkable price of free.

Reward: You've received a slightly-used Tin Foil Lens Cap. Refurbished. Non-returnable.

infosecurity-magazine.com/news

(2/2)

##

AAKL@infosec.exchange at 2026-09-16T16:32:55.000Z ##

In case you didn't have enough problems with cameras, here's another one.

OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras opswat.com/blog/authentication

More:

Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping infosecurity-magazine.com/news #infosec #vulnerability #spyware #zeroday #threatresearch

##

security_crawler_carl@infosec.exchange at 2026-09-16T13:10:27.000Z ##

CVE-2026-15316 throws in a denial-of-service against the onboarding flow as a bonus gift with purchase.

Perhaps you'd like our Extended Vulnerability Warranty? Only $49.99. Or — and hear me out — you could just update your Tapo C200 to firmware V5_1.4.6, released August 18, for the remarkable price of free.

Reward: You've received a slightly-used Tin Foil Lens Cap. Refurbished. Non-returnable.

infosecurity-magazine.com/news

#ZeroDay #CyberSecurity (2/2)

##

CVE-2026-80881
(0 None)

EPSS: 0.17%

updated 2026-09-04T17:17:00.390000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix buffer head management in ocfs2_read_blocks() In ocfs2_read_blocks(), caller should't assume that buffer head returned by 'sb_getblk()' is exclusively owned and so 'put_bh()' always drops b_count from 1 to 0. If it is not so, buffer head remains on hold and likely to be returned by the next call to 'sb_getblk()' unch

sigint@fosstodon.org at 2026-09-15T23:45:08.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-09-16

Another kernel CVE patched upstream and in Ubuntu. If you run your own kernel builds or LTS HWE stacks, check this against your running version before your next reboot window.

🔗 vulners.com/osv/OSV:UBUNTU-CVE

#Ubuntu #Linux #infosec

##

CVE-2026-81572
(7.8 HIGH)

EPSS: 0.17%

updated 2026-09-01T20:56:59.203000

1 posts

In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that poin

certvde@infosec.exchange at 2026-09-15T08:17:37.000Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

#OT #Advisory

##

CVE-2026-81576
(7.7 HIGH)

EPSS: 0.33%

updated 2026-09-01T20:56:59.203000

1 posts

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.

certvde@infosec.exchange at 2026-09-15T08:17:37.000Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

#OT #Advisory

##

CVE-2026-56210
(7.1 HIGH)

EPSS: 0.31%

updated 2026-09-01T13:19:50.477000

2 posts

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can inf

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-39113
(4.0 None)

EPSS: 0.21%

updated 2026-08-31T18:31:16

2 posts

Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11) and later snapshots/builds allows an attacker to cause a denial of service via the ext/misc/sqlar.c, sqlarUncompressFunc(), sqlar_uncompress(), sqlite3_value_int

1 repos

https://github.com/20000419/CVE-2026-39113

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-56211
(7.1 HIGH)

EPSS: 0.48%

updated 2026-08-31T15:34:31

2 posts

A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In fork-based video processing services, an attacker can use this to hijack the cyclic

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-56208
(7.6 HIGH)

EPSS: 0.42%

updated 2026-08-31T15:34:31

2 posts

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-56209
(7.1 HIGH)

EPSS: 0.35%

updated 2026-08-31T15:34:31

2 posts

An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then writes approximately 1,200 bytes at the attacker-controlled address. This is full

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-81574
(8.2 HIGH)

EPSS: 0.41%

updated 2026-08-27T12:30:27

1 posts

In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and remotely

certvde@infosec.exchange at 2026-09-15T08:17:37.000Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

#OT #Advisory

##

CVE-2026-81573
(8.6 HIGH)

EPSS: 0.46%

updated 2026-08-27T12:30:27

1 posts

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the

certvde@infosec.exchange at 2026-09-15T08:17:37.000Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

#OT #Advisory

##

CVE-2026-81575
(7.5 HIGH)

EPSS: 0.44%

updated 2026-08-27T12:30:26

1 posts

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a segmentation fault that ultimately crashes the CodeMeter Runtime.

certvde@infosec.exchange at 2026-09-15T08:17:37.000Z ##

🔒 New CSAF advisory published

VDE-2026-091
TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities
CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, CVE-2026-81576

The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowin…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: trumpf.csaf-tp.certvde.com/.we

#OT #Advisory

##

CVE-2026-56368
(3.7 LOW)

EPSS: 0.26%

updated 2026-08-26T20:48:48

1 posts

A memory leak vulnerability exists in multiple coders that write raw pixel data where an object is not freed. ``` Direct leak of 160 byte(s) in 1 object(s) allocated from: ```

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 45.88%

updated 2026-08-18T18:32:52

2 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

2 repos

https://github.com/BiuTrap/CVE-2026-59310

https://github.com/HORKimhab/CVE-2026-59310

undercodenews@mastodon.social at 2026-09-16T20:14:48.000Z ##

CISA Warns Ransomware Gangs Are Exploiting Critical VMware vCenter RCE Vulnerability + Video

A Critical Warning for Virtual Infrastructure A dangerous VMware vCenter vulnerability has moved into a far more serious phase. CVE-2026-59310, a critical directory traversal vulnerability affecting the vCenter Server Syslog component, is now associated with ransomware activity, according to the latest reporting on CISA's Known Exploited Vulnerabilities program. The…

undercodenews.com/cisa-warns-r

##

undercodenews@mastodon.social at 2026-09-15T17:41:50.000Z ##

CISA Warns VMware vCenter Flaw Is Now in the Hands of Ransomware Gangs + Video

CISA Warns VMware vCenter Flaw Is Now in the Hands of Ransomware Gangs A Critical VMware Vulnerability Has Entered a More Dangerous Phase A critical vulnerability in VMware vCenter Server has moved from a serious patching concern to an active ransomware threat. CISA has warned that ransomware operators are now exploiting CVE-2026-59310, a critical directory-traversal vulnerability that can…

undercodenews.com/cisa-warns-v

##

CVE-2026-19487
(5.3 MEDIUM)

EPSS: 0.42%

updated 2026-08-13T21:37:11

2 posts

Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass. The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-17T00:13:30.000Z ##

#Ubuntu 24.04.5 で #update

aom (3.8.2-2ubuntu0.2)
CVE-2026-56208, CVE-2026-56209, CVE-2026-56210, CVE-2026-56211へのセキュリティ対応。
ibaom3

perl (5.38.2-3.2ubuntu0.6)
CVE-2026-15534、CVE-2026-19487へのセキュリティ対応。
libperl5.38t64
perl-base
perl-modules-5.38

sqlite3 (3.45.1-1ubuntu2.8)
CVE-2026-39113へのセキュリティ対応。
libsqlite3-0

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-62721
(7.8 HIGH)

