## Updated at UTC 2026-08-21T20:58:40.456290

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-77234 8.8 0.00% 2 0 2026-08-21T20:16:44.947000 Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unpriv
CVE-2026-73570 8.9 0.54% 11 1 2026-08-21T19:21:23.023000 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor
CVE-2026-76017 8.8 0.36% 1 0 2026-08-21T19:17:50.497000 Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a
CVE-2026-63462 7.5 0.00% 2 0 2026-08-21T19:17:31.927000 Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, an
CVE-2026-54682 8.2 0.00% 2 0 2026-08-21T19:17:03.610000 DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exp
CVE-2026-54071 7.8 0.00% 2 0 2026-08-21T19:17:02.720000 BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF
CVE-2026-76397 8.1 0.25% 1 0 2026-08-21T18:56:07.450000 In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk r
CVE-2026-75932 8.6 0.00% 2 0 2026-08-21T18:35:02 Jet Admin allows an attacker to create a malicious app and connect it to a targe
CVE-2026-69502 10.0 0.00% 2 0 2026-08-21T18:35:01 Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized
CVE-2026-75501 None 0.00% 2 0 2026-08-21T18:34:56 A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residentia
CVE-2026-77812 0 0.00% 2 0 2026-08-21T18:16:52.527000 DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over
CVE-2026-77806 9.8 0.00% 2 0 2026-08-21T18:16:52.373000 SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary
CVE-2026-72848 8.6 0.48% 1 0 2026-08-21T18:16:50.890000 SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py a
CVE-2026-71862 7.5 0.00% 2 0 2026-08-21T18:16:50.730000 Checkmate is an open-source, self-hosted tool designed to track and monitor serv
CVE-2026-69836 10.0 1.37% 16 1 2026-08-21T18:16:50.120000 Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized a
CVE-2026-62674 9.0 0.00% 2 0 2026-08-21T18:16:49.460000 Omnigent is an open-source AI agent framework and meta-harness for orchestrating
CVE-2026-76590 9.9 0.61% 2 0 2026-08-21T17:16:46 A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by
CVE-2026-73040 8.8 0.67% 1 0 2026-08-21T17:16:43.950000 Dockge validates a stack name only on the write path. In backend/stack.ts the al
CVE-2026-67567 9.9 0.32% 3 0 2026-08-21T17:16:41.320000 A flaw was found in the multicloud-operators-subscription component. This vulner
CVE-2026-39909 8.1 0.00% 2 0 2026-08-21T17:16:30.810000 llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server
CVE-2026-77087 9.6 0.00% 3 0 2026-08-21T16:18:21.993000 Paperclip before 0.3.1 in default local_trusted mode fails to validate Host head
CVE-2026-18781 8.1 0.21% 1 0 2026-08-21T15:33:14 The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin befor
CVE-2026-77814 7.5 0.00% 2 0 2026-08-21T15:32:19 is_path_trusted in scripts/iib/api.py compares the requested path against each a
CVE-2026-77815 7.5 0.00% 2 0 2026-08-21T15:32:18 to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.no
CVE-2026-77645 0 0.47% 1 0 2026-08-21T15:16:47.430000 A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
CVE-2026-63125 9.9 0.00% 1 0 2026-08-21T15:16:46.427000 Incus is a system container and virtual machine manager. Prior to version 7.3.0,
CVE-2026-59279 7.5 0.00% 2 0 2026-08-21T15:16:42.257000 The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not
CVE-2026-21580 0 0.36% 1 0 2026-08-21T15:16:39.883000 This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security
CVE-2026-76156 0 0.83% 1 0 2026-08-21T14:16:53.017000 OS command injection in the api endpoint of Datiphy Data Management Center from
CVE-2026-50112 8.8 0.17% 2 0 2026-08-21T14:16:50.423000 SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a
CVE-2026-77683 9.9 0.00% 2 0 2026-08-21T12:30:37 A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this
CVE-2026-77775 8.6 0.00% 2 0 2026-08-21T12:30:35 Headroom's LLM proxy lets a client choose the upstream destination with the x-he
CVE-2026-77776 9.1 0.00% 5 0 2026-08-21T12:16:36.967000 Headroom's LLM proxy derives the memory owner from the x-headroom-user-id reques
CVE-2026-76234 7.5 0.22% 1 0 2026-08-21T12:16:33.233000 libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, con
CVE-2026-76310 9.4 0.37% 1 0 2026-08-21T04:18:20.733000 In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unaut
CVE-2026-75144 7.8 0.14% 1 0 2026-08-21T04:18:19.900000 FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in th
CVE-2026-75141 7.8 0.14% 1 0 2026-08-21T04:18:19.413000 FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box wri
CVE-2026-67364 0 0.29% 1 0 2026-08-21T04:18:14.833000 Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms <
CVE-2026-76158 None 0.41% 1 0 2026-08-21T03:31:30 External Control of File Name or Path in the upload API endpoint of Datiphy Data
CVE-2026-76155 None 0.29% 1 0 2026-08-21T03:31:29 Use of default credentials in Datiphy Data Management Center from v8.3.0 through
CVE-2026-77651 9.8 0.43% 1 0 2026-08-21T03:31:29 The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when
CVE-2026-77647 9.8 0.81% 3 0 2026-08-21T00:31:31 SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary
CVE-2026-69855 7.7 0.48% 1 0 2026-08-21T00:31:31 Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an autho
CVE-2026-72860 8.5 0.22% 1 0 2026-08-21T00:31:31 The POST /api/provider-nodes/validate route in 9router takes a caller-supplied b
CVE-2026-72818 7.5 0.51% 1 0 2026-08-21T00:31:31 The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetToken
CVE-2026-77642 7.5 0.19% 1 0 2026-08-21T00:31:31 tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus
CVE-2026-72843 9.8 0.57% 1 0 2026-08-21T00:31:24 The customer update route in EverShop is declared with "access": "public" in pac
CVE-2026-66785 9.9 0.29% 2 0 2026-08-20T21:31:36 A flaw was found in Submariner. This vulnerability allows a malicious cluster (s
CVE-2026-72852 7.8 0.14% 1 0 2026-08-20T21:31:36 hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by
CVE-2026-77148 9.9 0.47% 1 0 2026-08-20T21:31:36 A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function
CVE-2026-19586 None 5.04% 1 0 2026-08-20T21:31:30 A pre-authentication OS command injection vulnerability has been identified in O
CVE-2026-73137 7.7 0.29% 1 0 2026-08-20T21:31:30 A flaw was found in the multicloud-operators-subscription component of Red Hat A
CVE-2026-77638 8.9 0.17% 1 0 2026-08-20T21:31:30 Tor before 0.4.9.11 is prone to a race condition where in just the right circums
CVE-2026-18420 8.8 0.96% 1 0 2026-08-20T21:17:06.137000 Improper input validation in the Time Series Visual Builder (TSVB) plugin in Ope
CVE-2026-73257 9.1 0.38% 1 0 2026-08-20T20:17:46.470000 Mongoose is an embedded web server and network library. Priro to version 7.22, a
CVE-2026-20315 10.0 0.32% 3 0 2026-08-20T19:16:51.673000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-16885 9.8 0.80% 1 0 2026-08-20T19:16:50.880000 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
CVE-2026-72530 9.0 0.97% 6 0 2026-08-20T18:31:47 A remote unauthorized attacker with network access via port 4307/TCP to the True
CVE-2026-76641 7.5 0.34% 1 0 2026-08-20T18:31:11 Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows att
CVE-2026-18290 7.8 0.26% 1 0 2026-08-20T18:31:06 OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution V
CVE-2026-77022 9.9 0.46% 1 0 2026-08-20T18:31:06 A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this
CVE-2026-75140 7.5 0.53% 1 0 2026-08-20T18:30:58 jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource
CVE-2026-63038 None 0.21% 1 0 2026-08-20T18:30:58 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-72529 9.8 0.78% 6 0 2026-08-20T18:30:43 A remote unauthorized attacker with network access via port 4307/TCP to the True
CVE-2026-71428 9.3 0.25% 1 0 2026-08-20T17:19:40.773000 The unstructured library provides open-source components for ingesting and pre-p
CVE-2026-14951 8.0 0.16% 1 0 2026-08-20T17:17:20.930000 An low privileged remote attacker can cause authenticated users to perform unint
CVE-2026-76879 7.5 0.28% 1 0 2026-08-20T16:18:21.780000 C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows den
CVE-2026-76832 8.8 0.84% 1 0 2026-08-20T16:18:20.903000 Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal v
CVE-2026-76633 8.1 0.24% 1 0 2026-08-20T16:18:19.223000 WeGIA before 3.9.2 contains an authorization bypass vulnerability in the passwor
CVE-2026-14953 4.3 0.20% 1 0 2026-08-20T16:17:07.463000 A low-privileged remote attacker can enumerate all configured users and identify
CVE-2026-14950 9.8 0.55% 3 0 2026-08-20T16:17:07.210000 An unauthenticated remote attacker in possession of a valid session identifier i
CVE-2026-76833 7.8 0.15% 1 0 2026-08-20T15:34:26 @cgauge/yaml npm package contains an arbitrary code execution vulnerability that
CVE-2026-76886 8.1 0.32% 1 0 2026-08-20T15:34:14 C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows den
CVE-2026-19490 None 0.33% 4 0 2026-08-20T15:34:03 Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: f
CVE-2026-61897 7.8 0.10% 1 0 2026-08-20T15:17:38.740000 An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partial
CVE-2026-28164 9.6 0.15% 1 0 2026-08-20T15:17:29.713000 Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Add
CVE-2026-66780 9.9 0.24% 1 0 2026-08-20T13:08:53.900000 A flaw was found in the submariner-operator component. The `submariner-k8s-broke
CVE-2026-20320 7.5 0.35% 1 0 2026-08-20T13:01:19.947000 A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWork
CVE-2026-76004 9.9 0.44% 2 0 2026-08-20T12:48:31.843000 A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-21090
CVE-2026-19598 9.8 0.50% 2 3 2026-08-20T12:48:10.287000 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to
CVE-2026-15748 9.8 3.45% 1 3 2026-08-20T12:48:10.287000 The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload
CVE-2026-24301 8.8 1.63% 2 1 2026-08-20T12:33:08.793000 Improper neutralization of special elements used in a command ('command injectio
CVE-2026-66582 7.1 0.18% 1 0 2026-08-20T12:31:30 Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.
CVE-2026-73198 7.5 0.35% 1 0 2026-08-20T12:31:29 A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vu
CVE-2026-13097 9.1 0.34% 1 0 2026-08-20T12:31:22 A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enfo
CVE-2026-73197 7.5 0.35% 1 0 2026-08-20T12:31:22 A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this
CVE-2026-75860 9.8 0.34% 1 0 2026-08-20T12:31:22 The JSON Options WordPress plugin through 0.0.4 does not have any capability che
CVE-2026-14947 7.2 0.94% 1 0 2026-08-20T09:31:23 A high-privileged remote attacker can upload malicious ZIP archive containing di
CVE-2026-14948 8.8 0.39% 1 0 2026-08-20T09:31:23 A low privileged remote attacker can hijack an active administrative session wit
CVE-2026-14946 7.2 0.52% 1 0 2026-08-20T09:31:23 A high privileged remote attacker can upload a .php file and then request it dir
CVE-2026-14949 6.5 0.26% 1 0 2026-08-20T09:31:23 A low privileged remote attacker with a valid session can submit a request to th
CVE-2026-14952 7.5 0.49% 1 0 2026-08-20T09:31:23 An unauthenticated remote attacker can retrieve sensible files from the FDS Web
CVE-2026-76928 7.5 0.28% 1 0 2026-08-20T00:35:18 X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows de
CVE-2026-76589 9.9 0.61% 2 0 2026-08-20T00:35:17 A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the
CVE-2026-76850 9.8 0.98% 2 0 2026-08-20T00:35:17 LMDeploy deserializes disaggregated-serving peer messages with pickle. The handl
CVE-2026-76880 7.5 0.28% 1 0 2026-08-20T00:35:17 RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial
CVE-2026-76399 8.1 0.25% 1 0 2026-08-20T00:35:11 In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk r
CVE-2026-76396 7.5 0.24% 1 0 2026-08-20T00:35:11 In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the sch
CVE-2026-76395 8.8 0.47% 1 0 2026-08-20T00:35:11 In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk r
CVE-2026-76404 9.1 0.56% 3 0 2026-08-20T00:35:08 In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splu
CVE-2026-20231 9.9 0.41% 1 0 2026-08-19T21:31:33 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20030 10.0 0.45% 1 0 2026-08-19T21:31:32 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-75569 7.7 0.29% 1 0 2026-08-19T21:30:46 A flaw was found in mce-operator-bundle. The build process fetches and executes
CVE-2026-76139 8.0 0.33% 1 0 2026-08-19T21:30:46 A flaw was found in acm-operator-bundle. The build process for this component do
CVE-2026-76584 9.9 0.49% 1 0 2026-08-19T21:30:40 A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected b
CVE-2026-70496 9.9 0.26% 2 0 2026-08-19T21:30:39 A flaw was found in search-v2-operator. The operator's ClusterRole has permissio
CVE-2026-18848 8.3 0.10% 1 0 2026-08-19T21:30:32 IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 thr
CVE-2026-20317 10.0 0.34% 2 0 2026-08-19T21:30:29 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-68900 7.6 0.25% 1 0 2026-08-19T20:17:21.727000 Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHT
CVE-2026-75149 8.8 0.64% 1 0 2026-08-19T18:33:02 marimo before 0.23.15 contains a code injection vulnerability in the notebook co
CVE-2026-32475 9.0 0.42% 10 0 2026-08-19T18:32:57 Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Eleme
CVE-2026-61518 8.8 0.31% 1 0 2026-08-19T18:32:57 ISPConfig contains an authenticated SQL injection vulnerability in the Remote AP
CVE-2026-66794 9.3 0.32% 1 0 2026-08-19T18:32:57 A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine f
CVE-2026-75143 9.8 0.40% 1 0 2026-08-19T18:32:57 FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protoco
CVE-2026-75142 7.8 0.14% 1 0 2026-08-19T18:32:57 FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS mux
CVE-2026-75146 8.1 0.26% 1 0 2026-08-19T18:32:57 FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer
CVE-2026-18051 10.0 0.43% 1 0 2026-08-19T18:32:44 The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the
CVE-2026-70408 8.8 0.33% 1 0 2026-08-19T16:18:58.590000 An incorrect authorization vulnerability exists in acmailer, which may allow a u
CVE-2026-73925 8.2 0.23% 1 0 2026-08-19T15:33:23 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-73924 9.1 0.29% 1 0 2026-08-19T15:33:23 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-73921 9.8 0.33% 1 0 2026-08-19T15:33:23 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-73938 7.5 0.38% 1 0 2026-08-19T15:33:23 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-71176 8.8 0.30% 1 0 2026-08-19T15:32:47 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutra
CVE-2026-71961 8.8 3.34% 1 0 2026-08-19T15:32:47 Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection
CVE-2026-73937 8.2 0.38% 1 0 2026-08-19T15:32:20 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-73922 9.1 0.29% 1 0 2026-08-19T15:32:19 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-19942 8.1 0.69% 1 0 2026-08-19T06:31:24 The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO
CVE-2026-76008 10.0 0.57% 1 0 2026-08-19T03:31:30 A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_
CVE-2026-76003 9.9 0.44% 2 0 2026-08-19T03:31:23 A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected
CVE-2026-18963 9.1 0.39% 7 1 2026-08-19T03:31:21 A flaw was found in the reset-credentials flow of the keycloak-services componen
CVE-2026-47627 9.8 0.43% 1 0 2026-08-18T21:31:53 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attac
CVE-2026-67271 9.8 0.46% 1 0 2026-08-18T18:32:05 Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/
CVE-2026-65400 7.1 0.75% 1 2 2026-08-18T18:31:47 An authentication issue was addressed with improved state management. This issue
CVE-2026-33824 9.8 77.90% 3 2 2026-08-18T18:31:46 Double free in Windows IKE Extension allows an unauthorized attacker to execute
CVE-2026-19478 9.4 1.51% 9 4 2026-08-18T14:57:10.630000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2
CVE-2026-64849 9.3 8.15% 5 3 2026-08-17T21:58:52 ### Summary The default MLflow Tracking Server (`mlflow server`, no authenticati
CVE-2026-66792 9.9 0.30% 1 0 2026-08-17T21:31:30 A flaw was found in the multicloud-operators-subscription component. This vulner
CVE-2026-47686 9.9 0.32% 1 0 2026-08-17T17:32:35 **Affected:** vm2 <= 3.11.3 **CVSS 3.1:** 9.9 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:N
CVE-2026-42945 8.1 66.04% 2 44 2026-08-17T12:18:36.420000 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo
CVE-2026-68820 7.0 0.33% 1 2 2026-08-16T19:17:24.183000 Use after free in Windows Ancillary Function Driver for WinSock allows an author
CVE-2026-17186 9.9 0.47% 1 0 2026-08-14T21:31:35 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute
CVE-2026-8715 9.6 0.32% 1 0 2026-08-13T21:36:21 Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read
CVE-2026-13737 None 0.43% 1 0 2026-08-11T18:30:43 CommServe contained an allowlist bypass vulnerability affecting command executio
CVE-2026-13738 0 0.53% 1 0 2026-08-11T17:17:47.660000 CommServe contained an authorization bypass vulnerability affecting a limited se
CVE-2026-66066 None 1.77% 2 7 2026-07-30T18:23:34 ### Impact In its default configuration, a Rails application that displays image
CVE-2026-11622 7.5 0.51% 1 0 2026-07-22T20:33:11.590000 A DNSSEC validating resolver that is under a random subdomain attack against a D
CVE-2026-47301 8.8 0.68% 1 1 2026-07-14T21:32:21 Improper access control in Microsoft Configuration Manager allows an authorized
CVE-2026-52929 7.5 0.39% 1 0 2026-07-08T15:28:40.107000 In the Linux kernel, the following vulnerability has been resolved: sctp: strea
CVE-2026-58472 5.9 0.22% 1 0 2026-07-07T21:31:43 GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflo
CVE-2026-8452 9.8 1.04% 2 3 2026-07-01T18:32:28 Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unp
CVE-2026-12569 9.8 30.20% 7 1 2026-06-26T15:33:15 A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
CVE-2026-20266 9.1 0.63% 1 0 2026-06-17T18:35:58 In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk r
CVE-2010-3854 0 5.92% 1 0 2026-06-16T23:23:40.850000 Multiple cross-site scripting (XSS) vulnerabilities in the web administration in
CVE-2026-0075 5.9 0.09% 2 1 2026-06-02T15:33:09 In multiple functions, there is a possible way to access the contacts database d
CVE-2008-5161 3.7 15.39% 1 1 2026-05-28T21:32:49 Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Conne
CVE-2026-1947 7.5 0.27% 1 4 2026-03-16T15:30:54 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vuln
CVE-2025-62593 None 1.01% 3 1 2025-12-01T16:02:43 # Summary Developers working with Ray as a development tool can be exploited vi
CVE-2012-0158 8.8 99.97% 2 2 2025-10-22T03:31:35 The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX control
CVE-2021-43226 7.8 3.07% 2 1 2025-10-22T00:33:30 Windows Common Log File System Driver Elevation of Privilege Vulnerability This
CVE-2020-5135 9.8 24.56% 2 0 2025-10-22T00:31:59 A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Den
CVE-2026-54789 0 0.00% 2 0 N/A
CVE-2026-59270 0 0.00% 2 0 N/A
CVE-2026-77176 0 0.41% 2 0 N/A
CVE-2026-71485 0 0.42% 1 0 N/A
CVE-2026-73256 0 0.40% 1 0 N/A
CVE-2026-59307 0 0.00% 1 0 N/A
CVE-2026-59324 0 0.00% 1 0 N/A
CVE-2026-63490 0 0.47% 1 0 N/A
CVE-2026-54330 0 0.00% 1 0 N/A
CVE-2026-68899 0 0.40% 1 0 N/A
CVE-2026-68561 0 0.38% 1 0 N/A

