##
Updated at UTC 2026-08-05T18:24:56.457420
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-20304 | 9.9 | 0.00% | 2 | 0 | 2026-08-05T17:16:50.890000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20303 | 9.9 | 0.00% | 2 | 0 | 2026-08-05T17:16:50.513000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20272 | 9.8 | 0.00% | 2 | 0 | 2026-08-05T17:16:49.053000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20267 | 9.0 | 0.00% | 2 | 0 | 2026-08-05T17:16:47.560000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-18898 | 8.8 | 0.47% | 1 | 0 | 2026-08-05T17:16:45.797000 | A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. Thi | |
| CVE-2026-70619 | 8.8 | 0.36% | 1 | 0 | 2026-08-05T16:17:05.093000 | Odysseus before commit bf325f6 contains a missing authorization vulnerability th | |
| CVE-2026-68981 | 7.5 | 0.32% | 1 | 0 | 2026-08-05T15:33:14 | Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the appl | |
| CVE-2026-71287 | 8.8 | 0.00% | 2 | 0 | 2026-08-05T15:32:29 | Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER | |
| CVE-2026-71285 | 8.1 | 0.00% | 2 | 0 | 2026-08-05T15:32:29 | Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js | |
| CVE-2026-71294 | 7.6 | 0.00% | 2 | 0 | 2026-08-05T15:32:29 | Cotonti CMS's Comments plugin deserializes user-supplied data without restrictin | |
| CVE-2026-71289 | 9.8 | 0.00% | 2 | 0 | 2026-08-05T15:32:29 | The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implement | |
| CVE-2026-71269 | 7.2 | 0.00% | 1 | 0 | 2026-08-05T15:32:20 | Node-RED's local-filesystem library storage module (getLibraryEntry() and saveLi | |
| CVE-2026-67857 | 7.5 | 0.35% | 1 | 0 | 2026-08-05T15:32:14 | open62541 1.5.5 contains an out-of-bounds read in the client-side function respo | |
| CVE-2026-67858 | 7.5 | 0.49% | 1 | 0 | 2026-08-05T15:32:14 | Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery | |
| CVE-2026-68979 | 9.8 | 0.35% | 1 | 0 | 2026-08-05T15:32:09 | Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API me | |
| CVE-2026-66066 | 0 | 1.70% | 4 | 7 | 2026-08-05T15:17:03.507000 | Action Pack is a framework for handling and responding to web requests. In versi | |
| CVE-2026-68580 | 7.5 | 0.24% | 1 | 0 | 2026-08-05T14:17:10.217000 | FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio inp | |
| CVE-2026-66310 | 7.7 | 0.40% | 1 | 0 | 2026-08-05T14:17:08.817000 | External control of file name or path in Microsoft Edge for Android allows an un | |
| CVE-2026-18933 | 7.2 | 0.00% | 1 | 0 | 2026-08-05T13:20:39.580000 | The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the | |
| CVE-2026-66747 | 9.8 | 0.00% | 2 | 0 | 2026-08-05T12:31:36 | Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, | |
| CVE-2026-71245 | 7.1 | 0.00% | 1 | 0 | 2026-08-05T12:31:36 | Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxController.php) | |
| CVE-2026-71254 | 9.8 | 0.00% | 1 | 0 | 2026-08-05T12:31:34 | nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server- | |
| CVE-2026-71214 | 9.8 | 0.34% | 1 | 0 | 2026-08-05T09:31:27 | The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-serve | |
| CVE-2026-70378 | 7.5 | 0.28% | 1 | 0 | 2026-08-05T09:31:26 | imagecli's `carve <ratio>` pipeline operation (Carve::apply() in src/image_ops.r | |
| CVE-2026-4431 | 9.1 | 0.33% | 1 | 0 | 2026-08-05T09:31:26 | The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modi | |
| CVE-2026-9273 | 9.3 | 0.28% | 1 | 0 | 2026-08-05T06:30:44 | The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restr | |
| CVE-2026-9198 | 9.8 | 17.05% | 5 | 3 | template | 2026-08-05T05:17:15.823000 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain |
| CVE-2026-58073 | 0 | 0.22% | 1 | 0 | 2026-08-05T05:17:02.413000 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated at | |
| CVE-2026-18556 | 7.4 | 0.49% | 6 | 0 | 2026-08-05T05:16:46.967000 | Authentication bypass using an alternate path or channel vulnerability in N-able | |
| CVE-2026-18897 | 8.8 | 0.57% | 1 | 0 | 2026-08-05T03:30:28 | A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. T | |
| CVE-2026-18895 | 8.8 | 0.57% | 1 | 0 | 2026-08-05T03:30:28 | A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacte | |
| CVE-2026-67859 | 7.5 | 0.47% | 1 | 0 | 2026-08-05T00:30:46 | Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to ca | |
| CVE-2026-67861 | 7.5 | 0.42% | 1 | 0 | 2026-08-05T00:30:39 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a den | |
| CVE-2026-45537 | 9.1 | 0.36% | 1 | 0 | 2026-08-04T23:16:51.687000 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versio | |
| CVE-2026-70554 | 9.8 | 0.85% | 1 | 0 | 2026-08-04T21:30:42 | MaxSite CMS contains a PHP object injection vulnerability that allows unauthenti | |
| CVE-2026-70553 | 9.8 | 0.88% | 2 | 0 | 2026-08-04T21:30:37 | MaxSite CMS contains a remote code execution vulnerability that allows unauthent | |
| CVE-2026-69703 | 9.8 | 0.46% | 1 | 0 | 2026-08-04T21:30:29 | Atlas-Livre contains an improper access control vulnerability in the admin contr | |
| CVE-2026-66803 | 10.0 | 0.48% | 1 | 0 | 2026-08-04T20:46:44.650000 | Improper access control in Azure Cosmos DB allows an unauthorized attacker to ex | |
| CVE-2026-49435 | 9.8 | 0.77% | 1 | 0 | 2026-08-04T20:16:52.160000 | Keysight IxChariot Endpoint and associated products contain a stack-based buffer | |
| CVE-2026-70486 | 8.2 | 0.37% | 1 | 0 | 2026-08-04T20:02:04 | ## Summary Any authenticated user with access to a terminal server could get scr | |
| CVE-2026-70482 | 8.1 | 0.34% | 1 | 0 | 2026-08-04T19:52:03 | ## Summary The OAuth token exchange endpoint accepts a raw provider access toke | |
| CVE-2026-70478 | None | 0.38% | 1 | 0 | 2026-08-04T19:37:38 | ### Summary The OAuth2 token refresh endpoint (`POST /api/v1/oauth2-credential/ | |
| CVE-2026-70477 | None | 0.44% | 1 | 0 | 2026-08-04T19:29:28 | -- ABSTRACT ------------------------------------- Trend Micro's Zero Day Initia | |
| CVE-2026-18830 | 8.1 | 0.29% | 1 | 0 | 2026-08-04T19:16:45.433000 | Insufficient input validation in Amazon Bedrock AgentCore harness might allow an | |
| CVE-2026-15958 | 9.3 | 0.20% | 1 | 0 | 2026-08-04T18:32:27 | The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform | |
| CVE-2026-24254 | 9.8 | 0.45% | 1 | 0 | 2026-08-04T18:31:37 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topol | |
| CVE-2026-64633 | None | 0.34% | 1 | 0 | 2026-08-04T18:31:36 | A vulnerability allowing remote unauthenticated code execution on the agent host | |
| CVE-2026-15920 | 6.1 | 0.30% | 2 | 0 | 2026-08-04T18:31:31 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `djang | |
| CVE-2026-15307 | 8.8 | 0.54% | 1 | 0 | 2026-08-04T18:31:31 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDja | |
| CVE-2026-24084 | 7.5 | 0.23% | 1 | 0 | 2026-08-04T18:31:31 | Weak configuration when UE does not verify the consistency of its additional sec | |
| CVE-2026-24083 | 7.8 | 0.11% | 1 | 0 | 2026-08-04T18:31:31 | Memory Corruption while processing IOCTL device driver requests with invalid arg | |
| CVE-2026-25292 | 7.6 | 0.16% | 1 | 0 | 2026-08-04T18:31:31 | Memory Corruption when processing untrusted user input in the fastboot command h | |
| CVE-2026-69100 | 8.8 | 0.55% | 1 | 0 | 2026-08-04T18:31:31 | LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains | |
| CVE-2026-69098 | 9.8 | 0.51% | 1 | 0 | 2026-08-04T18:31:31 | kotaemon through 0.12.0 contains an insecure deserialization vulnerability in th | |
| CVE-2026-69110 | 9.1 | 0.55% | 1 | 0 | 2026-08-04T17:16:59.733000 | OpenCode Studio before 2.4.4 contains a missing authentication vulnerability tha | |
| CVE-2026-18684 | 9.8 | 2.03% | 1 | 0 | 2026-08-04T17:16:47.273000 | A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affe | |
| CVE-2026-48326 | 9.9 | 0.48% | 1 | 0 | 2026-08-04T16:16:25.497000 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia | |
| CVE-2026-18686 | 9.8 | 2.61% | 1 | 0 | 2026-08-04T16:16:21.593000 | A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected elem | |
| CVE-2026-18577 | 8.1 | 4.10% | 12 | 1 | 2026-08-04T15:33:20 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco | |
| CVE-2026-60007 | None | 0.45% | 1 | 0 | 2026-08-04T15:32:29 | In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns | |
| CVE-2026-58061 | 0 | 0.21% | 1 | 0 | 2026-08-04T14:50:12.360000 | In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to calle | |
| CVE-2026-58062 | 0 | 0.20% | 2 | 1 | 2026-08-04T14:50:12.360000 | In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without bi | |
| CVE-2026-48331 | 10.0 | 0.47% | 1 | 0 | 2026-08-04T14:48:22.933000 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) | |
| CVE-2026-15721 | 9.8 | 0.23% | 1 | 0 | 2026-08-04T14:16:30.620000 | Cleartext storage of sensitive information vulnerability in Bilin Software and I | |
| CVE-2026-14175 | 9.8 | 0.40% | 2 | 0 | 2026-08-04T12:34:56 | Unrestricted upload of file with dangerous type vulnerability in Bilin Software | |
| CVE-2026-14804 | 9.1 | 0.30% | 2 | 0 | 2026-08-04T12:34:56 | Use of hard-coded cryptographic key vulnerability in Bilin Software and Informat | |
| CVE-2026-17566 | 9.9 | 0.43% | 1 | 1 | 2026-08-04T12:31:51.160000 | pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by in | |
| CVE-2026-18754 | 9.1 | 0.31% | 1 | 0 | 2026-08-04T09:31:41 | The product firmware contains an embedded, static RSA private key utilized by th | |
| CVE-2026-6837 | 7.2 | 0.95% | 1 | 0 | 2026-08-04T03:31:16 | A post-authentication command injection vulnerability in the "export-cgi" CGI pr | |
| CVE-2026-62354 | None | 0.26% | 1 | 0 | 2026-08-04T00:35:57 | Authorization handling for Parameter Context validation requests in Apache NiFi | |
| CVE-2026-48333 | 9.8 | 0.47% | 1 | 0 | 2026-08-04T00:35:01 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi | |
| CVE-2026-48323 | 10.0 | 0.62% | 2 | 0 | 2026-08-04T00:35:01 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia | |
| CVE-2026-66318 | 8.1 | 0.37% | 1 | 0 | 2026-08-04T00:35:01 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorize | |
| CVE-2026-18685 | 9.8 | 1.99% | 1 | 0 | 2026-08-04T00:35:01 | A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Imp | |
| CVE-2026-48330 | 10.0 | 0.68% | 1 | 0 | 2026-08-04T00:35:01 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia | |
| CVE-2026-66315 | 7.5 | 0.62% | 1 | 0 | 2026-08-04T00:34:55 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke | |
| CVE-2026-59913 | 7.8 | 0.11% | 1 | 0 | 2026-08-03T21:31:44 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, co | |
| CVE-2026-59912 | 7.8 | 0.10% | 1 | 0 | 2026-08-03T21:31:36 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, co | |
| CVE-2026-18108 | 9.8 | 0.22% | 1 | 0 | 2026-08-03T21:31:35 | Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _ve | |
| CVE-2026-69240 | 9.8 | 0.32% | 1 | 0 | 2026-08-03T20:29:52 | ### Summary SQL Injection is possible with strings only **if dialect is set to ` | |
| CVE-2026-18589 | 9.8 | 0.61% | 1 | 0 | 2026-08-03T20:17:15.910000 | A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the | |
| CVE-2026-18614 | 9.8 | 2.01% | 1 | 0 | 2026-08-03T19:16:45.200000 | A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the func | |
| CVE-2026-16300 | 9.8 | 0.30% | 1 | 0 | 2026-08-03T18:31:51 | The ChamaWP WordPress plugin before 1.0.13 does not properly validate a passwor | |
| CVE-2026-18574 | None | 0.99% | 2 | 0 | 2026-08-03T15:32:49 | An authentication bypass vulnerability in Check Point Security Management Server | |
| CVE-2026-33591 | None | 0.52% | 3 | 0 | 2026-08-03T12:32:43 | A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unaut | |
| CVE-2026-9593 | 6.7 | 0.11% | 1 | 0 | 2026-08-03T09:32:46 | A vulnerability in the iDTM FDI allows an attacker with elevated privileges and | |
| CVE-2026-12816 | None | 0.16% | 1 | 0 | 2026-08-03T09:32:36 | In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via len | |
| CVE-2026-8763 | None | 0.33% | 2 | 1 | 2026-08-03T09:32:36 | In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot | |
| CVE-2026-12803 | None | 0.17% | 1 | 0 | 2026-08-03T09:32:36 | In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce w | |
| CVE-2026-5674 | 8.8 | 0.13% | 1 | 0 | 2026-08-03T08:17:20.920000 | A flaw was found in PipeWire, a multimedia server. This vulnerability allows an | |
| CVE-2026-59639 | None | 0.17% | 1 | 0 | 2026-08-03T06:32:44 | In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for Sig | |
| CVE-2026-59650 | None | 0.26% | 1 | 1 | 2026-08-03T06:32:44 | In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalid | |
| CVE-2026-59638 | None | 0.28% | 1 | 1 | 2026-08-03T06:32:44 | In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enable | |
| CVE-2026-3245 | 7.5 | 0.24% | 1 | 0 | 2026-08-03T00:30:35 | A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that | |
| CVE-2025-71399 | 8.6 | 0.31% | 1 | 0 | 2026-08-02T15:30:21 | Better Auth relies on better-call, which uses the rou3 router library. In affect | |
| CVE-2026-64531 | 7.8 | 0.13% | 2 | 4 | 2026-08-01T09:30:23 | In the Linux kernel, the following vulnerability has been resolved: net: openvs | |
| CVE-2026-9044 | None | 0.97% | 2 | 0 | 2026-08-01T00:31:02 | An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 | |
| CVE-2026-63223 | 9.8 | 0.49% | 1 | 2 | 2026-08-01T00:17:17.750000 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and | |
| CVE-2025-69935 | 9.8 | 0.26% | 1 | 0 | 2026-07-31T21:32:56 | CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the | |
| CVE-2026-14319 | 7.5 | 0.32% | 1 | 0 | 2026-07-31T21:32:56 | The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to | |
| CVE-2025-69933 | 9.8 | 0.26% | 1 | 0 | 2026-07-31T21:32:55 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /me | |
| CVE-2026-43831 | 7.5 | 0.24% | 1 | 0 | 2026-07-31T21:32:55 | Successful exploitation of the vulnerability could allow an unauthenticated atta | |
| CVE-2026-43830 | 9.8 | 0.31% | 1 | 0 | 2026-07-31T21:31:54 | Successful exploitation of the command injection vulnerability could allow an at | |
| CVE-2025-69936 | 9.8 | 0.26% | 1 | 0 | 2026-07-31T21:31:53 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /ed | |
| CVE-2026-56673 | 7.5 | 0.43% | 1 | 0 | 2026-07-31T20:16:52.487000 | ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node | |
| CVE-2026-43832 | 7.5 | 0.24% | 1 | 0 | 2026-07-31T20:16:50.777000 | Full details and mitigation steps are currently restricted and will be published | |
| CVE-2026-43829 | 7.5 | 0.24% | 1 | 0 | 2026-07-31T20:16:50.317000 | Full details and mitigation steps are currently restricted and will be published | |
| CVE-2025-69934 | 9.8 | 0.26% | 1 | 0 | 2026-07-31T19:17:03.113000 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /de | |
| CVE-2026-12720 | 7.5 | 0.30% | 1 | 1 | 2026-07-31T18:33:20 | The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be | |
| CVE-2026-12695 | 8.1 | 0.29% | 1 | 0 | 2026-07-31T18:33:20 | The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitte | |
| CVE-2026-12721 | 8.6 | 0.26% | 1 | 0 | 2026-07-31T18:33:20 | The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape | |
| CVE-2026-15969 | 9.8 | 0.98% | 2 | 0 | 2026-07-31T18:33:17 | SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via by | |
| CVE-2026-58048 | None | 0.50% | 1 | 1 | 2026-07-31T18:32:25 | Improper preservation of SQL mode when renaming databases in cPanel allows exec | |
| CVE-2026-14919 | 9.8 | 0.28% | 1 | 0 | 2026-07-31T18:32:17 | The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its | |
| CVE-2026-35847 | 9.8 | 0.37% | 1 | 0 | 2026-07-31T18:32:13 | An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrar | |
| CVE-2026-12251 | 8.1 | 0.23% | 1 | 0 | 2026-07-31T18:17:09.777000 | The Ultimate Member WordPress plugin before 2.12.1 does not filter administrato | |
| CVE-2026-13609 | 8.8 | 0.25% | 1 | 0 | 2026-07-31T17:16:32.347000 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML ent | |
| CVE-2025-69937 | 9.8 | 0.26% | 1 | 0 | 2026-07-31T16:16:56.643000 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the | |
| CVE-2026-14333 | 7.5 | 0.30% | 1 | 0 | 2026-07-31T15:33:51 | The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in | |
| CVE-2026-14830 | 7.5 | 0.21% | 1 | 0 | 2026-07-31T14:16:46.133000 | The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment proces | |
| CVE-2026-38709 | 9.8 | 2.67% | 2 | 0 | 2026-07-31T12:31:33 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, W | |
| CVE-2026-52539 | 9.1 | 0.30% | 1 | 0 | 2026-07-31T12:30:30 | Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOK | |
| CVE-2026-14483 | 9.8 | 0.61% | 1 | 2 | 2026-07-31T09:31:25 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulner | |
| CVE-2026-63362 | 5.9 | 1.53% | 1 | 0 | 2026-07-31T00:30:29 | An unsigned integer underflow in the PubSub signature verification path in open | |
| CVE-2026-12562 | 8.8 | 0.28% | 1 | 0 | 2026-07-31T00:30:29 | The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that | |
| CVE-2026-66418 | 9.3 | 0.34% | 1 | 1 | 2026-07-30T21:31:57 | OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability t | |
| CVE-2026-12943 | 9.8 | 0.92% | 2 | 0 | 2026-07-30T21:31:50 | IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1 | |
| CVE-2026-51291 | 9.8 | 0.00% | 1 | 0 | 2026-07-30T21:31:47 | sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert functi | |
| CVE-2026-17191 | 9.1 | 2.83% | 1 | 0 | 2026-07-30T19:10:52.250000 | An input validation vulnerability exists in an API component of the orchestrator | |
| CVE-2026-41709 | 2.7 | 0.38% | 1 | 0 | 2026-07-30T19:07:59.843000 | VMware ESX contains an insufficient logging vulnerability. A malicious administr | |
| CVE-2026-59310 | 9.8 | 1.14% | 1 | 0 | 2026-07-30T16:17:15.183000 | VMware vCenter contains a directory traversal vulnerability in the Syslog server | |
| CVE-2026-47876 | 9.3 | 0.28% | 1 | 0 | 2026-07-30T15:31:54 | VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual | |
| CVE-2026-59309 | 9.8 | 0.74% | 1 | 0 | 2026-07-30T15:31:54 | VMware vCenter contains an authentication bypass vulnerability in the VMware Dir | |
| CVE-2026-41703 | 7.6 | 0.56% | 1 | 0 | 2026-07-30T15:31:50 | VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. | |
| CVE-2026-5491 | 7.5 | 1.54% | 1 | 1 | 2026-07-30T14:18:46.477000 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera | |
| CVE-2026-5487 | 7.5 | 1.54% | 1 | 0 | 2026-07-30T14:18:46.477000 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera | |
| CVE-2026-12935 | 0 | 0.81% | 1 | 0 | 2026-07-30T14:12:18.697000 | The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking | |
| CVE-2026-14869 | 8.6 | 0.29% | 1 | 0 | 2026-07-30T14:08:23.057000 | The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side req | |
| CVE-2026-16496 | 8.9 | 0.27% | 1 | 0 | 2026-07-30T14:08:23.057000 | The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization | |
| CVE-2026-48449 | 10.0 | 0.54% | 1 | 0 | 2026-07-30T03:31:28 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi | |
| CVE-2026-5492 | 6.5 | 1.60% | 1 | 0 | 2026-07-29T21:31:08 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera | |
| CVE-2026-20316 | 5.3 | 0.79% | 2 | 0 | 2026-07-29T21:31:00 | A vulnerability in the web interface of Cisco Secure Firewall Management Center | |
| CVE-2026-53264 | 7.8 | 0.21% | 1 | 1 | 2026-07-29T21:30:47 | In the Linux kernel, the following vulnerability has been resolved: net/sched: | |
| CVE-2026-67192 | 8.1 | 0.62% | 1 | 0 | 2026-07-29T18:31:46 | Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overfl | |
| CVE-2026-16655 | 7.2 | 0.30% | 1 | 0 | 2026-07-29T12:31:30 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Fo | |
| CVE-2026-16498 | 10.0 | 0.33% | 2 | 0 | 2026-07-28T21:31:39 | The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant cr | |
| CVE-2026-16462 | 9.8 | 0.42% | 1 | 0 | 2026-07-28T12:31:27 | In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This a | |
| CVE-2026-11841 | 9.4 | 0.46% | 1 | 0 | 2026-07-28T12:31:20 | An attacker may perform unauthenticated read and write operations on sensitive f | |
| CVE-2026-45112 | 7.5 | 1.94% | 1 | 0 | 2026-07-27T21:32:25 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thr | |
| CVE-2026-17192 | 8.5 | 2.34% | 1 | 0 | 2026-07-27T18:31:56 | A VCO feature does not sufficiently validate caller-supplied input, allowing req | |
| CVE-2026-12495 | None | 0.16% | 1 | 0 | 2026-07-27T12:32:01 | Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http | |
| CVE-2026-46300 | 7.8 | 7.01% | 1 | 15 | 2026-07-23T11:10:00.120000 | In the Linux kernel, the following vulnerability has been resolved: net: skbuff | |
| CVE-2026-50522 | 9.8 | 75.76% | 1 | 5 | 2026-07-22T21:31:51 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut | |
| CVE-2026-10702 | 4.3 | 0.72% | 1 | 2 | 2026-07-22T19:10:00.120000 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w | |
| CVE-2026-50343 | 7.8 | 3.50% | 1 | 1 | 2026-07-22T16:17:42.747000 | Improper privilege management in Microsoft Install Service allows an authorized | |
| CVE-2026-54121 | 8.8 | 1.05% | 1 | 12 | 2026-07-21T19:54:33.623000 | Improper authorization in Active Directory Certificate Services (AD CS) allows a | |
| CVE-2026-42533 | 8.1 | 3.60% | 1 | 9 | 2026-07-15T15:33:14 | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive | |
| CVE-2026-15409 | 10.0 | 78.44% | 2 | 6 | template | 2026-07-14T21:32:22 | A Server-side request forgery (SSRF) vulnerability has been identified in the SM |
| CVE-2026-15410 | 7.2 | 76.35% | 2 | 3 | 2026-07-14T21:32:21 | Post-authentication improper control of generation of code ('Code Injection') vu | |
| CVE-2026-31431 | 7.8 | 94.55% | 1 | 100 | template | 2026-07-14T15:32:55 | In the Linux kernel, the following vulnerability has been resolved: crypto: alg |
| CVE-2026-43284 | 7.8 | 93.23% | 1 | 44 | 2026-07-14T15:31:59 | In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: | |
| CVE-2025-26399 | 9.8 | 88.33% | 1 | 1 | 2026-06-17T09:01:42.407000 | SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxP | |
| CVE-2023-32233 | 7.8 | 12.97% | 1 | 7 | 2026-06-17T05:58:22.273000 | In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when | |
| CVE-2026-48030 | 9.9 | 1.54% | 1 | 1 | 2026-06-09T22:00:36 | ### Summary An OS Command Injection vulnerability in the terminal action handle | |
| CVE-2026-34486 | 7.5 | 81.16% | 3 | 6 | template | 2026-06-08T23:28:56 | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the f |
| CVE-2026-42897 | 8.1 | 70.31% | 2 | 1 | 2026-05-15T18:30:32 | Improper neutralization of input during web page generation ('cross-site scripti | |
| CVE-2026-20079 | 10.0 | 37.67% | 2 | 1 | template | 2026-03-04T18:32:03 | A vulnerability in the web interface of Cisco Secure Firewall Management Center |
| CVE-2026-1070 | 4.3 | 0.16% | 1 | 2 | 2026-01-24T09:30:33 | The Alex User Counter plugin for WordPress is vulnerable to Cross-Site Request F | |
| CVE-2013-4786 | 7.5 | 78.57% | 2 | 1 | 2025-04-11T04:12:49 | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (R | |
| CVE-2026-44945 | 0 | 0.74% | 1 | 0 | N/A | ||
| CVE-2026-53921 | 0 | 0.00% | 1 | 2 | N/A | ||
| CVE-2026-59726 | 0 | 0.48% | 2 | 1 | N/A | ||
| CVE-2026-59774 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-65321 | 0 | 0.44% | 2 | 1 | N/A | ||
| CVE-2026-56670 | 0 | 0.22% | 1 | 0 | N/A | ||
| CVE-2026-56671 | 0 | 0.66% | 1 | 0 | N/A | ||
| CVE-2026-56672 | 0 | 0.24% | 1 | 0 | N/A | ||
| CVE-2026-63222 | 0 | 0.45% | 1 | 0 | N/A | ||
| CVE-2026-63221 | 0 | 0.38% | 1 | 0 | N/A | ||
| CVE-2026-4941 | 0 | 0.00% | 1 | 2 | N/A | ||
| CVE-2026-49413 | 0 | 0.15% | 1 | 1 | N/A |
updated 2026-08-05T17:16:50.890000
2 posts
Cisco SD-WAN vulnerability CVE-2026-20303 and CVE-2026-20304 reach CVSS 9.9. Cisco urges Catalyst SD-WAN customers to patch now.
#Cisco #SDWAN #CVE202620303 #CVE202620304 #CyberSecurity #NetworkSecurity
Cisco SD-WAN vulnerability CVE-2026-20303 and CVE-2026-20304 reach CVSS 9.9. Cisco urges Catalyst SD-WAN customers to patch now.
#Cisco #SDWAN #CVE202620303 #CVE202620304 #CyberSecurity #NetworkSecurity
updated 2026-08-05T17:16:50.513000
2 posts
Cisco SD-WAN vulnerability CVE-2026-20303 and CVE-2026-20304 reach CVSS 9.9. Cisco urges Catalyst SD-WAN customers to patch now.
#Cisco #SDWAN #CVE202620303 #CVE202620304 #CyberSecurity #NetworkSecurity
Cisco SD-WAN vulnerability CVE-2026-20303 and CVE-2026-20304 reach CVSS 9.9. Cisco urges Catalyst SD-WAN customers to patch now.
#Cisco #SDWAN #CVE202620303 #CVE202620304 #CyberSecurity #NetworkSecurity
updated 2026-08-05T17:16:49.053000
2 posts
Cisco IOS XE vulnerability CVE-2026-20272 hits CVSS 9.8 and CVE-2026-20267 scores 9.0. Cisco urges customers to patch now.
#Cisco #IOSXE #CVE202620272 #CVE202620267 #CyberSecurity #NetworkSecurity
##Cisco IOS XE vulnerability CVE-2026-20272 hits CVSS 9.8 and CVE-2026-20267 scores 9.0. Cisco urges customers to patch now.
#Cisco #IOSXE #CVE202620272 #CVE202620267 #CyberSecurity #NetworkSecurity
##updated 2026-08-05T17:16:47.560000
2 posts
Cisco IOS XE vulnerability CVE-2026-20272 hits CVSS 9.8 and CVE-2026-20267 scores 9.0. Cisco urges customers to patch now.
#Cisco #IOSXE #CVE202620272 #CVE202620267 #CyberSecurity #NetworkSecurity
##Cisco IOS XE vulnerability CVE-2026-20272 hits CVSS 9.8 and CVE-2026-20267 scores 9.0. Cisco urges customers to patch now.
#Cisco #IOSXE #CVE202620272 #CVE202620267 #CyberSecurity #NetworkSecurity
##updated 2026-08-05T17:16:45.797000
1 posts
🟠 CVE-2026-18898 - High (8.8)
A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart results in stack-based buffer overflow. The attack can be l...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18898/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T16:17:05.093000
1 posts
🟠 CVE-2026-70619 - High (8.8)
Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session authentication...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70619/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T15:33:14
1 posts
Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption.
##updated 2026-08-05T15:32:29
2 posts
🟠 CVE-2026-71287 - High (8.8)
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex `preg_replace('/[^a-zA-Z0-9_().]/', '', $column)`. Because this allowlist retains letters, digits, underscore, parentheses, and dot (in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71287/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-71287 - High (8.8)
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex `preg_replace('/[^a-zA-Z0-9_().]/', '', $column)`. Because this allowlist retains letters, digits, underscore, parentheses, and dot (in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71287/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T15:32:29
2 posts
🟠 CVE-2026-71285 - High (8.1)
Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo `siteId` value as a bare, unquoted JavaScript expression inside a block rendered on every public status page: `_paq.push(['set...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71285/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-71285 - High (8.1)
Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo `siteId` value as a bare, unquoted JavaScript expression inside a block rendered on every public status page: `_paq.push(['set...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71285/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T15:32:29
2 posts
🟠 CVE-2026-71294 - High (7.6)
Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a `ci` POST parameter obtained via `cot_import('ci', 'P', 'TXT')` (tr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71294/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-71294 - High (7.6)
Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a `ci` POST parameter obtained via `cot_import('ci', 'P', 'TXT')` (tr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-71294/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T15:32:29
2 posts
CVE-2026-71289 (CRITICAL, CVSS 9.8): NASA-AMMOS ANMS exposes amp-manager REST API w/ no auth. Remote attackers can control system & disrupt ops. Restrict access, avoid default configs, check vendor for patches. https://radar.offseq.com/threat/cve-2026-71289-cwe-306-in-nasa-ammos-anms-e9bcfd162464d056 #OffSeq #CVE #NASA #Infosec
##CVE-2026-71289 (CRITICAL, CVSS 9.8): NASA-AMMOS ANMS exposes amp-manager REST API w/ no auth. Remote attackers can control system & disrupt ops. Restrict access, avoid default configs, check vendor for patches. https://radar.offseq.com/threat/cve-2026-71289-cwe-306-in-nasa-ammos-anms-e9bcfd162464d056 #OffSeq #CVE #NASA #Infosec
##updated 2026-08-05T15:32:20
1 posts
CVE-2026-71269 - Path traversal in Node-RED local-filesystem library storage. Authenticated users can read/write arbitrary files via GET/POST /library endpoints. CVSS 7.2. Unpatched - restrict access and monitor. #CVE #NodeRED #infosec
##updated 2026-08-05T15:32:14
1 posts
🟠 CVE-2026-67857 - High (7.5)
open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67857/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T15:32:14
1 posts
🟠 CVE-2026-67858 - High (7.5)
Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 requ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67858/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T15:32:09
1 posts
Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption.
##updated 2026-08-05T15:17:03.507000
4 posts
7 repos
https://github.com/paveg/rails-activestorage-vips-audit
https://github.com/Zer0SumGam3/CVE-2026-66066-POC
https://github.com/HackSpeak/CVE-2026-66066
https://github.com/0xsha/KindaRails2Shell
https://github.com/0xBlackash/CVE-2026-66066
Zero-Day to Zero Doubt: AI-Powered CVE Forensics in an Afternoon
Rails Active Storage의 CVE-2026-66066(KindaRails2Shell)는 libvips·libmatio의 파일 형식 해석 불일치를 악용해 조작된 업로드 파일로 서버 파일을 읽고, 비밀값 탈취 시 서명된 ID·쿠키 위조를 통한 RCE로 이어질 수 있는 취약점이다. Rails 팀은 패치와 함께 Claude Code용 에이전트 스킬 기반 포렌식 도구를 제공해, 노출 기간 산정과 Active Storage 내 악성 파일 헤더 탐지를 지원한다. 이 도구는 운영 DB...
##A critical KindaRails2Shell Rails RCE flaw (CVE-2026-66066) in Active Storage exposes servers to secret theft and remote code execution via image uploads.
#RubyOnRails #KindaRails2Shell #CVE202666066 #Cybersecurity #WebSecurity
##📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
Ruby on Rails warnt vor CVE-2026-66066 in Active Storage. Angreifer können über präparierte Bild-Uploads Dateien des Servers auslesen und so an Schlüssel oder Zugangsdaten gelangen. Betroffen sind Anwendungen mit libvips. Updates und forensische Prüfwerkzeuge stehen bereit.
1/2
##updated 2026-08-05T14:17:10.217000
1 posts
🟠 CVE-2026-68580 - High (7.5)
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can su...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68580/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T14:17:08.817000
1 posts
🟠 CVE-2026-66310 - High (7.7)
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66310/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T13:20:39.580000
1 posts
CVE-2026-18933 - Arbitrary file upload in WordPress wp-downloadmanager plugin. Admin-privileged RCE risk via unsanitized uploads. CVSS 7.2. Unpatched - disable plugin or restrict access now. #CVE #WordPress #infosec
##updated 2026-08-05T12:31:36
2 posts
Endlessdoors Is Phoning Home. Pick Up
VulnCheck은 Zbtlink 및 OEM 재브랜딩 라우터 약 20개 모델의 펌웨어에 부팅 시 자동 실행되는 ENDLESSDOORS 백도어가 포함됐다고 공개했다. 이 임플란트는 `kworker`라는 위장 프로세스로 외부 C2에 TCP 연결을 건 뒤, 인증·암호화·명령 검증 없이 수신한 명령을 root 권한으로 `popen()` 실행하며, `rctlbash` 명령으로 대화형 root 셸도 제공한다. 공격자는 C2 경로 또는 DNS 해석을 탈취하면 NAT 뒤의 라우터에도 아웃바운드 연결을 통해 접근할 수 있으며, 연구진은 CVE-2026-66747을 할당했다. 해당 장비는 신뢰할 수 없는 펌웨어로 간주해 모델 번호 기준 자산 조...
##Today, VulnCheck is disclosing #ENDLESSDOORS, a phone-home implant CTO @albinolobster discovered in Zbtlink routers. ENDLESSDOORS starts automatically, runs with root privileges, and attempts to connect to command-and-control infrastructure roughly every 35 seconds. The backdoor ships by default across 20+ Zbtlink router models, which are white-labeled and sold on popular retail sites including Amazon, AliExpress, and Alibaba.
The implant and server implement no encryption or verification, meaning anyone along the network path can hijack the client-server communication and obtain a root shell on the device, regardless of the router's network position.
The VulnCheck CNA has assigned CVE-2026-66747 to track backdoored firmware versions; our blog also has guidance for defenders, including affected firmware images, hashes, network indicators, a YARA rule, and network signatures (Suricata / Snort).
##updated 2026-08-05T12:31:36
1 posts
CVE-2026-71245 - SQL injection in Mautic via unsanitized field param in AjaxController. Improper validation leads to raw SQL concat. CVSS 7.1. Unpatched - update immediately. #CVE #Mautic #infosec
##updated 2026-08-05T12:31:34
1 posts
CVE-2026-71254: CRITICAL out-of-bounds write in debevv nanoMODBUS (≤v1.23.0). Unauthenticated FC 0x14 requests can cause memory corruption, leading to DoS or RCE — especially on embedded targets. Patch/mitigate now. https://radar.offseq.com/threat/cve-2026-71254-cwe-787-in-debevv-nanomodbus-649361bc8788d305 #OffSeq #CVE #ICS #infosec
##updated 2026-08-05T09:31:27
1 posts
CVE-2026-71214: NASA-AMMOS plandev sequencing-server has a CRITICAL vuln (CVSS 9.8) — unauthenticated users can inject commands by spoofing session roles or using whitelisted endpoints. Patch urgently. More: https://radar.offseq.com/threat/cve-2026-71214-cwe-306-missing-authentication-for-critical-function-in-nasa-ammos-plandev-sequencing-a69c1ea44211854b #OffSeq #Vuln #NASA #CyberSec #CVSS
##updated 2026-08-05T09:31:26
1 posts
CVE-2026-70378 - DoS via negative ratio in Rust imagecli carve. Panic on width<2 crashes process. CVSS 7.5. Unpatched - restrict input validation now. #CVE #Rust #infosec
##updated 2026-08-05T09:31:26
1 posts
CVE-2026-4431: CRITICAL vuln in Easy Post Submission ≤2.3.0 for WordPress. Missing auth lets unauthenticated attackers modify or unpublish any post via AJAX. No patch yet — disable plugin if possible. https://radar.offseq.com/threat/cve-2026-4431-cwe-862-missing-authorization-in-themeruby-easy-post-submission-frontend-posting-guest-a356c334d549556e #OffSeq #WordPress #Vuln #CVE20264431
##updated 2026-08-05T06:30:44
1 posts
Kadence Memberships (stellarwp) ≤4.0.0 suffers CRITICAL vuln (CVE-2026-9273, CVSS 9.3): attackers can hijack any account by poisoning password reset links. Restrict reset features & monitor for patches. https://radar.offseq.com/threat/cve-2026-9273-cwe-640-weak-password-recovery-mechanism-for-forgotten-password-in-stellarwp-membership-10c6cffc948a3c97 #OffSeq #WordPress #Vuln #Security
##updated 2026-08-05T05:17:15.823000
5 posts
3 repos
https://github.com/ywh-jfellus/CVE-2026-9198
🔵 THREAT INTELLIGENCE
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
Vulnerability | CRITICAL
CVEs: CVE-2026-9198
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV)...
Full analysis:
https://www.yazoul.net/news/article/cisa-flags-langflow-rce-tomcat-and-n-central-flaws-as-actively-exploited
by Yazoul AI
##IBM Langflow AI Platform Under Active Exploitation
A critical flaw in IBM's Langflow AI platform, tracked as CVE-2026-9198, is under active exploitation by hackers, who can use it to execute code remotely on vulnerable deployments. CISA has urged organizations to upgrade to Langflow OSS version 1.10.1 or later to mitigate the vulnerability.
##🚨 CISA KEV ALERT: CVE-2026-9198 identifies a critical unauthenticated code injection flaw in IBM Langflow allowing full RCE on default deployments. Active exploitation confirmed. Get the execution mechanics, CrowdStrike CQL detection, and compensating controls now: https://thecybermind.co/fi0v
##🚨 [CISA-2026:0804] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-18556 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18556)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: https://uptime.n-able.com/ ; https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-18556
⚠️ CVE-2026-34486 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-34486)
- Name: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Tomcat
- Notes: https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-34486
⚠️ CVE-2026-9198 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9198)
- Name: IBM Langflow Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: IBM
- Product: Langflow
- Notes: https://www.ibm.com/support/pages/node/7278927 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-9198
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260804 #cisa20260804 #cve_2026_18556 #cve_2026_34486 #cve_2026_9198 #cve202618556 #cve202634486 #cve20269198
##CVE ID: CVE-2026-9198
Vendor: IBM
Product: Langflow
Date Added: 2026-08-04
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9198
updated 2026-08-05T05:17:02.413000
1 posts
A critical Veeam Service Provider Console flaw lets attackers steal agent credentials, while a second enables remote code execution. Update to 9.3 now.
#Veeam #VSPC #ServiceProviderConsole #CVE202658073 #RCE #RemoteCodeExecution #Vulnerability #MSP #CyberSecurity #InfoSec
https://securityonline.info/veeam-vspc-cve-2026-58073/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-05T05:16:46.967000
6 posts
🚨 CISA KEV ALERT: CVE-2026-18556 exposes N-able N-central installations to authentication bypass via alternate channel paths. Active exploitation confirmed. Get the forensic breakdown, Splunk/KQL/Chronicle detection logic, and hardening guidance now: https://thecybermind.co/radr
##🚨 CISA KEV ALERT: CVE-2026-18556 exposes N-able N-central installations to authentication bypass via alternate channel paths. Active exploitation confirmed. Get the forensic breakdown, Splunk/KQL/Chronicle detection logic, and hardening guidance now: https://thecybermind.co/radr
##🚨 [CISA-2026:0804] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-18556 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18556)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: https://uptime.n-able.com/ ; https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-18556
⚠️ CVE-2026-34486 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-34486)
- Name: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Tomcat
- Notes: https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-34486
⚠️ CVE-2026-9198 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9198)
- Name: IBM Langflow Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: IBM
- Product: Langflow
- Notes: https://www.ibm.com/support/pages/node/7278927 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-9198
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260804 #cisa20260804 #cve_2026_18556 #cve_2026_34486 #cve_2026_9198 #cve202618556 #cve202634486 #cve20269198
##CVE ID: CVE-2026-18556
Vendor: N-able
Product: N-central
Date Added: 2026-08-04
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18556
CISA added this vulnerability to the catalogue yesterday, if you missed it:
CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-18577
Arctic Wolf: CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching https://arcticwolf.com/resources/blog/cve-2026-18556-cve-2026-18577/ #infosec #vulnerability #CISA
##🏆 New Achievement! Management Remotely Destroyed!
Today's dungeon crawl is brought to you by Deferred Patch Tuesdays — when you're too busy managing clients to manage yourself. N-able N-central, the RMM platform MSPs trust to run everyone else's networks, is harboring CVE-2026-18556, a CVSS 9.8 authentication bypass being actively exploited in the wild. Attackers are waltzing — no, sorry — strolling right through, dropping Cloudflare tunnels for cozy, persistent access. (1/2)
##updated 2026-08-05T03:30:28
1 posts
🟠 CVE-2026-18897 - High (8.8)
A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of the argument tempName leads to stack-based buffer overflow. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18897/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T03:30:28
1 posts
🟠 CVE-2026-18895 - High (8.8)
A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argument cipher results in stack-based buffer overflow. It is possible to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18895/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T00:30:46
1 posts
🟠 CVE-2026-67859 - High (7.5)
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67859/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-05T00:30:39
1 posts
🟠 CVE-2026-67861 - High (7.5)
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67861/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T23:16:51.687000
1 posts
🔴 CVE-2026-45537 - Critical (9.1)
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI components (protocol, username, domain, port, params) into a fixed 1024-byte gl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45537/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T21:30:42
1 posts
MaxSite CMS 0.78 is vulnerable (CVE-2026-70554, CRITICAL): PHP object injection via maxsite_comuser cookie enables unauthenticated RCE. No patch available. Restrict access, deploy WAF, and monitor activity. https://radar.offseq.com/threat/cve-2026-70554-deserialization-of-untrusted-data-in-maxsite-maxsite-cms-e8db7f34d62a5e30 #OffSeq #Vuln #CMS #PHP #RCE
##updated 2026-08-04T21:30:37
2 posts
CVE-2026-70553: CRITICAL RCE in MaxSite CMS 105.2 (CVSS 9.3). Attackers can inject PHP via POST to the install endpoint, gaining persistent code exec as www-data. Restrict endpoint & monitor traffic until patched. Details: https://radar.offseq.com/threat/cve-2026-70553-improper-control-of-generation-of-code-code-injection-in-maxsite-maxsite-cms-5161bdfb2e6804e9 #OffSeq #CVE #websecurity #RCE
##🔴 CVE-2026-70553 - Critical (9.8)
MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70553/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T21:30:29
1 posts
🔴 CVE-2026-69703 - Critical (9.8)
Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69703/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T20:46:44.650000
1 posts
🔴 CVE-2026-66803 - Critical (10)
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66803/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T20:16:52.160000
1 posts
🔴 CVE-2026-49435 - Critical (9.8)
Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49435/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T20:02:04
1 posts
🟠 CVE-2026-70486 - High (8.2)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files served from...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70486/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T19:52:03
1 posts
🟠 CVE-2026-70482 - High (8.1)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it by calling ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70482/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T19:37:38
1 posts
FlowiseAI Flowise (<3.1.3) has a CRITICAL vuln (CVE-2026-70478): unauthenticated POST endpoint leaks refreshed OAuth tokens if credential ID is known. Upgrade to 3.1.3+ ASAP. https://radar.offseq.com/threat/cve-2026-70478-cwe-200-exposure-of-sensitive-information-to-an-unauthorized-actor-in-flowiseai-flowise-2c912baff770743c #OffSeq #CVE202670478 #OAuth #infosec
##updated 2026-08-04T19:29:28
1 posts
FlowiseAI Flowise <3.1.3 is affected by CRITICAL CVE-2026-70477 (code injection, CVSS 9.5). Exploitation via CSV Agent node allows arbitrary Python execution. Patch to 3.1.3+ ASAP. https://radar.offseq.com/threat/cve-2026-70477-cwe-94-improper-control-of-generation-of-code-code-injection-in-flowiseai-flowise-52ff32a90a84fd22 #OffSeq #Infosec #CVE #AppSec
##updated 2026-08-04T19:16:45.433000
1 posts
CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation
Bulletin ID: 2026-073-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 10:00 AM PDT
Description:
We have identified CVE-2026-18830 in the Amazon Bedrock AgentCore harness InvokeHarness API...
https://aws.amazon.com/security/security-bulletins/rss/2026-073-aws/
##updated 2026-08-04T18:32:27
1 posts
CVE-2026-15958 (CRITICAL): Easy Integration for Dropbox <2.2.0 suffers from missing authorization, letting unauthenticated users manage Dropbox files and access account emails. Patch or disable plugin. https://radar.offseq.com/threat/cve-2026-15958-cwe-862-missing-authorization-in-easy-integration-for-dropbox-50b9554583db42aa #OffSeq #WordPress #CVE #Security
##updated 2026-08-04T18:31:37
1 posts
NVIDIA Dynamo Code Execution Flaw CVE-2026-24254 CVSS 9.8
##updated 2026-08-04T18:31:36
1 posts
A critical Veeam ONE vulnerability, CVE-2026-64633, allows remote unauthenticated code execution at CVSS 10.0. Update to build 13.1.0.7034 now.
#Veeam #VeeamONE #CVE202664633 #RCE #RemoteCodeExecution #Vulnerability #CVSS10 #PatchNow #CyberSecurity #InfoSec
##updated 2026-08-04T18:31:31
2 posts
Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920) https://syntetisk.tech/blog/posts/stored-xss-in-djangos-admin-via-an-unvalidated-urlfield-display-path-cve-2026-15920/
##Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920) https://syntetisk.tech/blog/posts/stored-xss-in-djangos-admin-via-an-unvalidated-urlfield-display-path-cve-2026-15920/
##updated 2026-08-04T18:31:31
1 posts
A high-severity Django vulnerability, CVE-2026-15307, can enable remote code execution through spatial lookups. Update to Django 6.0.8 or 5.2.17 now.
#Django #DjangoSecurity #CVE202615307 #RCE #RemoteCodeExecution #Vulnerability #Python #WebSecurity #InfoSec #CyberSecurity
##updated 2026-08-04T18:31:31
1 posts
🟠 CVE-2026-24084 - High (7.5)
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-24084/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T18:31:31
1 posts
🟠 CVE-2026-24083 - High (7.8)
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-24083/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T18:31:31
1 posts
🟠 CVE-2026-25292 - High (7.6)
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-25292/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T18:31:31
1 posts
🟠 CVE-2026-69100 - High (8.8)
LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitel...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69100/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T18:31:31
1 posts
🔴 CVE-2026-69098 - Critical (9.8)
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T17:16:59.733000
1 posts
🔴 CVE-2026-69110 - Critical (9.1)
OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69110/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T17:16:47.273000
1 posts
CVE-2026-18684 | CRITICAL command injection in GL.iNet GL-MT3000 (fw 4.4.0 – 4.4.5) 🛡️ Remote attackers can execute commands — no patch yet. Restrict access and watch for vendor updates. Info: https://radar.offseq.com/threat/cve-2026-18684-command-injection-in-glinet-gl-mt3000-4a4de87391e0f428 #OffSeq #CVE202618684 #IoTSecurity
##updated 2026-08-04T16:16:25.497000
1 posts
🔴 CVE-2026-48326 - Critical (9.9)
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48326/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T16:16:21.593000
1 posts
CVE-2026-18686: CRITICAL command injection in GL.iNet GL-MT3000 (4.4.0 – 4.4.5). Remote, unauthenticated code execution possible — no patch yet. Limit admin interface exposure & monitor for abuse. https://radar.offseq.com/threat/cve-2026-18686-command-injection-in-glinet-gl-mt3000-14534eb705079787 #OffSeq #CVE #RouterSecurity
##updated 2026-08-04T15:33:20
12 posts
1 repos
🚨 [CISA-2026:0804] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-18556 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18556)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: https://uptime.n-able.com/ ; https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-18556
⚠️ CVE-2026-34486 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-34486)
- Name: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Tomcat
- Notes: https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-34486
⚠️ CVE-2026-9198 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9198)
- Name: IBM Langflow Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: IBM
- Product: Langflow
- Notes: https://www.ibm.com/support/pages/node/7278927 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-9198
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260804 #cisa20260804 #cve_2026_18556 #cve_2026_34486 #cve_2026_9198 #cve202618556 #cve202634486 #cve20269198
##New.
Rapid7: CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild/ @Rapid7Official #infosec #vulnerabiity
##CISA added this vulnerability to the catalogue yesterday, if you missed it:
CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-18577
Arctic Wolf: CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching https://arcticwolf.com/resources/blog/cve-2026-18556-cve-2026-18577/ #infosec #vulnerability #CISA
##Geopolitical: Trump indicates ongoing talks with Iran for Strait of Hormuz reopening (Aug 3-4), though Tehran denies. Gaza operations persist.
Technology: SK hynix & Sandisk unveil HBF standard for AI memory (Aug 4). White House schedules AI safety talks (Aug 4).
Cybersecurity: CISA alerts to active exploitation of N-able N-central flaw (CVE-2026-18577) (Aug 3). Interpol: AI fuels over 55% of African cybercrime (Aug 3).
#AnonNews_irc #Cybersecurity #News
URGENT C-SUITE BRIEF: Active exploitation verified on CISA KEV for CVE-2026-18577 (N-able N-central). Executive leadership must oversee immediate patch deployment, supply chain auditing, and trust model revalidation to safeguard organizational assets. Full strategic analysis: https://thecybermind.co/0156
##N-able warns of N-central auth bypass flaw exploited in attacks
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-...
🔗️ [Bleepingcomputer] https://link.is.it/tS9UYV
##N-able warns of N-central auth bypass flaw exploited in attacks
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-...
🔗️ [Bleepingcomputer] https://www.bleepingcomputer.com/news/security/n-able-warns-of-n-central-auth-bypass-flaw-exploited-in-attacks/
##ALERT: Active exploitation verified for CVE-2026-18577 in N-able N-central. Unauthenticated attackers can execute account takeovers via alternate path manipulation. Access our complete threat breakdown, SPL/KQL detection logic, and hardening guidance here: https://thecybermind.co/jily
##🚨 [CISA-2026:0803] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0803)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-18577 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18577)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF1_Release_Notes.htm ; https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-18577
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260803 #cisa20260803 #cve_2026_18577 #cve202618577
##CVE ID: CVE-2026-18577
Vendor: N-able
Product: N-central
Date Added: 2026-08-03
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18577
CVE-2026-18577 is being exploited in the wild for N-central account takeover. An incomplete patch let attackers gain admin access. Update to 2026.3.1.7.
#Nable #Ncentral #CVE202618577 #AccountTakeover #RMM #CyberSecurity
##Some time ago I discovered a meddler in the middle vulnerability between N-able agent and nCentral server that allowed full SYSTEM compromise of the endpoints, but this vulnerability in nCentral server is far far far worse:
https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/
##updated 2026-08-04T15:32:29
1 posts
Eclipse Milo (0.6.0 – 1.1.4) faces a CRITICAL flaw (CVE-2026-60007): error messages in username-token RSA PKCS#1 v1.5 handling enable padding oracle attacks, risking password compromise. Patch status unclear. https://radar.offseq.com/threat/cve-2026-60007-cwe-204-in-eclipse-foundation-eclipse-milo-bf23a775f0392e71 #OffSeq #EclipseMilo #Vuln #Infosec
##updated 2026-08-04T14:50:12.360000
1 posts
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:
- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.
https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/
##updated 2026-08-04T14:50:12.360000
2 posts
1 repos
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:
- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.
https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/
##CVE-2026-58062 (CRITICAL, CVSS 9.3): Bouncy Castle Java improperly validates stapled OCSP, risking cert trust. Affects =1.66, <1.85, LTS <2.73.12. Update to 1.85+ or LTS 2.73.12. Details: https://radar.offseq.com/threat/cve-2026-58062-cwe-295-improper-certificate-validation-in-legion-of-the-bouncy-castle-inc-bc-java-1fb42d02f3400e15 #OffSeq #BouncyCastle #JavaSecurity
##updated 2026-08-04T14:48:22.933000
1 posts
Adobe patched critical Adobe Campaign Classic flaws. CVE-2026-48331 scores CVSS 10.0 and enables arbitrary code execution. Update to build 9399 now.
#Adobe #AdobeCampaignClassic #CVE202648331 #ArbitraryCodeExecution #Vulnerability #SSRF #SQLInjection #InfoSec #CyberSecurity
##updated 2026-08-04T14:16:30.620000
1 posts
🔴 CVE-2026-15721 - Critical (9.8)
Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection.
This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T12:34:56
2 posts
🔴 CVE-2026-14175 - Critical (9.8)
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.
This issue affects HUMANIST Digital Human Resources: from...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14175/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-14175 (CRITICAL, CVSS 9.8): HUMANIST Digital HR v26.0 has an unrestricted file upload flaw — attackers can deploy web shells for full compromise. No patch yet. Restrict uploads, monitor, and apply network controls. https://radar.offseq.com/threat/cve-2026-14175-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-bilin-software-and-caf423644ef42f8e #OffSeq #Vuln #AppSec
##updated 2026-08-04T12:34:56
2 posts
🔴 CVE-2026-14804 - Critical (9.1)
Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable.
This issue affects HUMANIST Digital Human Resources: from ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14804/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-14804: CRITICAL (CVSS 9.1) in HUMANIST Digital HR v26.0 🛡️ Hard-coded cryptographic key (CWE-321) allows data exposure & integrity loss. No official fix — limit access & track vendor updates. https://radar.offseq.com/threat/cve-2026-14804-cwe-321-use-of-hard-coded-cryptographic-key-in-bilin-software-and-informatics-7feb29c78f0c5d49 #OffSeq #Vulnerability #CVE202614804
##updated 2026-08-04T12:31:51.160000
1 posts
1 repos
pgAdmin 4 RCE Flaw Leads Three Critical Fixes in Version 9.17
##updated 2026-08-04T09:31:41
1 posts
CVE-2026-18754: GeoVision GV-AS1620 (GV-Cloud) v1.16 has a CRITICAL bug — static RSA key in firmware lets attackers decrypt HTTPS & spoof server. No fix yet; restrict access & watch for vendor updates. https://radar.offseq.com/threat/cve-2026-18754-cwe-321-use-of-hard-coded-cryptographic-key-in-geovision-inc-gv-as1620-gv-cloud-c051119ceee7e889 #OffSeq #Vuln #Cybersecurity #TLS
##updated 2026-08-04T03:31:16
1 posts
CVE-2026-6837 - Post-auth command injection in Zyxel WAX650S export-cgi. Admin RCE. CVSS 7.2. Unpatched - restrict admin access now. #CVE #Zyxel #infosec
##updated 2026-08-04T00:35:57
1 posts
Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption.
##updated 2026-08-04T00:35:01
1 posts
CVE-2026-48333 (CRITICAL, CVSS 9.8): Incorrect Authorization in Adobe Campaign Classic enables attackers to escalate privileges without user interaction. No patch info yet — monitor vendor updates. https://radar.offseq.com/threat/cve-2026-48333-incorrect-authorization-cwe-863-in-adobe-adobe-campaign-classic-c17f18d3ff17c03b #OffSeq #Adobe #Security #CVE202648333
##updated 2026-08-04T00:35:01
2 posts
Adobe Campaign Classic is impacted by CVE-2026-48323 (CRITICAL, CVSS 10). Improper neutralization in the template engine allows remote code execution — no user interaction needed. No patch yet. Monitor advisories: https://radar.offseq.com/threat/cve-2026-48323-improper-neutralization-of-special-elements-used-in-a-template-engine-cwe-1336-in-adobe-9070fce8af299a9b #OffSeq #Adobe #Vuln #CVE202648323
##🔴 CVE-2026-48323 - Critical (10)
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vul...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48323/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T00:35:01
1 posts
🟠 CVE-2026-66318 - High (8.1)
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66318/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T00:35:01
1 posts
CVE-2026-18685: CRITICAL command injection in GL.iNet GL-MT3000 (4.4.0 – 4.4.5). Remote, unauthenticated RCE possible. No patch yet — restrict access & monitor for abuse. Details: https://radar.offseq.com/threat/cve-2026-18685-command-injection-in-glinet-gl-mt3000-32060ee21fb81c76 #OffSeq #vuln #IoT #infosec
##updated 2026-08-04T00:35:01
1 posts
🔴 CVE-2026-48330 - Critical (10)
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could e...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48330/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-04T00:34:55
1 posts
🟠 CVE-2026-66315 - High (7.5)
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66315/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T21:31:44
1 posts
🟠 CVE-2026-59913 - High (7.8)
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59913/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T21:31:36
1 posts
🟠 CVE-2026-59912 - High (7.8)
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59912/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T21:31:35
1 posts
CVE-2026-18108 - Critical auth bypass in Perl Net::SAML2. Encrypted assertions without signatures accepted. CVSS 9.8. Upgrade to >=0.86 now. #CVE #Perl #infosec
##updated 2026-08-03T20:29:52
1 posts
🔴 CVE-2026-69240 - Critical (9.8)
Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69240/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T20:17:15.910000
1 posts
CVE-2026-18589 (CRITICAL, CVSS 9.3) in Wavlink WL-NU516U1: Stack buffer overflow in nas.cgi enables unauthenticated RCE/DoS. Patch available — update ASAP. https://radar.offseq.com/threat/cve-2026-18589-stack-based-buffer-overflow-in-wavlink-wl-nu516u1-be242f6f491145cd #OffSeq #CVE202618589 #IoTSecurity #PatchManagement
##updated 2026-08-03T19:16:45.200000
1 posts
🔴 CVE-2026-18614 - Critical (9.8)
A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18614/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T18:31:51
1 posts
CVE-2026-16300: ChamaWP (<1.0.13) is vulnerable to missing authorization — attackers can reset any user’s password, including admins. Risk: full site takeover. Patch status unconfirmed; restrict password resets & monitor logs. https://radar.offseq.com/threat/cve-2026-16300-cwe-862-missing-authorization-in-chamawp-fe7ac84163659c18 #OffSeq #WordPress #Vuln
##updated 2026-08-03T15:32:49
2 posts
CVE-2026-18574 is a Check Point authentication bypass rated CVSS 9.3, letting attackers run commands as admin. Patch via the latest Jumbo Hotfix.
#CheckPoint #CVE202618574 #AuthenticationBypass #SecurityManagement #CyberSecurity #Firewall
##CRITICAL auth bypass (CVE-2026-18574, CVSS 9.3) affects Check Point Security Management Server & MDS. Remote attackers can execute commands w/o auth. No patch yet — restrict management access. https://radar.offseq.com/threat/cve-2026-18574-cwe-288-authentication-bypass-using-an-alternate-path-or-channel-in-checkpoint-security-b30ba167a9a0b365 #OffSeq #CVE202618574 #CheckPoint #Infosec 🔒
##updated 2026-08-03T12:32:43
3 posts
📢 [VULN] WAPT Server : cette faille permet de contourner l'authentification (CVE-2026-33591)
La faille de sécurité CVE-2026-33591 affecte certaines versions de WAPT Server, la solution de déploiement logiciel éditée par Tranquil IT. En l'exploitant, un attaquant distant non authentifié peut contourner une restriction de sécurité et récupérer un jeton de session valide pour le compte ciblé.
🔗 https://www.it-connect.fr/wapt-server-cve-2026-33591/
💬 discussion : https://infosec.pub/post/50502015
#Vulnérabilité #CVE #Cyberveille
WAPT Server (CVE-2026-33591) : une faille permet de contourner l’authentification https://www.it-connect.fr/wapt-server-cve-2026-33591/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
##Tranquil IT WAPT Server 2.6.0.16767 hit by CVE-2026-33591 (CRITICAL, CVSS 10). Remote attackers can bypass authentication & grab session tokens via crafted packets. No patch yet — restrict access & monitor logs. https://radar.offseq.com/threat/cve-2026-33591-cwe-288-authentication-bypass-using-an-alternate-path-or-channel-in-tranquil-it-systems-98c0bb813dbf7caa #OffSeq #CVE202633591 #Infosec #Vulnerability
##updated 2026-08-03T09:32:46
1 posts
#OT #Advisory VDE-2026-065
Endress+Hauser: iDTM Debug Interface Vulnerability in the FDI Package Library
A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory.
#CVE CVE-2026-9593
https://certvde.com/en/advisories/vde-2026-065/
#CSAF https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-065.json
##updated 2026-08-03T09:32:36
1 posts
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:
- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.
https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/
##updated 2026-08-03T09:32:36
2 posts
1 repos
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:
- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.
https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/
##CVE-2026-8763: CRITICAL vuln in Bouncy Castle BC-JAVA (<1.85, 2.73.0-2.73.11). Improper cert validation via trailing dot bypasses name constraints — risk of MITM attacks. No patch yet. Monitor vendor for updates. https://radar.offseq.com/threat/cve-2026-8763-cwe-295-improper-certificate-validation-in-legion-of-the-bouncy-castle-inc-bc-java-e499664fa1a18bc4 #OffSeq #BouncyCastle #Vuln #CVE20268763
##updated 2026-08-03T09:32:36
1 posts
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:
- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.
https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/
##updated 2026-08-03T08:17:20.920000
1 posts
Simple Flatpak sandbox escape through pipewire:
1. Missing auth 2. Insecure default module loader
Vulns like these do not exist because devs lack the capability to look for them, but they lack the capacity.
I predict this class of issue will soon™️ cease to exist. LLM harnesses like the one used by Johann are getting productized at scale currently. The question is just how cheap can we make them and how quickly can we get them into CI pipelines.
https://embracethered.com/blog/posts/2026/pipewire-flatpak-linux-sandbox-escape-cve-2026-5674/
updated 2026-08-03T06:32:44
1 posts
Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:
- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.
https://www.bouncycastle.org/resources/new-release-bouncy-castle-java-1-85/
##updated 2026-08-03T06:32:44
1 posts
1 repos
BC-JAVA users: CVE-2026-59650 (CRITICAL, CVSS 9.3) exposes MTI/A0 Diffie-Hellman via improper input validation. Affects <1.85, 2.73.0 – 2.73.11. No patch yet — avoid affected versions & monitor for updates. https://radar.offseq.com/threat/cve-2026-59650-cwe-20-improper-input-validation-in-legion-of-the-bouncy-castle-inc-bc-java-bfb9720e803b614a #OffSeq #Vulnerability #Java #Cryptography
##updated 2026-08-03T06:32:44
1 posts
1 repos
CVE-2026-59638 (CRITICAL, CVSS 9.3) in BC-JAVA: Improper cert validation due to default CN-fallback can expose TLS connections to MITM. Affects <1.85, LTS <2.73.12. Patch status unknown — monitor vendor & consider disabling fallback. https://radar.offseq.com/threat/cve-2026-59638-cwe-297-improper-validation-of-certificate-with-host-mismatch-in-legion-of-the-bouncy-aa319f6f20b27a8a #OffSeq #CVE202659638 #infosec
##updated 2026-08-03T00:30:35
1 posts
🟠 CVE-2026-3245 - High (7.5)
A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-3245/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T15:30:21
1 posts
🟠 CVE-2025-71399 - High (8.6)
Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71399/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T09:30:23
2 posts
4 repos
https://github.com/mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool
https://github.com/HackSpeak/CVE-2026-64531
https://thecybersecguru.com/news/ovswrap-cve-2026-64531-linux-kernel-openvswitch-root-vulnerability/
##Linux Flaw Exposes Local Users to Root via Open vSwitch
A newly discovered Linux flaw, CVE-2026-64531, lets local users potentially gain root access via Open vSwitch, even without an existing OVS bridge, running ovs-vswitchd, or host-level CAP_NET_ADMIN privileges. This vulnerability, with a CVSS score of 7.8, was quickly patched after being responsibly disclosed.
#Cve202664531 #OpenVswitch #LinuxKernel #MemoryCorruption #Ovswrap
##updated 2026-08-01T00:31:02
2 posts
CVE-2026-9044 is a command injection flaw in TP-Link Archer AXE75 OpenVPN, CVSS 8.5. Update to firmware 1.5.6 Build 20260623 now.
#TPLink #CVE20269044 #CommandInjection #OpenVPN #RouterSecurity #CyberSecurity
##CVE-2026-9044 is a command injection flaw in TP-Link Archer AXE75 OpenVPN, CVSS 8.5. Update to firmware 1.5.6 Build 20260623 now.
#TPLink #CVE20269044 #CommandInjection #OpenVPN #RouterSecurity #CyberSecurity
##updated 2026-08-01T00:17:17.750000
1 posts
2 repos
🔴 CVE-2026-63223 - Critical (9.8)
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an applicat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63223/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:32:56
1 posts
🔴 CVE-2025-69935 - Critical (9.8)
CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-69935/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:32:56
1 posts
🟠 CVE-2026-14319 - High (7.5)
The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their n...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14319/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:32:55
1 posts
🔴 CVE-2025-69933 - Critical (9.8)
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-69933/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:32:55
1 posts
🟠 CVE-2026-43831 - High (7.5)
Full details and mitigation steps are currently restricted and will be published at a later date.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43831/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:31:54
1 posts
🔴 CVE-2026-43830 - Critical (9.8)
Full details and mitigation steps are currently restricted and will be published at a later date.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43830/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:31:53
1 posts
🔴 CVE-2025-69936 - Critical (9.8)
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-69936/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T20:16:52.487000
1 posts
🟠 CVE-2026-56673 - High (7.5)
ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56673/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T20:16:50.777000
1 posts
🟠 CVE-2026-43832 - High (7.5)
Full details and mitigation steps are currently restricted and will be published at a later date.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43832/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T20:16:50.317000
1 posts
🟠 CVE-2026-43829 - High (7.5)
Full details and mitigation steps are currently restricted and will be published at a later date.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43829/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:17:03.113000
1 posts
🔴 CVE-2025-69934 - Critical (9.8)
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-69934/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:33:20
1 posts
1 repos
https://github.com/webshellseo8/CVE-2026-12720-Proof-of-Concept
🟠 CVE-2026-12720 - High (7.5)
The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12720/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:33:20
1 posts
🟠 CVE-2026-12695 - High (8.1)
The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12695/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:33:20
1 posts
🟠 CVE-2026-12721 - High (8.6)
The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:33:17
2 posts
Six SGLang vulnerabilities include unauthenticated RCE via CVE-2026-15969, plus data and model-weight theft. No patch exists yet.
#SGLang #RCE #LLMSecurity #CVE202615969 #InfoSec
https://securityonline.info/sglang-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social
##Six SGLang vulnerabilities include unauthenticated RCE via CVE-2026-15969, plus data and model-weight theft. No patch exists yet.
#SGLang #RCE #LLMSecurity #CVE202615969 #InfoSec
https://securityonline.info/sglang-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-07-31T18:32:25
1 posts
1 repos
CVE-2026-58048: cPanel Root SQL Execution Flaw Patched
##updated 2026-07-31T18:32:17
1 posts
🔴 CVE-2026-14919 - Critical (9.8)
The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to red...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14919/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:32:13
1 posts
🔴 CVE-2026-35847 - Critical (9.8)
An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-35847/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:17:09.777000
1 posts
🟠 CVE-2026-12251 - High (8.1)
The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12251/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T17:16:32.347000
1 posts
🟠 CVE-2026-13609 - High (8.8)
The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauth...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13609/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T16:16:56.643000
1 posts
🔴 CVE-2025-69937 - Critical (9.8)
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-69937/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T15:33:51
1 posts
🟠 CVE-2026-14333 - High (7.5)
The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14333/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T14:16:46.133000
1 posts
🟠 CVE-2026-14830 - High (7.5)
The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without pa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14830/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T12:31:33
2 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
🔴 CVE-2026-38709 - Critical (9.8)
TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulne...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-38709/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T12:30:30
1 posts
🔴 CVE-2026-52539 - Critical (9.1)
Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52539/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T09:31:25
1 posts
2 repos
🔴 CVE-2026-14483 - Critical (9.8)
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14483/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T00:30:29
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-31T00:30:29
1 posts
🟠 CVE-2026-12562 - High (8.8)
The RCU II+ and Multiload II+ are vulnerable to an unauthenticated
service that exposes a debug interface granting full root-level access
to the embedded system. This vulnerability stems from a
network-accessible port running a Target Communica...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12562/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T21:31:57
1 posts
1 repos
🔴 CVE-2026-66418 - Critical (9.3)
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is reco...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66418/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T21:31:50
2 posts
IBM critical vulnerabilities hit App Connect, Power HMC, and webMethods. CVE-2026-12943 lets attackers execute arbitrary commands at CVSS 9.8.
##IBM critical vulnerabilities hit App Connect, Power HMC, and webMethods. CVE-2026-12943 lets attackers execute arbitrary commands at CVSS 9.8.
##updated 2026-07-30T21:31:47
1 posts
Ok, the first one is absolutely it:
##Furthermore, we deploy MLG-UAF to conduct large-scale security auditing on mainstream open-source software such as libtiff, LibRaw, SQLite, ImageMagick and Zephyr RTOS. In real-world industrial source code scanning, our framework successfully discovered 17 unique confirmed UAF vulnerabilities assigned with independent Common Vulnerabilities and Exposures (CVE) IDs (CVE-2026 series, RESERVED and not yet publicized), covering cross-functional kernel UAF, intra-procedural cache UAF, race-condition UAF and multimedia parsing UAF scenarios.Real CVE case studies on CVE-2026-51291 (SQLite JSON cache flaw) and CVE-2023-32233 (Linux netfilter kernel vulnerability) demonstrate that MLG-UAF can precisely capture the fixed free-then-use spatial topological fingerprint of UAF defects and accurately resolve ambiguous multi-level pointer aliasing, even under heavy control-flow obfuscation.
updated 2026-07-30T19:10:52.250000
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-30T19:07:59.843000
1 posts
New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##updated 2026-07-30T16:17:15.183000
1 posts
New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##updated 2026-07-30T15:31:54
1 posts
New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##updated 2026-07-30T15:31:54
1 posts
New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##updated 2026-07-30T15:31:50
1 posts
New;
Broadcom has released advisories relating to several high and medium-severity vulnerabilities https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Nvidia:
CRITICAL: NVIDIA Dynamo - July 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5842
NVIDIA Triton Inference Server - June 2026 https://nvidia.custhelp.com/app/answers/detail/a_id/5860 #Nvidia
Dell:
Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities https://www.dell.com/support/kbdoc/en-us/000450699/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities #Dell #Apache
Google:
This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 #google #infosec #vulnerability
##updated 2026-07-30T14:18:46.477000
1 posts
1 repos
https://github.com/BiiTts/CVE-2026-54917-SeaweedFS-Cross-Bucket-Traversal
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-30T14:18:46.477000
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-30T14:12:18.697000
1 posts
A TP-Link TL-WR940N flaw, CVE-2026-12935, allows unauthenticated remote code execution via an RTSP stack buffer overflow. Update the router firmware now.
#TPLink #TLWR940N #CVE202612935 #RCE #RouterSecurity #InfoSec
##updated 2026-07-30T14:08:23.057000
1 posts
Hcsec-2026-23: Multiple vulnerabilities impacting HashiCorp Terraform MCP Server
HashiCorp Terraform MCP Server 0.2.1~1.0.0의 streamable-HTTP 전송 계층에서 SSRF 및 멀티테넌트 자격증명 격리 실패를 포함한 3건의 취약점이 발견됐습니다. CVE-2026-14869는 인증 없이 쿼리 파라미터로 Terraform 엔드포인트를 바꿔 서버의 bearer token을 공격자 서버로 유출할 수 있는 SSRF이며, CVE-2026-16496은 stateful 모드에서 탈취한...
##updated 2026-07-30T14:08:23.057000
1 posts
Hcsec-2026-23: Multiple vulnerabilities impacting HashiCorp Terraform MCP Server
HashiCorp Terraform MCP Server 0.2.1~1.0.0의 streamable-HTTP 전송 계층에서 SSRF 및 멀티테넌트 자격증명 격리 실패를 포함한 3건의 취약점이 발견됐습니다. CVE-2026-14869는 인증 없이 쿼리 파라미터로 Terraform 엔드포인트를 바꿔 서버의 bearer token을 공격자 서버로 유출할 수 있는 SSRF이며, CVE-2026-16496은 stateful 모드에서 탈취한...
##updated 2026-07-30T03:31:28
1 posts
Adobe fixes a CVSS 10 RCE in Campaign Classic (CVE-2026-48449) and eight critical flaws in Bridge. Update to build 9398 and Bridge 15.1.7 or 16.0.6 now.
#AdobeCampaign #CVE202648449 #AdobeBridge #CriticalPatch #RCE
##updated 2026-07-29T21:31:08
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-29T21:31:00
2 posts
Broadcom has addressed several vulnerabilities published yesterday, all of them ranked high-severity https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Cisco has a new advisory for a critical vulnerability that was published yesterday:
CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
This addresses a vulnerability that was first published on July 29:
High: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh @TalosSecurity #Cisco #infosec #vulnerability
##Broadcom has addressed several vulnerabilities published yesterday, all of them ranked high-severity https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Cisco has a new advisory for a critical vulnerability that was published yesterday:
CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
This addresses a vulnerability that was first published on July 29:
High: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh @TalosSecurity #Cisco #infosec #vulnerability
##updated 2026-07-29T21:30:47
1 posts
1 repos
A Linux kernel vulnerability, CVE-2026-53264, lets a local user run arbitrary code via a net/sched use-after-free. A public PoC is now available.
#CVE202653264 #LinuxKernel #UseAfterFree #PrivilegeEscalation #InfoSec
##updated 2026-07-29T18:31:46
1 posts
Pre-Auth Stack Buffer Overflow Hits Xlight FTP Server (CVE-2026-67192)
https://securityonline.info/xlight-ftp-cve-2026-67192/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-07-29T12:31:30
1 posts
Fluent Forms CVE-2026-16655 scores 7.2 on the CVSS scale — High severity — and allows data manipulation or extraction without admin credentials. If my sites were running Fluent Forms below 6.2.8, updating would be my immediate priority. Check your version now and update to 6.2.8.
#WordPress #WordPressSecurity #FluentForms #CVE #WebSecurity
##updated 2026-07-28T21:31:39
2 posts
Veeam, HashiCorp, Django Patch Flaws
A critical security flaw, CVE-2026-16498, with a perfect CVSS score of 10.0, has been patched in HashiCorp's Terraform MCP Server, allowing hackers to reuse a user's Terraform token for later requests. This bug, now fixed in version 1.1.0, has also prompted patches from Veeam and Django.
https://osintsights.com/veeam-hashicorp-django-patch-flaws?utm_source=mastodon&utm_medium=social
#TerraformSecurityFlaws #Hashicorp #Veeam #Django #Geodjango
##Terraform MCP Server Flaw CVE-2026-16498 Scores CVSS 10.0
##updated 2026-07-28T12:31:27
1 posts
CVE-2026-16462 is a critical SQL injection in Weidmueller PROCON-WEB SCADA, rated CVSS 9.8. An unauthenticated attacker can run SQL commands. Patch now.
#PROCONWEB #Weidmueller #CVE202616462 #SQLInjection #SCADA #CyberSecurity
##updated 2026-07-28T12:31:20
1 posts
CVE-2026-11841 lets an unauthenticated attacker reach internal files on SICK InspectorP6xx devices, risking device compromise. CVSS 9.4. Update to 5.4.0.
#SICK #InspectorP6xx #CVE202611841 #OTSecurity #ICS #CyberSecurity
##updated 2026-07-27T21:32:25
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-27T18:31:56
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-27T12:32:01
1 posts
Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon's best-selling router https://rotcee.github.io/posts/analyzing-the-mersusys-mb115-4g-router/#cve-2026-12495-finding-a-pre-auth-stack-buffer-overflow-in-the-mercusys-mb115-4g
##updated 2026-07-23T11:10:00.120000
1 posts
15 repos
https://github.com/Maxime288/Fragnesia-CVE-2026-46300
https://github.com/cumakurt/linuxpi
https://github.com/BenedictEjepu/CVE-2026-46300-Fragnesia---TryHackMe-Lab-Walkthrough
https://github.com/0xBlackash/CVE-2026-46300
https://github.com/Sentebale/CVE-2026-46300
https://github.com/MadExploits/CVE-2026-46300
https://github.com/azilRababe/CVE-2026-46300
https://github.com/AzDevops143/FRAGNESIA-Charan-cve-2026-46300
https://github.com/1neptune/Fragnesia
https://github.com/ExploitEoom/CVE-2026-46300
https://github.com/BenedictEjepu/CVE-2026-46300-Fragnesia---TryHackMe-Lab-Project
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/First-John/cve_2026_frag_family_fix
#OT #Advisory VDE-2026-072
Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI
The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.
#CVE CVE-2026-43284, CVE-2026-46300, CVE-2026-31431
https://certvde.com/en/advisories/vde-2026-072/
#CSAF https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2026/ppsa-2026-003.json
##updated 2026-07-22T21:31:51
1 posts
5 repos
https://github.com/webshellseo8/CVE-2026-50522-Proof-of-Concept
https://github.com/4minx/CVE-2026-50522
https://github.com/ChPratik/CVE-2026-50522
(CISA TS-SOC) CVE-2026-50522 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Severity: CRITICAL Impact Summary: An unauthorized attacker could exploit a deserialization vulnerability in Microsoft SharePoint to execute arbitrary code over a network....
##updated 2026-07-22T19:10:00.120000
1 posts
2 repos
⚪️ A Single Visit to a Malicious Page Could Compromise Tor Browser
🗨️ Researchers at Nebula Security have disclosed details of CVE-2026-10702, a vulnerability in Firefox’s JIT compiler. To carry out an attack, it was enough for a victim to open a specially crafted page; no settings changes, clicks, or other actions were…
##updated 2026-07-22T16:17:42.747000
1 posts
1 repos
Details and proof-of-concept exploit code for CVE-2026-50343 are now public. The Windows privilege escalation flaw hands standard users SYSTEM privileges.
##updated 2026-07-21T19:54:33.623000
1 posts
12 repos
https://github.com/sam00/POC-CVE-2026-54121-Certighost
https://github.com/AtlasVector/Certighost-CVE-2026-54121
https://github.com/tc4dy/CVE-2026-54121-PoC-Exploit
https://github.com/nafiez/Metasploit-CVE-2026-54121-Certighost
https://github.com/marcgoam/CVE-2026-54121-CertiGhost
https://github.com/aniqfakhrul/CVE-2026-54121
https://github.com/ChPratik/CVE-2026-54121
https://github.com/HORKimhab/CVE-2026-54121
https://github.com/mwnickerson/certighost-bof
https://github.com/0xBlackash/CVE-2026-54121
https://github.com/GlendonNotGlen/certighost-cve-2026-54121-slides
A Microsoft acaba de corrigir a falha Certighost, que permitia a um utilizador com acessos básicos manipular o sistema de cadastro e obter um certificado válido em nome de um Controlador de Domínio, assumindo a gestão absoluta de uma rede Windows. A falha, classificada como de gravidade alta, foi corrigida com a CVE-2026-54121. 🛡️
##updated 2026-07-15T15:33:14
1 posts
9 repos
https://github.com/ChPratik/NGINX_2026_CVE_Bundle_CTI_Report
https://github.com/Daniyal48/ghostlock-vagrant-box
https://github.com/gagaltotal/CVE-2026-42533-nginx
https://github.com/srkyn/nginx-map-risk-audit
https://github.com/jelasin/CVE-2026-42533
https://github.com/imbas007/CVE-2026-42533
https://github.com/suominen/CVE-2026-42533
https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner
Here's my five-week holiday, June 27 - August 2. This is the evidence trail of a man who does not know how to stop.
Running (11 runs, ~131 km):
- Jun 27: 12 km
- Jun 29: 6.5 km easy
- Jul 1: 8.37 km Mile Repeats treadmill
- Jul 4: 15.14 km trail long run
- Jul 6: 5.33 km easy hill run in drizzle
- Jul 11: 10.33 km long run in +30°C heat
- Jul 17: 6.26 km Zwift Hill Repeats
- Jul 18: 21.90 km half marathon
- Jul 21: 6.01 km Tempo 2-1 outdoors
- Jul 23: 5.05 km Current Pace Calibration 5K
- Jul 25: 25.03 km "Lost in the Swamp" 25K trail, 397m elevation
- Jul 27: 5.04 km Zwift Lutece Express, Paris
- Jul 28: 6.16 km Zwift On Off Ks
- Jul 30: 5.04 km 5x1km intervals
- Aug 1: 26.41 km 26K trail adventure, 415m elevation, 211 min
Health setbacks:
- Jun 27: 9/10 migraine at 23:55
- Jul 18: 9/10 migraine
- Jul 19: terrible postdrome
- Jun 28: postdrome day
Linux desktop deep dive (the real holiday project):
- Switched compositor from Hyprland to driftwm (infinite canvas + DMS shell)
- Built the "quantum realm" living wallpaper - transparent evolving fbm fog/stream/void over a NASA starmap
- Fixed driftwm animated blur GPU overheating (PR #220), stale pointer constraint, VRR support
- Submitted PRs for driftwm blur mask caching (#185) and animate_fps background cap (#184)
- Tried and rejected niri (tile columns kill floating workflow I'm fond of)
- Tried and abandoned Nourish/Y5 Dev session (no XWayland, launcher friction)
- Wrote a full compositor alternatives comparison doc
RAM saga:
- Diagnosed OW2 FPS collapse on Arch: 30 GB demand vs 16 GB RAM, swap full issue
- Survived earlyoom killing the compositor under a ~21 GB DMS shell leak, since fixed
- Ordered Corsair LPX 2x16 GB DDR4-3200, installed to 48 GB total
- Fixed accidentally forgotten MemoryHigh=3G shell cap that had throttled 1.3M times and forced 10 GB into swap
Gaming:
- Started Red Dead Redemption 2 (Jul 4)
- Overwatch 2: fixed dead-zone click bug, recovered corrupted update (75 GB repair), played several comps
- Played RV There Yet? with my son, laughed our assess off (Jul 22)
- Deeper gaming and compatibility optimizations on Linux
Mementomori ry association:
- Filed Mementomori ry association application to PRH - registered Jul 7
- Applied for bank account, handled phone calls, paperwork, meeting minutes
- Set up emails
- Rewrote mementomori.social terms of service
- Decided membership fees, signed board minutes
- Built sophisticated signup-report-monitor (Mastodon to Matrix forwarder)
- Built members.mementomori.social MVP
- Mementods Mastodon fork upgrades from upstream to v4.7.0-alpha.1 and alpha.2
Open source contributions:
- Halloy IRC client: timestamp position PR (#2206), blank space fix PR (#2221), ISO-8859-1 decode PR (#2254)
- Sidra music player: Last.fm scrobbling PR (#145)
- DMS plugin registry: CPU, Disk, I/O monitors submitted
- Released dms-cpu-monitor, dms-disk-monitor, dms-ram-monitor, dms-vram-monitor, dms-gpu-monitor (all from 1.0.0 through multiple releases)
- Released lc (linux-cleaner) among other side projects
Server / infra:
- 2 server maintenance windows
- Upgraded 31 servers in total
- One dist-upgrade from Ubuntu server 20.04 through 22.04 to 24.04 LTS
- Built another personal dedicated server for side projects, migrated some services to it from other servers
- Fixed some StorageBox issues, shipped open source tool backup-to-storagebox v3.0.0
- Fixed minor DNS/Redis issues on multiple servers
- Addressed nginx CVE-2026-42533
- Fixed some failing certs, stale mounts, CIFS hangs due incident calls
Customer client work (yes, on holiday, I'm an entrepreneur):
- ~25 tickets handled
- Fixed issues for 14 sites
- Sent 2 quotes
- Handled 5 job applications
- Fixed one unauthenticated nonce type confusion vulnerability
- Fixed one caching issue
Personal infra / tools:
- Built and iterated dough (open source personal budgeting app): releases 3.3.0 through 3.16.0
- Built dough-mcp (releases 0.2.0 through 0.3.0)
- Nanoclaw (Son of Anton) fork releases 1.19.0 through 1.30.0 (12 releases)
- Personal day planner tool releases 1.22.0 through 1.24.0
- Dotfiles releases 2.10.7 through 2.42.2 (relentless)
- Rewrote completelty our home weather system c.rolle.wtf with precipitation and better forecast
- Set up quick tool based on ff2mpv + mpv for instant adless YouTube playback
- Ungoogled-chromium optimization pass with NVDEC hardware decode
- Fixed home WiFi dropouts (5 GHz DFS, channel splitting, RSSI deauth) with Ubiquity router
- Tested alternative browsers: Thorium, Zen, Brave Origin Nightly, Orion
- Tried dozens of new alternative AI models
- Released lc 0.1.0, omnishuffle 1.3.1, lastfm-recommendations 2.1.0
- Released Luku for iOS 1.2.3
- Fixed some technical challenges long overdue
Finance / admin:
- Paid taxes
- Paid bills
- Categorized and flagged hundreds of transactions
- Daily dough reconciliations
- Company finance review
- Updated company finance sheets
Family:
- 18th anniversary with my wife (Jul 2) - pizza and movie at home
- Weekly café dates with my wife (Jul 5, 12, 19, 26)
- Sushi lunch with my wife (Jul 1)
- Coffee with a friend (Jul 10, sat down for 4 hours)
- Family lunch (Jul 31)
- Trip to mom's place for a few days with kids, strawberries, pancakes, summer days (Jul 13)
Other:
- Migrated off Google Photos to PixelUnion, cancelled Google One
- Wrote a blog post about the Google Photos migration
- Completed CRM migration off Pipedrive (yes, work stuff but a fun one)
- Completed GitBook to Outline tech doc migration (also fun work stuff)
Zero actual rest days that contained zero commits. Oops.
This is everything I have documented.
Tomorrow, I get to rest at the office 😂
##updated 2026-07-14T21:32:22
2 posts
6 repos
https://github.com/tc4dy/CVE-2026-15409-15410-Framework
https://github.com/remmons-r7/rapid7-CVE-2026-15409
https://github.com/HORKimhab/CVE-2026-15409
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
CVE-2026-15409 - Changed to Known Ransomware Status
SonicWall SMA1000 Appliances Server-Side Request Forgery VulnerabilityVendor: SonicWallProduct: SMA1000 AppliancesSonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.Status changed from Unknown to Known for ransomware campaign usage.Flip https://nvd.nist.gov/vuln/detail/CVE-2026-15409
##A SonicWall SMA exploit chain (CVE-2026-15409, CVE-2026-15410) grants root access and now feeds INC Ransomware attacks. Patch to 12.5.0-02835+.
#SonicWall #INCRansomware #CVE202615409 #VPNSecurity #CyberSecurity #UTA0533
##updated 2026-07-14T21:32:21
2 posts
3 repos
https://github.com/HORKimhab/CVE-2026-15410
https://github.com/tc4dy/CVE-2026-15409-15410-Framework
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
CVE-2026-15410 - Changed to Known Ransomware Status
SonicWall SMA1000 Appliances Code Injection VulnerabilityVendor: SonicWallProduct: SMA1000 AppliancesSonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: https://nvd.nist.gov/vuln/detail/CVE-2026-15410
##A SonicWall SMA exploit chain (CVE-2026-15409, CVE-2026-15410) grants root access and now feeds INC Ransomware attacks. Patch to 12.5.0-02835+.
#SonicWall #INCRansomware #CVE202615409 #VPNSecurity #CyberSecurity #UTA0533
##updated 2026-07-14T15:32:55
1 posts
100 repos
https://github.com/Juguitos/copy-fail
https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail
https://github.com/kadir/copy-fail-CVE-2026-31431-IOC
https://github.com/wgnet/wg.copyfail.patch
https://github.com/Xerxes-2/CVE-2026-31431-rs
https://github.com/Iamliuxiaozhen/copy_fail
https://github.com/tgies/copy-fail-c
https://github.com/JnamerZ/CopyFail-CVE-2026-31431
https://github.com/mrunalp/block-copyfail
https://github.com/ExploitEoom/CVE-2026-31431
https://github.com/ncmprbll/copy-fail-rs
https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431
https://github.com/sgkdev/page_inject
https://github.com/bigwario/copy-fail-CVE-2026-31431-C
https://github.com/malwarekid/CVE-2026-31431
https://github.com/Alfredooe/CVE-2026-31431
https://github.com/lonelyor/CVE-2026-31431-exp
https://github.com/H1d3r/copy-fail_LPE_Interactive
https://github.com/SeanRickerd/cve-2026-31431
https://github.com/xeloxa/copyfail-exploit
https://github.com/professional-slacker/alg_check
https://github.com/insomnisec/Detections-CVE-2026-31431
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC
https://github.com/theori-io/copy-fail-CVE-2026-31431
https://github.com/cs8425/copy-fail-go
https://github.com/b5null/CVE-2026-31431-C
https://github.com/jbnetwork-git/copy-fail-check
https://github.com/philfry/cve-2026-31431-ftrace
https://github.com/novysodope/copy-fail-CVE-2026-31431-C
https://github.com/aestechno/cve-2026-31431-ansible
https://github.com/MrAriaNet/cPanel-Fix
https://github.com/desultory/CVE-2026-31431
https://github.com/sgkdev/ptrace_may_dream
https://github.com/wuwu001/CVE-2026-31431-exploit
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431
https://github.com/Smarttfoxx/copyfail
https://github.com/sammwyy/copyfail-rs
https://github.com/povzayd/CVE-2026-31431
https://github.com/1neptune/CopyFail
https://github.com/yuspring/cve-2026-31431-poc
https://github.com/0xBlackash/CVE-2026-31431
https://github.com/AdityaBhatt3010/CVE-2026-31431
https://github.com/rvzsec/CVE-2026-31431
https://github.com/0xShe/CVE-2026-31431
https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs
https://github.com/4xura/CVE-2026-31431-Copy-Fail
https://github.com/TheMalwareGuardian/CVE-2026-31431
https://github.com/wesmar/CVE-2026-31431
https://github.com/rootsecdev/cve_2026_31431
https://github.com/badsectorlabs/copyfail-go
https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script
https://github.com/ben-slates/CVE-2026-31431-Exploit
https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431
https://github.com/cozystack/copy-fail-blocker
https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized
https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit
https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431
https://github.com/qi4L/CVE-2026-31431-Container-Escape
https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431
https://github.com/diemoeve/copyfail-rs
https://github.com/Huchangzhi/autorootlinux
https://github.com/erlangparasu/mitigate_cve_2026_31431-sh
https://github.com/cyber-joker/copy-fail-python
https://github.com/kvakirsanov/CVE-2026-31431-live-process-code-injection
https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE
https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite
https://github.com/pedromizz/copy-fail
https://github.com/Boos4721/copyfail-rs
https://github.com/sec17br/CVE-2026-31431-Copy-Fail
https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe
https://github.com/AliHzSec/CVE-2026-31431
https://github.com/bootsareme/copyfail-deconstructed
https://github.com/luotian2/CVE-2026-31431
https://github.com/pascal-gujer/CVE-2026-31431
https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail
https://github.com/Sl4cK0TH/CVE-2026-31431-PoC
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/atgreen/block-copyfail
https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4
https://github.com/Dabbleam/CVE-2026-31431-mitigation
https://github.com/XsanFlip/CVE-2026-31431-Patch
https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit
https://github.com/yxdm02/CVE-2026-31431
https://github.com/guiimoraes/CVE-2026-31431
https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC
https://github.com/JuanBindez/CVE-2026-31431
https://github.com/samanzamani/copy-fail-checker
https://github.com/st4rburn/public-passwd
https://github.com/MartinPham/copy-fail-CVE-2026-31431-php
https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit
https://github.com/ZephrFish/CopyFail-CVE-2026-31431
https://github.com/ErdemOzgen/copy-fail-cve-2026-31431
https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell
https://github.com/abdullaabdullazade/CVE-2026-31431
https://github.com/kinryulabs/rootpacket-cve-2026-31431
https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation
#OT #Advisory VDE-2026-072
Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI
The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.
#CVE CVE-2026-43284, CVE-2026-46300, CVE-2026-31431
https://certvde.com/en/advisories/vde-2026-072/
#CSAF https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2026/ppsa-2026-003.json
##updated 2026-07-14T15:31:59
1 posts
44 repos
https://github.com/armircetaj/tetragon-dirtyfrag
https://github.com/DylanClaudio/Reporte-de-Escalada-de-Privilegios-Local-Dirty-Frag
https://github.com/metalx1993/dirtyfrag-patches
https://github.com/MadExploits/CVE-2026-46300
https://github.com/ryan2929/CVE-2026-43284-
https://github.com/XRSecCD/202605_dirty_frag
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/0xlane/pagecache-guard
https://github.com/nonameuserosint-hue/DirtyFrag-go
https://github.com/AK777177/Dirty-Frag-Analysis
https://github.com/scriptzteam/Paranoid-Dirty-Frag-CVE-2026-43284
https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC
https://github.com/cumakurt/linuxpi
https://github.com/nabhan-mohy/Dirty-Frag-Research-CVE-2026-43284-
https://github.com/AtlasVector/Dirty-Frag-CVE-2026-43284
https://github.com/liamromanis101/DirtyFrag-Detector
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/1neptune/DirtyFrag
https://github.com/suominen/CVE-2026-43284
https://github.com/mym0us3r/DIRTY-FRAG-Detection-with-Wazuh-4.14.4
https://github.com/LucasPDiniz/CVE-2026-43284
https://github.com/First-John/cve_2026_frag_family_fix
https://github.com/t1ckprivate/CVE-2026-43284-Dirty-Frag
https://github.com/attaattaatta/CVE-2026-43500
https://github.com/linnemanlabs/dirtyfrag-arm64
https://github.com/krisiasty/vcheck
https://github.com/kuniyal08/Dirty-Frag-CVE-2026-43284
https://github.com/haydenjames/dirty-frag-check
https://github.com/dixyes/dirtypatch
https://github.com/grabesec/XCP_ng_CVE-2026-43284_tester
https://github.com/aettern/copyfrag-fuse
https://github.com/RevyHub/CVE-2026-43284---DirtyFrag-Analysis-THM-
https://github.com/gagaltotal/CVE-2026-43284-CVE-2026-43500-scan
https://github.com/6abc/Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284
https://github.com/ChernStepanov/DirtyFrag-for-dummies
https://github.com/Aiyakami/rust_dirtyfrag
https://github.com/millikanjohnl-blip/dirtyfrag-detection-rules
https://github.com/jayhutajulu1/CVE-2026-43284-DirtyFrag-PoC
https://github.com/xd20111/CVE-2026-43284
https://github.com/lukeslp/redtail-ioc
https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe
https://github.com/g0thamRabb1t/CVE-2026-43284-dirtyfrag-detection
#OT #Advisory VDE-2026-072
Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI
The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.
#CVE CVE-2026-43284, CVE-2026-46300, CVE-2026-31431
https://certvde.com/en/advisories/vde-2026-072/
#CSAF https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2026/ppsa-2026-003.json
##updated 2026-06-17T09:01:42.407000
1 posts
1 repos
CVE-2025-26399 - Changed to Known Ransomware Status
SolarWinds Web Help Desk Deserialization of Untrusted Data VulnerabilityVendor: SolarWindsProduct: Web Help DeskSolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 04, 2026 at 18:08:17 UTCDate https://nvd.nist.gov/vuln/detail/CVE-2025-26399
##updated 2026-06-17T05:58:22.273000
1 posts
7 repos
https://github.com/void0red/CVE-2023-32233
https://github.com/Liuk3r/CVE-2023-32233
https://github.com/oferchen/POC-CVE-2023-32233
https://github.com/Destawell/gemini-2.5-pro-nf-tables-red-teamin
https://github.com/PIDAN-HEIDASHUAI/CVE-2023-32233
https://github.com/RogelioPumajulca/TEST-CVE-2023-32233
https://github.com/Destawell/gemini-2.5-pro-nf-tables-red-teaming
Ok, the first one is absolutely it:
##Furthermore, we deploy MLG-UAF to conduct large-scale security auditing on mainstream open-source software such as libtiff, LibRaw, SQLite, ImageMagick and Zephyr RTOS. In real-world industrial source code scanning, our framework successfully discovered 17 unique confirmed UAF vulnerabilities assigned with independent Common Vulnerabilities and Exposures (CVE) IDs (CVE-2026 series, RESERVED and not yet publicized), covering cross-functional kernel UAF, intra-procedural cache UAF, race-condition UAF and multimedia parsing UAF scenarios.Real CVE case studies on CVE-2026-51291 (SQLite JSON cache flaw) and CVE-2023-32233 (Linux netfilter kernel vulnerability) demonstrate that MLG-UAF can precisely capture the fixed free-then-use spatial topological fingerprint of UAF defects and accurately resolve ambiguous multi-level pointer aliasing, even under heavy control-flow obfuscation.
updated 2026-06-09T22:00:36
1 posts
1 repos
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-06-08T23:28:56
3 posts
6 repos
https://github.com/anonmrc/CVE-2026-34486-e-Tomcat-Tribes
https://github.com/razureink/cve-2026-34486-tomcat_encrypt_bypass_reproduction
https://github.com/404-src/CVE-2026-34486
https://github.com/AirSkye/CVE-2026-34486-poc
🚨 CISA KEV ALERT: CVE-2026-34486 exposes Apache Tomcat installations to EncryptInterceptor bypasses and data interception. Active exploitation confirmed. Get the forensic breakdown, Splunk/KQL/Chronicle detection queries, and hardening steps: https://thecybermind.co/it1p
Top-of-the-Line LinkedIn Post
##🚨 [CISA-2026:0804] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0804)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-18556 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-18556)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: https://uptime.n-able.com/ ; https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-18556
⚠️ CVE-2026-34486 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-34486)
- Name: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Tomcat
- Notes: https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-34486
⚠️ CVE-2026-9198 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9198)
- Name: IBM Langflow Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: IBM
- Product: Langflow
- Notes: https://www.ibm.com/support/pages/node/7278927 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-9198
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260804 #cisa20260804 #cve_2026_18556 #cve_2026_34486 #cve_2026_9198 #cve202618556 #cve202634486 #cve20269198
##CVE ID: CVE-2026-34486
Vendor: Apache
Product: Tomcat
Date Added: 2026-08-04
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-34486
updated 2026-05-15T18:30:32
2 posts
1 repos
Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati
Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...
🔗️ [Cybersecurity360] https://link.is.it/ssYZlG
##Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati
Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...
🔗️ [Cybersecurity360] https://link.is.it/ssYZlG
##updated 2026-03-04T18:32:03
2 posts
1 repos
Broadcom has addressed several vulnerabilities published yesterday, all of them ranked high-severity https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Cisco has a new advisory for a critical vulnerability that was published yesterday:
CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
This addresses a vulnerability that was first published on July 29:
High: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh @TalosSecurity #Cisco #infosec #vulnerability
##Broadcom has addressed several vulnerabilities published yesterday, all of them ranked high-severity https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Cisco has a new advisory for a critical vulnerability that was published yesterday:
CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
This addresses a vulnerability that was first published on July 29:
High: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh @TalosSecurity #Cisco #infosec #vulnerability
##updated 2026-01-24T09:30:33
1 posts
2 repos
⚪️ A Single Visit to a Malicious Page Could Compromise Tor Browser
🗨️ Researchers at Nebula Security have disclosed details of CVE-2026-10702, a vulnerability in Firefox’s JIT compiler. To carry out an attack, it was enough for a victim to open a specially crafted page; no settings changes, clicks, or other actions were…
##updated 2025-04-11T04:12:49
2 posts
1 repos
⚠️ CRITICAL: Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
CVE-2013-4786 in IPMI 2.0 allows unauthenticated attackers to harvest password hashes from Baseboard Management Controllers via UDP 623, then crack them offline. Over 24,000 internet-exposed BMCs are vulnerable, and many run weak or predictable default credentials. Compromised BMCs give attackers d…
🤖 AI generated summary
##LAVA found 36,872 exposed BMCs leaking IPMI password hashes via CVE-2013-4786. Some are already exploited in the wild. Here is how to lock them down.
#BMC #IPMI #CVE20134786 #DataCenter #Supermicro #CyberSecurity
##SUSE Rancher CVE-2026-44945 (CRITICAL, CVSS 9.1): Privilege escalation flaw lets authenticated users with default global role gain full admin on Rancher & clusters. Restrict access & monitor pending patch. https://radar.offseq.com/threat/cve-2026-44945-cwe-441-unintended-proxy-or-intermediary-confused-deputy-in-suse-rancher-9a7358d4ec1c0d9c #OffSeq #infosec #CVE202644945 #Kubernetes
##⚪️ OpenWrt Fixes Critical Vulnerability in DHCPv6 Server
🗨️ OpenWrt developers have released updates that fix a critical vulnerability in the DHCPv6 server. The flaw allowed an unauthenticated attacker to execute arbitrary code with root privileges and potentially fully compromise a vulnerable router. The issue, tracked as CVE-2026-53921 (CVSS…
##RufRoot CVE-2026-59726: Unauthenticated RCE in Ruflo MCP Bridge Exposes AI Agent Keys
##🏆 New Achievement! RufRoot Has Entered The Arena!
PHASE ONE BEGINS. The challenger: CVE-2026-59726, alias RufRoot, a CVSS 10.0 critical flaw in the open-source AI agent platform Ruflo. Its special move — exploiting an exposed Model Context Protocol bridge to hand unauthenticated attackers full control of enterprise AI environments. No credentials required. No mercy shown. Noma Security surfaced this beast hiding in every Ruflo version before 3.16.3.
This is not a warm-up encounter. (1/2)
##Gitea Vulnerability CVE-2026-59774 Enables Unauthenticated Remote Code Execution
##CRITICAL: PyAthena <3.35.4 is vulnerable to SQL injection (CVE-2026-65321). Improper escaping allows unauthenticated attackers to inject SQL, risking data loss/exfiltration. Patch status unconfirmed — restrict DELETE/CTAS use. https://radar.offseq.com/threat/cve-2026-65321-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-in-1db4ff7a0ac0fe70 #OffSeq #CVE202665321 #PyAthena
##🔴 CVE-2026-65321 - Critical (9.8)
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65321/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-56670 - High (8.2)
ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56670/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-56671 - High (7.5)
ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py joins an unrestricted filename route capture to a selected model directory without a containment che...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56671/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-56672 - High (8.2)
ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and acc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56672/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63222 - High (7.5)
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63222/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-63221 - Critical (9.4)
CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63221/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-49413 - FreeBSD LPE via Linuxulator AT_SECURE Logic Bug https://lobste.rs/s/j1sfc2 #freebsd #security
https://ii4gsp.github.io/cve-2026-49413/
CVE-2026-49413 - FreeBSD LPE via Linuxulator AT_SECURE Logic Bug https://lobste.rs/s/j1sfc2 #freebsd #security
https://ii4gsp.github.io/cve-2026-49413/