EPSS: 0.41%

updated 2026-08-11T18:31:23

1 posts

Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.

briankrebs@infosec.exchange at 2026-09-14T20:43:08.000Z ##

Microsoft today released an out of band update that includes a security update to a vulnerability they first patched in August. I guess the first patch didn't work broadly enough or introduced more flaws (or both). According to MS, though, there aren't any signs this vulnerability is actively being exploited. MS just says "The CVE was updated with links to security updates for Windows 11, version 26H1, 25H2, and 24H2 to address a missed fix."

support.microsoft.com/en-us/se

msrc.microsoft.com/update-guid

##

CVE-2026-5430
(10.0 CRITICAL)

EPSS: 0.32%

updated 2026-08-10T12:35:29.103000

6 posts

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of adm

1 repos

https://github.com/HORKimhab/CVE-2026-5430

netsecio@mastodon.social at 2026-09-16T16:03:11.000Z ##

📰 Critical WSO2 API Flaw Under Active Attack, Exposes Enterprise Data

Critical auth bypass (CVE-2026-5430, CVSS 10.0) in WSO2 API Manager is now actively exploited. Attackers can take over admin accounts. Patched in April 2026, ensure your systems are updated! #WSO2 #APISecurity #CyberAttack

🔗 cyber.netsecops.io/articles/cr

##

security_crawler_carl at 2026-09-16T10:21:45.670Z ##

The prosecution notes that your API interception layer, by design, sits squarely between attackers and internal systems, creating what the record describes as "Lateral Movement-as-a-Service." Administrative accounts, sensitive data in transit — all fair game.

Sentencing is immediate. Apply the April patch for CVE-2026-5430 and audit your JWT token validation and administrative account access without further delay. (2/3)

##

security_crawler_carl at 2026-09-16T10:21:45.514Z ##

🏆 New Achievement! The Honorable CVE-2026-5430 Finds You Guilty!

The court has reviewed the evidence. WSO2 API Manager, you stand charged with allowing JWT authentication to be bypassed via an unsupported signing algorithm — a flaw patched in April that threat actors are now actively exploiting in the wild. WatchTowr delivered the indictment on Tuesday. (1/3)

##

Analyst207@mastodon.social at 2026-09-16T07:04:14.000Z ##

WSO2 API Manager Flaw Sees Active Exploitation Attempts

A critical flaw in WSO2 API Manager, tracked as CVE-2026-5430, is under active exploitation, allowing hackers to bypass JWT authentication and gain unauthorized access with a CVSS score of 9.8 out of 10.0, potentially leading to account takeover and compromise of administrative accounts.

osintsights.com/wso2-api-manag

#Cve20265430 #Wso2ApiManager #JwtBypass #ApiSecurity #HacktronTeam

##

security_crawler_carl@infosec.exchange at 2026-09-16T10:21:45.000Z ##

The prosecution notes that your API interception layer, by design, sits squarely between attackers and internal systems, creating what the record describes as "Lateral Movement-as-a-Service." Administrative accounts, sensitive data in transit — all fair game.

Sentencing is immediate. Apply the April patch for CVE-2026-5430 and audit your JWT token validation and administrative account access without further delay. (2/3)

##

security_crawler_carl@infosec.exchange at 2026-09-16T10:21:45.000Z ##

🏆 New Achievement! The Honorable CVE-2026-5430 Finds You Guilty!

The court has reviewed the evidence. WSO2 API Manager, you stand charged with allowing JWT authentication to be bypassed via an unsupported signing algorithm — a flaw patched in April that threat actors are now actively exploiting in the wild. WatchTowr delivered the indictment on Tuesday. (1/3)

##

CVE-2026-15830
(5.3 MEDIUM)

EPSS: 1.26%

updated 2026-08-04T18:31:31

2 posts

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spa

djangonews@mastodon.social at 2026-09-16T20:00:11.000Z ##

[Django Fellow Reports] Django Fellow Report - Jacob

Jacob reviewed six Django pull requests and authored changes covering GEOS 3.10 support removal and expanded WKT depth-check coverage related to CVE-2026-15830.
forum.djangoproject.com/t/djan

##

djangonews@mastodon.social at 2026-09-16T20:00:11.000Z ##

[Django Fellow Reports] Django Fellow Report - Jacob

Jacob reviewed six Django pull requests and authored changes covering GEOS 3.10 support removal and expanded WKT depth-check coverage related to CVE-2026-15830.
forum.djangoproject.com/t/djan

##

CVE-2026-62946
(5.1 MEDIUM)

EPSS: 0.09%

updated 2026-08-03T16:19:22.763000

1 posts

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This issue has been fixed in versions 6.9.13-52 and 7.1.2-27.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-45659
(8.8 HIGH)

EPSS: 76.08%

updated 2026-07-23T11:10:00.120000

2 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

2 repos

https://github.com/WismanSec/sharepoint-2026-poc

https://github.com/HORKimhab/CVE-2026-45659

CVE-2026-61864
(2.9 LOW)

EPSS: 0.10%

updated 2026-07-15T12:32:06

1 posts

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory is not released.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-61863
(2.9 LOW)

EPSS: 0.19%

updated 2026-07-15T12:32:05

1 posts

ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting in a small memory leak.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-61866
(2.9 LOW)

EPSS: 0.19%

updated 2026-07-15T12:32:05

1 posts

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-61865
(2.9 LOW)

EPSS: 0.10%

updated 2026-07-15T12:32:05

1 posts

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation fails, a small memory leak occurs.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-61465
(3.3 LOW)

EPSS: 0.17%

updated 2026-07-14T15:17:09.260000

1 posts

ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a crafted image that causes ImageMagick to allocate more memory than permitted by the configured policy, resulting in a denial of service.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-56366
(3.3 LOW)

EPSS: 0.17%

updated 2026-07-14T02:16:56.757000

1 posts

ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-61870
(2.9 LOW)

EPSS: 0.19%

updated 2026-07-13T22:07:31.147000

1 posts

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted VIFF images to exhaust available memory and cause denial of service.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-56373
(3.7 LOW)

EPSS: 0.23%

updated 2026-07-13T15:15:51.143000

1 posts

ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a single zero byte to freed memory.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-61857
(3.7 LOW)

EPSS: 0.27%

updated 2026-07-11T15:30:30

1 posts

ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-55945
(4.2 MEDIUM)