CVE-2026-77234
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-21T20:16:44.947000

2 posts

Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later.

thehackerwire@mastodon.social at 2026-08-21T19:00:45.000Z ##

🟠 CVE-2026-77234 - High (8.8)

Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T19:00:45.000Z ##

🟠 CVE-2026-77234 - High (8.8)

Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73570
(8.9 HIGH)

EPSS: 0.54%

updated 2026-08-21T19:21:23.023000

11 posts

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands a

1 repos

https://github.com/HORKimhab/CVE-2026-73570

secdb at 2026-08-21T19:00:10.468Z ##

🚨 [CISA-2026:0821] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-69836 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Entra ID Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Entra ID
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-73570 (secdb.nttzen.cloud/cve/detail/)
- Name: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Synacor
- Product: Zimbra Collaboration Suite (ZCS)
- Notes: wiki.zimbra.com/wiki/Zimbra_Se ; blog.zimbra.com/2026/07/patch- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-08-21T17:01:04.000Z ##

CVE ID: CVE-2026-73570
Vendor: Synacor
Product: Zimbra Collaboration Suite (ZCS)
Date Added: 2026-08-21
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

undercodenews@mastodon.social at 2026-08-21T10:44:35.000Z ##

Zimbra Under Attack: Critical CVE-2026-73570 Turns Internet-Facing Mail Servers Into High-Value Targets + Video

A Warning That Arrived Just 28 Days After the Patch A newly confirmed exploitation campaign against Zimbra Collaboration Suite is raising the pressure on organizations that operate their own email infrastructure. Poland’s national computer emergency response team, CERT Polska, has confirmed that attackers are actively exploiting CVE-2026-73570, a critical…

undercodenews.com/zimbra-under

##

beyondmachines1 at 2026-08-21T09:01:12.566Z ##

Critical Zimbra RCE Vulnerability Exploited in Global Attacks

Zimbra patched nine vulnerabilities in its Collaboration Suite, including a critical RCE flaw (CVE-2026-73570) that attackers are currently exploiting to take control of mail servers. Organizations should update to version 10.1.20 and check logs for signs of compromise.

**If you run Zimbra Collaboration Suite, update to version 10.1.20 ASAP. Attackers are already exploiting this to take over mail servers, and everything older is vulnerable. Because this flaw is being actively exploited, also check for signs of breach: look for unexpected files in `/opt/zimbra/jetty/webapps/` and `/tmp/`, and review `/var/log/zimbra.log` for services restarting on their own.**

beyondmachines.net/event_detai

##

secdb@infosec.exchange at 2026-08-21T19:00:10.000Z ##

🚨 [CISA-2026:0821] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-69836 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Entra ID Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Entra ID
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-73570 (secdb.nttzen.cloud/cve/detail/)
- Name: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Synacor
- Product: Zimbra Collaboration Suite (ZCS)
- Notes: wiki.zimbra.com/wiki/Zimbra_Se ; blog.zimbra.com/2026/07/patch- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260821 #cisa20260821 #cve_2026_69836 #cve_2026_73570 #cve202669836 #cve202673570

##

cisakevtracker@mastodon.social at 2026-08-21T17:01:04.000Z ##

CVE ID: CVE-2026-73570
Vendor: Synacor
Product: Zimbra Collaboration Suite (ZCS)
Date Added: 2026-08-21
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

beyondmachines1@infosec.exchange at 2026-08-21T09:01:12.000Z ##

Critical Zimbra RCE Vulnerability Exploited in Global Attacks

Zimbra patched nine vulnerabilities in its Collaboration Suite, including a critical RCE flaw (CVE-2026-73570) that attackers are currently exploiting to take control of mail servers. Organizations should update to version 10.1.20 and check logs for signs of compromise.

**If you run Zimbra Collaboration Suite, update to version 10.1.20 ASAP. Attackers are already exploiting this to take over mail servers, and everything older is vulnerable. Because this flaw is being actively exploited, also check for signs of breach: look for unexpected files in `/opt/zimbra/jetty/webapps/` and `/tmp/`, and review `/var/log/zimbra.log` for services restarting on their own.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-08-20T22:20:00.000Z ##

CVE-2026-73570 in Zimbra Collaboration Suite is under active exploitation. CERT Polska flagged real-world attacks this week. The flaw grants unauthenticated remote OS command execution when zimbra-snmp is installed with SNMP enabled. Attacker identity and campaign goals remain unknown — patch priority is critical for affected deployments.

#Zimbra #CVE202673570 #ThreatIntelligence #PatchNow

cyberworldops.eu/en/zimbra-cve

##

cyberworldops@infosec.exchange at 2026-08-20T18:20:00.000Z ##

Active exploitation of CVE-2026-73570 in Zimbra Collaboration Suite is underway. The command injection flaw enables unauthenticated RCE on ZCS versions prior to 10.1.20 when zimbra-snmp is installed with SNMP notifications active. Attackers exploit this via crafted SMTP requests for full server compromise. Patch or disable SNMP immediately.

#ZimbraRCE #CVE202673570 #PatchNow

cyberworldops.eu/en/zimbra-vul

##

offseq@infosec.exchange at 2026-08-20T10:30:27.000Z ##

CRITICAL: CVE-2026-73570 in Zimbra Collaboration Suite is under active exploit. RCE via SNMP notifications lets unauth attackers run OS commands as Zimbra user. Patch to 10.1.20 now & monitor for abnormal files/restarts. Details: radar.offseq.com/threat/critic #OffSeq #Zimbra #Vuln

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T02:38:01.000Z ##

CVE-2026-73570 is exploited in the wild. This unauthenticated RCE hits Zimbra Collaboration via SNMP notifications. Patch to 10.1.20 now.

#Zimbra #CVE #RCE #RemoteCodeExecution #ExploitedInTheWild #InfoSec #PatchNow

securityonline.info/zimbra-cve

##

CVE-2026-76017
(8.8 HIGH)

EPSS: 0.36%

updated 2026-08-21T19:17:50.497000

1 posts

Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)

CVE-2026-63462
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-21T19:17:31.927000

2 posts

Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/bad-data-error.ts passes a raw request value from lodash.get to JSON.stringify in genericErrorMessage and fromOpenApiValidationErrors without guarding stack exhaustion. An unauthenticated attacker can send a roughly 10 KB JSON value nested thousands of

thehackerwire@mastodon.social at 2026-08-21T20:00:16.000Z ##

🟠 CVE-2026-63462 - High (7.5)

Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/bad-data-error.ts passes a raw request value from lodash.get to JSON.stringify in genericErrorMessag...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T20:00:16.000Z ##

🟠 CVE-2026-63462 - High (7.5)

Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/bad-data-error.ts passes a raw request value from lodash.get to JSON.stringify in genericErrorMessag...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54682
(8.2 HIGH)

EPSS: 0.00%

updated 2026-08-21T19:17:03.610000

2 posts

DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/Exporting/MessageGroupTemplate.cshtml and render it without HTML entity encoding. The affected fields include message.Content, message.ForwardedMessage.C

thehackerwire@mastodon.social at 2026-08-21T20:00:29.000Z ##

🟠 CVE-2026-54682 - High (8.2)

DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T20:00:29.000Z ##

🟠 CVE-2026-54682 - High (8.2)

DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54071
(7.8 HIGH)

EPSS: 0.00%

updated 2026-08-21T19:17:02.720000

2 posts

BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/pdfminer/cmapdb.py deserializes untrusted pickle data when CMapDB._load_data() loads CMap files. PDF-controlled Encoding or CMapName values and embedded PostScript usecmap operators can reach this sink after path separators are decoded, while _normalize_cmap_name() removes only a leading slash. Abso

thehackerwire@mastodon.social at 2026-08-21T20:00:43.000Z ##

🟠 CVE-2026-54071 - High (7.8)

BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/pdfminer/cmapdb.py deserializes untrusted pickle data when CMapDB._load_data() loads CMap files. PDF-controlled Encoding or CMapName values and emb...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T20:00:43.000Z ##

🟠 CVE-2026-54071 - High (7.8)

BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/pdfminer/cmapdb.py deserializes untrusted pickle data when CMapDB._load_data() loads CMap files. PDF-controlled Encoding or CMapName values and emb...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76397
(8.1 HIGH)

EPSS: 0.25%

updated 2026-08-21T18:56:07.450000

1 posts

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolkit does not preserve the trusted experiment scope when it processes caller-controlled query values before accessing restricted history data. For more info

thehackerwire@mastodon.social at 2026-08-20T05:00:14.000Z ##

🟠 CVE-2026-76397 - High (8.1)

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolki...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75932
(8.6 HIGH)

EPSS: 0.00%

updated 2026-08-21T18:35:02

2 posts

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client ID and Client Secret if the victim is using an OAuth provider.

thehackerwire@mastodon.social at 2026-08-21T17:00:47.000Z ##

🟠 CVE-2026-75932 - High (8.6)

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T17:00:47.000Z ##

🟠 CVE-2026-75932 - High (8.6)

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69502
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-08-21T18:35:01

2 posts

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-08-21T17:00:55.000Z ##

🔴 CVE-2026-69502 - Critical (10)

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T17:00:55.000Z ##

🔴 CVE-2026-69502 - Critical (10)

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75501(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-08-21T18:34:56

2 posts

A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router allows unauthenticated remote attackers to modify NAT port‑forwarding rules via the UPnP WANIPConnection service. The device exposes the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls. A remote attacker can send crafted SOAP requests to add, delete, or enumerate port m

DailyCyberSecurity at 2026-08-21T16:32:05.916Z ##

CVE-2026-75501 exposes an unauthenticated UPnP service on Calix routers. Public details and PoC code show how attackers bypass NAT and firewall protections.

securityonline.info/cve-2026-7

##

DailyCyberSecurity@infosec.exchange at 2026-08-21T16:32:05.000Z ##

CVE-2026-75501 exposes an unauthenticated UPnP service on Calix routers. Public details and PoC code show how attackers bypass NAT and firewall protections.

#CVE202675501 #Calix #UPnP #RouterSecurity #NAT #IoTSecurity

securityonline.info/cve-2026-7

##

CVE-2026-77812
(0 None)

EPSS: 0.00%

updated 2026-08-21T18:16:52.527000

2 posts

DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the drone over Wi-Fi, or when the drone is switched to QuickTransfer mode, the DJI Fly application exchanges DUML messages with the drone over BLE, including the Wi-Fi credentials. An attacker within BLE range can passively sniff this t

CVE-2026-77806
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-21T18:16:52.373000

2 posts

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.

DailyCyberSecurity at 2026-08-21T16:59:33.307Z ##

CVE-2026-77806, a CVSS 9.8 SPIP unauthenticated RCE, is exploited in the wild. A public Metasploit module and full details are now available.

securityonline.info/cve-2026-7

##

DailyCyberSecurity@infosec.exchange at 2026-08-21T16:59:33.000Z ##

CVE-2026-77806, a CVSS 9.8 SPIP unauthenticated RCE, is exploited in the wild. A public Metasploit module and full details are now available.

#CVE202677806 #SPIP #RCE #ExploitedInTheWild #Metasploit #CMS

securityonline.info/cve-2026-7

##

CVE-2026-72848
(8.6 HIGH)

EPSS: 0.48%

updated 2026-08-21T18:16:50.890000

1 posts

SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nested sitemap elements passes the child loc straight to self.scrape_all([loc.text], "xml"), which reaches WebBaseLoader.scrape_all and an aiohttp GET, with no dom

thehackerwire@mastodon.social at 2026-08-20T23:00:58.000Z ##

🟠 CVE-2026-72848 - High (8.6)

SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nested sit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71862
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-21T18:16:50.730000

2 posts

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global showURL setting causes the unauthenticated GET /api/v1/status-page/:url endpoint to return complete monitor objects from server/src/controllers/statusPageController.ts. The response

thehackerwire@mastodon.social at 2026-08-21T19:00:55.000Z ##

🟠 CVE-2026-71862 - High (7.5)

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global showURL setting causes the u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T19:00:55.000Z ##

🟠 CVE-2026-71862 - High (7.5)

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global showURL setting causes the u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69836
(10.0 CRITICAL)

EPSS: 1.37%

updated 2026-08-21T18:16:50.120000

16 posts

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

1 repos

https://github.com/HORKimhab/CVE-2026-69836

secdb at 2026-08-21T19:00:10.468Z ##

🚨 [CISA-2026:0821] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-69836 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Entra ID Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Entra ID
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-73570 (secdb.nttzen.cloud/cve/detail/)
- Name: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Synacor
- Product: Zimbra Collaboration Suite (ZCS)
- Notes: wiki.zimbra.com/wiki/Zimbra_Se ; blog.zimbra.com/2026/07/patch- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cR0w at 2026-08-21T17:04:39.206Z ##

CVE-2026-69836 was added to the KEV. It was published yesterday by Microsoft:

msrc.microsoft.com/update-guid

Microsoft says:

Publicly disclosed: No
Exploited: No
Exploitability assessment: Exploitation Less Likely

and

This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.

So does this mean that Microsoft was made aware by a third party that it was EITW? Because presumably it was exploited before it was published if no action is needed by the customer and Microsoft doesn't list it as EITW.

Edit: I now see this revision in the advisory:

Corrected Exploited to No. This vulnerability was not exploited in the wild. This is an informational change only.

So I assume that because it was incorrectly listed as EITW it ended up in the KEV. But now they say it wasn't EITW. Which is it? That's kind of important you fucking sloppy ass clanker fuckers.

##

cisakevtracker@mastodon.social at 2026-08-21T17:00:49.000Z ##

CVE ID: CVE-2026-69836
Vendor: Microsoft
Product: Entra ID
Date Added: 2026-08-21
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

benzogaga33@mamot.fr at 2026-08-21T15:40:03.000Z ##

Entra ID : une faille critique a été exploitée, mais vous n’avez rien à patcher it-connect.fr/entra-id-cve-202 #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft #EntraID

##

CapTechGroup@mastodon.social at 2026-08-21T12:52:36.000Z ##

A maximum-severity CVSS 10.0 flaw in Microsoft Entra ID is under active exploitation, allowing remote code execution. Two CVEs are in play, CVE-2026-68820 and CVE-2026-69836, with activity attributed to the Lazarus Group.

captechgroup.com/threat-intell

##

cyberworldops at 2026-08-21T12:20:00.667Z ##

A critical deserialization vulnerability (CVE-2026-69836) has been actively exploited in Microsoft Entra ID. The flaw could allow unauthorized access to identity and access management functions across Azure, M365, and Dynamics CRM Online.

cyberworldops.eu/en/cve-2026-6

##

tugatech@masto.pt at 2026-08-21T12:07:17.000Z ##

Microsoft corrige falha crítica no Entra ID, uma vulnerabilidade que permitia a execução de código malicioso sem privilégios. A falha, classificada como CVE-2026-69836, já foi explorada em ataques informáticos. 🛡️

🔗 tugatech.com.pt/t89674-microso

#falha #microsoft 

##

Analyst207@mastodon.social at 2026-08-21T11:25:44.000Z ##

Microsoft patches exploited Entra ID flaw amid rising attacks

Microsoft has patched a critical vulnerability in its Entra ID platform, known as CVE-2026-69836, which allowed attackers to execute code remotely with ease, and has already been exploited in recent attacks. This flaw enabled unauthorized threat actors to gain control and wreak havoc, making swift action crucial to prevent…

osintsights.com/microsoft-patc

#MicrosoftEntraId #IdentityManagement #Cve202669836 #ZeroDay #EmergingThreats

##

secdb@infosec.exchange at 2026-08-21T19:00:10.000Z ##

🚨 [CISA-2026:0821] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-69836 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Entra ID Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Entra ID
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-73570 (secdb.nttzen.cloud/cve/detail/)
- Name: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Synacor
- Product: Zimbra Collaboration Suite (ZCS)
- Notes: wiki.zimbra.com/wiki/Zimbra_Se ; blog.zimbra.com/2026/07/patch- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260821 #cisa20260821 #cve_2026_69836 #cve_2026_73570 #cve202669836 #cve202673570

##

cR0w@infosec.exchange at 2026-08-21T17:04:39.000Z ##

CVE-2026-69836 was added to the KEV. It was published yesterday by Microsoft:

msrc.microsoft.com/update-guid

Microsoft says:

Publicly disclosed: No
Exploited: No
Exploitability assessment: Exploitation Less Likely

and

This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.

So does this mean that Microsoft was made aware by a third party that it was EITW? Because presumably it was exploited before it was published if no action is needed by the customer and Microsoft doesn't list it as EITW.

Edit: I now see this revision in the advisory:

Corrected Exploited to No. This vulnerability was not exploited in the wild. This is an informational change only.

So I assume that because it was incorrectly listed as EITW it ended up in the KEV. But now they say it wasn't EITW. Which is it? That's kind of important you fucking sloppy ass clanker fuckers.

##

cisakevtracker@mastodon.social at 2026-08-21T17:00:49.000Z ##

CVE ID: CVE-2026-69836
Vendor: Microsoft
Product: Entra ID
Date Added: 2026-08-21
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

benzogaga33@mamot.fr at 2026-08-21T15:40:03.000Z ##

Entra ID : une faille critique a été exploitée, mais vous n’avez rien à patcher it-connect.fr/entra-id-cve-202 #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft #EntraID

##

cyberworldops@infosec.exchange at 2026-08-21T12:20:00.000Z ##

A critical deserialization vulnerability (CVE-2026-69836) has been actively exploited in Microsoft Entra ID. The flaw could allow unauthorized access to identity and access management functions across Azure, M365, and Dynamics CRM Online.

#CriticalVulnerability #MicrosoftEntra #IdentitySecurity #Deserialization

cyberworldops.eu/en/cve-2026-6

##

tugatech@masto.pt at 2026-08-21T12:07:17.000Z ##

Microsoft corrige falha crítica no Entra ID, uma vulnerabilidade que permitia a execução de código malicioso sem privilégios. A falha, classificada como CVE-2026-69836, já foi explorada em ataques informáticos. 🛡️

🔗 tugatech.com.pt/t89674-microso

#falha #microsoft 

##

ottoto2017@prattohome.com at 2026-08-21T07:08:22.000Z ##

「Microsoft Entra IDの脆弱性(CVSS 10.0)が実際に悪用され、リモートコード実行が可能になる 」: #TheHackerNews

「マイクロソフトは木曜日、Entra IDに重大なセキュリティ上の欠陥があり、既に悪用されていると警告したが、顧客による対応は不要であると述べた。

CVE-2026-69836 (CVSSスコア:10.0)として追跡されているこの脆弱性は、 リモートコード実行によって、このテクノロジー大手企業のクラウドベースのIDおよびアクセス管理サービスに影響を与える事例です。このサービスは以前はAzure Active DirectoryまたはAzure ADと呼ばれていました。

マイクロソフトは木曜日に発表した警告の中で、 「Microsoft Entra IDにおける信頼できないデータの逆シリアル化により、権限のない攻撃者がネットワーク上でコードを実行できる可能性がある」 と述べた。 」

thehackernews.com/2026/08/micr

#prattohome

##

DailyCyberSecurity@infosec.exchange at 2026-08-21T02:29:49.000Z ##

CVE-2026-69836, a CVSS 10 Entra ID remote code execution flaw, was exploited in the wild. Microsoft has fully mitigated it server-side.

#CVE202669836 #EntraID #RemoteCodeExecution #Microsoft #CloudSecurity #RCE

securityonline.info/cve-2026-6

##

CVE-2026-62674
(9.0 CRITICAL)

EPSS: 0.00%

updated 2026-08-21T18:16:49.460000

2 posts

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not reject a bound shared or template agent whose agent.session_id is None. An authenticated user with edit access to a session can replace that shared agent bundle through omnigent/server/routes/session

thehackerwire@mastodon.social at 2026-08-21T19:01:04.000Z ##

🔴 CVE-2026-62674 - Critical (9)

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not reject a bound shared or template agent whose ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T19:01:04.000Z ##

🔴 CVE-2026-62674 - Critical (9)

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not reject a bound shared or template agent whose ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76590
(9.9 CRITICAL)

EPSS: 0.61%

updated 2026-08-21T17:16:46

2 posts

A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument cameo.wan.wan_pppoe_password_00 leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.

offseq@infosec.exchange at 2026-08-20T00:00:37.000Z ##

CVE-2026-76590: CRITICAL stack buffer overflow in TRENDnet TEW-755AP (/cgi-bin/wan.cgi, CVSS 9.4). Remote code execution possible. No patch — restrict access, monitor endpoints. Exploit code public, no active attacks yet. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSec #CVE2026

##

thehackerwire@mastodon.social at 2026-08-19T23:01:04.000Z ##

🔴 CVE-2026-76590 - Critical (9.9)

A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument cameo.wan.wan_pppoe_password_00 leads to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73040
(8.8 HIGH)

EPSS: 0.67%

updated 2026-08-21T17:16:43.950000

1 posts

Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0-9_-]+$, is reached from save() alone, while the path getter returns path.join(this.server.stacksDir, this.name) and Stack.getStack builds path.join(server.stacksDir, stackName) with no check. The socket handlers in backend/agent-socket-handlers/docke

thehackerwire@mastodon.social at 2026-08-20T22:00:25.000Z ##

🟠 CVE-2026-73040 - High (8.8)

Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0-9_-]+$, is reached from save() alone, while the path getter returns path.join(this.server.stacksD...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67567
(9.9 CRITICAL)

EPSS: 0.32%

updated 2026-08-21T17:16:41.320000

3 posts

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount privileges without proper validation. This enables the tenant to deploy arbitrary reso

DailyCyberSecurity at 2026-08-21T08:11:18.173Z ##

Three Red Hat flaws enable privilege escalation, led by CVE-2026-67567 (CVSS 9.9) in ACM. Two FreeIPA bugs can reach full domain compromise.

securityonline.info/red-hat-pr

##

DailyCyberSecurity@infosec.exchange at 2026-08-21T08:11:18.000Z ##

Three Red Hat flaws enable privilege escalation, led by CVE-2026-67567 (CVSS 9.9) in ACM. Two FreeIPA bugs can reach full domain compromise.

#RedHat #CVE202667567 #PrivilegeEscalation #FreeIPA #Kubernetes #ACM

securityonline.info/red-hat-pr

##

thehackerwire@mastodon.social at 2026-08-20T22:01:26.000Z ##

🔴 CVE-2026-67567 - Critical (9.9)

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller pr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39909
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-21T17:16:30.810000

2 posts

llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows unauthenticated remote attackers to achieve arbitrary read and write access by storing a computation graph, freeing referenced buffers, and reclaiming freed memory with attacker-controlled content. Attackers can send RPC requests to trigger re-execution of stored graphs with dangl

thehackerwire@mastodon.social at 2026-08-21T17:59:50.000Z ##

🟠 CVE-2026-39909 - High (8.1)

llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows unauthenticated remote attackers to achieve arbitrary read and write access by storing a computation graph, freeing referenced b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T17:59:50.000Z ##

🟠 CVE-2026-39909 - High (8.1)

llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows unauthenticated remote attackers to achieve arbitrary read and write access by storing a computation graph, freeing referenced b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77087
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-08-21T16:18:21.993000

3 posts

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the process adapter.

hugovalters@mastodon.social at 2026-08-21T17:06:05.000Z ##

CVE-2026-77087 - Critical RCE in Paperclip <0.3.1 via DNS rebinding. Host header validation flaw allows authenticated API abuse. CVSS 9.6. No patch yet - update when available. #CVE #infosec #Paperclip

valtersit.com/cve/CVE-2026-770

##

thehackerwire@mastodon.social at 2026-08-21T16:00:10.000Z ##

🔴 CVE-2026-77087 - Critical (9.6)

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T16:00:10.000Z ##

🔴 CVE-2026-77087 - Critical (9.6)

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18781
(8.1 HIGH)

EPSS: 0.21%

updated 2026-08-21T15:33:14

1 posts

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server.

offseq@infosec.exchange at 2026-08-21T07:30:24.000Z ##

CVE-2026-18781: CRITICAL code injection in Drag and Drop Multiple File Upload for Contact Form 7 <1.3.9.9. Unauthenticated users can run code on affected WordPress servers. No patch yet — restrict or disable plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #CVE202618781

##

CVE-2026-77814
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-21T15:32:19

2 posts

is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.startswith(parent_path), without appending a path separator. A directory whose name merely begins with an allowed path therefore satisfies the comparison, so where /data/images is allowed a request for /data/images_private/secret.txt is treated as trusted and served by FileResponse, di

thehackerwire@mastodon.social at 2026-08-21T16:00:20.000Z ##

🟠 CVE-2026-77814 - High (7.5)

is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.startswith(parent_path), without appending a path separator. A directory whose name merely begins with an allowed path therefore sati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T16:00:20.000Z ##

🟠 CVE-2026-77814 - High (7.5)

is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.startswith(parent_path), without appending a path separator. A directory whose name merely begins with an allowed path therefore sati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77815
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-21T15:32:18

2 posts

to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links. A symlink placed inside a scanned directory therefore satisfies the containment comparison performed by is_path_trusted in scripts/iib/api.py while pointing outside that directory, and FileResponse follows the link when serving the response, so a

thehackerwire@mastodon.social at 2026-08-21T16:00:31.000Z ##

🟠 CVE-2026-77815 - High (7.5)

to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links. A symlink placed inside a scanned directory therefore satisfies the containment comparison pe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T16:00:31.000Z ##

🟠 CVE-2026-77815 - High (7.5)

to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links. A symlink placed inside a scanned directory therefore satisfies the containment comparison pe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77645
(0 None)

EPSS: 0.47%

updated 2026-08-21T15:16:47.430000

1 posts

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.

offseq@infosec.exchange at 2026-08-21T00:00:37.000Z ##

CRITICAL RCE flaw (CVE-2026-77645) in PTC Windchill PDMLink (multiple versions). Unauthenticated attackers can execute remote code via insecure deserialization. No patch yet — restrict access & monitor closely. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #PTC #Infosec

##

CVE-2026-63125
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-08-21T15:16:46.427000

1 posts

Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on the host. A crafted image ships `backup.yaml` as a symlink to a host file. When the root daemon writes the instance's backup file, it follows the symlin

hugovalters@mastodon.social at 2026-08-21T18:03:44.000Z ##

CVE-2026-63125 – Critical RCE/privesc in Incus. Unprivileged user can execute code as root via symlink attack. CVSS 9.9. Patch to 7.3.0 immediately. #CVE #Incus #infosec

valtersit.com/cve/CVE-2026-631

##

CVE-2026-59279
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-21T15:16:42.257000

2 posts

The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to accumulate an unbounded number of sessions over time, gradually exhausting available memory and ultimately causing a Denial of Service that affects al

thehackerwire@mastodon.social at 2026-08-21T14:00:36.000Z ##

🟠 CVE-2026-59279 - High (7.5)

The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T14:00:36.000Z ##

🟠 CVE-2026-59279 - High (7.5)

The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-21580
(0 None)

EPSS: 0.36%

updated 2026-08-21T15:16:39.883000

1 posts

This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server. This Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability,

DailyCyberSecurity@infosec.exchange at 2026-08-19T06:40:51.000Z ##

A Confluence vulnerability, CVE-2026-21580, is a stored XSS flaw (CVSS 8.6) allowing unauthenticated attacks. A Jira flaw also patched. Update now.

#Atlassian #Confluence #CVE202621580 #StoredXSS #Jira #InfoSec

securityonline.info/confluence

##

CVE-2026-76156
(0 None)

EPSS: 0.83%

updated 2026-08-21T14:16:53.017000

1 posts

OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root.

offseq@infosec.exchange at 2026-08-21T04:30:26.000Z ##

CVE-2026-76156: CRITICAL OS command injection in Datiphy Data Management Center (8.3.0 – 8.5.1). Authenticated admins can run root OS commands via API. No patch yet — restrict admin access, monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #CVE202676156 #Vuln #Infosec

##

CVE-2026-50112
(8.8 HIGH)

EPSS: 0.17%

updated 2026-08-21T14:16:50.423000

2 posts

SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing internal targets. The Secondary Storage VM will retrieve the data and persist it as a template file, which can later be downloaded through normal APIs. RCE on KVM hypervisor via NFS, Metalink files with/without Direct Downloads: An authenticated Cl

DailyCyberSecurity at 2026-08-21T15:57:22.657Z ##

Apache CloudStack patched 20 flaws. CVE-2026-50112, a critical bug, allows cross-tenant remote code execution as root on KVM hypervisor hosts.

securityonline.info/cve-2026-5

##

DailyCyberSecurity@infosec.exchange at 2026-08-21T15:57:22.000Z ##

Apache CloudStack patched 20 flaws. CVE-2026-50112, a critical bug, allows cross-tenant remote code execution as root on KVM hypervisor hosts.

#ApacheCloudStack #CVE202650112 #RCE #KVM #CloudSecurity #IaaS

securityonline.info/cve-2026-5

##

CVE-2026-77683
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-08-21T12:30:37

2 posts

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone. The manipulation of the argument timestr results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

offseq at 2026-08-21T10:30:27.958Z ##

CVE-2026-77683: CRITICAL command injection in Comfast CF-N1-S (2.6.0.1) via /cgi-bin/mbox-config timestr parameter. Public exploit available, remote exploitation possible. Patch unavailable. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-21T10:30:27.000Z ##

CVE-2026-77683: CRITICAL command injection in Comfast CF-N1-S (2.6.0.1) via /cgi-bin/mbox-config timestr parameter. Public exploit available, remote exploitation possible. Patch unavailable. radar.offseq.com/threat/cve-20 #OffSeq #CVE202677683 #IoTSecurity #CommandInjection

##

CVE-2026-77775
(8.6 HIGH)

EPSS: 0.00%

updated 2026-08-21T12:30:35

2 posts

Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with an http or https scheme and a hostname, and returns it for use as the upstream base; _select_passthrough_base_url in headroom/providers/proxy_routes.py reads the

thehackerwire@mastodon.social at 2026-08-21T14:00:11.000Z ##

🟠 CVE-2026-77775 - High (8.6)

Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with an http o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T14:00:11.000Z ##

🟠 CVE-2026-77775 - High (8.6)

Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with an http o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77776
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-08-21T12:16:36.967000

5 posts

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the value to the caller. A client can therefore name another user's identifier and read or write that user's stored LLM memory. The fix introduces a single r

hugovalters@mastodon.social at 2026-08-21T15:02:38.000Z ##

CVE-2026-77776 - Critical IDOR in Headroom LLM proxy. Spoof x-headroom-user-id to read/write other users' memory. CVSS 9.1. No patch yet - restrict access now. #CVE #Headroom #infosec

valtersit.com/cve/CVE-2026-777

##

thehackerwire@mastodon.social at 2026-08-21T14:00:24.000Z ##

🔴 CVE-2026-77776 - Critical (9.1)

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-21T12:00:31.471Z ##

CRITICAL: CVE-2026-77776 in Headroom Labs Headroom (<0.36.1) allows unauth'd attackers to spoof x-headroom-user-id and access/modify any user's LLM memory. Default configs expose this via 0.0.0.0 binding. Restrict access & use auth tokens. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-21T14:00:24.000Z ##

🔴 CVE-2026-77776 - Critical (9.1)

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-21T12:00:31.000Z ##

CRITICAL: CVE-2026-77776 in Headroom Labs Headroom (<0.36.1) allows unauth'd attackers to spoof x-headroom-user-id and access/modify any user's LLM memory. Default configs expose this via 0.0.0.0 binding. Restrict access & use auth tokens. radar.offseq.com/threat/cve-20 #OffSeq #CVE #infosec #LLM

##

CVE-2026-76234
(7.5 HIGH)

EPSS: 0.22%

updated 2026-08-21T12:16:33.233000

1 posts

libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain cryptographic implementation bugs. libcrux-ecdh did not properly check length and clamping during X25519 secret validation (and had a broken clamping check for imported X25519 secret keys); libcrux-ed25519 performed a duplicated clamping step during key generation; and libcrux-psq panicked instead of propagating a

thehackerwire@mastodon.social at 2026-08-19T15:00:19.000Z ##

🟠 CVE-2026-76234 - High (7.5)

libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain cryptographic implementation bugs. libcrux-ecdh did not properly check length and clamping during X25519 secret validation (and had a broken clamping check for im...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76310
(9.4 CRITICAL)

EPSS: 0.37%

updated 2026-08-21T04:18:20.733000

1 posts

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material, and use it to access all relevant data available to the report owner and affect system integrity, including by performing administrative actions when the owner holds the "admin" Splunk r

CVE-2026-75144
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-21T04:18:19.900000

1 posts

FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit. The packetizer copies an input-derived data unit or fragment size into a fixed-size buffer without an upper bound check, causing a heap buffer overflow when the crafted inp

thehackerwire@mastodon.social at 2026-08-19T18:01:28.000Z ##

🟠 CVE-2026-75144 - High (7.8)

FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit. The packetizer copi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75141
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-21T04:18:19.413000

1 posts

FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffer overflow. A crafted HEVC input file triggers the overflow during muxing.

thehackerwire@mastodon.social at 2026-08-19T18:00:20.000Z ##

🟠 CVE-2026-75141 - High (7.8)

FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap bu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67364
(0 None)

EPSS: 0.29%

updated 2026-08-21T04:18:14.833000

1 posts

Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, letting an unauthenticated attacker inject arbitrar

offseq@infosec.exchange at 2026-08-19T13:30:25.000Z ##

CVE-2026-67364 (CVSS 10): CRITICAL pre-auth PHP code injection in Balbooa Forms for Joomla (v1.0.0 – 2.4.3.1). Exploitable via unescaped query param in custom-PHP handler. Update to 2.4.3.2+ now. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #CVE202667364 #WebSecurity

##

CVE-2026-76158(CVSS UNKNOWN)

EPSS: 0.41%

updated 2026-08-21T03:31:30

1 posts

External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.

offseq@infosec.exchange at 2026-08-21T03:00:24.000Z ##

CVE-2026-76158: Datiphy Data Management Center 8.3.0 faces CRITICAL vuln (CVSS 9.3) — upload API allows unauthenticated file writes anywhere via path traversal 🗂️. Restrict access & monitor uploads until patch. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Datiphy #CVE202676158

##

CVE-2026-76155(CVSS UNKNOWN)

EPSS: 0.29%

updated 2026-08-21T03:31:29

1 posts

Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform by logging in with default administrator credentials.

offseq@infosec.exchange at 2026-08-21T06:00:24.000Z ##

Datiphy Data Management Center 8.3.0 hit by CRITICAL vuln (CVE-2026-76155) due to default admin creds. Remote attackers can gain full access. No patch yet — change credentials & limit access ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Vuln #Datiphy

##

CVE-2026-77651
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-08-21T03:31:29

1 posts

The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.

offseq@infosec.exchange at 2026-08-21T01:30:22.000Z ##

CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: radar.offseq.com/threat/cve-20 #OffSeq #RustLang #CVE2026 #Infosec

##

CVE-2026-77647
(9.8 CRITICAL)

EPSS: 0.81%

updated 2026-08-21T00:31:31

3 posts

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character.

netsecio@mastodon.social at 2026-08-21T17:46:07.000Z ##

📰 Critical RCE Flaw in SPIP CMS Under Active Exploitation

🚨 Critical RCE vulnerability (CVE-2026-77647, CVSS 9.8) in SPIP CMS is under active exploitation. The unauthenticated flaw allows full server takeover. All versions before 4.4.20 are vulnerable. #SPIP #RCE #Vulnerability #PatchNow

🔗 cyber.netsecops.io/articles/cr

##

DailyCyberSecurity@infosec.exchange at 2026-08-21T02:49:11.000Z ##

CVE-2026-77647, a CVSS 9.8 unauthenticated RCE in SPIP before 4.4.20, is exploited in the wild. Update now.

#SPIP #CVE202677647 #RCE #ExploitedInTheWild #CMS #WebSecurity

securityonline.info/cve-2026-7

##

thehackerwire@mastodon.social at 2026-08-21T00:00:04.000Z ##

🔴 CVE-2026-77647 - Critical (9.8)

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of &lt;?php blocks, and var_export&#039;s mishandling of certain cases such ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69855
(7.7 HIGH)

EPSS: 0.48%

updated 2026-08-21T00:31:31

1 posts

Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.

thehackerwire@mastodon.social at 2026-08-20T23:01:19.000Z ##

🟠 CVE-2026-69855 - High (7.7)

Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72860
(8.5 HIGH)

EPSS: 0.22%

updated 2026-08-21T00:31:31

1 posts

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That guard compares hostname strings only: it resolves no DNS, does not revalidate after a redirect, and its IPv4-mapped IPv6 branch is unreachable. The branch matches ^::ffff:(\d+\.\d+\.

thehackerwire@mastodon.social at 2026-08-20T23:01:08.000Z ##

🟠 CVE-2026-72860 - High (8.5)

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That guard compares hostname strin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72818
(7.5 HIGH)

EPSS: 0.51%

updated 2026-08-21T00:31:31

1 posts

The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisting of many alternating label separators can be partitioned in exponentially many ways, and because the branch also requires a trailing top-level domain t

thehackerwire@mastodon.social at 2026-08-20T23:00:07.000Z ##

🟠 CVE-2026-72818 - High (7.5)

The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisti...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77642
(7.5 HIGH)

EPSS: 0.19%

updated 2026-08-21T00:31:31

1 posts

tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.

thehackerwire@mastodon.social at 2026-08-20T22:59:57.000Z ##

🟠 CVE-2026-77642 - High (7.5)

tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-20...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72843
(9.8 CRITICAL)

EPSS: 0.57%

updated 2026-08-21T00:31:24

1 posts

The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the caller, and no customer-session middleware guards the route; the only middleware in the chain parses the JSON body. The handler in updateCustomer.js then loads the cust

thehackerwire@mastodon.social at 2026-08-20T23:00:18.000Z ##

🔴 CVE-2026-72843 - Critical (9.8)

The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the caller, and no ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66785
(9.9 CRITICAL)

EPSS: 0.29%

updated 2026-08-20T21:31:36

2 posts

A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted network endpoint. The system fails to properly validate the network subnets provided by the malicious cluster, enabling it to declare arbitrary network ranges. Consequently, all network traffic intended for

hugovalters@mastodon.social at 2026-08-21T11:14:14.000Z ##

CVE-2026-66785 - Critical network redirection flaw in Submariner. Malicious clusters can hijack peer traffic via crafted endpoints. CVSS 9.9. No patch yet - isolate clusters, monitor traffic. #CVE #Submariner #infosec

valtersit.com/cve/CVE-2026-667

##

thehackerwire@mastodon.social at 2026-08-20T21:00:21.000Z ##

🔴 CVE-2026-66785 - Critical (9.9)

A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted network endpoint. The system fails to properly valida...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72852
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-20T21:31:36

1 posts

hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken from a .cfg file in unchecked 32-bit int arithmetic. In src-lib/convolutional_layer.cpp, l.nweights is computed as (c / groups) * n * size * size and l.outputs as l.out_h * l.out_w * l.out_c, and both feed xcalloc directly. A .cfg whose true dimension product exceeds INT_MAX wraps

thehackerwire@mastodon.social at 2026-08-20T21:00:10.000Z ##

🟠 CVE-2026-72852 - High (7.8)

hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken from a .cfg file in unchecked 32-bit int arithmetic. In src-lib/convolutional_layer.cpp, l.nweights is computed as (c / groups) ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77148
(9.9 CRITICAL)

EPSS: 0.47%

updated 2026-08-20T21:31:36

1 posts

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.

thehackerwire@mastodon.social at 2026-08-20T21:00:00.000Z ##

🔴 CVE-2026-77148 - Critical (9.9)

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management. The manipulation results in stack-based buffer overflow. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19586(CVSS UNKNOWN)

EPSS: 5.04%

updated 2026-08-20T21:31:30

1 posts

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requir

CVE-2026-73137
(7.7 HIGH)

EPSS: 0.29%

updated 2026-08-20T21:31:30

1 posts

A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function in the HelmRelease controller to fetch sensitive credentials from any namespace, which are then sent to an attacker-cont

thehackerwire@mastodon.social at 2026-08-20T22:00:36.000Z ##

🟠 CVE-2026-73137 - High (7.7)

A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77638
(8.9 HIGH)

EPSS: 0.17%

updated 2026-08-20T21:31:30

1 posts

Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.

thehackerwire@mastodon.social at 2026-08-20T22:00:15.000Z ##

🟠 CVE-2026-77638 - High (8.9)

Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18420
(8.8 HIGH)

EPSS: 0.96%

updated 2026-08-20T21:17:06.137000

1 posts

Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution.  To remediate this issue, users should upgrade to OpenSearch Dashboards

thehackerwire@mastodon.social at 2026-08-20T22:01:36.000Z ##

🟠 CVE-2026-18420 - High (8.8)

Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. Th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73257
(9.1 CRITICAL)

EPSS: 0.38%

updated 2026-08-20T20:17:46.470000

1 posts

Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count checks in the mg_http_parse() and http_cb() paths in src/http.c accept both headers and prioritize chunked encoding, while a Content-Length-preferring reverse proxy can use

thehackerwire@mastodon.social at 2026-08-20T19:00:25.000Z ##

🔴 CVE-2026-73257 - Critical (9.1)

Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count checks in the mg_htt...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20315
(10.0 CRITICAL)

EPSS: 0.32%

updated 2026-08-20T19:16:51.673000

3 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20315 are related to improper access control issues that are

ottoto2017@prattohome.com at 2026-08-21T07:22:35.000Z ##

「Ciscoのバグの深刻度警告は、オリンピック体操競技の得点のように、10、10、9.9、9.6、7.5と表示されます。
/Secure Workload Softwareには5つの重大な欠陥があり、SaaSユーザーでさえアップデートをインストールする必要がある。 」: #TheRegister

「シスコは、ネットワーク内での攻撃者の横方向への移動を阻止することを目的としたマイクロセグメンテーションツールであるセキュアワークロードソフトウェア(旧称Tetration)に、4つの重大な欠陥と、さらに1つの深刻なバグが存在することを明らかにした。

CVE-2026-20315とCVE-2026-20317は、最高評価の10点満点バグです。どちらも不適切なアクセス制御に関連しています。 」

theregister.com/security/2026/

#prattohome

##

AAKL@infosec.exchange at 2026-08-20T20:15:43.000Z ##

CISA has added two known vulnerabilities to the KEV catalogue.

- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-72530: TrueConf Server Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Yesterday:

Cisco:

CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T02:06:30.000Z ##

Cisco patches Secure Workload flaws CVE-2026-20315 and CVE-2026-20317, an authentication bypass and privilege escalation pair scoring CVSS 10. Upgrade now.

#Cisco #CVE #AuthenticationBypass #PrivilegeEscalation #Vulnerability #InfoSec #PatchNow

securityonline.info/cisco-secu

##

CVE-2026-16885
(9.8 CRITICAL)

EPSS: 0.80%

updated 2026-08-20T19:16:50.880000

1 posts

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

offseq@infosec.exchange at 2026-08-20T06:00:23.000Z ##

Stack-based buffer overflow (CVE-2026-16885) in IBM AIX 7.2, 7.3 & PowerVM VIOS 4.1 (CRITICAL, CVSS 9.8). Remote, unauthenticated code execution possible. No patch yet — monitor IBM advisories. radar.offseq.com/threat/cve-20 #OffSeq #IBM #AIX #Vuln

##

CVE-2026-72530
(9.0 None)

EPSS: 0.97%

updated 2026-08-20T18:31:47

6 posts

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

Matchbook3469@mastodon.social at 2026-08-21T15:06:36.000Z ##

🔴 New security advisory:

CVE-2026-72530 affects Trueconf Server.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#InfoSec #ZeroDay #ThreatIntel

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T21:30:12.000Z ##

CISA confirms two TrueConf Server flaws, CVE-2026-72529 and CVE-2026-72530, are exploited in the wild to deliver PhantomCore malware. Patch now.

#TrueConf #CVE #ExploitedInTheWild #PhantomCore #HeadMare #InfoSec #PatchNow

securityonline.info/trueconf-c

##

AAKL@infosec.exchange at 2026-08-20T20:15:43.000Z ##

CISA has added two known vulnerabilities to the KEV catalogue.

- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-72530: TrueConf Server Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Yesterday:

Cisco:

CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

secdb@infosec.exchange at 2026-08-20T19:00:11.000Z ##

🚨 [CISA-2026:0820] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-72529 (secdb.nttzen.cloud/cve/detail/)
- Name: TrueConf Server Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: TrueConf
- Product: Server
- Notes: trueconf.com/blog/news/securit ; ics-cert.kaspersky.com/advisor ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-72530 (secdb.nttzen.cloud/cve/detail/)
- Name: TrueConf Server Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: TrueConf
- Product: Server
- Notes: trueconf.com/blog/news/securit ; ics-cert.kaspersky.com/advisor ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260820 #cisa20260820 #cve_2026_72529 #cve_2026_72530 #cve202672529 #cve202672530

##

cisakevtracker@mastodon.social at 2026-08-20T18:01:06.000Z ##

CVE ID: CVE-2026-72530
Vendor: TrueConf
Product: Server
Date Added: 2026-08-20
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

thehackerwire@mastodon.social at 2026-08-19T18:01:44.000Z ##

🔴 CVE-2026-72530 - Critical (9)

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and exec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76641
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-20T18:31:11

1 posts

Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to read the attIndex member past allocated memory boundaries, resulting in failure to normalize whitespace in non-CDATA attr

thehackerwire@mastodon.social at 2026-08-20T19:00:04.000Z ##

🟠 CVE-2026-76641 - High (7.5)

Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18290
(7.8 HIGH)

EPSS: 0.26%

updated 2026-08-20T18:31:06

1 posts

OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGG fil

hugovalters@mastodon.social at 2026-08-21T12:07:43.000Z ##

CVE-2026-18290 - RCE in OriginLab OriginPro via OGG parsing. Out-of-bounds write leads to arbitrary code execution. CVSS 7.8. No patch yet; avoid opening untrusted OGG files. #CVE #OriginPro #infosec

valtersit.com/cve/CVE-2026-182

##

CVE-2026-77022
(9.9 CRITICAL)

EPSS: 0.46%

updated 2026-08-20T18:31:06

1 posts

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSID Configuration. The manipulation of the argument ssid results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks

thehackerwire@mastodon.social at 2026-08-20T18:00:20.000Z ##

🔴 CVE-2026-77022 - Critical (9.9)

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSID Configuration. The manipulation of the argument ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75140
(7.5 HIGH)

EPSS: 0.53%

updated 2026-08-20T18:30:58

1 posts

jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers ca

thehackerwire@mastodon.social at 2026-08-20T17:00:10.000Z ##

🟠 CVE-2026-75140 - High (7.5)

jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63038(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-08-20T18:30:58

1 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the dbName, tableName, schemaName, and username parameters.  This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https

DailyCyberSecurity@infosec.exchange at 2026-08-20T16:40:07.000Z ##

An Apache InLong SQL injection flaw, CVE-2026-63038, lets attackers inject SQL via multiple parameters. Two more bugs join it. Upgrade to 2.4.0.

#ApacheInLong #SQLInjection #CVE #SSRF #InfoSec #OpenSource

securityonline.info/apache-inl

##

CVE-2026-72529
(9.8 CRITICAL)

EPSS: 0.78%

updated 2026-08-20T18:30:43

6 posts

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

thecybermind at 2026-08-21T15:01:53.473Z ##

Critical Alert: CVE-2026-72529 allows unauthenticated command execution on TrueConf Servers. Our T-SUITE report maps the attack surface and provides immediate hardening steps to secure your perimeter. Read the full brief here. thecybermind.co/jily

##

thecybermind@infosec.exchange at 2026-08-21T15:01:53.000Z ##

Critical Alert: CVE-2026-72529 allows unauthenticated command execution on TrueConf Servers. Our T-SUITE report maps the attack surface and provides immediate hardening steps to secure your perimeter. Read the full brief here. thecybermind.co/jily

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T21:30:12.000Z ##

CISA confirms two TrueConf Server flaws, CVE-2026-72529 and CVE-2026-72530, are exploited in the wild to deliver PhantomCore malware. Patch now.

#TrueConf #CVE #ExploitedInTheWild #PhantomCore #HeadMare #InfoSec #PatchNow

securityonline.info/trueconf-c

##

AAKL@infosec.exchange at 2026-08-20T20:15:43.000Z ##

CISA has added two known vulnerabilities to the KEV catalogue.

- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-72530: TrueConf Server Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Yesterday:

Cisco:

CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

secdb@infosec.exchange at 2026-08-20T19:00:11.000Z ##

🚨 [CISA-2026:0820] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-72529 (secdb.nttzen.cloud/cve/detail/)
- Name: TrueConf Server Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: TrueConf
- Product: Server
- Notes: trueconf.com/blog/news/securit ; ics-cert.kaspersky.com/advisor ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-72530 (secdb.nttzen.cloud/cve/detail/)
- Name: TrueConf Server Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: TrueConf
- Product: Server
- Notes: trueconf.com/blog/news/securit ; ics-cert.kaspersky.com/advisor ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260820 #cisa20260820 #cve_2026_72529 #cve_2026_72530 #cve202672529 #cve202672530

##

cisakevtracker@mastodon.social at 2026-08-20T18:01:22.000Z ##

CVE ID: CVE-2026-72529
Vendor: TrueConf
Product: Server
Date Added: 2026-08-20
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-71428
(9.3 CRITICAL)

EPSS: 0.25%

updated 2026-08-20T17:19:40.773000

1 posts

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, and partition_md is fetched without host validation in unstructured/partition/auto.py, unstructured/partition/html/partition.py, and unstructured/partition/md.py. An

thehackerwire@mastodon.social at 2026-08-20T18:00:43.000Z ##

🔴 CVE-2026-71428 - Critical (9.3)

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, and partitio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14951
(8.0 HIGH)

EPSS: 0.16%

updated 2026-08-20T17:17:20.930000

1 posts

An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.

certvde@infosec.exchange at 2026-08-20T08:20:37.000Z ##

#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

#CSAF frauscher.csaf-tp.certvde.com/

##

CVE-2026-76879
(7.5 HIGH)

EPSS: 0.28%

updated 2026-08-20T16:18:21.780000

1 posts

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

thehackerwire@mastodon.social at 2026-08-20T01:04:17.000Z ##

🟠 CVE-2026-76879 - High (7.5)

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76832
(8.8 HIGH)

EPSS: 0.84%

updated 2026-08-20T16:18:20.903000

1 posts

Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in the file_name argument passed to read_file, save_to_file, or run_python_file tool actions. Attackers can inject traversal sequences such as '../../../../../../etc/passwd' through direct too

thehackerwire@mastodon.social at 2026-08-19T23:01:13.000Z ##

🟠 CVE-2026-76832 - High (8.8)

Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in the file_name argument passed to rea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76633
(8.1 HIGH)

EPSS: 0.24%

updated 2026-08-20T16:18:19.223000

1 posts

WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of the alterarSenha method from permission checks in controle/control.php. Attackers can manipulate the redir parameter to point to alterar_senha.php, routin

thehackerwire@mastodon.social at 2026-08-20T15:00:03.000Z ##

🟠 CVE-2026-76633 - High (8.1)

WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14953
(4.3 MEDIUM)

EPSS: 0.20%

updated 2026-08-20T16:17:07.463000

1 posts

A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.

certvde@infosec.exchange at 2026-08-20T08:20:37.000Z ##

#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

#CSAF frauscher.csaf-tp.certvde.com/

##

CVE-2026-14950
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-08-20T16:17:07.210000

3 posts

An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access to the FDS web interface.

DailyCyberSecurity@infosec.exchange at 2026-08-20T16:54:52.000Z ##

Frauscher FDS102 vulnerabilities include CVE-2026-14950 (CVSS 9.8), a session flaw enabling unauthorized continued access. Update to v2.14.0.

#Frauscher #FDS102 #ICS #RailwaySecurity #CVE #OTSecurity

securityonline.info/frauscher-

##

offseq@infosec.exchange at 2026-08-20T09:00:26.000Z ##

Frauscher FDS 102 v2.1.0 hit by CRITICAL vuln (CVE-2026-14950): insufficient session expiration lets remote attackers keep using stolen session tokens. No patch yet — monitor sessions, restrict access. radar.offseq.com/threat/cve-20 #OffSeq #ICS #CVE202614950 #Security

##

certvde@infosec.exchange at 2026-08-20T08:20:37.000Z ##

#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

#CSAF frauscher.csaf-tp.certvde.com/

##

CVE-2026-76833
(7.8 HIGH)

EPSS: 0.15%

updated 2026-08-20T15:34:26

1 posts

@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a custom !js YAML tag whose construct callback unconditionally calls eval() on attacker-supplied string values during document parsing. Any application parsing untrusted YAML input with this library exposes full Node.js runtime authority, including environm

thehackerwire@mastodon.social at 2026-08-20T14:59:52.000Z ##

🟠 CVE-2026-76833 - High (7.8)

@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a custom !js YAML tag whose construct callback unconditionally calls eval() on attacker-supplied string ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76886
(8.1 HIGH)

EPSS: 0.32%

updated 2026-08-20T15:34:14

1 posts

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

thehackerwire@mastodon.social at 2026-08-20T01:03:18.000Z ##

🟠 CVE-2026-76886 - High (8.1)

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19490(CVSS UNKNOWN)

EPSS: 0.33%

updated 2026-08-20T15:34:03

4 posts

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

ottoto2017@prattohome.com at 2026-08-21T07:42:40.000Z ##

「Citrixは、NetScalerの新たな脆弱性をできるだけ早く修正するよう管理者に強く求めている。」: #BLEEPINGCOMPUTER

「Citrixは、NetScaler GatewayセキュアリモートアクセスソリューションとNetScaler ADCネットワークアプライアンスに影響を与える2つの脆弱性からシステムを保護するため、顧客に対し直ちにセキュリティ対策を講じるよう警告した。

2つのうちより深刻な脆弱性( CVE-2026-19490 として追跡)では、NetScalerのファームウェアバージョンとSAMLアクションが構成されているかどうかに応じて、アプライアンスがAAA仮想サーバーまたはゲートウェイ(SSL VPN、ICAプロキシ、CVPN、RDPプロキシ)として構成されている場合に、権限を持たないリモート攻撃者が認証をバイパスできる可能性があります。 」

bleepingcomputer.com/news/secu

#prattohome

##

ottoto2017@prattohome.com at 2026-08-21T07:42:40.000Z ##

「Citrixは、NetScalerの新たな脆弱性をできるだけ早く修正するよう管理者に強く求めている。」: #BLEEPINGCOMPUTER

「Citrixは、NetScaler GatewayセキュアリモートアクセスソリューションとNetScaler ADCネットワークアプライアンスに影響を与える2つの脆弱性からシステムを保護するため、顧客に対し直ちにセキュリティ対策を講じるよう警告した。

2つのうちより深刻な脆弱性( CVE-2026-19490 として追跡)では、NetScalerのファームウェアバージョンとSAMLアクションが構成されているかどうかに応じて、アプライアンスがAAA仮想サーバーまたはゲートウェイ(SSL VPN、ICAプロキシ、CVPN、RDPプロキシ)として構成されている場合に、権限を持たないリモート攻撃者が認証をバイパスできる可能性があります。 」

bleepingcomputer.com/news/secu

#prattohome

##

cyberworldops@infosec.exchange at 2026-08-20T10:20:01.000Z ##

Citrix has released patches for CVE-2026-19490, a CVSS 9.3 authentication bypass in NetScaler ADC and Gateway. An unauthenticated remote attacker can exploit the flaw via an alternative path to bypass authentication on appliances configured as SSL VPN, ICA Proxy, CVPN, RDP Proxy, or AAA servers.

#CitrixBleb #NetScalerVuln #CVSS9 #RemoteAccessSecurity

cyberworldops.eu/en/netscaler-

##

DailyCyberSecurity@infosec.exchange at 2026-08-19T15:23:33.000Z ##

CVE-2026-19490 (CVSS 9.3) is a critical NetScaler authentication bypass in NetScaler Gateway and ADC. Patch now to block unauthenticated access.

#NetScaler #Citrix #CVE202619490 #AuthBypass #InfoSec

securityonline.info/netscaler-

##

CVE-2026-61897
(7.8 HIGH)

EPSS: 0.10%

updated 2026-08-20T15:17:38.740000

1 posts

An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.

thehackerwire@mastodon.social at 2026-08-20T17:00:47.000Z ##

🟠 CVE-2026-61897 - High (7.8)

An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-28164
(9.6 CRITICAL)

EPSS: 0.15%

updated 2026-08-20T15:17:29.713000

1 posts

Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7.

offseq@infosec.exchange at 2026-08-20T13:30:26.000Z ##

CVE-2026-28164: CRITICAL CSRF in HashThemes Easy Elementor Addons ≤2.3.7. Remote attackers can exploit this for full user compromise. No patch yet — track vendor advisories. CVSS 9.6. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CSRF #CVE2026_28164

##

CVE-2026-66780
(9.9 CRITICAL)

EPSS: 0.24%

updated 2026-08-20T13:08:53.900000

1 posts

A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an attacker can redirect inter-cluster tunnel traffic, enabling a Man-in-the-Middle (

DailyCyberSecurity@infosec.exchange at 2026-08-20T13:00:08.000Z ##

A critical Red Hat vulnerability, CVE-2026-66780 (CVSS 9.9), enables a MITM attack across a cluster mesh. Two more critical flaws also disclosed.

#RedHat #CVE202666780 #MITM #Kubernetes #Keycloak #InfoSec

securityonline.info/redhat-vul

##

CVE-2026-20320
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-20T13:01:19.947000

1 posts

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML me

CVE-2026-76004
(9.9 CRITICAL)

EPSS: 0.44%

updated 2026-08-20T12:48:31.843000

2 posts

A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/aspApBasicConfigUrcp of the component HTTP Handler. The manipulation of the argument pvid leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

offseq@infosec.exchange at 2026-08-19T04:30:24.000Z ##

UTT HiPER 1250GW v3.2.7-210907-180535 hit by CRITICAL stack-based buffer overflow (CVE-2026-76004) in HTTP handler. Exploitable via 'pvid' arg. No patch yet — restrict remote access & monitor traffic. radar.offseq.com/threat/cve-20 #OffSeq #CVE202676004 #Vuln #Infosec

##

thehackerwire@mastodon.social at 2026-08-19T04:00:55.000Z ##

🔴 CVE-2026-76004 - Critical (9.9)

A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/aspApBasicConfigUrcp of the component HTTP Handler. The manipulation of the argumen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19598
(9.8 CRITICAL)

EPSS: 0.50%

updated 2026-08-20T12:48:10.287000

2 posts

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON met

3 repos

https://github.com/ksotaria1337/CVE-2026-19598

https://github.com/sag-asab/CVE-2026-19598

https://github.com/DeadExpl0it/CVE-2026-19598-PoC

DailyCyberSecurity at 2026-08-21T16:17:01.243Z ##

CVE-2026-19598, a CVSS 9.8 flaw in the Pods WordPress plugin, enables complete site takeover. Wordfence is already blocking attacks in the wild.

securityonline.info/cve-2026-1

##

DailyCyberSecurity@infosec.exchange at 2026-08-21T16:17:01.000Z ##

CVE-2026-19598, a CVSS 9.8 flaw in the Pods WordPress plugin, enables complete site takeover. Wordfence is already blocking attacks in the wild.

#Pods #CVE202619598 #WordPress #PrivilegeEscalation #SiteTakeover #WebSecurity

securityonline.info/cve-2026-1

##

CVE-2026-15748
(9.8 CRITICAL)

EPSS: 3.45%

updated 2026-08-20T12:48:10.287000

1 posts

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler th

3 repos

https://github.com/ubaydev/CVE-2026-15748

https://github.com/HORKimhab/CVE-2026-15826-CVE-2026-15748

https://github.com/yora1928/cve-2026-15748

beyondmachines1@infosec.exchange at 2026-08-19T09:01:23.000Z ##

Unauthenticated RCE Vulnerability Patched in Forminator Forms Plugin

WPMU DEV patched a critical vulnerability (CVE-2026-15748) in the Forminator Forms plugin that allowed unauthenticated attackers to upload and execute PHP files. The flaw can lead to full remote code execution and site compromise.

**If you use the Forminator Forms plugin on your WordPress site, update it to version 1.56.2 or later ASAP away: attackers can take over the whole site without logging in. After updating, check your upload folders for any unfamiliar PHP files. If you can't update yet, delete any forms that use both File Upload and Select fields.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-24301
(8.8 HIGH)

EPSS: 1.63%

updated 2026-08-20T12:33:08.793000

2 posts

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

1 repos

https://github.com/CSOAI-ORG/memory-poisoning-axis

benzogaga33@mamot.fr at 2026-08-20T09:40:03.000Z ##

CoSnitch : Copilot a lui-même livré la faille qui permet de voler vos données it-connect.fr/cosnitch-cve-202 #ActuCybersécurité #Cybersécurité #Microsoft #Copilot #IA

##

PC_Fluesterer@social.tchncs.de at 2026-08-19T13:38:47.000Z ##

Von wegen KI: MS Copilot ist strunzdumm

Das Sicherheitsunternehmen Varonis hat eine Sicherheitslücke in Microsoft (MS) Copilot gefunden. Die hat inzwischen auch einen Namen bekommen und eine CVE-Nummer: CVE-2026-24301 oder CoSnitch. Sie ist mit 8,8 von 10 als kritisch eingestuft. Anscheinend gibt es noch keinen Flicken dagegen. Wer diese Lücke ausnutzt, kann Copilot von Ferne heimlich (ohne Interaktion des Opfers) dazu veranlassen, sensible geheime Daten zu senden. Zwar hat Copilot Schutzvorkehrungen gegen solchen Missbrauch, aber die sind unvollständig. Der Trick der Forscher/innen bestand darin, Copilot sich selbst hacken zu lassen! Immer wenn die KI einen ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#cybercrime #datenleck #KI #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump

##

CVE-2026-66582
(7.1 HIGH)

EPSS: 0.18%

updated 2026-08-20T12:31:30

1 posts

Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.

hugovalters@mastodon.social at 2026-08-21T14:06:42.000Z ##

CVE-2026-66582 - Unauthenticated XSS in TranslatePress ≤3.3.2. CVSS 7.1. No patch yet. Disable or restrict access now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-665

##

CVE-2026-73198
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-20T12:31:29

1 posts

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsiveness, and a denial of service (DoS) condition.

thehackerwire@mastodon.social at 2026-08-20T12:01:00.000Z ##

🟠 CVE-2026-73198 - High (7.5)

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memor...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13097
(9.1 CRITICAL)

EPSS: 0.34%

updated 2026-08-20T12:31:22

1 posts

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized a

thehackerwire@mastodon.social at 2026-08-20T12:01:13.000Z ##

🔴 CVE-2026-13097 - Critical (9.1)

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73197
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-20T12:31:22

1 posts

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage, slower request handling, and potential service disruption or denial of service.

thehackerwire@mastodon.social at 2026-08-20T12:00:50.000Z ##

🟠 CVE-2026-73197 - High (7.5)

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75860
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-08-20T12:31:22

1 posts

The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to enable user registration and set the default role to administrator, leading to privilege escalation and full site takeover.

offseq@infosec.exchange at 2026-08-20T07:30:24.000Z ##

CVE-2026-75860: CRITICAL privilege escalation in JSON Options ≤0.0.4. Unauthenticated attackers can update WordPress options & gain admin access. Remove or disable plugin until fix is available. Full site takeover risk. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202675860

##

CVE-2026-14947
(7.2 HIGH)

EPSS: 0.94%

updated 2026-08-20T09:31:23

1 posts

A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise.

certvde@infosec.exchange at 2026-08-20T08:20:37.000Z ##

#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

#CSAF frauscher.csaf-tp.certvde.com/

##

CVE-2026-14948
(8.8 HIGH)

EPSS: 0.39%

updated 2026-08-20T09:31:23

1 posts

A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.

certvde@infosec.exchange at 2026-08-20T08:20:37.000Z ##

#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

#CSAF frauscher.csaf-tp.certvde.com/

##

CVE-2026-14946
(7.2 HIGH)

EPSS: 0.52%

updated 2026-08-20T09:31:23

1 posts

A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.

certvde@infosec.exchange at 2026-08-20T08:20:37.000Z ##

#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

#CSAF frauscher.csaf-tp.certvde.com/

##

CVE-2026-14949
(6.5 MEDIUM)

EPSS: 0.26%

updated 2026-08-20T09:31:23

1 posts

A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.

certvde@infosec.exchange at 2026-08-20T08:20:37.000Z ##

#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

#CSAF frauscher.csaf-tp.certvde.com/

##

CVE-2026-14952
(7.5 HIGH)

EPSS: 0.49%

updated 2026-08-20T09:31:23

1 posts

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.

certvde@infosec.exchange at 2026-08-20T08:20:37.000Z ##

#OT #Advisory VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
#CVE CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

#CSAF frauscher.csaf-tp.certvde.com/

##

CVE-2026-76928
(7.5 HIGH)

EPSS: 0.28%

updated 2026-08-20T00:35:18

1 posts

X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

thehackerwire@mastodon.social at 2026-08-19T23:59:47.000Z ##

🟠 CVE-2026-76928 - High (7.5)

X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76589
(9.9 CRITICAL)

EPSS: 0.61%

updated 2026-08-20T00:35:17

2 posts

A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.

offseq@infosec.exchange at 2026-08-20T04:30:26.000Z ##

TRENDnet TEW-755AP is affected by CVE-2026-76589 (CRITICAL, CVSS 9.4): stack-based buffer overflow in /sbin/mycli, exploitable remotely. Public exploit; no patch yet. Restrict device access and monitor. radar.offseq.com/threat/cve-20 #OffSeq #CVE202676589 #IoTSecurity

##

thehackerwire@mastodon.social at 2026-08-19T23:00:26.000Z ##

🔴 CVE-2026-76589 - Critical (9.9)

A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack may be launched remotely. The exp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76850
(9.8 CRITICAL)

EPSS: 0.98%

updated 2026-08-20T00:35:17

2 posts

LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes with pickle.loads(), and the isinstance check against DistServeCacheFreeRequest runs only after deserialization has already completed. The peer that supplie

offseq@infosec.exchange at 2026-08-20T01:30:25.000Z ##

CVE-2026-76850 (CRITICAL): InternLM lmdeploy <0.16.0 vulnerable to remote code execution via untrusted pickle deserialization on ZeroMQ endpoints. Enable API keys or disable disaggregated serving to mitigate. radar.offseq.com/threat/cve-20 #OffSeq #Infosec #Vuln #CVE202676850

##

thehackerwire@mastodon.social at 2026-08-19T23:00:07.000Z ##

🔴 CVE-2026-76850 - Critical (9.8)

LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes wit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76880
(7.5 HIGH)

EPSS: 0.28%

updated 2026-08-20T00:35:17

1 posts

RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

thehackerwire@mastodon.social at 2026-08-20T01:04:26.000Z ##

🟠 CVE-2026-76880 - High (7.5)

RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76399
(8.1 HIGH)

EPSS: 0.25%

updated 2026-08-20T00:35:11

1 posts

In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access to all relevant data and affect system integrity. The vulnerability is possible because Splunk AI Toolkit gives the "power" Splunk role permission to mod

thehackerwire@mastodon.social at 2026-08-20T05:00:25.000Z ##

🟠 CVE-2026-76399 - High (8.1)

In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76396
(7.5 HIGH)

EPSS: 0.24%

updated 2026-08-20T00:35:11

1 posts

In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible because Splunk AI Toolkit does not mark the apply search command as risky. For more information see Troubleshoot the AI Toolkit (https://help.splunk.com/e

thehackerwire@mastodon.social at 2026-08-20T05:00:04.000Z ##

🟠 CVE-2026-76396 - High (7.5)

In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76395
(8.8 HIGH)

EPSS: 0.47%

updated 2026-08-20T00:35:11

1 posts

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible because a model codec in Splunk AI Toolkit deserializes sparse matrix data without guarding against embedded pickle content. For more information see Tro

thehackerwire@mastodon.social at 2026-08-19T23:01:24.000Z ##

🟠 CVE-2026-76395 - High (8.8)

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76404
(9.1 CRITICAL)

EPSS: 0.56%

updated 2026-08-20T00:35:08

3 posts

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking whether the content is of the expected type.

DailyCyberSecurity@infosec.exchange at 2026-08-20T05:31:55.000Z ##

Splunk patches CVE-2026-76404, a critical remote code execution flaw in the MCP Server app, plus 16 more bugs across its apps and add-ons.

#Splunk #CVE #RemoteCodeExecution #RCE #MCPServer #Deserialization #InfoSec #PatchNow

securityonline.info/splunk-app

##

offseq@infosec.exchange at 2026-08-20T03:00:25.000Z ##

Splunk MCP Server app v1.2 is impacted by CVE-2026-76404 (CRITICAL, CVSS 9.1) — insecure deserialization lets admin users run arbitrary OS commands. Limit admin access & monitor for misuse until a patch is released. radar.offseq.com/threat/cve-20 #OffSeq #Splunk #Infosec #CVE202676404

##

thehackerwire@mastodon.social at 2026-08-19T23:00:17.000Z ##

🔴 CVE-2026-76404 - Critical (9.1)

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20231
(9.9 CRITICAL)

EPSS: 0.41%

updated 2026-08-19T21:31:33

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. &nbsp; The vulnerabilities tracked by CVE-2026-20231 are related to improper neutralization of special e

AAKL@infosec.exchange at 2026-08-20T20:15:43.000Z ##

CISA has added two known vulnerabilities to the KEV catalogue.

- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-72530: TrueConf Server Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Yesterday:

Cisco:

CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-20030
(10.0 CRITICAL)

EPSS: 0.45%

updated 2026-08-19T21:31:32

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20030 are related to improper neutralization of special elements used

CVE-2026-75569
(7.7 HIGH)

EPSS: 0.29%

updated 2026-08-19T21:30:46

1 posts

A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during the build. The consequence is a compromised build process, potentially leading to t

thehackerwire@mastodon.social at 2026-08-19T22:00:41.000Z ##

🟠 CVE-2026-75569 - High (7.7)

A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76139
(8.0 HIGH)

EPSS: 0.33%

updated 2026-08-19T21:30:46

1 posts

A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote attacker could exploit this vulnerability to inject malicious code, leading to u

thehackerwire@mastodon.social at 2026-08-19T22:00:16.000Z ##

🟠 CVE-2026-76139 - High (8)

A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub acces...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76584
(9.9 CRITICAL)

EPSS: 0.49%

updated 2026-08-19T21:30:40

1 posts

A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The manipulation of the argument Currenttime results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

thehackerwire@mastodon.social at 2026-08-19T22:00:27.000Z ##

🔴 CVE-2026-76584 - Critical (9.9)

A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The manipulation of the argument Currenttime results in st...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70496
(9.9 CRITICAL)

EPSS: 0.26%

updated 2026-08-19T21:30:39

2 posts

A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork. This grants excessive privileges beyond what is necessary for the operator's intended function, potentially le

DailyCyberSecurity@infosec.exchange at 2026-08-20T03:01:45.000Z ##

Red Hat ACM privilege escalation flaws (CVE-2026-70496, CVSS 9.9) let attackers seize full cluster control. See the three Kubernetes bugs.

#RedHat #Kubernetes #PrivilegeEscalation #CVE #ACM #CloudSecurity #InfoSec

securityonline.info/red-hat-ac

##

thehackerwire@mastodon.social at 2026-08-19T20:00:15.000Z ##

🔴 CVE-2026-70496 - Critical (9.9)

A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18848
(8.3 HIGH)

EPSS: 0.10%

updated 2026-08-19T21:30:32

1 posts

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An attacker who can lure a logged-in ASMI administrator to visit a crafted web page can, under specific conditions, silently perform administrative actions on the FSP on behalf of that administrator, resulting in a c

thehackerwire@mastodon.social at 2026-08-19T20:00:28.000Z ##

🟠 CVE-2026-18848 - High (8.3)

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An attacker who can lure a logged-in ASMI administrator to visi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20317
(10.0 CRITICAL)

EPSS: 0.34%

updated 2026-08-19T21:30:29

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20317 are related to improper authentication issues that are gr

AAKL@infosec.exchange at 2026-08-20T20:15:43.000Z ##

CISA has added two known vulnerabilities to the KEV catalogue.

- CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-72530: TrueConf Server Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Yesterday:

Cisco:

CRITICAL: CVE-2026-20231, CVE-2026-20315, and CVE-2026-20317: Secure Workload Software Security Hardening Release: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T02:06:30.000Z ##

Cisco patches Secure Workload flaws CVE-2026-20315 and CVE-2026-20317, an authentication bypass and privilege escalation pair scoring CVSS 10. Upgrade now.

#Cisco #CVE #AuthenticationBypass #PrivilegeEscalation #Vulnerability #InfoSec #PatchNow

securityonline.info/cisco-secu

##

CVE-2026-68900
(7.6 HIGH)

EPSS: 0.25%

updated 2026-08-19T20:17:21.727000

1 posts

Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/lib/exportHTML.js read a card title and body through textContent, which decoded entity-encoded markup, and then interpolated titleText and allText into content.innerHTML in the exported index.html. A board member could store an entity-encoded event-handler payload in a card title that remained inert

thehackerwire@mastodon.social at 2026-08-19T21:00:45.000Z ##

🟠 CVE-2026-68900 - High (7.6)

Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/lib/exportHTML.js read a card title and body through textContent, which decoded entity-encoded markup, and then interpolated titleText and allText ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75149
(8.8 HIGH)

EPSS: 0.64%

updated 2026-08-19T18:33:02

1 posts

marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a notebook. When the notebook is opened in edit mode, marimo launches the specified command as a local subprocess before any notebook cell is executed, re

thehackerwire@mastodon.social at 2026-08-19T19:00:17.000Z ##

🟠 CVE-2026-75149 - High (8.8)

marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-32475
(9.0 None)

EPSS: 0.42%

updated 2026-08-19T18:32:57

10 posts

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.

cyberveille@mastobot.ping.moi at 2026-08-21T14:00:05.000Z ##

📢 [VULN] WordPress : cette faille Elementor Pro ouvre votre site aux pirates CVE-2026-32475

Nouvelle alerte à destination de tous les administrateurs de sites WordPress : la faille CVE-2026-32475, corrigée le 19 août 2026 dans Elementor Pro, permet à un visiteur anonyme de déposer un fichier PHP sur un site WordPress, puis de l'exécuter. Aucun compte, aucune interaction avec un administrateur.

🔗 it-connect.fr/elementor-pro-cv
💬 discussion : infosec.pub/post/51237084
#CVE #Cyberveille

##

benzogaga33@mamot.fr at 2026-08-21T09:40:03.000Z ##

Elementor Pro : une faille critique permet de prendre le contrôle d’un site WordPress it-connect.fr/elementor-pro-cv #ActuCybersécurité #Cybersécurité #Vulnérabilité #Wordpress

##

DailyCyberSecurity at 2026-08-21T07:56:13.137Z ##

CVE-2026-32475 (CVSS 9.8) is an unauthenticated file upload flaw in Elementor Pro. It threatens complete site compromise across 6 million sites.

securityonline.info/cve-2026-3

##

ottoto2017@prattohome.com at 2026-08-21T07:39:49.000Z ##

「Elementor Proの重大なバグにより、WordPressサイトがリモートコード実行攻撃に晒される 」: #BLEEPINGCOMPUTER

「WordPressプラグイン「Elementor Pro」に存在する重大な脆弱性により、攻撃者が実行可能ファイルをアップロードして、サーバー上でリモートコードを実行できる可能性がある。

CVE-2026-32475として識別されたこの脆弱性は、Elementor Proのバージョン4.2.2より前のバージョンに影響し、ファイル検証と処理に別々のループを使用するファイルアップロードモジュールに起因しており、ファイル名が空のアップロードの処理方法が異なっています。」

bleepingcomputer.com/news/secu

#prattohome

##

cyberveille@mastobot.ping.moi at 2026-08-21T14:00:05.000Z ##

📢 [VULN] WordPress : cette faille Elementor Pro ouvre votre site aux pirates CVE-2026-32475

Nouvelle alerte à destination de tous les administrateurs de sites WordPress : la faille CVE-2026-32475, corrigée le 19 août 2026 dans Elementor Pro, permet à un visiteur anonyme de déposer un fichier PHP sur un site WordPress, puis de l'exécuter. Aucun compte, aucune interaction avec un administrateur.

🔗 it-connect.fr/elementor-pro-cv
💬 discussion : infosec.pub/post/51237084
#CVE #Cyberveille

##

benzogaga33@mamot.fr at 2026-08-21T09:40:03.000Z ##

Elementor Pro : une faille critique permet de prendre le contrôle d’un site WordPress it-connect.fr/elementor-pro-cv #ActuCybersécurité #Cybersécurité #Vulnérabilité #Wordpress

##

DailyCyberSecurity@infosec.exchange at 2026-08-21T07:56:13.000Z ##

CVE-2026-32475 (CVSS 9.8) is an unauthenticated file upload flaw in Elementor Pro. It threatens complete site compromise across 6 million sites.

#ElementorPro #CVE202632475 #WordPress #RCE #FileUpload #WebSecurity

securityonline.info/cve-2026-3

##

ottoto2017@prattohome.com at 2026-08-21T07:39:49.000Z ##

「Elementor Proの重大なバグにより、WordPressサイトがリモートコード実行攻撃に晒される 」: #BLEEPINGCOMPUTER

「WordPressプラグイン「Elementor Pro」に存在する重大な脆弱性により、攻撃者が実行可能ファイルをアップロードして、サーバー上でリモートコードを実行できる可能性がある。

CVE-2026-32475として識別されたこの脆弱性は、Elementor Proのバージョン4.2.2より前のバージョンに影響し、ファイル検証と処理に別々のループを使用するファイルアップロードモジュールに起因しており、ファイル名が空のアップロードの処理方法が異なっています。」

bleepingcomputer.com/news/secu

#prattohome

##

cyberworldops@infosec.exchange at 2026-08-20T16:20:01.000Z ##

A critical flaw in Elementor Pro (CVE-2026-32475) enables unauthenticated remote code execution via the File Upload module. Two desynchronized processing loops mishandle empty filenames, bypassing validation entirely. All versions below 4.2.2 are affected. Patch immediately and audit server logs for indicators of exploitation.

#ElementorPro #WordPress #RemoteCodeExecution #CVE202632475

cyberworldops.eu/en/elementor-

##

shawnhooper@fosstodon.org at 2026-08-19T18:17:50.000Z ##

WordPress admins running Elementor Pro:

CVSS 9.8 - CVE-2026-32475

WordPress Elementor Pro Plugin <= 4.2.1 is vulnerable to a high priority Arbitrary File Upload

patchstack.com/articles/critic

#wordpresss

##

CVE-2026-61518
(8.8 HIGH)

EPSS: 0.31%

updated 2026-08-19T18:32:57

1 posts

ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods is concatenated directly into SQL WHERE clauses without integer casting or parameterized query binding. The built-in SQL injection scanner does not block quote-free boolean payloads and does not reject requests in its default configuration. A remote AP

thehackerwire@mastodon.social at 2026-08-19T19:00:43.000Z ##

🟠 CVE-2026-61518 - High (8.8)

ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods is concatenated directly into SQL WHERE clauses without integer casting or parameterized query bind...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66794
(9.3 CRITICAL)

EPSS: 0.32%

updated 2026-08-19T18:32:57

1 posts

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy requests to arbitrary services across any managed cluster. This enables unauthorized access to internal

thehackerwire@mastodon.social at 2026-08-19T19:00:29.000Z ##

🔴 CVE-2026-66794 - Critical (9.3)

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manip...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75143
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-08-19T18:32:57

1 posts

FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overflowing it when the payload exceeds the destination size. This is reachable via the async:rist:// URL scheme, where the async wrapper supplies a smaller

thehackerwire@mastodon.social at 2026-08-19T18:01:18.000Z ##

🔴 CVE-2026-75143 - Critical (9.8)

FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, ove...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75142
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-19T18:32:57

1 posts

FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams triggers the overflow during MPEG-PS muxing.

thehackerwire@mastodon.social at 2026-08-19T18:00:35.000Z ##

🟠 CVE-2026-75142 - High (7.8)

FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75146
(8.1 HIGH)

EPSS: 0.26%

updated 2026-08-19T18:32:57

1 posts

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an

thehackerwire@mastodon.social at 2026-08-19T18:00:06.000Z ##

🟠 CVE-2026-75146 - High (8.1)

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negativ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18051
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-08-19T18:32:44

1 posts

The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the same flaw overwrites the site's .htaccess files, which breaks the site and can stri

CVE-2026-70408
(8.8 HIGH)

EPSS: 0.33%

updated 2026-08-19T16:18:58.590000

1 posts

An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.

thehackerwire@mastodon.social at 2026-08-19T06:00:01.000Z ##

🟠 CVE-2026-70408 - High (8.8)

An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73925
(8.2 HIGH)

EPSS: 0.23%

updated 2026-08-19T15:33:23

1 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data o

thehackerwire@mastodon.social at 2026-08-19T11:01:03.000Z ##

🟠 CVE-2026-73925 - High (8.2)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73924
(9.1 CRITICAL)

EPSS: 0.29%

updated 2026-08-19T15:33:23

1 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data o

thehackerwire@mastodon.social at 2026-08-19T11:00:46.000Z ##

🔴 CVE-2026-73924 - Critical (9.1)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73921
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-08-19T15:33:23

1 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity a

thehackerwire@mastodon.social at 2026-08-19T05:00:39.000Z ##

🔴 CVE-2026-73921 - Critical (9.8)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73938
(7.5 HIGH)

EPSS: 0.38%

updated 2026-08-19T15:33:23

1 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon acc

thehackerwire@mastodon.social at 2026-08-19T05:00:24.000Z ##

🟠 CVE-2026-73938 - High (7.5)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71176
(8.8 HIGH)

EPSS: 0.30%

updated 2026-08-19T15:32:47

1 posts

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

thehackerwire@mastodon.social at 2026-08-19T16:01:27.000Z ##

🟠 CVE-2026-71176 - High (8.8)

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulner...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71961
(8.8 HIGH)

EPSS: 3.34%

updated 2026-08-19T15:32:47

1 posts

Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges by sending unsanitized input through the mesh MQTT command interface. The sync_command binary forwards unsanitized input directly to a shell execution sink in command.lua, enabling attackers with access to the MQTT b

thehackerwire@mastodon.social at 2026-08-19T16:01:15.000Z ##

🟠 CVE-2026-71961 - High (8.8)

Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges by sending unsanitized input through the mesh MQTT command inte...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73937
(8.2 HIGH)

EPSS: 0.38%

updated 2026-08-19T15:32:20

1 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (comp

thehackerwire@mastodon.social at 2026-08-19T05:00:12.000Z ##

🟠 CVE-2026-73937 - High (8.2)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73922
(9.1 CRITICAL)

EPSS: 0.29%

updated 2026-08-19T15:32:19

1 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data o

thehackerwire@mastodon.social at 2026-08-19T11:00:31.000Z ##

🔴 CVE-2026-73922 - Critical (9.1)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19942
(8.1 HIGH)

EPSS: 0.69%

updated 2026-08-19T06:31:24

1 posts

The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the AVCF_Abilities_Media::register (replace-media-file execute_callback) function in all versions up to, and including, 5.1.1. This makes it possible for authenticated attackers, with author-level

thehackerwire@mastodon.social at 2026-08-19T06:00:13.000Z ##

🟠 CVE-2026-19942 - High (8.1)

The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the AVCF_Abilities_Media::register (repla...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76008
(10.0 CRITICAL)

EPSS: 0.57%

updated 2026-08-19T03:31:30

1 posts

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflow. The attack can be initiated remotely.

thehackerwire@mastodon.social at 2026-08-19T04:00:34.000Z ##

🔴 CVE-2026-76008 - Critical (10)

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76003
(9.9 CRITICAL)

EPSS: 0.44%

updated 2026-08-19T03:31:23

2 posts

A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of the argument timestart can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

offseq@infosec.exchange at 2026-08-19T06:00:27.000Z ##

CVE-2026-76003 (CRITICAL): Stack-based buffer overflow in UTT HiPER 1200GW (2.5.3-170306). Remote code execution possible via timestart argument; public exploit exists. No patch yet. Restrict access & monitor. radar.offseq.com/threat/cve-20 #OffSeq #CVE202676003 #infosec #vuln

##

thehackerwire@mastodon.social at 2026-08-19T04:00:44.000Z ##

🔴 CVE-2026-76003 - Critical (9.9)

A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of the argument timestart can lead to stack-based buffer overflow. The attack may ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18963
(9.1 CRITICAL)

EPSS: 0.39%

updated 2026-08-19T03:31:21

7 posts

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user

1 repos

https://github.com/kyos-public/keycloak-cve-2026-18963-hunt

benzogaga33@mamot.fr at 2026-08-21T15:40:04.000Z ##

Keycloak : cette faille critique permet de pirater un compte via la fonction de mot de passe oublié it-connect.fr/keycloak-cve-202 #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

sayzard@mastodon.sayzard.org at 2026-08-21T11:40:29.000Z ##

Keycloak Unauthenticated Account Takeover

벨기에 사이버보안센터(CCB)는 Red Hat build of Keycloak 26.4 및 26.6의 자격 증명 재설정 흐름에서 원격 비인증 계정 탈취가 가능한 CVE-2026-18963을 경고했다. CVSS 9.1의 CWE-640 취약점으로, 공격자는 비밀번호 재설정 이메일의 검증 링크를 클릭하지 않고도 임의 사용자의 재설정을 강제하고 새 자격 증명을 설정할 수 있다. Keycloak이 SSO·인증·권한 부여의 중심에 배치되는 경우 영향 범위가 해당 계정에 연결된 다수의 AI 서비스, 에이전트,...

ccb.belgium.be/advisories/warn

##

DailyCyberSecurity at 2026-08-21T09:17:33.411Z ##

A Keycloak account takeover flaw, CVE-2026-18963, lets attackers reset any user's password with no email verification. Update to 26.7.2 now.

securityonline.info/keycloak-a

##

benzogaga33@mamot.fr at 2026-08-21T15:40:04.000Z ##

Keycloak : cette faille critique permet de pirater un compte via la fonction de mot de passe oublié it-connect.fr/keycloak-cve-202 #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

DailyCyberSecurity@infosec.exchange at 2026-08-21T09:17:33.000Z ##

A Keycloak account takeover flaw, CVE-2026-18963, lets attackers reset any user's password with no email verification. Update to 26.7.2 now.

#Keycloak #AccountTakeover #CVE #IAM #InfoSec #RedHat

securityonline.info/keycloak-a

##

smeyer@univention.social at 2026-08-20T07:23:48.000Z ##

Guten Morgen an @univention Kund*innen, die unsere #Keycloak App einsetzen! Wir werden demnächst Version 26.7.2 herausbringen. Von dem Account-Takeover-CVE ist unsere App nicht betroffen.

Details findet Ihr hier: help.univention.com/t/keycloak

##

hacksilon@infosec.exchange at 2026-08-19T17:02:26.000Z ##

PSA: Critical unauthenticated account takeover vulnerability in #Keycloak - allows resetting arbitrary users‘ passwords. Update to 26.7.2 immediately or disable password reset. Tracked as CVE-2026-18963. github.com/keycloak/keycloak/i

#infosec

##

CVE-2026-47627
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-08-18T21:31:53

1 posts

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service.

CVE-2026-67271
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-08-18T18:32:05

1 posts

Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and Remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet and cause a crash, that is persistent in case automatic restarts are enabled.

DailyCyberSecurity@infosec.exchange at 2026-08-20T14:05:08.000Z ##

A critical Dell PowerStore vulnerability, CVE-2026-67271 (CVSS 9.8), allows unauthenticated remote code execution via SMB. Two more flaws patched.

#DellPowerStore #CVE202667271 #RCE #SMB #Storage #InfoSec

securityonline.info/dell-power

##

CVE-2026-65400
(7.1 HIGH)

EPSS: 0.75%

updated 2026-08-18T18:31:47

1 posts

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

2 repos

https://github.com/panchocosil/CVE-2026-65400-poc

https://github.com/HORKimhab/CVE-2026-65400

cktodon@mas.to at 2026-08-21T16:00:12.000Z ##

El fallo de #macOS que permite entrar sin #contraseña por compartir pantalla ya está siendo explotado: actualiza ahora

wwwhatsnew.com/2026/08/20/cve-

##

CVE-2026-33824
(9.8 CRITICAL)

EPSS: 77.90%

updated 2026-08-18T18:31:46

3 posts

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

2 repos

https://github.com/kaleth4/CVE-2026-33824

https://github.com/EpSiLoNPoInTOrI/IKEV2-POC

DailyCyberSecurity@infosec.exchange at 2026-08-21T04:48:04.000Z ##

CISA confirmed active exploitation of CVE-2026-33824, an unauthenticated Windows IKE double-free flaw patched in April, ordering federal agencies to remediate within three days.

#CVE202633824 #Windows #CISA #IKE #Vulnerability

meterpreter.org/cve-2026-33824

##

beyondmachines1@infosec.exchange at 2026-08-20T10:01:03.000Z ##

CISA Warns of Active Exploitation of Critical Microsoft IKE Remote Code Execution Flaw

CISA reports active exploitation of a Windows IKE service critical remote code execution vulnerability (CVE-2026-33824). The flaw allows unauthenticated attackers to take full control of affected systems by sending malicious network packets.

**If you run Windows systems with IKEv2 enabled (VPN gateways, RRAS servers, IPsec endpoints), apply Microsoft's patch for CVE-2026-33824 immediately. Attackers are actively taking over these machines with no login or user action needed. If you can't patch right away, block inbound UDP ports 500 and 4500 at your firewall and only allow those ports from trusted, known IP addresses.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

offseq@infosec.exchange at 2026-08-19T10:30:25.000Z ##

CVE-2026-33824: CRITICAL RCE in Windows IKE Extension is being actively exploited. All supported Windows 10, 11 & Server are impacted. Patch immediately or block UDP 500/4500 if IKE not used. More at radar.offseq.com/threat/critic #OffSeq #RCE #Windows #BlueTeam

##

CVE-2026-19478
(9.4 CRITICAL)

EPSS: 1.51%

updated 2026-08-18T14:57:10.630000

9 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

4 repos

https://github.com/n0xdaemon/cve-2026-19478

https://github.com/davkharrr/CVE-2026-19478-PoC

https://github.com/HORKimhab/CVE-2026-19650-CVE-2026-19478

https://github.com/renzi25031469/CVE-2026-19478

undercodenews@mastodon.social at 2026-08-21T10:44:40.000Z ##

Critical GitLab Flaw CVE-2026-19478 Is Under Active Attack: Why Organizations Need to Patch Now + Video

A Dangerous Warning for GitLab Administrators A critical vulnerability in self-managed GitLab installations has moved from a serious security concern to an immediate incident-response priority. Security researchers are warning that attackers are actively exploiting CVE-2026-19478, a flaw rated CVSS 9.4, that can allow completely unauthenticated attackers to remotely…

undercodenews.com/critical-git

##

cyberworldops at 2026-08-21T10:20:01.010Z ##

watchTowr reports active exploitation of CVE-2026-19478 in GitLab within days of public disclosure. The flaw is a code injection via GraphQL directives, exploitable by unauthenticated remote attackers. Reproduction was possible within minutes of the advisory going live. Patch immediately.

cyberworldops.eu/en/gitlab-cve

##

benzogaga33@mamot.fr at 2026-08-21T09:40:04.000Z ##

GitLab : la faille critique CVE-2026-19478 est déjà exploitée, deux jours après le correctif it-connect.fr/gitlab-cve-2026- #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

cyberworldops@infosec.exchange at 2026-08-21T10:20:01.000Z ##

watchTowr reports active exploitation of CVE-2026-19478 in GitLab within days of public disclosure. The flaw is a code injection via GraphQL directives, exploitable by unauthenticated remote attackers. Reproduction was possible within minutes of the advisory going live. Patch immediately.

#GitLab #CVE202619478 #CodeInjection #PatchNow

cyberworldops.eu/en/gitlab-cve

##

benzogaga33@mamot.fr at 2026-08-21T09:40:04.000Z ##

GitLab : la faille critique CVE-2026-19478 est déjà exploitée, deux jours après le correctif it-connect.fr/gitlab-cve-2026- #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

linuxmint_hun@mastodon.social at 2026-08-21T08:38:00.000Z ##

A GitLab CVE-2026-19478 sebezhetőséget napokkal a nyilvánosságra hozatal után már aktívan kihasználják

linuxmint.hu/hir/2026/08/a-git

##

hackmag@infosec.exchange at 2026-08-20T04:30:06.000Z ##

⚪️ Critical GitLab Vulnerability Allowed Deletion of Public Projects

🗨️ GitLab developers have released emergency patches for Community Edition (CE) and Enterprise Edition (EE) that address the critical vulnerability CVE-2026-19478 (CVSS score: 9.4). Under certain conditions, the flaw allowed an unauthenticated attacker to remotely modify or delete public projects and…

🔗 hackmag.com/news/cve-2026-1947

#news

##

threatcodex@infosec.exchange at 2026-08-19T14:17:54.000Z ##

Critical and High-Severity GraphQL CVEs in GitLab: Code Injection and CSRF via One Directive
#GitLab #CVE_2026_19478 #CVE_2026_19650
ox.security/blog/gitlab-graphq

##

oversecurity@mastodon.social at 2026-08-19T08:13:08.000Z ##

Critical GitLab Flaw Lets Hackers Alter or Delete Public Projects

GitLab has patched two security flaws, including CVE-2026-19478, a critical code injection vulnerability that could allow unauthenticated attackers...

🔗️ [Thecyberexpress] link.is.it/otTWyh

##

CVE-2026-64849
(9.3 CRITICAL)

EPSS: 8.15%

updated 2026-08-17T21:58:52

5 posts

### Summary The default MLflow Tracking Server (`mlflow server`, no authentication, default SQLite backend) exposes the model-registry webhooks API unauthenticated, including a synchronous `POST /api/2.0/mlflow/webhooks/{id}/test` endpoint that returns the upstream response status and body to the caller. The SSRF guard added in PR #20747 (`_validate_webhook_url`, shipped in 3.10.0) resolves the we

3 repos

https://github.com/zavisco/CVE-2026-64849.yaml

https://github.com/codeb0ssx/CVE-2026-64849-PoC

https://github.com/BiuTrap/CVE-2026-64849

thecybermind@infosec.exchange at 2026-08-20T16:44:32.000Z ##

CVE-2026-64849 exposes unauthenticated MLflow tracking servers to critical server-side request forgery (SSRF) threats via redirect bypasses. Discover immediate mitigation strategies, CISA KEV compliance guidelines, and SOC detection playbooks to secure your AI infrastructure. thecybermind.co/jily

##

cyberworldops@infosec.exchange at 2026-08-20T14:20:00.000Z ##

CISA has detected active exploitation of CVE-2026-64849, a critical SSRF in MLflow. Exposed tracking servers without authentication can be abused to query cloud metadata, internal services, and loopback addresses, leading to credential theft and internal reconnaissance.

#CloudSecurity #SSRF #Vulnerability #ThreatIntel

cyberworldops.eu/en/mlflow-und

##

secdb@infosec.exchange at 2026-08-19T19:00:12.000Z ##

🚨 [CISA-2026:0819] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-64849 (secdb.nttzen.cloud/cve/detail/)
- Name: MLflow Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MLflow
- Product: MLflow
- Notes: github.com/mlflow/mlflow/pull/ ; github.com/mlflow/mlflow/issue ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260819 #cisa20260819 #cve_2026_64849 #cve202664849

##

cisakevtracker@mastodon.social at 2026-08-19T18:00:51.000Z ##

CVE ID: CVE-2026-64849
Vendor: MLflow
Product: MLflow
Date Added: 2026-08-19
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

beyondmachines1@infosec.exchange at 2026-08-19T08:01:23.000Z ##

Attackers Exploit a Critical MLflow Vulnerability

Attackers are actively exploiting a critical flaw in MLflow (CVE-2026-64849) to steal cloud credentials and gain remote code execution.

**If you run MLflow, update it to version 3.15.0 or later ASAP, and make sure the server is not reachable from the internet. Then check your audit logs for any odd requests to cloud metadata services. If you see any (or aren't sure), rotate your cloud credentials and keys as a precaution.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-66792
(9.9 CRITICAL)

EPSS: 0.30%

updated 2026-08-17T21:31:30

1 posts

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to

CVE-2026-47686
(9.9 CRITICAL)

EPSS: 0.32%

updated 2026-08-17T17:32:35

1 posts

**Affected:** vm2 <= 3.11.3 **CVSS 3.1:** 9.9 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) **CWE:** CWE-693 (Protection Mechanism Failure) **Prerequisite:** Embedder exposes a host function that throws an Error with `.cause` referencing a powerful host object (e.g., `process`) ## Summary I found that `handleException()` in `lib/setup-sandbox.js` recursively sanitizes sub-errors for `Suppr

DailyCyberSecurity@infosec.exchange at 2026-08-20T13:15:58.000Z ##

A vm2 sandbox escape (CVE-2026-47686, CVSS 9.9) with public PoC lets attackers hijack the host. Two more critical flaws also patched. Update to 3.11.6.

#vm2 #CVE202647686 #SandboxEscape #RCE #NodeJS #InfoSec

securityonline.info/vm2-sandbo

##

CVE-2026-42945
(8.1 HIGH)

EPSS: 66.04%

updated 2026-08-17T12:18:36.420000

2 posts

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond it

44 repos

https://github.com/dinosn/cve-2026-42945-nginx32-lab

https://github.com/sec-sys/CVE-2026-42945-Reverse-Shell-POC

https://github.com/cipherspy/CVE-2026-42945-POC

https://github.com/friparia/NGINX_RIFT_SCAN_CVE_2026_42945

https://github.com/fkj-src/fix_nginx_cve_2026_42945

https://github.com/oseasfr/Scanner_CVE_2026-42945

https://github.com/F2u0a0d3/CVE-2026-42945-nginx-rift-poc

https://github.com/gagaltotal/CVE-2026-42945-NGINX-Rift-Toolkit

https://github.com/nanwinata/nginxrift-CVE-2026-42945

https://github.com/hnytgl/CVE-2026-42945

https://github.com/strivepan/Nginx_cve-2026-42945-scanner-gui

https://github.com/rheodev/CVE-2026-42945

https://github.com/webdev75950-ux/nginx-rce-cve-2026-42945

https://github.com/simota/nginx-rift-scanner

https://github.com/realityone/cve-2026-42945-scan

https://github.com/Renison-Gohel/CVE-2026-42945-NGINX-Rift

https://github.com/iammerrida-source/nginx-rift-detect

https://github.com/forxiucn/nginx-cve-2026-42945-poc

https://github.com/azilRababe/CVE-2026-42945

https://github.com/limo57640-crypto/nginx-rift-detector

https://github.com/p3Nt3st3r-sTAr/CVE-2026-42945-POC

https://github.com/byezero/nginx-cve-2026-42945-check

https://github.com/ChamsBouzaiene/ai-vuln-rediscovery-nginx-cve-2026-42945

https://github.com/hulina9900-boop/DIY-CVE-2026-42945-POC

https://github.com/chenqin231/CVE-2026-42945

https://github.com/jelasin/CVE-2026-42945

https://github.com/josephfelix/CVE-2026-42945-nginx-rift

https://github.com/nu0l/NGINX-Rift

https://github.com/yusufdalbudak/CVE-2026-42945

https://github.com/aratane/CVE-2026-42945

https://github.com/BarAppTeam/nginx-cve-fix

https://github.com/CynepMyx/nginx-rift-check

https://github.com/lowilol/CVE-2026-42945-NGINX-Rift-Check-Script

https://github.com/quantumworld-dpdns-io/CVE-2026-42945

https://github.com/MateusVerass/nGixshell

https://github.com/RedCrazyGhost/CVE-2026-42945

https://github.com/LiaoZiqi-GZFLS/CVE-2026-42945

https://github.com/imSre9/CVE-2026-42945

https://github.com/tal7aouy/nginx-cve-2026-42945

https://github.com/0xBlackash/CVE-2026-42945

https://github.com/Kentox493/CVE-2026-42945_NginxRift

https://github.com/sibersan/web-server-audit_CVE-2026-42945

https://github.com/soksofos/wazuh-nginx-cve-2026-42945-sca-lab

https://github.com/edgecases-PurpleHax/cve-images

kubesploit@learnk8s.news at 2026-08-21T19:06:03.000Z ##

Nginx Rift is a proof of concept for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module that allows unauthenticated remote code execution on servers using rewrite and set directives
The README lists affected and fixed versions

ku.bz/PQSlZ7Khl

##

kubesploit@learnk8s.news at 2026-08-21T19:06:03.000Z ##

Nginx Rift is a proof of concept for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module that allows unauthenticated remote code execution on servers using rewrite and set directives
The README lists affected and fixed versions

ku.bz/PQSlZ7Khl

##

CVE-2026-68820
(7.0 HIGH)

EPSS: 0.33%

updated 2026-08-16T19:17:24.183000

1 posts

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

2 repos

https://github.com/ubitquity/Windows-WinSock-UAF-Mitigation

https://github.com/HORKimhab/CVE-2026-68820

CapTechGroup@mastodon.social at 2026-08-21T12:52:36.000Z ##

A maximum-severity CVSS 10.0 flaw in Microsoft Entra ID is under active exploitation, allowing remote code execution. Two CVEs are in play, CVE-2026-68820 and CVE-2026-69836, with activity attributed to the Lazarus Group.

captechgroup.com/threat-intell

##

CVE-2026-17186
(9.9 CRITICAL)

EPSS: 0.47%

updated 2026-08-14T21:31:35

1 posts

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.

CVE-2026-8715
(9.6 CRITICAL)

EPSS: 0.32%

updated 2026-08-13T21:36:21

1 posts

Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. Th

CVE-2026-13737(CVSS UNKNOWN)

EPSS: 0.43%

updated 2026-08-11T18:30:43

1 posts

CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.

DailyCyberSecurity@infosec.exchange at 2026-08-19T12:57:03.000Z ##

Protect your network from CVE-2026-13737 and CVE-2026-13738. These critical Commvault command execution flaws allow hackers to bypass authorization checks.

#Commvault #CVE202613737 #CVE202613738 #Cybersecurity #Vulnerability

securityonline.info/commvault-

##

CVE-2026-13738
(0 None)

EPSS: 0.53%

updated 2026-08-11T17:17:47.660000

1 posts

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.

DailyCyberSecurity@infosec.exchange at 2026-08-19T12:57:03.000Z ##

Protect your network from CVE-2026-13737 and CVE-2026-13738. These critical Commvault command execution flaws allow hackers to bypass authorization checks.

#Commvault #CVE202613737 #CVE202613738 #Cybersecurity #Vulnerability

securityonline.info/commvault-

##

CVE-2026-66066(CVSS UNKNOWN)

EPSS: 1.77%

updated 2026-07-30T18:23:34

2 posts

### Impact In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process environment. That environment typically holds `secret_key_base` and often credentials for external systems, which may in turn allow escalation to remote code execution or lateral movement to those systems. ##

7 repos

https://github.com/paveg/rails-activestorage-vips-audit

https://github.com/0xBlackash/CVE-2026-66066

https://github.com/0xsha/KindaRails2Shell

https://github.com/rails/rails-forensics-CVE-2026-66066

https://github.com/shinthink/CVE-2026-66066

https://github.com/Zer0SumGam3/CVE-2026-66066-POC

https://github.com/HackSpeak/CVE-2026-66066

ottoto2017@prattohome.com at 2026-08-21T08:16:05.000Z ##

Mastodon v4.7 へのupgrade をRails v8.1.3 の脆弱性解消とは、関係ないことを学習。

Google AI:
「今回の「KindaRails2Shell (CVE-2026-66066)」という脆弱性の攻撃ルートを、Mastodon自体が完全に通らない構造になっているためです。

Active Storage(問題の部品)を完全排除している

ダイレクトアップロード機能も使っていない」

以上の回答を得ました。

Mastodon v4.7 が Rails v8.1.3 の対策で出されたと言う以前の私の投稿を訂正いたします。

#prattohome

##

ottoto2017@prattohome.com at 2026-08-21T08:16:05.000Z ##

Mastodon v4.7 へのupgrade をRails v8.1.3 の脆弱性解消とは、関係ないことを学習。

Google AI:
「今回の「KindaRails2Shell (CVE-2026-66066)」という脆弱性の攻撃ルートを、Mastodon自体が完全に通らない構造になっているためです。

Active Storage(問題の部品)を完全排除している

ダイレクトアップロード機能も使っていない」

以上の回答を得ました。

Mastodon v4.7 が Rails v8.1.3 の対策で出されたと言う以前の私の投稿を訂正いたします。

#prattohome

##

CVE-2026-11622
(7.5 HIGH)

EPSS: 0.51%

updated 2026-07-22T20:33:11.590000

1 posts

A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.

ondrej@sury.org at 2026-08-19T19:03:47.000Z ##

WTF?

> The fix for CVE-2026-11622 was reverted in commit d76328bfc7 on the development branch, reintroducing this vulnerability in the current stable release (9.20.27).

The branch was never merged and it was prepared just as an experiment. And this little ...person… tried to report this as CVSS 7.5.

##

CVE-2026-47301
(8.8 HIGH)

EPSS: 0.68%

updated 2026-07-14T21:32:21

1 posts

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

1 repos

https://github.com/OmriBaso/SCCM-CVE-2026-47301-Remote-Code-Execution-Exploit

CVE-2026-52929
(7.5 HIGH)

EPSS: 0.39%

updated 2026-07-08T15:28:40.107000

1 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: stream: fully roll back denied add-stream state When ADD_OUT_STREAMS is denied, SCTP only shrinks the queued chunks and then lowers outcnt. That leaves removed stream metadata behind, so a later re-add can reuse a stale ext and hit a null-pointer dereference in the scheduler get path. Fix the rollback by tearing down the

CVE-2026-58472
(5.9 MEDIUM)

EPSS: 0.22%

updated 2026-07-07T21:31:43

1 posts

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output si

ottoto2017@prattohome.com at 2026-08-21T00:27:09.000Z ##

#Ubuntu 24.04.4 で #update

console-setup (1.226ubuntu1.1)
セキュリティ対応ではない。
console-setup-linux
keyboard-configuration

open-vm-tools (2:13.0.10-0ubuntu0.24.04.1)
セキュリティ対応ではない。

snapd (2.76.3+ubuntu24.04)
セキュリティ対応ではない。

wget (1.21.4-1ubuntu4.5)
CVE-2026-58472へのセキュリティ対応。

#prattohome #更新

##

CVE-2026-8452
(9.8 CRITICAL)

EPSS: 1.04%

updated 2026-07-01T18:32:28

2 posts

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

3 repos

https://github.com/BishopFox/CVE-2026-8452-check

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

https://github.com/derekpreston81/CVE_ADC_IOC_2026

beyondmachines1 at 2026-08-21T13:01:26.798Z ##

Citrix NetScaler Flaws Under Active Attack Following Exploit Release

Citrix NetScaler ADC and Gateway appliances are being exploited via a critical SAML memory overflow vulnerability (CVE-2026-8452) that allows pre-authentication remote code execution. Attackers are targeting perimeter devices to gain unauthorized access to internal corporate networks following the release of public proof-of-concept code.

**If you run Citrix NetScaler ADC or Gateway, patch immediately to version 14.1-72.61 or 13.1-63.18 (or the matching FIPS builds). Attackers are already exploiting these appliances and a public exploit PoC is available. If you can't patch right away, restrict the management interface to trusted internal networks only, review your SAML configuration, and check logs for unexpected admin logins or config changes.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-21T13:01:26.000Z ##

Citrix NetScaler Flaws Under Active Attack Following Exploit Release

Citrix NetScaler ADC and Gateway appliances are being exploited via a critical SAML memory overflow vulnerability (CVE-2026-8452) that allows pre-authentication remote code execution. Attackers are targeting perimeter devices to gain unauthorized access to internal corporate networks following the release of public proof-of-concept code.

**If you run Citrix NetScaler ADC or Gateway, patch immediately to version 14.1-72.61 or 13.1-63.18 (or the matching FIPS builds). Attackers are already exploiting these appliances and a public exploit PoC is available. If you can't patch right away, restrict the management interface to trusted internal networks only, review your SAML configuration, and check logs for unexpected admin logins or config changes.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-12569
(9.8 CRITICAL)

EPSS: 30.20%

updated 2026-06-26T15:33:15

7 posts

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

1 repos

https://github.com/west-wind/Threat-Hunting-With-Splunk

threatnoir@infosec.exchange at 2026-08-20T16:06:30.000Z ##

⚠️ CRITICAL: Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

Clop ransomware operators deployed a custom JSP web shell targeting PTC Windchill and FlexPLM servers, exploiting CVE-2026-12569 to decrypt stored credentials and exfiltrate engineering data. Any organization running vulnerable Windchill instances is at immediate risk of credential compromise, late…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

DailyCyberSecurity@infosec.exchange at 2026-08-20T13:02:20.000Z ##

ReliaQuest found Clop deploying a purpose-built JSP web shell that abuses Windchill's internal APIs to decrypt secrets and steal files after exploiting CVE-2026-12569.

#Clop #Windchill #CVE202612569 #WebShell #DataExfiltration

meterpreter.org/clop-windchill

##

cyberworldops@infosec.exchange at 2026-08-20T00:20:00.000Z ##

Cl0p published full names of over 40 organizations allegedly breached through CVE-2026-12569 in PTC Windchill and FlexPLM. The flaw was added to CISA KEV in June, yet dozens of instances remained unpatched into August.

#Cl0p #Windchill #SupplyChainSecurity #CVE202612569

cyberworldops.eu/en/cl0p-targe

##

security_crawler_carl@infosec.exchange at 2026-08-19T16:30:24.000Z ##

You built your product lifecycle management empire on unpatched servers. Magnificent. Truly. Patch CVE-2026-12569 on all PTC Windchill and FlexPLM instances immediately, and hunt for unauthorized web shells before Clop finishes admiring your data.

Reward: You've unlocked the Hollow Trophy — a shiny gold cup with absolutely nothing inside it, just like your patch management schedule.

#Ransomware #CyberSecurity #ClopRansomware #PtcWindchill #WebShell #PatchedOrPerish (2/2)

##

security_crawler_carl@infosec.exchange at 2026-08-19T16:30:23.000Z ##

🏆 New Achievement! Shell We Dance, PTC?

Ahem. Allow me to explain my genius. Clop — yes, the ransomware operation, the one you've heard about in hushed tones — identified CVE-2026-12569 in PTC Windchill and FlexPLM servers and deployed a custom web shell so elegantly minimal it needs no additional tooling whatsoever. Credentials? Siphoned. Sensitive engineering data? Exfiltrated. It's almost beautiful, like a Bond villain who remembered to actually press the button. (1/2)

##

cyberworldops@infosec.exchange at 2026-08-19T14:20:00.000Z ##

ReliaQuest has documented a custom JSP web shell deployed by Clop after exploitation of CVE-2026-12569 on PTC Windchill and FlexPLM servers. The implant maps design vaults, decrypts keystore credentials, and queries databases via the application's own identity.

#Clop #PTCWindchill #WebShell #ThreatIntelligence

cyberworldops.eu/en/clop-explo

##

offseq@infosec.exchange at 2026-08-19T12:00:30.000Z ##

PTC Windchill/FlexPLM (CVE-2026-12569) exploited by Cl0p ransomware: CRITICAL severity, remote code execution, 40+ orgs hit. Patch ASAP to block active data theft & extortion. Full details: radar.offseq.com/threat/cl0p-r #OffSeq #Ransomware #CVE202612569 #Infosec

##

CVE-2026-20266
(9.1 CRITICAL)

EPSS: 0.63%

updated 2026-06-17T18:35:58

1 posts

In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation.

CVE-2010-3854
(0 None)

EPSS: 5.92%

updated 2026-06-16T23:23:40.850000

1 posts

Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

freddy@security.plumbing at 2026-08-19T20:16:47.000Z ##

@janl Oh no, I doxed myself. The reporter of CVE-2010-3854 wanted to stay anonymous, heh.

##

CVE-2026-0075
(5.9 MEDIUM)

EPSS: 0.09%

updated 2026-06-02T15:33:09

2 posts

In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

1 repos

https://github.com/QM4RS/CVE-2026-0075

DarkWebInformer@infosec.exchange at 2026-08-19T19:18:13.000Z ##

🚨 Public PoC available for high-severity Android ContactsProvider flaw

github.com/qm4rs/cve-2026-0075

CVE-2026-0075 affects Android 14, 15, 16, and 16 QPR2 and can allow access to information from the contacts database through a SQL-related side channel without user interaction.

Researcher QM4RS has now released a controlled Android PoC that intentionally requests neither READ_CONTACTS nor WRITE_CONTACTS.

The issue involves ContactsProvider2 returning detailed SQLite errors to callers that lack contacts permission. Those errors could potentially be abused as an information side channel.

Google's fix strips sensitive JSON-related SQLite exception details from unauthorized callers.

The researcher cautions that the PoC is build-specific and does not demonstrate a universal exploitation path across every Android device.

Devices with the June 5, 2026 Android security patch level or later address the issue.

##

DailyCyberSecurity@infosec.exchange at 2026-08-19T13:27:49.000Z ##

A public PoC for CVE-2026-0075 shows an Android elevation of privilege in ContactsProvider2 that needs no user interaction.

#CVE20260075 #Android #ElevationOfPrivilege #ContactsProvider #SQLInjection #AndroidSecurity

securityonline.info/cve-2026-0

##

CVE-2008-5161
(3.7 LOW)

EPSS: 15.39%

updated 2026-05-28T21:32:49

1 posts

Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux on IBM System z 6.0.4; Server for IBM z/OS 5.5.1 and earlier, 6.0.0, and 6.0.1; and Client 4.0-J through 4.3.3-J and 4.0-K through 4.3.10-K; and (2) OpenSSH 4.7p1 and possibly other

1 repos

https://github.com/talha3117/OpenSSH-4.7p1-CVE-2008-5161-Exploit

CVE-2026-1947
(7.5 HIGH)

EPSS: 0.27%

updated 2026-03-16T15:30:54

1 posts

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 9.1.9 via the submit_nex_form() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to to overwrite arbitrary form entries via the 'nf_set_entry_update_id' parameter.

4 repos

https://github.com/n0xdaemon/cve-2026-19478

https://github.com/davkharrr/CVE-2026-19478-PoC

https://github.com/HORKimhab/CVE-2026-19650-CVE-2026-19478

https://github.com/renzi25031469/CVE-2026-19478

hackmag@infosec.exchange at 2026-08-20T04:30:06.000Z ##

⚪️ Critical GitLab Vulnerability Allowed Deletion of Public Projects

🗨️ GitLab developers have released emergency patches for Community Edition (CE) and Enterprise Edition (EE) that address the critical vulnerability CVE-2026-19478 (CVSS score: 9.4). Under certain conditions, the flaw allowed an unauthenticated attacker to remotely modify or delete public projects and…

🔗 hackmag.com/news/cve-2026-1947

#news

##

CVE-2025-62593(CVSS UNKNOWN)

EPSS: 1.01%

updated 2025-12-01T16:02:43

3 posts

# Summary Developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. Due to the longstanding [decision](https://docs.ray.io/en/releases-2.51.1/ray-security/index.html) by the Ray Development team to not implement any sort of authentication on critical endpoints, like the `/api/jobs` & `/api/job_agent/jobs/` has once ag

1 repos

https://github.com/Boreas37/CVE-2025-62593-PoC

cyberworldops at 2026-08-21T16:20:01.034Z ##

CISA has added CVE-2025-62593 to the KEV catalog: a CVSS 8.8 flaw in Anyscale Ray enabling remote code execution against AI development environments. Active exploitation confirmed. Versions below 2.52.0 are affected. Patch immediately and audit for compromise — attackers are targeting the ML build layer as an initial access vector.

cyberworldops.eu/en/ray-added-

##

cyberworldops@infosec.exchange at 2026-08-21T16:20:01.000Z ##

CISA has added CVE-2025-62593 to the KEV catalog: a CVSS 8.8 flaw in Anyscale Ray enabling remote code execution against AI development environments. Active exploitation confirmed. Versions below 2.52.0 are affected. Patch immediately and audit for compromise — attackers are targeting the ML build layer as an initial access vector.

#RayFramework #CVE202562593 #ActiveExploitation #CISA

cyberworldops.eu/en/ray-added-

##

beyondmachines1@infosec.exchange at 2026-08-20T08:01:03.000Z ##

Ray Framework Remote Code Execution Vulnerability Under Active Exploitation

CISA warned that attackers are exploiting a remote code execution vulnerability in the Ray framework to target machine learning developers. The flaw allows attackers to bypass browser security checks and run arbitrary commands on developer machines and internal networks.

**If you use the Ray framework, update it to version 2.52.0 or later ASAP. Attackers are actively exploiting CVE-2025-62593 to run commands on developer machines. Also make sure Ray is never reachable from the internet and only accessible from trusted networks, and watch for unusual traffic between developer laptops and your internal compute clusters.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2012-0158
(8.8 HIGH)

EPSS: 99.97%

updated 2025-10-22T03:31:35

2 posts

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2;

2 repos

https://github.com/Sunqiz/CVE-2012-0158-reproduction

https://github.com/RobertoLeonFR-ES/Exploit-Win32.CVE-2012-0158.F.doc

kev_Stalker at 2026-08-21T17:45:41.941Z ##

CVE-2012-0158 - Changed to Known Ransomware Status

Microsoft MSCOMCTL.OCX Remote Code Execution VulnerabilityVendor: MicrosoftProduct: MSCOMCTL.OCXMicrosoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August nvd.nist.gov/vuln/detail/CVE-2

##

kev_Stalker@infosec.exchange at 2026-08-21T17:45:41.000Z ##

CVE-2012-0158 - Changed to Known Ransomware Status

Microsoft MSCOMCTL.OCX Remote Code Execution VulnerabilityVendor: MicrosoftProduct: MSCOMCTL.OCXMicrosoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2021-43226
(7.8 HIGH)

EPSS: 3.07%

updated 2025-10-22T00:33:30

2 posts

Windows Common Log File System Driver Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43207.

1 repos

https://github.com/Rosayxy/cve-2021-43226PoC

kev_Stalker at 2026-08-21T17:40:57.164Z ##

CVE-2021-43226 - Changed to Known Ransomware Status

Microsoft Windows Privilege Escalation VulnerabilityVendor: MicrosoftProduct: WindowsMicrosoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 21, 2026 at 13:08:17 UTCDate Added to nvd.nist.gov/vuln/detail/CVE-2

##

kev_Stalker@infosec.exchange at 2026-08-21T17:40:57.000Z ##

CVE-2021-43226 - Changed to Known Ransomware Status

Microsoft Windows Privilege Escalation VulnerabilityVendor: MicrosoftProduct: WindowsMicrosoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 21, 2026 at 13:08:17 UTCDate Added to nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2020-5135
(9.8 CRITICAL)

EPSS: 24.56%

updated 2025-10-22T00:31:59

2 posts

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. This vulnerability affected SonicOS Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0.

kev_Stalker at 2026-08-21T17:50:34.176Z ##

CVE-2020-5135 - Changed to Known Ransomware Status

SonicWall SonicOS Buffer Overflow VulnerabilityVendor: SonicWallProduct: SonicOSA buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 21, 2026 at 13:08:17 UTCDate Added tohttps://nvd.nist.gov/vuln/detail/CVE-2020-5135

##

kev_Stalker@infosec.exchange at 2026-08-21T17:50:34.000Z ##

CVE-2020-5135 - Changed to Known Ransomware Status

SonicWall SonicOS Buffer Overflow VulnerabilityVendor: SonicWallProduct: SonicOSA buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 21, 2026 at 13:08:17 UTCDate Added tohttps://nvd.nist.gov/vuln/detail/CVE-2020-5135

##

CVE-2026-54789
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-21T17:01:06.000Z ##

🟠 CVE-2026-54789 - High (7.5)

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds wr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-21T17:01:06.000Z ##

🟠 CVE-2026-54789 - High (7.5)

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds wr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59270
(0 None)

EPSS: 0.00%

2 posts

N/A

undercodenews@mastodon.social at 2026-08-21T10:24:14.000Z ##

Spring Security Vulnerability CVE-2026-59270 Exposes Embedded LDAP Servers to Remote Attackers

A Quiet Configuration Flaw With Serious Security Consequences A vulnerability hiding inside an embedded LDAP component can be easy to overlook—until an attacker discovers that the directory server is listening on a network interface it was never supposed to expose. That is the danger behind CVE-2026-59270, a newly disclosed Spring Security vulnerability affecting applications…

undercodenews.com/spring-secur

##

DailyCyberSecurity@infosec.exchange at 2026-08-21T02:11:36.000Z ##

Four Spring Security vulnerabilities were disclosed, led by CVE-2026-59270 (CVSS 9.4). Attackers can read or modify entries in the in-memory directory.

#SpringSecurity #CVE202659270 #LDAP #WebAuthn #DPoP #AppSec

securityonline.info/spring-sec

##

CVE-2026-77176
(0 None)

EPSS: 0.41%

2 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-08-21T02:02:38.000Z ##

CVE-2026-77176 lets a malicious operator mount arbitrary guest rootfs paths in Kata Containers Confidential Containers setups. Update to Kata 4.1.0.

#CVE202677176 #KataContainers #ConfidentialContainers #CloudSecurity #genpolicy #infosec

securityonline.info/cve-2026-7

##

thehackerwire@mastodon.social at 2026-08-20T18:00:32.000Z ##

🟠 CVE-2026-77176 - High (8.1)

A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71485
(0 None)

EPSS: 0.42%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-20T22:01:14.000Z ##

🔴 CVE-2026-71485 - Critical (9.1)

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers, and SetEm...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73256
(0 None)

EPSS: 0.40%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-20T19:00:14.000Z ##

🔴 CVE-2026-73256 - Critical (9.1)

Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting framing. The http_cb() f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59307
(0 None)

EPSS: 0.00%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-08-20T17:17:17.000Z ##

Two critical Spring Integration vulnerabilities, CVE-2026-59307 and CVE-2026-59324, expose systems to remote code execution and data leakage. Update now.

#SpringIntegration #CyberSecurity #CVE202659307 #CVE202659324 #Vulnerability

securityonline.info/spring-int

##

CVE-2026-59324
(0 None)

EPSS: 0.00%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-08-20T17:17:17.000Z ##

Two critical Spring Integration vulnerabilities, CVE-2026-59307 and CVE-2026-59324, expose systems to remote code execution and data leakage. Update now.

#SpringIntegration #CyberSecurity #CVE202659307 #CVE202659324 #Vulnerability

securityonline.info/spring-int

##

CVE-2026-63490
(0 None)

EPSS: 0.47%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-20T17:00:28.000Z ##

🟠 CVE-2026-63490 - High (7.5)

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader without the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54330
(0 None)

EPSS: 0.00%

1 posts

N/A

alina@girldick.gay at 2026-08-20T09:20:37.000Z ##

docs.ceph.com/en/latest/securi

github.com/ceph/ceph/commit/89

>RGW: This release contains a fix for CVE-2026-54330. We now reject Sigv4 requests with `host` and `x-amz-` headers not included in the signed subset. Unfortunately, the REST client used in multisite was generating such improperly signed requests.

can't make this shit up

> If you are running multisite, you must set the ``rgw_sigv4_insecure`` option to true before you begin to upgrade. After all clusters are upgraded, set the option to ``false`` again.

??! D:

they want me to backdoor the cluster in order to fix a security vuln in the cluster lmfao

##

CVE-2026-68899
(0 None)

EPSS: 0.40%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-19T21:00:25.000Z ##

🟠 CVE-2026-68899 - High (8.7)

Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation.js used the Unix file command for content-based MIME detection, but detectMimeFromFile() silently returned undefined when that binary was unavaila...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68561
(0 None)

EPSS: 0.38%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-19T21:00:07.000Z ##

🟠 CVE-2026-68561 - High (8.8)

Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) rule in server/permissions/boards.js called canUpdateBoardSort in server/lib/utils.js, which authorized any board member whenever fieldNames included...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites