## Updated at UTC 2026-07-24T17:57:53.586498

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-66027 8.3 0.00% 2 0 2026-07-24T17:17:34.993000 Suna before 0.9.102 contains a broken access control vulnerability in the messag
CVE-2026-8789 8.1 0.00% 2 0 2026-07-24T16:16:56.127000 The Easy Appointments plugin for WordPress is vulnerable to unauthorized modific
CVE-2026-57106 10.0 0.00% 2 0 2026-07-24T16:16:34.720000 Server-side request forgery (ssrf) in Data Quality allows an unauthorized attack
CVE-2026-64600 None 0.64% 2 2 2026-07-24T15:34:00 In the Linux kernel, the following vulnerability has been resolved: xfs: resamp
CVE-2026-58630 10.0 0.00% 2 0 2026-07-24T15:18:47.847000 Improper access control in Azure App Service allows an unauthorized attacker to
CVE-2026-56165 9.8 0.74% 1 0 2026-07-24T15:18:33.220000 Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker
CVE-2026-16730 5.5 0.00% 1 0 2026-07-24T15:17:12.307000 A flaw was found in dbus-broker. When the process file-descriptor limit is reach
CVE-2026-62825 10.0 0.70% 1 0 2026-07-24T13:18:28.327000 Improper authentication in Azure Key Vault allows an unauthorized attacker to el
CVE-2026-24727 0 0.67% 2 0 2026-07-24T13:17:34.217000 An unrestricted upload of file with dangerous type vulnerability in the e-paper
CVE-2026-14172 7.8 0.11% 2 0 2026-07-24T09:32:22 Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables
CVE-2026-12981 None 0.18% 1 0 2026-07-24T09:32:22 The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication
CVE-2026-15704 9.8 0.35% 4 0 2026-07-24T09:32:16 In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled
CVE-2026-16870 8.8 0.36% 2 0 2026-07-24T06:34:17 Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior
CVE-2026-54120 9.9 0.71% 2 0 2026-07-24T03:31:56 Improper input validation in Microsoft Surface allows an authorized attacker to
CVE-2026-56160 9.1 0.65% 3 0 2026-07-24T03:31:56 Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized att
CVE-2026-50517 9.9 1.25% 1 0 2026-07-24T03:31:55 Deserialization of untrusted data in M365 Copilot allows an authorized attacker
CVE-2026-10697 7.5 0.18% 1 0 2026-07-23T21:31:09 Improper Authentication vulnerability in Progress MOVEit Transfer. This issue a
CVE-2026-65917 8.8 0.36% 1 0 2026-07-23T18:31:49 CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct o
CVE-2026-47056 10.0 0.33% 1 0 2026-07-23T18:30:55.460000 Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware
CVE-2026-60217 10.0 0.45% 1 0 2026-07-23T18:30:41.573000 Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CVE-2026-16232 9.1 12.68% 5 1 2026-07-23T15:44:54.743000 An authentication bypass vulnerability in the Check Point SmartConsole login pro
CVE-2026-64811 7.8 0.13% 1 0 2026-07-23T12:32:54 In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible b
CVE-2026-50522 9.8 57.10% 2 1 2026-07-22T21:31:51 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-53359 8.8 0.91% 2 6 2026-07-22T19:07:43.103000 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: F
CVE-2026-54121 8.8 0.80% 6 1 2026-07-21T19:54:33.623000 Improper authorization in Active Directory Certificate Services (AD CS) allows a
CVE-2021-27137 8.1 16.49% 1 0 2026-07-21T18:30:50 An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An uns
CVE-2026-16242 9.4 0.37% 2 0 2026-07-20T09:31:15 A flaw was found in the Konnectivity proxy-server configuration for hosted contr
CVE-2026-42533 8.1 2.79% 2 6 2026-07-15T15:33:14 A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive
CVE-2026-50454 7.8 0.44% 2 0 2026-07-14T18:32:32 Relative path traversal in Windows User Interface Core allows an authorized atta
CVE-2026-11405 9.8 1.62% 2 1 2026-07-08T15:32:52 The web server binary /bin/httpd contains a hidden backdoor authentication mecha
CVE-2026-12569 9.8 2.26% 3 1 2026-06-26T15:33:15 A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
CVE-2025-66376 7.2 21.62% 4 0 2026-06-17T09:56:44.753000 Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Clas
CVE-2026-47668 10.0 4.34% 1 1 template 2026-06-05T16:25:28 ### Summary DbGate's JSON script runner (`POST /runners/start`) allows remote co
CVE-2026-0770 None 53.46% 2 7 template 2026-02-19T22:09:33 Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere R
CVE-2025-0679 4.3 0.29% 2 0 2025-05-22T15:35:02 An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 be
CVE-2026-61884 0 0.00% 2 0 N/A
CVE-2026-63030 0 97.92% 4 67 template N/A
CVE-2026-60137 0 77.97% 2 42 N/A
CVE-2026-25243 0 3.00% 1 3 N/A
CVE-2026-25589 0 1.38% 1 1 N/A

CVE-2026-66027
(8.3 HIGH)

EPSS: 0.00%

updated 2026-07-24T17:17:34.993000

2 posts

Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read pending prompt queues of all users, read or delete individual sessions, and inject arbitrary prompts into another user's sess

thehackerwire@mastodon.social at 2026-07-24T16:59:50.000Z ##

🟠 CVE-2026-66027 - High (8.3)

Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-24T16:59:50.000Z ##

🟠 CVE-2026-66027 - High (8.3)

Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8789
(8.1 HIGH)

EPSS: 0.00%

updated 2026-07-24T16:16:56.127000

2 posts

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary connection records from the `

thehackerwire@mastodon.social at 2026-07-24T17:00:27.000Z ##

🟠 CVE-2026-8789 - High (8.1)

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-24T17:00:27.000Z ##

🟠 CVE-2026-8789 - High (8.1)

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57106
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-07-24T16:16:34.720000

2 posts

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-07-24T17:00:48.000Z ##

🔴 CVE-2026-57106 - Critical (10)

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-24T17:00:48.000Z ##

🔴 CVE-2026-57106 - Critical (10)

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64600(CVSS UNKNOWN)

EPSS: 0.64%

updated 2026-07-24T15:34:00

2 posts

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently

2 repos

https://github.com/HORKimhab/CVE-2026-64600

https://github.com/0xBlackash/CVE-2026-64600

DailyCyberSecurity at 2026-07-24T13:31:15.831Z ##

Discover the RefluXFS Linux vulnerability (CVE-2026-64600) in XFS that allows local users to overwrite protected files and gain root privileges.

meterpreter.org/refluxfs-linux

##

DailyCyberSecurity@infosec.exchange at 2026-07-24T13:31:15.000Z ##

Discover the RefluXFS Linux vulnerability (CVE-2026-64600) in XFS that allows local users to overwrite protected files and gain root privileges.

#RefluXFS #CVE202664600 #LinuxKernel #Cybersecurity #XFS

meterpreter.org/refluxfs-linux

##

CVE-2026-58630
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-07-24T15:18:47.847000

2 posts

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-07-24T17:00:38.000Z ##

🔴 CVE-2026-58630 - Critical (10)

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-24T17:00:38.000Z ##

🔴 CVE-2026-58630 - Critical (10)

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56165
(9.8 CRITICAL)

EPSS: 0.74%

updated 2026-07-24T15:18:33.220000

1 posts

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-07-24T05:00:32.000Z ##

🔴 CVE-2026-56165 - Critical (9.8)

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16730
(5.5 MEDIUM)

EPSS: 0.00%

updated 2026-07-24T15:17:12.307000

1 posts

A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the db

dotstdy@mastodon.social at 2026-07-24T16:31:03.000Z ##

got a red hat cve for the bug i found trying out superluminal on linux. this means that i'm a SECURITY RESEARCHER now! access.redhat.com/security/cve

##

CVE-2026-62825
(10.0 CRITICAL)

EPSS: 0.70%

updated 2026-07-24T13:18:28.327000

1 posts

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

hugovalters@mastodon.social at 2026-07-24T11:08:38.000Z ##

CVE-2026-62825 - Critical auth bypass in Azure Key Vault. CVSS 10.0. No patch available. Attackers can elevate privileges over network. Mitigate immediately. #CVE #Azure #infosec

valtersit.com/cve/CVE-2026-628

##

CVE-2026-24727
(0 None)

EPSS: 0.67%

updated 2026-07-24T13:17:34.217000

2 posts

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.

offseq at 2026-07-24T10:30:26.154Z ##

CVE-2026-24727 (CRITICAL, CVSS 9.3): SUNNET Corporate Training Mgmt System v10.3 allows admins to upload ZIP files with executable code, enabling server command execution. No patch yet — restrict admin access & monitor uploads. radar.offseq.com/threat/cve-20 🛡️

##

offseq@infosec.exchange at 2026-07-24T10:30:26.000Z ##

CVE-2026-24727 (CRITICAL, CVSS 9.3): SUNNET Corporate Training Mgmt System v10.3 allows admins to upload ZIP files with executable code, enabling server command execution. No patch yet — restrict admin access & monitor uploads. radar.offseq.com/threat/cve-20 #OffSeq #CVE202624727 #infosec 🛡️

##

CVE-2026-14172
(7.8 HIGH)

EPSS: 0.11%

updated 2026-07-24T09:32:22

2 posts

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0.

thehackerwire@mastodon.social at 2026-07-24T12:00:22.000Z ##

🟠 CVE-2026-14172 - High (7.8)

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYS...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-24T12:00:22.000Z ##

🟠 CVE-2026-14172 - High (7.8)

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYS...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12981(CVSS UNKNOWN)

EPSS: 0.18%

updated 2026-07-24T09:32:22

1 posts

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.

offseq@infosec.exchange at 2026-07-24T07:30:26.000Z ##

CVE-2026-12981: CRITICAL vuln in CAFEHAUS API plugin ≤1.0.0 (WordPress). No authentication on password updates — attackers can reset any user password, including admins. Remove/disable plugin until fixed. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vulnerability #PrivilegeEscalation

##

CVE-2026-15704
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-07-24T09:32:16

4 posts

In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The shared router configuration used Chi's `middleware.StripSlashes`, so a request such as `GET /shells/` was dispatched to the registered `GET /shells` route. However

thehackerwire@mastodon.social at 2026-07-24T12:00:12.000Z ##

🔴 CVE-2026-15704 - Critical (9.8)

In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router.

The shared rou...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-07-24T09:00:31.006Z ##

Eclipse BaSyx Go Components (<=1.0.0) suffer a CRITICAL auth bypass (CVE-2026-15704): ABAC checks can be evaded by adding a trailing slash to API routes. Immediate upgrade to 1.0.1 is required. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-07-24T12:00:12.000Z ##

🔴 CVE-2026-15704 - Critical (9.8)

In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router.

The shared rou...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-24T09:00:31.000Z ##

Eclipse BaSyx Go Components (<=1.0.0) suffer a CRITICAL auth bypass (CVE-2026-15704): ABAC checks can be evaded by adding a trailing slash to API routes. Immediate upgrade to 1.0.1 is required. radar.offseq.com/threat/cve-20 #OffSeq #CVE202615704 #infosec #AppSec

##

CVE-2026-16870
(8.8 HIGH)

EPSS: 0.36%

updated 2026-07-24T06:34:17

2 posts

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a crafted encryption metadata field to a shared internal stage that a victim proces

thehackerwire@mastodon.social at 2026-07-24T12:00:32.000Z ##

🟠 CVE-2026-16870 - High (8.8)

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-24T12:00:32.000Z ##

🟠 CVE-2026-16870 - High (8.8)

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54120
(9.9 CRITICAL)

EPSS: 0.71%

updated 2026-07-24T03:31:56

2 posts

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

offseq at 2026-07-24T13:30:30.159Z ##

CVE-2026-54120 (CRITICAL, CVSS 9.9): Improper input validation in Microsoft Surface Management Services lets authorized attackers run code remotely. Patch now: radar.offseq.com/threat/cve-20 🖥️

##

offseq@infosec.exchange at 2026-07-24T13:30:30.000Z ##

CVE-2026-54120 (CRITICAL, CVSS 9.9): Improper input validation in Microsoft Surface Management Services lets authorized attackers run code remotely. Patch now: radar.offseq.com/threat/cve-20 🖥️ #OffSeq #infosec #Microsoft #CVE202654120

##

CVE-2026-56160
(9.1 CRITICAL)

EPSS: 0.65%

updated 2026-07-24T03:31:56

3 posts

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

offseq at 2026-07-24T12:00:29.999Z ##

CRITICAL improper authorization vuln (CVE-2026-56160) in Azure Red Hat OpenShift (ARO): privilege escalation risk for authorized users. No active exploits. Microsoft has released a fix — ensure your ARO instances are updated. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-24T12:00:29.000Z ##

CRITICAL improper authorization vuln (CVE-2026-56160) in Azure Red Hat OpenShift (ARO): privilege escalation risk for authorized users. No active exploits. Microsoft has released a fix — ensure your ARO instances are updated. Details: radar.offseq.com/threat/cve-20 #OffSeq #Azure #CVE202656160

##

thehackerwire@mastodon.social at 2026-07-24T05:00:23.000Z ##

🔴 CVE-2026-56160 - Critical (9.1)

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50517
(9.9 CRITICAL)

EPSS: 1.25%

updated 2026-07-24T03:31:55

1 posts

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

offseq@infosec.exchange at 2026-07-24T06:00:25.000Z ##

CVE-2026-50517: CRITICAL deserialization flaw (CVSS 9.9) in Microsoft 365 Copilot permits remote code execution by authorized attackers. Microsoft has issued a server-side fix — confirm your environment is protected. radar.offseq.com/threat/cve-20 #OffSeq #Microsoft365 #CloudSecurity #CVE202650517

##

CVE-2026-10697
(7.5 HIGH)

EPSS: 0.18%

updated 2026-07-23T21:31:09

1 posts

Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

hugovalters@mastodon.social at 2026-07-24T15:06:51.000Z ##

CVE-2026-10697 - Improper Authentication in Progress MOVEit Transfer. CVSS 7.5. No patch yet. Mitigate immediately if affected. #CVE #Progress #infosec

valtersit.com/cve/CVE-2026-106

##

CVE-2026-65917
(8.8 HIGH)

EPSS: 0.36%

updated 2026-07-23T18:31:49

1 posts

CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup handlers (deleteBackup, fetchRestorePoints, and restorePoint) that allows authenticated panel users to access or manipulate other tenants' backup resources by supplying an attacker-controlled globally sequential IncJob integer ID th

hugovalters@mastodon.social at 2026-07-24T14:14:22.000Z ##

CVE-2026-65917 - IDOR in Cyberpanel IncBackups allows authenticated users to access/delete other tenants' backups via sequential job IDs. CVSS 8.8. No patch yet. Isolate or restrict access now. #CVE #CyberPanel #infosec

valtersit.com/cve/CVE-2026-659

##

CVE-2026-47056
(10.0 CRITICAL)

EPSS: 0.33%

updated 2026-07-23T18:30:55.460000

1 posts

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator. While the vulnerability is in Oracle Data Integrator, attacks may significantly impact add

sayzard@mastodon.sayzard.org at 2026-07-24T17:38:47.000Z ##

Oracle drops 1,449 security patches like it's the new normal

Oracle가 분기 보안 업데이트에서 1,449건의 패치를 배포했으며, 이 중 Oracle Fusion Middleware 관련 취약점 10건은 CVSS 10.0이다. 특히 인증 없이 HTTP로 Oracle Data Integrator를 장악할 수 있는 CVE-2026-47056과 TCP를 통해 Oracle Coherence를 장악할 수 있는 CVE-2026-60217은 즉시 패치 우선순위가 높다. Oracle Database Server에도 저권한 원격 코드 실행 가...

theregister.com/security/2026/

##

CVE-2026-60217
(10.0 CRITICAL)

EPSS: 0.45%

updated 2026-07-23T18:30:41.573000

1 posts

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additi

sayzard@mastodon.sayzard.org at 2026-07-24T17:38:47.000Z ##

Oracle drops 1,449 security patches like it's the new normal

Oracle가 분기 보안 업데이트에서 1,449건의 패치를 배포했으며, 이 중 Oracle Fusion Middleware 관련 취약점 10건은 CVSS 10.0이다. 특히 인증 없이 HTTP로 Oracle Data Integrator를 장악할 수 있는 CVE-2026-47056과 TCP를 통해 Oracle Coherence를 장악할 수 있는 CVE-2026-60217은 즉시 패치 우선순위가 높다. Oracle Database Server에도 저권한 원격 코드 실행 가...

theregister.com/security/2026/

##

CVE-2026-16232
(9.1 CRITICAL)

EPSS: 12.68%

updated 2026-07-23T15:44:54.743000

5 posts

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server I

1 repos

https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

netsecio@mastodon.social at 2026-07-24T17:48:06.000Z ##

📰 Check Point Patches Actively Exploited SmartConsole Auth Bypass Flaw

🚨 CRITICAL PATCH: Check Point fixes an actively exploited auth bypass zero-day (CVE-2026-16232, CVSS 9.3) in SmartConsole. Flaw allows full admin access. CISA added to KEV. Patch NOW. #CyberSecurity #ZeroDay #CheckPoint #Infosec

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ch

##

thecybermind at 2026-07-24T15:16:52.487Z ##

(CISA TS-SOC) CVE-2026-16232 – Check Point SmartConsole Improper Authentication Vulnerability

Severity: CRITICAL Impact Summary: An unauthenticated remote attacker can obtain an application login token and use it to authenticate with full administrative privileges....

thecybermind.co/2026/07/24/cis

##

youranonnewsirc@nerdculture.de at 2026-07-24T10:26:30.000Z ##

Geopolitical tensions escalated as US strikes on Iran continued and Houthi attacks on Saudi tankers raised oil prices. In cybersecurity, a critical Check Point zero-day (CVE-2026-16232) is actively exploited. US agencies warned of Iranian cyber campaigns targeting critical infrastructure PLCs and Russian state-backed phishing on Zimbra Collaboration Suite. AI agents are now a primary attack surface.

#Cybersecurity #Geopolitics #TechNews

##

youranonnewsirc@nerdculture.de at 2026-07-24T10:26:30.000Z ##

Geopolitical tensions escalated as US strikes on Iran continued and Houthi attacks on Saudi tankers raised oil prices. In cybersecurity, a critical Check Point zero-day (CVE-2026-16232) is actively exploited. US agencies warned of Iranian cyber campaigns targeting critical infrastructure PLCs and Russian state-backed phishing on Zimbra Collaboration Suite. AI agents are now a primary attack surface.

#Cybersecurity #Geopolitics #TechNews

##

nyanbinary@infosec.exchange at 2026-07-24T07:04:37.000Z ##

why am I confronted with this crime against language and common sense? discourse.ifin.network/t/cve-2 thats why (eitw vuln)

##

CVE-2026-64811
(7.8 HIGH)

EPSS: 0.13%

updated 2026-07-23T12:32:54

1 posts

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration

hugovalters@mastodon.social at 2026-07-24T12:03:23.000Z ##

CVE-2026-64811 High severity code execution in JetBrains IntelliJ IDEA before 2026.2 via dev container config before project trust. CVSS 7.8. Update immediately. #CVE #JetBrains #infosec

valtersit.com/cve/CVE-2026-648

##

CVE-2026-50522
(9.8 CRITICAL)

EPSS: 57.10%

updated 2026-07-22T21:31:51

2 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

1 repos

https://github.com/HORKimhab/CVE-2026-50522

thecybermind at 2026-07-24T15:22:59.629Z ##

(CISA TS-SOC) CVE-2026-50522 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Severity: CRITICAL Impact Summary: An unauthorized attacker can execute code over a network via deserialization of untrusted data....

thecybermind.co/2026/07/24/cis

##

thecybermind@infosec.exchange at 2026-07-24T15:22:59.000Z ##

(CISA TS-SOC) CVE-2026-50522 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Severity: CRITICAL Impact Summary: An unauthorized attacker can execute code over a network via deserialization of untrusted data....

thecybermind.co/2026/07/24/cis

##

CVE-2026-53359
(8.8 HIGH)

EPSS: 0.91%

updated 2026-07-22T19:07:43.103000

2 posts

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. Th

6 repos

https://github.com/chuzhongyun/CVE-2026-53359-Kernel-Fix

https://github.com/ndouglas-cloudsmith/CVE-2026-53359

https://github.com/0xBlackash/CVE-2026-53359

https://github.com/Aoripus-LTD/Januscape-Hotfix

https://github.com/HORKimhab/CVE-2026-53359

https://github.com/xj2268-TA/KVM-Januscape

tisba@ruby.social at 2026-07-24T09:04:20.000Z ##

@janl @jschauma not all LPE do fully break kernel namespaces ("containers”) - not sure about the quoted one though. While I don't disagree with your assessment, I'd still argue that containers made various security related features much more approachable and still provide value. In the end it always has been about defense in depth.