EPSS: 0.19%

updated 2026-07-03T21:31:47

1 posts

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

sayzard@mastodon.sayzard.org at 2026-09-16T19:41:05.000Z ##

With 1 Extension: $20K in Bounties from Anthropic, Perplexity, Google, Microsoft

Forever Security 연구진은 브라우저 확장 프로그램의 콘텐츠 스크립트·DNR(Declarative Net Request) 권한을 악용해 내장 AI 에이전트를 가로채는 ‘BragJack’ 공격군을 공개했습니다. Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, Claude in Chrome에서 총 5건의 취약점(CVE-2026-0628, CVE-2026-55945 포함)을 보고했으며, 일부 경우 사용자 클릭 없이 로컬 파일·브...

forever.security/blog/bragjack

##

CVE-2026-56371
(5.3 MEDIUM)

EPSS: 0.26%

updated 2026-07-02T15:17:07.390000

1 posts

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each time a crafted TXT file with a texture attribute is processed.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-56379(CVSS UNKNOWN)

EPSS: 0.88%

updated 2026-06-30T03:38:15

1 posts

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-47203(CVSS UNKNOWN)

EPSS: 0.45%

updated 2026-06-26T21:32:44

2 posts

### Impact **CVSSv4 Baseline Score:** Moderate 6.3 **CVSSv4 Weighted Score:** Low 2.9 The full CVSSv4 Vector for this vulnerability is: > CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:L/IR:L/AR:L/MAV:N/MAC:H/MAT:N/MPR:N/MUI:N/MVC:L/MVI:N/MVA:N/MSC:N/MSI:N/MSA:N/S:N/AU:Y/R:U/V:D/RE:L/U:Green **CVSSv3.1 Baseline Score:** Low 3.7 **CVSSv3.1 Overall Score:** Medium 4.0

IanTwenty@piefed.social at 2026-09-15T19:05:41.993Z ##

Say that new authelia exploit looks like one fail2ban already recognises or relies on timing/brute-force then you’re covered even before a patch is available.

Here’s a real authelia vuln:

https://app.opencve.io/cve/CVE-2026-47203

allowing an attacker to circumvent login throttling or account lockouts by simply altering the case of their credentials.

I think fail2ban would help protect authelia here?

##

IanTwenty@piefed.social at 2026-09-15T19:05:41.993Z ##

Say that new authelia exploit looks like one fail2ban already recognises or relies on timing/brute-force then you’re covered even before a patch is available.

Here’s a real authelia vuln:

https://app.opencve.io/cve/CVE-2026-47203

allowing an attacker to circumvent login throttling or account lockouts by simply altering the case of their credentials.

I think fail2ban would help protect authelia here?

##

CVE-2026-56378
(3.7 LOW)

EPSS: 0.22%

updated 2026-06-26T13:41:36.727000

1 posts

ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-56370
(3.3 LOW)

EPSS: 0.12%

updated 2026-06-24T13:10:05

1 posts

When the `connected-components:*` define specifies an invalid index and out of bound operation will result in an access violation.

ottoto2017@prattohome.com at 2026-09-15T00:51:24.000Z ##

#Ubuntu 24.04.5 で #update

imagemagick (8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13)
CVE-2026-56366, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56373, CVE-2026-56378, CVE-2026-56379, CVE-2026-61465, CVE-2026-61857, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61870, CVE-2026-62946へのセキュリティ対応。
imagemagick-6-common imagemagick-6.q16
libmagickcore-6.q16-7-extra libmagickcore-6.q16-7t64
libmagickwand-6.q16-7t64

セキュリティ対応なのでお早めに。

#prattohome #更新

##

CVE-2026-32746
(9.8 CRITICAL)

EPSS: 23.67%

updated 2026-06-17T10:36:18.783000

6 posts

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.

8 repos

https://github.com/danindiana/cve-2026-32746-mitigation

https://github.com/duduLiu8787/CVE-2026-32746-Exploit

https://github.com/watchtowrlabs/watchtowr-vs-telnetd-CVE-2026-32746

https://github.com/chosenonehacks/CVE-2026-32746

https://github.com/kaleth4/CVE-2026-32746

https://github.com/MonkeySeC-sys/Kangaroo

https://github.com/jeffaf/cve-2026-32746

https://github.com/ekomsSavior/telnet_scan

hnbot@chrispelli.fun at 2026-09-17T04:59:36.000Z ##

A 32-year-old bug walks into a Telnet server - labs.watchtowr.com/a-32-year-o

#hackernews

##

ngate@mastodon.social at 2026-09-17T04:59:21.000Z ##

😂 Oh, look, a bug older than some of you on this site! GNU #inetutils just realized their #Telnet server had a 32-year-old #exploit hiding like a dusty family heirloom. Who knew pre-auth RCE could double as a boomer joke? 🧐🔍
labs.watchtowr.com/a-32-year-o #bugreport #cybersecurity #humor #technews #HackerNews #ngated

##

h4ckernews@mastodon.social at 2026-09-17T04:59:17.000Z ##

A 32-year-old bug walks into a Telnet server

labs.watchtowr.com/a-32-year-o

Comments: news.ycombinator.com/item?id=4

#HackerNews #bugfix #cybersecurity #Telnet #server #technology #vulnerabilities #GNU #inetutils

##

sayzard@mastodon.sayzard.org at 2026-09-16T05:43:20.000Z ##

A 32-Year-Old Bug Walks into a Telnet Server

watchTowr는 GNU inetutils 기반 Telnetd의 LINEMODE SLC 협상 처리에 존재하는 1994년 기원 사전 인증 BSS 버퍼 오버플로우(CVE-2026-32746)를 분석했다. 공격자는 조작된 Telnet 옵션 협상 메시지로 고정 크기 전역 배열 뒤의 약 400바이트를 덮어쓸 수 있으며, Ubuntu·Debian·FreeBSD·NetBSD·Citrix NetScaler·macOS Tahoe 등 여러 포크 및 배포판에 영향이 확인됐다. 다만 입력이 3바이트 SLC 트리플릿과 프로토콜...

labs.watchtowr.com/a-32-year-o

##

ngate@mastodon.social at 2026-09-17T04:59:21.000Z ##

😂 Oh, look, a bug older than some of you on this site! GNU #inetutils just realized their #Telnet server had a 32-year-old #exploit hiding like a dusty family heirloom. Who knew pre-auth RCE could double as a boomer joke? 🧐🔍
labs.watchtowr.com/a-32-year-o #bugreport #cybersecurity #humor #technews #HackerNews #ngated

##

h4ckernews@mastodon.social at 2026-09-17T04:59:17.000Z ##

A 32-year-old bug walks into a Telnet server

labs.watchtowr.com/a-32-year-o

Comments: news.ycombinator.com/item?id=4

#HackerNews #bugfix #cybersecurity #Telnet #server #technology #vulnerabilities #GNU #inetutils

##

CVE-2026-27540
(9.0 CRITICAL)

EPSS: 2.32%

updated 2026-06-17T10:27:18.693000

5 posts

Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1.

