## Updated at UTC 2026-06-27T04:38:36.591522

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-56414 7.2 0.00% 2 0 2026-06-26T23:17:09.137000 A vulnerability exists in H.View IP cameras certificate-related upload interface
CVE-2026-55975 7.2 0.00% 2 0 2026-06-26T23:17:08.997000 A vulnerability exists in H.View IP cameras that could allow an authenticated us
CVE-2026-28701 9.8 0.00% 2 0 2026-06-26T23:17:08.537000 Various versions of Daktronics Controller Firmware could allow authenticated and
CVE-2026-52784 8.8 0.00% 1 0 2026-06-26T20:20:22.420000 OpenProject is open-source, web-based project management software. Prior to 17.3
CVE-2026-48933 7.5 0.57% 1 0 2026-06-26T20:19:23.707000 A flaw in Node.js WebCrypto implementation can crash the process if the input of
CVE-2026-10561 10.0 0.53% 1 0 2026-06-26T20:19:05.520000 IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper iso
CVE-2026-9222 8.1 0.24% 1 0 2026-06-26T20:08:23.053000 Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior o
CVE-2026-44727 5.4 0.24% 1 0 2026-06-26T18:57:43.417000 Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the n
CVE-2026-43503 8.8 0.13% 3 4 2026-06-26T18:57:17.887000 In the Linux kernel, the following vulnerability has been resolved: net: skbuff
CVE-2026-57879 9.8 0.53% 1 0 2026-06-26T17:16:35.653000 An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in G
CVE-2026-11702 7.5 0.16% 1 0 2026-06-26T17:16:31.963000 Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state
CVE-2026-8380 6.5 0.18% 1 1 2026-06-26T16:17:26.200000 The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly
CVE-2026-12569 9.8 0.93% 4 1 2026-06-26T15:33:15 A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
CVE-2026-56025 7.5 0.00% 1 0 2026-06-26T15:32:16 Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 version
CVE-2026-20230 8.6 51.24% 9 3 2026-06-26T14:58:43.440000 A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco U
CVE-2026-56265 9.8 0.43% 1 0 2026-06-26T13:52:16.050000 Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a h
CVE-2026-57880 9.8 0.53% 1 0 2026-06-26T09:30:54 An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in G
CVE-2026-57881 9.8 0.38% 1 0 2026-06-26T09:30:54 An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in
CVE-2026-8797 None 0.12% 1 0 2026-06-26T06:30:38 An access control deficiency vulnerability exists in ExpressUpdate Agent for Win
CVE-2026-48618 7.7 0.61% 1 0 2026-06-26T03:31:36 A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator
CVE-2026-54158 9.9 0.29% 1 0 2026-06-26T00:16:53.823000 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, t
CVE-2026-23879 8.0 0.40% 1 0 2026-06-25T20:21:19.853000 py7zr is a Python-based library and utility to support 7zip archive compression,
CVE-2026-9702 7.5 0.21% 1 0 2026-06-25T15:33:04 The InPost PL WordPress plugin before 1.9.1 does not verify that the request ori
CVE-2026-33612 7.5 0.12% 1 0 2026-06-25T15:32:08 A malicious authoritative server can send a crafted zone via the ZoneToCache fun
CVE-2026-12851 9.1 1.68% 1 0 2026-06-25T14:02:35.347000 Multiple OS command injection vulnerabilities exist in the libNetSetObj.so funct
CVE-2026-12417 9.8 0.45% 1 1 2026-06-25T13:26:11.740000 The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass
CVE-2026-46752 None 0.40% 1 0 2026-06-25T12:32:11 Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This
CVE-2026-41566 None 0.29% 1 0 2026-06-25T12:32:10 Improper Handling of Insufficient Permissions or Privileges vulnerability in Apa
CVE-2026-55200 8.1 0.92% 6 1 2026-06-24T18:33:40 libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write
CVE-2026-11374 9.0 1.24% 1 0 2026-06-24T17:16:56.437000 In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and
CVE-2026-10735 7.5 0.39% 1 2 2026-06-24T15:31:43 Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimoni
CVE-2026-34908 10.0 2.45% 6 1 2026-06-24T14:50:41.720000 A malicious actor with access to the network could exploit an Improper Access Co
CVE-2026-34910 10.0 78.55% 4 0 template 2026-06-24T14:49:47.237000 A malicious actor with access to the network could exploit an Improper Input Val
CVE-2026-12416 9.8 0.36% 1 2 2026-06-24T09:30:46 The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via
CVE-2026-12850 9.1 1.72% 1 0 2026-06-24T06:31:51 Multiple OS command injection vulnerabilities exist in the libNetSetObj.so funct
CVE-2025-52465 7.2 0.35% 1 0 2026-06-24T05:17:25.543000 GeoServer is an open source server that allows users to share and edit geospatia
CVE-2026-11807 9.6 0.36% 1 0 2026-06-24T03:31:40 A missing authorization vulnerability was found in the Event-Driven Ansible (EDA
CVE-2026-44914 7.2 0.39% 1 0 2026-06-23T21:31:29 Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Proces
CVE-2026-12958 7.8 0.14% 1 0 2026-06-23T19:36:18.347000 Missing symlink validation in Language Servers for AWS may allow an arbitrary fi
CVE-2026-34909 10.0 2.27% 4 0 2026-06-23T18:34:16 A malicious actor with access to the network could exploit a Path Traversal vuln
CVE-2025-67038 9.8 1.13% 7 1 2026-06-23T18:31:31 An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module exec
CVE-2026-28496 0 1.89% 1 0 template 2026-06-23T16:16:59.350000 FOSSBilling is a free, open-source billing and client management system. Version
CVE-2026-49494 7.5 0.54% 1 0 2026-06-23T15:33:40 Comodo Internet Security's firewall driver Inspect.sys contains an integer under
CVE-2026-56394 6.5 0.34% 1 0 2026-06-23T14:17:24.290000 Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability
CVE-2026-10521 7.2 0.31% 3 0 2026-06-23T09:32:28 An high privileged remote attacker can access a hidden configuration method, tha
CVE-2026-12866 9.8 0.45% 1 0 2026-06-23T06:30:41 All versions of the package expr-eval are vulnerable to Code Execution via the t
CVE-2026-6645 0 0.14% 1 0 2026-06-23T05:17:05.117000 An insecure process execution vulnerability exists in the pc-printer-updater.exe
CVE-2026-11833 None 0.22% 1 0 2026-06-23T03:31:48 Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web s
CVE-2026-12581 7.5 0.30% 1 0 2026-06-22T20:17:59.447000 EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unau
CVE-2026-7166 0 0.38% 1 0 2026-06-22T19:45:16.537000 Vulnerability involving the exposure of sensitive data provided without adequate
CVE-2022-50972 9.8 0.63% 1 0 2026-06-22T18:40:05.833000 WooCommerce 7.1.0 contains a remote code execution vulnerability that allows att
CVE-2026-8157 8.8 0.24% 1 0 2026-06-22T18:38:02.507000 The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles
CVE-2026-10789 9.6 0.29% 1 0 2026-06-22T18:34:24 A maliciously crafted webpage, when visited by a user with Autodesk Fusion Deskt
CVE-2026-7664 9.8 0.28% 1 0 2026-06-22T18:34:23 IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to ac
CVE-2026-41950 6.5 0.33% 1 0 2026-06-22T18:34:02 Dify before version 1.14.0 contains an authorization bypass vulnerability that a
CVE-2026-41948 7.7 0.51% 1 0 2026-06-22T18:34:01 Dify version 1.14.1 and prior contain a path traversal vulnerability that allows
CVE-2026-41947 7.4 0.45% 1 0 2026-06-22T18:34:00 Dify version 1.14.1 and prior contains an authorization bypass vulnerability tha
CVE-2026-56448 None 0.29% 1 0 2026-06-22T15:30:52 A path traversal vulnerability exists in AIL Framework before the release contai
CVE-2026-12806 8.8 0.46% 1 0 2026-06-21T21:31:04 A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element
CVE-2026-56382 7.2 0.49% 1 0 2026-06-21T15:31:31 Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contai
CVE-2026-54317 7.6 0.19% 1 0 2026-06-19T19:35:48 ### Summary The Konnected integration registers an HTTP endpoint, `KonnectedVie
CVE-2026-46331 None 0.29% 3 3 2026-06-19T15:33:15 In the Linux kernel, the following vulnerability has been resolved: net/sched:
CVE-2026-11409 7.2 2.79% 1 0 2026-06-18T21:33:34 An authenticated OS command injection vulnerability exists in the IPv6 PPPoE con
CVE-2026-11410 7.2 2.79% 1 0 2026-06-18T21:33:34 An authenticated OS command injection vulnerability exists in the BigPond Cable
CVE-2026-56022 5.3 0.31% 1 0 2026-06-18T18:35:31 Webmin accepts basic authentication without session cookies when an attacker pro
CVE-2026-8461 8.8 0.39% 18 4 2026-06-18T15:32:09 An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specificall
CVE-2026-54388 9.1 0.39% 1 0 2026-06-17T21:34:45 Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests cont
CVE-2026-55199 5.9 0.41% 1 0 2026-06-17T21:34:45 libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication d
CVE-2026-42055 8.1 1.82% 1 1 2026-06-17T18:36:07 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_m
CVE-2026-42530 8.1 2.39% 1 3 2026-06-17T18:36:07 NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGI
CVE-2026-53876 7.2 1.79% 1 0 2026-06-17T16:18:00.113000 RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vuln
CVE-2026-50871 9.8 1.57% 1 0 2026-06-17T10:57:46.930000 An OS command injection vulnerability in the media archiving and export pipeline
CVE-2026-45504 8.8 0.46% 1 1 2026-06-17T10:52:10.200000 Server-side request forgery (ssrf) in Microsoft Exchange Server allows an author
CVE-2026-34926 6.7 12.68% 2 1 2026-06-17T10:39:49.727000 A directory traversal vulnerability in the Apex One (on-premise) server could al
CVE-2026-33017 9.8 98.41% 2 11 template 2026-06-17T10:36:47.177000 Langflow is a tool for building and deploying AI-powered agents and workflows. I
CVE-2026-22678 5.4 0.17% 1 0 2026-06-17T10:20:13.247000 Webmin before 2.641 contains a stored cross-site scripting vulnerability in the
CVE-2026-20045 8.2 4.31% 1 1 2026-06-17T10:16:58.097000 A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unif
CVE-2024-40766 9.8 15.69% 1 0 2026-06-17T07:46:30.123000 An improper access control vulnerability has been identified in the SonicWall So
CVE-2013-6786 0 2.17% 1 0 2026-06-17T00:00:56.043000 Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as use
CVE-2026-50874 8.1 1.12% 1 0 2026-06-16T21:33:04 An OS command injection vulnerability in the /manage/features/media component of
CVE-2026-38065 9.8 1.34% 1 0 2026-06-16T21:32:59 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the
CVE-2026-50656 7.8 3.39% 1 1 2026-06-16T21:31:57 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect
CVE-2026-53753 9.8 0.45% 1 0 2026-06-16T20:13:08 ### Summary The `_safe_eval_expression()` function in the computed fields featu
CVE-2026-20262 6.5 7.68% 2 2 2026-06-15T21:31:39 A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN
CVE-2026-48970 8.1 0.32% 1 0 2026-06-15T21:30:58 Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.
CVE-2026-12219 6.3 1.52% 1 0 2026-06-15T06:31:46 A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is
CVE-2026-12223 5.5 1.53% 1 0 2026-06-15T06:31:41 A vulnerability was identified in Yealink SIP-T46U 108.86.0.118. Affected by thi
CVE-2026-12197 7.2 2.38% 1 0 2026-06-15T00:31:55 A security flaw has been discovered in Ruijie EG105G-P 2.340. The impacted eleme
CVE-2026-9271 5.9 0.14% 1 0 2026-06-12T18:32:55 Vulnerability Title
CVE-2026-34182 9.1 0.24% 1 0 2026-06-10T18:32:45 Issue Summary: Cryptographic Message Services (CMS) processing fails to perform
CVE-2026-25860 6.1 0.29% 1 1 2026-06-10T00:31:50 OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability i
CVE-2026-20245 7.8 9.92% 6 3 2026-06-09T21:32:21 A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vMa
CVE-2026-7473 5.8 0.84% 1 1 2026-06-09T18:30:34 On affected platforms running Arista EOS where a tunnel decapsulation configurat
CVE-2026-26980 9.4 70.00% 1 6 template 2026-06-08T23:22:35 ### Impact A SQL injection vulnerability existed in Ghost's Content API that al
CVE-2026-45034 None 0.35% 1 1 2026-06-08T23:00:17 ## Summary CVE-2026-34084 was patched by the helper `File::prohibitWrappers`. T
CVE-2026-20175 6.1 0.18% 1 0 2026-06-03T18:33:18 A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker
CVE-2026-49103 None 0.30% 1 0 2026-05-27T15:33:37 Webmin before 2.640 does not safely construct a filename for saving of an attach
CVE-2026-23243 7.8 0.12% 1 0 2026-05-21T18:33:06 In the Linux kernel, the following vulnerability has been resolved: RDMA/umad:
CVE-2026-6637 8.8 0.38% 2 0 2026-05-14T15:31:59 Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged datab
CVE-2026-28910 3.3 0.12% 1 0 2026-05-13T00:49:16 This issue was addressed with improved permissions checking. This issue is fixed
CVE-2026-4020 7.5 39.70% 1 1 template 2026-03-31T03:31:35 The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exp
CVE-2026-20971 7.8 0.13% 2 0 2026-01-15T21:31:44 Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local atta
CVE-2025-8088 8.8 85.78% 1 32 2025-10-22T00:34:26 A path traversal vulnerability affecting the Windows version of WinRAR allows th
CVE-2014-9222 None 63.75% 1 2 2025-04-12T12:44:27 AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products a
CVE-2014-9223 None 6.03% 1 0 2025-04-12T12:44:27 Multiple buffer overflows in AllegroSoft RomPager, as used in Huawei Home Gatewa
CVE-2024-2658 None 0.41% 1 2 2025-01-30T18:32:09 A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1
CVE-2019-1003037 6.5 1.30% 1 0 2023-12-14T18:25:14 An information exposure vulnerability exists in Jenkins Azure VM Agents Plugin 0
CVE-2026-11705 0 0.00% 1 0 N/A
CVE-2026-20896 0 0.00% 1 0 N/A
CVE-2026-8932 0 0.00% 2 1 N/A
CVE-2026-13311 0 0.36% 1 0 N/A
CVE-2026-50551 0 0.44% 1 0 N/A
CVE-2026-55570 0 0.33% 1 0 N/A
CVE-2026-55454 0 0.31% 1 0 N/A
CVE-2026-50000 0 0.00% 1 0 N/A
CVE-2026-53662 0 0.24% 1 0 N/A
CVE-2026-50160 0 0.00% 1 0 N/A
CVE-2026-12957 0 0.12% 1 0 N/A
CVE-2026-47729 0 0.00% 1 1 N/A
CVE-2026-10658 0 0.17% 1 0 N/A

CVE-2026-56414
(7.2 HIGH)

EPSS: 0.00%

updated 2026-06-26T23:17:09.137000

2 posts

A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This design omission enables the placement of unexpected or malformed data in locations intended for trusted certificate material, which could affect system integrity o

offseq at 2026-06-27T01:30:27.955Z ##

CVE-2026-56414: H.VIEW HV-500S6 IP Camera has a HIGH-severity vuln (CVSS 7.2) allowing authenticated users to upload arbitrary files via certificate upload, risking persistent compromise. Restrict admin access & monitor uploads. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-27T01:30:27.000Z ##

CVE-2026-56414: H.VIEW HV-500S6 IP Camera has a HIGH-severity vuln (CVSS 7.2) allowing authenticated users to upload arbitrary files via certificate upload, risking persistent compromise. Restrict admin access & monitor uploads. radar.offseq.com/threat/cve-20 #OffSeq #IoTSecurity #CVE #Vulnerability

##

CVE-2026-55975
(7.2 HIGH)

EPSS: 0.00%

updated 2026-06-26T23:17:08.997000

2 posts

A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to the device's certificate generation interface, which are incorporated into a backend certificate creation command without proper input validation. This may allow for command execution with elevated privileges during certificate generation.

offseq at 2026-06-27T03:00:23.955Z ##

H.VIEW HV-500S6 IP Camera has a HIGH severity bug (CVE-2026-55975, CVSS 7.2): Authenticated users may inject commands using unsanitized XML in cert generation. Restrict access, monitor activity, and check for patches. radar.offseq.com/threat/cve-20 🔒

##

offseq@infosec.exchange at 2026-06-27T03:00:23.000Z ##

H.VIEW HV-500S6 IP Camera has a HIGH severity bug (CVE-2026-55975, CVSS 7.2): Authenticated users may inject commands using unsanitized XML in cert generation. Restrict access, monitor activity, and check for patches. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity 🔒

##

CVE-2026-28701
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-06-26T23:17:08.537000

2 posts

Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.

offseq at 2026-06-27T00:00:40.082Z ##

Daktronics VFC-DMP-5000 firmware has a CRITICAL vuln (CVE-2026-28701, CVSS 9.8): remote attackers can traverse directories & enumerate file paths — no auth needed. No patch yet. Restrict network access & monitor closely. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-06-27T00:00:40.000Z ##

Daktronics VFC-DMP-5000 firmware has a CRITICAL vuln (CVE-2026-28701, CVSS 9.8): remote attackers can traverse directories & enumerate file paths — no auth needed. No patch yet. Restrict network access & monitor closely. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec #IoT

##

CVE-2026-52784
(8.8 HIGH)

EPSS: 0.00%

updated 2026-06-26T20:20:22.420000

1 posts

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a CSRF on TARGET through /users/:id via POST parameter "user[admin]". This vulnerability is fixed in 17.3.3 and 17.4.1.

hugovalters@mastodon.social at 2026-06-26T23:13:15.000Z ##

CVE-2026-52784 - Critical CSRF in OpenProject. Attackers can escalate privileges via /users/:id. CVSS 8.8. Update to 17.3.3 or 17.4.1 immediately. #CVE #OpenProject #infosec

valtersit.com/cve/CVE-2026-527

##

CVE-2026-48933
(7.5 HIGH)

EPSS: 0.57%

updated 2026-06-26T20:19:23.707000

1 posts

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

offseq@infosec.exchange at 2026-06-26T04:30:25.000Z ##

Node.js WebCrypto in v22.22.3, v24.16.0, v26.3.0 is affected by CVE-2026-48933 (HIGH). Integer overflow in subtle.encrypt() can crash processes with inputs ≥ 2 GiB, causing DoS. Avoid large inputs while awaiting a fix. 🔐 radar.offseq.com/threat/cve-20 #OffSeq #Nodejs #Vuln

##

CVE-2026-10561
(10.0 CRITICAL)

EPSS: 0.53%

updated 2026-06-26T20:19:05.520000

1 posts

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise

offseq@infosec.exchange at 2026-06-22T15:00:13.000Z ##

IBM Langflow OSS v1.0.0 – 1.9.3 hit by CRITICAL code injection (CVE-2026-10561, CVSS 10). Auth bypass enables unauth'd RCE & total compromise. No patch yet — track IBM advisories for updates. radar.offseq.com/threat/cve-20 #OffSeq #Infosec #CVE202610561

##

CVE-2026-9222
(8.1 HIGH)

EPSS: 0.24%

updated 2026-06-26T20:08:23.053000

1 posts

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.

offseq@infosec.exchange at 2026-06-26T00:00:40.000Z ##

Setracker2 Android app (com.tgelec.setracker) hit by CRITICAL vuln (CVE-2026-9222, CVSS 9.2): uses password hash for authentication. Anyone with the hash can access backend services. Update guidance pending. radar.offseq.com/threat/cve-20 #OffSeq #AndroidSec #CVE20269222

##

CVE-2026-44727
(5.4 MEDIUM)

EPSS: 0.24%

updated 2026-06-26T18:57:43.417000

1 posts

Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their Content-Security-Policy. Combined with nbconvert.HTMLExporter's default non-sanitizing behavior, a notebook carrying an HTML payload in a display_data output triggers stored XSS with

offseq@infosec.exchange at 2026-06-23T00:00:39.000Z ##

CVE-2026-44727: CRITICAL XSS in jupyter_server <2.20. Malicious notebooks can lead to cookie theft & remote code execution due to missing CSP sandboxing. Upgrade to 2.20+ to secure your server. Details: radar.offseq.com/threat/cve-20 #OffSeq #XSS #Jupyter #Security

##

CVE-2026-43503
(8.8 HIGH)

EPSS: 0.13%

updated 2026-06-26T18:57:17.887000

3 posts

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when moving frags from source to destination. __pskb_copy_fclone() defers the rest of the shinfo metadata to skb_copy_header(

4 repos

https://github.com/aexdyhaxor/CVE-2026-43503-DirtyClone

https://github.com/sec0x/CVE-2026-43503

https://github.com/mooder1/dirtyclone-CVE-2026-43503

https://github.com/0xBlackash/CVE-2026-43503

halildeniz@mastodon.social at 2026-06-26T18:50:38.000Z ##

My latest technical deep-dive is live! 🚨

Deep dive into CVE-2026-43503 (DirtyClone) in the Linux kernel network stack. Learn how a metadata propagation gap drops the SHARED_FRAG flag, bypasses COW guards, and grants instant LPE root access:

denizhalil.com/2026/06/26/cve-

#CVE202643503 #DirtyClone #LinuxKernel #LPE #Cybersecurity

##

guru@thecybersecguru.com at 2026-06-26T17:40:04.000Z ##

Two new Linux LPEs hit page cache from opposite ends of the kernel

Two new Linux kernel LPEs, CVE-2026-46331 (pedit COW) and CVE-2026-43503 (DirtyClone), corrupt page-cache memory to gain root without touching disk. Working exploits are public

thecybersecguru.com/news/linux

##

guru@thecybersecguru.com at 2026-06-26T17:40:04.000Z ##

Two new Linux LPEs hit page cache from opposite ends of the kernel

Two new Linux kernel LPEs, CVE-2026-46331 (pedit COW) and CVE-2026-43503 (DirtyClone), corrupt page-cache memory to gain root without touching disk. Working exploits are public

thecybersecguru.com/news/linux

##

CVE-2026-57879
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-06-26T17:16:35.653000

1 posts

An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing RTSP custom authentication data. A remote attacker may exploit this vulnerability by sending a crafted RTSP request, resulting in memory corruption, denial of service, or potentially arbitra

offseq@infosec.exchange at 2026-06-26T13:30:35.000Z ##

GeoVision GV-LPC2011/2211 (≤v1.12) affected by CVE-2026-57879: CRITICAL stack-based buffer overflow in ssvr (CVSS 9.8). Remote, unauthenticated code execution possible via crafted RTSP. Restrict RTSP & monitor. radar.offseq.com/threat/cve-20 #OffSeq #CVE202657879 #infosec #IoT

##

CVE-2026-11702
(7.5 HIGH)

EPSS: 0.16%

updated 2026-06-26T17:16:31.963000

1 posts

Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes. When an object is initialised before forking, then the internal state for the PRNG is shared across processes and identical random streams will be produced. Secrets generated in multiprocess applications are predictable across processes.

mastokukei@social.josko.org at 2026-06-26T18:01:59.000Z ##

(Obsidian/Notion alternative), OpenMontage (agentic video production), NeoStreaming (C++ streaming library), Libre Barcode Project.
- **Web development**: CSS `field-sizing`, `text-box-trim`, SVG charts, scroll-driven animations, Deno 2.9 (desktop app support).
- **Security updates**: Expat 2.8.2 (security release), CVE-2026-11702 in p5-Bytes-Random-Secure-Tiny, GitHub OAuth for Cloudflare, `Secs-man` secrets manager.
- **Chess engines**: Stockfish dev-20260625, Avalanche [2/3]

##

CVE-2026-8380
(6.5 MEDIUM)

EPSS: 0.18%

updated 2026-06-26T16:17:26.200000

1 posts

The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with author-level access and above to permanently delete arbitrary posts and pages. When the Frontend File Manager Plugin WordPress plugin through 23.6's "Allow guest uploads" setting is enabled by an administrator, the sam

1 repos

https://github.com/tiagob0b/CVE-2026-8380

offseq@infosec.exchange at 2026-06-26T07:30:25.000Z ##

CVE-2026-8380: HIGH severity in Frontend File Manager Plugin (≤23.6) for WordPress. Author+ users can delete any post/page; guest deletion possible if enabled. Disable 'Allow guest uploads' until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #BlueTeam

##

CVE-2026-12569
(9.8 CRITICAL)

EPSS: 0.93%

updated 2026-06-26T15:33:15

4 posts

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

1 repos

https://github.com/west-wind/Threat-Hunting-With-Splunk

thecybermind@infosec.exchange at 2026-06-26T13:11:01.000Z ##

CISA adds CVE-2026-12569 to the KEV catalog as adversaries actively exploit PTC Windchill & FlexPLM platforms. This is an immediate threat to supply chain integrity and intellectual property. Access our complete executive risk mitigation framework for corporate leadership: thecybermind.co/lacm

##

thecybermind@infosec.exchange at 2026-06-26T12:01:50.000Z ##

CISA adds CVE-2026-12569 to the KEV catalog as adversaries actively exploit PTC Windchill & FlexPLM input validation vulnerabilities. Lock down your supply chain assets. Full forensic indicators, lateral movement tracking, and active endpoint hardening protocols are live: thecybermind.co/y7tn

##

secdb@infosec.exchange at 2026-06-25T21:02:25.000Z ##

🚨 [CISA-2026:0625] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-12569 (secdb.nttzen.cloud/cve/detail/)
- Name: PTC Windchill and FlexPLM Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: PTC
- Product: Windchill and FlexPLM
- Notes: ptc.com/en/support/article/CS4 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-20230 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Unified Communications Manager
- Notes: cisco.com/c/en/us/support/docs ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260625 #cisa20260625 #cve_2026_12569 #cve_2026_20230 #cve202612569 #cve202620230

##

cisakevtracker@mastodon.social at 2026-06-25T20:00:51.000Z ##

CVE ID: CVE-2026-12569
Vendor: PTC
Product: Windchill and FlexPLM
Date Added: 2026-06-25
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-56025
(7.5 HIGH)

EPSS: 0.00%

updated 2026-06-26T15:32:16

1 posts

Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.

hugovalters@mastodon.social at 2026-06-26T17:04:51.000Z ##

CVE-2026-56025 - Info disclosure via unauthenticated broken access control in Paymob for WooCommerce <=4.1.2. CVSS 7.5. No patch available. Restrict access immediately. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-560

##

CVE-2026-20230
(8.6 HIGH)

EPSS: 51.24%

updated 2026-06-26T14:58:43.440000

9 posts

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this

3 repos

https://github.com/HORKimhab/CVE-2026-20230

https://github.com/HalilDeniz/CVE-2026-20230-Scanner

https://github.com/W5M1n9/Cisco-Unified-Communications-Manager-Server-Side-Forgery-Request-Vulnerability-CVE-2026-20230

Analyst207@mastodon.social at 2026-06-26T20:14:06.000Z ##

CISA Mandates Urgent Patching for Exploited Cisco Flaw

Don't wait until it's too late: Cisco has issued a critical patch for a vulnerability (CVE-2026-20230) in its Unified Communications Manager Server, and the US Cybersecurity and Infrastructure Security Agency (CISA) is requiring urgent remediation by June 28. Act now to protect your system from potential remote exploitation.

osintsights.com/cisa-mandates-

#Cisa #Cisco #Cve202620230 #ServersideRequestForgery #UnifiedCommunicationsManagerServer

##

secdb@infosec.exchange at 2026-06-25T21:02:25.000Z ##

🚨 [CISA-2026:0625] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-12569 (secdb.nttzen.cloud/cve/detail/)
- Name: PTC Windchill and FlexPLM Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: PTC
- Product: Windchill and FlexPLM
- Notes: ptc.com/en/support/article/CS4 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-20230 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Unified Communications Manager
- Notes: cisco.com/c/en/us/support/docs ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260625 #cisa20260625 #cve_2026_12569 #cve_2026_20230 #cve202612569 #cve202620230

##

cisakevtracker@mastodon.social at 2026-06-25T20:01:06.000Z ##

CVE ID: CVE-2026-20230
Vendor: Cisco
Product: Unified Communications Manager
Date Added: 2026-06-25
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

PC_Fluesterer@social.tchncs.de at 2026-06-25T16:42:41.000Z ##

Cisco unter Beschuss

Es ist alles nicht so schlimm wie es aussieht, es ist alles viel viel schlimmer. Nicht nur werden in schöner (?) Regelmäßigkeit gefährliche Sicherheitslücken in Cisco-Produkten gefunden, sondern sie werden auch sofort für Angriffe ausgenutzt - manche schon vor der Veröffentlichung (Zero-Day). Eine kleine Historie füge ich unten an. Beginnen wir mit CVE-2026-20230 (8,6 von 10), über die ich noch nicht explizit berichtet hatte. Am Anfang Juni hatte Cisco Flicken gegen diese Sicherheitslücke veröffentlicht. Damals vermeldete die Firma, dass ein PoC Exploit vorläge. Anscheinend haben unbekannte Hacker den PoC gleich in einen

pc-fluesterer.info/wordpress/2

#0day #backdoor #cybercrime #exploits #hersteller #politik #privacy #sicherheit #spionage #UnplugTrump #wissen #zeroday

##

thecybermind@infosec.exchange at 2026-06-25T10:06:07.000Z ##

Critical zero-day alert: Cisco CUCM WebDialer SSRF (CVE-2026-20230) allows unauthenticated remote root file-writes. We map out the Tomcat log baselines, JSP shell indicators, and edge isolation steps in our latest TSUITE Runbook. Protect your voice network: mike@thecybermind.co. #Infosec

##

beyondmachines1@infosec.exchange at 2026-06-25T09:01:30.000Z ##

Active Exploitation of Cisco Unified Communications Manager Vulnerabilities Grants Root Access

Cisco Unified Communications Manager is facing active exploitation of two vulnerabilities, CVE-2026-20230 and CVE-2026-20045, which allow unauthenticated attackers to gain root access and deploy webshells.

**Apply the latest software updates, including Unified CM 14SU6 and 15SU5, immediately. If patching is not possible, disable the Cisco WebDialer Web Service to sever the attack path, and aggressively audit your /platform-services/ directory for unusual .jsp files or unauthorized webshells.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

thenewoil@mastodon.thenewoil.org at 2026-06-24T20:00:03.000Z ##

#Cisco #UnifiedCM flaw CVE-2026-20230 now exploited in attacks

bleepingcomputer.com/news/secu

#cybersecurity

##

tugatech@masto.pt at 2026-06-24T06:45:50.000Z ##

Falha crítica em servidores da Cisco está a ser ativamente explorada. A vulnerabilidade CVE-2026-20230 afeta o Unified Communications Manager e a Session Management Edition, exigindo ação imediata dos administradores de sistemas em Portugal. ⚠️

🔗 tugatech.com.pt/t86118-falha-c

#falha 

##

oversecurity@mastodon.social at 2026-06-23T22:30:19.000Z ##

Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks

A high-severity SSRF vulnerability, tracked as CVE-2026-20230, in Cisco Unified Communications Manager Server is now being exploited in attacks.

🔗️ [Bleepingcomputer] link.is.it/Y4BXYl

##

CVE-2026-56265
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-06-26T13:52:16.050000

1 posts

Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentication tokens for any user, bypassing authentication and gaining full access to protected functionality.

CVE-2026-57880
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-06-26T09:30:54

1 posts

An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing RTSP Digest authentication fields. A remote attacker may exploit this vulnerability by sending a crafted RTSP request containing overly long authentication data, resulting in memory corruption,

offseq@infosec.exchange at 2026-06-26T12:00:28.000Z ##

GeoVision GV-LPC2011/2211 devices (≤1.12) face CRITICAL CVE-2026-57880: stack-based buffer overflow in RTSP auth enables remote, unauthenticated DoS or code execution. Restrict RTSP access, monitor traffic. Patch status unknown. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSecurity #CVE

##

CVE-2026-57881
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-06-26T09:30:54

1 posts

An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient length validation when processing remote login data. A remote attacker may exploit this vulnerability by sending crafted login data with overly long input, resulting in memory corruption, denial of service, or potentially

offseq@infosec.exchange at 2026-06-26T10:30:26.000Z ##

GeoVision GV-LPC2011/2211 (<=1.12) hit by CVE-2026-57881: CRITICAL stack-based buffer overflow in vlsvr enables unauthenticated RCE or DoS. No patch yet — restrict access & monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSecurity #CVE202657881

##

CVE-2026-8797(CVSS UNKNOWN)

EPSS: 0.12%

updated 2026-06-26T06:30:38

1 posts

An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges.

offseq@infosec.exchange at 2026-06-26T06:00:25.000Z ##

HIGH severity: CVE-2026-8797 impacts NEC ExpressUpdate Agent for Windows. Exposed IOCTL enables local privilege escalation to SYSTEM. No patch yet — restrict local access, monitor activity. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Windows #PrivilegeEscalation

##

CVE-2026-48618
(7.7 HIGH)

EPSS: 0.61%

updated 2026-06-26T03:31:36

1 posts

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js

offseq@infosec.exchange at 2026-06-26T03:00:24.000Z ##

CVE-2026-48618: Node.js HIGH severity vuln in TLS hostname handling (Unicode dot normalization flaw). Affects 22.22.3, 24.16.0, 26.3.0. No patch yet — restrict use & monitor vendor advisory. radar.offseq.com/threat/cve-20 #OffSeq #NodeJS #Vulnerability #TLS #Security

##

CVE-2026-54158
(9.9 CRITICAL)

EPSS: 0.29%

updated 2026-06-26T00:16:53.823000

1 posts

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in four of its branches: text, url, phone, and mAsset. A cell value like </textarea><img src=x onerror="..."> or "><img src=x onerror="..."> breaks out of its surrounding tag and runs arbitrary JavaScript in the renderer when the vi

offseq@infosec.exchange at 2026-06-25T04:30:26.000Z ##

CVE-2026-54158: CRITICAL XSS in SiYuan (<3.7.0) allows persistent JS injection; on Electron clients, can escalate to RCE. Upgrade to 3.7.0+ ASAP. No active exploits reported. radar.offseq.com/threat/cve-20 #OffSeq #XSS #CVE202654158 #SiYuan

##

CVE-2026-23879
(8.0 HIGH)

EPSS: 0.40%

updated 2026-06-25T20:21:19.853000

1 posts

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to be recreated outside the destination directory via crafted malicious symbolic link chains. When using extractall to extract an archive, the library restores these symbolic

hugovalters@mastodon.social at 2026-06-24T23:14:50.000Z ##

CVE-2026-23879 - Critical RCE in Py7zr. Arbitrary file write via symbolic link chains allows escape from destination directory. CVSS 8.0. No patch available. Update or avoid extraction of untrusted 7z archives. #CVE #infosec #Python

valtersit.com/cve/CVE-2026-238

##

CVE-2026-9702
(7.5 HIGH)

EPSS: 0.21%

updated 2026-06-25T15:33:04

1 posts

The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destination to be updated, allowing unauthenticated attackers to silently redirect the shipping destination of any pending or processing order on the site.

offseq@infosec.exchange at 2026-06-25T07:30:26.000Z ##

HIGH severity: CVE-2026-9702 in InPost PL WordPress plugin (<1.9.1) lets unauthenticated attackers redirect WooCommerce order shipping. No patch yet — restrict access, monitor for changes. Details: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vulnerability #Ecommerce

##

CVE-2026-33612
(7.5 HIGH)

EPSS: 0.12%

updated 2026-06-25T15:32:08

1 posts

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.

offseq@infosec.exchange at 2026-06-25T13:30:24.000Z ##

CVE-2026-33612 (HIGH, CVSS 7.5) impacts PowerDNS Recursor ≤5.4.3. Crafted zones from malicious servers can trigger cache poisoning via ZoneToCache. Review deployments, monitor for patches: radar.offseq.com/threat/cve-20 #OffSeq #PowerDNS #vuln #dns

##

CVE-2026-12851
(9.1 CRITICAL)

EPSS: 1.68%

updated 2026-06-25T14:02:35.347000

1 posts

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various servi

offseq@infosec.exchange at 2026-06-24T06:00:25.000Z ##

CVE-2026-12851: CRITICAL OS command injection in GeoVision GV-I/O Box 4E v2.09 via DVRSearch/Network.cgi allows remote code execution. Patch status pending — restrict access & monitor endpoints. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity #CVE #Security

##

CVE-2026-12417
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-06-25T13:26:11.740000

1 posts

The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_password()` AJAX handler — registered via `wp_ajax_nopriv_pravel_change_password` and therefore accessible to unauthenticated users — performing no nonce verification, no capability

1 repos

https://github.com/Nxploited/CVE-2026-12416-CVE-2026-12417

offseq@infosec.exchange at 2026-06-24T10:30:27.000Z ##

pravel SignUp & SignIn (<=1.0.0) has a CRITICAL flaw (CVE-2026-12417): unauthenticated attackers can reset any WordPress user password, including admins. Remove or disable plugin until patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #CVE202612417

##

CVE-2026-46752(CVSS UNKNOWN)

EPSS: 0.40%

updated 2026-06-25T12:32:11

1 posts

Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.

offseq@infosec.exchange at 2026-06-25T12:00:29.000Z ##

CVE-2026-46752: CRITICAL heap-based buffer overflow in Apache Kvrocks (2.0.4 – 2.15.0) via Redis Lua cjson. RCE & DoS possible. Upgrade to 2.16.0 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Kvrocks #CVE202646752 #infosec

##

CVE-2026-41566(CVSS UNKNOWN)

EPSS: 0.29%

updated 2026-06-25T12:32:10

1 posts

Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: 2.8.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.

offseq@infosec.exchange at 2026-06-25T10:30:25.000Z ##

CVE-2026-41566 (CRITICAL, CVSS 9.4) in Apache Kvrocks 2.8.0 allows privilege escalation via improper permission handling. Upgrade to 2.16.0 is required — no other mitigation. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202641566 #Kvrocks #Security

##

CVE-2026-55200
(8.1 HIGH)

EPSS: 0.92%

updated 2026-06-24T18:33:40

6 posts

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.

1 repos

https://github.com/0xBlackash/CVE-2026-55200

Sempf@infosec.exchange at 2026-06-26T00:53:38.000Z ##

Just saw there is an exploit example for that libssh2 vuln. Has anyone given it a try yet? I might be too lazy to get my laptop out.

github.com/0xBlackash/CVE-2026

##

xeiaso.net@bsky.brid.gy at 2026-06-24T17:31:32.235Z ##

"No way to prevent this" say users of only language where this regularly happens https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-55200/

"No way to prevent this" say u...

##

cadey@pony.social at 2026-06-24T17:31:32.000Z ##

"No way to prevent this" say users of only language where this regularly happens

xeiaso.net/shitposts/no-way-to

##

bortzmeyer@mastodon.gougere.fr at 2026-06-23T09:21:40.000Z ##

Ah sinon, si vous utilisez du logiciel, vous allez être piraté. Cette fois, c'est SSH (CVE-2026-55200).
cve.org/CVERecord?id=CVE-2026-

##

harrysintonen@infosec.exchange at 2026-06-22T09:58:42.000Z ##

For example it seems Debian stable is currently affected: security-tracker.debian.org/tr

##

beyondmachines1@infosec.exchange at 2026-06-22T09:01:09.000Z ##

libssh2 Vulnerabilities Enable Remote Code Execution and Denial of Service

libssh2 disclosed two vulnerabilities, including a critical out-of-bounds write (CVE-2026-55200) and a high-severity denial of service (CVE-2026-55199), affecting versions up to 1.11.1. These flaws allow malicious servers to execute code on connecting clients or cause resource exhaustion.

**Plan to update libssh2 to a patched build as soon as a fixed release is available. In the meantime audit your tools (curl/libcurl, PHP ssh2 extension, monitoring utilities, IoT firmware) for the vulnerable library versions up to 1.11.1. Only connect to SSH servers you trust and isolate sensitive management interfaces so they're reachable from trusted networks only, since a malicious server can now attack your client.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-11374
(9.0 CRITICAL)

EPSS: 1.24%

updated 2026-06-24T17:16:56.437000

1 posts

In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.

offseq@infosec.exchange at 2026-06-23T10:30:32.000Z ##

Zoho ManageEngine ADSelfService Plus hit by CRITICAL CVE-2026-11374: predictable SSO tickets enable unauthenticated account takeover. No patch yet — monitor advisories and review exposure. radar.offseq.com/threat/cve-20 #OffSeq #Zoho #Vuln #SSO #Infosec

##

CVE-2026-10735
(7.5 HIGH)

EPSS: 0.39%

updated 2026-06-24T15:31:43

1 posts

Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 were distributed with malicious code throug

2 repos

https://github.com/HORKimhab/CVE-Wordpress

https://github.com/xxconi/CVE-2026-49777-CVE-2026-10735

offseq@infosec.exchange at 2026-06-24T07:30:26.000Z ##

CVE-2026-10735 (CRITICAL): smart-post-show-pro 4.0.1 for WordPress shipped with malicious code via compromised update server. Unauth attackers can exfiltrate creds & control sites. Remove/disable affected plugin & monitor for IOCs. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #SupplyChain

##

CVE-2026-34908
(10.0 CRITICAL)

EPSS: 2.45%

updated 2026-06-24T14:50:41.720000

6 posts

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

1 repos

https://github.com/BishopFox/CVE-2026-34908-check

rswebsols@mastodon.social at 2026-06-27T00:41:46.000Z ##

CISA Issues Alert on Actively Exploited Vulnerability in Ubiquiti UniFi OS #internet #cybersecurity

CISA warns of actively exploited vulnerabilities in Ubiquiti UniFi OS. The alert highlights CVE-2026-34908 (critical access control flaw) and related CVEs 34909 and 34910, with remediation guidance and BOD 26-04 deadlines. Read the full analysis and required mitigations here: ift.tt/6eMqVP4

Source: ift.tt/6eMqVP4 | Image: ift.tt/0lLnI6S

##

offseq@infosec.exchange at 2026-06-24T13:30:30.000Z ##

CRITICAL UniFi OS vulnerabilities (CVE-2026-34908/09/10) allow remote, unauthenticated attackers to bypass auth and execute commands (pre-5.0.8). Exploited in the wild. Patch ASAP: radar.offseq.com/threat/critic #OffSeq #infosec #Ubiquiti #vulnerability

##

beyondmachines1@infosec.exchange at 2026-06-24T13:01:42.000Z ##

CISA Repoers Active Exploitation of Three Critical Ubiquiti UniFi OS Vulnerabilities

CISA added three critical Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910) to its Known Exploited Vulnerabilities Catalog due to active exploitation. These flaws allow unauthenticated attackers to gain full control over network gateways and consoles through command injection and improper access controls.

**Now this advisory is urgent, since the flaws are actively exploited. Make sure all your UniFi devices (UDM, UNVR, UCG gateways, Cloud Keys, etc.) are isolated from the internet and accessible only from trusted networks. Immediately update UniFi OS to the latest patched version for your model (5.1.12+ for most hardware, 5.0.8 for UniFi OS Server, 4.0.14 for Express).**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

AAKL@infosec.exchange at 2026-06-23T19:03:54.000Z ##

CISA has updated the KEV catalogue:

- CVE-2026-34908: Ubiquiti UniFi OS Improper Access Control Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34909: Ubiquiti UniFi OS Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34910: Ubiquiti UniFi OS Improper Input Validation Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2025-67038:
Lantronix EDS5000 Code Injection Vulnerability cve.org/CVERecord?id=CVE-2025- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-06-23T19:00:51.000Z ##

🚨 [CISA-2026:0623] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-67038 (secdb.nttzen.cloud/cve/detail/)
- Name: Lantronix EDS5000 Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Lantronix
- Product: EDS5000
- Notes: ltrxdev.atlassian.net/wiki/spa ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34908 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34909 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34910 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260623 #cisa20260623 #cve_2025_67038 #cve_2026_34908 #cve_2026_34909 #cve_2026_34910 #cve202567038 #cve202634908 #cve202634909 #cve202634910

##

cisakevtracker@mastodon.social at 2026-06-23T18:01:34.000Z ##

CVE ID: CVE-2026-34908
Vendor: Ubiquiti
Product: UniFi OS
Date Added: 2026-06-23
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-34910
(10.0 CRITICAL)

EPSS: 78.55%

updated 2026-06-24T14:49:47.237000

4 posts

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

Nuclei template

beyondmachines1@infosec.exchange at 2026-06-24T13:01:42.000Z ##

CISA Repoers Active Exploitation of Three Critical Ubiquiti UniFi OS Vulnerabilities

CISA added three critical Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910) to its Known Exploited Vulnerabilities Catalog due to active exploitation. These flaws allow unauthenticated attackers to gain full control over network gateways and consoles through command injection and improper access controls.

**Now this advisory is urgent, since the flaws are actively exploited. Make sure all your UniFi devices (UDM, UNVR, UCG gateways, Cloud Keys, etc.) are isolated from the internet and accessible only from trusted networks. Immediately update UniFi OS to the latest patched version for your model (5.1.12+ for most hardware, 5.0.8 for UniFi OS Server, 4.0.14 for Express).**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

AAKL@infosec.exchange at 2026-06-23T19:03:54.000Z ##

CISA has updated the KEV catalogue:

- CVE-2026-34908: Ubiquiti UniFi OS Improper Access Control Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34909: Ubiquiti UniFi OS Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34910: Ubiquiti UniFi OS Improper Input Validation Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2025-67038:
Lantronix EDS5000 Code Injection Vulnerability cve.org/CVERecord?id=CVE-2025- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-06-23T19:00:51.000Z ##

🚨 [CISA-2026:0623] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-67038 (secdb.nttzen.cloud/cve/detail/)
- Name: Lantronix EDS5000 Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Lantronix
- Product: EDS5000
- Notes: ltrxdev.atlassian.net/wiki/spa ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34908 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34909 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34910 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260623 #cisa20260623 #cve_2025_67038 #cve_2026_34908 #cve_2026_34909 #cve_2026_34910 #cve202567038 #cve202634908 #cve202634909 #cve202634910

##

cisakevtracker@mastodon.social at 2026-06-23T18:01:01.000Z ##

CVE ID: CVE-2026-34910
Vendor: Ubiquiti
Product: UniFi OS
Date Added: 2026-06-23
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-12416
(9.8 CRITICAL)

EPSS: 0.36%

updated 2026-06-24T09:30:46

1 posts

The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invoice_change_password()` function being registered as a nopriv AJAX handler with no nonce verification and no authorization check, and performing a loose equality comparison between the supplied `reset_activation_code` POST parame

2 repos

https://github.com/xxconi/CVE-2026-12415-or-CVE-2026-12416.py

https://github.com/Nxploited/CVE-2026-12416-CVE-2026-12417

offseq@infosec.exchange at 2026-06-24T09:00:32.000Z ##

CRITICAL (CVSS 9.8): CVE-2026-12416 impacts pravel Invoice Generator ≤1.0.0. Weak password reset lets unauthenticated attackers reset any user’s password, including admins. Restrict access or disable plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE #infosec

##

CVE-2026-12850
(9.1 CRITICAL)

EPSS: 1.72%

updated 2026-06-24T06:31:51

1 posts

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various servi

offseq@infosec.exchange at 2026-06-24T12:00:28.000Z ##

CVE-2026-12850: CRITICAL OS command injection in GeoVision GV-I/O Box 4E v2.09 via libNetSetObj.so allows remote code execution. No patch — restrict access to DVRSearch & Network.cgi. Details: radar.offseq.com/threat/cve-20 #OffSeq #ICS #infosec #vulnerability

##

CVE-2025-52465
(7.2 HIGH)

EPSS: 0.35%

updated 2026-06-24T05:17:25.543000

1 posts

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a vulnerability exists that allows an authenticated administrator with access to GeoServer's security system to pass arbitrary file names to the Master Password Dump web page and create files containing the master password in plaintext. The provided file name must be an abso

CVE-2026-11807
(9.6 CRITICAL)

EPSS: 0.36%

updated 2026-06-24T03:31:40

1 posts

A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send a forged message with an arbitrary activation_id to receive plaintext credentials associated with that activation, including OAuth tokens, vault passwords, and SSH

offseq@infosec.exchange at 2026-06-24T00:00:36.000Z ##

CVE-2026-11807 (CRITICAL, CVSS 9.6) affects Red Hat Ansible Automation Platform 2.5: missing authorization in EDA websocket API lets any authenticated user access plaintext credentials. Patch immediately. radar.offseq.com/threat/cve-20 #OffSeq #RedHat #Ansible #Vuln

##

CVE-2026-44914
(7.2 HIGH)

EPSS: 0.39%

updated 2026-06-23T21:31:29

1 posts

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework authorization did not check restricted status when handling requests to replace Process Groups. The missing authorization pe

offseq@infosec.exchange at 2026-06-22T09:00:27.000Z ##

CVE-2026-44914: HIGH severity in Apache NiFi (1.12.0 – 2.9.0). Missing authorization lets users with write access add restricted components. Upgrade to 2.9.0 or enforce specific controls. radar.offseq.com/threat/cve-20 #OffSeq #NiFi #Vuln #Infosec

##

CVE-2026-12958
(7.8 HIGH)

EPSS: 0.14%

updated 2026-06-23T19:36:18.347000

1 posts

Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary. To remediate this issue, users should upgrade to version 1.69.0 or higher.

awssecurityfeed@infosec.exchange at 2026-06-23T16:30:01.000Z ##

CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins

Bulletin ID: 2026-047-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/23/2026 09:30 AM PDT
Description:
Language Servers for AWS provide the underlying language-server runtime that powers Amazon ...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-34909
(10.0 CRITICAL)

EPSS: 2.27%

updated 2026-06-23T18:34:16

4 posts

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

beyondmachines1@infosec.exchange at 2026-06-24T13:01:42.000Z ##

CISA Repoers Active Exploitation of Three Critical Ubiquiti UniFi OS Vulnerabilities

CISA added three critical Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910) to its Known Exploited Vulnerabilities Catalog due to active exploitation. These flaws allow unauthenticated attackers to gain full control over network gateways and consoles through command injection and improper access controls.

**Now this advisory is urgent, since the flaws are actively exploited. Make sure all your UniFi devices (UDM, UNVR, UCG gateways, Cloud Keys, etc.) are isolated from the internet and accessible only from trusted networks. Immediately update UniFi OS to the latest patched version for your model (5.1.12+ for most hardware, 5.0.8 for UniFi OS Server, 4.0.14 for Express).**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

AAKL@infosec.exchange at 2026-06-23T19:03:54.000Z ##

CISA has updated the KEV catalogue:

- CVE-2026-34908: Ubiquiti UniFi OS Improper Access Control Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34909: Ubiquiti UniFi OS Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34910: Ubiquiti UniFi OS Improper Input Validation Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2025-67038:
Lantronix EDS5000 Code Injection Vulnerability cve.org/CVERecord?id=CVE-2025- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-06-23T19:00:51.000Z ##

🚨 [CISA-2026:0623] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-67038 (secdb.nttzen.cloud/cve/detail/)
- Name: Lantronix EDS5000 Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Lantronix
- Product: EDS5000
- Notes: ltrxdev.atlassian.net/wiki/spa ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34908 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34909 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34910 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260623 #cisa20260623 #cve_2025_67038 #cve_2026_34908 #cve_2026_34909 #cve_2026_34910 #cve202567038 #cve202634908 #cve202634909 #cve202634910

##

cisakevtracker@mastodon.social at 2026-06-23T18:01:17.000Z ##

CVE ID: CVE-2026-34909
Vendor: Ubiquiti
Product: UniFi OS
Date Added: 2026-06-23
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2025-67038
(9.8 CRITICAL)

EPSS: 1.13%

updated 2026-06-23T18:31:31

7 posts

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

1 repos

https://github.com/HORKimhab/CVE-2025-67038

darses@mastodon.nl at 2026-06-26T17:49:52.000Z ##

If you have any LuCI-based #Lantronix Serial-to-Ethernet device exposed on the internet, then you may want to kickoff your incident response plan.

My suspicion is that the unauthenticated Remote Code Execution vulnerability CVE-2025-67038 affects a lot more device types than just the EDS5000 that is mentioned in the advisory.

The vulnerable code path is in a modified OpenWRT LuCI RPC module that puts a user-controlled variable inside a Lua `os.execute` call. This vulnerable code is contained in a lot of device firmware versions released in or after 2023. Unfortunately, I do not have the devices to actually test exploitability. My analysis is based purely on patch diffing and grepping publicly released firmware versions. The incomplete list of device types that contain the vulnerable code: EDS5000, G520, G526, G526RP, G527, G528, X300, X300-WiFi, X303, X304. I also suspect E210 is on the incomplete list of vulnerable devices.

Back in April this vulnerability was published by Forescout as part of their BRIDGE:BREAK report on Serial-to-Ethernet adapters. Two days ago this vulnerability was added to the CISA KEV Catalog. Yesterday Forescout published a blogpost they first observed exploitation attempts on the 5th of April 2026. Attacks are attributed to a new cluster Chaya_006. It is unclear if Lantronix took the effort to check if any of their other devices are vulnerable given that they contain the same RPC module.

You want to look for POST requests to `/cgi-bin/luci/rpc/auth` in your logs. Forescout has a number 3 octet IP addresses as Indicator of Compromise here: forescout.com/blog/analyzing-a . The running theory is that these are supposed to be /24 CIDR ranges.

@Secure_ICS_OT
@cisacyber

#vulnerability #cybersecurity #ics #CVE202567038

##

darses@mastodon.nl at 2026-06-26T17:49:52.000Z ##

If you have any LuCI-based #Lantronix Serial-to-Ethernet device exposed on the internet, then you may want to kickoff your incident response plan.

My suspicion is that the unauthenticated Remote Code Execution vulnerability CVE-2025-67038 affects a lot more device types than just the EDS5000 that is mentioned in the advisory.

The vulnerable code path is in a modified OpenWRT LuCI RPC module that puts a user-controlled variable inside a Lua `os.execute` call. This vulnerable code is contained in a lot of device firmware versions released in or after 2023. Unfortunately, I do not have the devices to actually test exploitability. My analysis is based purely on patch diffing and grepping publicly released firmware versions. The incomplete list of device types that contain the vulnerable code: EDS5000, G520, G526, G526RP, G527, G528, X300, X300-WiFi, X303, X304. I also suspect E210 is on the incomplete list of vulnerable devices.

Back in April this vulnerability was published by Forescout as part of their BRIDGE:BREAK report on Serial-to-Ethernet adapters. Two days ago this vulnerability was added to the CISA KEV Catalog. Yesterday Forescout published a blogpost they first observed exploitation attempts on the 5th of April 2026. Attacks are attributed to a new cluster Chaya_006. It is unclear if Lantronix took the effort to check if any of their other devices are vulnerable given that they contain the same RPC module.

You want to look for POST requests to `/cgi-bin/luci/rpc/auth` in your logs. Forescout has a number 3 octet IP addresses as Indicator of Compromise here: forescout.com/blog/analyzing-a . The running theory is that these are supposed to be /24 CIDR ranges.

@Secure_ICS_OT
@cisacyber

#vulnerability #cybersecurity #ics #CVE202567038

##

beyondmachines1@infosec.exchange at 2026-06-24T20:01:42.000Z ##

CISA Reports Active Exploitation of Lantronix Flaws

CISA flagged an actively exploited critical flaw (CVE-2025-67038) in Lantronix EDS5000 v2.1.0.0R3 devices: an unauthenticated OS command injection in the HTTP RPC module that lets attackers gain root access and fully compromise the equipment.

**Make sure all Lantronix EDS5000 devices are isolated from the internet and accessible only from trusted networks, since this flaw lets attackers gain full root control without any login. Check your inventory for version 2.1.0.0R3, apply the latest firmware update from Lantronix, and because attackers can survive patches by creating rogue admin accounts, audit for unknown accounts and rotate any stored secrets after patching.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

thecybermind@infosec.exchange at 2026-06-24T18:30:10.000Z ##

For the Boardroom: A critical unauthenticated code injection flaw (CVE-2025-67038) in Lantronix EDS5000 servers is under active exploitation. Read the full C-SUITE threat advisory on mitigating this operational risk. Ping the word 'ok' mike@thecybermind.co to upgrade your intel. thecybermind.co/jpul
#CyberSec #RiskManagement

##

AAKL@infosec.exchange at 2026-06-23T19:03:54.000Z ##

CISA has updated the KEV catalogue:

- CVE-2026-34908: Ubiquiti UniFi OS Improper Access Control Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34909: Ubiquiti UniFi OS Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34910: Ubiquiti UniFi OS Improper Input Validation Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2025-67038:
Lantronix EDS5000 Code Injection Vulnerability cve.org/CVERecord?id=CVE-2025- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-06-23T19:00:51.000Z ##

🚨 [CISA-2026:0623] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-67038 (secdb.nttzen.cloud/cve/detail/)
- Name: Lantronix EDS5000 Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Lantronix
- Product: EDS5000
- Notes: ltrxdev.atlassian.net/wiki/spa ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34908 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34909 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34910 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260623 #cisa20260623 #cve_2025_67038 #cve_2026_34908 #cve_2026_34909 #cve_2026_34910 #cve202567038 #cve202634908 #cve202634909 #cve202634910

##

cisakevtracker@mastodon.social at 2026-06-23T18:00:45.000Z ##

CVE ID: CVE-2025-67038
Vendor: Lantronix
Product: EDS5000
Date Added: 2026-06-23
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-28496
(0 None)

EPSS: 1.89%

updated 2026-06-23T16:16:59.350000

1 posts

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template Injection (SSTI) vulnerability in the template rendering system. Administrators with access to features that render Twig templates (email templates, mass mail campaigns, custom payment adapters, and the `string_render` API endpoint) can inject arbitrary Twig expressions, lea

Nuclei template

AAKL@infosec.exchange at 2026-06-23T18:20:05.000Z ##

New.

"Today VulnCheck is disclosing CVE-2026-28496, an unauthenticated remote code execution chain in FOSSBilling, the open-source billing and client-management platform."

VulnCheck: CVE-2026-28496 - FOSSBilling Auth Bypass and Twig SSTI to Unauthenticated RCE vulncheck.com/blog/fossbilling @vulncheck #infosec #opensource #vulnerability

##

CVE-2026-49494
(7.5 HIGH)

EPSS: 0.54%

updated 2026-06-23T15:33:40

1 posts

Comodo Internet Security's firewall driver Inspect.sys contains an integer underflow in its IPv6 packet parser. The parser decrements an unsigned 64-bit payload-length value (taken from the IPv6 fixed header's payload length field) by the size of each IPv6 extension header without validating it, so a packet whose declared payload length is smaller than the sum of its extension-header lengths under

malwaretech@infosec.exchange at 2026-06-25T20:07:45.000Z ##

I think it’s hilarious that I now have my first CVE because I got annoyed with an unresponsive vendor and just posted the zero day exploit I was trying to report to them on my GitHub 😆

nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-56394
(6.5 MEDIUM)

EPSS: 0.34%

updated 2026-06-23T14:17:24.290000

1 posts

Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can bypass extension validation by passing traversal sequences that resolve to existing SVG files, allowing local file read access.

offseq@infosec.exchange at 2026-06-22T01:30:27.000Z ##

CVE-2026-56394: HIGH severity path traversal in Craft CMS 4.0.0-RC1 & 5.0.0-RC1. Authenticated attackers can read local files via assets/icon endpoint. Restrict access & monitor activity. No patch yet. radar.offseq.com/threat/cve-20 #OffSeq #CraftCMS #Vuln #PathTraversal

##

CVE-2026-10521
(7.2 HIGH)

EPSS: 0.31%

updated 2026-06-23T09:32:28

3 posts

An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters. This can result in a total loss of confidentiality, integrity and availability.

offseq@infosec.exchange at 2026-06-23T12:00:37.000Z ##

CVE-2026-10521 (HIGH, CVSS 8.6) in mbCONNECT24: Remote attackers with high privileges can access hidden configs, risking full system compromise. No patch yet — restrict access & monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #ICS #Security

##

certvde@infosec.exchange at 2026-06-23T07:45:42.000Z ##

#OT #Advisory VDE-2026-070
Helmholz: Authenticated unintended access to critical program parameters in myREX24V2/myREX24V2.virtual

There is a vulnerability in myREX24V2/myREX24V2.virtual that allows an authenticated remote attacker to access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters.
#CVE CVE-2026-10521

certvde.com/en/advisories/vde-

#CSAF helmholz.csaf-tp.certvde.com/.

##

certvde@infosec.exchange at 2026-06-23T07:36:27.000Z ##

#OT #Advisory VDE-2026-068
MB connect line: Authenticated unintended access to critical program parameters in mbCONNECT24/mymbCONNECT24

There is a vulnerability in mbCONNECT24/mymbCONNECT24 that allows an authenticated remote attacker to access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters.
#CVE CVE-2026-10521

certvde.com/en/advisories/vde-

#CSAF mbconnectline.csaf-tp.certvde.

##

CVE-2026-12866
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-06-23T06:30:41

1 posts

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code w

offseq@infosec.exchange at 2026-06-23T06:00:27.000Z ##

CVE-2026-12866 | CRITICAL severity in expr-eval (all versions): Arbitrary code execution via toJSFunction() API. No patch yet — avoid untrusted input. Risk: full app compromise. Details: radar.offseq.com/threat/cve-20 #OffSeq #infosec #security #CVE202612866

##

CVE-2026-6645
(0 None)

EPSS: 0.14%

updated 2026-06-23T05:17:05.117000

1 posts

An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system utility using an unqualified file reference. Because the application does not specify an absolute pa

offseq@infosec.exchange at 2026-06-22T04:30:24.000Z ##

CVE-2026-6645 (HIGH, CVSS 7.3) affects PaperCut Print Deploy for Windows. Insecure search path in pc-printer-updater.exe lets local attackers execute malicious code as SYSTEM. Audit directories & monitor for suspicious files. radar.offseq.com/threat/cve-20 #OffSeq #CVE20266645 #infosec

##

CVE-2026-11833(CVSS UNKNOWN)

EPSS: 0.22%

updated 2026-06-23T03:31:48

1 posts

Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing the CI Server setting information. This information could be exploited by an attacker for other attacks. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04 CI Server (All packages) R1.01 to R1.04

offseq@infosec.exchange at 2026-06-23T03:00:29.000Z ##

Yokogawa FAST/TOOLS & CI Server (R9.01 – R10.04, R1.01 – R1.04) affected by HIGH severity CVE-2026-11833 (CVSS 8.2): config data sent in cleartext 🛡️. Limit access, monitor advisories. radar.offseq.com/threat/cve-20 #OffSeq #ICS #Vuln #Cybersecurity

##

CVE-2026-12581
(7.5 HIGH)

EPSS: 0.30%

updated 2026-06-22T20:17:59.447000

1 posts

EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in.

offseq@infosec.exchange at 2026-06-22T12:00:27.000Z ##

CVE-2026-12581 (HIGH): Digiwin EasyFlow .NET is exposed to session fixation — attackers can hijack user sessions after login. No patch yet; apply session controls & monitor activity. Details: radar.offseq.com/threat/cve-20 #OffSeq #vulnerability #infosec #security

##

CVE-2026-7166
(0 None)

EPSS: 0.38%

updated 2026-06-22T19:45:16.537000

1 posts

Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and phone number data from the ‘email’ and ‘telefon’ fields. This vulnerability is also present in the local database, as it contains accessible sensitive information such as data on minors and municipal users. Successful exploitation of this vulnerability could allow an unauthenticat

offseq@infosec.exchange at 2026-06-22T19:30:11.000Z ##

Gaudire Assassin game hit by CRITICAL vuln (CVE-2026-7166, CVSS 9.2): API & DB leak emails, phone numbers, and sensitive user info (including minors). No auth needed. Restrict access & monitor for fixes. radar.offseq.com/threat/cve-20 #OffSeq #CVE20267166 #infosec #dataleak

##

CVE-2022-50972
(9.8 CRITICAL)

EPSS: 0.63%

updated 2026-06-22T18:40:05.833000

1 posts

WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send requests to the class-wc-meta-box-product-images.php endpoint with unsanitized product-type values to write malicious PHP files to the web root.

wpguyuk@infosec.exchange at 2026-06-23T07:04:29.000Z ##

If your WooCommerce store is running below version 7.1.0, I'd update it today. CVE-2022-50972 carries a CVSS score of 9.8 out of 10 — meaning an attacker can gain full admin control, access every customer record, and wipe your database entirely. No patch exists for older versions. Updating is the only viable option right now.

#WordPress #WooCommerce #SecurityHardening #CVE #WordPressSecurity

wpguy.uk/blog/critical-vulnera

##

CVE-2026-8157
(8.8 HIGH)

EPSS: 0.24%

updated 2026-06-22T18:38:02.507000

1 posts

The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a custom Vitepos WordPress plugin before 3.4.2 role to escalate privileges to administrator.

offseq@infosec.exchange at 2026-06-22T07:30:32.000Z ##

Vitepos WordPress plugin <3.4.2 has a HIGH severity privilege escalation vuln (CVE-2026-8157). Auth users with custom Vitepos roles can become admins via REST API. Restrict API access & monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE20268157 #Infosec

##

CVE-2026-10789
(9.6 CRITICAL)

EPSS: 0.29%

updated 2026-06-22T18:34:24

1 posts

A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user.

offseq@infosec.exchange at 2026-06-22T18:00:12.000Z ##

CVE-2026-10789: CRITICAL code injection in Autodesk Fusion MCP ext (v2703.1.11). Visiting a crafted page can lead to arbitrary code execution with user rights. Update guidance pending. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Autodesk #CVE2026_10789

##

CVE-2026-7664
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-06-22T18:34:23

1 posts

IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

offseq@infosec.exchange at 2026-06-22T16:30:14.000Z ##

CVE-2026-7664 (CRITICAL, CVSS 9.8): IBM Langflow OSS 1.0.0 – 1.8.4 has an improper auth flaw in MCP endpoint, allowing unauthenticated access to protected resources. Patch status unknown — monitor IBM advisories. radar.offseq.com/threat/cve-20 #OffSeq #CVE #IBM #infosec

##

CVE-2026-41950
(6.5 MEDIUM)

EPSS: 0.33%

updated 2026-06-22T18:34:02

1 posts

Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same tenant by supplying an arbitrary file UUID in the files array of a chat-messages request. Attackers can exploit insufficient permission verification in the chat-messages endpoints to access files without ownership valid

threatnoir@infosec.exchange at 2026-06-24T21:05:19.000Z ##

⚠️ CRITICAL: Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

Four critical vulnerabilities in Dify AI platform (CVE-2026-41947, CVE-2026-41948, CVE-2026-41950) enable unauthorized access to private chats, cross-tenant document theft, and lateral API calls across multi-tenant environments. The platform powers 1 million applications, making this a widespread s…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-41948
(7.7 HIGH)

EPSS: 0.51%

updated 2026-06-22T18:34:01

1 posts

Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant path using unencoded dot sequences in task identifiers or manipulated filename parameters to access internal endpoints su

threatnoir@infosec.exchange at 2026-06-24T21:05:19.000Z ##

⚠️ CRITICAL: Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

Four critical vulnerabilities in Dify AI platform (CVE-2026-41947, CVE-2026-41948, CVE-2026-41950) enable unauthorized access to private chats, cross-tenant document theft, and lateral API calls across multi-tenant environments. The platform powers 1 million applications, making this a widespread s…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-41947
(7.4 HIGH)

EPSS: 0.45%

updated 2026-06-22T18:34:00

1 posts

Dify version 1.14.1 and prior contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant ownership. Attackers can exploit missing tenant ownership checks in the trace configuration endpoints to redirect all messages and responses from victim applications to attacker-controlled LLM trace provi

threatnoir@infosec.exchange at 2026-06-24T21:05:19.000Z ##

⚠️ CRITICAL: Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

Four critical vulnerabilities in Dify AI platform (CVE-2026-41947, CVE-2026-41948, CVE-2026-41950) enable unauthorized access to private chats, cross-tenant document theft, and lateral API calls across multi-tenant environments. The platform powers 1 million applications, making this a widespread s…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-56448(CVSS UNKNOWN)

EPSS: 0.29%

updated 2026-06-22T15:30:52

1 posts

A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticated AIL user can supply crafted object identifiers through the investigation workflow to cause file paths to resolve outside the intended image, favicon, or screenshot storage directories. This may allow the attacker to download and read arbitrary files

offseq@infosec.exchange at 2026-06-22T13:30:29.000Z ##

CVE-2026-56448 (HIGH, CVSS 8.3) in ail framework v0: Authenticated users can exploit path traversal to access files beyond intended dirs. Restrict permissions & monitor file access until patch is released. radar.offseq.com/threat/cve-20 #OffSeq #CyberSecurity #Vuln #PathTraversal

##

CVE-2026-12806
(8.8 HIGH)

EPSS: 0.46%

updated 2026-06-21T21:31:04

1 posts

A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component POST Request Handler. The manipulation of the argument selSSID leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early ab

offseq@infosec.exchange at 2026-06-22T00:00:37.000Z ##

CVE-2026-12806: HIGH severity buffer overflow in Edimax BR-6478AC V2 (fw 1.23). Remote exploitation possible, no patch available. Limit access & watch for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #RouterSecurity #Infosec

##

CVE-2026-56382
(7.2 HIGH)

EPSS: 0.49%

updated 2026-06-21T15:31:31

1 posts

Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability in the FieldsController::actionRenderCardPreview() method, which passes the fieldLayoutConfig POST parameter directly to Fields::createLayout() without calling Component::cleanseConfig(). An authenticated admin user can inject Yii2 event handlers (e.g., 'on init' keys) via the fi

offseq@infosec.exchange at 2026-06-22T03:00:24.000Z ##

CVE-2026-56382: HIGH severity RCE in Craft CMS (5.5.0 – 5.9.13). Authenticated admins can inject code via FieldsController, leaking sensitive env vars. Patch now by upgrading to 5.9.14+. radar.offseq.com/threat/cve-20 #OffSeq #CraftCMS #RCE #Vuln

##

CVE-2026-54317
(7.6 HIGH)

EPSS: 0.19%

updated 2026-06-19T19:35:48

1 posts

### Summary The Konnected integration registers an HTTP endpoint, `KonnectedView` (`homeassistant/components/konnected/__init__.py`), that is marked as **not requiring authentication** (`requires_auth = False`). A comment next to that line says auth is instead handled "via the access token from configuration." That promise is only half true: - **Write requests (POST and PUT)** are handled by `u

hugovalters@mastodon.social at 2026-06-24T12:14:14.000Z ##

CVE-2026-54317 - Authentication Bypass in Home Assistant. Konnected integration exposes an unauthenticated HTTP endpoint allowing unauthorized write requests. CVSS 7.6. Update to 2026.6.0 immediately. #CVE #HomeAssistant #infosec

valtersit.com/cve/CVE-2026-543

##

CVE-2026-46331(CVSS UNKNOWN)

EPSS: 0.29%

updated 2026-06-19T15:33:15

3 posts

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd. Fix by moving skb

3 repos

https://github.com/HORKimhab/CVE-2026-46331

https://github.com/sgkdev/packet_edit_meme

https://github.com/0xBlackash/CVE-2026-46331

guru@thecybersecguru.com at 2026-06-26T17:40:04.000Z ##

Two new Linux LPEs hit page cache from opposite ends of the kernel

Two new Linux kernel LPEs, CVE-2026-46331 (pedit COW) and CVE-2026-43503 (DirtyClone), corrupt page-cache memory to gain root without touching disk. Working exploits are public

thecybersecguru.com/news/linux

##

linux@activitypub.awakari.com at 2026-06-26T13:00:41.000Z ## New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries TheHackerNews CVE-2026-46331 lets local users gain root on affected Linux systems by corrupting page-cache memory throug...

#Security #News

Origin | Interest | Match ##

guru@thecybersecguru.com at 2026-06-26T17:40:04.000Z ##

Two new Linux LPEs hit page cache from opposite ends of the kernel

Two new Linux kernel LPEs, CVE-2026-46331 (pedit COW) and CVE-2026-43503 (DirtyClone), corrupt page-cache memory to gain root without touching disk. Working exploits are public

thecybersecguru.com/news/linux

##

CVE-2026-11409
(7.2 HIGH)

EPSS: 2.79%

updated 2026-06-18T21:33:34

1 posts

An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-11410
(7.2 HIGH)

EPSS: 2.79%

updated 2026-06-18T21:33:34

1 posts

An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-56022
(5.3 MEDIUM)

EPSS: 0.31%

updated 2026-06-18T18:35:31

1 posts

Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.641.

beyondmachines1@infosec.exchange at 2026-06-25T12:01:31.000Z ##

Webmin 2.641 Patches Root Takeover and 2FA Bypass Vulnerabilities

Webmin version 2.641 addresses multiple critical vulnerabilities, including a root-level stored XSS (CVE-2026-22678), a path traversal file overwrite (CVE-2026-49103), and a 2FA bypass (CVE-2026-56022). These flaws allow low-privileged users to compromise root accounts and bypass multi-factor authentication in multi-tenant hosting environments.

**Update your Webmin instances to version 2.641 immediately to prevent low-privileged users from taking over your root account. If you cannot patch today, restrict access to the mail and notification modules to only your most trusted administrators.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-8461
(8.8 HIGH)

EPSS: 0.39%

updated 2026-06-18T15:32:09

18 posts

An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpeg before version 8.1.2.

4 repos

https://github.com/Y5neKO/CVE-2026-8461-EXP

https://github.com/HORKimhab/CVE-2026-8461

https://github.com/0xBlackash/CVE-2026-8461

https://github.com/anyanything/CVE-2026-8461-PoC

ottoto2017@prattohome.com at 2026-06-26T00:26:53.000Z ##

#Mastodon v4.6.2 へ #update した。

CVE-2026-8461へのセキュリティ対応。

git fetch && git checkout v4.6.2
だけで完了。

#prattohome #更新

##

xeiaso.net@bsky.brid.gy at 2026-06-25T22:11:38.191Z ##

"No way to prevent this" say users of only language where this regularly happens

https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-8461/

"No way to prevent this" say u...

##

cadey@pony.social at 2026-06-25T22:11:38.000Z ##

"No way to prevent this" say users of only language where this regularly happens

xeiaso.net/shitposts/no-way-to

##

null@puddle.town at 2026-06-25T18:29:09.000Z ##

I built FFmpeg 7.1.5 from source since Ubuntu is moving slowly on CVE-2026-8461, and leaving a Mastodon server that processes untrusted media all day long unpatched seems like a bad idea. So anyway, testing with a #Goose post.

##

apz@some.apz.fi at 2026-06-25T17:45:39.000Z ##

Looks like #ffmpeg leaks (CVE-2026-8461), #mastodon Docker images have all been updated with a fixed version.

#infosec #vulnerability

##

jenbanim@mastodo.neoliber.al at 2026-06-25T16:32:33.000Z ##

#Sysadmin #Infosec #MastoAdmin am I reading correctly that Ubuntu is still triaging the lastest FFMPEG vulnerability and hasn't released a fix?

Running 24.04 LTS and I don't wanna get pwned

ubuntu.com/security/CVE-2026-8

#ffmpeg

##

adamhotep@infosec.exchange at 2026-06-25T14:25:54.000Z ##

RE: social.coop/@cwebber/116810673

Every once in a while, we observe flaws in media players that allow exploits to be delivered by video files. These files often get free passes in security gateways.

Fortunately, it doesn't work by default. BleepingComputer wrote:

the RCE exploit requires ASLR (Address Space Layout Randomization) to be disabled, and that CVE-2026-8461 alone does not bypass this memory protection.

In theory, a separate information-disclosure bug in FFmpeg's FlashSV decoder could be chained with PixelSmash to bypass ASLR.

##

vv@solarpunk.moe at 2026-06-25T13:07:51.000Z ##

@cwebber Ubuntu doesn't either: ubuntu.com/security/CVE-2026-8

Does the ubuntu security team need to be briefed on how concerning this issue is?

##

glitch_soc_release_watcher@kodesumber.com at 2026-06-25T11:52:26.000Z ##

v4.6.2

This release is made solely to update FFmpeg in our docker container images to fix CVE-2026-8461 (critical severity). It is critical to update if you use our docker container images. If you are not using our docker container images, please make...

github.com/glitch-soc/mastodon

#glitchsoc #glitch #mastodon #mastoadmin

##

glitch_soc_release_watcher@kodesumber.com at 2026-06-25T11:52:26.000Z ##

v4.5.13

This release is made solely to update FFmpeg in our docker container images to fix CVE-2026-8461 (critical severity). It is critical to update if you use our docker container images. If you are not using our docker container images, please make...

github.com/glitch-soc/mastodon

#glitchsoc #glitch #mastodon #mastoadmin

##

mstdn_release_watcher@kodesumber.com at 2026-06-25T11:35:06.000Z ##

v4.5.13

This release is made solely to update FFmpeg in our docker container images to fix CVE-2026-8461 (critical severity). It is critical to update if you use our docker container images. If you are not using our docker container images, please make...

github.com/mastodon/mastodon/r

#mastodon #mastoadmin

##

mstdn_release_watcher@kodesumber.com at 2026-06-25T11:35:05.000Z ##

v4.6.2

This release is made solely to update FFmpeg in our docker container images to fix CVE-2026-8461 (critical severity). It is critical to update if you use our docker container images. If you are not using our docker container images, please make...

github.com/mastodon/mastodon/r

#mastodon #mastoadmin

##

admin@m.somincola.org at 2026-06-25T10:16:20.000Z ##

🌿 站点更新完成:Mastodon 4.6.2

服务器花园完成了一轮快速修整!Somincola Social 已从 Mastodon 4.6.0 更新至 4.6.2,目前运行正常。🐘

本次更新包括:
• 修复 Emoji、下拉菜单、高级界面、个人资料字段及 LDAP 登录等问题
• 更新 Docker 镜像中的 FFmpeg,修复严重安全漏洞 CVE-2026-8461
• 本站的 5000 字符上限继续保留
大家无需进行额外操作。Tangerine UI 目前宣布停更,暂时移出了服务器花园。希望它在花园外能继续茁壮成长

感谢大家的等待!辛勤的园艺师傅已经扫完落叶,联邦小路继续开放啦。🌿

#SomincolaSocial #Mastodon #站点更新

##

love@jiaojiao.org at 2026-06-25T09:57:28.000Z ##

@mastodon_releases
Mastodon v4.6.2 has been released, fixing critical FFmpeg vulnerability CVE-2026-8461.

Attackers can upload malicious videos to crash the service or execute arbitrary code. High risk.

Please update Mastodon/FFmpeg ASAP. Ensure your FFmpeg version is:
• 8.1.2
• 7.1.5
• 6.1.6
• 5.1.10

nvd.nist.gov/vuln/detail/CVE-2

##

admin@fnordon.de at 2026-06-25T09:43:50.000Z ##

Mastodon 4.6.2
(manchmal kommen sie schnell hintereinander, diesmal wegen CVE-2026-8461)

#Mastoadmin

##

beyondmachines1@infosec.exchange at 2026-06-23T10:01:04.000Z ##

PixelSmash Vulnerability in FFmpeg Enables Remote Code Execution

FFmpeg version 8.1.2 patches a high-severity heap overflow (CVE-2026-8461) in the MagicYUV decoder that allows attackers to execute arbitrary code via malicious video files. The flaw impacts a wide range of media applications, including Jellyfin and Nextcloud.

**Update FFmpeg to version 8.1.2 or later immediately to close the PixelSmash flaw (CVE-2026-8461), and update any apps that bundle it like Jellyfin, Nextcloud, Kodi, or OBS. If you can't update right away, restrict file uploads to trusted users only and isolate any servers that automatically scan or process media files.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

tugatech@masto.pt at 2026-06-23T07:23:13.000Z ##

Foi descoberta uma vulnerabilidade crítica na biblioteca FFmpeg, denominada PixelSmash, que pode permitir a execução remota de código em servidores Jellyfin e causar a negação de serviço em plataformas como Kodi. A falha, identificada como CVE-2026-8461, recebeu uma pontuação de gravidade significativa. 💻

🔗 tugatech.com.pt/t86024-ffmpeg-

#kodi #vulnerabilidade 

##

offseq@infosec.exchange at 2026-06-22T22:30:13.000Z ##

FFmpeg MagicYUV decoder CRITICAL heap out-of-bounds bug (CVE-2026-8461): AVI/MKV/MOV files can trigger DoS or RCE in apps like Jellyfin, Nextcloud. Patch to 8.1.2 ASAP. radar.offseq.com/threat/ffmpeg #OffSeq #FFmpeg #CVE20268461 #infosec

##

CVE-2026-54388
(9.1 CRITICAL)

EPSS: 0.39%

updated 2026-06-17T21:34:45

1 posts

Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing values, forwarding all duplicate headers to the backend while using the first value to determine how many request body bytes to consume. Remote attackers can desynchronize the proxy and backend parser state, allowing injection of arbitrary HTTP requests to the backe

DailyCyberSecurity@infosec.exchange at 2026-06-23T06:49:29.000Z ##

Three critical Tinyproxy request smuggling vulnerabilities, including CVE-2026-54388, expose networks to severe attacks. Update your proxy servers immediately.

#Tinyproxy #RequestSmuggling #CVE202654388 #CVE202655202 #CVE202654387
securityonline.info/tinyproxy-

##

CVE-2026-55199
(5.9 MEDIUM)

EPSS: 0.41%

updated 2026-06-17T21:34:45

1 posts

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop f

beyondmachines1@infosec.exchange at 2026-06-22T09:01:09.000Z ##

libssh2 Vulnerabilities Enable Remote Code Execution and Denial of Service

libssh2 disclosed two vulnerabilities, including a critical out-of-bounds write (CVE-2026-55200) and a high-severity denial of service (CVE-2026-55199), affecting versions up to 1.11.1. These flaws allow malicious servers to execute code on connecting clients or cause resource exhaustion.

**Plan to update libssh2 to a patched build as soon as a fixed release is available. In the meantime audit your tools (curl/libcurl, PHP ssh2 extension, monitoring utilities, IoT firmware) for the vulnerable library versions up to 1.11.1. Only connect to SSH servers you trust and isolate sensitive management interfaces so they're reachable from trusted networks only, since a malicious server can now attack your client.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-42055
(8.1 HIGH)

EPSS: 1.82%

updated 2026-06-17T18:36:07

1 posts

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attack

1 repos

https://github.com/HORKimhab/CVE-2026-42055

hackmag@infosec.exchange at 2026-06-22T04:30:02.000Z ##

⚪️ NGINX Patches Two Critical RCE Vulnerabilities

🗨️ F5 developers have released out-of-band patches for two critical issues in NGINX that, under certain conditions, allowed remote execution of arbitrary code. The vulnerabilities have been assigned identifiers CVE-2026-42530 and CVE-2026-42055, and each received a CVSS score of 9.2. They…

🔗 hackmag.com/news/two-nginx-rce

#news

##

CVE-2026-42530
(8.1 HIGH)

EPSS: 2.39%

updated 2026-06-17T18:36:07

1 posts

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers

3 repos

https://github.com/HORKimhab/CVE-2026-42530

https://github.com/v4ltonn/CVE-2026-42530

https://github.com/0xBlackash/CVE-2026-42530

hackmag@infosec.exchange at 2026-06-22T04:30:02.000Z ##

⚪️ NGINX Patches Two Critical RCE Vulnerabilities

🗨️ F5 developers have released out-of-band patches for two critical issues in NGINX that, under certain conditions, allowed remote execution of arbitrary code. The vulnerabilities have been assigned identifiers CVE-2026-42530 and CVE-2026-42055, and each received a CVSS score of 9.2. They…

🔗 hackmag.com/news/two-nginx-rce

#news

##

CVE-2026-53876
(7.2 HIGH)

EPSS: 1.79%

updated 2026-06-17T16:18:00.113000

1 posts

RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary command execution with the root privilege by a user who logs in to the web console as an administrator.

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-50871
(9.8 CRITICAL)

EPSS: 1.57%

updated 2026-06-17T10:57:46.930000

1 posts

An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input.

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-45504
(8.8 HIGH)

EPSS: 0.46%

updated 2026-06-17T10:52:10.200000

1 posts

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

1 repos

https://github.com/hawktrace/CVE-2026-45504

obivan@infosec.exchange at 2026-06-24T18:49:48.000Z ##

CVE-2026-45504 Microsoft Exchange SSRF via File Read hawktrace.com/blog/CVE-2026-45

##

CVE-2026-34926
(6.7 MEDIUM)

EPSS: 12.68%

updated 2026-06-17T10:39:49.727000

2 posts

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained adminis

1 repos

https://github.com/HORKimhab/CVE-2026-34926

thecybermind at 2026-06-27T02:41:06.236Z ##

CISA confirms active zero-day exploitation of Trend Micro Apex One (CVE-2026-34926), introducing critical directory traversal and code injection risks across the endpoint control plane. Access our full executive advisory on asset mitigation and strategic governance alignment: thecybermind.co/22mw

##

thecybermind@infosec.exchange at 2026-06-27T02:41:06.000Z ##

CISA confirms active zero-day exploitation of Trend Micro Apex One (CVE-2026-34926), introducing critical directory traversal and code injection risks across the endpoint control plane. Access our full executive advisory on asset mitigation and strategic governance alignment: thecybermind.co/22mw

##

CVE-2026-33017
(9.8 CRITICAL)

EPSS: 98.41%

updated 2026-06-17T10:36:47.177000

2 posts

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored f

Nuclei template

11 repos

https://github.com/0xBlackash/CVE-2026-33017

https://github.com/rootdirective-sec/CVE-2026-33017-Lab

https://github.com/MaxMnMl/langflow-CVE-2026-33017-poc

https://github.com/z4yd3/PoC-CVE-2026-33017

https://github.com/omer-efe-curkus/CVE-2026-33017-Langflow-RCE-PoC

https://github.com/r3nsi15/CVE-2026-33017-langflow-rce

https://github.com/SimoesCTT/Sovereign-Echo-33017

https://github.com/Jorrit-VM/CVE-2026-33017

https://github.com/oscar-mine/CVE-2026-33017-Exploit

https://github.com/masterwok/PoC-CVE-2026-33017

https://github.com/EQSTLab/CVE-2026-33017

DailyCyberSecurity at 2026-06-27T01:05:40.879Z ##

Langflow Cryptominer Malware Exploits CVE-2026-33017

At least 39 rival malware families appear on a kill list used by a new Langflow cryptominer malware campaign. Threat actors now target exposed artificial intelligence application endpoints to breach enterprise networks. They exploit CVE-2026-33017, which is a critical remote code execution vulnerability. Consequently, attackers hijack servers to mine cryptocurrency. At a glance Malware Family: Modified KORKERDS/MALXMR variant Threat Actor:

securityonline.info/langflow-c

##

DailyCyberSecurity@infosec.exchange at 2026-06-27T01:05:40.000Z ##

Langflow Cryptominer Malware Exploits CVE-2026-33017

At least 39 rival malware families appear on a kill list used by a new Langflow cryptominer malware campaign. Threat actors now target exposed artificial intelligence application endpoints to breach enterprise networks. They exploit CVE-2026-33017, which is a critical remote code execution vulnerability. Consequently, attackers hijack servers to mine cryptocurrency. At a glance Malware Family: Modified KORKERDS/MALXMR variant Threat Actor:

securityonline.info/langflow-c

##

CVE-2026-22678
(5.4 MEDIUM)

EPSS: 0.17%

updated 2026-06-17T10:20:13.247000

1 posts

Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status module that allows low-privileged authenticated attackers to execute arbitrary JavaScript in the browser context of administrators by injecting unsanitized input stored in save_tmpl.cgi and rendered unescaped in list_tmpls.cgi.

beyondmachines1@infosec.exchange at 2026-06-25T12:01:31.000Z ##

Webmin 2.641 Patches Root Takeover and 2FA Bypass Vulnerabilities

Webmin version 2.641 addresses multiple critical vulnerabilities, including a root-level stored XSS (CVE-2026-22678), a path traversal file overwrite (CVE-2026-49103), and a 2FA bypass (CVE-2026-56022). These flaws allow low-privileged users to compromise root accounts and bypass multi-factor authentication in multi-tenant hosting environments.

**Update your Webmin instances to version 2.641 immediately to prevent low-privileged users from taking over your root account. If you cannot patch today, restrict access to the mail and notification modules to only your most trusted administrators.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-20045
(8.2 HIGH)

EPSS: 4.31%

updated 2026-06-17T10:16:58.097000

1 posts

A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying

1 repos

https://github.com/dkstar11q/Ashwesker-CVE-2026-20045

beyondmachines1@infosec.exchange at 2026-06-25T09:01:30.000Z ##

Active Exploitation of Cisco Unified Communications Manager Vulnerabilities Grants Root Access

Cisco Unified Communications Manager is facing active exploitation of two vulnerabilities, CVE-2026-20230 and CVE-2026-20045, which allow unauthenticated attackers to gain root access and deploy webshells.

**Apply the latest software updates, including Unified CM 14SU6 and 15SU5, immediately. If patching is not possible, disable the Cisco WebDialer Web Service to sever the attack path, and aggressively audit your /platform-services/ directory for unusual .jsp files or unauthorized webshells.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2024-40766
(9.8 CRITICAL)

EPSS: 15.69%

updated 2026-06-17T07:46:30.123000

1 posts

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

sans_isc@infosec.exchange at 2026-06-23T03:05:21.000Z ##

CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration. isc.sans.edu/diary/33094

##

CVE-2013-6786
(0 None)

EPSS: 2.17%

updated 2026-06-17T00:00:56.043000

1 posts

Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the "forbidden author header" protection mechanism is bypassed, allows remote attackers to inject arbitrary web script or HTML by requesting a nonexistent URI in conjunction with a crafted HTTP Referer head

certvde@infosec.exchange at 2026-06-23T07:37:32.000Z ##

#OT #Advisory VDE-2026-071
JUMO: Allegro RomPager webserver vulnerability in JUMO mTRONT, DICON touch, AQUIS touch devices

Multiple products from JUMO are affected by webserver vulnerability "CVE-2013-6786, CVE-2014-9222, CVE-2014-9223. This vulnerability leads to DOS of the device by using a misfortune cookie and reflected XSS attacks.
#CVE CVE-2014-9222, CVE-2013-6786, CVE-2014-9223

certvde.com/en/advisories/vde-

#CSAF jumo.csaf-tp.certvde.com/.well

##

CVE-2026-50874
(8.1 HIGH)

EPSS: 1.12%

updated 2026-06-16T21:33:04

1 posts

An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input.

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-38065
(9.8 CRITICAL)

EPSS: 1.34%

updated 2026-06-16T21:32:59

1 posts

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter.

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-50656
(7.8 HIGH)

EPSS: 3.39%

updated 2026-06-16T21:31:57

1 posts

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;RoguePlanet &quot;. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

1 repos

https://github.com/0xBlackash/CVE-2026-50656

youranonnewsirc@nerdculture.de at 2026-06-22T22:23:57.000Z ##

Geopolitical tensions escalate as US-Iran talks stall amidst renewed Israel-Hezbollah strikes and Trump's Strait of Hormuz threats; Iran reportedly closed the waterway. In technology, Anthropic's Fable 5 AI models remain offline due to a US export ban. Cybersecurity alerts include active exploitation of Microsoft Defender zero-day (CVE-2026-50656), Cisco SD-WAN, and Splunk flaws.

#AnonNews_irc #Cybersecurity #News

##

CVE-2026-53753
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-06-16T20:13:08

1 posts

### Summary The `_safe_eval_expression()` function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore. Python generator and frame object attributes (`gi_frame`, `f_back`, `f_builtins`) do NOT start with underscore, enabling a complete sandbox escape to achieve arbitrary code execution. The attack requires no authentication (JWT disabled by d

offseq@infosec.exchange at 2026-06-24T01:30:27.000Z ##

CVE-2026-53753: CRITICAL code injection in unclecode crawl4ai (<0.8.7). Unauthenticated RCE via /crawl POST request due to insufficient AST validation. Patch to 0.8.7 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202653753 #infosec #vuln

##

CVE-2026-20262
(6.5 MEDIUM)

EPSS: 7.68%

updated 2026-06-15T21:31:39

2 posts

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sen

2 repos

https://github.com/fevar54/CVE-2026-20262-Cisco-Catalyst-SD-WAN-Manager-Arbitrary-File-Write-

https://github.com/HORKimhab/CVE-2026-20262

hackmag@infosec.exchange at 2026-06-22T08:00:04.000Z ##

⚪️ Cisco Patches Zero‑Day Vulnerability in SD‑WAN

🗨️ Cisco specialists have released patches for vulnerability CVE-2026-20262 in Catalyst SD-WAN Manager (formerly SD-WAN vManage). According to the company, the issue has already been exploited in real-world attacks and allowed attackers to escalate privileges to the root level. Since the…

🔗 hackmag.com/news/sd-wan-patch?

#news

##

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-48970
(8.1 HIGH)

EPSS: 0.32%

updated 2026-06-15T21:30:58

1 posts

Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.

wpguyuk@infosec.exchange at 2026-06-22T07:05:50.000Z ##

Really Simple Security below 9.5.10.1 has a high-severity vulnerability (CVE-2026-48970, disclosed 15 June 2026) that requires no admin credentials to exploit. I find it particularly concerning given this plugin exists specifically to harden WordPress security. If your site is running an older version, update it now.

#WordPress #SecurityHardening #WordPressSecurity #CVE #SSL

wpguy.uk/blog/high-vulnerabili

##

CVE-2026-12219
(6.3 MEDIUM)

EPSS: 1.52%

updated 2026-06-15T06:31:46

1 posts

A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is the function mod_diagnose.CommandShellByType of the file /api/diagnosis/start of the component Web FastCGI Service. This manipulation of the argument Time causes command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12223
(5.5 MEDIUM)

EPSS: 1.53%

updated 2026-06-15T06:31:41

1 posts

A vulnerability was identified in Yealink SIP-T46U 108.86.0.118. Affected by this vulnerability is the function mod_webd.TFTPUploadIperf of the file /api/inner/tftpuploadiperf of the component Web FastCGI Service. The manipulation of the argument ip/port leads to command injection. The attack needs to be initiated within the local network. The exploit is publicly available and might be used. The v

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12197
(7.2 HIGH)

EPSS: 2.38%

updated 2026-06-15T00:31:55

1 posts

A security flaw has been discovered in Ruijie EG105G-P 2.340. The impacted element is the function nslookup of the file /cgi-bin/luci/api/diagnose of the component JSON-RPC Diagnose Endpoint. Performing a manipulation of the argument params.target results in command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. T

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-9271
(5.9 MEDIUM)

EPSS: 0.14%

updated 2026-06-12T18:32:55

1 posts

Vulnerability Title

CVE-2026-34182
(9.1 CRITICAL)

EPSS: 0.24%

updated 2026-06-10T18:32:45

1 posts

Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises. Impact Summary: Attackers making use of these vulnerabilities may achieve key-equivalent functionality for a given CMS recipient and/or bypass integrity validation for a given mess

redsakana@infosec.exchange at 2026-06-23T15:44:53.000Z ##

this-is-fine dog of the week (from oss-sec):

blog.calif.io/p/how-to-format- discusses how the issue that OpenSSL disclosed on June 9 as CVE-2026-34182 similarly affected the PKCS#7 / CMS parsing implementations from WolfSSL, Bouncy Castle, & GnuPG.

The common failure is accepting the sender provided length for the authentication tag, and not enforcing the minimum length specified in the RFC - allowing an attacker to specify a one-byte tag length and then use brute force to determine which of the 256 possible values matches the first byte of the actual tag.

##

CVE-2026-25860
(6.1 MEDIUM)

EPSS: 0.29%

updated 2026-06-10T00:31:50

1 posts

OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that allows attackers to execute arbitrary JavaScript in a victim's browser by embedding malicious payloads in DICOM file metadata fields. Attackers can craft a DICOM file with JavaScript payloads in metadata fields such as Study Description, which are reflected without sanitization in

1 repos

https://github.com/partywavesec/CVE-2026-25860

CVE-2026-20245
(7.8 HIGH)

EPSS: 9.92%

updated 2026-06-09T21:32:21

6 posts

A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A su

3 repos

https://github.com/0xBlackash/CVE-2026-20245

https://github.com/HORKimhab/CVE-2026-20245

https://github.com/fevar54/CVE-2026-20245---Cisco-SD-WAN-Privilege-Escalation-Exploit

vitobotta@mastodon.social at 2026-06-26T14:19:36.000Z ##

Cisco SD-WAN zero-day CVE-2026-20245 exploited for two months before disclosure. Mandiant found the traces. Attacker had netadmin access, escalated to root, cleaned up config files. Inside for months.

thehackernews.com/2026/06/cisc

##

DailyCyberSecurity@infosec.exchange at 2026-06-26T12:15:27.000Z ##

Cisco SD-WAN Zero-Day Exploited in Attacks

At a glance Actor: Unknown threat actor Activity Type: Privilege escalation and zero-day exploitation Targets: Service provider infrastructure Scale: Unknown victim count Jurisdiction: Active investigation; no arrests reported Source: Mandiant TL;DR Attackers breached a service provider using a Cisco SD-WAN zero-day flaw. They exploited CVE-2026-20245 to gain root-level control over network systems. Therefore, administrators must upgrade their software immediately to block further intrusions.

securityonline.info/cisco-sd-w

##

oversecurity@mastodon.social at 2026-06-26T08:44:10.000Z ##

CVE-2026-20245 Zero-Day Exploited in Cisco Catalyst SD-WAN Manager to Gain Root Access

A newly disclosed zero-day vulnerability, CVE-2026-20245, has been exploited by a threat actor targeting Cisco Catalyst SD-WAN Manager. By exploiting

🔗️ [Thecyberexpress] link.is.it/YtDctR

##

oversecurity@mastodon.social at 2026-06-24T21:40:06.000Z ##

Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access

New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to...

🔗️ [Bleepingcomputer] link.is.it/gbIA4V

##

AAKL@infosec.exchange at 2026-06-24T15:57:48.000Z ##

New.

Mandiant: Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager cloud.google.com/blog/topics/t #Google

Microsoft:

StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them microsoft.com/en-us/security/b

Kaspersky:

StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader securelist.com/strikeshark-cam @Kaspersky

Symantec: Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker security.com/threat-intelligen

Picus:

The ShinyHunters Domino Effect: One Breach, Hundreds of Victims picussecurity.com/resource/blo

Proofpoint:

StealC You Later: Proofpoint and IBM X-Force Support Operation Endgame Disruptions proofpoint.com/us/blog/threat- #threatresearch #cybercrime #Microsoft #infosec #threatintelligence #Cisco #vulnerability #zeroday #ransomware

##

Mozilla@activitypub.awakari.com at 2026-06-24T14:15:55.000Z ## Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan Introduction to Malware Binary Triage (IMBT) ...

#Malware #News

Origin | Interest | Match ##

CVE-2026-7473
(5.8 MEDIUM)

EPSS: 0.84%

updated 2026-06-09T18:30:34

1 posts

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not ver

1 repos

https://github.com/fevar54/CVE-2026-7473---Arista-EOS-Tunnel-Decapsulation-Bypass

thecybermind@infosec.exchange at 2026-06-23T07:20:31.000Z ##

🚨 New CSUITE Brief: Arista EOS vulnerability CVE-2026-7473 requires immediate executive oversight. Understand the organizational risk and the strategic governance required to protect your infrastructure. Read the full risk assessment here: thecybermind.co/tugq

#CyberSecurity #ExecutiveRisk #AristaEOS

##

CVE-2026-26980
(9.4 CRITICAL)

EPSS: 70.00%

updated 2026-06-08T23:22:35

1 posts

### Impact A SQL injection vulnerability existed in Ghost's Content API that allowed unauthenticated attackers to read arbitrary data from the database. ### Vulnerable Versions This vulnerability is present in Ghost v3.24.0 to v6.19.0. ### Patches v6.19.1 contains a fix for this issue. **Note:** as this vulnerability lets an attacker gain access to a site's API keys, we recommend reviewing

Nuclei template

6 repos

https://github.com/dinosn/ghost-cve-2026-26980

https://github.com/EQSTLab/CVE-2026-26980

https://github.com/vognik/CVE-2026-26980

https://github.com/gagaltotal/CVE-2026-26980-Ghost-CMS-Api

https://github.com/n0bitaemon/CVE-2026-26980-PoC

https://github.com/Kulik-Labs-Development/Ghost-CMS-Code-Injection-Audit-CVE-2026-26980

oversecurity@mastodon.social at 2026-06-23T14:51:51.000Z ##

Ghost Stories: investigating an undocumented ClickFix C2 in Ghost CMS

Read-only research into an active campaign that exploits CVE-2026-26980 in Ghost CMS. Every result below comes from public GET requests. We did not...

🔗️ [Sicuranext] link.is.it/r78ZkS

##

CVE-2026-45034(CVSS UNKNOWN)

EPSS: 0.35%

updated 2026-06-08T23:00:17

1 posts

## Summary CVE-2026-34084 was patched by the helper `File::prohibitWrappers`. The helper calls `parse_url($filename, PHP_URL_SCHEME)` and then checks `is_string($scheme) && strlen($scheme) > 1` to reject stream wrappers such as `phar://`, `php://`, `data://` or `expect://`. The check is not equivalent to "does the path contain a wrapper". When the input has the form `phar:///path/file.phar/inner`

1 repos

https://github.com/Cyber-DarkNay/CVE-2026-45034

offseq@infosec.exchange at 2026-06-22T21:00:12.000Z ##

CVE-2026-45034: CRITICAL deserialization of untrusted data in PHPOffice PhpSpreadsheet allows RCE via phar stream wrappers. Patch to 1.30.5 to mitigate. PHP 7.x at highest risk. radar.offseq.com/threat/cve-20 #OffSeq #CVE202645034 #PHP #infosec

##

CVE-2026-20175
(6.1 MEDIUM)

EPSS: 0.18%

updated 2026-06-03T18:33:18

1 posts

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks. This vulnerability is due to insufficient validation of user-supplied input for HTTP requests that are sent to an affected device. An attacker who has knowledge of the address of

AAKL@infosec.exchange at 2026-06-25T16:45:31.000Z ##

New advisory.

CVE-2026-20175, medium severity: Cisco Finesse Remote File Inclusion Vulnerability sec.cloudapps.cisco.com/securi

From yesterday:

Cisco Advance Notification for Publication of July 1, 2026, Security Advisories sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-49103(CVSS UNKNOWN)

EPSS: 0.30%

updated 2026-05-27T15:33:37

1 posts

Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.

beyondmachines1@infosec.exchange at 2026-06-25T12:01:31.000Z ##

Webmin 2.641 Patches Root Takeover and 2FA Bypass Vulnerabilities

Webmin version 2.641 addresses multiple critical vulnerabilities, including a root-level stored XSS (CVE-2026-22678), a path traversal file overwrite (CVE-2026-49103), and a 2FA bypass (CVE-2026-56022). These flaws allow low-privileged users to compromise root accounts and bypass multi-factor authentication in multi-tenant hosting environments.

**Update your Webmin instances to version 2.641 immediately to prevent low-privileged users from taking over your root account. If you cannot patch today, restrict access to the mail and notification modules to only your most trusted administrators.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-23243
(7.8 HIGH)

EPSS: 0.12%

updated 2026-05-21T18:33:06

1 posts

In the Linux kernel, the following vulnerability has been resolved: RDMA/umad: Reject negative data_len in ib_umad_write ib_umad_write computes data_len from user-controlled count and the MAD header sizes. With a mismatched user MAD header size and RMPP header length, data_len can become negative and reach ib_create_send_mad(). This can make the padding calculation exceed the segment size and tr

offseq@infosec.exchange at 2026-06-23T01:30:26.000Z ##

CRITICAL kernel vulnerabilities in RHEL 7 ELS (e.g., CVE-2026-23243) risk DoS, memory corruption, and network/filesystem instability. Update & reboot required per RHSA-2026:27729. radar.offseq.com/threat/red-ha #OffSeq #Linux #RedHat #Infosec

##

CVE-2026-6637
(8.8 HIGH)

EPSS: 0.38%

updated 2026-05-14T15:31:59

2 posts

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update v

mastokukei@social.josko.org at 2026-06-26T18:01:59.000Z ##

Blip blop, I'm a #mastobot.
Here is a summary (in beta) of the latest posts in #programmingAtKukei masto.kukei.eu/browse/programm category:
- **PostgreSQL updates**: Critical CVEs in 2026-05-14 release (CVE-2026-6637), pg_qualstats 2.1.4, pg_stat_kcache 2.3.2, PGDay.UK 2026 schedule.
- **AI and coding agents**: Claude Code workflows, multi-agent systems (MCP), DeepSeek bugs, Ornith-1.0 (Gemma 4/Qwen 3.5-based), GLM-5.2, AI-native applications.
- **Open-source tools**: OpenKnowledge [1/3]

##

mastokukei@social.josko.org at 2026-06-26T18:01:46.000Z ##

projects.
- **PostgreSQL updates and vulnerabilities**: Security patches (CVE-2026-6637), new releases, and community discussions on database management. [3/3]

##

CVE-2026-28910
(3.3 LOW)

EPSS: 0.12%

updated 2026-05-13T00:49:16

1 posts

This issue was addressed with improved permissions checking. This issue is fixed in macOS Tahoe 26.4. A malicious app may be able to access arbitrary files.

mysk@mastodon.social at 2026-06-26T16:02:35.000Z ##

@0 Oh, I stopped dragging and dropping things in the Terminal since we published this:

mysk.blog/2026/05/19/cve-2026-

##

CVE-2026-4020
(7.5 HIGH)

EPSS: 39.70%

updated 2026-03-31T03:31:35

1 posts

The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor to access it. When the ?page=gravitysmtp-settings query parameter is appended, th

Nuclei template

1 repos

https://github.com/HORKimhab/CVE-2026-4020

beyondmachines1@infosec.exchange at 2026-06-23T08:01:05.000Z ##

Attackers Mass-Exploit Gravity SMTP Plugin to Steal WordPress API Keys

Attackers are mass-exploiting a sensitive information exposure vulnerability (CVE-2026-4020) in the Gravity SMTP WordPress plugin to steal API keys and system configuration data. Over 17 million exploit attempts have been blocked as threat actors target approximately 100,000 active installations.

**If you run the Gravity SMTP plugin for WordPress, update it to version 2.1.5 or later right away, since attackers are actively stealing API keys and credentials through older versions. After updating, rotate all your third-party email API keys and secrets (like Amazon SES, Google, Mailjet, Resend, and Zoho), and check your web server logs for any suspicious requests to the "mock-data" endpoint.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-20971
(7.8 HIGH)

EPSS: 0.13%

updated 2026-01-15T21:31:44

2 posts

Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code.

_r_netsec@infosec.exchange at 2026-06-24T10:58:06.000Z ##

CVE-2026-20971: Samsung Android kernel UAF affecting Galaxy S9-S25 lucidbitlabs.com/blog/when-def

##

informapirata@mastodon.uno at 2026-06-23T23:06:19.000Z ##

La vulnerabilità UAF del kernel KNOX di Samsung espone milioni di dispositivi Galaxy.

La vulnerabilità KNOX di Samsung (CVE-2026-20971) è una UAF del kernel in PROCA/FIVE che può consentire la corruzione [della memoria] tramite una race condition; Samsung l'ha corretta nel gennaio 2026.

securityaffairs.com/194090/sec

@informatica

infosec.exchange/@securityaffa

##

CVE-2025-8088
(8.8 HIGH)

EPSS: 85.78%

updated 2025-10-22T00:34:26

1 posts

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

32 repos

https://github.com/pentestfunctions/best-CVE-2025-8088

https://github.com/ilhamrzr/RAR-Anomaly-Inspector

https://github.com/Shinkirou789/Cve-2025-8088-WinRar-vulnerability

https://github.com/onlytoxi/CVE-2025-8088-Winrar-Tool

https://github.com/pentestfunctions/CVE-2025-8088-Multi-Document

https://github.com/hexsecteam/CVE-2025-8088-Winrar-Tool

https://github.com/shaheeryasirofficial/CVE-2025-8088

https://github.com/knight0x07/WinRAR-CVE-2025-8088-PoC-RAR

https://github.com/IsmaelCosma/CVE-2025-8088

https://github.com/kitsuneshade/WinRAR-Exploit-Tool---Rust-Edition

https://github.com/aldisakti2/CVE-2025-8088-BUILDER-Winrar-Tool

https://github.com/jordan922/CVE-2025-8088

https://github.com/travisbgreen/cve-2025-8088

https://github.com/pescada-dev/-CVE-2025-8088

https://github.com/techcorp/CVE-2025-8088-Exploit

https://github.com/sxyrxyy/CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit-

https://github.com/AdityaBhatt3010/CVE-2025-8088-WinRAR-Zero-Day-Path-Traversal

https://github.com/xi0onamdev/WinRAR-CVE-2025-8088-Exploitation-Toolkit

https://github.com/starfallreverie/winrar-exploit

https://github.com/Lewis-Ricardo/Amaranth-Project

https://github.com/nhattanhh/CVE-2025-8088

https://github.com/lennertdefauw/CVE-2025-8088

https://github.com/nuky-alt/CVE-2025-8088

https://github.com/walidpyh/CVE-2025-8088

https://github.com/Syrins/CVE-2025-8088-Winrar-Tool-Gui

https://github.com/papcaii2004/CVE-2025-8088-WinRAR-builder

https://github.com/undefined-name12/CVE-2025-8088-Winrar

https://github.com/hbesljx/CVE-2025-8088-EXP

https://github.com/0xAbolfazl/CVE-2025-8088-WinRAR-PathTraversal-PoC

https://github.com/DeepBlue-dot/CVE-2025-8088-WinRAR-Startup-PoC

https://github.com/ghostn4444/CVE-2025-8088

https://github.com/pexlexity/WinRAR-CVE-2025-8088-Path-Traversal-PoC

CVE-2014-9222(CVSS UNKNOWN)

EPSS: 63.75%

updated 2025-04-12T12:44:27

1 posts

AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gain privileges via a crafted cookie that triggers memory corruption, aka the "Misfortune Cookie" vulnerability.

2 repos

https://github.com/mercul1ninna/MIPS-CVE-2014-9222

https://github.com/donfanning/MIPS-CVE-2014-9222

certvde@infosec.exchange at 2026-06-23T07:37:32.000Z ##

#OT #Advisory VDE-2026-071
JUMO: Allegro RomPager webserver vulnerability in JUMO mTRONT, DICON touch, AQUIS touch devices

Multiple products from JUMO are affected by webserver vulnerability "CVE-2013-6786, CVE-2014-9222, CVE-2014-9223. This vulnerability leads to DOS of the device by using a misfortune cookie and reflected XSS attacks.
#CVE CVE-2014-9222, CVE-2013-6786, CVE-2014-9223

certvde.com/en/advisories/vde-

#CSAF jumo.csaf-tp.certvde.com/.well

##

CVE-2014-9223(CVSS UNKNOWN)

EPSS: 6.03%

updated 2025-04-12T12:44:27

1 posts

Multiple buffer overflows in AllegroSoft RomPager, as used in Huawei Home Gateway products and other vendors and products, allow remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors related to authorization.

certvde@infosec.exchange at 2026-06-23T07:37:32.000Z ##

#OT #Advisory VDE-2026-071
JUMO: Allegro RomPager webserver vulnerability in JUMO mTRONT, DICON touch, AQUIS touch devices

Multiple products from JUMO are affected by webserver vulnerability "CVE-2013-6786, CVE-2014-9222, CVE-2014-9223. This vulnerability leads to DOS of the device by using a misfortune cookie and reflected XSS attacks.
#CVE CVE-2014-9222, CVE-2013-6786, CVE-2014-9223

certvde.com/en/advisories/vde-

#CSAF jumo.csaf-tp.certvde.com/.well

##

CVE-2024-2658(CVSS UNKNOWN)

EPSS: 0.41%

updated 2025-01-30T18:32:09

1 posts

A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated p

2 repos

https://github.com/laoqin1234/Linux-Root-CVE-2024-26581-PoC

https://github.com/madfxr/CVE-2024-26581-Checker

AAKL@infosec.exchange at 2026-06-26T14:39:26.000Z ##

New and part promo.

Kaspersky:Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk securelist.com/tr/schneider-el @Kaspersky #infosec #vulnerability

##

CVE-2019-1003037
(6.5 MEDIUM)

EPSS: 1.30%

updated 2023-12-14T18:25:14

1 posts

An information exposure vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMCloud.java that allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

nyanbinary@infosec.exchange at 2026-06-22T14:44:21.000Z ##

Ok, so. Originally CVE IDs where 4 digits. At some point in the mid '10s it went "4+ digits". There is a chance we'll require 6 digits this or next year.

Meanwhile, in 2019: Fuck it, we ball: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-11705
(0 None)

EPSS: 0.00%

1 posts

N/A

beyondmachines1@infosec.exchange at 2026-06-26T16:01:21.000Z ##

Arista Patches Critical Telemetry and Authentication Flaws in EOS Network Operating System

Arista Networks has patched six vulnerabilities in its EOS operating system, including a critical flaw (CVE-2026-11705) in the telemetry agent that allows attackers to modify system data. The updates also fix policy-based authentication bypass and internal credential exposure risks in data center and cloud environments.

**First, make sure all Arista EOS management interfaces and streaming telemetry is isolated from the internet and reachable only from trusted management networks. Then update affected devices (EOS 4.31 through 4.36) to version 4.36.1F or apply Arista's telemetry agent hotfixes; As a mitigation, ensure the telemetry agent isn't running from the /usr/bin/TerminAttrRW path and remove the -cveapimode=queued flag.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-20896
(0 None)

EPSS: 0.00%

1 posts

N/A

guru@thecybersecguru.com at 2026-06-26T04:51:47.000Z ##

Three Vulnerabilities, One Platform: Why Your Self-Hosted Gitea/Gogs Instance Is Probably Already Owned

Three critical Gitea and Gogs CVEs disclosed in 2026: a CVSS 9.8 auth bypass via X-WEBAUTH-USER header, a stored DOM XSS through Semantic UI's preserveHTML, and an incomplete SSRF fix exposing AWS IMDS credentials

thecybersecguru.com/news/cve-2

##

CVE-2026-8932
(0 None)

EPSS: 0.00%

2 posts

N/A

1 repos

https://github.com/0xBlackash/CVE-2026-8932

beyondmachines1@infosec.exchange at 2026-06-25T17:01:31.000Z ##

curl Patches 25-Year-Old Vulnerability and 17 Other Flaws

curl version 8.21.0 addresses 18 vulnerabilities, including a 25-year-old authentication bypass (CVE-2026-8932) and multiple memory safety issues. The flaws primarily affect libcurl, the library used by billions of devices for data transfer.

**Plan to update your curl and libcurl installations to version 8.21.0. Since libcurl is hidden inside many apps and devices, you should check your entire software stack for outdated versions.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

bagder@mastodon.social at 2026-06-24T07:20:34.000Z ##

CVE-2026-8932 is the oldest #curl vulnerability reported so far. 25.25 years old. Shipped in releases since curl version 7.7, released on March 22 2001

Still rather benign and it probably hurt about three users, at most.

curl.se/docs/CVE-2026-8932.html

##

CVE-2026-13311
(0 None)

EPSS: 0.36%

1 posts

N/A

offseq@infosec.exchange at 2026-06-25T06:00:27.000Z ##

ljharb shell-quote <=1.8.4 is impacted by CVE-2026-13311 (HIGH). Inefficient parsing can let attackers trigger DoS by blocking the Node.js event loop. Patch to 1.8.5+ now! 🛡️ radar.offseq.com/threat/cve-20 #OffSeq #InfoSec #NodeJS #CVE202613311

##

CVE-2026-50551
(0 None)

EPSS: 0.44%

1 posts

N/A

offseq@infosec.exchange at 2026-06-25T03:00:24.000Z ##

CVE-2026-50551: SiYuan (<3.7.0) suffers CRITICAL stored XSS in Attribute View, enabling RCE via Electron client. Upgrade to v3.7.0+ to mitigate. No workaround available. Details: radar.offseq.com/threat/cve-20 #OffSeq #XSS #SiYuan #Cybersecurity

##

CVE-2026-55570
(0 None)

EPSS: 0.33%

1 posts

N/A

offseq@infosec.exchange at 2026-06-25T01:30:24.000Z ##

CVE-2026-55570: CRITICAL XSS in SiYuan (<3.7.0) enables arbitrary HTML injection. On the desktop client, attackers can escalate to OS command execution due to nodeIntegration. Upgrade to 3.7.0+ now! radar.offseq.com/threat/cve-20 #OffSeq #XSS #Vuln #SiYuan

##

CVE-2026-55454
(0 None)

EPSS: 0.31%

1 posts

N/A

offseq@infosec.exchange at 2026-06-25T00:00:36.000Z ##

CVE-2026-55454: CRITICAL (CVSS 9.9) vuln in appsmithorg Appsmith <2.1. Unauth Caddy admin API inside container can be exploited via SSRF by low-priv users to control reverse proxy. Upgrade to 2.1+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE202655454 #appsmith

##

CVE-2026-50000
(0 None)

EPSS: 0.00%

1 posts

N/A

legoktm@wikis.world at 2026-06-24T14:57:43.000Z ##

RE: social.freedom.press/@securedr

The low priority issue we disclosed today managed to get assigned CVE-2026-50000.

Didn't include this in the writeup, but just for the purpose of keeping score, this would likely not have happened if it was written in #Rust because mutability is part of the type system, so you don't end up accidentally mutating what should be an immutable object!

github.com/freedomofpress/secu

##

CVE-2026-53662
(0 None)

EPSS: 0.24%

1 posts

N/A

offseq@infosec.exchange at 2026-06-24T03:00:27.000Z ##

immich-app suffers CRITICAL reflected XSS (CVE-2026-53662) in /auth/login (commits 4ffa26c9 – 4eb1003). Exploitation = persistent account takeover via API key minting. Update to commit 4eb1003 or later. radar.offseq.com/threat/cve-20 #OffSeq #CVE202653662 #XSS #infosec

##

CVE-2026-50160
(0 None)

EPSS: 0.00%

1 posts

N/A

_r_netsec@infosec.exchange at 2026-06-23T17:43:05.000Z ##

CVE-2026-50160: Four Independent Weaknesses Combine Into a CVSS 10.0 Full Compromise in Hoppscotch offgridsec.com/blog-hoppscotch

##

CVE-2026-12957
(0 None)

EPSS: 0.12%

1 posts

N/A

awssecurityfeed@infosec.exchange at 2026-06-23T16:30:01.000Z ##

CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins

Bulletin ID: 2026-047-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/23/2026 09:30 AM PDT
Description:
Language Servers for AWS provide the underlying language-server runtime that powers Amazon ...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-47729
(0 None)

EPSS: 0.00%

1 posts

N/A

1 repos

https://github.com/0xBlackash/CVE-2026-47729

benzogaga33@mamot.fr at 2026-06-23T09:40:04.000Z ##

Squidbleed : une faille vieille de 29 ans fait fuiter les identifiants des utilisateurs du proxy Squid it-connect.fr/squidbleed-faill #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

CVE-2026-10658
(0 None)

EPSS: 0.17%

1 posts

N/A

offseq@infosec.exchange at 2026-06-23T04:30:29.000Z ##

Zephyr <=4.4.0 Bluetooth Host ISO path has CVE-2026-10658 (HIGH). Missing SDU header length checks can cause denial of service (kernel assert) or OOB reads if CONFIG_BT_ISO_RX is enabled. Evaluate mitigations now. radar.offseq.com/threat/cve-20 #OffSeq #Zephyr #CVE #Bluetooth

##

Visit counter For Websites