If we start to see more issues in KVM like CVE-2026-53359, we are really screwed! Then we're basically back to hardware isolation for everything that matters 🫣

##

tisba@ruby.social at 2026-07-24T09:04:20.000Z ##

@janl @jschauma not all LPE do fully break kernel namespaces ("containers”) - not sure about the quoted one though. While I don't disagree with your assessment, I'd still argue that containers made various security related features much more approachable and still provide value. In the end it always has been about defense in depth.

If we start to see more issues in KVM like CVE-2026-53359, we are really screwed! Then we're basically back to hardware isolation for everything that matters 🫣

##

CVE-2026-54121
(8.8 HIGH)

EPSS: 0.80%

updated 2026-07-21T19:54:33.623000

6 posts

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

1 repos

https://github.com/aniqfakhrul/CVE-2026-54121

netsecio@mastodon.social at 2026-07-24T17:47:44.000Z ##

📰 PoC Exploit 'Certighost' for Critical AD CS Flaw Now Public

PoC exploit 'Certighost' released for critical AD CS flaw CVE-2026-54121 (CVSS 8.8). Exploit allows low-privilege users to impersonate a Domain Controller, leading to full domain compromise. Patching is urgent. #ActiveDirectory #CyberSecurity #BlueTeam

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ce

##

AAKL at 2026-07-24T15:49:06.544Z ##

New.

GitHub/H0j3n: Certighost (CVE-2026-54121) gist.github.com/H0j3n/a5ef2609

More:

The Hacker News: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller thehackernews.com/2026/07/cert @thehackernews

##

Analyst207@mastodon.social at 2026-07-24T15:06:28.000Z ##

Certighost Exploit Enables Low-Privilege AD Users to Impersonate Domain Controllers

A newly discovered exploit, dubbed Certighost, lets low-privileged Active Directory users impersonate Domain Controllers, posing a significant threat to security. This vulnerability, tracked as CVE-2026-54121, allows attackers to obtain a certificate for a Domain Controller and…

osintsights.com/certighost-exp

#ActiveDirectoryExploit #Certighost #Cve202654121 #DomainControllerImpersonation #IdentityAuthentication

##

darses@mastodon.nl at 2026-07-24T14:30:58.000Z ##

A Proof-of-Concept was published for Microsoft Active Directory Certificate Services Privilege Escalation vulnerability CVE-2026-54121

db.gcve.eu/vuln/cve-2026-54121

#vulnerability #cybersecurity #cve_2026_54121

##

AAKL@infosec.exchange at 2026-07-24T15:49:06.000Z ##

New.

GitHub/H0j3n: Certighost (CVE-2026-54121) gist.github.com/H0j3n/a5ef2609

More:

The Hacker News: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller thehackernews.com/2026/07/cert @thehackernews #infosec #vulnerability #Microsoft #Windows

##

rtfmkiesel@infosec.exchange at 2026-07-24T06:56:18.000Z ##

New ADCS vuln + PoC dropped

Only requires a low priv user and results in a DC cert

Certighost (CVE-2026-54121)

gist.github.com/H0j3n/a5ef2609

##

CVE-2021-27137
(8.1 HIGH)

EPSS: 16.49%

updated 2026-07-21T18:30:50

1 posts

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachab

thecybermind@infosec.exchange at 2026-07-24T05:48:48.000Z ##

(CISA TS-SOC) CVE-2021-27137 – DD-WRT Stack-Based Buffer Overflow Vulnerability

Severity: HIGH Impact Summary: Allows unauthenticated attackers to execute arbitrary code on the device via a stack-based buffer overflow in the UPnP component....

thecybermind.co/2026/07/24/cis

##

CVE-2026-16242
(9.4 CRITICAL)

EPSS: 0.37%

updated 2026-07-20T09:31:15

2 posts

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy,

CVE-2026-42533
(8.1 HIGH)

EPSS: 2.79%

updated 2026-07-15T15:33:14

2 posts

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyon

6 repos

https://github.com/srkyn/nginx-map-risk-audit

https://github.com/Daniyal48/ghostlock-vagrant-box

https://github.com/gagaltotal/CVE-2026-42533-nginx

https://github.com/suominen/CVE-2026-42533

https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner

https://github.com/seguridadentrerios/CVE-2026-42533

ChrisShort@hachyderm.io at 2026-07-24T15:29:13.000Z ##

15-Year-Old Pre-Auth nginx RCE Across 13 Call Sites: Two-Pass Capture Clobbering CVE-2026-42533 – cyberstan #devopsish cyberstan.co.uk/nginx-rce/

##

ChrisShort@hachyderm.io at 2026-07-24T15:29:13.000Z ##

15-Year-Old Pre-Auth nginx RCE Across 13 Call Sites: Two-Pass Capture Clobbering CVE-2026-42533 – cyberstan #devopsish cyberstan.co.uk/nginx-rce/

##

CVE-2026-50454
(7.8 HIGH)

EPSS: 0.44%

updated 2026-07-14T18:32:32

2 posts

Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

DailyCyberSecurity at 2026-07-24T14:05:56.285Z ##

A public proof-of-concept details the Windows AppResolver LPE (CVE-2026-50454), a UAC bypass that chains an admin token to a SYSTEM shell.

securityonline.info/windows-ap

##

DailyCyberSecurity@infosec.exchange at 2026-07-24T14:05:56.000Z ##

A public proof-of-concept details the Windows AppResolver LPE (CVE-2026-50454), a UAC bypass that chains an admin token to a SYSTEM shell.

#Windows #CVE202650454 #PrivilegeEscalation #UACBypass #InfoSec

securityonline.info/windows-ap

##

CVE-2026-11405
(9.8 CRITICAL)

EPSS: 1.62%

updated 2026-07-08T15:32:52

2 posts

The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). - After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuratio

1 repos

https://github.com/HORKimhab/CVE-2026-11405

sekurakbot@mastodon.com.pl at 2026-07-24T09:35:00.000Z ##

Odnaleziono backdoor w routerach Tenda

W oprogramowaniu popularnego – również w naszym kraju – chińskiego producenta sprzętu sieciowego Tenda, odkryto ukrytą funkcjonalność. Pozwala ona na dostęp do interfejsu zarządzania WWW na prawach administratora urządzenia przy pomocy zapisanego na stałe hasła. TLDR: Czyli mamy do czynienia z klasyczną tylną furtką, zwaną powszechnie backdoorem. Podatność została oznaczona identyfikatorem CVE-2026-11405 i polega na modyfikacji...

#WBiegu #Backdoor #Cve #Router #Tenda

sekurak.pl/odnaleziono-backdoo

##

sekurakbot@mastodon.com.pl at 2026-07-24T09:35:00.000Z ##

Odnaleziono backdoor w routerach Tenda

W oprogramowaniu popularnego – również w naszym kraju – chińskiego producenta sprzętu sieciowego Tenda, odkryto ukrytą funkcjonalność. Pozwala ona na dostęp do interfejsu zarządzania WWW na prawach administratora urządzenia przy pomocy zapisanego na stałe hasła. TLDR: Czyli mamy do czynienia z klasyczną tylną furtką, zwaną powszechnie backdoorem. Podatność została oznaczona identyfikatorem CVE-2026-11405 i polega na modyfikacji...

#WBiegu #Backdoor #Cve #Router #Tenda

sekurak.pl/odnaleziono-backdoo

##

CVE-2026-12569
(9.8 CRITICAL)

EPSS: 2.26%

updated 2026-06-26T15:33:15

3 posts

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

1 repos

https://github.com/west-wind/Threat-Hunting-With-Splunk

sayzard@mastodon.sayzard.org at 2026-07-24T12:38:03.000Z ##

Clop ransomware targets Windchill, FlexPLM in data theft attacks

Clop(Cl0p) 랜섬웨어 조직이 인터넷에 노출된 PTC Windchill 및 FlexPLM 서버의 CVE-2026-12569(CVSS 9.3)을 악용해 인증 없이 원격 코드 실행을 수행하고 JSP 웹셸을 설치하는 정황이 확인됐다. 공격자는 제품 설계·제조 관련 민감 데이터를 유출한 뒤, 탈취한 이메일 계정을 이용해 다수 직원에게 갈취 메일을 보내는 방식으로 압박한다. PTC는 6월부터 패치를 제공했으며 CISA는 해당 취약점을 KEV 목록에 올려 연방기관에 3일...

bleepingcomputer.com/news/secu

##

undercodenews@mastodon.social at 2026-07-24T10:07:57.000Z ##

Clop Exploits Critical Windchill Vulnerability, Turning Engineering Systems Into Targets for Data Extortion + Video

Introduction: A New Cyber Threat Against Industrial Innovation A new wave of cyberattacks is putting engineering organizations, manufacturing companies, and product development environments under increasing pressure. The notorious Clop threat group is reportedly exploiting a newly identified vulnerability, CVE-2026-12569, targeting exposed PTC Windchill…

undercodenews.com/clop-exploit

##

Analyst207@mastodon.social at 2026-07-24T08:06:42.000Z ##

Clop Ransomware Targets PTC Windchill in Data Theft Attacks

A critical vulnerability, CVE-2026-12569, with a near-perfect CVSS score of 9.3 is being exploited by Clop ransomware attackers to breach PTC Windchill and FlexPLM systems, putting sensitive data at risk. Security patches are available, but urgent action is needed to prevent data theft.

osintsights.com/clop-ransomwar

#ClopRansomware #Cve202612569 #PtcWindchill #Flexplm #RansomwareAttacks

##

CVE-2025-66376
(7.2 HIGH)

EPSS: 21.62%

updated 2026-06-17T09:56:44.753000

4 posts

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

netsecio@mastodon.social at 2026-07-24T17:48:03.000Z ##

📰 Russian APT 'Laundry Bear' Targets West with Zero-Click Zimbra Exploit

International advisory warns of Russian APT 'Laundry Bear' using a zero-click Zimbra exploit (CVE-2025-66376) in a widespread espionage campaign against Western targets. Actors steal emails & credentials. #ThreatIntel #Zimbra #CyberSecurity

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ru

##

netsecio@mastodon.social at 2026-07-24T17:48:00.000Z ##

📰 Russian Hackers Use Zero-Click Zimbra Exploit in Global Spy Campaign

Russian state actors (Void Blizzard) are exploiting a zero-click Zimbra vulnerability (CVE-2025-66376) to steal credentials and emails. The campaign uses JavaScript injection via phishing emails. Patching is critical. #CyberEspionage #Zimbra #ThreatI...

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ru

##

VirusBulletin at 2026-07-24T09:25:53.416Z ##

Proofpoint uncovered that Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) was exploiting a previously unknown vulnerability against Zimbra mailservers for at least five months during 2025, until the issue was patched with CVE-2025-66376. proofpoint.com/us/blog/threat-

##

VirusBulletin@infosec.exchange at 2026-07-24T09:25:53.000Z ##

Proofpoint uncovered that Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) was exploiting a previously unknown vulnerability against Zimbra mailservers for at least five months during 2025, until the issue was patched with CVE-2025-66376. proofpoint.com/us/blog/threat-

##

CVE-2026-47668
(10.0 CRITICAL)

EPSS: 4.34%

updated 2026-06-05T16:25:28

1 posts

### Summary DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. ### Details #### Step 1:

Nuclei template

1 repos

https://github.com/Nxploited/CVE-2026-47668

Matchbook3469@mastodon.social at 2026-07-24T09:06:14.000Z ##

🔴 New security advisory:

CVE-2026-47668 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

#Cybersecurity #ZeroDay #ThreatIntel

##

CVE-2026-0770(CVSS UNKNOWN)

EPSS: 53.46%

updated 2026-02-19T22:09:33

2 posts

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The

Nuclei template

7 repos

https://github.com/0xBlackash/CVE-2026-0770

https://github.com/Yetazyyy/CVE-2026-0770

https://github.com/affix/CVE-2026-0770-PoC

https://github.com/0xgh057r3c0n/CVE-2026-0770

https://github.com/diamorphine666/CVE-2026-0770

https://github.com/Ez4rd1x1/CVE-2026-0770

https://github.com/razureink/cve-2026-0770-langflow_rce_reproduction

thecybermind at 2026-07-24T11:06:41.851Z ##

(CISA TS-SOC) CVE-2026-0770 – Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Severity: UNKNOWN Impact Summary: Remote attackers can execute arbitrary code on affected installations. Timestamp: 2026-07-24T01:31:37.336Z ATT&CK Mapping…...

thecybermind.co/2026/07/24/cis

##

thecybermind@infosec.exchange at 2026-07-24T11:06:41.000Z ##

(CISA TS-SOC) CVE-2026-0770 – Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Severity: UNKNOWN Impact Summary: Remote attackers can execute arbitrary code on affected installations. Timestamp: 2026-07-24T01:31:37.336Z ATT&CK Mapping…...

thecybermind.co/2026/07/24/cis

##

CVE-2025-0679
(4.3 MEDIUM)

EPSS: 0.29%

updated 2025-05-22T15:35:02

2 posts

An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured.

security_crawler_carl at 2026-07-24T12:21:18.555Z ##

CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.

Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.

Reward: You've received a hollow Authenticator Token — pre-drained.

(2/2)

##

security_crawler_carl@infosec.exchange at 2026-07-24T12:21:18.000Z ##

CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.

Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.

Reward: You've received a hollow Authenticator Token — pre-drained.

#ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)

##

CVE-2026-61884
(0 None)

EPSS: 0.00%

2 posts

N/A

CVE-2026-63030
(0 None)

EPSS: 97.92%

4 posts

N/A

Nuclei template

67 repos

https://github.com/securelayer7/WordPresShell

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/4B3R4M4-607D/CVE-2026-63030-POC

https://github.com/ZenithGenius/wordpress-batch-rce-lab

https://github.com/shinthink/CVE-2026-63030

https://github.com/attackercan/wp2shell-poc2

https://github.com/raphy76/wp2shell-poc-fulljs

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/fullhunt/wp2shell-scan

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/Crypto-Cat/wp2shell

https://github.com/administrator-01001/CVE-2026-63030

https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause

https://github.com/ikow/wp2shell

https://github.com/TomorrowX6/CVE-2026-63030-poc

https://github.com/mcipekci/wp2shell

https://github.com/ananay/wp2shell-lab

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/0xh7ml/CVE-2026-63030

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/mhtsec/CVE-2026-63030

https://github.com/zi3lak/wp2shell_scanner

https://github.com/zeroc00I/CVE-2026-63030

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/CybersecSpirit/CVE-2026-63030

https://github.com/Ch4120N/CVE-2026-63030

https://github.com/4minx/CVE-2026-63030

https://github.com/mrx-arafat/CVE-2026-63030-POC

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/kulichr/wp2shell

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/0xWhoknows/wp2shell

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/InstaWP/wp2shell-scan

https://github.com/wn-iqbal/wp2shell

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/47Cid/wp2shell-lab

https://github.com/gbrsh/CVE-2026-63030

https://github.com/h4cd0c/wp2shell

https://github.com/NULL200OK/WP2Shell

https://github.com/0xsha/wp2shell

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/bahartanir/wp2shell-scanner

https://github.com/Lutfifakee-Project/wp2shell

https://github.com/yoerivegt/wp2shell-poc

https://github.com/mverschu/CVE-2026-63030

https://github.com/ChiefYoru/CVE-2026-63030_PoC

https://github.com/c0gnit00/Wp2Shell

https://github.com/vulnquest58/PressVector

https://github.com/ebrasha/abdal-cve-2026-63030

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/dinosn/wp2shell-lab

https://github.com/0xBlackash/CVE-2026-63030

https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t

https://github.com/0xjessie21/wp2shell-checker

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/ekomsSavior/wp2shell

https://github.com/Icex0/wp2shell-poc

thecybermind at 2026-07-24T11:29:34.912Z ##

(CISA TS-SOC) CVE-2026-60137 – WordPress Core SQL Injection Vulnerability

Severity: MEDIUM Impact Summary: Allows unauthenticated attackers to perform SQL injection, which can be chained with CVE-2026-63030 to achieve remote code execution on default WordPress installations....

thecybermind.co/2026/07/24/cis

##

thecybermind at 2026-07-24T11:19:33.810Z ##

(CISA TS-SOC) CVE-2026-63030 – WordPress Core Interpretation Conflict Vulnerability

Severity: CRITICAL Impact Summary: An attacker can exploit an interpretation conflict in WordPress Core to perform SQL Injection, which may be chained to achieve Remote Code Execution....

thecybermind.co/2026/07/24/cis

##

thecybermind@infosec.exchange at 2026-07-24T11:29:34.000Z ##

(CISA TS-SOC) CVE-2026-60137 – WordPress Core SQL Injection Vulnerability

Severity: MEDIUM Impact Summary: Allows unauthenticated attackers to perform SQL injection, which can be chained with CVE-2026-63030 to achieve remote code execution on default WordPress installations....

thecybermind.co/2026/07/24/cis

##

thecybermind@infosec.exchange at 2026-07-24T11:19:33.000Z ##

(CISA TS-SOC) CVE-2026-63030 – WordPress Core Interpretation Conflict Vulnerability

Severity: CRITICAL Impact Summary: An attacker can exploit an interpretation conflict in WordPress Core to perform SQL Injection, which may be chained to achieve Remote Code Execution....

thecybermind.co/2026/07/24/cis

##

CVE-2026-60137
(0 None)

EPSS: 77.97%

2 posts

N/A

42 repos

https://github.com/securelayer7/WordPresShell

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/shinthink/CVE-2026-63030

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/Crypto-Cat/wp2shell

https://github.com/ikow/wp2shell

https://github.com/mcipekci/wp2shell

https://github.com/ananay/wp2shell-lab

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/zi3lak/wp2shell_scanner

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/0xWhoknows/wp2shell

https://github.com/kulichr/wp2shell

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/wn-iqbal/wp2shell

https://github.com/ebrasha/abdal-cve-2026-60137

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/47Cid/wp2shell-lab

https://github.com/h4cd0c/wp2shell

https://github.com/NULL200OK/WP2Shell

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/0xsha/wp2shell

https://github.com/bahartanir/wp2shell-scanner

https://github.com/yoerivegt/wp2shell-poc

https://github.com/vulnquest58/PressVector

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/dinosn/wp2shell-lab

https://github.com/0xjessie21/wp2shell-checker

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/ekomsSavior/wp2shell

https://github.com/Icex0/wp2shell-poc

thecybermind at 2026-07-24T11:29:34.912Z ##

(CISA TS-SOC) CVE-2026-60137 – WordPress Core SQL Injection Vulnerability

Severity: MEDIUM Impact Summary: Allows unauthenticated attackers to perform SQL injection, which can be chained with CVE-2026-63030 to achieve remote code execution on default WordPress installations....

thecybermind.co/2026/07/24/cis

##

thecybermind@infosec.exchange at 2026-07-24T11:29:34.000Z ##

(CISA TS-SOC) CVE-2026-60137 – WordPress Core SQL Injection Vulnerability

Severity: MEDIUM Impact Summary: Allows unauthenticated attackers to perform SQL injection, which can be chained with CVE-2026-63030 to achieve remote code execution on default WordPress installations....

thecybermind.co/2026/07/24/cis

##

sayzard@mastodon.sayzard.org at 2026-07-24T10:38:37.000Z ##

Kimi K3 found 19 0days in latest Redis 8.8.0 in 1.5hrs

공개 GitHub 저장소가 Redis 6.2.22·7.4.9·8.6.4·8.8.0/8.8.1에서 인증된 사용자가 원격 코드 실행(RCE)을 얻을 수 있다는 PoC를 공개했다. 주장된 경로에는 Streams consumer-group의 shared-NACK double-free와 기본 번들 RedisBloom 모듈의 TDigest heap overflow, TopK wild free가 포함되며, 일부는 CVE-2026-25243 및 CVE-2026-25589 수정 우회라고 설명한다. 특히 RedisBloom이 포함된 8.8.x 배포와 EVAL·RESTORE·XGROUP 권한을 보유한 Redis 서비스는 공급망/...

github.com/berabuddies/redis-p

##

sayzard@mastodon.sayzard.org at 2026-07-24T10:38:37.000Z ##

Kimi K3 found 19 0days in latest Redis 8.8.0 in 1.5hrs

공개 GitHub 저장소가 Redis 6.2.22·7.4.9·8.6.4·8.8.0/8.8.1에서 인증된 사용자가 원격 코드 실행(RCE)을 얻을 수 있다는 PoC를 공개했다. 주장된 경로에는 Streams consumer-group의 shared-NACK double-free와 기본 번들 RedisBloom 모듈의 TDigest heap overflow, TopK wild free가 포함되며, 일부는 CVE-2026-25243 및 CVE-2026-25589 수정 우회라고 설명한다. 특히 RedisBloom이 포함된 8.8.x 배포와 EVAL·RESTORE·XGROUP 권한을 보유한 Redis 서비스는 공급망/...

github.com/berabuddies/redis-p

##

Visit counter For Websites