1 repos

https://github.com/Nxploited/CVE-2026-27542-CVE-2026-27540-

cyberworldops at 2026-09-16T10:40:01.040Z ##

Attackers are actively exploiting CVE-2026-27540 in the WooCommerce Wholesale Lead Capture WordPress plugin to upload PHP web shells without authentication. The flaw affects a plugin with more than 6,000 active installations and can enable remote code execution.

cyberworldops.eu/en/attackers-

##

security_crawler_carl at 2026-09-15T19:55:23.914Z ##

🏆 New Achievement! Exceeded All KPIs Except Staying Uncompromised!

Your Q3 infrastructure review is in. Uptime: stellar. Deployment pipeline: smooth. WooCommerce Wholesale Lead Capture plugin: actively backdoored via CVE-2026-27540. That last one is what we in management call an "opportunity area."

Attackers are currently exploiting this critical flaw in the wild, planting PHP backdoors and achieving full takeover of WordPress stores. Everything was going so well, team. Really. (1/3)

##

undercodenews@mastodon.social at 2026-09-15T19:36:55.000Z ##

Critical WooCommerce Vulnerability Is Under Active Attack, Putting WordPress Stores at Risk of PHP Backdoors and Full Takeover + Video

Introduction: A WordPress Plugin Became an Open Door A critical vulnerability in the WooCommerce Wholesale Lead Capture plugin is now being actively exploited by attackers, turning a seemingly ordinary WordPress extension into a potential gateway for complete website compromise. The vulnerability, tracked as CVE-2026-27540, allows…

undercodenews.com/critical-woo

##

cyberworldops@infosec.exchange at 2026-09-16T10:40:01.000Z ##

Attackers are actively exploiting CVE-2026-27540 in the WooCommerce Wholesale Lead Capture WordPress plugin to upload PHP web shells without authentication. The flaw affects a plugin with more than 6,000 active installations and can enable remote code execution. #WordPressSecurity #VulnerabilityManagement #ThreatDetection

cyberworldops.eu/en/attackers-

##

security_crawler_carl@infosec.exchange at 2026-09-15T19:55:23.000Z ##

🏆 New Achievement! Exceeded All KPIs Except Staying Uncompromised!

Your Q3 infrastructure review is in. Uptime: stellar. Deployment pipeline: smooth. WooCommerce Wholesale Lead Capture plugin: actively backdoored via CVE-2026-27540. That last one is what we in management call an "opportunity area."

Attackers are currently exploiting this critical flaw in the wild, planting PHP backdoors and achieving full takeover of WordPress stores. Everything was going so well, team. Really. (1/3)

##

CVE-2026-0628
(8.8 HIGH)

EPSS: 6.63%

updated 2026-06-17T10:11:06.543000

1 posts

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

2 repos

https://github.com/fevar54/CVE-2026-0628-POC

https://github.com/sastraadiwiguna-purpleeliteteaming/Dissecting-CVE-2026-0628-Chromium-Extension-Privilege-Escalation

sayzard@mastodon.sayzard.org at 2026-09-16T19:41:05.000Z ##

With 1 Extension: $20K in Bounties from Anthropic, Perplexity, Google, Microsoft

Forever Security 연구진은 브라우저 확장 프로그램의 콘텐츠 스크립트·DNR(Declarative Net Request) 권한을 악용해 내장 AI 에이전트를 가로채는 ‘BragJack’ 공격군을 공개했습니다. Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, Claude in Chrome에서 총 5건의 취약점(CVE-2026-0628, CVE-2026-55945 포함)을 보고했으며, 일부 경우 사용자 클릭 없이 로컬 파일·브...

forever.security/blog/bragjack

##

CVE-2025-30208
(5.3 MEDIUM)

EPSS: 74.97%

updated 2026-06-17T09:08:21.517000

1 posts

Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses this limitation and returns the file content if it exists. This bypass exists because trailing separators such as `?` are removed in several places

23 repos

https://github.com/ThemeHackers/CVE-2025-30208

https://github.com/iSee857/CVE-2025-30208-PoC

https://github.com/sumeet-darekar/CVE-2025-30208

https://github.com/Lusensec/CVE-2025-30208

https://github.com/TH-SecForge/CVE-2025-30208

https://github.com/r0ngy40/CVE-2025-30208-Series

https://github.com/MiclelsonCN/CVE-2025-30208_POC

https://github.com/imbas007/CVE-2025-30208-template

https://github.com/lilil3333/Vite-CVE-2025-30208-EXP

https://github.com/keklick1337/CVE-2025-30208-ViteVulnScanner

https://github.com/cc3305/CVE-2025-30208

https://github.com/ThumpBo/CVE-2025-30208-EXP

https://github.com/0xshaheen/CVE-2025-30208

https://github.com/marino-admin/Vite-CVE-2025-30208-Scanner

https://github.com/nkuty/CVE-2025-30208-31125-31486-32395

https://github.com/HaGsec/CVE-2025-30208

https://github.com/jackieya/ViteVulScan

https://github.com/4m3rr0r/CVE-2025-30208-PoC

https://github.com/sadhfdw129/CVE-2025-30208-Vite

https://github.com/4xura/CVE-2025-30208

https://github.com/HazaVVIP/CVE-2025-30208

https://github.com/On1onss/CVE-2025-30208

https://github.com/xuemian168/CVE-2025-30208

cyberworldops@infosec.exchange at 2026-09-15T01:00:00.000Z ##

F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence

cyberworldops.eu/en/hackers-sc

##

CVE-2024-3400
(10.0 CRITICAL)

EPSS: 100.00%

updated 2026-06-17T07:44:11.533000

1 posts

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

45 repos

https://github.com/W01fh4cker/CVE-2024-3400-RCE-Scan

https://github.com/index2014/CVE-2024-3400-Checker

https://github.com/Yuvvi01/CVE-2024-3400

https://github.com/Yafiah-Darwesh/cs50-cyber-paloalto-oauth

https://github.com/h4x0r-dz/CVE-2024-3400

https://github.com/razureink/cve-2024-3400-panos_rce_reproduction

https://github.com/HackingLZ/panrapidcheck

https://github.com/FoxyProxys/CVE-2024-3400

https://github.com/CyprianAtsyor/letsdefend-cve2024-3400-case-study

https://github.com/SimoesCTT/-CTT-PAN-OS-EXPLOIT-CVE-2024-340

https://github.com/P4rC3L/Global-Protect_VPN_Vuln

https://github.com/Chocapikk/CVE-2024-3400

https://github.com/CyberBibs/SOC274---Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-3400-

https://github.com/0x0d3ad/CVE-2024-3400

https://github.com/GhassanSabir/CVE-2024-3400-poc

https://github.com/codeblueprint/CVE-2024-3400

https://github.com/andrelia-hacks/CVE-2024-3400

https://github.com/hashdr1ft/SOC274-Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-3400

https://github.com/0xr2r/CVE-2024-3400-Palo-Alto-OS-Command-Injection

https://github.com/wa6n3r/CVE-2024-3400

https://github.com/LoanVitor/CVE-2024-3400-

https://github.com/MurrayR0123/CVE-2024-3400-Compromise-Checker

https://github.com/swaybs/CVE-2024-3400

https://github.com/workshop748/CVE-2024-3400

https://github.com/ZephrFish/CVE-2024-3400-Canary

https://github.com/marconesler/CVE-2024-3400

https://github.com/Kr0ff/cve-2024-3400

https://github.com/zam89/CVE-2024-3400-pot

https://github.com/schooldropout1337/CVE-2024-3400

https://github.com/momika233/CVE-2024-3400

https://github.com/ihebski/CVE-2024-3400

https://github.com/CerTusHack/CVE-2024-3400-PoC

https://github.com/hahasagined/CVE-2024-3400

https://github.com/pwnj0hn/CVE-2024-3400

https://github.com/tfrederick74656/cve-2024-3400-poc

https://github.com/CONDITIONBLACK/CVE-2024-3400-POC

https://github.com/Ravaan21/CVE-2024-3400

https://github.com/ivan-n0v/cve-2024-3400

https://github.com/sxyrxyy/CVE-2024-3400-Check

https://github.com/AdaniKamal/CVE-2024-3400

https://github.com/Zedocun/PAN-OS-CVE-2024-3400-Command-Injection-Investigation

https://github.com/retkoussa/CVE-2024-3400

https://github.com/ak1t4/CVE-2024-3400

https://github.com/MrR0b0t19/CVE-2024-3400

https://github.com/terminalJunki3/CVE-2024-3400-Checker

hugovalters@mastodon.social at 2026-09-16T11:00:17.000Z ##

SOC triage: one curl call, CVE plus exploit status plus vendor fix, into your ticket.

curl "valtersit.com/api/v1/cve/CVE-2"

Metered, no seat fees. valtersit.com/cve/pricing/

##

CVE-2025-48595
(8.4 HIGH)

EPSS: 1.71%

updated 2026-06-02T21:30:39

2 posts

In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

3 repos

https://github.com/fevar54/CVE-2025-48595-Android-Framework-Integer-Overflow-

https://github.com/XiaoBaiLovesStirring/CVE-2025-48595-Exploit

https://github.com/HORKimhab/CVE-2025-48595

skyblitz@ieji.de at 2026-09-16T12:00:11.000Z ##

@GrapheneOS funny to see google fixing : CVE-2025-48595 that was fixed looooooong ago in your.

i don't see CVE-2026-58704, is it already fixed ?

bleepingcomputer.com/news/secu

##

skyblitz@ieji.de at 2026-09-16T12:00:11.000Z ##

@GrapheneOS funny to see google fixing : CVE-2025-48595 that was fixed looooooong ago in your.

i don't see CVE-2026-58704, is it already fixed ?

bleepingcomputer.com/news/secu

##

CVE-2026-39987
(9.8 CRITICAL)

EPSS: 98.95%

updated 2026-04-27T16:30:09

1 posts

## Summary Marimo (19.6k stars) has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint `/terminal/ws` lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., `/ws`) that correctly call `validate_auth()` for authentication, the `/terminal/ws` endpoint only checks the

25 repos

https://github.com/jasonbernier/CVE-2026-39987

https://github.com/MADA0L/CVE-2026-39987-Poc

https://github.com/iapetus12/cohort-htb

https://github.com/julichaan/CVE-2026-39987_POC

https://github.com/stapat1245/CVE-2026-39987-PoC

https://github.com/gbuyssens/CVE-2026-39987

https://github.com/Clara-M-Grossl/Exploit-Marimo

https://github.com/h3raklez/CVE-2026-39987

https://github.com/keraattin/CVE-2026-39987

https://github.com/Wind010/CVE-2026-39987_PoC

https://github.com/fevar54/marimo_CVE-2026-39987_RCE_PoC

https://github.com/M3PH1569/CVE-2026-39987-POC

https://github.com/rootdirective-sec/CVE-2026-39987-Lab

https://github.com/Nxploited/CVE-2026-39987

https://github.com/mki9/CVE-2026-39987_exploit

https://github.com/alreadyClosed/CVE-2026-39987

https://github.com/Ghxstsec/CVE-2026-39987

https://github.com/0xBlackash/CVE-2026-39987

https://github.com/Dhiaelhak-Rached/CVE-2026-39987-lab-or-marimo-cve-lab

https://github.com/K3ysTr0K3R/CVE-2026-39987

https://github.com/matesz44/cve-2026-39987

https://github.com/0xdeadroot/CVE-2026-39987-marimo-rce

https://github.com/dodeepsink/CVE-2026-39987.py

https://github.com/vanhari/CVE-2026-39987

https://github.com/HORKimhab/CVE-2026-39987

cyberworldops@infosec.exchange at 2026-09-15T14:50:01.000Z ##

Sysdig reports a human operator exploited CVE-2026-39987, a pre-auth RCE in Marimo, and pivoted from the notebook to an SSH bastion in eight seconds with a custom Python toolkit. It shows manual tradecraft can match automation speed, shrinking detection windows for exposed dev infrastructure. #MarimoRce #SshBastion #IncidentResponse

cyberworldops.eu/en/human-oper

##

CVE-2026-39364(CVSS UNKNOWN)

EPSS: 2.00%

updated 2026-04-07T22:16:19

3 posts

### Summary The contents of files that are specified by [`server.fs.deny`](https://vite.dev/config/server-options#server-fs-deny) can be returned to the browser. ### Impact Only apps that match the following conditions are affected: - explicitly exposes the Vite dev server to the network (using `--host` or [`server.host` config option](https://vitejs.dev/config/server-options.html#server-host)

ottoto2017@prattohome.com at 2026-09-15T05:47:23.000Z ##

「ハッカーがViteの開発サーバーを標的にAWSとAzureの機密情報を盗み出す 」: #BLEEPINGCOMPUTER

「インターネットに公開されているVite開発サーバーを標的とした大規模なスキャンキャンペーンが、AWSおよびAzure環境からクラウド認証情報と設定を盗み出そうとしている。

この攻撃は、Vite バージョン 7.1.0 から 7.3.2、および 8.x ブランチの 8.0.5 より前のバージョンにおいて、ファイルの読み取り/アクセス制御を回避できる深刻な脆弱性である CVE-2026-39364 を悪用するものです。

この脆弱性は4月7日に公表され、認証されていない攻撃者がHTTP GETリクエストのクエリパラメータを操作することで、セキュリティ制限を回避し、通常はアクセスできないはずの場所から平文のファイルを取得できるというものである。」

bleepingcomputer.com/news/secu

#prattohome

##

DailyCyberSecurity@infosec.exchange at 2026-09-15T01:40:44.000Z ##

The Vite development server vulnerability CVE-2026-39364 is exploited in mass scanning for credential harvesting. F5 Labs logged 32,000 events. Patch now.

#Vite #CVE202639364 #CloudSecurity #CredentialHarvesting #F5Labs #DevSecOps #FileDisclosure #InfoSec #AWS #MassScanning

securityonline.info/vite-cve-2

##

cyberworldops@infosec.exchange at 2026-09-15T01:00:00.000Z ##

F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence

cyberworldops.eu/en/hackers-sc

##

CVE-2025-31125
(5.3 MEDIUM)

EPSS: 58.46%

updated 2026-01-22T21:47:41

1 posts

### Summary The contents of arbitrary files can be returned to the browser. ### Impact Only apps explicitly exposing the Vite dev server to the network (using `--host` or [`server.host` config option](https://vitejs.dev/config/server-options.html#server-host)) are affected. ### Details - base64 encoded content of non-allowed files is exposed using `?inline&import` (originally reported as `?imp

7 repos

https://github.com/jackieya/ViteVulScan

https://github.com/harshgupptaa/Path-Transversal-CVE-2025-31125-

https://github.com/sunhuiHi666/CVE-2025-31125

https://github.com/0xgh057r3c0n/CVE-2025-31125

https://github.com/MuhammadWaseem29/Vitejs-exploit

https://github.com/nkuty/CVE-2025-30208-31125-31486-32395

https://github.com/xuemian168/CVE-2025-30208

cyberworldops@infosec.exchange at 2026-09-15T01:00:00.000Z ##

F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence

cyberworldops.eu/en/hackers-sc

##

CVE-2023-38198
(9.8 CRITICAL)

EPSS: 1.08%

updated 2024-10-30T21:30:36

2 posts

acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.

niconiconi@mk.absturztau.be at 2026-09-16T02:31:21.811Z ##

Using acme.sh to renew a certificate as root sounds like a RCE-as-root waiting to happen. A Web client written in pure shell, what could possibly go wrong? I just wrote a script to drop its own privilege when it calls acme.sh, so it's safe to use in a root cronjob.

After writing this, I found RCE-as-root is not just "waiting" to happen, it has already happened as CVE-2023-38198. Someone even argued the case as a possible mechanism responsible for the jabber.ru wiretapping incident.
https://remyhax.xyz/posts/reproducing-lawful-tls-wiretapping/

##

niconiconi@mk.absturztau.be at 2026-09-16T02:31:21.811Z ##

Using acme.sh to renew a certificate as root sounds like a RCE-as-root waiting to happen. A Web client written in pure shell, what could possibly go wrong? I just wrote a script to drop its own privilege when it calls acme.sh, so it's safe to use in a root cronjob.

After writing this, I found RCE-as-root is not just "waiting" to happen, it has already happened as CVE-2023-38198. Someone even argued the case as a possible mechanism responsible for the jabber.ru wiretapping incident.
https://remyhax.xyz/posts/reproducing-lawful-tls-wiretapping/

##

CVE-2024-20260
(8.6 HIGH)

EPSS: 0.62%

updated 2024-10-23T18:33:16

2 posts

A vulnerability in the VPN and management web servers of the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv), formerly Cisco Firepower Threat Defense Virtual, platforms could allow an unauthenticated, remote attacker to cause the virtual devices to run out of system memory, which could cause SSL VPN connection processing to slow down and eve

CVE-2024-45811
(5.3 MEDIUM)

EPSS: 1.06%

updated 2024-09-19T18:34:34

1 posts

### Summary The contents of arbitrary files can be returned to the browser. ### Details `@fs` denies access to files outside of Vite serving allow list. Adding `?import&raw` to the URL bypasses this limitation and returns the file content if it exists. ### PoC ```sh $ npm create vite@latest $ cd vite-project/ $ npm install $ npm run dev $ echo "top secret content" > /tmp/secret.txt # expected

cyberworldops@infosec.exchange at 2026-09-15T01:00:00.000Z ##

F5 observed mass scanning of exposed Vite dev servers exploiting CVE-2026-39364 and older flaws CVE-2025-30208, CVE-2025-31125, CVE-2024-45811. Stolen AWS/Azure credentials and deployment configs enable full cloud compromise, so isolate dev servers and rotate secrets. #Vite #CloudSecurity #ThreatIntelligence

cyberworldops.eu/en/hackers-sc

##

CVE-2024-3094
(10.0 CRITICAL)

EPSS: 85.97%

updated 2024-03-29T18:30:50

2 posts

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. The tarballs included extra .m4 files, which contained instructions for building with automake that did not exist in the repository. These instructions, through a series of complex obfuscations, extract a prebuilt object file from one of the test archives, which is then used to modify specific functions in t

90 repos

https://github.com/shefirot/CVE-2024-3094

https://github.com/iheb2b/CVE-2024-3094-Checker

https://github.com/extracoding-dozen/CVE-2024-3094

https://github.com/lypd0/CVE-2024-3094-Vulnerabity-Checker

https://github.com/hackingetico21/revisaxzutils

https://github.com/michalAshurov/writeup-CVE-2024-3094

https://github.com/badsectorlabs/ludus_xz_backdoor

https://github.com/ykhurshudyan-blip/CVE-2024-3094

https://github.com/gensecaihq/CVE-2024-3094-Vulnerability-Checker-Fixer

https://github.com/MagpieRYL/CVE-2024-3094-backdoor-env-container

https://github.com/Juul/xz-backdoor-scan

https://github.com/brinhosa/CVE-2024-3094-One-Liner

https://github.com/namegabevictoire01-sys/cs50-cybersecurity-final-project

https://github.com/amlweems/xzbot

https://github.com/x-cmd-build/xz

https://github.com/laxmikumari615/Linux---Security---Detect-and-Mitigate-CVE-2024-3094

https://github.com/TheTorjanCaptain/CVE-2024-3094-Checker

https://github.com/lockness-Ko/xz-vulnerable-honeypot

https://github.com/valeriot30/cve-2024-3094

https://github.com/vnchk1/sec_review_cve-2024-3094

https://github.com/dah4k/CVE-2024-3094

https://github.com/KaminaDuck/ansible-CVE-2024-3094

https://github.com/pentestfunctions/CVE-2024-3094

https://github.com/OpensourceICTSolutions/xz_utils-CVE-2024-3094

https://github.com/Horizon-Software-Development/CVE-2024-3094

https://github.com/AndreaCicca/Sicurezza-Informatica-Presentazione

https://github.com/Simplifi-ED/CVE-2024-3094-patcher

https://github.com/galacticquest/cve-2024-3094-detect

https://github.com/neuralinhibitor/xzwhy

https://github.com/weltregie/liblzma-scan

https://github.com/0xlane/xz-cve-2024-3094

https://github.com/hackura/xz-cve-2024-3094

https://github.com/hazemkya/CVE-2024-3094-checker

https://github.com/Michel-DV/xz-utils-backdoor-case-study

https://github.com/przemoc/xz-backdoor-links

https://github.com/BOSE122/CVE-2024-3094

https://github.com/ScrimForever/CVE-2024-3094

https://github.com/buluma/ansible-role-cve_2024_3094

https://github.com/HackerHermanos/CVE-2024-3094_xz_check

https://github.com/Preacher98/Report-XZ-Utils-CVE-2024-3094

https://github.com/Ava-Vispilio/CVE-2024-3094

https://github.com/Titus-soc/-CVE-2024-3094-Vulnerability-Checker-Fixer-Public

https://github.com/spidygal/CVE-2024-3094-Nmap-NSE-script

https://github.com/Mustafa1986/CVE-2024-3094

https://github.com/harekrishnarai/xz-utils-vuln-checker

https://github.com/teyhouse/CVE-2024-3094

https://github.com/hariskhalil555000-sketch/What-utility-does-CVE-2024-3094-refer-to-

https://github.com/encikayelwhitehat-glitch/CVE-2024-3094

https://github.com/ashwani95/CVE-2024-3094

https://github.com/Yuma-Tsushima07/CVE-2024-3094

https://github.com/mightysai1997/CVE-2024-3094

https://github.com/r0binak/xzk8s

https://github.com/FabioBaroni/CVE-2024-3094-checker

https://github.com/nnatsopoulos/xz-backdoor-research

https://github.com/mhicairo-hue/cs50-cybersecurity-final-project

https://github.com/bioless/xz_cve-2024-3094_detection

https://github.com/felipecosta09/cve-2024-3094

https://github.com/mightysai1997/CVE-2024-3094-info

https://github.com/Fractal-Tess/CVE-2024-3094

https://github.com/emirkmo/xz-backdoor-github

https://github.com/M1lo25/CS50FinalProject

https://github.com/jfrog/cve-2024-3094-tools

https://github.com/Security-Phoenix-demo/CVE-2024-3094-fix-exploits

https://github.com/bsekercioglu/cve2024-3094-Checker

https://github.com/mesutgungor/xz-backdoor-vulnerability

https://github.com/ackemed/detectar_cve-2024-3094

https://github.com/mrk336/CVE-2024-3094

https://github.com/stevehenderson/lab_xz_backdoor

https://github.com/ElinaNotElina/cve-2024-3094-analysis

https://github.com/jbnetwork-git/CVE-2024-3094-XZ-Utils-Check

https://github.com/24Owais/threat-intel-cve-2024-3094

https://github.com/robertdfrench/ifuncd-up

https://github.com/robertdebock/ansible-playbook-cve-2024-3094

https://github.com/h3raklez/CVE-2024-3094

https://github.com/wgetnz/CVE-2024-3094-check

https://github.com/vesjolyjd/Kaspersky_CVE-2024-3094

https://github.com/zpxlz/CVE-2024-3094

https://github.com/isuruwa/CVE-2024-3094

https://github.com/byinarie/CVE-2024-3094-info

https://github.com/been22426/CVE-2024-3094

https://github.com/0xBlackash/CVE-2024-3094

https://github.com/Dermot-lab/TryHack

https://github.com/MrBUGLF/XZ-Utils_CVE-2024-3094

https://github.com/ThomRgn/xzutils_backdoor_obfuscation

https://github.com/Bella-Bc/xz-backdoor-CVE-2024-3094-Check

https://github.com/Ikram124/CVE-2024-3094-analysis

https://github.com/fevar54/Detectar-Backdoor-en-liblzma-de-XZ-utils-CVE-2024-3094-

https://github.com/gustavorobertux/CVE-2024-3094

https://github.com/robertdebock/ansible-role-cve_2024_3094

https://github.com/devjanger/CVE-2024-3094-XZ-Backdoor-Detector

hugovalters@mastodon.social at 2026-09-17T03:20:30.000Z ##

CVE lookups in your build pipeline: one GET returns CVSS, affected vendors, and known exploits as JSON. Metered, no scraping.

curl valtersit.com/api/cve/CVE-2024

Pricing: valtersit.com/cve/pricing/

##

hugovalters@mastodon.social at 2026-09-16T03:20:23.000Z ##

Scraping NVD means rate limits, pagination, and schema drift you own forever. The ValtersIT CVE API returns normalized CVE, vendor, and exploit data in one call: curl valtersit.com/api/cve/CVE-2024 Pricing: valtersit.com/cve/pricing/

##

CVE-2026-87886
(0 None)

EPSS: 0.00%

9 posts

N/A

cisakevtracker@mastodon.social at 2026-09-16T20:00:47.000Z ##

CVE ID: CVE-2026-87886
Vendor: Acronis
Product: Backup
Date Added: 2026-09-16
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

sayzard@mastodon.sayzard.org at 2026-09-16T17:43:43.000Z ##

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis가 cPanel & WHM 및 Plesk용 백업 플러그인에서 Linux 로컬 권한 상승 취약점(CVE-2026-87886)이 제한적 표적 공격에 실제 악용된 정황을 공개했다. CVSS 7.8의 고위험 취약점으로, 낮은 권한의 공격자가 사용자 상호작용 없이 서버 권한을 상승시켜 민감 데이터 접근·변조 또는 시스템 중단을 일으킬 수 있다. cPanel & WHM 플러그인은 1.9.3 HF3(빌드 1.9.3.1021 이상), Plesk 확장은...

bleepingcomputer.com/news/secu

##

undercodenews@mastodon.social at 2026-09-16T09:29:06.000Z ##

Acronis Backup Vulnerability Exploited in the Wild: Critical Warning for cPanel and Plesk Hosting Servers

Introduction: A Quiet Privilege Escalation With Potentially Wide Consequences Acronis has released security updates for its Backup Plugin for cPanel & WHM and Backup Extension for Plesk after detecting limited, targeted exploitation of a high-severity local privilege-escalation vulnerability affecting Linux-based systems. CVE-2026-87886: What Happened? Tracked as…

undercodenews.com/acronis-back

##

undercodenews@mastodon.social at 2026-09-16T03:27:17.000Z ##

Acronis Backup Plugin Under Attack: Critical Linux Privilege Escalation Flaw Puts Hosting Servers at Risk + Video

A New Warning for Web Hosting Administrators Acronis has disclosed CVE-2026-87886, a high-severity Linux local privilege escalation vulnerability affecting its backup integrations for cPanel & WHM and Plesk. The vulnerability carries a CVSS score of 7.8 and, more importantly, Acronis says exploitation has already been detected in limited, targeted attacks…

undercodenews.com/acronis-back

##

cyberworldops at 2026-09-16T01:00:01.227Z ##

Acronis confirmed active exploitation of CVE-2026-87886, a CVSS 7.8 local privilege escalation in its backup plugin for cPanel and WHM and Plesk. Any local user on shared hosting could escalate to root and compromise all tenants, making immediate patching and audit critical.

cyberworldops.eu/en/acronis-wa

##

Analyst207@mastodon.social at 2026-09-15T22:03:31.000Z ##

Acronis Discloses Exploited Flaw in cPanel Backup Plugin

A high-severity flaw, CVE-2026-87886, has been discovered in the Acronis Backup plugin for cPanel &amp; WHM deployments, and it's been exploited in limited, targeted attacks. This Linux local privilege-escalation vulnerability has a CVSS severity score of 7.8, making it a critical issue that needs attention.

osintsights.com/acronis-disclo

#Cve202687886 #Acronis #Cpanel #Linux #LocalPrivilegeEscalation

##

undercodenews@mastodon.social at 2026-09-15T22:00:28.000Z ##

Acronis Backup Vulnerability Puts Linux Hosting Servers at Risk as Limited Attacks Begin + Video

Introduction: A Quiet Flaw With Serious Consequences A vulnerability hiding inside a widely used server-backup integration has turned into an urgent warning for Linux hosting administrators. Acronis has disclosed CVE-2026-87886, a high-severity local privilege escalation flaw affecting its backup integrations for cPanel & WHM and Plesk, two platforms commonly used to manage…

undercodenews.com/acronis-back

##

cisakevtracker@mastodon.social at 2026-09-16T20:00:47.000Z ##

CVE ID: CVE-2026-87886
Vendor: Acronis
Product: Backup
Date Added: 2026-09-16
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cyberworldops@infosec.exchange at 2026-09-16T01:00:01.000Z ##

Acronis confirmed active exploitation of CVE-2026-87886, a CVSS 7.8 local privilege escalation in its backup plugin for cPanel and WHM and Plesk. Any local user on shared hosting could escalate to root and compromise all tenants, making immediate patching and audit critical. #LinuxSecurity #PrivilegeEscalation #CpanelSecurity

cyberworldops.eu/en/acronis-wa

##

CVE-2026-61642
(0 None)

EPSS: 0.00%

2 posts

N/A

DailyCyberSecurity at 2026-09-16T00:32:00.460Z ##

Multiple critical Squid proxy vulnerabilities, including CVE-2026-61642, allow request smuggling and buffer overflows. Patch your servers immediately.

securityonline.info/squid-prox

##

DailyCyberSecurity@infosec.exchange at 2026-09-16T00:32:00.000Z ##

Multiple critical Squid proxy vulnerabilities, including CVE-2026-61642, allow request smuggling and buffer overflows. Patch your servers immediately.

#SquidProxy #CVE202661642 #Cybersecurity #Vulnerability #InfoSec

securityonline.info/squid-prox

##

CVE-2026-85498
(0 None)

EPSS: 0.00%

2 posts

N/A

ottoto2017@prattohome.com at 2026-09-16T00:18:47.000Z ##

#Ubuntu 24.04.5 で #update

krb5 (1.20.1-6ubuntu2.10)
セキュリティ対応ではない。
krb5-locales
libgssapi-krb5-2
libk5crypto3
libkrb5-3
libkrb5support0

netplan.io (1.1.2-8ubuntu1~24.04.3)
セキュリティ対応ではない。
libnetplan1
netplan-generator
python3-netplan

policykit-1 (124-2ubuntu1.24.04.4)
CVE-2026-85498へのセキュリティ対応。
libpolkit-agent-1-0
libpolkit-gobject-1-0
libsrt1.5-gnutls
polkitd

セキュリティ対応もあるので、お早めに。

#prattohome #更新

##

ottoto2017@prattohome.com at 2026-09-16T00:18:47.000Z ##

#Ubuntu 24.04.5 で #update

krb5 (1.20.1-6ubuntu2.10)
セキュリティ対応ではない。
krb5-locales
libgssapi-krb5-2
libk5crypto3
libkrb5-3
libkrb5support0

netplan.io (1.1.2-8ubuntu1~24.04.3)
セキュリティ対応ではない。
libnetplan1
netplan-generator
python3-netplan

policykit-1 (124-2ubuntu1.24.04.4)
CVE-2026-85498へのセキュリティ対応。
libpolkit-agent-1-0
libpolkit-gobject-1-0
libsrt1.5-gnutls
polkitd

セキュリティ対応もあるので、お早めに。

#prattohome #更新

##

CVE-2026-88065
(0 None)

EPSS: 0.37%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-15T22:00:50.000Z ##

🟠 CVE-2026-88065 - High (7.5)

`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/photo` and `...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T22:00:50.000Z ##

🟠 CVE-2026-88065 - High (7.5)

`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/photo` and `...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63443
(0 None)

EPSS: 0.42%

2 posts

N/A

thehackerwire@mastodon.social at 2026-09-15T18:01:40.000Z ##

🟠 CVE-2026-63443 - High (8.3)

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request U...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-15T18:01:40.000Z ##

🟠 CVE-2026-63443 - High (8.3)

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request U...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73496
(0 None)

EPSS: 0.33%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-14T21:00:46.000Z ##

🟠 CVE-2026-73496 - High (7.7)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlas...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites