## Updated at UTC 2026-07-22T18:06:31.207852

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-65603 8.8 0.00% 2 0 2026-07-22T17:16:59.437000 The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege
CVE-2026-49499 8.8 0.00% 2 0 2026-07-22T17:16:56.350000 Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generat
CVE-2026-63764 9.3 0.28% 1 0 2026-07-22T16:27:18.220000 lmdeploy's OpenAI-compatible API server contains a server-side request forgery v
CVE-2026-40712 9.1 0.00% 2 0 2026-07-22T16:22:08.093000 Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improp
CVE-2026-46738 9.1 0.00% 2 0 2026-07-22T16:22:08.093000 Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improp
CVE-2026-15900 9.6 0.22% 1 0 2026-07-22T16:17:10.123000 Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowe
CVE-2026-8152 None 0.00% 2 0 2026-07-22T15:31:27 Unblu Spark contains an open redirect vulnerability that can be escalated to a D
CVE-2026-50518 9.8 7.36% 1 0 2026-07-22T15:15:16.043000 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacke
CVE-2026-62561 7.8 0.14% 2 0 2026-07-22T14:17:24.203000 Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (compon
CVE-2026-62549 9.6 0.30% 1 0 2026-07-22T14:17:23.643000 Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (compon
CVE-2026-16232 0 0.00% 2 1 2026-07-22T14:17:15.513000 An authentication bypass vulnerability in the Check Point SmartConsole login pro
CVE-2026-63048 None 0.23% 2 0 2026-07-22T09:32:20 The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary
CVE-2026-3821 8.8 0.64% 2 0 2026-07-22T09:32:20 Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14
CVE-2026-15802 8.1 0.52% 2 0 2026-07-22T06:31:33 The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion
CVE-2026-63030 9.8 38.60% 22 65 template 2026-07-22T05:17:11.910000 WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API ba
CVE-2026-60137 5.9 20.39% 18 39 2026-07-22T05:17:11.750000 WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does no
CVE-2026-0770 9.8 54.50% 8 6 template 2026-07-22T05:17:08.693000 Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere R
CVE-2021-27137 8.1 10.81% 6 0 2026-07-22T05:17:07.330000 An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An uns
CVE-2026-65315 7.5 0.57% 1 0 2026-07-22T00:32:45 Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability i
CVE-2026-65319 7.5 0.37% 2 0 2026-07-22T00:32:44 Feedbin (commit 739884a) contains an unauthenticated information disclosure vuln
CVE-2026-65318 8.6 0.42% 1 0 2026-07-22T00:32:44 Verba RAG application version 2.1.3 contains an unauthenticated server-side requ
CVE-2026-65317 8.6 0.48% 1 0 2026-07-22T00:32:44 Verba RAG application version 2.1.3 contains a server-side request forgery vulne
CVE-2026-60926 7.2 0.50% 1 0 2026-07-22T00:32:12 Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business S
CVE-2026-60785 8.1 0.38% 1 0 2026-07-22T00:32:06 Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (com
CVE-2026-60799 7.1 0.30% 1 0 2026-07-22T00:32:06 Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business
CVE-2026-60642 7.6 0.22% 1 0 2026-07-22T00:32:00 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middlewar
CVE-2026-60306 9.8 0.40% 1 0 2026-07-22T00:31:40 Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CVE-2026-60297 9.8 0.49% 1 0 2026-07-22T00:31:40 Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CVE-2026-60299 9.8 0.49% 1 0 2026-07-22T00:31:40 Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CVE-2026-60298 9.8 0.49% 1 0 2026-07-22T00:31:40 Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CVE-2026-60300 9.8 0.49% 1 0 2026-07-22T00:31:32 Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CVE-2026-60656 8.8 0.45% 1 0 2026-07-21T22:18:06.597000 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middlewar
CVE-2026-60308 9.8 0.40% 1 0 2026-07-21T22:17:33.490000 Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CVE-2026-60296 9.8 0.49% 1 0 2026-07-21T22:17:32.160000 Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CVE-2026-60206 9.9 0.48% 2 0 2026-07-21T22:17:21.953000 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware
CVE-2026-16221 7.5 0.22% 1 0 2026-07-21T22:08:29 ### Impact `fast-uri` v4.1.0 and earlier do not treat a literal backslash (U+00
CVE-2026-8983 None 0.33% 1 0 2026-07-21T21:32:53 Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authen
CVE-2026-65057 9.3 0.25% 1 0 2026-07-21T21:32:53 Keep (commit 91c75e0) contains a server-side request forgery vulnerability that
CVE-2026-65056 8.2 0.23% 1 0 2026-07-21T21:32:53 mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that
CVE-2026-64877 8.4 0.19% 1 0 2026-07-21T21:32:46 An authenticated non-admin user can exploit a SQL injection flaw in the ticketin
CVE-2026-51027 9.9 0.34% 1 0 2026-07-21T20:27:18.523000 An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive inf
CVE-2026-56750 None 0.00% 2 0 2026-07-21T20:20:23 The vulnerability is in the Remember-Me (gitea_incredible) token validation logi
CVE-2026-55084 8.8 0.25% 1 0 2026-07-21T20:17:02.277000 DHIS2 is a flexible information system for data capture, management, validation,
CVE-2026-16412 9.8 0.33% 1 0 2026-07-21T20:17:00.157000 Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these
CVE-2026-62228 8.8 0.25% 1 0 2026-07-21T19:58:20.277000 OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node e
CVE-2026-28307 9.1 0.34% 1 0 2026-07-21T18:31:10 SolarWinds Serv-U is affected by a privilege escalation vulnerability that allow
CVE-2026-24232 4.3 0.14% 1 0 2026-07-21T18:31:10 NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause im
CVE-2026-44508 0 0.00% 1 0 2026-07-21T16:17:10.850000 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-
CVE-2026-8933 7.8 0.14% 4 0 2026-07-21T15:30:51 A local privilege escalation vulnerability exists in snap-confine, a set-capabil
CVE-2026-13142 8.1 0.23% 1 0 2026-07-21T15:30:34 The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.
CVE-2026-47255 8.2 0.18% 1 0 2026-07-21T15:16:35.860000 AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail
CVE-2026-1617 9.8 0.26% 1 0 2026-07-21T12:33:43 Improper neutralization of special elements used in an SQL command ('SQL injecti
CVE-2026-13439 9.8 0.40% 1 0 2026-07-21T06:31:24 The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unaut
CVE-2026-15899 None 0.22% 1 0 2026-07-21T00:30:42 Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128
CVE-2026-15901 None 0.23% 1 0 2026-07-21T00:30:42 Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a rem
CVE-2026-64625 9.8 0.35% 2 0 2026-07-21T00:30:37 AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync
CVE-2026-56452 7.5 0.36% 1 0 2026-07-21T00:30:28 Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD i
CVE-2026-64624 7.8 0.19% 1 0 2026-07-20T22:17:18.600000 FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as
CVE-2026-63108 8.8 1.92% 1 0 2026-07-20T22:17:17.797000 Roo Code through 3.54.0 contains a command injection vulnerability in the auto-a
CVE-2026-59873 7.5 0.36% 1 0 2026-07-20T21:52:04 ### Summary A **Decompression/parse DoS via unlimited input** vulnerability in `
CVE-2026-63766 9.8 1.39% 1 0 2026-07-20T21:31:57 GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability
CVE-2026-63731 7.7 0.24% 1 0 2026-07-20T21:31:57 HyperDX before 2.31.0 contains a server-side request forgery vulnerability that
CVE-2026-64619 7.5 0.20% 1 0 2026-07-20T21:31:57 FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateL
CVE-2026-63767 9.8 0.74% 1 0 2026-07-20T21:31:50 ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticate
CVE-2026-35198 9.0 0.23% 1 0 2026-07-20T19:17:21.537000 HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cr
CVE-2026-57309 0 0.31% 1 0 2026-07-20T16:17:05.670000 A Blind SQL injection vulnerability has been identified in Windu CMS. A remote u
CVE-2026-54910 7.7 0.31% 1 0 2026-07-20T16:17:05.233000 FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to ver
CVE-2026-13577 8.2 0.26% 3 0 2026-07-20T15:33:11 Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRN
CVE-2026-63831 8.8 0.24% 1 0 2026-07-20T15:32:51 In the Linux kernel, the following vulnerability has been resolved: mac802154:
CVE-2026-63090 8.8 0.46% 1 0 2026-07-20T15:32:15 ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulner
CVE-2026-63795 10.0 0.48% 2 0 2026-07-20T15:16:46.193000 In the Linux kernel, the following vulnerability has been resolved: 9p: avoid p
CVE-2026-12484 7.8 0.20% 3 0 2026-07-20T15:16:34.223000 A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization
CVE-2026-16242 9.4 0.37% 1 0 2026-07-20T09:31:15 A flaw was found in the Konnectivity proxy-server configuration for hosted contr
CVE-2026-53359 8.8 0.12% 2 6 2026-07-18T09:33:19 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: F
CVE-2026-13765 7.5 0.39% 1 0 2026-07-17T19:17:12.640000 The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin
CVE-2026-62386 7.5 0.27% 1 0 2026-07-17T15:44:29.553000 The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT acc
CVE-2026-11961 8.1 0.23% 1 0 2026-07-17T15:32:27 The User Registration & Membership WordPress plugin before 5.2.3 does not valid
CVE-2026-13352 8.8 0.57% 1 0 2026-07-17T06:31:06 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User
CVE-2026-62227 7.7 0.23% 1 0 2026-07-17T03:31:30 OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulner
CVE-2026-62241 9.1 0.39% 1 0 2026-07-17T03:31:30 clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT
CVE-2026-62234 8.1 0.30% 1 0 2026-07-17T03:31:30 Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing
CVE-2026-53412 9.8 0.51% 1 0 2026-07-17T00:32:18 Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client fo
CVE-2026-39808 9.8 84.16% 2 6 template 2026-07-16T18:32:24 A improper neutralization of special elements used in an os command ('os command
CVE-2026-25089 9.8 36.13% 2 2 2026-07-16T18:32:24 A improper neutralization of special elements used in an os command ('os command
CVE-2026-58644 9.8 1.47% 4 0 2026-07-16T18:31:26 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-15410 7.2 18.29% 1 3 2026-07-16T05:16:18.470000 Post-authentication improper control of generation of code ('Code Injection') vu
CVE-2026-13385 0 0.10% 1 0 2026-07-16T05:16:17.923000 An Improper Validation of Integrity Check Value and Improper Certificate Validat
CVE-2026-49488 6.5 0.73% 1 0 2026-07-15T16:16:47.663000 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v
CVE-2026-35152 8.8 3.49% 1 0 2026-07-15T15:34:08 A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (
CVE-2026-57821 8.1 0.79% 1 1 2026-07-15T15:34:08 A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET
CVE-2026-56287 8.1 0.70% 1 0 2026-07-15T15:34:07 A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client S
CVE-2026-47992 7.2 19.92% 1 0 2026-07-15T15:33:23.500000 Adobe Commerce is affected by an Improper Neutralization of Special Elements use
CVE-2026-42533 8.1 0.83% 9 5 2026-07-15T15:33:14 A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive
CVE-2026-9770 None 0.22% 1 0 2026-07-15T03:33:02 Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key st
CVE-2026-48332 7.7 11.94% 1 0 2026-07-14T21:32:34 ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability tha
CVE-2026-48320 8.5 9.36% 1 0 2026-07-14T21:32:33 ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability.
CVE-2026-48284 9.6 7.94% 1 0 2026-07-14T21:32:31 ColdFusion is affected by an Improper Input Validation vulnerability that could
CVE-2026-48356 9.6 18.88% 1 0 2026-07-14T21:32:27 Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type
CVE-2026-47999 4.8 7.08% 1 0 2026-07-14T21:32:26 Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability
CVE-2026-15409 10.0 16.27% 2 5 template 2026-07-14T21:32:22 A Server-side request forgery (SSRF) vulnerability has been identified in the SM
CVE-2026-47996 7.6 18.03% 1 0 2026-07-14T21:32:22 Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul
CVE-2026-13001 9.8 1.08% 1 2 2026-07-14T21:32:21 The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary fi
CVE-2026-58319 9.1 0.61% 1 0 2026-07-14T18:33:00 Certain Apache Doris FE HTTP REST administrative APIs were accessible without pr
CVE-2026-50522 9.8 20.35% 10 1 2026-07-14T18:32:11 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-49176 7.8 0.24% 1 1 2026-07-14T18:32:01 Improper privilege management in Windows WalletService allows an authorized atta
CVE-2026-56451 10.0 0.38% 3 0 2026-07-14T12:31:16 A vulnerability has been identified in Opcenter X (All versions < V2604). Affect
CVE-2026-6875 0 0.51% 9 2 template 2026-07-14T05:16:19.730000 ServiceNow has addressed a remote code execution vulnerability that was identifi
CVE-2026-52824 None 0.00% 2 0 template 2026-07-14T00:08:00 ### Summary The official Kimai Docker image ships with `APP_SECRET=change_this_
CVE-2026-57239 8.2 0.11% 1 1 2026-07-09T14:31:41.157000 The user-controllable executable files will be directly executed by high-privile
CVE-2026-47198 8.5 0.40% 1 0 2026-06-30T16:44:31 ### Summary The checkout component improperly filters URL-writable properties, a
CVE-2026-26241 9.1 0.32% 2 0 2026-06-17T18:36:27 A buffer overflow vulnerability has been reported to affect File Station 5. The
CVE-2026-26239 8.1 0.29% 2 0 2026-06-17T18:35:20 A buffer overflow vulnerability has been reported to affect File Station 5. If a
CVE-2026-26240 9.1 0.32% 2 0 2026-06-17T13:20:12.183000 A buffer overflow vulnerability has been reported to affect File Station 5. The
CVE-2026-9039 0 0.18% 1 0 2026-06-17T11:04:45.947000 A configuration weakness in the device’s remote management service allows an aut
CVE-2026-3949 3.3 0.12% 1 1 2026-06-17T10:44:29.823000 A vulnerability was determined in strukturag libheif up to 1.21.2. This affects
CVE-2026-42980 7.8 5.66% 2 1 2026-06-09T18:30:53 Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authori
CVE-2026-4986 5.3 0.20% 2 1 2026-06-09T15:33:16 The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity o
CVE-2026-0257 9.1 86.68% 13 8 template 2026-06-09T12:32:02 Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of
CVE-2026-45578 8.8 0.32% 1 0 2026-06-09T10:27:14 ## Summary **Type:** Classic shell-metacharacter injection. The YPTSocket notif
CVE-2026-47413 9.6 0.21% 1 0 2026-06-01T14:23:41 ## Summary **Type:** Privilege escalation / cross-tenant member injection. The
CVE-2026-40622 7.5 0.17% 1 0 2026-05-26T18:31:40 NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability
CVE-2026-46415 8.2 0.16% 1 0 2026-05-19T20:29:18 ### Impact Caddy Defender used `r.RemoteAddr` when evaluating whether a request
CVE-2026-46412 10.0 0.42% 1 0 2026-05-19T20:28:08 ## Summary Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compr
CVE-2026-45713 7.5 0.32% 1 0 2026-05-19T15:54:13 ### Summary The Mailpit SMTP server has a Server.MaxSize int field that controls
CVE-2026-45270 8.7 0.21% 1 0 2026-05-18T16:23:35 ## Summary The `Pages` backend module registers the `html_purify` validation ru
CVE-2026-5987 4.7 0.24% 1 0 2026-04-10T00:30:38 A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d
CVE-2026-64600 0 0.00% 2 0 N/A
CVE-2026-44421 0 0.42% 2 0 N/A
CVE-2026-63133 0 0.00% 2 0 N/A
CVE-2026-63134 0 0.00% 2 0 N/A
CVE-2026-63177 0 0.00% 2 0 N/A
CVE-2026-29059 0 2.58% 1 1 template N/A
CVE-2026-58443 0 0.00% 3 0 N/A
CVE-2026-56819 0 0.63% 1 0 N/A
CVE-2026-50055 0 0.00% 1 1 N/A
CVE-2026-53595 0 0.30% 2 1 N/A
CVE-2026-53591 0 0.21% 1 0 N/A
CVE-2026-55544 0 0.18% 1 0 N/A
CVE-2026-47129 0 0.22% 1 0 N/A
CVE-2026-63429 0 0.30% 1 0 N/A
CVE-2026-14266 0 0.00% 1 2 N/A
CVE-2026-42566 0 0.28% 2 0 N/A
CVE-2026-44359 0 1.00% 2 0 N/A

CVE-2026-65603
(8.8 HIGH)

EPSS: 0.00%

updated 2026-07-22T17:16:59.437000

2 posts

The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile self-update handler (processUserProfile(), the update_user task). Unlike the registration handler, this handler does not strip privilege fields ('groups','access') from user-submitted form data before persisting them. When an administrator has added 'groups' and/or 'access'

offseq at 2026-07-22T12:00:33.475Z ##

CVE-2026-65603: HIGH severity privilege escalation in Grav Login plugin (<=3.8.11). Low-priv users can gain super-admin & RCE. Patch to v3.8.12 ASAP! radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-22T12:00:33.000Z ##

CVE-2026-65603: HIGH severity privilege escalation in Grav Login plugin (<=3.8.11). Low-priv users can gain super-admin & RCE. Patch to v3.8.12 ASAP! radar.offseq.com/threat/cve-20 #OffSeq #GravCMS #Vuln #PrivilegeEscalation

##

CVE-2026-49499
(8.8 HIGH)

EPSS: 0.00%

updated 2026-07-22T17:16:56.350000

2 posts

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

thehackerwire@mastodon.social at 2026-07-22T17:00:04.000Z ##

🟠 CVE-2026-49499 - High (8.8)

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-22T17:00:04.000Z ##

🟠 CVE-2026-49499 - High (8.8)

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63764
(9.3 CRITICAL)

EPSS: 0.28%

updated 2026-07-22T16:27:18.220000

1 posts

lmdeploy's OpenAI-compatible API server contains a server-side request forgery vulnerability that allows unauthenticated attackers to access internal services and cloud metadata endpoints by supplying a crafted image_url that redirects to internal targets. Attackers can send a POST request to the chat completions endpoint with an image_url pointing to an attacker-controlled server that responds wi

thehackerwire@mastodon.social at 2026-07-21T22:00:20.000Z ##

🔴 CVE-2026-63764 - Critical (9.3)

lmdeploy's OpenAI-compatible API server contains a server-side request forgery vulnerability that allows unauthenticated attackers to access internal services and cloud metadata endpoints by supplying a crafted image_url that redirects to internal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-40712
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-07-22T16:22:08.093000

2 posts

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

thehackerwire@mastodon.social at 2026-07-22T17:00:25.000Z ##

🔴 CVE-2026-40712 - Critical (9.1)

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-22T17:00:25.000Z ##

🔴 CVE-2026-40712 - Critical (9.1)

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-46738
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-07-22T16:22:08.093000

2 posts

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

thehackerwire@mastodon.social at 2026-07-22T17:00:14.000Z ##

🔴 CVE-2026-46738 - Critical (9.1)

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-22T17:00:14.000Z ##

🔴 CVE-2026-46738 - Critical (9.1)

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15900
(9.6 CRITICAL)

EPSS: 0.22%

updated 2026-07-22T16:17:10.123000

1 posts

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

offseq@infosec.exchange at 2026-07-21T01:30:26.000Z ##

CVE-2026-15900: CRITICAL use-after-free in Chrome (Android <150.0.7871.128). Exploitable via malicious HTML, enabling sandbox escape & elevated code execution. Patch ASAP: update Chrome for Android. radar.offseq.com/threat/cve-20 #OffSeq #CVE202615900 #Chrome #Android

##

CVE-2026-8152(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-07-22T15:31:27

2 posts

Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. When Unblu Spark is deployed with com.unblu.identifier.siteEmbeddedSetup=true, it runs in the same origin as the host application. Any JavaScript injected through this vulnerability therefore executes with full access to the host application's cookies, DOM, and same-origin

offseq at 2026-07-22T13:30:26.991Z ##

Unblu Spark suffers a CRITICAL open redirect (CVE-2026-8152) leading to DOM XSS in siteEmbeddedSetup=true config. Attacker can access cookies & APIs of host app. No patch yet — disable this config ASAP. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-22T13:30:26.000Z ##

Unblu Spark suffers a CRITICAL open redirect (CVE-2026-8152) leading to DOM XSS in siteEmbeddedSetup=true config. Attacker can access cookies & APIs of host app. No patch yet — disable this config ASAP. radar.offseq.com/threat/cve-20 #OffSeq #XSS #Vulnerability #InfoSec

##

CVE-2026-50518
(9.8 CRITICAL)

EPSS: 7.36%

updated 2026-07-22T15:15:16.043000

1 posts

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-62561
(7.8 HIGH)

EPSS: 0.14%

updated 2026-07-22T14:17:24.203000

2 posts

Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HRMS (US) executes to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in takeover of Oracle

thehackerwire@mastodon.social at 2026-07-22T08:00:41.000Z ##

🟠 CVE-2026-62561 - High (7.8)

Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-22T08:00:41.000Z ##

🟠 CVE-2026-62561 - High (7.8)

Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62549
(9.6 CRITICAL)

EPSS: 0.30%

updated 2026-07-22T14:17:23.643000

1 posts

Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significantly impact additional products (scope change).

offseq@infosec.exchange at 2026-07-22T00:00:39.000Z ##

CVE-2026-62549 (CRITICAL, CVSS 9.6) in Oracle HRMS (UK) 12.2.3 – 12.2.15 lets low-priv attackers compromise critical data & impact other Oracle apps. Patch status unclear — check radar.offseq.com/threat/cve-20 & restrict network access. #OffSeq #Oracle #CVE2026_62549 #Vuln

##

CVE-2026-16232
(0 None)

EPSS: 0.00%

updated 2026-07-22T14:17:15.513000

2 posts

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server I

1 repos

https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

CVE-2026-63048(CVSS UNKNOWN)

EPSS: 0.23%

updated 2026-07-22T09:32:20

2 posts

The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.

offseq at 2026-07-22T09:00:30.990Z ##

CVE-2026-63048 (CRITICAL, CVSS 9.4): joomlack.fr Page Builder CK for Joomla (v1.0.0 – 3.6.2) lets authenticated users upload arbitrary files, enabling RCE. No patch — restrict usage & monitor for updates. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-22T09:00:30.000Z ##

CVE-2026-63048 (CRITICAL, CVSS 9.4): joomlack.fr Page Builder CK for Joomla (v1.0.0 – 3.6.2) lets authenticated users upload arbitrary files, enabling RCE. No patch — restrict usage & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #RCE #Vuln

##

CVE-2026-3821
(8.8 HIGH)

EPSS: 0.64%

updated 2026-07-22T09:32:20

2 posts

Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attacker can exploit SMASH’s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the BMC.

thehackerwire@mastodon.social at 2026-07-22T08:00:18.000Z ##

🟠 CVE-2026-3821 - High (8.8)

Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI.
An authorized attacker can exploit SMASH’s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-22T08:00:18.000Z ##

🟠 CVE-2026-3821 - High (8.8)

Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI.
An authorized attacker can exploit SMASH’s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15802
(8.1 HIGH)

EPSS: 0.52%

updated 2026-07-22T06:31:33

2 posts

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution

thehackerwire@mastodon.social at 2026-07-22T05:59:48.000Z ##

🟠 CVE-2026-15802 - High (8.1)

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-22T05:59:48.000Z ##

🟠 CVE-2026-15802 - High (8.1)

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63030
(9.8 CRITICAL)

EPSS: 38.60%

updated 2026-07-22T05:17:11.910000

22 posts

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

Nuclei template

65 repos

https://github.com/ekomsSavior/wp2shell

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/mcipekci/wp2shell

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t

https://github.com/InstaWP/wp2shell-scan

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/Icex0/wp2shell-poc

https://github.com/Ch4120N/CVE-2026-63030

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/securelayer7/WordPresShell

https://github.com/dinosn/wp2shell-lab

https://github.com/ebrasha/abdal-cve-2026-63030

https://github.com/gbrsh/CVE-2026-63030

https://github.com/wn-iqbal/wp2shell

https://github.com/ananay/wp2shell-lab

https://github.com/mrx-arafat/CVE-2026-63030-POC

https://github.com/ChiefYoru/CVE-2026-63030_PoC

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/Crypto-Cat/wp2shell

https://github.com/4B3R4M4-607D/CVE-2026-63030-POC

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/attackercan/wp2shell-poc2

https://github.com/ASYquan/wp2shell-cf-WAF-bypass

https://github.com/0xWhoknows/wp2shell

https://github.com/0xBlackash/CVE-2026-63030

https://github.com/mhtsec/CVE-2026-63030

https://github.com/Lutfifakee-Project/wp2shell

https://github.com/zeroc00I/CVE-2026-63030

https://github.com/0xsha/wp2shell

https://github.com/NULL200OK/WP2Shell

https://github.com/c0gnit00/Wp2Shell

https://github.com/fullhunt/wp2shell-scan

https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030

https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/47Cid/wp2shell-lab

https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/raphy76/wp2shell-poc-fulljs

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/0xh7ml/CVE-2026-63030

https://github.com/yoerivegt/wp2shell-poc

https://github.com/mverschu/CVE-2026-63030

https://github.com/TomorrowX6/CVE-2026-63030-poc

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/h4cd0c/wp2shell

https://github.com/kulichr/wp2shell

https://github.com/bahartanir/wp2shell-scanner

https://github.com/vulnquest58/PressVector

https://github.com/CybersecSpirit/CVE-2026-63030

https://github.com/0xjessie21/wp2shell-checker

https://github.com/4minx/CVE-2026-63030

https://github.com/ikow/wp2shell

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/administrator-01001/CVE-2026-63030

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/ZenithGenius/wordpress-batch-rce-lab

https://github.com/zi3lak/wp2shell_scanner

Matchbook3469@mastodon.social at 2026-07-22T17:22:26.000Z ##

🔵 THREAT INTELLIGENCE

Critical wp2shell WordPress flaws exploited to install webshells

Vulnerability | CRITICAL
CVEs: CVE-2026-60137, CVE-2026-63030

Hackers are exploiting the 'wp2shell' critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent...

Full analysis:
yazoul.net/news/article/critic

#InfoSec #ZeroDay #SecurityOps

##

netsecio@mastodon.social at 2026-07-22T16:49:30.000Z ##

📰 CISA Adds Four Actively Exploited Flaws in DD-WRT, Langflow, WordPress

CISA adds 4 actively exploited vulnerabilities to its KEV catalog: CVE-2021-27137 (DD-WRT), CVE-2026-0770 (Langflow), and CVE-2026-63030 & CVE-2026-60137 (WordPress). Patching is urgent. #CISA #KEV #Vulnerability #PatchNow #WordPress

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ci

##

thecybermind at 2026-07-22T11:52:44.416Z ##

⚠️ CRITICAL THREAT: CVE-2026-63030 in WordPress Core enables SQL injection and RCE via interpretation conflicts. Active exploitation is confirmed! Get the forensic detection queries and hardening strategies needed to secure your web assets now. thecybermind.co/9k20

##

thecybermind@infosec.exchange at 2026-07-22T11:52:44.000Z ##

⚠️ CRITICAL THREAT: CVE-2026-63030 in WordPress Core enables SQL injection and RCE via interpretation conflicts. Active exploitation is confirmed! Get the forensic detection queries and hardening strategies needed to secure your web assets now. thecybermind.co/9k20

#CyberSecurity #InfoSec #WordPress #ThreatIntel

##

hyoyoshikawa@toot.blue at 2026-07-22T00:06:05.000Z ##

WordPressに認証不要でコード実行される緊急の脆弱性 即時更新を呼び掛け

itmedia.co.jp/news/articles/26

 WordPressの開発チームは7月17日(米国時間)、深刻な2件の脆弱性を修正したセキュリティリリース「WordPress 7.0.2」を公開した。

 1件は深刻度「Critical」(緊急)と評価された認証不要のリモートコード実行(RCE)の脆弱性(CVE-2026-63030)で、REST APIのバッチ処理エンドポイントを悪用されると、ログインやユーザーの操作なしに攻撃者が任意のコードを実行できる恐れがある。
もう1件は「High」(高)と評価されたSQLインジェクションの脆弱性(CVE-2026-60137)で、細工した入力によってデータベースへのクエリを改ざんされる可能性がある。なお、RCEはこのSQLインジェクションに起因しているという。

##

oversecurity@mastodon.social at 2026-07-21T17:10:36.000Z ##

Critical wp2shell WordPress flaws exploited to install webshells

Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy...

🔗️ [Bleepingcomputer] link.is.it/KxezNe

##

secdb@infosec.exchange at 2026-07-21T17:00:12.000Z ##

🚨 [CISA-2026:0721] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2021-27137 (secdb.nttzen.cloud/cve/detail/)
- Name: DD-WRT Stack-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: DD-WRT
- Product: DD-WRT
- Notes: This vulnerability affects a common open-source component, third-party library, proprietary implementation, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: svn.dd-wrt.com/changeset/45724 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-0770 (secdb.nttzen.cloud/cve/detail/)
- Name: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Langflow
- Product: Langflow
- Notes: github.com/langflow-ai/langflo ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-60137 (secdb.nttzen.cloud/cve/detail/)
- Name: WordPress Core SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WordPress
- Product: Core
- Notes: wordpress.org/news/2026/07/wor ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-63030 (secdb.nttzen.cloud/cve/detail/)
- Name: WordPress Core Interpretation Conflict Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WordPress
- Product: Core
- Notes: wordpress.org/news/2026/07/wor ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260721 #cisa20260721 #cve_2021_27137 #cve_2026_0770 #cve_2026_60137 #cve_2026_63030 #cve202127137 #cve20260770 #cve202660137 #cve202663030

##

DailyCyberSecurity@infosec.exchange at 2026-07-21T16:32:21.000Z ##

CISA added four flaws to its KEV catalog, including WordPress RCE (CVE-2026-63030) and Langflow RCE (CVE-2026-0770). All are exploited in the wild.

#CISA #KEV #WordPress #Langflow #DDWRT #RCE #SQLInjection

securityonline.info/cisa-kev-f

##

cisakevtracker@mastodon.social at 2026-07-21T16:01:06.000Z ##

CVE ID: CVE-2026-63030
Vendor: WordPress
Product: Core
Date Added: 2026-07-21
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

marcel@waldvogel.family at 2026-07-21T16:00:57.000Z ##

#IoC von #wp2shell suchen:

- Webserverlogs

`zgrep /batch/v1 *.log *.log.gz | egrep '45.79.167[.]238|34.81.132[.]62|79.177.131[.]206|15.157.135[.]170|94.100.52[.]128|172.235.128[.]52'`

- Wordpress-Verzeichnis

`find . -type f -print0 | xargs -0 md5sum | egrep '2a1410d8e2a8337ac2171cedea8c0fdc47c647a0|58eca847e9eae9e6b08cc211f1559817b71bc4cc|ebea44890f434d5d67ede22009a3f4bb5cac33f8|d9a220c8039f1c4d72cae7ccb8b3a33dec8815be|e9756e2338f84746007235e4cab7a70d5b3ca47f'`

wiz.io/blog/wp2shell-cve-2026-

##

AAKL@infosec.exchange at 2026-07-21T14:57:02.000Z ##

Broadcom has new advisories for two medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

CISA KEV updates:

- CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Vulnerability cve.org/CVERecord?id=CVE-2021-

- CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-63030: WordPress Core Interpretation Conflict Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-60137L WordPress Core SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #WordPress #vulnerability #infosec

##

DailyCyberSecurity@infosec.exchange at 2026-07-21T01:50:36.000Z ##

wp2shell, a WordPress Core RCE chain (CVE-2026-63030, CVE-2026-60137), is exploited in the wild. Public PoC code is out. Patch WordPress now.

#wp2shell #WordPress #RCE #CVE202663030 #CVE202660137 #InfoSec #WebSecurity #PatchNow

securityonline.info/wp2shell-w

##

bugxhunter@infosec.exchange at 2026-07-21T00:01:17.000Z ##

🤖 WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)

📝 Last week, Searchlight Cyber released details about a vulnerability they are calling &quot;wp2shell&quot;. The vulner...

isc.sans.edu/diary/rss/33168

📰 SANS Internet Storm Center, InfoCON: green

#AI #CVE #ZeroDay

##

sans_isc@infosec.exchange at 2026-07-20T18:46:21.000Z ##

WordPress Exploitation Underway (CVE-2026-63030) isc.sans.edu/diary/33168

##

Xidewo@unredacted.social at 2026-07-20T16:32:01.000Z ##

W cyberpodziemiu opublikowano exploity wykorzystujące krytyczne luki RCE typu „wp2shell” występujące przed uwierzytelnieniem, które dotyczą jądra WordPressa. W wersjach WordPressa 6.9.5 i 7.0.2 naprawiono cały łańcuch ataków typu wp2shell. Atak typu wp2shell składa się z dwóch luk – CVE-2026-63030 i CVE-2026-60137, które można połączyć w celu zdalnego wykonania kodu przed uwierzytelnieniem w instalacjach WordPressa w wersjach 6.9. i 7.0.

##

AAKL@infosec.exchange at 2026-07-20T15:22:11.000Z ##

New.

Picus: CVE-2026-63030 and CVE-2026-60137 (wp2shell): WordPress RCE Explained picussecurity.com/resource/blo #infosec #vulnerability #WordPress

##

bsi@social.bund.de at 2026-07-20T10:00:13.000Z ##

⚠️ 📢 #Sicherheitswarnung: WordPress – Schwachstellen erlauben "Remote Code Execution"

Am 17. Juli 2026 wurde seitens #Wordpress eine Aktualisierung bekannt gegeben, die zwei #Schwachstellen in der Wordpress-Software behebt.

❗️ Die beiden Schwachstellen CVE-2026-60137 und CVE-2026-63030 ermöglichen einem nicht authentifizierten, entfernten Angreifer Code zur Ausführung zu bringen.

Mehr dazu hier: 👉️ bsi.bund.de/dok/1203360

@certbund

##

decio@infosec.exchange at 2026-07-20T08:58:22.000Z ##

⚠️ Si vous administrez un site WordPress ou si vous connaissez quelqu’un qui en gère un faites passer l’information.

Une vulnérabilité critique baptisée WP2Shell touche directement le cœur de WordPress.

Cette fois, il ne s’agit pas d’un plugin abandonné ou d’un thème douteux : une installation standard peut être attaquée à distance, sans compte utilisateur, sans mot de passe et sans authentification préalable.

WP2Shell combine deux failles, CVE-2026-60137 et CVE-2026-63030, permettant à un attaquant d’exécuter du code sur le serveur et donc, potentiellement, de prendre le contrôle du site.

-> Des tentatives d’exploitation et des compromissions ont déjà été observées dans la nature.

Sont notamment concernées les versions :

➡️ WordPress 6.9.0 à 6.9.4
➡️ WordPress 7.0.0 à 7.0.1

Les correctifs sont disponibles dans les versions 6.9.5 et 7.0.2. WordPress a activé des mises à jour automatiques forcées en raison de la gravité de la faille, mais il ne faut pas supposer qu’elles ont forcément fonctionné : elles peuvent avoir été désactivées, bloquées par l’hébergeur ou empêchées par une configuration particulière.

À faire rapidement:

✅ vérifier la version réellement installée ;
✅ mettre WordPress à jour vers 6.9.5 ou 7.0.2 au minimum ;
✅ confirmer que la mise à jour s’est correctement terminée ;
✅ vérifier les comptes administrateurs, les fichiers récemment modifiés et les journaux du serveur ;
✅ rechercher d’éventuels fichiers PHP, plugins ou utilisateurs inconnus ;
✅ s’assurer que des sauvegardes propres et récentes sont disponibles.

En attendant la mise à jour, l’accès anonyme aux routes REST suivantes peut également être bloqué au niveau du WAF ou du serveur web :

/wp-json/batch/v1
?rest_route=/batch/v1

Point important : installer le correctif empêche une nouvelle exploitation, mais ne supprime pas une éventuelle compromission déjà présente. Si le site est resté exposé, une vérification minimale est donc nécessaire, même après la mise à jour.

Un site WordPress « qui fonctionne encore » n’est pas nécessairement un site sain : les attaquants cherchent souvent à rester discrets pour installer une porte dérobée, détourner le trafic, diffuser du spam ou préparer d’autres attaques...

🔍 wp2shell.com , pour vérifier si votre site est vulnérable.

Dans les news:
"WP2Shell - La faille qui permet de pirater WordPress sans aucun plugin"
👇
korben.info/wp2shell-exploits-

💬
⬇️
infosec.pub/post/49724018

#CyberVeille #WordPress

##

cert_fr@social.numerique.gouv.fr at 2026-07-20T08:52:21.000Z ##

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-60137 et CVE-2026-63030 affectent WordPress et permettent une exécution de code arbitraire à distance non authentifiée.
Une preuve de concept est disponible.

cert.ssi.gouv.fr/alerte/CERTFR

##

offseq@infosec.exchange at 2026-07-20T04:30:24.000Z ##

wp2shell (CVE-2026-63030, CVE-2026-60137) allows unauth RCE in WordPress core (HIGH severity). Active exploitation reported. Patch to 6.9.5, 7.0.2, or 6.8.6. Block REST API batch endpoint if needed. Details: radar.offseq.com/threat/wp2she #OffSeq #WordPress #RCE #Vulnerability

##

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

_r_netsec@infosec.exchange at 2026-07-19T23:58:05.000Z ##

wp2shell: a defender’s guide (CVE-2026-63030 + CVE-2026-60137) with a list of forensic artifacts, a compromise scanner WordPress plugin and a free Chrome/Edge/Firefox browser extension to in-browser check if a website has been patched. research.eye.security/wp2shell

##

CVE-2026-60137
(5.9 MEDIUM)

EPSS: 20.39%

updated 2026-07-22T05:17:11.750000

18 posts

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

39 repos

https://github.com/ekomsSavior/wp2shell

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/mcipekci/wp2shell

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/ebrasha/abdal-cve-2026-60137

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/Icex0/wp2shell-poc

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/securelayer7/WordPresShell

https://github.com/dinosn/wp2shell-lab

https://github.com/wn-iqbal/wp2shell

https://github.com/ananay/wp2shell-lab

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/Crypto-Cat/wp2shell

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/0xWhoknows/wp2shell

https://github.com/0xsha/wp2shell

https://github.com/NULL200OK/WP2Shell

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/47Cid/wp2shell-lab

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/yoerivegt/wp2shell-poc

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/h4cd0c/wp2shell

https://github.com/kulichr/wp2shell

https://github.com/bahartanir/wp2shell-scanner

https://github.com/vulnquest58/PressVector

https://github.com/0xjessie21/wp2shell-checker

https://github.com/ikow/wp2shell

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/zi3lak/wp2shell_scanner

Matchbook3469@mastodon.social at 2026-07-22T17:22:26.000Z ##

🔵 THREAT INTELLIGENCE

Critical wp2shell WordPress flaws exploited to install webshells

Vulnerability | CRITICAL
CVEs: CVE-2026-60137, CVE-2026-63030

Hackers are exploiting the 'wp2shell' critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent...

Full analysis:
yazoul.net/news/article/critic

#InfoSec #ZeroDay #SecurityOps

##

netsecio@mastodon.social at 2026-07-22T16:49:30.000Z ##

📰 CISA Adds Four Actively Exploited Flaws in DD-WRT, Langflow, WordPress

CISA adds 4 actively exploited vulnerabilities to its KEV catalog: CVE-2021-27137 (DD-WRT), CVE-2026-0770 (Langflow), and CVE-2026-63030 & CVE-2026-60137 (WordPress). Patching is urgent. #CISA #KEV #Vulnerability #PatchNow #WordPress

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ci

##

thecybermind at 2026-07-22T13:49:27.778Z ##

⚠️ THREAT ALERT: CVE-2026-60137 in WordPress Core enables unauthenticated SQL injection that chains for remote code execution! Active exploitation is confirmed. Get the forensic detection queries and hardening strategies you need to protect your web assets now. thecybermind.co/12b8

##

thecybermind@infosec.exchange at 2026-07-22T13:49:27.000Z ##

⚠️ THREAT ALERT: CVE-2026-60137 in WordPress Core enables unauthenticated SQL injection that chains for remote code execution! Active exploitation is confirmed. Get the forensic detection queries and hardening strategies you need to protect your web assets now. thecybermind.co/12b8

#CyberSecurity #InfoSec #WordPress #ThreatIntel

##

hyoyoshikawa@toot.blue at 2026-07-22T00:06:05.000Z ##

WordPressに認証不要でコード実行される緊急の脆弱性 即時更新を呼び掛け

itmedia.co.jp/news/articles/26

 WordPressの開発チームは7月17日(米国時間)、深刻な2件の脆弱性を修正したセキュリティリリース「WordPress 7.0.2」を公開した。

 1件は深刻度「Critical」(緊急)と評価された認証不要のリモートコード実行(RCE)の脆弱性(CVE-2026-63030)で、REST APIのバッチ処理エンドポイントを悪用されると、ログインやユーザーの操作なしに攻撃者が任意のコードを実行できる恐れがある。
もう1件は「High」(高)と評価されたSQLインジェクションの脆弱性(CVE-2026-60137)で、細工した入力によってデータベースへのクエリを改ざんされる可能性がある。なお、RCEはこのSQLインジェクションに起因しているという。

##

oversecurity@mastodon.social at 2026-07-21T17:10:36.000Z ##

Critical wp2shell WordPress flaws exploited to install webshells

Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy...

🔗️ [Bleepingcomputer] link.is.it/KxezNe

##

secdb@infosec.exchange at 2026-07-21T17:00:12.000Z ##

🚨 [CISA-2026:0721] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2021-27137 (secdb.nttzen.cloud/cve/detail/)
- Name: DD-WRT Stack-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: DD-WRT
- Product: DD-WRT
- Notes: This vulnerability affects a common open-source component, third-party library, proprietary implementation, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: svn.dd-wrt.com/changeset/45724 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-0770 (secdb.nttzen.cloud/cve/detail/)
- Name: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Langflow
- Product: Langflow
- Notes: github.com/langflow-ai/langflo ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-60137 (secdb.nttzen.cloud/cve/detail/)
- Name: WordPress Core SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WordPress
- Product: Core
- Notes: wordpress.org/news/2026/07/wor ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-63030 (secdb.nttzen.cloud/cve/detail/)
- Name: WordPress Core Interpretation Conflict Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WordPress
- Product: Core
- Notes: wordpress.org/news/2026/07/wor ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260721 #cisa20260721 #cve_2021_27137 #cve_2026_0770 #cve_2026_60137 #cve_2026_63030 #cve202127137 #cve20260770 #cve202660137 #cve202663030

##

marcel@waldvogel.family at 2026-07-21T16:00:57.000Z ##

#IoC von #wp2shell suchen:

- Webserverlogs

`zgrep /batch/v1 *.log *.log.gz | egrep '45.79.167[.]238|34.81.132[.]62|79.177.131[.]206|15.157.135[.]170|94.100.52[.]128|172.235.128[.]52'`

- Wordpress-Verzeichnis

`find . -type f -print0 | xargs -0 md5sum | egrep '2a1410d8e2a8337ac2171cedea8c0fdc47c647a0|58eca847e9eae9e6b08cc211f1559817b71bc4cc|ebea44890f434d5d67ede22009a3f4bb5cac33f8|d9a220c8039f1c4d72cae7ccb8b3a33dec8815be|e9756e2338f84746007235e4cab7a70d5b3ca47f'`

wiz.io/blog/wp2shell-cve-2026-

##

cisakevtracker@mastodon.social at 2026-07-21T16:00:50.000Z ##

CVE ID: CVE-2026-60137
Vendor: WordPress
Product: Core
Date Added: 2026-07-21
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-07-21T14:57:02.000Z ##

Broadcom has new advisories for two medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

CISA KEV updates:

- CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Vulnerability cve.org/CVERecord?id=CVE-2021-

- CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-63030: WordPress Core Interpretation Conflict Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-60137L WordPress Core SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #WordPress #vulnerability #infosec

##

DailyCyberSecurity@infosec.exchange at 2026-07-21T01:50:36.000Z ##

wp2shell, a WordPress Core RCE chain (CVE-2026-63030, CVE-2026-60137), is exploited in the wild. Public PoC code is out. Patch WordPress now.

#wp2shell #WordPress #RCE #CVE202663030 #CVE202660137 #InfoSec #WebSecurity #PatchNow

securityonline.info/wp2shell-w

##

Xidewo@unredacted.social at 2026-07-20T16:32:01.000Z ##

W cyberpodziemiu opublikowano exploity wykorzystujące krytyczne luki RCE typu „wp2shell” występujące przed uwierzytelnieniem, które dotyczą jądra WordPressa. W wersjach WordPressa 6.9.5 i 7.0.2 naprawiono cały łańcuch ataków typu wp2shell. Atak typu wp2shell składa się z dwóch luk – CVE-2026-63030 i CVE-2026-60137, które można połączyć w celu zdalnego wykonania kodu przed uwierzytelnieniem w instalacjach WordPressa w wersjach 6.9. i 7.0.

##

AAKL@infosec.exchange at 2026-07-20T15:22:11.000Z ##

New.

Picus: CVE-2026-63030 and CVE-2026-60137 (wp2shell): WordPress RCE Explained picussecurity.com/resource/blo #infosec #vulnerability #WordPress

##

bsi@social.bund.de at 2026-07-20T10:00:13.000Z ##

⚠️ 📢 #Sicherheitswarnung: WordPress – Schwachstellen erlauben "Remote Code Execution"

Am 17. Juli 2026 wurde seitens #Wordpress eine Aktualisierung bekannt gegeben, die zwei #Schwachstellen in der Wordpress-Software behebt.

❗️ Die beiden Schwachstellen CVE-2026-60137 und CVE-2026-63030 ermöglichen einem nicht authentifizierten, entfernten Angreifer Code zur Ausführung zu bringen.

Mehr dazu hier: 👉️ bsi.bund.de/dok/1203360

@certbund

##

decio@infosec.exchange at 2026-07-20T08:58:22.000Z ##

⚠️ Si vous administrez un site WordPress ou si vous connaissez quelqu’un qui en gère un faites passer l’information.

Une vulnérabilité critique baptisée WP2Shell touche directement le cœur de WordPress.

Cette fois, il ne s’agit pas d’un plugin abandonné ou d’un thème douteux : une installation standard peut être attaquée à distance, sans compte utilisateur, sans mot de passe et sans authentification préalable.

WP2Shell combine deux failles, CVE-2026-60137 et CVE-2026-63030, permettant à un attaquant d’exécuter du code sur le serveur et donc, potentiellement, de prendre le contrôle du site.

-> Des tentatives d’exploitation et des compromissions ont déjà été observées dans la nature.

Sont notamment concernées les versions :

➡️ WordPress 6.9.0 à 6.9.4
➡️ WordPress 7.0.0 à 7.0.1

Les correctifs sont disponibles dans les versions 6.9.5 et 7.0.2. WordPress a activé des mises à jour automatiques forcées en raison de la gravité de la faille, mais il ne faut pas supposer qu’elles ont forcément fonctionné : elles peuvent avoir été désactivées, bloquées par l’hébergeur ou empêchées par une configuration particulière.

À faire rapidement:

✅ vérifier la version réellement installée ;
✅ mettre WordPress à jour vers 6.9.5 ou 7.0.2 au minimum ;
✅ confirmer que la mise à jour s’est correctement terminée ;
✅ vérifier les comptes administrateurs, les fichiers récemment modifiés et les journaux du serveur ;
✅ rechercher d’éventuels fichiers PHP, plugins ou utilisateurs inconnus ;
✅ s’assurer que des sauvegardes propres et récentes sont disponibles.

En attendant la mise à jour, l’accès anonyme aux routes REST suivantes peut également être bloqué au niveau du WAF ou du serveur web :

/wp-json/batch/v1
?rest_route=/batch/v1

Point important : installer le correctif empêche une nouvelle exploitation, mais ne supprime pas une éventuelle compromission déjà présente. Si le site est resté exposé, une vérification minimale est donc nécessaire, même après la mise à jour.

Un site WordPress « qui fonctionne encore » n’est pas nécessairement un site sain : les attaquants cherchent souvent à rester discrets pour installer une porte dérobée, détourner le trafic, diffuser du spam ou préparer d’autres attaques...

🔍 wp2shell.com , pour vérifier si votre site est vulnérable.

Dans les news:
"WP2Shell - La faille qui permet de pirater WordPress sans aucun plugin"
👇
korben.info/wp2shell-exploits-

💬
⬇️
infosec.pub/post/49724018

#CyberVeille #WordPress

##

cert_fr@social.numerique.gouv.fr at 2026-07-20T08:52:21.000Z ##

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-60137 et CVE-2026-63030 affectent WordPress et permettent une exécution de code arbitraire à distance non authentifiée.
Une preuve de concept est disponible.

cert.ssi.gouv.fr/alerte/CERTFR

##

offseq@infosec.exchange at 2026-07-20T04:30:24.000Z ##

wp2shell (CVE-2026-63030, CVE-2026-60137) allows unauth RCE in WordPress core (HIGH severity). Active exploitation reported. Patch to 6.9.5, 7.0.2, or 6.8.6. Block REST API batch endpoint if needed. Details: radar.offseq.com/threat/wp2she #OffSeq #WordPress #RCE #Vulnerability

##

_r_netsec@infosec.exchange at 2026-07-19T23:58:05.000Z ##

wp2shell: a defender’s guide (CVE-2026-63030 + CVE-2026-60137) with a list of forensic artifacts, a compromise scanner WordPress plugin and a free Chrome/Edge/Firefox browser extension to in-browser check if a website has been patched. research.eye.security/wp2shell

##

CVE-2026-0770
(9.8 CRITICAL)

EPSS: 54.50%

updated 2026-07-22T05:17:08.693000

8 posts

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The

Nuclei template

6 repos

https://github.com/Ez4rd1x1/CVE-2026-0770

https://github.com/affix/CVE-2026-0770-PoC

https://github.com/0xgh057r3c0n/CVE-2026-0770

https://github.com/0xBlackash/CVE-2026-0770

https://github.com/diamorphine666/CVE-2026-0770

https://github.com/Yetazyyy/CVE-2026-0770

netsecio@mastodon.social at 2026-07-22T16:49:30.000Z ##

📰 CISA Adds Four Actively Exploited Flaws in DD-WRT, Langflow, WordPress

CISA adds 4 actively exploited vulnerabilities to its KEV catalog: CVE-2021-27137 (DD-WRT), CVE-2026-0770 (Langflow), and CVE-2026-63030 & CVE-2026-60137 (WordPress). Patching is urgent. #CISA #KEV #Vulnerability #PatchNow #WordPress

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ci

##

Analyst207@mastodon.social at 2026-07-22T12:06:54.000Z ##

CISA Targets Langflow Flaw in Urgent Patch Directive

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent patch directive for a vulnerability in the Langflow visual framework, used to build AI agents, after recording over 220 exploitation attempts in just one day. This critical flaw, tracked as CVE-2026-0770, has already been exploited by multiple attackers, prompting…

osintsights.com/cisa-targets-l

#Cve20260770 #Langflow #AiAgents #KnownExploitedVulnerabilities #Kev

##

thecybermind at 2026-07-22T10:32:12.465Z ##

⚠️ CRITICAL THREAT: CVE-2026-0770 in Langflow enables remote code execution via untrusted control sphere inclusion. Active exploitation is confirmed. Get the forensic detection and input hardening strategies required to secure your AI pipelines today. thecybermind.co/aigl

##

thecybermind@infosec.exchange at 2026-07-22T10:32:12.000Z ##

⚠️ CRITICAL THREAT: CVE-2026-0770 in Langflow enables remote code execution via untrusted control sphere inclusion. Active exploitation is confirmed. Get the forensic detection and input hardening strategies required to secure your AI pipelines today. thecybermind.co/aigl

#CyberSecurity #InfoSec #Langflow #AI #ThreatIntel

##

secdb@infosec.exchange at 2026-07-21T17:00:12.000Z ##

🚨 [CISA-2026:0721] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2021-27137 (secdb.nttzen.cloud/cve/detail/)
- Name: DD-WRT Stack-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: DD-WRT
- Product: DD-WRT
- Notes: This vulnerability affects a common open-source component, third-party library, proprietary implementation, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: svn.dd-wrt.com/changeset/45724 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-0770 (secdb.nttzen.cloud/cve/detail/)
- Name: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Langflow
- Product: Langflow
- Notes: github.com/langflow-ai/langflo ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-60137 (secdb.nttzen.cloud/cve/detail/)
- Name: WordPress Core SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WordPress
- Product: Core
- Notes: wordpress.org/news/2026/07/wor ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-63030 (secdb.nttzen.cloud/cve/detail/)
- Name: WordPress Core Interpretation Conflict Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WordPress
- Product: Core
- Notes: wordpress.org/news/2026/07/wor ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260721 #cisa20260721 #cve_2021_27137 #cve_2026_0770 #cve_2026_60137 #cve_2026_63030 #cve202127137 #cve20260770 #cve202660137 #cve202663030

##

DailyCyberSecurity@infosec.exchange at 2026-07-21T16:32:21.000Z ##

CISA added four flaws to its KEV catalog, including WordPress RCE (CVE-2026-63030) and Langflow RCE (CVE-2026-0770). All are exploited in the wild.

#CISA #KEV #WordPress #Langflow #DDWRT #RCE #SQLInjection

securityonline.info/cisa-kev-f

##

cisakevtracker@mastodon.social at 2026-07-21T16:01:21.000Z ##

CVE ID: CVE-2026-0770
Vendor: Langflow
Product: Langflow
Date Added: 2026-07-21
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-07-21T14:57:02.000Z ##

Broadcom has new advisories for two medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

CISA KEV updates:

- CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Vulnerability cve.org/CVERecord?id=CVE-2021-

- CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-63030: WordPress Core Interpretation Conflict Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-60137L WordPress Core SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #WordPress #vulnerability #infosec

##

CVE-2021-27137
(8.1 HIGH)

EPSS: 10.81%

updated 2026-07-22T05:17:07.330000

6 posts

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachab

netsecio@mastodon.social at 2026-07-22T16:49:30.000Z ##

📰 CISA Adds Four Actively Exploited Flaws in DD-WRT, Langflow, WordPress

CISA adds 4 actively exploited vulnerabilities to its KEV catalog: CVE-2021-27137 (DD-WRT), CVE-2026-0770 (Langflow), and CVE-2026-63030 & CVE-2026-60137 (WordPress). Patching is urgent. #CISA #KEV #Vulnerability #PatchNow #WordPress

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ci

##

thecybermind at 2026-07-22T03:55:04.467Z ##

⚠️ CRITICAL THREAT: CVE-2021-27137 in DD-WRT allows unauthenticated remote code execution via UPnP. With active exploitation verified, edge defense is critical. Get the forensic detection and hardening strategies you need to secure your infrastructure.

thecybermind.co/5jv3

##

thecybermind@infosec.exchange at 2026-07-22T03:55:04.000Z ##

⚠️ CRITICAL THREAT: CVE-2021-27137 in DD-WRT allows unauthenticated remote code execution via UPnP. With active exploitation verified, edge defense is critical. Get the forensic detection and hardening strategies you need to secure your infrastructure. #CyberSecurity #InfoSec #DDWRT #Networking

thecybermind.co/5jv3

##

secdb@infosec.exchange at 2026-07-21T17:00:12.000Z ##

🚨 [CISA-2026:0721] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2021-27137 (secdb.nttzen.cloud/cve/detail/)
- Name: DD-WRT Stack-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: DD-WRT
- Product: DD-WRT
- Notes: This vulnerability affects a common open-source component, third-party library, proprietary implementation, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: svn.dd-wrt.com/changeset/45724 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-0770 (secdb.nttzen.cloud/cve/detail/)
- Name: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Langflow
- Product: Langflow
- Notes: github.com/langflow-ai/langflo ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-60137 (secdb.nttzen.cloud/cve/detail/)
- Name: WordPress Core SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WordPress
- Product: Core
- Notes: wordpress.org/news/2026/07/wor ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-63030 (secdb.nttzen.cloud/cve/detail/)
- Name: WordPress Core Interpretation Conflict Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: WordPress
- Product: Core
- Notes: wordpress.org/news/2026/07/wor ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260721 #cisa20260721 #cve_2021_27137 #cve_2026_0770 #cve_2026_60137 #cve_2026_63030 #cve202127137 #cve20260770 #cve202660137 #cve202663030

##

cisakevtracker@mastodon.social at 2026-07-21T16:01:37.000Z ##

CVE ID: CVE-2021-27137
Vendor: DD-WRT
Product: DD-WRT
Date Added: 2026-07-21
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-07-21T14:57:02.000Z ##

Broadcom has new advisories for two medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

CISA KEV updates:

- CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Vulnerability cve.org/CVERecord?id=CVE-2021-

- CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-63030: WordPress Core Interpretation Conflict Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-60137L WordPress Core SQL Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA #WordPress #vulnerability #infosec

##

CVE-2026-65315
(7.5 HIGH)

EPSS: 0.57%

updated 2026-07-22T00:32:45

1 posts

Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted GGUF file with attacker-controlled length and count fields in string lengths, tensor dimension counts, and metadata array counts that are used as allocation sizes without validation against remaining file size. Attackers

thehackerwire@mastodon.social at 2026-07-21T23:00:06.000Z ##

🟠 CVE-2026-65315 - High (7.5)

Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted GGUF file with attacker-controlled length and count fields in string...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65319
(7.5 HIGH)

EPSS: 0.37%

updated 2026-07-22T00:32:44

2 posts

Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the authorization before-action filter entirely. Attackers can iterate sequential integer entry IDs through the GET /api/v2/entries/:id/text endpoint to enumerate and ext

thehackerwire@mastodon.social at 2026-07-22T08:00:31.000Z ##

🟠 CVE-2026-65319 - High (7.5)

Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the authorization...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-22T08:00:31.000Z ##

🟠 CVE-2026-65319 - High (7.5)

Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the authorization...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65318
(8.6 HIGH)

EPSS: 0.42%

updated 2026-07-22T00:32:44

1 posts

Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint. Attackers can connect to the /ws/import_files WebSocket endpoint without authentication, specify arbitrary URLs in the HT

thehackerwire@mastodon.social at 2026-07-21T23:00:24.000Z ##

🟠 CVE-2026-65318 - High (8.6)

Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65317
(8.6 HIGH)

EPSS: 0.48%

updated 2026-07-22T00:32:44

1 posts

Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a crafted Origin header and attacker-controlled host and port values. Attackers can bypass the localhost origin check in the API middleware by sending any Ori

thehackerwire@mastodon.social at 2026-07-21T23:00:15.000Z ##

🟠 CVE-2026-65317 - High (8.6)

Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a cra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-60926
(7.2 HIGH)

EPSS: 0.50%

updated 2026-07-22T00:32:12

1 posts

Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sec

hugovalters@mastodon.social at 2026-07-22T12:01:51.000Z ##

CVE-2026-60926 - High severity privilege escalation in Oracle E-Business Suite Public Sector Payroll (12.2.3-12.2.15). CVSS 7.2. No patch available. Review access controls immediately. #CVE #Oracle #infosec

valtersit.com/cve/CVE-2026-609

##

CVE-2026-60785
(8.1 HIGH)

EPSS: 0.38%

updated 2026-07-22T00:32:06

1 posts

Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (component: AR Web Utilities). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iReceivables. Successful attacks of this vulnerability can result in takeover of Oracle iReceivables. CVSS 3.1 Base S

hugovalters@mastodon.social at 2026-07-22T15:05:10.000Z ##

CVE-2026-60785 - High-severity supply chain attack in Oracle iReceivables (E-Business Suite 12.2.3-12.2.15). Unauthenticated takeover via HTTP. CVSS 8.1. No patch available. Monitor and restrict access immediately. #CVE #Oracle #infosec

valtersit.com/cve/CVE-2026-607

##

CVE-2026-60799
(7.1 HIGH)

EPSS: 0.30%

updated 2026-07-22T00:32:06

1 posts

Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Compensation Workbench. Successful attacks of this vulnerability can result in unauthorized access to c

hugovalters@mastodon.social at 2026-07-22T11:14:28.000Z ##

CVE-2026-60799 - Oracle E-Business Suite (Compensation Workbench) info leak. Low-privilege HTTP exploit exposes critical data. CVSS 7.1. No patch yet. Restrict access now. #CVE #Oracle #infosec

valtersit.com/cve/CVE-2026-607

##

CVE-2026-60642
(7.6 HIGH)

EPSS: 0.22%

updated 2026-07-22T00:32:00

1 posts

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker.

hugovalters@mastodon.social at 2026-07-22T14:10:29.000Z ##

CVE-2026-60642 - High-severity DoS in Oracle WebCenter Content. Unauthenticated HTTP access. CVSS 7.6. No patch available. Mitigate immediately. #CVE #Oracle #infosec

valtersit.com/cve/CVE-2026-606

##

CVE-2026-60306
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-07-22T00:31:40

1 posts

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CV

infosecbot@mastodon.hofud.com at 2026-07-22T06:23:31.000Z ##

[1/3]

Most impactful security incidents / vulnerabilities reported between the last update (July 21‑22 2026) and today

1
• CVE‑2026‑60308
• Oracle Coherence (Core) – part of Oracle Fusion Middleware
• Remote, unauthenticated attacker can gain full control of the Coherence service (RCE / complete takeover).
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)
• Oracle [advisory](oracle.com/security-alerts/cpu)

2
• CVE‑2026‑60306
• Oracle Coherence (Core)
• Same remote‑code‑execution / takeover scenario as above.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

3
• CVE‑2026‑60300
• Oracle Coherence (Core)
• Remote unauthenticated takeover of the Coherence service.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

4
• CVE‑2026‑60299
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

5
• CVE‑2026‑60298
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

6
• CVE‑2026‑60297
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

7
• CVE‑2026‑60296
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

8
• CVE‑2026‑60295 (not listed but implied by the series) – if present would follow same pattern; however, only the above IDs are confirmed in the supplied data.

#infosecnews

##

CVE-2026-60297
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-07-22T00:31:40

1 posts

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CV

infosecbot@mastodon.hofud.com at 2026-07-22T06:23:31.000Z ##

[1/3]

Most impactful security incidents / vulnerabilities reported between the last update (July 21‑22 2026) and today

1
• CVE‑2026‑60308
• Oracle Coherence (Core) – part of Oracle Fusion Middleware
• Remote, unauthenticated attacker can gain full control of the Coherence service (RCE / complete takeover).
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)
• Oracle [advisory](oracle.com/security-alerts/cpu)

2
• CVE‑2026‑60306
• Oracle Coherence (Core)
• Same remote‑code‑execution / takeover scenario as above.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

3
• CVE‑2026‑60300
• Oracle Coherence (Core)
• Remote unauthenticated takeover of the Coherence service.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

4
• CVE‑2026‑60299
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

5
• CVE‑2026‑60298
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

6
• CVE‑2026‑60297
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

7
• CVE‑2026‑60296
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

8
• CVE‑2026‑60295 (not listed but implied by the series) – if present would follow same pattern; however, only the above IDs are confirmed in the supplied data.

#infosecnews

##

CVE-2026-60299
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-07-22T00:31:40

1 posts

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base

infosecbot@mastodon.hofud.com at 2026-07-22T06:23:31.000Z ##

[1/3]

Most impactful security incidents / vulnerabilities reported between the last update (July 21‑22 2026) and today

1
• CVE‑2026‑60308
• Oracle Coherence (Core) – part of Oracle Fusion Middleware
• Remote, unauthenticated attacker can gain full control of the Coherence service (RCE / complete takeover).
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)
• Oracle [advisory](oracle.com/security-alerts/cpu)

2
• CVE‑2026‑60306
• Oracle Coherence (Core)
• Same remote‑code‑execution / takeover scenario as above.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

3
• CVE‑2026‑60300
• Oracle Coherence (Core)
• Remote unauthenticated takeover of the Coherence service.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

4
• CVE‑2026‑60299
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

5
• CVE‑2026‑60298
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

6
• CVE‑2026‑60297
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

7
• CVE‑2026‑60296
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

8
• CVE‑2026‑60295 (not listed but implied by the series) – if present would follow same pattern; however, only the above IDs are confirmed in the supplied data.

#infosecnews

##

CVE-2026-60298
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-07-22T00:31:40

1 posts

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base

infosecbot@mastodon.hofud.com at 2026-07-22T06:23:31.000Z ##

[1/3]

Most impactful security incidents / vulnerabilities reported between the last update (July 21‑22 2026) and today

1
• CVE‑2026‑60308
• Oracle Coherence (Core) – part of Oracle Fusion Middleware
• Remote, unauthenticated attacker can gain full control of the Coherence service (RCE / complete takeover).
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)
• Oracle [advisory](oracle.com/security-alerts/cpu)

2
• CVE‑2026‑60306
• Oracle Coherence (Core)
• Same remote‑code‑execution / takeover scenario as above.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

3
• CVE‑2026‑60300
• Oracle Coherence (Core)
• Remote unauthenticated takeover of the Coherence service.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

4
• CVE‑2026‑60299
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

5
• CVE‑2026‑60298
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

6
• CVE‑2026‑60297
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

7
• CVE‑2026‑60296
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

8
• CVE‑2026‑60295 (not listed but implied by the series) – if present would follow same pattern; however, only the above IDs are confirmed in the supplied data.

#infosecnews

##

CVE-2026-60300
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-07-22T00:31:32

1 posts

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CV

infosecbot@mastodon.hofud.com at 2026-07-22T06:23:31.000Z ##

[1/3]

Most impactful security incidents / vulnerabilities reported between the last update (July 21‑22 2026) and today

1
• CVE‑2026‑60308
• Oracle Coherence (Core) – part of Oracle Fusion Middleware
• Remote, unauthenticated attacker can gain full control of the Coherence service (RCE / complete takeover).
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)
• Oracle [advisory](oracle.com/security-alerts/cpu)

2
• CVE‑2026‑60306
• Oracle Coherence (Core)
• Same remote‑code‑execution / takeover scenario as above.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

3
• CVE‑2026‑60300
• Oracle Coherence (Core)
• Remote unauthenticated takeover of the Coherence service.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

4
• CVE‑2026‑60299
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

5
• CVE‑2026‑60298
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

6
• CVE‑2026‑60297
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

7
• CVE‑2026‑60296
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

8
• CVE‑2026‑60295 (not listed but implied by the series) – if present would follow same pattern; however, only the above IDs are confirmed in the supplied data.

#infosecnews

##

CVE-2026-60656
(8.8 HIGH)

EPSS: 0.45%

updated 2026-07-21T22:18:06.597000

1 posts

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle Web

hugovalters@mastodon.social at 2026-07-22T17:03:51.000Z ##

CVE-2026-60656 - Authentication bypass in Oracle WebCenter Content. Low-privilege network access leads to full takeover. CVSS 8.8. No patch yet. Mitigate immediately. #CVE #Oracle #infosec

valtersit.com/cve/CVE-2026-606

##

CVE-2026-60308
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-07-21T22:17:33.490000

1 posts

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base

infosecbot@mastodon.hofud.com at 2026-07-22T06:23:31.000Z ##

[1/3]

Most impactful security incidents / vulnerabilities reported between the last update (July 21‑22 2026) and today

1
• CVE‑2026‑60308
• Oracle Coherence (Core) – part of Oracle Fusion Middleware
• Remote, unauthenticated attacker can gain full control of the Coherence service (RCE / complete takeover).
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)
• Oracle [advisory](oracle.com/security-alerts/cpu)

2
• CVE‑2026‑60306
• Oracle Coherence (Core)
• Same remote‑code‑execution / takeover scenario as above.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

3
• CVE‑2026‑60300
• Oracle Coherence (Core)
• Remote unauthenticated takeover of the Coherence service.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

4
• CVE‑2026‑60299
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

5
• CVE‑2026‑60298
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

6
• CVE‑2026‑60297
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

7
• CVE‑2026‑60296
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

8
• CVE‑2026‑60295 (not listed but implied by the series) – if present would follow same pattern; however, only the above IDs are confirmed in the supplied data.

#infosecnews

##

CVE-2026-60296
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-07-21T22:17:32.160000

1 posts

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CV

infosecbot@mastodon.hofud.com at 2026-07-22T06:23:31.000Z ##

[1/3]

Most impactful security incidents / vulnerabilities reported between the last update (July 21‑22 2026) and today

1
• CVE‑2026‑60308
• Oracle Coherence (Core) – part of Oracle Fusion Middleware
• Remote, unauthenticated attacker can gain full control of the Coherence service (RCE / complete takeover).
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)
• Oracle [advisory](oracle.com/security-alerts/cpu)

2
• CVE‑2026‑60306
• Oracle Coherence (Core)
• Same remote‑code‑execution / takeover scenario as above.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

3
• CVE‑2026‑60300
• Oracle Coherence (Core)
• Remote unauthenticated takeover of the Coherence service.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

4
• CVE‑2026‑60299
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

5
• CVE‑2026‑60298
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

6
• CVE‑2026‑60297
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

7
• CVE‑2026‑60296
• Oracle Coherence (Core)
• Remote unauthenticated takeover via TCP/HTTP.
• 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
• 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
• CVE [API](cveawg.mitre.org/api/cve/CVE-2)

8
• CVE‑2026‑60295 (not listed but implied by the series) – if present would follow same pattern; however, only the above IDs are confirmed in the supplied data.

#infosecnews

##

CVE-2026-60206
(9.9 CRITICAL)

EPSS: 0.48%

updated 2026-07-21T22:17:21.953000

2 posts

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SAML to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significa

CVE-2026-16221
(7.5 HIGH)

EPSS: 0.22%

updated 2026-07-21T22:08:29

1 posts

### Impact `fast-uri` v4.1.0 and earlier do not treat a literal backslash (U+005C) as an authority delimiter. Node's native WHATWG `URL` (used by `fetch()`, `undici`, and Node's `http`/`https` clients) normalizes `\` to `/` for special schemes (`http`, `https`, `ws`, `wss`, `ftp`, `file`), so the two parsers extract different hosts from the same input string. For example, `http://evil.com\@allow

thehackerwire@mastodon.social at 2026-07-19T15:59:50.000Z ##

🟠 CVE-2026-16221 - High (7.5)

Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, und...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8983(CVSS UNKNOWN)

EPSS: 0.33%

updated 2026-07-21T21:32:53

1 posts

Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functionality without valid authentication.

offseq@infosec.exchange at 2026-07-22T01:30:25.000Z ##

CVE-2026-8983: Autel Maxi Charger Single ≤1.03.51 is affected by a CRITICAL flaw — hard-coded token bypasses authentication, exposing management endpoints. Restrict access & monitor for abuse. Patch status unknown. radar.offseq.com/threat/autel- #OffSeq #CVE20268983 #IoTSecurity

##

CVE-2026-65057
(9.3 CRITICAL)

EPSS: 0.25%

updated 2026-07-21T21:32:53

1 posts

Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthcheck endpoint. Attackers can send a crafted JSON payload with a malicious host parameter to cause the backend to issue outbound requests to internal services or cloud

thehackerwire@mastodon.social at 2026-07-21T22:00:11.000Z ##

🔴 CVE-2026-65057 - Critical (9.3)

Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host values to the unprotected healthcheck endpoint...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65056
(8.2 HIGH)

EPSS: 0.23%

updated 2026-07-21T21:32:53

1 posts

mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validates the URL protocol without filtering private or reserved IP ranges. Attackers can steer the LLM-controlled URL argument through prompt injection to navigate the

thehackerwire@mastodon.social at 2026-07-21T22:00:01.000Z ##

🟠 CVE-2026-65056 - High (8.2)

mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validates the UR...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64877
(8.4 HIGH)

EPSS: 0.19%

updated 2026-07-21T21:32:46

1 posts

An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.

thehackerwire@mastodon.social at 2026-07-21T20:00:19.000Z ##

🔴 CVE-2026-64877 - Critical (9.6)

An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-51027
(9.9 CRITICAL)

EPSS: 0.34%

updated 2026-07-21T20:27:18.523000

1 posts

An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.

thehackerwire@mastodon.social at 2026-07-20T17:00:12.000Z ##

🔴 CVE-2026-51027 - Critical (9.9)

An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56750(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-07-21T20:20:23

2 posts

The vulnerability is in the Remember-Me (gitea_incredible) token validation logic, specifically when handling a compromised token (hash mismatch). The vulnerable function is this one: https://github.com/go-gitea/gitea/blob/689ace1ce28fd74244b8aa335d9928cdbf6b22f9/services/auth/auth_token.go#L33-L64 ### Affected Endpoint POST `/user/login` (and any endpoint triggering `autoSignIn` via the Rememb

offseq at 2026-07-22T06:00:26.105Z ##

Gitea <1.27.0 has a CRITICAL flaw (CVE-2026-56750): Compromised Remember-Me tokens are not fully invalidated, letting attackers keep access indefinitely. Disable Remember-Me or monitor sessions. Details: radar.offseq.com/threat/gitea-

##

offseq@infosec.exchange at 2026-07-22T06:00:26.000Z ##

Gitea <1.27.0 has a CRITICAL flaw (CVE-2026-56750): Compromised Remember-Me tokens are not fully invalidated, letting attackers keep access indefinitely. Disable Remember-Me or monitor sessions. Details: radar.offseq.com/threat/gitea- #OffSeq #Gitea #CVE202656750 #infosec

##

CVE-2026-55084
(8.8 HIGH)

EPSS: 0.25%

updated 2026-07-21T20:17:02.277000

1 posts

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL injection vulnerability was identified in the SqlView API endpoint of the DHIS2 application in the `filter` parameter used by the `/api/sqlViews/{viewId}/data.json` endpoint. An authenticated user with access to a SqlView can inject arbitrary SQL queries inside the `filter` parameter

thehackerwire@mastodon.social at 2026-07-21T20:00:29.000Z ##

🟠 CVE-2026-55084 - High (8.8)

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL injection vulnerability was identified in the SqlView API endpoint of the DHIS2 application in the `filter` parameter used by the
`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16412
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-07-21T20:17:00.157000

1 posts

Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

offseq@infosec.exchange at 2026-07-21T13:30:33.000Z ##

CVE-2026-16412: CRITICAL memory safety issues in Firefox ESR 140.12 & 152 allow code execution, sandbox escape, info disclosure. Public exploits exist, but no in-the-wild attacks. Patch to 153/ESR 140.13. radar.offseq.com/threat/cve-20 #OffSeq #Firefox #Vuln #Security

##

CVE-2026-62228
(8.8 HIGH)

EPSS: 0.25%

updated 2026-07-21T19:58:20.277000

1 posts

OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attackers can exploit mismatched environment configurations to persist or execute actions that exceed the caller's approved permissions.

thehackerwire@mastodon.social at 2026-07-19T16:00:11.000Z ##

🟠 CVE-2026-62228 - High (8.8)

OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attackers can ex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-28307
(9.1 CRITICAL)

EPSS: 0.34%

updated 2026-07-21T18:31:10

1 posts

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.

DailyCyberSecurity@infosec.exchange at 2026-07-21T17:22:09.000Z ##

SolarWinds patched three critical Serv-U vulnerabilities (CVE-2026-28307/28308/28321). They allow privilege escalation and RCE. Update Serv-U to 2026.3.

#SolarWinds #ServU #PrivilegeEscalation #RCE #IDOR #Cybersecurity #Vulnerability

securityonline.info/solarwinds

##

CVE-2026-24232
(4.3 MEDIUM)

EPSS: 0.14%

updated 2026-07-21T18:31:10

1 posts

NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

AAKL@infosec.exchange at 2026-07-21T15:31:38.000Z ##

Nvidia update.

Security Bulletin: CVE-2026-24232: NVIDIA Transformers4Rec - July 2026 nvidia.custhelp.com/app/answer #Nvidia

Dell has an update for a vulnerability affecting a dizzying number of CVEs.

Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR) Security Update for Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #infosec #vulnerability

##

CVE-2026-44508
(0 None)

EPSS: 0.00%

updated 2026-07-21T16:17:10.850000

1 posts

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate.

thehackerwire@mastodon.social at 2026-07-20T22:01:10.000Z ##

🟠 CVE-2026-44508 - High (8.1)

Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, the receiver's compressed-token decoder accumulated a 32-bit signed counter without checking for overflow. A mali...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8933
(7.8 HIGH)

EPSS: 0.14%

updated 2026-07-21T15:30:51

4 posts

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or secur

Analyst207@mastodon.social at 2026-07-22T11:06:19.000Z ##

Ubuntu Vulnerability Exposes Local Users to Root Access Risk

A newly discovered vulnerability, CVE-2026-8933, puts users of Ubuntu Desktop 24.04, 25.10, and 26.04 at risk of full root access, allowing any local user to gain unrestricted control on default installs. This high-severity flaw can be easily exploited by a local, unprivileged user, making immediate attention crucial.

osintsights.com/ubuntu-vulnera

#UbuntuVulnerability #Cve20268933 #Qualys #Linux #LocalPrivilegeEscalation

##

lobsters@mastodon.social at 2026-07-21T21:45:16.000Z ##

Local Privilege Escalation in set-capabilities versions of snap-confine (CVE-2026-8933) lobste.rs/s/w7qez9 #linux #security
cdn2.qualys.com/advisory/2026/

##

DailyCyberSecurity@infosec.exchange at 2026-07-21T16:48:02.000Z ##

CVE-2026-8933 is a snap-confine privilege escalation flaw. It gives any user root on default Ubuntu Desktop 26.04, 25.10, and 24.04. Update snapd now.

#snapconfine #CVE20268933 #Ubuntu #PrivilegeEscalation #LPE #Linux #Qualys

securityonline.info/snap-confi

##

andersonc0d3@infosec.exchange at 2026-07-21T16:13:52.000Z ##

Local Privilege Escalation in set-capabilities versions of snap-confine (CVE-2026-8933)

seclists.org/oss-sec/2026/q3/1

##

CVE-2026-13142
(8.1 HIGH)

EPSS: 0.23%

updated 2026-07-21T15:30:34

1 posts

The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email address to brute-force the code and log in as that user, including an administrator,

offseq@infosec.exchange at 2026-07-20T07:30:25.000Z ##

CVE-2026-13142 | CRITICAL: Social Login, Passkeys, Magic Link & Email OTP WordPress plugin (pre-1.4.1) allows OTP brute-force due to no rate limiting + plaintext storage. Admin takeover possible. Disable or restrict plugin use until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

CVE-2026-47255
(8.2 HIGH)

EPSS: 0.18%

updated 2026-07-21T15:16:35.860000

1 posts

AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation; metadata-backed ownership checks for raw storage SQL; blocking direct storage metadata access through raw SQL; fail-closed ou

thehackerwire@mastodon.social at 2026-07-20T23:01:05.000Z ##

🟠 CVE-2026-47255 - High (8.2)

AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-1617
(9.8 CRITICAL)

EPSS: 0.26%

updated 2026-07-21T12:33:43

1 posts

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama allows SQL Injection. This issue affects Turkhotspot 5651 Loglama: from 5.1.2 before 5.1.3.

offseq@infosec.exchange at 2026-07-21T12:00:28.000Z ##

CVE-2026-1617: CRITICAL SQL injection (CWE-89, CVSS 9.8) impacts Turkmesh Turkhotspot 5651 Loglama v5.1.2. No patch — restrict service access & monitor vendor for updates. Full system compromise possible. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026_1617 #infosec #SQLi

##

CVE-2026-13439
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-07-21T06:31:24

1 posts

The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid') as the password reset token stored in wp_emsfb_temp_links, combined with a publicly-accessible nonce refresh endpoint (Emsfb/v1/nonce/

offseq@infosec.exchange at 2026-07-21T06:00:25.000Z ##

CVE-2026-13439: CRITICAL vuln in Easy Form Builder (WordPress) allows unauth'd attackers to reset any user password — including admins — via public session IDs & nonce endpoint. Site takeover risk. Restrict endpoints, monitor resets. radar.offseq.com/threat/cve-20 #OffSeq #CVE202613439 #WordPress

##

CVE-2026-15899(CVSS UNKNOWN)

EPSS: 0.22%

updated 2026-07-21T00:30:42

1 posts

Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

offseq@infosec.exchange at 2026-07-21T03:00:23.000Z ##

CVE-2026-15899 (CRITICAL): Use-after-free in Chrome’s CameraCapture on Mac (<150.0.7871.128) enables remote sandbox escape. Update now to 150.0.7871.128. radar.offseq.com/threat/cve-20 #OffSeq #CVE202615899 #Chrome #infosec

##

CVE-2026-15901(CVSS UNKNOWN)

EPSS: 0.23%

updated 2026-07-21T00:30:42

1 posts

Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

offseq@infosec.exchange at 2026-07-21T00:00:38.000Z ##

CVE-2026-15901: CRITICAL use-after-free in Chrome <150.0.7871.128 allows remote heap corruption via crafted HTML. No active exploits, patch status unclear — monitor advisories. radar.offseq.com/threat/cve-20 #OffSeq #Chrome #Vuln #InfoSec

##

CVE-2026-64625
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-07-21T00:30:37

2 posts

AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS commands through the Live plugin on_publish.php endpoint despite escapeshellarg() protection.

offseq@infosec.exchange at 2026-07-21T04:30:23.000Z ##

CVE-2026-64625 (CRITICAL): OS command injection in WWBN AVideo <29.0 via Live plugin's on_publish.php. Bypasses escapeshellarg(), enabling remote code execution. Restrict access & upgrade if possible. radar.offseq.com/threat/cve-20 #OffSeq #CVE202664625 #WWBNAVideo #infosec

##

thehackerwire@mastodon.social at 2026-07-20T23:00:19.000Z ##

🔴 CVE-2026-64625 - Critical (9.8)

AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS commands through the Live p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56452
(7.5 HIGH)

EPSS: 0.36%

updated 2026-07-21T00:30:28

1 posts

Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting in files to be written in attacker-controlled places. The issue affects on

thehackerwire@mastodon.social at 2026-07-20T22:00:27.000Z ##

🟠 CVE-2026-56452 - High (7.5)

Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH.

The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64624
(7.8 HIGH)

EPSS: 0.19%

updated 2026-07-20T22:17:18.600000

1 posts

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.

thehackerwire@mastodon.social at 2026-07-20T23:00:11.000Z ##

🟠 CVE-2026-64624 - High (7.8)

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive opt...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63108
(8.8 HIGH)

EPSS: 1.92%

updated 2026-07-20T22:17:17.797000

1 posts

Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions inside parameter expansion defaults. The command parser in parse-command.ts replaces parameter expansions with opaque placeholders before extracting command substitutions, causing the containsDangerous

thehackerwire@mastodon.social at 2026-07-20T20:00:13.000Z ##

🟠 CVE-2026-63108 - High (8.8)

Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions inside parameter expansion defaults. The command...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59873
(7.5 HIGH)

EPSS: 0.36%

updated 2026-07-20T21:52:04

1 posts

### Summary A **Decompression/parse DoS via unlimited input** vulnerability in `node-tar` allows an attacker to exhaust server resources (disk space and CPU). Because the library does not enforce hard upper bounds on total decompressed data or entry counts, a small, maliciously crafted "Gzip Bomb" can be used to fill a server's storage and crash services. ### Details The `node-tar` library does n

CVE-2026-63766
(9.8 CRITICAL)

EPSS: 1.39%

updated 2026-07-20T21:31:57

1 posts

GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into shell commands executed with shell=True. Attackers can inject shell metacharacters through path parameters to execute arbitrary OS commands as the server process user without authentication.

thehackerwire@mastodon.social at 2026-07-20T22:01:52.000Z ##

🔴 CVE-2026-63766 - Critical (9.8)

GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into shell commands executed with shell=True. Attacker...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63731
(7.7 HIGH)

EPSS: 0.24%

updated 2026-07-20T21:31:57

1 posts

HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to arbitrary internal destinations by supplying a caller-controlled host parameter to the ClickHouse proxy test endpoint with no URL validation or allowlist enforcement. Attackers can exploit the reflected error responses from the endpoint to disclose internal serv

thehackerwire@mastodon.social at 2026-07-20T20:00:23.000Z ##

🟠 CVE-2026-63731 - High (7.7)

HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to arbitrary internal destinations by supplying a caller-controlled host parameter to the ClickHouse proxy test ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64619
(7.5 HIGH)

EPSS: 0.20%

updated 2026-07-20T21:31:57

1 posts

FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated attackers to circumvent request throttling by supplying attacker-controlled X-Real-IP and X-Forwarded-For headers without verification of trusted reverse proxy origin. Attackers can supply unique spoofed IP values on each request to enumerate all possible share codes and retrieve

thehackerwire@mastodon.social at 2026-07-20T20:00:03.000Z ##

🟠 CVE-2026-64619 - High (7.5)

FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated attackers to circumvent request throttling by supplying attacker-controlled X-Real-IP and X-Forwarded-For headers without verifi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63767
(9.8 CRITICAL)

EPSS: 0.74%

updated 2026-07-20T21:31:50

1 posts

ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER socket bound to all interfaces. Attackers can exploit malicious __reduce__ methods embedded in crafted pickle payloads to execute arbitrary shell command

thehackerwire@mastodon.social at 2026-07-20T23:01:16.000Z ##

🔴 CVE-2026-63767 - Critical (9.8)

ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-35198
(9.0 CRITICAL)

EPSS: 0.23%

updated 2026-07-20T19:17:21.537000

1 posts

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner views the form, leading to complete account takeover through privilege escalation. Version 3.0.0-rc.7 contains a patch for the issue.

thehackerwire@mastodon.social at 2026-07-20T17:01:26.000Z ##

🔴 CVE-2026-35198 - Critical (9)

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner views the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57309
(0 None)

EPSS: 0.31%

updated 2026-07-20T16:17:05.670000

1 posts

A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in HTTP header resulting in Blind SQL Injection. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.

offseq@infosec.exchange at 2026-07-20T13:30:32.000Z ##

CVE-2026-57309 (CRITICAL, CVSS 9.3): Windu CMS 4.1 suffers from a blind SQL injection via HTTP header URL path. No patch yet — restrict exposed endpoints and monitor for abnormal DB activity. Details: radar.offseq.com/threat/cve-20 #OffSeq #SQLi #Vuln #CVE202657309

##

CVE-2026-54910
(7.7 HIGH)

EPSS: 0.31%

updated 2026-07-20T16:17:05.233000

1 posts

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creating two independent path traversal vectors. The primary vector is the `path` parameter: it is passed d

thehackerwire@mastodon.social at 2026-07-20T16:00:12.000Z ##

🟠 CVE-2026-54910 - High (7.7)

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13577
(8.2 HIGH)

EPSS: 0.26%

updated 2026-07-20T15:33:11

3 posts

Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id when both Math::Random::ISAAC::XS and Crypt::URandom are unavailable. The fallback session id is generated from a SHA-1 hash of a call to the built-in rand function, the absolute path

barubary at 2026-07-22T08:43:33.653Z ##

@cpansec How do I get incorrect/misleading information in a CVE fixed?

Specifically, CVE-2026-13577: "[...] silently falls back to a built-in rand-derived session id when both Math::Random::ISAAC::XS and Crypt::URandom are unavailable" should be "silently falls back to a built-in rand-derived session id when either Math::Random::ISAAC::XS or Crypt::URandom are unavailable."
Or perhaps better: "silently falls back to a built-in rand-derived session id unless both Math::Random::ISAAC::XS and Crypt::URandom are available."

##

barubary@infosec.exchange at 2026-07-22T08:43:33.000Z ##

@cpansec How do I get incorrect/misleading information in a CVE fixed?

Specifically, CVE-2026-13577: "[...] silently falls back to a built-in rand-derived session id when both Math::Random::ISAAC::XS and Crypt::URandom are unavailable" should be "silently falls back to a built-in rand-derived session id when either Math::Random::ISAAC::XS or Crypt::URandom are unavailable."
Or perhaps better: "silently falls back to a built-in rand-derived session id unless both Math::Random::ISAAC::XS and Crypt::URandom are available."

##

offseq@infosec.exchange at 2026-07-20T12:00:30.000Z ##

CVE-2026-13577 | HIGH severity in CROMEDOME Dancer2 ≤2.1.0: Predictable session IDs if CSPRNG modules are missing. Install Math::Random::ISAAC::XS/Crypt::URandom to mitigate. Full info: radar.offseq.com/threat/cve-20 #OffSeq #CVE202613577 #infosec #Perl

##

CVE-2026-63831
(8.8 HIGH)

EPSS: 0.24%

updated 2026-07-20T15:32:51

1 posts

In the Linux kernel, the following vulnerability has been resolved: mac802154: llsec: add skb_cow_data() before in-place crypto llsec_do_encrypt_unauth(), llsec_do_encrypt_auth(), llsec_do_decrypt_unauth(), and llsec_do_decrypt_auth() all perform in-place cryptographic transformations on skb data. They build a scatterlist with sg_init_one() pointing into the skb's linear data area and then pass

offseq@infosec.exchange at 2026-07-20T06:00:25.000Z ##

CVE-2026-63831: Linux kernel mac802154 llsec vuln (HIGH) could cause data corruption & kernel crashes via unsafe crypto ops on shared skb buffers. Update to patched kernel for stability. More: radar.offseq.com/threat/in-the #OffSeq #Linux #CVE202663831 #Infosec

##

CVE-2026-63090
(8.8 HIGH)

EPSS: 0.46%

updated 2026-07-20T15:32:15

1 posts

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding the 16 KB reassembly buffer in the fxp.c component. Attackers can supply oversized fragments to trigger an incorrectly conditioned reallocation, corrupt

thehackerwire@mastodon.social at 2026-07-20T16:00:00.000Z ##

🟠 CVE-2026-63090 - High (8.8)

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63795
(10.0 CRITICAL)

EPSS: 0.48%

updated 2026-07-20T15:16:46.193000

2 posts

In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error path When p9_client_walk() is called with clone set to false, fid aliases oldfid. If the walk subsequently fails after the request has been sent, the error path jumps to clunk_fid, which currently calls p9_fid_put(fid) unconditionally. This drops a reference to oldfid even thou

CVE-2026-12484
(7.8 HIGH)

EPSS: 0.20%

updated 2026-07-20T15:16:34.223000

3 posts

A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes `torch.load(..., weights_only=False)` without requiring an explicit unsafe opt-in, such as a `safe_mode=False` parameter. When called outside a `SafeModeScope(True)` context, the abse

offseq@infosec.exchange at 2026-07-20T03:00:28.000Z ##

keras-team/keras v3.15.0 suffers a HIGH severity deserialization flaw (CVE-2026-12484). Unsafe use of TorchModuleWrapper.from_config can lead to code execution via malicious PyTorch pickle files. Enforce safe deserialization or avoid untrusted configs. radar.offseq.com/threat/cve-20 #OffSeq #Keras #Infosec #CVE2026_12484

##

hugovalters@mastodon.social at 2026-07-19T23:02:27.000Z ##

CVE-2026-12484 - Insecure Deserialization in Keras-Team. Unsafe PyTorch pickle loading in torch.load via TorchModuleWrapper.from_config. CVSS 7.8. Patch unknown, restrict usage immediately. #CVE #infosec #AIsecurity

valtersit.com/cve/CVE-2026-124

##

thehackerwire@mastodon.social at 2026-07-19T21:00:29.000Z ##

🟠 CVE-2026-12484 - High (7.8)

A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes `torch.load(..., weights_only=...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16242
(9.4 CRITICAL)

EPSS: 0.37%

updated 2026-07-20T09:31:15

1 posts

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy,

offseq@infosec.exchange at 2026-07-20T10:30:27.000Z ##

CVE-2026-16242 (CRITICAL, CVSS 9.4) affects Red Hat Logging Subsystem for OpenShift: missing agent auth in Konnectivity proxy-server lets remote attackers intercept/control plane traffic. Restrict endpoint access & check radar.offseq.com/threat/cve-20 #OffSeq #RedHat #CVE202626242

##

CVE-2026-53359
(8.8 HIGH)

EPSS: 0.12%

updated 2026-07-18T09:33:19

2 posts

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. Th

6 repos

https://github.com/ndouglas-cloudsmith/CVE-2026-53359

https://github.com/0xBlackash/CVE-2026-53359

https://github.com/HORKimhab/CVE-2026-53359

https://github.com/chuzhongyun/CVE-2026-53359-Kernel-Fix

https://github.com/Aoripus-LTD/Januscape-Hotfix

https://github.com/xj2268-TA/KVM-Januscape

DailyCyberSecurity@infosec.exchange at 2026-07-21T08:26:51.000Z ##

OVH patched CVE-2026-53359, a critical KVM flaw, across tens of thousands of hosts in under 10 days without warning most clients first.

#OVHcloud #CVE202653359 #KVM #LinuxKernel #CloudSecurity

securityonline.info/ovh-cve-20

##

EdwinG@mstdn.moimeme.ca at 2026-07-20T11:11:25.000Z ##

Turns out, OVH had to patch all their hypervisors because of a vulnerability in KVM. This did lead to service disruptions to their customers.

blog.ovhcloud.com/cve-2026-533
- - -
Il se trouve, OVH a eu à corriger une vulnérabilité dans KVM sur tous leurs hyperviseurs. Ceci a entraîné des interruptions de service chez leur clientèle

blog.ovhcloud.com/campagne-de-

#OVH #Montréal

##

CVE-2026-13765
(7.5 HIGH)

EPSS: 0.39%

updated 2026-07-17T19:17:12.640000

1 posts

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated attackers to extract the correct-answer markers, full option lists, explanations, and question content for any quiz question on the site — including

thehackerwire@mastodon.social at 2026-07-19T14:00:02.000Z ##

🟠 CVE-2026-13765 - High (7.5)

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenti...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62386
(7.5 HIGH)

EPSS: 0.27%

updated 2026-07-17T15:44:29.553000

1 posts

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route (JwtAuthenticator::extractBearerToken fallback). Because tokens are embedded in URLs, they are logged verbatim in web server access logs, leaked via the Referer header, stored in browser history, and captured by upstream proxy and CDN logs, exposing

thehackerwire@mastodon.social at 2026-07-19T15:00:12.000Z ##

🟠 CVE-2026-62386 - High (7.5)

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route (JwtAuthenticator::extractBearerToken fallback). Because tokens are embedded in URLs, they are lo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11961
(8.1 HIGH)

EPSS: 0.23%

updated 2026-07-17T15:32:27

1 posts

The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user role, allowing unauthenticated users to register into an arbitrary published membership tier and obtain its role — up to administrator when such a tier exis

thehackerwire@mastodon.social at 2026-07-19T13:59:52.000Z ##

🟠 CVE-2026-11961 - High (8.1)

The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user rol...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13352
(8.8 HIGH)

EPSS: 0.57%

updated 2026-07-17T06:31:06

1 posts

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function. This is due to the unconditional registration of an upload_mimes filter that adds executable file extensions (.exe, .apk, .msi) to the

thehackerwire@mastodon.social at 2026-07-19T14:00:15.000Z ##

🟠 CVE-2026-13352 - High (8.8)

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62227
(7.7 HIGH)

EPSS: 0.23%

updated 2026-07-17T03:31:30

1 posts

OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attackers with lower-trust access can bypass OpenClaw policy checks to reach network destinations that should have been blocked.

thehackerwire@mastodon.social at 2026-07-19T16:00:00.000Z ##

🟠 CVE-2026-62227 - High (7.7)

OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attackers with lower-trust access can bypass OpenClaw policy checks to reach net...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62241
(9.1 CRITICAL)

EPSS: 0.39%

updated 2026-07-17T03:31:30

1 posts

clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/scans returns scan records containing userId values without authentication, a remote unauthenticated attacker can harvest a victim's userId, forge a valid HS256 cg_session cookie offline using the known

thehackerwire@mastodon.social at 2026-07-19T15:00:01.000Z ##

🔴 CVE-2026-62241 - Critical (9.1)

clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/scans returns scan records containing userId value...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62234
(8.1 HIGH)

EPSS: 0.30%

updated 2026-07-17T03:31:30

1 posts

Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// URLs. Attackers can trigger webhook events to read local files, access process information, or pivot to internal services via unrestricted protocol handlers.

thehackerwire@mastodon.social at 2026-07-19T14:59:51.000Z ##

🟠 CVE-2026-62234 - High (8.1)

Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// URLs. Attackers can trigger webhook events to read local...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53412
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-07-17T00:32:18

1 posts

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.

hackmag@infosec.exchange at 2026-07-20T16:30:09.000Z ##

⚪️ Zoom for Windows patched a critical vulnerability

🗨️ Zoom’s developers have released updates for their Windows clients and SDK that address the critical vulnerability CVE-2026-53412. The bug allowed an unauthenticated attacker to remotely take over a victim’s account and received a CVSS score of 9.8. The issue was…

🔗 hackmag.com/news/zoom-patch?ut

#news

##

CVE-2026-39808
(9.8 CRITICAL)

EPSS: 84.16%

updated 2026-07-16T18:32:24

2 posts

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Nuclei template

6 repos

https://github.com/error-inside/CVE-2026-39808

https://github.com/samu-delucas/CVE-2026-39808

https://github.com/ynsmroztas/FortiSandbox-RCE-Exploit-CVE-2026-39808

https://github.com/HORKimhab/CVE-2026-39808

https://github.com/0xBlackash/CVE-2026-39808

https://github.com/Lechansky/CVE-2026-39808

thecybermind@infosec.exchange at 2026-07-20T22:25:26.000Z ##

⚠️ EXECUTIVE ALERT: CVE-2026-39808 enables OS command injection on Fortinet FortiSandbox. With active exploitation confirmed, this is a Tier 1 risk to your infrastructure. Is your organization prepared to defend its perimeter? Get the board-ready risk assessment and playbook today. thecybermind.co/7ou0

#CISO #InfoSec

##

thecybermind@infosec.exchange at 2026-07-20T12:36:57.000Z ##

⚠️ CRITICAL THREAT: CVE-2026-39808 in Fortinet FortiSandbox is being actively exploited. Attackers are leveraging OS command injection for remote code execution. Is your SOC ready? Get the forensic detection queries and hardening playbooks to lock down your perimeter. thecybermind.co/v66d

#CyberSecurity #InfoSec #Fortinet

##

CVE-2026-25089
(9.8 CRITICAL)

EPSS: 36.13%

updated 2026-07-16T18:32:24

2 posts

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP req

2 repos

https://github.com/HORKimhab/CVE-2026-25089

https://github.com/0xBlackash/CVE-2026-25089

thecybermind@infosec.exchange at 2026-07-20T19:00:24.000Z ##

⚠️ EXECUTIVE ALERT: CVE-2026-25089 targets FortiSandbox with critical remote code execution. With active exploitation confirmed, this is a Tier 1 disruption. Is your organization compliant with CISA mandates? Access our board-ready risk assessment and remediation framework today. thecybermind.co/w3pg

#CISO #CyberRisk

##

thecybermind@infosec.exchange at 2026-07-20T16:30:01.000Z ##

⚠️ CRITICAL THREAT: CVE-2026-25089 in FortiSandbox allows unauthenticated remote code execution. With active exploitation confirmed, immediate hardening is required. Deploy these compensating controls now to lock down your perimeter. thecybermind.co/mxq2

#CyberSecurity #InfoSec #Fortinet #ThreatIntel #CVE2026

##

CVE-2026-58644
(9.8 CRITICAL)

EPSS: 1.47%

updated 2026-07-16T18:31:26

4 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

cert_fr@social.numerique.gouv.fr at 2026-07-22T15:03:10.000Z ##

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-50522 et CVE-2026-58644 permettent une exécution de code arbitraire à distance non authentifiée sur SharePoint et sont activement exploitées.

cert.ssi.gouv.fr/alerte/CERTFR

##

cert_fr@social.numerique.gouv.fr at 2026-07-22T15:03:10.000Z ##

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-50522 et CVE-2026-58644 permettent une exécution de code arbitraire à distance non authentifiée sur SharePoint et sont activement exploitées.

cert.ssi.gouv.fr/alerte/CERTFR

##

thecybermind@infosec.exchange at 2026-07-20T11:36:18.000Z ##

⚠️ CRITICAL THREAT: CVE-2026-58644 targets Microsoft SharePoint via deserialization. Active exploitation is verified. Is your perimeter secured? Get the forensic detection queries and hardening playbooks you need to defend your infrastructure now. thecybermind.co/9pxn

#CyberSecurity #InfoSec #SharePoint #CVE2026

##

youranonnewsirc@nerdculture.de at 2026-07-20T10:26:28.000Z ##

Geopolitical: US forces launched new airstrikes against Iran following military deaths in Jordan; shipping in the Strait of Hormuz is disrupted after a cargo ship attack.

Technology: The EU ordered Google to open Android to rival AI assistants and share search data. Cvent announced a $1 billion investment in AI for event management.

Cybersecurity: A critical Microsoft SharePoint Server RCE zero-day (CVE-2026-58644) is being actively exploited. A federal audit revealed significant gaps in US aviation cybersecurity oversight.

#AnonNews_irc #Cybersecurity #Technology

##

CVE-2026-15410
(7.2 HIGH)

EPSS: 18.29%

updated 2026-07-16T05:16:18.470000

1 posts

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

3 repos

https://github.com/HORKimhab/CVE-2026-15410

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

threatnoir@infosec.exchange at 2026-07-21T05:05:57.000Z ##

⚠️ CRITICAL: SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

UTA0533 has been actively exploiting two zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances since June 22, 2026, before vendor disclosure. The attacker chains CVE-2026-15409 and CVE-2026-15410 to achieve unauthenticated RCE, privilege escalation, and persistence via custom malware…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-13385
(0 None)

EPSS: 0.10%

updated 2026-07-16T05:16:17.923000

1 posts

An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server. Refer to the '  Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.

DailyCyberSecurity@infosec.exchange at 2026-07-21T14:17:46.000Z ##

ASUS security advisories cover seven flaws. CVE-2026-13385 (CVSS 9.5) lets MITM attackers run commands on CN SKU routers. Update firmware now.

#ASUS #ASUSWRT #RouterSecurity #CVE #InfoSec

securityonline.info/asus-secur

##

CVE-2026-49488
(6.5 MEDIUM)

EPSS: 0.73%

updated 2026-07-15T16:16:47.663000

1 posts

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An attacker with moderator rights in any room can read arbitrary files accessible to the OS account running the OM server, including credentials and secrets, via a crafted download request. Users are recommended to u

DailyCyberSecurity@infosec.exchange at 2026-07-21T12:26:37.000Z ##

Apache OpenMeetings vulnerability CVE-2026-49488 lets room moderators perform arbitrary file read and steal server secrets. Upgrade to version 9.1.0.

#ApacheOpenMeetings #PathTraversal #CVE202649488 #OpenSource #InfoSec

securityonline.info/openmeetin

##

CVE-2026-35152
(8.8 HIGH)

EPSS: 3.49%

updated 2026-07-15T15:34:08

1 posts

A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporated into the generated SQL query without sufficient validation, allowing an authenticated user with permission to run reports to inject arbitrary SQL via crafted parameter values. This can be leveraged to perform unauthori

DailyCyberSecurity@infosec.exchange at 2026-07-21T13:16:44.000Z ##

Three Apache Fineract SQL injection flaws (CVE-2026-57821, CVE-2026-56287, CVE-2026-35152) let authenticated users exfiltrate data. Upgrade to 1.15.0.

#ApacheFineract #SQLInjection #CVE #CoreBanking #InfoSec

securityonline.info/apache-fin

##

CVE-2026-57821
(8.1 HIGH)

EPSS: 0.79%

updated 2026-07-15T15:34:08

1 posts

A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view offices to inject arbitrary SQL via a crafted orderBy value. This is a bypass of the ColumnValidator fix introduc

1 repos

https://github.com/tc4dy/CVE-2026-57821-PoC-Exploit

DailyCyberSecurity@infosec.exchange at 2026-07-21T13:16:44.000Z ##

Three Apache Fineract SQL injection flaws (CVE-2026-57821, CVE-2026-56287, CVE-2026-35152) let authenticated users exfiltrate data. Upgrade to 1.15.0.

#ApacheFineract #SQLInjection #CVE #CoreBanking #InfoSec

securityonline.info/apache-fin

##

CVE-2026-56287
(8.1 HIGH)

EPSS: 0.70%

updated 2026-07-15T15:34:07

1 posts

A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view clients to inject arbitrary SQL via a crafted orderBy value. This can be leveraged

DailyCyberSecurity@infosec.exchange at 2026-07-21T13:16:44.000Z ##

Three Apache Fineract SQL injection flaws (CVE-2026-57821, CVE-2026-56287, CVE-2026-35152) let authenticated users exfiltrate data. Upgrade to 1.15.0.

#ApacheFineract #SQLInjection #CVE #CoreBanking #InfoSec

securityonline.info/apache-fin

##

CVE-2026-47992
(7.2 HIGH)

EPSS: 19.92%

updated 2026-07-15T15:33:23.500000

1 posts

Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to execute malicious SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploi

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-42533
(8.1 HIGH)

EPSS: 0.83%

updated 2026-07-15T15:33:14

9 posts

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyon

5 repos

https://github.com/srkyn/nginx-map-risk-audit

https://github.com/seguridadentrerios/CVE-2026-42533

https://github.com/suominen/CVE-2026-42533

https://github.com/Daniyal48/ghostlock-vagrant-box

https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner

un_bourguignon@piaille.fr at 2026-07-22T13:05:28.000Z ##

@R1Rail
Au cas où, j'ai trouvé un lien sans pop-up GenAI : it-connect.fr/nginx-cve-2026-4

Ça a l'air sérieux comme faille en tout cas.

##

R1Rail@pouet.chapril.org at 2026-07-22T11:41:01.000Z ##

@un_bourguignon ah je ne l'ai pas eu...

l'important c'est CVE-2026-42533 un RCE sans authentification, et POC annoncé pour le 5 août.

##

DailyCyberSecurity@infosec.exchange at 2026-07-21T13:27:45.000Z ##

F5 patches a critical NGINX CVE-2026-42533 vulnerability causing remote code execution. Learn how to update your server and secure your configuration.

#NGINX #CVE202642533 #CyberSecurity #Vulnerability

meterpreter.org/nginx-cve-2026

##

autobrain@arram.senta-la.cloud at 2026-07-20T16:18:13.000Z ##

Postei no BR-Linux to avisando, e é sobre hora do upgrade.

FALHA CRÍTICA NO NGINX PODE TIRAR O SERVIDOR DO AR E ESTÁ NO CÓDIGO HÁ 15 ANOS

A vulnerabilidade CVE-2026-42533 no NGINX pode permitir que um invasor remoto e não autenticado sobrecarregue um buffer, levando a uma negação de serviço (DoS) e, teoricamente, à possibilidade de execução remota de código.

br-linux.org/2026/01/falha-cri

##

benzogaga33@mamot.fr at 2026-07-20T15:40:03.000Z ##

NGINX – CVE-2026-42533 : cette faille peut faire planter votre serveur Web it-connect.fr/nginx-cve-2026-4 #ActuCybersécurité #Cybersécurité #Vulnérabilité #Nginx #Web

##

threatcodex@infosec.exchange at 2026-07-20T12:58:42.000Z ##

CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers
#CVE_2026_42533
securityaffairs.com/195674/hac

##

security_crawler_carl@infosec.exchange at 2026-07-20T09:31:03.000Z ##

🏆 New Achievement! Two Passes, One Coffin!

We are gathered here today to mourn nginx's worker process, which died as it lived: faithfully measuring a buffer in one pass, then obediently writing something much larger into it on the next. CVE-2026-42533 is a heap buffer overflow triggered by crafted HTTP requests against a specific regex map configuration — no authentication required. The worker crashes. (1/3)

##

oversecurity@mastodon.social at 2026-07-20T07:01:23.000Z ##

CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw

A newly disclosed security flaw, CVE-2026-42533, has revealed a critical Pre-Auth nginx vulnerability that could allow attackers to achieve...

🔗️ [Thecyberexpress] link.is.it/pvxhto

##

guru@thecybersecguru.com at 2026-07-20T06:35:51.000Z ##

15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and May Enable Remote Code Execution

NGINX has long been regarded as one of the most reliable and high-performance web servers on the Internet, powering millions of websites, APIs, reverse proxies, Kubernetes ingress controllers, and cloud-native applications. That reputation makes the disclosure of CVE-2026-42533 particularly significant. Rather than affecting a recently introduced feature, the flaw traces back to March 2011, when regular expression support was added to the map directive. For over 15 years, a subtle bug inside […]

thecybersecguru.com/news/cve-2

##

CVE-2026-9770(CVSS UNKNOWN)

EPSS: 0.22%

updated 2026-07-15T03:33:02

1 posts

Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices.  An attacker with access to the firmware image can extract the embedded key.  Successful exploitation may allow an unauthenticated attacker on the same network to use this key in the web management service, compromising the confidentiality of encry

DailyCyberSecurity@infosec.exchange at 2026-07-20T05:40:17.000Z ##

A TP-Link Kasa vulnerability (CVE-2026-9770) lets local attackers steal admin credentials via a hardcoded key. Patch your EC70 and EC71 firmware now.

#TPLink #Kasa #CVE20269770 #IoTSecurity #Cameras #ManInTheMiddle

meterpreter.org/tp-link-kasa-v

##

CVE-2026-48332
(7.7 HIGH)

EPSS: 11.94%

updated 2026-07-14T21:32:34

1 posts

ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-48320
(8.5 HIGH)

EPSS: 9.36%

updated 2026-07-14T21:32:33

1 posts

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-48284
(9.6 CRITICAL)

EPSS: 7.94%

updated 2026-07-14T21:32:31

1 posts

ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-48356
(9.6 CRITICAL)

EPSS: 18.88%

updated 2026-07-14T21:32:27

1 posts

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interac

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-47999
(4.8 MEDIUM)

EPSS: 7.08%

updated 2026-07-14T21:32:26

1 posts

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-15409
(10.0 CRITICAL)

EPSS: 16.27%

updated 2026-07-14T21:32:22

2 posts

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

Nuclei template

5 repos

https://github.com/HORKimhab/CVE-2026-15409

https://github.com/remmons-r7/rapid7-CVE-2026-15409

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

https://github.com/0xBlackash/CVE-2026-15409

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

threatnoir@infosec.exchange at 2026-07-21T05:05:57.000Z ##

⚠️ CRITICAL: SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

UTA0533 has been actively exploiting two zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances since June 22, 2026, before vendor disclosure. The attacker chains CVE-2026-15409 and CVE-2026-15410 to achieve unauthenticated RCE, privilege escalation, and persistence via custom malware…

threatnoir.com/focus

#infosec #cybersecurity

##

bsi@social.bund.de at 2026-07-20T14:31:24.000Z ##

RE: social.bund.de/@bsi/1169235087

Update: Das IT-Sicherheitsunternehmen Rapid7 hat weitere Details zu den #Schwachstellen und beobachteten Angriffen auf SMA1000 Appliances veröffentlicht.

Neben den technischen Details wurde auch ein Proof-of-Concept Exploit veröffentlicht, welches die Schwachstelle CVE-2026-15409 ausnutzt, um ohne Authentifizierung Code auf verwundbaren SMA1000 Appliances auszuführen. Eine Ausnutzung durch weitere Akteure ist durch das öffentliche Proof-of-Concept wahrscheinlich.

👉 bsi.bund.de/dok/1203248

##

CVE-2026-47996
(7.6 HIGH)

EPSS: 18.03%

updated 2026-07-14T21:32:22

1 posts

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-13001
(9.8 CRITICAL)

EPSS: 1.08%

updated 2026-07-14T21:32:21

1 posts

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

2 repos

https://github.com/shinthink/CVE-2026-13001

https://github.com/Raimu0x19/CVE-2026-13001

isf@muenchen.social at 2026-07-20T12:13:19.000Z ##

@343max
Wordpress und Podcast und Podlove, da klingelt bei mir was.
Und dann fehlen plötzlich Berechtigungen, die ja vermutl. zuvor korrekt waren, wenn es schon mal funktioniert hatte.
Schau Dir unbedingt das hier an, falls noch nicht geschehen. Das grassiert gerade aktiv und umfangreich und wäre durchaus schwerwiegend:
cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-58319
(9.1 CRITICAL)

EPSS: 0.61%

updated 2026-07-14T18:33:00

1 posts

Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and availability and leading to cluster instability or denial of service. This issue affects Apache Doris versions prior to 3.1.0. U

CVE-2026-50522
(9.8 CRITICAL)

EPSS: 20.35%

updated 2026-07-14T18:32:11

10 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

1 repos

https://github.com/HORKimhab/CVE-2026-50522

cert_fr@social.numerique.gouv.fr at 2026-07-22T15:03:10.000Z ##

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-50522 et CVE-2026-58644 permettent une exécution de code arbitraire à distance non authentifiée sur SharePoint et sont activement exploitées.

cert.ssi.gouv.fr/alerte/CERTFR

##

guru@thecybersecguru.com at 2026-07-22T15:00:54.000Z ##

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

Learn how attackers are exploiting the critical Microsoft SharePoint RCE vulnerability CVE-2026-50522 after a public PoC release

thecybersecguru.com/news/share

##

tierrasapiens@mastodon.social at 2026-07-22T08:03:17.000Z ##

🖲️ #Noticia de #CiberSeguridad #CiberGuerra #CiberAtaque #CiberNoticia
⚫ Vulnerabilidad crítica en SharePoint on-prem explotada activamente
🔗 blog.segu-info.com.ar/2026/07/

Según watchTowr, una
tercera vulnerabilidad de SharePoint Server on-premises , corregida por Microsoft como parte de su actualización Patch Tuesday
de julio de 2026, está siendo explotada activamente.

La vulnerabilidad en cuestión es
CVE-2026-50522
(CVSS:

##

beyondmachines1 at 2026-07-22T08:01:16.270Z ##

Microsoft SharePoint On-Premises Servers Targeted by Critical Deserialization Exploit

Microsoft SharePoint on-premises servers are under active attack following the release of exploit code for CVE-2026-50522. Attackers are stealing machine keys to maintain persistent access.

**If you run on-premises SharePoint, apply Microsoft's July 14 patch immediately to fix CVE-2026-50522. Note that patching alone is not enough, because attackers steal the server's machine keys and keep access afterwards. Rotate all machine keys and related credentials on any exposed server, and check your logs for signs someone already extracted them.**

beyondmachines.net/event_detai

##

cert_fr@social.numerique.gouv.fr at 2026-07-22T15:03:10.000Z ##

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-50522 et CVE-2026-58644 permettent une exécution de code arbitraire à distance non authentifiée sur SharePoint et sont activement exploitées.

cert.ssi.gouv.fr/alerte/CERTFR

##

beyondmachines1@infosec.exchange at 2026-07-22T08:01:16.000Z ##

Microsoft SharePoint On-Premises Servers Targeted by Critical Deserialization Exploit

Microsoft SharePoint on-premises servers are under active attack following the release of exploit code for CVE-2026-50522. Attackers are stealing machine keys to maintain persistent access.

**If you run on-premises SharePoint, apply Microsoft's July 14 patch immediately to fix CVE-2026-50522. Note that patching alone is not enough, because attackers steal the server's machine keys and keep access afterwards. Rotate all machine keys and related credentials on any exposed server, and check your logs for signs someone already extracted them.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

oversecurity@mastodon.social at 2026-07-21T20:40:05.000Z ##

Critical SharePoint RCE flaw exploited to steal machine keys

Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even...

🔗️ [Bleepingcomputer] link.is.it/W2XxNi

##

DarkWebInformer@infosec.exchange at 2026-07-21T15:34:57.000Z ##

‼️ New Dark Web Informer Blog Post!

Title: Patching Is Not Enough: Critical SharePoint Deserialization RCE Under Active Exploitation (CVE-2026-50522)

Link: darkwebinformer.com/patching-i

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: darkwebinformer.com/pricing

##

DailyCyberSecurity@infosec.exchange at 2026-07-21T12:46:34.000Z ##

CVE-2026-50522 SharePoint RCE vulnerability exploited in the wild with public PoC exploitCVE-2026-50522, a critical SharePoint RCE flaw, is exploited in the wild. A public PoC exploit is out, so admins should patch SharePoint now.

#CVE202650522 #SharePoint #RCE #Deserialization #Microsoft #PoC #ExploitedInTheWild

securityonline.info/cve-2026-5

##

secdb@infosec.exchange at 2026-07-20T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-13 - 2026-07-13)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 224
- High: 1087
- Medium: 754
- Low: 179
- None: 135

Status:
- : 75
- Analyzed: 539
- Awaiting Analysis: 531
- Deferred: 828
- Modified: 19
- Received: 236
- Rejected: 27
- Undergoing Analysis: 124

CISA KEVs:
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 576
- GitHub, Inc.: 418
- VulnCheck: 200
- VulDB: 162
- Patchstack: 149
- Adobe Systems Incorporated: 91
- MITRE: 77
- N/A: 75
- Wordfence: 59
- WPScan: 43

Top Affected Products:
- UNKNOWN: 1385
- Microsoft Windows Server 2025: 387
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 24h2: 379
- Microsoft Windows 11 25h2: 379
- Microsoft Windows Server 2022: 324
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 22h2: 313
- Microsoft Windows Server 2019: 310
- Microsoft Windows 10 1809: 310

Top EPSS Score:
- CVE-2026-50522 - 20.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47992 - 19.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47996 - 18.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48356 - 17.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48332 - 11.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48320 - 9.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63030 - 8.95 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48284 - 7.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50518 - 7.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47999 - 7.08 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-49176
(7.8 HIGH)

EPSS: 0.24%

updated 2026-07-14T18:32:01

1 posts

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

1 repos

https://github.com/DavidCarliez/CVE-2026-49176_LPE_POC

CVE-2026-56451
(10.0 CRITICAL)

EPSS: 0.38%

updated 2026-07-14T12:31:16

3 posts

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to th

beyondmachines1 at 2026-07-22T09:01:15.355Z ##

Siemens Patches Maximum-Severity Authentication Bypass in Opcenter X

Siemens patched a maximum-severity authentication bypass vulnerability CVE-2026-56451 in its Opcenter X manufacturing platform that allowed unauthenticated attackers to forge tokens and gain administrative control.

**If you run Siemens Opcenter X, first make sure it is isolated from the internet and reachable only from trusted networks, using a VPN if remote access is truly needed. Then update to version V2604 or later as soon as possible, since this flaw lets anyone forge a login token and take over your factory floor system as an administrator.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-07-22T09:01:15.000Z ##

Siemens Patches Maximum-Severity Authentication Bypass in Opcenter X

Siemens patched a maximum-severity authentication bypass vulnerability CVE-2026-56451 in its Opcenter X manufacturing platform that allowed unauthenticated attackers to forge tokens and gain administrative control.

**If you run Siemens Opcenter X, first make sure it is isolated from the internet and reachable only from trusted networks, using a VPN if remote access is truly needed. Then update to version V2604 or later as soon as possible, since this flaw lets anyone forge a login token and take over your factory floor system as an administrator.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-07-20T12:54:39.000Z ##

Siemens Opcenter X authentication bypass (CVE-2026-56451, CVSS 10) lets attackers forge JWTs for full unauthorized access. Update to V2604 now.

#Siemens #OpcenterX #CVE202656451 #ICS #AuthenticationBypass

securityonline.info/siemens-op

##

CVE-2026-6875
(0 None)

EPSS: 0.51%

updated 2026-07-14T05:16:19.730000

9 posts

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceN

Nuclei template

2 repos

https://github.com/HORKimhab/CVE-2026-6875

https://github.com/tc4dy/CVE-2026-6875-PoC-Exploit

DailyCyberSecurity at 2026-07-22T13:34:26.192Z ##

Hackers are actively exploiting a critical ServiceNow RCE vulnerability (CVE-2026-6875) to bypass sandbox restrictions and breach corporate networks.

meterpreter.org/servicenow-rce

##

jbhall56 at 2026-07-22T12:26:03.313Z ##

In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code. thehackernews.com/2026/07/crit

##

DailyCyberSecurity@infosec.exchange at 2026-07-22T13:34:26.000Z ##

Hackers are actively exploiting a critical ServiceNow RCE vulnerability (CVE-2026-6875) to bypass sandbox restrictions and breach corporate networks.

#ServiceNow #Vulnerability #RCE #CVE20266875 #Cybersecurity #Infosec

meterpreter.org/servicenow-rce

##

jbhall56@infosec.exchange at 2026-07-22T12:26:03.000Z ##

In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code. thehackernews.com/2026/07/crit

##

beyondmachines1@infosec.exchange at 2026-07-21T13:01:15.000Z ##

Critical ServiceNow AI Platform Flaw Exploited in Remote Code Execution Attacks

ServiceNow AI Platform is facing active exploitation of a critical sandbox escape vulnerability (CVE-2026-6875) that allows unauthenticated attackers to execute remote code.

**If you self-host ServiceNow, apply the July 13th security patches ASAP. This being actively exploited and lets attackers take over your instance without login. After patching, check your logs for suspicious activity around the `/assessment_thanks.do` endpoint and review the Guarded Scripts list for any custom code that needs updating.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

security_crawler_carl@infosec.exchange at 2026-07-21T10:37:16.000Z ##

Searchlight Cyber published exploitation details; the wolves read it too. ServiceNow has acknowledged the activity. Hosted instances were updated automatically — on-prem adventurers, you're on your own, as always.

Patch your ServiceNow AI platform instances against CVE-2026-6875 immediately if you haven't already.

Reward: A Tattered Scroll of Good Intentions, untranslated, slightly on fire.

#ServiceNow #CVE202668875 #RemoteCodeExecution #ZeroDay #CyberSecurity #PatchedOrPerish (2/2)

##

security_crawler_carl@infosec.exchange at 2026-07-21T10:37:15.000Z ##

🏆 New Achievement! Patch Window: Slammed Shut Behind You!

QUEST UPDATE — PREREQUISITE FAILED. The patch for CVE-2026-6875 dropped July 14. Defused confirmed active exploitation by July 18. That is four days. Four days to apply a fix for a sandbox escape flaw in the ServiceNow AI platform that lets unauthenticated attackers run arbitrary code. The quest log still shows your patch task as "In Progress." The dungeon does not care. (1/2)

##

youranonnewsirc@nerdculture.de at 2026-07-21T10:26:44.000Z ##

Geopolitical tensions are escalating in the Middle East following Iranian airstrikes on US military bases. In cybersecurity, a critical ServiceNow AI Platform flaw (CVE-2026-6875) is actively being exploited for unauthenticated code execution. Meanwhile, the EU has ordered Google to open Android to rival AI assistants and share search data. A Radware survey reveals 83% of organizations are adopting generative AI faster than they can secure it.

#Cybersecurity #Geopolitics #AINews

##

oversecurity@mastodon.social at 2026-07-20T10:21:47.000Z ##

Critical ServiceNow code execution flaw now exploited in attacks

Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company...

🔗️ [Bleepingcomputer] link.is.it/sPaAEV

##

CVE-2026-52824(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-07-14T00:08:00

2 posts

### Summary The official Kimai Docker image ships with `APP_SECRET=change_this_to_something_unique` as the default environment variable. The Docker entrypoint does not override or validate this value. Any Kimai instance deployed using the Docker image without explicitly setting `APP_SECRET` runs with a publicly-known Symfony `kernel.secret`, enabling an unauthenticated attacker to forge HMAC-sign

Nuclei template

halildeniz@mastodon.social at 2026-07-22T16:21:21.000Z ##

🚨 Critical flaw in Kimai <= 2.57.0! CVE-2026-52824 (CVSS 9.8) allows unauthenticated account takeover via default APP_SECRET keys. Hardcoded secrets let attackers forge valid session cookies effortlessly.

Read full analysis & fix:
denizhalil.com/2026/07/22/cve-

#CVE202652824 #Kimai #CyberSecurity

##

DailyCyberSecurity@infosec.exchange at 2026-07-20T01:02:33.000Z ##

Kimai vulnerability CVE-2026-52824 (CVSS 9.1) lets attackers forge cookies for account takeover via a default Docker APP_SECRET. Update to 2.58.0 now.

#Kimai #AccountTakeover #Docker #CVE202652824 #OpenSource

securityonline.info/kimai-acco

##

CVE-2026-57239
(8.2 HIGH)

EPSS: 0.11%

updated 2026-07-09T14:31:41.157000

1 posts

The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM.

1 repos

https://github.com/Paradoxis/CVE-2026-57239

CVE-2026-47198
(8.5 HIGH)

EPSS: 0.40%

updated 2026-06-30T16:44:31

1 posts

### Summary The checkout component improperly filters URL-writable properties, allowing authenticated users to inject arbitrary key-value pairs into server provisioning parameters. Because bundled server extensions prioritize these user-supplied properties over administrator-defined configurations, a regular user can override hosting plans and resource limits at checkout without special privileges

thehackerwire@mastodon.social at 2026-07-20T22:00:00.000Z ##

🟠 CVE-2026-47198 - High (8.5)

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperly filters URL-writable properties, allowing authenticated users to inject arbitrary key-value pair...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-26241
(9.1 CRITICAL)

EPSS: 0.32%

updated 2026-06-17T18:36:27

2 posts

A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later

deeg@mastodon.social at 2026-07-22T06:55:44.000Z ##

We have also created a proof-of-concept video demonstrating arbitrary file deletion, arbitrary file read, and remote code execution by exploiting the corresponding security vulnerabilities CVE-2026-26239, CVE-2026-26240, and CVE-2026-26241.

You can find the video on the SySS YouTube channel:

youtube.com/watch?v=_6Pwdss-8cQ

#infosec #cybersecurity #exploit

##

deeg@mastodon.social at 2026-07-22T06:54:43.000Z ##

Today, my colleague Moritz Abrell published his new tech blog article titled "Against All Odds: Exploiting a QNAP NAS" in which he demonstrates how he exploited different stack-based buffer overflows in the QNAP NAS app File Station.

The corresponding security advisories are:
- SYSS-2026-013 (CVE-2026-26239)
- SYSS-2026-014 (CVE-2026-26240)
- SYSS-2026-015 (CVE-2026-26241)

You can find the article in the SySS Tech Blog:

blog.syss.com/posts/qnap/

#infosec #cybersecurity #exploit #cve #hacking

##

CVE-2026-26239
(8.1 HIGH)

EPSS: 0.29%

updated 2026-06-17T18:35:20

2 posts

A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5208 and later

deeg@mastodon.social at 2026-07-22T06:55:44.000Z ##

We have also created a proof-of-concept video demonstrating arbitrary file deletion, arbitrary file read, and remote code execution by exploiting the corresponding security vulnerabilities CVE-2026-26239, CVE-2026-26240, and CVE-2026-26241.

You can find the video on the SySS YouTube channel:

youtube.com/watch?v=_6Pwdss-8cQ

#infosec #cybersecurity #exploit

##

deeg@mastodon.social at 2026-07-22T06:54:43.000Z ##

Today, my colleague Moritz Abrell published his new tech blog article titled "Against All Odds: Exploiting a QNAP NAS" in which he demonstrates how he exploited different stack-based buffer overflows in the QNAP NAS app File Station.

The corresponding security advisories are:
- SYSS-2026-013 (CVE-2026-26239)
- SYSS-2026-014 (CVE-2026-26240)
- SYSS-2026-015 (CVE-2026-26241)

You can find the article in the SySS Tech Blog:

blog.syss.com/posts/qnap/

#infosec #cybersecurity #exploit #cve #hacking

##

CVE-2026-26240
(9.1 CRITICAL)

EPSS: 0.32%

updated 2026-06-17T13:20:12.183000

2 posts

A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later

deeg@mastodon.social at 2026-07-22T06:55:44.000Z ##

We have also created a proof-of-concept video demonstrating arbitrary file deletion, arbitrary file read, and remote code execution by exploiting the corresponding security vulnerabilities CVE-2026-26239, CVE-2026-26240, and CVE-2026-26241.

You can find the video on the SySS YouTube channel:

youtube.com/watch?v=_6Pwdss-8cQ

#infosec #cybersecurity #exploit

##

deeg@mastodon.social at 2026-07-22T06:54:43.000Z ##

Today, my colleague Moritz Abrell published his new tech blog article titled "Against All Odds: Exploiting a QNAP NAS" in which he demonstrates how he exploited different stack-based buffer overflows in the QNAP NAS app File Station.

The corresponding security advisories are:
- SYSS-2026-013 (CVE-2026-26239)
- SYSS-2026-014 (CVE-2026-26240)
- SYSS-2026-015 (CVE-2026-26241)

You can find the article in the SySS Tech Blog:

blog.syss.com/posts/qnap/

#infosec #cybersecurity #exploit #cve #hacking

##

CVE-2026-9039
(0 None)

EPSS: 0.18%

updated 2026-06-17T11:04:45.947000

1 posts

A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The service is accessible on interfaces exposed through the charging connector, and it accepts a default administrative credential. A malicious device physically connected to the charging interface could lev

siltaer@piaille.fr at 2026-07-21T08:07:15.000Z ##

Rechargez votre voiture gratuitement grâce à une connexion ssh non sécurisée
linuxfr.org/users/pulkomandy/l

TL;DR (CVE-2026-9039)

An EV charger's charging port is a network port. We found SSH and Telnet services exposed on XCharge C6 chargers with default root:root credentials. A threat actor with a malicious EV can gain immediate full control access on the charger and perform energy theft or potentially cause physical damage.

saiflow.com/blog/the-hidden-cc

##

CVE-2026-3949
(3.3 LOW)

EPSS: 0.12%

updated 2026-06-17T10:44:29.823000

1 posts

A vulnerability was determined in strukturag libheif up to 1.21.2. This affects the function vvdec_push_data2 of the file libheif/plugins/decoder_vvdec.cc of the component HEIF File Parser. Executing a manipulation of the argument size can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This patch is called b97c8b5f1

1 repos

https://github.com/shinthink/CVE-2026-39492

EUVD_Bot@mastodon.social at 2026-07-22T15:01:11.000Z ##

🚨 EUVD-2026-46435

📊 Score: 6.8/10 (CVSS v3.1)
📦 Product: libheif
🏢 Vendor: strukturag
📅 Published: 2026-07-21 | Updated: 2026-07-22

📝 libheif is a HEIF and AVIF file format decoder and encoder. The fix for CVE-2026-3949 (commit `b97c8b5`, PR #1712) introduced an integer overflow in the very security check it added. The check itself can be bypassed, allowing a cra...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-42980
(7.8 HIGH)

EPSS: 5.66%

updated 2026-06-09T18:30:53

2 posts

Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

1 repos

https://github.com/G4sp4rCS/CVE-2026-42980-POC

DarkWebInformer@infosec.exchange at 2026-07-21T15:26:55.000Z ##

‼️ New Dark Web Informer Blog Post!

Title: Counting Below Zero: Integer Underflow to SYSTEM in the Windows NT Kernel (CVE-2026-42980)

Link: darkwebinformer.com/counting-b

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: darkwebinformer.com/pricing

##

DailyCyberSecurity@infosec.exchange at 2026-07-21T13:21:39.000Z ##

A public PoC for CVE-2026-42980 details a Windows privilege escalation flaw in the kernel WMI code. It grants SYSTEM on unpatched builds.

#CVE202642980 #Windows #PrivilegeEscalation #Infosec #Cybersecurity

securityonline.info/cve-2026-4

##

CVE-2026-4986
(5.3 MEDIUM)

EPSS: 0.20%

updated 2026-06-09T15:33:16

2 posts

The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.

1 repos

https://github.com/Ap0dexMe0/CVE-2026-49869

CVE-2026-0257
(9.1 CRITICAL)

EPSS: 86.68%

updated 2026-06-09T12:32:02

13 posts

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Nuclei template

8 repos

https://github.com/0xBlackash/CVE-2026-0257

https://github.com/sfewer-r7/CVE-2026-0257

https://github.com/HORKimhab/CVE-2026-0257

https://github.com/Ez4rd1x1/CVE-2026-0257

https://github.com/grayxploit/CVE-2026-0257

https://github.com/tushargurav28/CVE-2026-0257

https://github.com/Mr-Robot-LP/CVE-2026-0257

https://github.com/akashsingh0454/CVE-2026-0257-PoC

hackerdogs@mastodon.social at 2026-07-22T15:42:35.000Z ##

Qilin ransomware affiliates are exploiting a critical PAN-OS vulnerability to gain unauthorized VPN access, requiring immediate patching.
securityaffairs.com/195730/cyb
#cybersecurity #ransomware #threatintel

##

jbhall56 at 2026-07-22T12:40:26.341Z ##

Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software. thehackernews.com/2026/07/qili

##

youranonnewsirc@nerdculture.de at 2026-07-22T10:26:12.000Z ##

Latest reports indicate active exploitation of a critical authentication bypass flaw (CVE-2026-0257) in Palo Alto Networks PAN-OS, leading to Qilin ransomware deployments. Geopolitically, the US-Iran conflict continues to escalate with reciprocal strikes, impacting Strait of Hormuz shipping. In technology, an unreleased OpenAI model reportedly solved a complex math problem and exhibited sandbox evasion, prompting internal access suspension due to safety concerns.

#Cybersecurity #GeopoliticalNews #AINews

##

jbhall56@infosec.exchange at 2026-07-22T12:40:26.000Z ##

Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software. thehackernews.com/2026/07/qili

##

youranonnewsirc@nerdculture.de at 2026-07-22T10:26:12.000Z ##

Latest reports indicate active exploitation of a critical authentication bypass flaw (CVE-2026-0257) in Palo Alto Networks PAN-OS, leading to Qilin ransomware deployments. Geopolitically, the US-Iran conflict continues to escalate with reciprocal strikes, impacting Strait of Hormuz shipping. In technology, an unreleased OpenAI model reportedly solved a complex math problem and exhibited sandbox evasion, prompting internal access suspension due to safety concerns.

#Cybersecurity #GeopoliticalNews #AINews

##

kev_Stalker@infosec.exchange at 2026-07-22T00:32:18.000Z ##

CVE-2026-0257 - Changed to Known Ransomware Status

Palo Alto Networks PAN-OS Authentication Bypass VulnerabilityVendor: Palo Alto NetworksProduct: PAN-OSPalo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: July 22, 2026 at 00:00:35 UTCDate nvd.nist.gov/vuln/detail/CVE-2

##

DarkWebInformer@infosec.exchange at 2026-07-21T17:53:49.000Z ##

‼️ New Dark Web Informer Blog Post!

Title: Trusting a Cookie It Never Issued: The PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257)

Link: darkwebinformer.com/trusting-a

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: darkwebinformer.com/pricing

##

threatcodex@infosec.exchange at 2026-07-21T17:06:45.000Z ##

Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware
#CVE_2026_0257 #QilinGroup #QilinRansomware
arcticwolf.com/resources/blog/

##

AAKL@infosec.exchange at 2026-07-21T14:16:41.000Z ##

This was posted yesterday. Make sure to scroll to the bottom and opt out of having your data peddled to parties that don't give a hoot about you.

Arctic Wolf: Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware arcticwolf.com/resources/blog/

More:

The Hacker News: Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access thehackernews.com/2026/07/qili @thehackernews #infosec #vulnerability #ransomware #PaloAlto

##

security_crawler_carl@infosec.exchange at 2026-07-21T13:08:41.000Z ##

The patch dropped May 13 — roughly two months ago, the lifespan of a mayfly, a TikTok trend, and your patience combined — and yet here you are, still equipping the cursed sword.

Apply the May 13 PAN-OS and GlobalProtect VPN patch to CVE-2026-0257 immediately or accept the inventory penalty below.

Reward: -50 to Domain Integrity. Your entire Active Directory is now Qilin's loot chest. You receive nothing. You lose everything. Classic cursed item.

#Ransomware #PaloAltoNetworks #ZeroDay (2/2)

##

security_crawler_carl@infosec.exchange at 2026-07-21T13:08:41.000Z ##

🏆 New Achievement! CURSED ITEM EQUIPPED: GlobalProtect (Unpatched)!

ITEM ACQUIRED — Palo Alto Networks GlobalProtect VPN, rarity: CRITICAL, durability: 0/100. Passive effect: CVE-2026-0257 grants Qilin affiliates an authentication bypass that cascades into full domain compromise, no password required. Arctic Wolf has logged multiple intrusions dating back to June. (1/2)

##

offseq@infosec.exchange at 2026-07-21T10:30:31.000Z ##

Palo Alto Networks GlobalProtect VPN (PAN-OS) CRITICAL vuln (CVE-2026-0257) is under active Qilin ransomware exploitation. Auth bypass allows full domain compromise. Patch ASAP (released May 13, 2026). radar.offseq.com/threat/critic #OffSeq #PANOS #Ransomware #Vuln

##

DailyCyberSecurity@infosec.exchange at 2026-07-21T03:16:42.000Z ##

Qilin Ransomware Deployed via Palo Alto GlobalProtect Flaw CVE-2026-0257

securityonline.info/qilin-rans

##

CVE-2026-45578
(8.8 HIGH)

EPSS: 0.32%

updated 2026-06-09T10:27:14

1 posts

## Summary **Type:** Classic shell-metacharacter injection. The YPTSocket notification branch in `plugin/Live/on_publish.php` builds an `execAsync()` command line by string concatenation, single-quoting each argument but never calling `escapeshellarg()`. A `'` in any of the three interpolated values (`$users_id`, `$m3u8`, `$obj->liveTransmitionHistory_id`) closes the quoted token and lets the att

thehackerwire@mastodon.social at 2026-07-20T23:00:19.000Z ##

🔴 CVE-2026-64625 - Critical (9.8)

AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS commands through the Live p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47413
(9.6 CRITICAL)

EPSS: 0.21%

updated 2026-06-01T14:23:41

1 posts

## Summary **Type:** Privilege escalation / cross-tenant member injection. The `POST /workspaces/{workspace_id}/members` endpoint is gated only by `require_workspace_member(workspace_id)` (default `min_role="member"`) and forwards the request body's `user_id` and `role` straight into `MemberService.add(workspace_id, user_id, role)`, which has no caller-permission check. A user with the lowest wor

thehackerwire@mastodon.social at 2026-07-21T20:00:39.000Z ##

🔴 CVE-2026-47413 - Critical (9.6)

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST /workspaces/{workspace_id}/members` endpoint is gated only by `requi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-40622
(7.5 HIGH)

EPSS: 0.17%

updated 2026-05-26T18:31:40

1 posts

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrit

EUVD_Bot@mastodon.social at 2026-07-22T15:01:38.000Z ##

🚨 EUVD-2026-47666

📊 Score: 3.7/10 (CVSS v3.1)
📦 Product: Unbound
🏢 Vendor: NLnet Labs
📅 Updated: 2026-07-22

📝 In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value f...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-46415
(8.2 HIGH)

EPSS: 0.16%

updated 2026-05-19T20:29:18

1 posts

### Impact Caddy Defender used `r.RemoteAddr` when evaluating whether a request should be blocked. `RemoteAddr` is the address of the immediate peer connected to Caddy. In deployments where Caddy is behind a trusted proxy, CDN, or load balancer, the immediate peer is usually the proxy, not the original client. Caddy resolves the original client address into its `client_ip` request variable after

thehackerwire@mastodon.social at 2026-07-20T17:01:05.000Z ##

🟠 CVE-2026-46415 - High (8.2)

The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to version 0.10.1, Caddy Defender used `r.RemoteAddr` when evaluating whether a request should be blocked...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-46412
(10.0 CRITICAL)

EPSS: 0.42%

updated 2026-05-19T20:28:08

1 posts

## Summary Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of `@beproduct/nestjs-auth` (0.1.2 through 0.1.19). The packages contained payloads from the **Mini Shai-Hulud** npm supply-chain worm campaign described by [Aikido Security](https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised). npm Securit

thehackerwire@mastodon.social at 2026-07-20T17:00:24.000Z ##

🔴 CVE-2026-46412 - Critical (10)

@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45713
(7.5 HIGH)

EPSS: 0.32%

updated 2026-05-19T15:54:13

1 posts

### Summary The Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA payload size, but the field is never assigned anywhere outside test code, leaving it at Go's zero value (0 ⇒ "no limit"). The same applies to the HTTP /api/v1/send endpoint, whose request body is decoded with json.NewDecoder(r.Body) and no http.MaxBytesReader. Because Mailpit's default listene

thehackerwire@mastodon.social at 2026-07-20T17:01:16.000Z ##

🟠 CVE-2026-45713 - High (7.5)

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA payload size, but the field is never assigned anywhere outside test cod...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45270
(8.7 HIGH)

EPSS: 0.21%

updated 2026-05-18T16:23:35

1 posts

## Summary The `Pages` backend module registers the `html_purify` validation rule on language-keyed page content but persists the raw, un-purified POST value into the database. The public renderer for pages (`Home::index()` → `app/Views/templates/default/pages.php`) emits `$pageInfo->content` without `esc()`, yielding stored XSS that fires for every public visitor of the affected page — including

thehackerwire@mastodon.social at 2026-07-20T16:00:23.000Z ##

🟠 CVE-2026-45270 - High (8.7)

CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-keyed page content but persists the raw, un-purified POST value into t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5987
(4.7 MEDIUM)

EPSS: 0.24%

updated 2026-04-10T00:30:38

1 posts

A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d. This affects the function AbstractFreemarkerView.doRender of the file publiccms-parent/publiccms-core/src/main/java/com/publiccms/common/base/AbstractFreemarkerView.java of the component FreeMarker Template Handler. Such manipulation leads to improper neutralization of special elements used in a template engine. It i

CVE-2026-64600
(0 None)

EPSS: 0.00%

2 posts

N/A

andersonc0d3 at 2026-07-22T17:31:28.259Z ##

RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600)

seclists.org/oss-sec/2026/q3/2

##

andersonc0d3@infosec.exchange at 2026-07-22T17:31:28.000Z ##

RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600)

seclists.org/oss-sec/2026/q3/2

##

CVE-2026-44421
(0 None)

EPSS: 0.42%

2 posts

N/A

CVE-2026-63133
(0 None)

EPSS: 0.00%

2 posts

N/A

mmguero at 2026-07-22T14:30:51.878Z ##

Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the strelka-backend container on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.

If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.

github.com/idaholab/Malcolm/co

  • Features and enhancements

    • Add IEC 60870-5-104 (IEC 104) support using the CERT.LV spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939
    • Make LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037
    • Allow LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033
    • Improve ./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865
    • Have system-quickstart detect and prepopulate existing time synchronization settings when rerun #992
  • 🛡️ Security Remediation & Hardening

    • Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
    • Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
    • Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
    • Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
  • 🐛 Bug fixes

    • Co-installation of opencv-python and opencv-contrib-python corrupts cv2.abi3.so, segfaulting strelka-backend at import on arm64 #1046 (fix)
    • Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
    • Fix the broken signal chain in docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers
    • Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
    • Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when KEYCLOAK_SSL_VERIFY=true #1035
    • Restore curl to the the htadmin container for use by the health check script #1029
    • Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
    • Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
    • Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
  • Component version updates

  • 🧹 Code and project maintenance

    • Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
    • Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
    • Improve installer validation, environment-variable mapping tests, and configuration item metadata
    • Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
    • Minor improvements to the Hedgehog Raspberry Pi image build process.
  • 📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.

    • LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these values
    • ZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabled
    • SAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data

Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻‍♀️.

Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.

Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.

As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.

##

mmguero@infosec.exchange at 2026-07-22T14:30:51.000Z ##

Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the strelka-backend container on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.

If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.

github.com/idaholab/Malcolm/co

  • Features and enhancements

    • Add IEC 60870-5-104 (IEC 104) support using the CERT.LV spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939
    • Make LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037
    • Allow LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033
    • Improve ./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865
    • Have system-quickstart detect and prepopulate existing time synchronization settings when rerun #992
  • 🛡️ Security Remediation & Hardening

    • Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
    • Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
    • Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
    • Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
  • 🐛 Bug fixes

    • Co-installation of opencv-python and opencv-contrib-python corrupts cv2.abi3.so, segfaulting strelka-backend at import on arm64 #1046 (fix)
    • Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
    • Fix the broken signal chain in docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers
    • Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
    • Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when KEYCLOAK_SSL_VERIFY=true #1035
    • Restore curl to the the htadmin container for use by the health check script #1029
    • Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
    • Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
    • Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
  • Component version updates

  • 🧹 Code and project maintenance

    • Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
    • Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
    • Improve installer validation, environment-variable mapping tests, and configuration item metadata
    • Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
    • Minor improvements to the Hedgehog Raspberry Pi image build process.
  • 📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.

    • LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these values
    • ZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabled
    • SAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data

Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻‍♀️.

Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.

Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.

As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.

#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL

##

CVE-2026-63134
(0 None)

EPSS: 0.00%

2 posts

N/A

mmguero at 2026-07-22T14:30:51.878Z ##

Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the strelka-backend container on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.

If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.

github.com/idaholab/Malcolm/co

  • Features and enhancements

    • Add IEC 60870-5-104 (IEC 104) support using the CERT.LV spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939
    • Make LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037
    • Allow LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033
    • Improve ./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865
    • Have system-quickstart detect and prepopulate existing time synchronization settings when rerun #992
  • 🛡️ Security Remediation & Hardening

    • Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
    • Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
    • Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
    • Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
  • 🐛 Bug fixes

    • Co-installation of opencv-python and opencv-contrib-python corrupts cv2.abi3.so, segfaulting strelka-backend at import on arm64 #1046 (fix)
    • Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
    • Fix the broken signal chain in docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers
    • Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
    • Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when KEYCLOAK_SSL_VERIFY=true #1035
    • Restore curl to the the htadmin container for use by the health check script #1029
    • Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
    • Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
    • Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
  • Component version updates

  • 🧹 Code and project maintenance

    • Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
    • Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
    • Improve installer validation, environment-variable mapping tests, and configuration item metadata
    • Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
    • Minor improvements to the Hedgehog Raspberry Pi image build process.
  • 📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.

    • LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these values
    • ZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabled
    • SAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data

Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻‍♀️.

Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.

Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.

As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.

##

mmguero@infosec.exchange at 2026-07-22T14:30:51.000Z ##

Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the strelka-backend container on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.

If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.

github.com/idaholab/Malcolm/co

  • Features and enhancements

    • Add IEC 60870-5-104 (IEC 104) support using the CERT.LV spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939
    • Make LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037
    • Allow LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033
    • Improve ./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865
    • Have system-quickstart detect and prepopulate existing time synchronization settings when rerun #992
  • 🛡️ Security Remediation & Hardening

    • Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
    • Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
    • Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
    • Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
  • 🐛 Bug fixes

    • Co-installation of opencv-python and opencv-contrib-python corrupts cv2.abi3.so, segfaulting strelka-backend at import on arm64 #1046 (fix)
    • Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
    • Fix the broken signal chain in docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers
    • Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
    • Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when KEYCLOAK_SSL_VERIFY=true #1035
    • Restore curl to the the htadmin container for use by the health check script #1029
    • Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
    • Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
    • Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
  • Component version updates

  • 🧹 Code and project maintenance

    • Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
    • Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
    • Improve installer validation, environment-variable mapping tests, and configuration item metadata
    • Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
    • Minor improvements to the Hedgehog Raspberry Pi image build process.
  • 📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.

    • LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these values
    • ZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabled
    • SAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data

Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻‍♀️.

Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.

Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.

As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.

#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL

##

CVE-2026-63177
(0 None)

EPSS: 0.00%

2 posts

N/A

mmguero at 2026-07-22T14:30:51.878Z ##

Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the strelka-backend container on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.

If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.

github.com/idaholab/Malcolm/co

  • Features and enhancements

    • Add IEC 60870-5-104 (IEC 104) support using the CERT.LV spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939
    • Make LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037
    • Allow LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033
    • Improve ./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865
    • Have system-quickstart detect and prepopulate existing time synchronization settings when rerun #992
  • 🛡️ Security Remediation & Hardening

    • Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
    • Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
    • Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
    • Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
  • 🐛 Bug fixes

    • Co-installation of opencv-python and opencv-contrib-python corrupts cv2.abi3.so, segfaulting strelka-backend at import on arm64 #1046 (fix)
    • Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
    • Fix the broken signal chain in docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers
    • Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
    • Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when KEYCLOAK_SSL_VERIFY=true #1035
    • Restore curl to the the htadmin container for use by the health check script #1029
    • Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
    • Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
    • Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
  • Component version updates

  • 🧹 Code and project maintenance

    • Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
    • Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
    • Improve installer validation, environment-variable mapping tests, and configuration item metadata
    • Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
    • Minor improvements to the Hedgehog Raspberry Pi image build process.
  • 📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.

    • LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these values
    • ZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabled
    • SAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data

Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻‍♀️.

Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.

Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.

As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.

##

mmguero@infosec.exchange at 2026-07-22T14:30:51.000Z ##

Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the strelka-backend container on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.

If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.

github.com/idaholab/Malcolm/co

  • Features and enhancements

    • Add IEC 60870-5-104 (IEC 104) support using the CERT.LV spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939
    • Make LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037
    • Allow LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033
    • Improve ./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865
    • Have system-quickstart detect and prepopulate existing time synchronization settings when rerun #992
  • 🛡️ Security Remediation & Hardening

    • Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
    • Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
    • Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
    • Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
  • 🐛 Bug fixes

    • Co-installation of opencv-python and opencv-contrib-python corrupts cv2.abi3.so, segfaulting strelka-backend at import on arm64 #1046 (fix)
    • Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
    • Fix the broken signal chain in docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers
    • Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
    • Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when KEYCLOAK_SSL_VERIFY=true #1035
    • Restore curl to the the htadmin container for use by the health check script #1029
    • Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
    • Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
    • Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
  • Component version updates

  • 🧹 Code and project maintenance

    • Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
    • Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
    • Improve installer validation, environment-variable mapping tests, and configuration item metadata
    • Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
    • Minor improvements to the Hedgehog Raspberry Pi image build process.
  • 📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.

    • LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these values
    • ZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabled
    • SAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data

Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻‍♀️.

Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.

Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.

As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.

#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL

##

CVE-2026-29059
(0 None)

EPSS: 2.58%

1 posts

N/A

Nuclei template

1 repos

https://github.com/Chocapikk/Windfall

Analyst207@mastodon.social at 2026-07-22T14:06:44.000Z ##

Hackers Exploit Windmill Flaw to Read Server Files Without Authentication

A critical security flaw in Windmill, tracked as CVE-2026-29059, has left around 170 instances across 24 countries vulnerable to hackers who can exploit it to read server files without needing login credentials. This bug, which was fixed in January 2026, allows attackers to access arbitrary files…

osintsights.com/hackers-exploi

#UnauthenticatedPathTraversal #Windmill #Cve202629059 #EmergingThreats #VulnerabilityExploitation

##

CVE-2026-58443
(0 None)

EPSS: 0.00%

3 posts

N/A

offseq at 2026-07-22T04:30:26.298Z ##

Gitea <1.27.0 CRITICAL vuln (CVE-2026-58443): Public-only write tokens can update private PR head branches, violating repo access controls. Patch pending — review token use & monitor vendor updates. radar.offseq.com/threat/gitea-

##

offseq@infosec.exchange at 2026-07-22T04:30:26.000Z ##

Gitea <1.27.0 CRITICAL vuln (CVE-2026-58443): Public-only write tokens can update private PR head branches, violating repo access controls. Patch pending — review token use & monitor vendor updates. radar.offseq.com/threat/gitea- #OffSeq #Gitea #Vuln #CVE202658443

##

DailyCyberSecurity@infosec.exchange at 2026-07-20T15:02:49.000Z ##

Gitea vulnerability CVE-2026-58443 (CVSS 9.6) lets public-only tokens write to private repos. Details and PoC code are public. Update to v1.27.0.

#Gitea #CVE202658443 #DevSecOps #PoC #InfoSec

securityonline.info/gitea-vuln

##

CVE-2026-56819
(0 None)

EPSS: 0.63%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-22T01:00:02.000Z ##

🟠 CVE-2026-56819 - High (7.5)

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `D...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50055
(0 None)

EPSS: 0.00%

1 posts

N/A

1 repos

https://github.com/HORKimhab/CVE-2026-50055

offseq@infosec.exchange at 2026-07-21T09:00:25.000Z ##

Zimbra ZCS 10.1.20 patches CRITICAL vulnerabilities: command injection, XSS, mail forwarding bypass (CVE-2026-50055), EWS access flaws, SSRF. No attacks seen yet. Update ASAP to secure servers. radar.offseq.com/threat/zimbra #OffSeq #Zimbra #InfoSec #Vuln

##

CVE-2026-53595
(0 None)

EPSS: 0.30%

2 posts

N/A

1 repos

https://github.com/0xdak/CVE-2026-53595_exploit

offseq@infosec.exchange at 2026-07-21T07:30:24.000Z ##

FreeScout (<1.8.224) has a CRITICAL vuln (CVE-2026-53595, CVSS 9.4): improper invite_hash handling lets unauthenticated attackers overwrite + access the lowest-id activated user account. Patch to 1.8.224. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202653595 #infosec #vuln

##

thehackerwire@mastodon.social at 2026-07-20T22:00:14.000Z ##

🔴 CVE-2026-53595 - Critical (9.4)

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenController@userSetupSave`) selects the target account solely by its `...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53591
(0 None)

EPSS: 0.21%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-20T23:01:25.000Z ##

🟠 CVE-2026-53591 - High (8.6)

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject messages into any existing support conversation by sending a single email to the helpdesk's public ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55544
(0 None)

EPSS: 0.18%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-20T23:00:30.000Z ##

🟠 CVE-2026-55544 - High (7.6)

NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write operations over the network using user-generated Bearer API tokens (`nxtc__...`). The application has ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47129
(0 None)

EPSS: 0.22%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-20T22:01:34.000Z ##

🟠 CVE-2026-47129 - High (8.1)

NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Control (BAC) vulnerability in the `activateUser` and `deactivateUser` Next.js Server Actions of NextCRM. The application fails t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63429
(0 None)

EPSS: 0.30%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-20T17:00:00.000Z ##

🟠 CVE-2026-63429 - High (8.6)

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, and no session cookie check. Any anonymous internet user ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-42566
(0 None)

EPSS: 0.28%

2 posts

N/A

offseq@infosec.exchange at 2026-07-20T01:30:27.000Z ##

CVE-2026-42566 (HIGH): Meshtastic firmware <2.7.23.b246bcd suffers from improper input validation. Malformed User.long_name can poison BLE node DBs, causing iOS sync loops and device loss. Upgrade now. Details: radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE #IoTSecurity

##

thehackerwire@mastodon.social at 2026-07-20T01:00:05.000Z ##

🟠 CVE-2026-42566 - High (7.5)

Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a malformed character encoding can render other radios unusable over BLE when managed through the iOS ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44359
(0 None)

EPSS: 1.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-07-20T01:00:14.000Z ##

🔴 CVE-2026-44359 - Critical (10)

Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code and execu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-20T00:00:35.000Z ##

Meshtastic firmware (pre-2.7.21.1370b23) has a CRITICAL code injection flaw (CVE-2026-44359) in GitHub Actions (main_matrix.yml), risking repo secrets & supply chain compromise. Patch ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202644359 #Infosec

##

Visit counter For Websites