## Updated at UTC 2026-10-03T19:42:42.633342

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-89236 8.6 0.17% 2 0 2026-10-03T18:32:06 The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and es
CVE-2026-88783 8.8 0.17% 2 0 2026-10-03T18:32:06 The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widen
CVE-2026-96451 8.8 0.00% 2 0 2026-10-03T18:31:05 Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Membe
CVE-2026-103514 7.5 0.19% 2 0 2026-10-03T18:31:03 The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-t
CVE-2026-101161 7.5 0.16% 2 0 2026-10-03T18:31:02 The WP Ultimate Review WordPress plugin before 2.4.4 does not prevent unauthenti
CVE-2026-101159 7.5 0.17% 2 0 2026-10-03T18:31:02 The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise
CVE-2026-96267 7.5 0.33% 2 0 2026-10-03T16:16:46.693000 The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable
CVE-2026-91078 8.2 0.14% 2 0 2026-10-03T16:16:41.237000 The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publi
CVE-2026-19660 9.8 0.40% 1 2 2026-10-03T16:16:36.710000 The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass
CVE-2026-15897 8.8 0.30% 1 0 2026-10-03T16:16:36.267000 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to
CVE-2026-103624 8.3 0.21% 2 0 2026-10-03T16:16:33.557000 Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0
CVE-2026-101923 8.1 0.34% 2 0 2026-10-03T16:16:32.120000 The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrar
CVE-2026-101160 7.5 0.16% 2 0 2026-10-03T16:16:31.560000 The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a su
CVE-2026-103065 8.2 0.00% 2 0 2026-10-03T15:30:32 Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirk
CVE-2026-105115 8.6 0.00% 2 0 2026-10-03T14:16:38.110000 OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation v
CVE-2026-105105 9.8 0.00% 4 0 2026-10-03T12:31:34 CWE-306: Missing Authentication for Critical Function in the ait.core.server tel
CVE-2026-75028 7.5 0.70% 2 0 2026-10-03T09:31:26 The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin
CVE-2026-94505 8.1 0.29% 2 0 2026-10-03T09:31:26 The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for Wo
CVE-2026-92084 9.1 0.53% 2 0 2026-10-03T09:31:26 The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for W
CVE-2026-71885 None 0.19% 2 0 2026-10-03T09:31:26 In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 94
CVE-2026-71887 None 0.09% 2 0 2026-10-03T09:31:26 In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a dat
CVE-2026-18443 8.8 0.37% 2 0 2026-10-03T09:31:25 The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin
CVE-2026-87115 9.1 0.88% 4 0 2026-10-03T09:31:25 The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable
CVE-2026-103913 7.5 0.38% 2 0 2026-10-03T06:31:25 The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the sto
CVE-2026-97337 7.5 0.37% 2 0 2026-10-03T06:31:25 The Simple Membership plugin for WordPress is vulnerable to unauthorized modific
CVE-2026-97644 8.8 0.50% 2 0 2026-10-03T06:31:19 The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress
CVE-2026-92536 8.8 0.63% 2 0 2026-10-03T06:31:12 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User
CVE-2026-103622 8.8 0.27% 2 0 2026-10-03T04:18:00.633000 Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote a
CVE-2026-93428 7.5 0.40% 2 0 2026-10-03T03:31:44 The Ultimate Member – User Profile, Registration, Login, Member Directory, Conte
CVE-2026-105080 9.9 0.33% 3 0 2026-10-03T03:31:39 In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, an
CVE-2026-84411 9.8 0.95% 5 0 2026-10-03T00:31:21 The web management service in affected RouterOS versions contains an integer und
CVE-2026-104433 7.5 0.37% 2 0 2026-10-03T00:31:21 Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerabil
CVE-2026-94592 8.4 0.13% 2 0 2026-10-03T00:31:17 Armatura One's database initialization routine assigns a fixed, vendor-defined p
CVE-2026-97363 7.5 0.32% 2 0 2026-10-03T00:31:16 The WebSocket Application Programming Interface lacks restrictions on the number
CVE-2026-95102 9.4 0.34% 4 0 2026-10-03T00:31:16 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to
CVE-2026-94593 7.8 0.11% 2 0 2026-10-03T00:31:16 Armatura One's backup and restore routine records the full database connection c
CVE-2026-94591 8.4 0.09% 2 0 2026-10-03T00:31:16 Armatura One stores database and message-broker credentials in an install config
CVE-2026-59265 None 0.22% 2 0 2026-10-03T00:31:13 A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and
CVE-2026-104861 7.5 0.43% 1 0 2026-10-02T23:18:02 ## Overview `probe-image-size` scans the SVG header with a searching regular ex
CVE-2026-19484 7.5 0.61% 1 0 2026-10-02T23:17:29 ### Impact Versions of `@fastify/busboy` from 3.1.0 and prior to 3.2.1 are vuln
CVE-2026-82039 8.8 0.34% 2 0 2026-10-02T21:32:19 UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupS
CVE-2026-82044 7.7 0.26% 2 0 2026-10-02T21:32:19 UTMStack before 11.2.16 contains a server-side request forgery vulnerability tha
CVE-2026-82042 9.8 0.55% 2 0 2026-10-02T21:32:19 UTMStack before 11.2.16 contains an authentication bypass vulnerability that all
CVE-2026-82041 9.9 0.44% 2 0 2026-10-02T21:32:19 UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMInc
CVE-2026-104988 8.1 0.20% 2 0 2026-10-02T21:32:18 A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plug
CVE-2026-39718 8.8 0.14% 2 0 2026-10-02T21:32:18 Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet
CVE-2026-96940 8.8 0.50% 7 0 2026-10-02T21:32:13 Weak authorization in Microsoft Exchange Server allows an authenticated attacker
CVE-2026-75937 None 0.53% 3 0 2026-10-02T21:32:07 A specially crafted HTTP POST request to the web administration interface allows
CVE-2026-103628 9.6 0.33% 3 0 2026-10-02T21:32:03 Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a r
CVE-2026-51916 7.5 0.43% 2 0 2026-10-02T21:16:55.427000 TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnera
CVE-2026-48005 7.5 0.61% 1 0 2026-10-02T20:54:53.960000 Missing authentication checks in mod_auth_digest in Apache Software Foundation A
CVE-2026-56153 7.5 0.50% 1 0 2026-10-02T20:53:53.630000 Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. T
CVE-2026-67989 7.5 0.34% 2 0 2026-10-02T20:17:03.933000 crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a pol
CVE-2026-51907 8.1 0.39% 2 0 2026-10-02T20:17:02.713000 In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function,
CVE-2026-18397 0 0.34% 2 0 2026-10-02T20:17:02.060000 This vulnerability enables unauthenticated remote code execution (RCE) on a vict
CVE-2026-103764 9.8 0.64% 1 0 2026-10-02T19:16:39.627000 Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference
CVE-2026-103098 7.5 0.16% 1 0 2026-10-02T19:16:39.350000 Transmission of a sensitive key in the URL over an unencrypted HTTP connection. 
CVE-2026-90970 9.9 0.94% 11 1 2026-10-02T18:44:11.270000 GitLab has remediated a vulnerability in the GitLab AI Gateway component affecti
CVE-2026-103922 9.3 0.21% 1 1 2026-10-02T18:44:11.270000 Capacitor is a cross-platform native runtime for web applications. From 6.0.0 un
CVE-2026-102489 9.8 1.40% 6 0 2026-10-02T18:32:21 Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability tha
CVE-2026-102667 8.3 0.19% 1 0 2026-10-02T18:32:21 Joyland AI app allows an attacker with shared network access to inject JavaScrip
CVE-2026-102490 9.8 0.63% 4 0 2026-10-02T18:32:21 All versions of Zammad including the latest alpha enable the local zammad user t
CVE-2026-102795 9.3 0.28% 1 0 2026-10-02T18:31:37 Improper Access Control vulnerability in Apache Traffic Server. This issue af
CVE-2026-103648 9.1 0.41% 1 1 2026-10-02T18:31:36 Path traversal in image-downloader 4.3.0 allows an attacker who can control the
CVE-2026-101104 7.7 0.27% 1 0 2026-10-02T18:31:25 The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization f
CVE-2026-96658 9.9 0.70% 1 0 2026-10-02T18:31:18 A flaw was found in Foreman. An authenticated attacker with low-level permission
CVE-2026-91135 0 0.46% 1 0 2026-10-02T18:17:06.963000 Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport.
CVE-2026-80298 8.8 0.29% 1 0 2026-10-02T18:17:05.370000 Improper neutralization of special elements used in an SQL command ('SQL injecti
CVE-2026-104410 7.5 0.38% 1 0 2026-10-02T18:17:00.790000 SiYuan before 3.8.5 contains an information disclosure vulnerability that allows
CVE-2026-104423 7.5 0.34% 1 0 2026-10-02T17:59:09.430000 Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerab
CVE-2026-104430 7.5 0.41% 1 0 2026-10-02T17:59:09.430000 Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature ope
CVE-2026-104845 7.5 0.43% 1 0 2026-10-02T16:16:47.200000 Seroval facilitates JS value stringification, including complex structures beyon
CVE-2026-104467 8.1 0.37% 1 0 2026-10-02T16:16:46.357000 YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiServic
CVE-2026-104026 7.8 0.13% 1 0 2026-10-02T15:31:37 In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to
CVE-2026-19652 9.8 0.33% 1 0 2026-10-02T15:31:32 The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation i
CVE-2026-104611 9.1 0.49% 1 0 2026-10-02T15:31:31 A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown fu
CVE-2026-104456 7.6 0.30% 1 0 2026-10-02T15:17:07.693000 YesWiki before 4.6.7 contains a second-order SQL injection vulnerability in AclS
CVE-2026-104610 10.0 0.64% 2 0 2026-10-02T14:17:09.267000 A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_
CVE-2026-104286 9.8 2.20% 14 2 2026-10-02T12:35:33.990000 An improper limitation of a pathname to a restricted directory ('path traversal'
CVE-2026-91828 7.5 0.31% 1 0 2026-10-02T12:32:16 The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin bef
CVE-2026-104448 8.1 0.16% 1 0 2026-10-02T12:31:26 YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the
CVE-2026-104462 7.5 0.31% 1 0 2026-10-02T12:31:26 YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuaget
CVE-2026-104472 7.5 0.34% 1 0 2026-10-02T12:31:26 YesWiki before 4.6.7 contains a missing authorization vulnerability in the attac
CVE-2026-104464 8.6 0.29% 1 0 2026-10-02T12:31:25 YesWiki before 4.6.7 contains a server-side request forgery vulnerability that a
CVE-2026-104460 7.5 0.39% 1 0 2026-10-02T12:31:25 YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newte
CVE-2026-104416 7.5 0.31% 1 0 2026-10-02T12:31:20 Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability
CVE-2026-104422 7.5 0.18% 1 0 2026-10-02T12:31:20 The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's heig
CVE-2026-104445 8.2 0.40% 1 0 2026-10-02T12:31:20 YesWiki before 4.6.7 contains an authentication bypass vulnerability in the Acti
CVE-2026-104443 8.1 0.36% 1 0 2026-10-02T12:31:20 YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete
CVE-2026-104414 8.1 0.28% 1 0 2026-10-02T12:31:19 Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerabil
CVE-2026-104431 7.5 0.34% 1 0 2026-10-02T12:31:19 Zebra before 6.0.0 contains a denial of service vulnerability that allows unauth
CVE-2026-86325 None 0.34% 2 0 2026-10-02T12:31:19 A stack-based buffer overflow vulnerability exists in protocol gateways' account
CVE-2026-94541 9.8 0.49% 2 1 2026-10-02T12:31:19 The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerabl
CVE-2026-86326 None 0.19% 2 0 2026-10-02T12:31:13 An improper verification of cryptographic signature vulnerability exists in prot
CVE-2026-104457 8.6 0.28% 1 0 2026-10-02T12:17:17.767000 YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filter
CVE-2026-97637 9.8 0.64% 2 0 2026-10-02T09:31:31 The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass vi
CVE-2026-93698 9.9 0.46% 2 0 2026-10-02T09:31:25 Insufficient validation allows arbitrary commands to be executed via the Multila
CVE-2026-93697 9.0 0.40% 1 0 2026-10-02T09:31:25 There is a stored XSS vulnerability allowing arbitrary code execution in the WHM
CVE-2026-93029 9.0 0.40% 2 0 2026-10-02T09:31:25 There is a stored XSS vulnerability allowing arbitrary code execution in the WHM
CVE-2026-92820 8.1 0.52% 1 0 2026-10-02T06:31:04 The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary f
CVE-2026-92174 7.5 0.56% 1 0 2026-10-02T06:31:03 The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File I
CVE-2026-14378 9.8 0.48% 2 3 2026-10-02T06:30:58 The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leadi
CVE-2026-15896 9.1 0.88% 2 0 2026-10-02T06:30:55 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to
CVE-2026-103096 7.5 0.15% 1 0 2026-10-02T03:31:14 API key is hardcoded and retrievable from the application package. Since Android
CVE-2026-104480 None 0.40% 1 0 2026-10-02T03:31:10 Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resu
CVE-2026-103097 7.5 0.15% 1 0 2026-10-02T03:31:10 An API key is hardcoded and retrievable from the application package. Since Andr
CVE-2026-86345 9.0 0.38% 1 0 2026-10-02T00:31:40 A flaw was found in 389-ds-base. The server does not discard plaintext bytes alr
CVE-2026-103765 9.4 0.50% 1 0 2026-10-02T00:31:39 Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in
CVE-2026-57941 9.8 0.44% 1 0 2026-10-01T21:33:58 Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared sessio
CVE-2026-63686 7.5 0.33% 1 0 2026-10-01T21:33:58 A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache H
CVE-2026-63292 7.5 0.58% 2 1 2026-10-01T21:33:58 Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apa
CVE-2026-59685 7.5 0.34% 1 0 2026-10-01T21:33:58 Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while process
CVE-2026-73636 8.1 0.37% 1 0 2026-10-01T21:33:58 Authentication bypass by capture-replay in mod_auth_digest in Apache Software Fo
CVE-2026-63718 7.5 0.32% 1 0 2026-10-01T21:33:58 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVE-2026-56449 7.5 0.42% 1 0 2026-10-01T21:33:57 Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with cr
CVE-2026-56154 9.8 0.42% 1 0 2026-10-01T21:33:57 Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using look
CVE-2026-103484 8.8 0.42% 1 0 2026-10-01T21:33:02 IVFFlat index build in pgvector before 0.8.7 allows a database user to write dat
CVE-2026-93546 8.8 0.34% 1 0 2026-10-01T21:17:26.023000 Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an au
CVE-2026-63045 7.5 0.33% 1 0 2026-10-01T21:17:23.433000 Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Softwar
CVE-2026-59797 9.8 0.39% 1 0 2026-10-01T21:17:23.263000 Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via
CVE-2026-102628 9.3 0.28% 1 0 2026-10-01T20:37:52.400000 The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode en
CVE-2026-102369 0 0.24% 1 0 2026-10-01T20:36:38.330000 Tapo C120 v1 and C200 V5 do not adequately protect login challenge data or sanit
CVE-2026-96760 9.8 0.28% 1 1 2026-10-01T15:31:30 Authlib (v1.7.2 and below) contains a signature verification bypass vulnerabilit
CVE-2026-79901 9.9 0.27% 2 0 2026-10-01T15:30:49 In deployments using BoKS keytab management, affected versions of boks_keytabmd
CVE-2024-58388 7.5 0.81% 1 0 2026-10-01T15:30:42 Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthentica
CVE-2026-71972 5.9 0.22% 1 0 2026-09-30T00:32:46 U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the
CVE-2026-86950 8.8 1.24% 2 3 2026-09-29T15:32:17 An out-of-bounds write issue was addressed with improved bounds checking. This i
CVE-2026-102437 7.8 0.99% 2 0 2026-09-29T15:31:45 OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation
CVE-2026-88771 9.8 1.06% 6 11 2026-09-29T04:18:01.603000 Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc
CVE-2026-93355 8.1 0.27% 2 0 2026-09-28T21:31:26 LiteLLM contains a weak authentication vulnerability that allows an attacker hol
CVE-2026-88772 8.1 1.30% 3 8 2026-09-28T12:26:47.670000 Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue
CVE-2026-85706 10.0 92.96% 2 14 template 2026-09-24T12:52:28.143000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7
CVE-2026-75791 8.6 1.71% 1 0 2026-09-22T19:32:25.730000 Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerab
CVE-2026-63278 0 0.15% 1 0 2026-09-22T19:09:32.273000 URLs could be constructed which expanded environment variable or INI file values
CVE-2026-18345 4.3 0.20% 1 0 2026-09-22T19:04:55.677000 The WP User Manager plugin for WordPress is vulnerable to unauthorized modificat
CVE-2026-87080 9.1 0.63% 1 0 2026-09-22T18:34:36 Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label t
CVE-2026-95619 7.7 0.36% 1 0 2026-09-22T18:34:31 A flaw was found in libstdc++. An integer overflow can occur when processing lar
CVE-2026-87078 9.1 0.65% 2 0 2026-09-22T18:33:29 Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buf
CVE-2026-95271 7.3 0.65% 1 0 2026-09-22T15:32:34 A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The
CVE-2026-92882 0 0.35% 1 0 2026-09-22T14:17:17.950000 Insufficiently protected credentials in the host and folder configuration endpoi
CVE-2026-90990 0 0.42% 1 0 2026-09-22T14:17:17.830000 Improper neutralization of newlines in filter values in the monitoring host and
CVE-2026-63276 None 0.17% 1 0 2026-09-22T12:30:32 LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens w
CVE-2026-87119 None 0.57% 1 0 2026-09-22T12:30:32 Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holdin
CVE-2026-95270 3.7 0.44% 1 0 2026-09-22T12:30:32 A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected
CVE-2026-4123 4.3 0.35% 1 0 2026-09-22T09:31:17 The RW Elephant Rental Inventory plugin for WordPress is vulnerable to Missing A
CVE-2026-9004 4.3 0.37% 1 0 2026-09-22T09:31:17 The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerab
CVE-2026-54049 8.7 0.26% 1 0 2026-08-24T19:37:55 ### Summary The Sakai Conversations tool stores topic and post messages without
CVE-2026-73570 8.9 11.74% 2 10 template 2026-08-24T13:19:17.577000 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor
CVE-2026-73916 9.1 0.43% 1 0 2026-08-19T15:32:19 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-61500 9.8 0.86% 2 1 2026-07-13T18:31:00 Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the
CVE-2024-12426 6.5 0.55% 1 0 2026-06-17T06:59:41.900000 Exposure of Environmental Variables and arbitrary INI file values to an Unauthor
CVE-2021-35394 9.8 99.86% 1 0 template 2026-06-17T03:57:29.187000 Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called
CVE-2026-8695 7.5 1.07% 1 2 2026-05-15T18:30:46 radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list()
CVE-2026-3323 7.5 0.52% 4 1 2026-04-28T12:31:36 An unsecured configuration interface on affected devices allows unauthenticated
CVE-2026-20700 7.8 1.37% 1 2 2026-02-12T21:31:27 A memory corruption issue was addressed with improved state management. This iss
CVE-2026-103956 0 0.47% 3 0 N/A
CVE-2026-103958 0 0.33% 2 0 N/A
CVE-2026-104019 0 1.42% 5 0 N/A
CVE-2026-65634 0 0.42% 1 0 N/A
CVE-2026-10426 0 0.00% 1 0 N/A
CVE-2026-104851 0 0.32% 1 0 N/A
CVE-2026-104846 0 0.34% 1 0 N/A
CVE-2026-94422 0 0.69% 1 0 N/A
CVE-2026-85714 0 0.00% 1 0 N/A
CVE-2026-86360 0 0.00% 1 0 N/A
CVE-2026-63692 0 0.00% 1 0 N/A
CVE-2026-63688 0 0.00% 1 0 N/A

CVE-2026-89236
(8.6 HIGH)

EPSS: 0.17%

updated 2026-10-03T18:32:06

2 posts

The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.

thehackerwire@mastodon.social at 2026-10-03T16:33:40.000Z ##

🟠 CVE-2026-89236 - High (8.6)

The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive info...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:33:40.000Z ##

🟠 CVE-2026-89236 - High (8.6)

The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive info...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88783
(8.8 HIGH)

EPSS: 0.17%

updated 2026-10-03T18:32:06

2 posts

The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to store markup which the Kubio AI Page Builder WordPress plugin before 2.9.3's own script later executes in the browser of any visitor, or of an administr

thehackerwire@mastodon.social at 2026-10-03T16:33:31.000Z ##

🟠 CVE-2026-88783 - High (8.8)

The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:33:31.000Z ##

🟠 CVE-2026-88783 - High (8.8)

The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96451
(8.8 HIGH)

EPSS: 0.00%

updated 2026-10-03T18:31:05

2 posts

Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.

thehackerwire@mastodon.social at 2026-10-03T16:17:34.000Z ##

🟠 CVE-2026-96451 - High (8.8)

Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:17:34.000Z ##

🟠 CVE-2026-96451 - High (8.8)

Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103514
(7.5 HIGH)

EPSS: 0.19%

updated 2026-10-03T18:31:03

2 posts

The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts.

thehackerwire@mastodon.social at 2026-10-03T16:47:36.000Z ##

🟠 CVE-2026-103514 - High (7.5)

The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:47:36.000Z ##

🟠 CVE-2026-103514 - High (7.5)

The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101161
(7.5 HIGH)

EPSS: 0.16%

updated 2026-10-03T18:31:02

2 posts

The WP Ultimate Review WordPress plugin before 2.4.4 does not prevent unauthenticated users from storing crafted review content that makes the reviewed page fail with a fatal error on every subsequent visit, resulting in a persistent denial of service when the WP Ultimate Review WordPress plugin before 2.4.4's review display settings have never been saved.

thehackerwire@mastodon.social at 2026-10-03T17:02:38.000Z ##

🟠 CVE-2026-101161 - High (7.5)

The WP Ultimate Review WordPress plugin before 2.4.4 does not prevent unauthenticated users from storing crafted review content that makes the reviewed page fail with a fatal error on every subsequent visit, resulting in a persistent denial of ser...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:02:38.000Z ##

🟠 CVE-2026-101161 - High (7.5)

The WP Ultimate Review WordPress plugin before 2.4.4 does not prevent unauthenticated users from storing crafted review content that makes the reviewed page fail with a fatal error on every subsequent visit, resulting in a persistent denial of ser...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101159
(7.5 HIGH)

EPSS: 0.17%

updated 2026-10-03T18:31:02

2 posts

The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews submitted through its public review form, which is available to unauthenticated visitors, allowing them to perform Stored Cross-Site Scripting attacks against any user, including administrators, viewing a page displaying the review, when user reviews are enabled.

thehackerwire@mastodon.social at 2026-10-03T16:47:45.000Z ##

🟠 CVE-2026-101159 - High (7.5)

The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews submitted through its public review form, which is available to unauthenticated visitors, allowing them to perform Stored Cross-Site Scripting attac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:47:45.000Z ##

🟠 CVE-2026-101159 - High (7.5)

The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews submitted through its public review form, which is available to unauthenticated visitors, allowing them to perform Stored Cross-Site Scripting attac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96267
(7.5 HIGH)

EPSS: 0.33%

updated 2026-10-03T16:16:46.693000

2 posts

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, and including, 8.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already exi

thehackerwire@mastodon.social at 2026-10-03T15:18:42.000Z ##

🟠 CVE-2026-96267 - High (7.5)

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, and including, 8.7 due to insufficient escaping on the user supplied parameter and lack of...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T15:18:42.000Z ##

🟠 CVE-2026-96267 - High (7.5)

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, and including, 8.7 due to insufficient escaping on the user supplied parameter and lack of...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91078
(8.2 HIGH)

EPSS: 0.14%

updated 2026-10-03T16:16:41.237000

2 posts

The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone with no identity or capability check, allowing unauthenticated attackers to obtain a privileged POS session and thereby read customer and site-user personal

thehackerwire@mastodon.social at 2026-10-03T16:33:49.000Z ##

🟠 CVE-2026-91078 - High (8.2)

The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone wit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:33:49.000Z ##

🟠 CVE-2026-91078 - High (8.2)

The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone wit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19660
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-10-03T16:16:36.710000

1 posts

The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled

2 repos

https://github.com/murrez/CVE-2026-19660

https://github.com/MRdark-ops/CVE-2026-19660-exploit

thehackerwire@mastodon.social at 2026-10-02T10:17:44.000Z ##

🔴 CVE-2026-19660 - Critical (9.8)

The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15897
(8.8 HIGH)

EPSS: 0.30%

updated 2026-10-03T16:16:36.267000

1 posts

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function, in its register_login_action='update' flow, trusting an attacker-supplied user_id value and passing it to wp_update_user() without any ownership or capability check. Bec

thehackerwire@mastodon.social at 2026-10-02T07:02:58.000Z ##

🟠 CVE-2026-15897 - High (8.8)

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function, in its registe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103624
(8.3 HIGH)

EPSS: 0.21%

updated 2026-10-03T16:16:33.557000

2 posts

Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-10-03T19:00:57.000Z ##

🟠 CVE-2026-103624 - High (8.3)

Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromiu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T19:00:57.000Z ##

🟠 CVE-2026-103624 - High (8.3)

Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromiu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101923
(8.1 HIGH)

EPSS: 0.34%

updated 2026-10-03T16:16:32.120000

2 posts

The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of a public review submission into the review's reviews-images comment meta without verifying that the IDs correspond to attachments owned by the submitter,

thehackerwire@mastodon.social at 2026-10-03T16:03:00.000Z ##

🟠 CVE-2026-101923 - High (8.1)

The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:03:00.000Z ##

🟠 CVE-2026-101923 - High (8.1)

The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101160
(7.5 HIGH)

EPSS: 0.16%

updated 2026-10-03T16:16:31.560000

2 posts

The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a submitted review rating is numeric before storing it and later using it in numeric operations when rendering reviews, allowing unauthenticated users to make the reviewed content fail with a fatal error for all visitors until the review is removed (a persistent denial of service), when user reviews are enabled.

thehackerwire@mastodon.social at 2026-10-03T16:47:54.000Z ##

🟠 CVE-2026-101160 - High (7.5)

The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a submitted review rating is numeric before storing it and later using it in numeric operations when rendering reviews, allowing unauthenticated users to make the reviewed...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:47:54.000Z ##

🟠 CVE-2026-101160 - High (7.5)

The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a submitted review rating is numeric before storing it and later using it in numeric operations when rendering reviews, allowing unauthenticated users to make the reviewed...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103065
(8.2 HIGH)

EPSS: 0.00%

updated 2026-10-03T15:30:32

2 posts

Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1.

thehackerwire@mastodon.social at 2026-10-03T15:17:27.000Z ##

🟠 CVE-2026-103065 - High (8.2)

Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T15:17:27.000Z ##

🟠 CVE-2026-103065 - High (8.2)

Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105115
(8.6 HIGH)

EPSS: 0.00%

updated 2026-10-03T14:16:38.110000

2 posts

OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadge

thehackerwire@mastodon.social at 2026-10-03T15:17:36.000Z ##

🟠 CVE-2026-105115 - High (8.6)

OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* wi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T15:17:36.000Z ##

🟠 CVE-2026-105115 - High (8.6)

OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* wi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105105
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-03T12:31:34

4 posts

CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus. The ait-serv

thehackerwire@mastodon.social at 2026-10-03T15:17:44.000Z ##

🔴 CVE-2026-105105 - Critical (9.8)

CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-10-03T13:30:23.755Z ##

NASA-AMMOS AIT-Core ≤3.1.1 has a CRITICAL vuln (CVE-2026-105105): ZeroMQ bus lacks auth, exposing command & telemetry to remote attackers. Upgrade to 3.1.2 restricts access to loopback. Details: radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-10-03T15:17:44.000Z ##

🔴 CVE-2026-105105 - Critical (9.8)

CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-03T13:30:23.000Z ##

NASA-AMMOS AIT-Core ≤3.1.1 has a CRITICAL vuln (CVE-2026-105105): ZeroMQ bus lacks auth, exposing command & telemetry to remote attackers. Upgrade to 3.1.2 restricts access to loopback. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #SpaceSec #Infosec

##

CVE-2026-75028
(7.5 HIGH)

EPSS: 0.70%

updated 2026-10-03T09:31:26

2 posts

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.18 via the (template scope) function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP c

thehackerwire@mastodon.social at 2026-10-03T15:33:01.000Z ##

🟠 CVE-2026-75028 - High (7.5)

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.18 via the (template scope) function. This makes it possible for authe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T15:33:01.000Z ##

🟠 CVE-2026-75028 - High (7.5)

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.18 via the (template scope) function. This makes it possible for authe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94505
(8.1 HIGH)

EPSS: 0.29%

updated 2026-10-03T09:31:26

2 posts

The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to permanently delete any reusable socia

thehackerwire@mastodon.social at 2026-10-03T15:18:33.000Z ##

🟠 CVE-2026-94505 - High (8.1)

The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0 This is due to the plugin not properly verifying that a user is authorized ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T15:18:33.000Z ##

🟠 CVE-2026-94505 - High (8.1)

The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0 This is due to the plugin not properly verifying that a user is authorized ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92084
(9.1 CRITICAL)

EPSS: 0.53%

updated 2026-10-03T09:31:26

2 posts

The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcode

thehackerwire@mastodon.social at 2026-10-03T15:18:23.000Z ##

🔴 CVE-2026-92084 - Critical (9.1)

The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an acti...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T15:18:23.000Z ##

🔴 CVE-2026-92084 - Critical (9.1)

The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an acti...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71885(CVSS UNKNOWN)

EPSS: 0.19%

updated 2026-10-03T09:31:26

2 posts

In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against the signature_key carried in the leaf itself, while the credential's X.509 certificate chain was stored but never parsed or validated, so the end-entity certificate's public key was ne

offseq at 2026-10-03T10:30:24.666Z ##

CRITICAL CVE-2026-71885 in Bouncy Castle BC-JAVA (<1.86): Improper X.509 cert validation in MLS lets attackers impersonate users & compromise group comms. Upgrade to 1.86+ ASAP. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-03T10:30:24.000Z ##

CRITICAL CVE-2026-71885 in Bouncy Castle BC-JAVA (<1.86): Improper X.509 cert validation in MLS lets attackers impersonate users & compromise group comms. Upgrade to 1.86+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202671885 #JavaSecurity #Infosec

##

CVE-2026-71887(CVSS UNKNOWN)

EPSS: 0.09%

updated 2026-10-03T09:31:26

2 posts

In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature carried no embedded Primary Key Binding (cross-certification) signature, in the case where that binding omits a Key Flags subpacket. RFC 9580 sec. 5.2.1.8 and sec. 10.1.3 require the embedded Primary Key Binding signature on any subkey that can issue s

offseq at 2026-10-03T09:00:25.321Z ##

CVE-2026-71887 | Legion of the Bouncy Castle BC-JAVA <1.86 has a HIGH severity flaw: improper signature verification can enable signature misattribution via public signing subkeys. Patch to 1.86+ now. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-03T09:00:25.000Z ##

CVE-2026-71887 | Legion of the Bouncy Castle BC-JAVA <1.86 has a HIGH severity flaw: improper signature verification can enable signature misattribution via public signing subkeys. Patch to 1.86+ now. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Java #Infosec

##

CVE-2026-18443
(8.8 HIGH)

EPSS: 0.37%

updated 2026-10-03T09:31:25

2 posts

The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and including, 8.97.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subs

thehackerwire@mastodon.social at 2026-10-03T15:33:19.000Z ##

🟠 CVE-2026-18443 - High (8.8)

The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and including, 8.97.0 due to insufficient escaping...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T15:33:19.000Z ##

🟠 CVE-2026-18443 - High (8.8)

The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and including, 8.97.0 due to insufficient escaping...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87115
(9.1 CRITICAL)

EPSS: 0.88%

updated 2026-10-03T09:31:25

4 posts

The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as

thehackerwire@mastodon.social at 2026-10-03T15:33:11.000Z ##

🔴 CVE-2026-87115 - Critical (9.1)

The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-10-03T07:30:22.893Z ##

VikAppointments Booking Calendar plugin (<=1.2.21) for WordPress is vulnerable to CRITICAL path traversal (CVE-2026-87115). Unauth attackers can delete files, risking RCE. Check for File-type fields & secure your site! radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-10-03T15:33:11.000Z ##

🔴 CVE-2026-87115 - Critical (9.1)

The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-03T07:30:22.000Z ##

VikAppointments Booking Calendar plugin (<=1.2.21) for WordPress is vulnerable to CRITICAL path traversal (CVE-2026-87115). Unauth attackers can delete files, risking RCE. Check for File-type fields & secure your site! radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202687115

##

CVE-2026-103913
(7.5 HIGH)

EPSS: 0.38%

updated 2026-10-03T06:31:25

2 posts

The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. This is due to insufficient escaping and the absence of numeric validation on coordinate values when a listing is saved, combined with the direct string interpolation of those values into a distance sub-expression in geodir_gps_q

thehackerwire@mastodon.social at 2026-10-03T16:02:51.000Z ##

🟠 CVE-2026-103913 - High (7.5)

The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. This is due to insufficient escaping and the absence of numeric validation o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:02:51.000Z ##

🟠 CVE-2026-103913 - High (7.5)

The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. This is due to insufficient escaping and the absence of numeric validation o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97337
(7.5 HIGH)

EPSS: 0.37%

updated 2026-10-03T06:31:25

2 posts

The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are dispatched from SwpmInitTimeTasks::check_and_do_email_activation() on frontend init with no authentication, nonce, capability, or ownership check, and th

thehackerwire@mastodon.social at 2026-10-03T16:02:42.000Z ##

🟠 CVE-2026-97337 - High (7.5)

The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:02:42.000Z ##

🟠 CVE-2026-97337 - High (7.5)

The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97644
(8.8 HIGH)

EPSS: 0.50%

updated 2026-10-03T06:31:19

2 posts

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the `create_contact` function in the v3 REST endpoint (`POST /gh/v3/contacts`) is gated solely by the `add_contacts` capability and forwards the full request payload — includi

thehackerwire@mastodon.social at 2026-10-03T17:02:48.000Z ##

🟠 CVE-2026-97644 - High (8.8)

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the `create_contact`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:02:48.000Z ##

🟠 CVE-2026-97644 - High (8.8)

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the `create_contact`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92536
(8.8 HIGH)

EPSS: 0.63%

updated 2026-10-03T06:31:12

2 posts

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the get_user_profile_structure. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract other users' email addres

thehackerwire@mastodon.social at 2026-10-03T17:02:56.000Z ##

🟠 CVE-2026-92536 - High (8.8)

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the g...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:02:56.000Z ##

🟠 CVE-2026-92536 - High (8.8)

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the g...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103622
(8.8 HIGH)

EPSS: 0.27%

updated 2026-10-03T04:18:00.633000

2 posts

Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-10-03T19:00:46.000Z ##

🟠 CVE-2026-103622 - High (8.8)

Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T19:00:46.000Z ##

🟠 CVE-2026-103622 - High (8.8)

Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93428
(7.5 HIGH)

EPSS: 0.40%

updated 2026-10-03T03:31:44

2 posts

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.1 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view privacy-restricted memb

thehackerwire@mastodon.social at 2026-10-03T17:18:31.000Z ##

🟠 CVE-2026-93428 - High (7.5)

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.1 This is due to the plugin ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:18:31.000Z ##

🟠 CVE-2026-93428 - High (7.5)

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.1 This is due to the plugin ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105080
(9.9 CRITICAL)

EPSS: 0.33%

updated 2026-10-03T03:31:39

3 posts

In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.

thehackerwire@mastodon.social at 2026-10-03T17:18:39.000Z ##

🔴 CVE-2026-105080 - Critical (9.9)

In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:18:39.000Z ##

🔴 CVE-2026-105080 - Critical (9.9)

In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-03T01:30:23.000Z ##

CVE-2026-105080 (CRITICAL, CVSS 9.4) in C4illin ConvertX <0.19.0: Untrusted .recipe files can execute code via Calibre's ebook-convert. Update to 0.19.0+ recommended. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CVE2026105080 #ConvertX #Calibre

##

CVE-2026-84411
(9.8 CRITICAL)

EPSS: 0.95%

updated 2026-10-03T00:31:21

5 posts

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.

thehackerwire@mastodon.social at 2026-10-03T17:30:26.000Z ##

🔴 CVE-2026-84411 - Critical (9.8)

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary cod...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

nyanbinary at 2026-10-03T06:32:36.401Z ##

Saturday morning RouterOS 9.8 :apartyblobcat:

db.gcve.eu/vuln/cve-2026-84411

##

thehackerwire@mastodon.social at 2026-10-03T17:30:26.000Z ##

🔴 CVE-2026-84411 - Critical (9.8)

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary cod...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

nyanbinary@infosec.exchange at 2026-10-03T06:32:36.000Z ##

Saturday morning RouterOS 9.8 :apartyblobcat:

db.gcve.eu/vuln/cve-2026-84411

##

offseq@infosec.exchange at 2026-10-03T00:00:37.000Z ##

CVE-2026-84411 (CRITICAL, CVSS 9.8) affects MikroTik RouterOS <7.24. Integer underflow in web mgmt lets unauth'd attackers exec root code or DoS via crafted HTTP. Restrict access & monitor now. radar.offseq.com/threat/cve-20 #OffSeq #CVE #MikroTik #InfoSec

##

CVE-2026-104433
(7.5 HIGH)

EPSS: 0.37%

updated 2026-10-03T00:31:21

2 posts

Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the hosting process, such as an SGLang inference serve

thehackerwire@mastodon.social at 2026-10-03T17:18:50.000Z ##

🟠 CVE-2026-104433 - High (7.5)

Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:18:50.000Z ##

🟠 CVE-2026-104433 - High (7.5)

Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94592
(8.4 HIGH)

EPSS: 0.13%

updated 2026-10-03T00:31:17

2 posts

Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed.

thehackerwire@mastodon.social at 2026-10-03T17:30:45.000Z ##

🟠 CVE-2026-94592 - High (8.4)

Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operatin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:30:45.000Z ##

🟠 CVE-2026-94592 - High (8.4)

Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operatin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97363
(7.5 HIGH)

EPSS: 0.32%

updated 2026-10-03T00:31:16

2 posts

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.

thehackerwire@mastodon.social at 2026-10-03T17:45:45.000Z ##

🟠 CVE-2026-97363 - High (7.5)

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:45:45.000Z ##

🟠 CVE-2026-97363 - High (7.5)

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-95102
(9.4 CRITICAL)

EPSS: 0.34%

updated 2026-10-03T00:31:16

4 posts

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.

thehackerwire@mastodon.social at 2026-10-03T17:45:34.000Z ##

🔴 CVE-2026-95102 - Critical (9.4)

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-10-03T03:00:24.797Z ##

Monta monta.app faces a CRITICAL risk (CVE-2026-95102, CVSS 9.4): missing auth on WebSocket endpoints allows attackers to impersonate charging stations & access sensitive data. Restrict access, monitor traffic. Details: radar.offseq.com/threat/cve-20 ⚡️

##

thehackerwire@mastodon.social at 2026-10-03T17:45:34.000Z ##

🔴 CVE-2026-95102 - Critical (9.4)

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-03T03:00:24.000Z ##

Monta monta.app faces a CRITICAL risk (CVE-2026-95102, CVSS 9.4): missing auth on WebSocket endpoints allows attackers to impersonate charging stations & access sensitive data. Restrict access, monitor traffic. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202695102 #InfoSec ⚡️

##

CVE-2026-94593
(7.8 HIGH)

EPSS: 0.11%

updated 2026-10-03T00:31:16

2 posts

Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available.

thehackerwire@mastodon.social at 2026-10-03T17:45:24.000Z ##

🟠 CVE-2026-94593 - High (7.8)

Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:45:24.000Z ##

🟠 CVE-2026-94593 - High (7.8)

Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94591
(8.4 HIGH)

EPSS: 0.09%

updated 2026-10-03T00:31:16

2 posts

Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package can recover this key and initialization vector, a

thehackerwire@mastodon.social at 2026-10-03T17:30:36.000Z ##

🟠 CVE-2026-94591 - High (8.4)

Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:30:36.000Z ##

🟠 CVE-2026-94591 - High (8.4)

Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59265(CVSS UNKNOWN)

EPSS: 0.22%

updated 2026-10-03T00:31:13

2 posts

A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user. This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase. Until then, users can mitigate this issue by disabling Java runtime integration in the Preferences d

CVE-2026-104861
(7.5 HIGH)

EPSS: 0.43%

updated 2026-10-02T23:18:02

1 posts

## Overview `probe-image-size` scans the SVG header with a searching regular expression, `/<[-_.:a-zA-Z0-9][^>]*>/`. On input that contains many `<` characters but no `>`, the engine restarts the `[^>]*` scan at every `<` position and runs to end of input each time, giving quadratic time complexity. Both the synchronous and the streaming parser are affected. ## Impact Every entry point that re

thehackerwire@mastodon.social at 2026-10-02T18:31:09.000Z ##

🟠 CVE-2026-104861 - High (7.5)

probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg.js and lib/parse_stream/svg.js use the searching regular expression /]*>/, which repeatedly scans to the end of input when attacker-cont...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19484
(7.5 HIGH)

EPSS: 0.61%

updated 2026-10-02T23:17:29

1 posts

### Impact Versions of `@fastify/busboy` from 3.1.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The vendored streaming multipart search stores its default skip distance in a `Uint8Array(256)`. A multipart boundary of exactly 252 bytes makes the search needle 256 bytes, and the table entry wraps to zero, so a crafted request keeps the search in a CPU-bound loop and stalls the Node.js

sayzard@mastodon.sayzard.org at 2026-10-03T10:40:09.000Z ##

Fastify/busboy DoS via oversized multipart boundary

@fastify/busboy 3.1.0 이상 3.2.1 미만에서 비정상적으로 긴 multipart boundary를 처리할 때 CPU 바운드 루프가 발생해 Node.js 이벤트 루프를 멈출 수 있는 DoS 취약점(CVE-2026-19484)이 공개됐다. 공격자는 인증 없이 작은 요청 하나로 이를 유발할 수 있으며, @fastify/busboy를 직접 사용하거나 @fastify/multipart를 통해 multipart/form-data를 파싱하는 서비스가 영향을 받는다. 원인은 252바이트 boundary가 내부 검색 needle을 256바이트로 만들며 U...

github.com/fastify/busboy/secu

##

CVE-2026-82039
(8.8 HIGH)

EPSS: 0.34%

updated 2026-10-02T21:32:19

2 posts

UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are inserted unsanitized into a native PostgreSQL query via String.format(). Attackers can exploit the GET /api/utm-asset-groups/searchGroupsByFilter endpoint to execute arb

thehackerwire@mastodon.social at 2026-10-03T18:15:23.000Z ##

🟠 CVE-2026-82039 - High (8.8)

UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are inserted unsanit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:15:23.000Z ##

🟠 CVE-2026-82039 - High (8.8)

UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are inserted unsanit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82044
(7.7 HIGH)

EPSS: 0.26%

updated 2026-10-02T21:32:19

2 posts

UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated url parameter to the PdfService.downloadPdf() method exposed via GET /api/generate-pdf-report. Attackers can leverage this to force the web-pdf microservice to fetch internal backend endpoints, the OpenS

thehackerwire@mastodon.social at 2026-10-03T18:00:57.000Z ##

🟠 CVE-2026-82044 - High (7.7)

UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated url parameter to the PdfService.downloadPdf() meth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:00:57.000Z ##

🟠 CVE-2026-82044 - High (7.7)

UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated url parameter to the PdfService.downloadPdf() meth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82042
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-10-02T21:32:19

2 posts

UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint without path restriction, constant-time comparison, rate limiting, or audit logging. Attackers who obtai

thehackerwire@mastodon.social at 2026-10-03T18:00:47.000Z ##

🔴 CVE-2026-82042 - Critical (9.8)

UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:00:47.000Z ##

🔴 CVE-2026-82042 - Critical (9.8)

UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82041
(9.9 CRITICAL)

EPSS: 0.44%

updated 2026-10-02T21:32:19

2 posts

UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before forwarding supplied commands. Any authenticated user, regardless of role, can send arbitrary operating-system commands over gRPC to any connected agent, res

thehackerwire@mastodon.social at 2026-10-03T18:00:37.000Z ##

🔴 CVE-2026-82041 - Critical (9.9)

UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before for...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:00:37.000Z ##

🔴 CVE-2026-82041 - Critical (9.9)

UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before for...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104988
(8.1 HIGH)

EPSS: 0.20%

updated 2026-10-02T21:32:18

2 posts

A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem's agent certificate, which causes downstream authorization checks to treat the request as agent-privileged. An authenticated EST use

thehackerwire@mastodon.social at 2026-10-03T18:15:42.000Z ##

🟠 CVE-2026-104988 - High (8.1)

A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retai...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:15:42.000Z ##

🟠 CVE-2026-104988 - High (8.1)

A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retai...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39718
(8.8 HIGH)

EPSS: 0.14%

updated 2026-10-02T21:32:18

2 posts

Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross Site Request Forgery.This issue affects Wallstreet: from n/a through 2.8.6.

thehackerwire@mastodon.social at 2026-10-03T18:15:32.000Z ##

🟠 CVE-2026-39718 - High (8.8)

Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross Site Request Forgery.This issue affects Wallstreet: from n/a through 2.8.6.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:15:32.000Z ##

🟠 CVE-2026-39718 - High (8.8)

Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross Site Request Forgery.This issue affects Wallstreet: from n/a through 2.8.6.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96940
(8.8 HIGH)

EPSS: 0.50%

updated 2026-10-02T21:32:13

7 posts

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-10-03T18:30:40.000Z ##

🟠 CVE-2026-96940 - High (8.8)

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

tugatech@masto.pt at 2026-10-03T14:51:34.000Z ##

Microsoft lança atualizações urgentes para corrigir falha crítica no Exchange Server, que permite a elevação de privilégios e acesso não autorizado a caixas de correio de outros utilizadores. A falha, CVE-2026-96940, afeta várias versões do Exchange Server local. 🚨

🔗 tugatech.com.pt/t92180-microso

#exchange #falha #lan #microsoft #server 

##

hugovalters@mastodon.social at 2026-10-03T11:11:02.000Z ##

CVE-2026-96940 - Privilege Escalation in Microsoft Exchange Server from weak authorization. CVSS 8.8. Currently unpatched. Restrict network access now. #CVE #Microsoft #infosec

valtersit.com/cve/CVE-2026-969

##

thehackerwire@mastodon.social at 2026-10-03T18:30:40.000Z ##

🟠 CVE-2026-96940 - High (8.8)

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

tugatech@masto.pt at 2026-10-03T14:51:34.000Z ##

Microsoft lança atualizações urgentes para corrigir falha crítica no Exchange Server, que permite a elevação de privilégios e acesso não autorizado a caixas de correio de outros utilizadores. A falha, CVE-2026-96940, afeta várias versões do Exchange Server local. 🚨

🔗 tugatech.com.pt/t92180-microso

#exchange #falha #lan #microsoft #server 

##

DailyCyberSecurity@infosec.exchange at 2026-10-03T01:00:29.000Z ##

Microsoft's September 2026 V2 Exchange Server security updates add CVE-2026-96940 for Exchange SE, 2019 and 2016. Install them now.

#Microsoft #ExchangeServer #ExchangeSE #CVE202696940 #SecurityUpdate #PatchManagement #ESU

securityonline.info/exchange-s

##

mderooij@mastodon.social at 2026-10-02T23:53:52.000Z ##

PSA: Exchange Server V2 Security Updates for September were published, additionally addressing CVE-2026-96940 eightwone.com/2026/10/03/v2-se #MSExchange

##

CVE-2026-75937(CVSS UNKNOWN)

EPSS: 0.53%

updated 2026-10-02T21:32:07

3 posts

A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device.

offseq at 2026-10-03T04:30:23.136Z ##

Digi IX Family devices hit by CRITICAL OS command injection (CVE-2026-75937, CVSS 9.4). Unauthenticated remote attackers can execute root commands via HTTP POST. Disable web admin interface to reduce risk. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-03T04:30:23.000Z ##

Digi IX Family devices hit by CRITICAL OS command injection (CVE-2026-75937, CVSS 9.4). Unauthenticated remote attackers can execute root commands via HTTP POST. Disable web admin interface to reduce risk. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoT #Infosec

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T22:00:22.000Z ##

Digi DAL OS vulnerability CVE-2026-75937 (CVSS 9.4) lets attackers run root commands on Digi Accelerated Linux devices. Patch now.

#Digi #DALOS #CVE202675937 #CommandInjection #IoTSecurity #OTSecurity #Vulnerability

securityonline.info/digi-dal-o

##

CVE-2026-103628
(9.6 CRITICAL)

EPSS: 0.33%

updated 2026-10-02T21:32:03

3 posts

Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

ssvc at 2026-10-03T03:17:16.884Z ##

Google Chrome published an empty blog post as a security advisory on Thursday afternoon. They filled it out in the past day, but don't make it easy to grasp the severity of their bugs.

For example, "Critical CVE-2026-103628: Out of bounds write in WebGL." is actually a CVSSv3.1: 9.6 critical because it allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. You'd have to chase down those details yourself on cve.org or elsewhere.

chromereleases.googleblog.com/

##

ssvc@infosec.exchange at 2026-10-03T03:17:16.000Z ##

Google Chrome published an empty blog post as a security advisory on Thursday afternoon. They filled it out in the past day, but don't make it easy to grasp the severity of their bugs.

For example, "Critical CVE-2026-103628: Out of bounds write in WebGL." is actually a CVSSv3.1: 9.6 critical because it allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. You'd have to chase down those details yourself on cve.org or elsewhere.

chromereleases.googleblog.com/

#google #chrome #CVE

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T21:49:21.000Z ##

Chrome security update: Chrome 154 fixes 11 flaws, including critical WebGL sandbox escape CVE-2026-103628. Update your browser now.

#Chrome #GoogleChrome #Chrome154 #CVE2026103628 #CVE2026103631 #BrowserSecurity #Vulnerability

securityonline.info/chrome-sec

##

CVE-2026-51916
(7.5 HIGH)

EPSS: 0.43%

updated 2026-10-02T21:16:55.427000

2 posts

TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowledge object without requiring authentication in the route and without verifying organization ownership of the supplied knowledge_id.

thehackerwire@mastodon.social at 2026-10-03T19:00:38.000Z ##

🟠 CVE-2026-51916 - High (7.5)

TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowle...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T19:00:38.000Z ##

🟠 CVE-2026-51916 - High (7.5)

TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowle...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48005
(7.5 HIGH)

EPSS: 0.61%

updated 2026-10-02T20:54:53.960000

1 posts

Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck . Users are recommended to upgrade to version 2.4.69, which fixes this issue.

thehackerwire@mastodon.social at 2026-10-02T19:15:41.000Z ##

🟠 CVE-2026-48005 - High (7.5)

Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorizati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56153
(7.5 HIGH)

EPSS: 0.50%

updated 2026-10-02T20:53:53.630000

1 posts

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

thehackerwire@mastodon.social at 2026-10-02T19:00:48.000Z ##

🟠 CVE-2026-56153 - High (7.5)

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite.

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67989
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-02T20:17:03.933000

2 posts

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x

thehackerwire@mastodon.social at 2026-10-03T18:45:42.000Z ##

🟠 CVE-2026-67989 - High (7.5)

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:45:42.000Z ##

🟠 CVE-2026-67989 - High (7.5)

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-51907
(8.1 HIGH)

EPSS: 0.39%

updated 2026-10-02T20:17:02.713000

2 posts

In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter.

thehackerwire@mastodon.social at 2026-10-03T18:45:51.000Z ##

🟠 CVE-2026-51907 - High (8.1)

In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:45:51.000Z ##

🟠 CVE-2026-51907 - High (8.1)

In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18397
(0 None)

EPSS: 0.34%

updated 2026-10-02T20:17:02.060000

2 posts

This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component. The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.

cyberworldops at 2026-10-03T06:40:00.641Z ##

Thales SConnect is affected by CVE-2026-18397 (CVSS 4.0 9.4), which allows a malicious website to reach the native host and achieve remote code execution. This matters because it fronts hardware-token authentication for SWIFT, Qatar Tawtheeq and Sweden Skatteverket.

cyberworldops.eu/en/sconnect-f

##

cyberworldops@infosec.exchange at 2026-10-03T06:40:00.000Z ##

Thales SConnect is affected by CVE-2026-18397 (CVSS 4.0 9.4), which allows a malicious website to reach the native host and achieve remote code execution. This matters because it fronts hardware-token authentication for SWIFT, Qatar Tawtheeq and Sweden Skatteverket. #Thales #SConnect #CriticalVulnerability

cyberworldops.eu/en/sconnect-f

##

CVE-2026-103764
(9.8 CRITICAL)

EPSS: 0.64%

updated 2026-10-02T19:16:39.627000

1 posts

Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory

thehackerwire@mastodon.social at 2026-10-02T00:46:23.000Z ##

🔴 CVE-2026-103764 - Critical (9.8)

Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a cr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103098
(7.5 HIGH)

EPSS: 0.16%

updated 2026-10-02T19:16:39.350000

1 posts

Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor network traffic could intercept the request and obtain the key

thehackerwire@mastodon.social at 2026-10-02T02:47:22.000Z ##

🟠 CVE-2026-103098 - High (7.5)

Transmission of a sensitive key in the URL
over an unencrypted HTTP connection.  The
request is sent over HTTP rather than HTTPS, meaning the key is transmitted in
plaintext across the network. An attacker with the ability to monitor network
traf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90970
(9.9 CRITICAL)

EPSS: 0.94%

updated 2026-10-02T18:44:11.270000

11 posts

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command

1 repos

https://github.com/techupdate24/gitlab-ai-gateway-cve-2026-90970

guru@thecybersecguru.com at 2026-10-03T13:31:19.000Z ##

Critical GitLab AI Gateway vulnerability (CVE-2026-90970) enables remote code execution on self-hosted servers

GitLab CVE-2026-90970 is a critical 9.9 AI Gateway sandbox escape affecting self-hosted deployments. Check affected versions and patches

thecybersecguru.com/exploits/g

##

beyondmachines1 at 2026-10-03T10:01:13.520Z ##

GitLab Issues Emergency Patches for Actively Exploited Critical AI Gateway and Path Traversal Flaws

GitLab released emergency security updates to fix a critical remote code execution vulnerability in its AI Gateway (CVE-2026-90970) and a maximum-severity path traversal flaw (CVE-2026-85706) that allows unauthenticated attackers to steal sensitive server data.

**If you run self-hosted GitLab (Community or Enterprise Edition) or a self-hosted GitLab AI Gateway for Duo, patch now: upgrade the AI Gateway to 19.2.4, 19.3.2 or 19.4.1 and apply GitLab's latest security release. One of the flaws is already actively exploited. After patching, check your logs for strange flow configurations or file access, and rotate all AI provider API keys and other secrets on those servers.**

beyondmachines.net/event_detai

##

cyberworldops at 2026-10-03T03:00:01.262Z ##

GitLab patched CVE-2026-90970, a sandbox escape in self-hosted AI Gateway allowing authenticated Duo Agent users to execute arbitrary commands via crafted flow configs. Self-hosted deployments should patch and audit for abuse, as gateway compromise can expose AI workflows and downstream systems.

cyberworldops.eu/en/gitlab-fix

##

guru@thecybersecguru.com at 2026-10-03T13:31:19.000Z ##

Critical GitLab AI Gateway vulnerability (CVE-2026-90970) enables remote code execution on self-hosted servers

GitLab CVE-2026-90970 is a critical 9.9 AI Gateway sandbox escape affecting self-hosted deployments. Check affected versions and patches

thecybersecguru.com/exploits/g

##

beyondmachines1@infosec.exchange at 2026-10-03T10:01:13.000Z ##

GitLab Issues Emergency Patches for Actively Exploited Critical AI Gateway and Path Traversal Flaws

GitLab released emergency security updates to fix a critical remote code execution vulnerability in its AI Gateway (CVE-2026-90970) and a maximum-severity path traversal flaw (CVE-2026-85706) that allows unauthenticated attackers to steal sensitive server data.

**If you run self-hosted GitLab (Community or Enterprise Edition) or a self-hosted GitLab AI Gateway for Duo, patch now: upgrade the AI Gateway to 19.2.4, 19.3.2 or 19.4.1 and apply GitLab's latest security release. One of the flaws is already actively exploited. After patching, check your logs for strange flow configurations or file access, and rotate all AI provider API keys and other secrets on those servers.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-10-03T03:00:01.000Z ##

GitLab patched CVE-2026-90970, a sandbox escape in self-hosted AI Gateway allowing authenticated Duo Agent users to execute arbitrary commands via crafted flow configs. Self-hosted deployments should patch and audit for abuse, as gateway compromise can expose AI workflows and downstream systems. #GitLab #AiSecurity #SandboxEscape

cyberworldops.eu/en/gitlab-fix

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T21:42:58.000Z ##

GitLab AI Gateway vulnerability CVE-2026-90970 (CVSS 9.9) lets Duo Agent Platform users run commands. Upgrade self-hosted gateways now.

#GitLab #AIGateway #GitLabDuo #CVE202690970 #RCE #DevSecOps #Vulnerability

securityonline.info/gitlab-ai-

##

news@fawkes.rocks at 2026-10-02T17:18:15.000Z ##

GitLab AI Gateway flaw CVE-2026-90970 enables RCE

fawkes.rocks/2026/10/02/gitlab

##

cR0w@infosec.exchange at 2026-10-02T16:23:33.000Z ##

Go hack more AI shit.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.9 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.

##

nyanbinary@infosec.exchange at 2026-10-02T15:43:07.000Z ##

Go hack more AI shit.
Go hack more Gitlab.

But most importantly, hack more Gitlab AI shit: db.gcve.eu/vuln/cve-2026-90970

##

thehackerwire@mastodon.social at 2026-10-02T15:18:39.000Z ##

🔴 CVE-2026-90970 - Critical (9.9)

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authentic...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103922
(9.3 CRITICAL)

EPSS: 0.21%

updated 2026-10-02T18:44:11.270000

1 posts

Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host and scheme but not its path, allowing a victim who activates an untrusted link to navigate a frame to /_capacitor_http_interceptor_. The native proxy can fetch an attacker-selected URL and return the re

1 repos

https://github.com/techupdate24/capacitor-flaw-cve-2026-103922

CVE-2026-102489
(9.8 CRITICAL)

EPSS: 1.40%

updated 2026-10-02T18:32:21

6 posts

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

security_crawler_carl@infosec.exchange at 2026-10-02T22:35:39.000Z ##

The Dutch Institute for Vulnerability Disclosure, whose entire ledger is OTHER people's vulnerabilities, has recorded a significant loss in column B.

Agentic AI in the threat actor slot: filed under Equipment Used Against Us. Session tokens: stolen. Root access: granted to strangers. Irony reserves: critically depleted.

Patch Zammad immediately to address CVE-2026-102489 and the second zero-day, and review DIVD's published findings for full remediation guidance. (2/3)

##

security_crawler_carl@infosec.exchange at 2026-10-02T22:35:38.000Z ##

🏆 New Achievement! Auditing the Auditors, Zero Days Found, Zero Days Remaining!

Conducting inventory review of DIVD assets. Status: two zero-day vulnerabilities in Zammad (CVE-2026-102489, CVSS 9.4, and a companion flaw) — unpatched, unaccounted for, now exploited. An AI-powered automated attack chained both flaws to hijack sessions, execute remote code, and escalate privileges to root. In seconds. (1/3)

##

AAKL@infosec.exchange at 2026-10-02T17:11:31.000Z ##

CISA has updated the catalogue. GMBH is looking like Swiss cheese these days.

- CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability cve.org/CVERecord?id=CVE-2026-

Yesterday's funny headline:

CISA Launches Cybersecurity Awareness Month: Securing the Next 250 cisa.gov/news-events/news/cisa #CISA #infosec #vulnerability

##

cisakevtracker@mastodon.social at 2026-10-02T17:01:17.000Z ##

CVE ID: CVE-2026-102489
Vendor: Zammad GmbH
Product: Zammad
Date Added: 2026-10-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-10-02T17:00:11.000Z ##

🚨 [CISA-2026:1002] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-102489 (secdb.nttzen.cloud/cve/detail/)
- Name: Zammad GmbH Zammad Session Fixation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Zammad GmbH
- Product: Zammad
- Notes: zammad.com/en/product/releases/ ; community.zammad.org/t/take-ca ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-102490 (secdb.nttzen.cloud/cve/detail/)
- Name: Zammad GmbH Zammad Improper Privilege Management Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Zammad GmbH
- Product: Zammad
- Notes: zammad.com/en/product/releases/ ; community.zammad.org/t/take-ca ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261002 #cisa20261002 #cve_2026_102489 #cve_2026_102490 #cve2026102489 #cve2026102490

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T03:54:26.000Z ##

Attackers exploited Zammad zero-day flaws CVE-2026-102489 and CVE-2026-102490 to gain root at DIVD. Upgrade to Zammad 7 or go offline.

#Zammad #ZeroDay #CVE2026102489 #CVE2026102490 #DIVD #AIAgent #ExploitedInTheWild

securityonline.info/zammad-zer

##

CVE-2026-102667
(8.3 HIGH)

EPSS: 0.19%

updated 2026-10-02T18:32:21

1 posts

Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream' module, or access app-internal storage. If the installed app has been granted permissions previously, the attacker can access the entire file system, camera, mi

thehackerwire@mastodon.social at 2026-10-02T17:45:33.000Z ##

🟠 CVE-2026-102667 - High (8.3)

Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream' module, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102490
(9.8 CRITICAL)

EPSS: 0.63%

updated 2026-10-02T18:32:21

4 posts

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

AAKL@infosec.exchange at 2026-10-02T17:11:31.000Z ##

CISA has updated the catalogue. GMBH is looking like Swiss cheese these days.

- CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability cve.org/CVERecord?id=CVE-2026-

Yesterday's funny headline:

CISA Launches Cybersecurity Awareness Month: Securing the Next 250 cisa.gov/news-events/news/cisa #CISA #infosec #vulnerability

##

cisakevtracker@mastodon.social at 2026-10-02T17:01:02.000Z ##

CVE ID: CVE-2026-102490
Vendor: Zammad GmbH
Product: Zammad
Date Added: 2026-10-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-10-02T17:00:11.000Z ##

🚨 [CISA-2026:1002] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-102489 (secdb.nttzen.cloud/cve/detail/)
- Name: Zammad GmbH Zammad Session Fixation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Zammad GmbH
- Product: Zammad
- Notes: zammad.com/en/product/releases/ ; community.zammad.org/t/take-ca ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-102490 (secdb.nttzen.cloud/cve/detail/)
- Name: Zammad GmbH Zammad Improper Privilege Management Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Zammad GmbH
- Product: Zammad
- Notes: zammad.com/en/product/releases/ ; community.zammad.org/t/take-ca ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261002 #cisa20261002 #cve_2026_102489 #cve_2026_102490 #cve2026102489 #cve2026102490

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T03:54:26.000Z ##

Attackers exploited Zammad zero-day flaws CVE-2026-102489 and CVE-2026-102490 to gain root at DIVD. Upgrade to Zammad 7 or go offline.

#Zammad #ZeroDay #CVE2026102489 #CVE2026102490 #DIVD #AIAgent #ExploitedInTheWild

securityonline.info/zammad-zer

##

CVE-2026-102795
(9.3 CRITICAL)

EPSS: 0.28%

updated 2026-10-02T18:31:37

1 posts

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. This CVE supersedes CVE-2026-41920, whose record listed the affected 9.x versions as 9.0.0 through 9.1.14 and the fixed version as 9.1.15. All 9.

thehackerwire@mastodon.social at 2026-10-02T18:31:18.000Z ##

🔴 CVE-2026-102795 - Critical (9.3)

Improper Access Control vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the is...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103648
(9.1 CRITICAL)

EPSS: 0.41%

updated 2026-10-02T18:31:36

1 posts

Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory.

1 repos

https://github.com/EterNullSec/CVE-2026-103648

thehackerwire@mastodon.social at 2026-10-02T16:19:06.000Z ##

🔴 CVE-2026-103648 - Critical (9.1)

Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101104
(7.7 HIGH)

EPSS: 0.27%

updated 2026-10-02T18:31:25

1 posts

The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions.

thehackerwire@mastodon.social at 2026-10-02T16:20:11.000Z ##

🟠 CVE-2026-101104 - High (7.7)

The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96658
(9.9 CRITICAL)

EPSS: 0.70%

updated 2026-10-02T18:31:18

1 posts

A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling them to run arbitrary commands on the hosting server.

CVE-2026-91135
(0 None)

EPSS: 0.46%

updated 2026-10-02T18:17:06.963000

1 posts

Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport. When an application enables the ZLIB transform for the frames it sends, THeaderTransport::transform() copies the compressed frame into the write buffer without making sure it fits. Data that does not compress, such as content a remote peer supplied, grows under compression, so the copy writes past the end of the hea

offseq@infosec.exchange at 2026-10-02T12:00:25.000Z ##

CVE-2026-91135: Apache Thrift (<0.25.0) has a CRITICAL heap-based buffer overflow in C++ THeaderTransport when ZLIB is enabled. Exploitable for RCE/DoS. Upgrade to 0.25.0+ now. CVSS 9.2. radar.offseq.com/threat/cve-20 #OffSeq #ApacheThrift #InfoSec #CVE202691135

##

CVE-2026-80298
(8.8 HIGH)

EPSS: 0.29%

updated 2026-10-02T18:17:05.370000

1 posts

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows SQL Injection. This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported.

thehackerwire@mastodon.social at 2026-10-02T17:20:08.000Z ##

🟠 CVE-2026-80298 - High (8.8)

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows SQL Injection.

This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104410
(7.5 HIGH)

EPSS: 0.38%

updated 2026-10-02T18:17:00.790000

1 posts

SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled database rows via the /api/export/preview endpoint. Attackers can request an export preview of a public document embedding a database view to obtain protected rows' primary-key text and cell values.

thehackerwire@mastodon.social at 2026-10-02T17:04:21.000Z ##

🟠 CVE-2026-104410 - High (7.5)

SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled database rows via the /api/export/preview endpoint. Attackers can request an export preview of a publi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104423
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-02T17:59:09.430000

1 posts

Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared unprioritized Halo2 verification queue with zero-fee transactions carrying zero-filled Orchard and Ironwood proofs, causing nodes to fall behind the chain tip.

thehackerwire@mastodon.social at 2026-10-02T16:48:27.000Z ##

🟠 CVE-2026-104423 - High (7.5)

Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared unprio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104430
(7.5 HIGH)

EPSS: 0.41%

updated 2026-10-02T17:59:09.430000

1 posts

Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold multisig redeem scripts so that a block zcashd accepts exceeds Zebra's inflated MAX_BL

thehackerwire@mastodon.social at 2026-10-02T16:34:37.000Z ##

🟠 CVE-2026-104430 - High (7.5)

Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104845
(7.5 HIGH)

EPSS: 0.43%

updated 2026-10-02T16:16:47.200000

1 posts

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.6.3, deserializeTypedArray in fromJSON and fromCrossJSON trusts a deserialized source value as an ArrayBuffer and does not bound the serialized element count. An attacker can provide a small untrusted JSON object with a large length value, causing the array-like TypedArray cons

thehackerwire@mastodon.social at 2026-10-02T16:18:48.000Z ##

🟠 CVE-2026-104845 - High (7.5)

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.6.3, deserializeTypedArray in fromJSON and fromCrossJSON trusts a deserialized source value as an ArrayBuffer and does not bo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104467
(8.1 HIGH)

EPSS: 0.37%

updated 2026-10-02T16:16:46.357000

1 posts

YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. Attackers can send requests to endpoints like api/ci/update_config and api/archives to overwrite configuration and list, download, or delete backup archives.

thehackerwire@mastodon.social at 2026-10-02T15:32:50.000Z ##

🟠 CVE-2026-104467 - High (8.1)

YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. Attackers can send requests to endpoints like ap...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104026
(7.8 HIGH)

EPSS: 0.13%

updated 2026-10-02T15:31:37

1 posts

In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl log/blame/annotate.

thehackerwire@mastodon.social at 2026-10-02T15:17:23.000Z ##

🟠 CVE-2026-104026 - High (7.8)

In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19652
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-02T15:31:32

1 posts

The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowe

thehackerwire@mastodon.social at 2026-10-02T15:17:40.000Z ##

🔴 CVE-2026-19652 - Critical (9.8)

The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104611
(9.1 CRITICAL)

EPSS: 0.49%

updated 2026-10-02T15:31:31

1 posts

A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fast_setting_internet_set of the component POST Request Handler. Performing a manipulation of the argument netWanType results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.

thehackerwire@mastodon.social at 2026-10-02T15:18:56.000Z ##

🔴 CVE-2026-104611 - Critical (9.1)

A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fast_setting_internet_set of the component POST Request Handler. Performing a manipulation of the argument netWanType results in stack-based...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104456
(7.6 HIGH)

EPSS: 0.30%

updated 2026-10-02T15:17:07.693000

1 posts

YesWiki before 4.6.7 contains a second-order SQL injection vulnerability in AclService::updateRequestWithACL, where a stored username is concatenated unescaped into a read-ACL LIKE clause. Attackers can self-register an account name containing a double-quote payload, then load non-admin ACL-filtered listings to read database contents and bypass read ACLs.

thehackerwire@mastodon.social at 2026-10-02T15:47:40.000Z ##

🟠 CVE-2026-104456 - High (7.6)

YesWiki before 4.6.7 contains a second-order SQL injection vulnerability in AclService::updateRequestWithACL, where a stored username is concatenated unescaped into a read-ACL LIKE clause. Attackers can self-register an account name containing a d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104610
(10.0 CRITICAL)

EPSS: 0.64%

updated 2026-10-02T14:17:09.267000

2 posts

A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

thehackerwire@mastodon.social at 2026-10-02T15:18:48.000Z ##

🔴 CVE-2026-104610 - Critical (10)

A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads to stac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w@infosec.exchange at 2026-10-02T13:18:54.000Z ##

cve.org/CVERecord?id=CVE-2026-

cc: @da_667

##

CVE-2026-104286
(9.8 CRITICAL)

EPSS: 2.20%

updated 2026-10-02T12:35:33.990000

14 posts

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

2 repos

https://github.com/ShadowForge-Cyber/CVE-2026-104286-POC

https://github.com/techupdate24/fortimail-zero-day-cve-2026-104286

netsecio@mastodon.social at 2026-10-03T19:05:11.000Z ##

📰 Critical Fortinet FortiMail Zero-Day Exploited for RCE

Fortinet warns of critical zero-day (CVE-2026-104286) in FortiMail, actively exploited for RCE. CVSS 9.8. CISA added to KEV. Patches are pending, but urgent workarounds are available. #Fortinet #ZeroDay #CVE2026104286 #CyberSecurity

🔗 cyber.netsecops.io/articles/cr

##

netsecio@mastodon.social at 2026-10-03T19:05:11.000Z ##

📰 Critical Fortinet FortiMail Zero-Day Exploited for RCE

Fortinet warns of critical zero-day (CVE-2026-104286) in FortiMail, actively exploited for RCE. CVSS 9.8. CISA added to KEV. Patches are pending, but urgent workarounds are available. #Fortinet #ZeroDay #CVE2026104286 #CyberSecurity

🔗 cyber.netsecops.io/articles/cr

##

censys@infosec.exchange at 2026-10-02T21:42:21.000Z ##

🚨 Fortinet reports active exploitation of CVE-2026-104286, a critical path traversal vulnerability affecting FortiMail.

Censys observes roughly 2,800 Internet-exposed FortiMail hosts after excluding honeypots. This is an exposure count, not a confirmed-vulnerable count.

No fixed builds have been released as of October 2. Censys ARC covers affected versions, Fortinet’s current workarounds, indicators, and remediation guidance: censys.com/advisory/cve-2026-1

#CensysARC #Fortinet #FortiMail #Cybersecurity #Vulnerability

##

jbz@indieweb.social at 2026-10-02T19:00:11.000Z ##

🚨 Fortinet sounds the alarm over actively exploited FortiMail zero-day

「 The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security platform 」

theregister.com/security/2026/

#fortinet #fortimail #cybersecurity

##

thehackerwire@mastodon.social at 2026-10-02T17:30:29.000Z ##

🔴 CVE-2026-104286 - Critical (9.8)

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an una...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

AAKL@infosec.exchange at 2026-10-02T16:11:11.000Z ##

Fortinet has a couple of advisories today, one pertaining to a critical vulnerability.

CRITICAL: CVE-2026-104286 - Improper Pathname Restriction Allows Unauthenticated Arbitrary File Write in Fortinet FortiMail app.opencve.io/cve/CVE-2026-10

More:

The Register: Fortinet sounds the alarm over actively exploited FortiMail zero-day theregister.com/security/2026/ @theregister @carlypage #infosec #Fortinet #zeroday #vulnerability

##

guru@thecybersecguru.com at 2026-10-02T13:16:06.000Z ##

Critical Fortinet FortiMail Zero-Day (CVE-2026-104286) Actively Exploited: Unauthenticated File Write Flaw Exposes Email Security Gateways Worldwide

CVE-2026-104286 is an actively exploited FortiMail zero-day allowing unauthenticated arbitrary file writes. See affected versions, IOCs and fixes

thecybersecguru.com/exploits/f

##

thecybermind@infosec.exchange at 2026-10-02T10:35:56.000Z ##

Critical Threat Advisory: CVE-2026-104286 Fortinet FortiMail

Immediate CISA KEV threat advisory for CVE-2026-104286 affecting Fortinet FortiMail. Includes behavioral workflow analysis, BOD 26-04 patch compliance guidance, and multi-vendor SOC detection queries....

thecybermind.co/t645

##

security_crawler_carl@infosec.exchange at 2026-10-02T07:20:56.000Z ##

Just stroll up and write arbitrary files anywhere on the system, courtesy of a path traversal flaw and a NULL-byte handling error working together like a buddy-cop duo nobody asked for.

Fortinet FortiMail administrators: patch CVE-2026-104286 immediately — authentication-free arbitrary file write is not a feature you want enabled by strangers.

Reward: You've received a complimentary Unpatched Appliance Trophy, proudly displayed in your attacker's loot screen. (2/3)

##

security_crawler_carl@infosec.exchange at 2026-10-02T07:20:56.000Z ##

🏆 New Achievement! Write Anything, Pay Nothing!

This achievement is brought to you by Deferred Patch Tuesdays — "Why fix it today when tomorrow is also a day?" Thanks to their generous sponsorship, attackers are actively exploiting CVE-2026-104286, a CVSS 9.8 zero-day in Fortinet FortiMail. No credentials required! (1/3)

##

decio@infosec.exchange at 2026-10-02T07:16:42.000Z ##

⚠️ CVE-2026-104286 (vulnerability.circl.lu/vuln/CV) — FortiMail, vulnérabilité critique et déjà exploitée comme 0-day.

S’il fallait encore des exemples sur le rythme auquel il faut désormais suivre les correctifs des équipements exposés : après Cisco, Citrix, Zimbra… voilà à nouveau FortiMail. 🙃

Sans authentification, un attaquant peut écrire des fichiers et exécuter du code via l’interface de gestion.

"Bien évidemment", il s’agit d’une bonne vieille traversée de chemin .../.../... :dumpster_fire_gif:

➡️ En attendant les versions corrigées : désactiver IBE ou restreindre strictement l’accès à l’interface d’administration.

🩹
👇 fortiguard.fortinet.com/psirt/

#Fortinet #FortiMail #CVE

##

teezeh@ieji.de at 2026-10-02T06:17:21.000Z ##

“Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices.”

bleepingcomputer.com/news/secu

##

security_crawler_carl@infosec.exchange at 2026-10-02T06:04:00.000Z ##

🏆 New Achievement! Unauthenticated File Write of Passage!

The System would like to direct your attention, counsel, to Exhibit A: CVE-2026-104286, a CVSS 9.8 zero-day in Fortinet's FortiMail, actively exploited in the wild. My client, the attacker, did not break in — they merely wrote files to a system that, per the public record, required no authentication to do so. Your Honor, the management interface was exposed. The vulnerability was critical. (1/2)

##

cyberworldops@infosec.exchange at 2026-10-02T04:40:00.000Z ##

Fortinet FortiMail management interface is impacted by CVE-2026-104286 (CVSS 9.8), exploited in the wild as zero-day for unauthenticated system file writes and command execution. Internet-exposed instances face immediate full-compromise risk; isolate management and patch urgently. #Fortinet #ZeroDay #ThreatIntel

cyberworldops.eu/en/fortimail-

##

CVE-2026-91828
(7.5 HIGH)

EPSS: 0.31%

updated 2026-10-02T12:32:16

1 posts

The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust the site's PHP worker pool and make the entire site unavailable.

thehackerwire@mastodon.social at 2026-10-02T17:20:19.000Z ##

🟠 CVE-2026-91828 - High (7.5)

The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104448
(8.1 HIGH)

EPSS: 0.16%

updated 2026-10-02T12:31:26

1 posts

YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the ajaxdeletepage handler, which permanently deletes a page on any GET request carrying a jsonp_callback parameter without checking a CSRF token. Attackers can lure a logged-in administrator or page owner to a crafted link to delete arbitrary pages along with their ACLs, links, triples, comments and referrers.

thehackerwire@mastodon.social at 2026-10-02T16:20:31.000Z ##

🟠 CVE-2026-104448 - High (8.1)

YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the ajaxdeletepage handler, which permanently deletes a page on any GET request carrying a jsonp_callback parameter without checking a CSRF token. Attackers can lure a log...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104462
(7.5 HIGH)

EPSS: 0.31%

updated 2026-10-02T12:31:26

1 posts

YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute into a raw SQL IN clause. Attackers with page-write access (unauthenticated on default installs) can embed a nuagetag tag ending in a backslash to break quote parity and inject a UNION subquery, exfiltrating password hashes and arbitrary table data.

thehackerwire@mastodon.social at 2026-10-02T15:47:22.000Z ##

🟠 CVE-2026-104462 - High (7.5)

YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute into a raw SQL IN clause. Attackers with page-write access (unauthenticated on default installs) can embed a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104472
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-02T12:31:26

1 posts

YesWiki before 4.6.7 contains a missing authorization vulnerability in the attachment download handler that allows unauthenticated attackers to bypass page read ACLs. Attackers can request the download handler with a known page tag and file parameter to retrieve confidential attachments from read-restricted pages.

thehackerwire@mastodon.social at 2026-10-02T15:32:40.000Z ##

🟠 CVE-2026-104472 - High (7.5)

YesWiki before 4.6.7 contains a missing authorization vulnerability in the attachment download handler that allows unauthenticated attackers to bypass page read ACLs. Attackers can request the download handler with a known page tag and file parame...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104464
(8.6 HIGH)

EPSS: 0.29%

updated 2026-10-02T12:31:25

1 posts

YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET requests by supplying an unvalidated actor URL to the Bazar abonnements sync action. Attackers can target internal hosts or cloud metadata endpoints and chain attacker-controlled outbox first/next links, with fetched responses stored as readable Bazar entries.

thehackerwire@mastodon.social at 2026-10-02T15:47:31.000Z ##

🟠 CVE-2026-104464 - High (8.6)

YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET requests by supplying an unvalidated actor URL to the Bazar abonnements sync action. Attackers can target inter...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104460
(7.5 HIGH)

EPSS: 0.39%

updated 2026-10-02T12:31:25

1 posts

YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}} action because Bazar list option ids are concatenated into SQL REGEXP/LIKE clauses in actions/newtextsearch.php without escaping. Anonymous attackers can plant a malicious option id in an anonymously editable Bazar list and use search requests as a boolean oracle to read arbitrary database data, including ad

thehackerwire@mastodon.social at 2026-10-02T15:32:59.000Z ##

🟠 CVE-2026-104460 - High (7.5)

YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}} action because Bazar list option ids are concatenated into SQL REGEXP/LIKE clauses in actions/newtextsearch.php without escaping. Anonymous attackers can pl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104416
(7.5 HIGH)

EPSS: 0.31%

updated 2026-10-02T12:31:20

1 posts

Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges.

thehackerwire@mastodon.social at 2026-10-02T17:04:11.000Z ##

🟠 CVE-2026-104416 - High (7.5)

Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for hig...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104422
(7.5 HIGH)

EPSS: 0.18%

updated 2026-10-02T12:31:20

1 posts

The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too far behind the tip before consensus validation, without penalizing the supplying peer. Because V5 transaction IDs exclude the scriptSig, a malicious peer can repeatedly serve a canonical block whose coinbase claims height 1 while keeping the re

thehackerwire@mastodon.social at 2026-10-02T16:48:18.000Z ##

🟠 CVE-2026-104422 - High (7.5)

The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too far behind the tip before consensus validation, without penalizing the supplying peer. Beca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104445
(8.2 HIGH)

EPSS: 0.40%

updated 2026-10-02T12:31:20

1 posts

YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. Unauthenticated attackers with any ActivityPub keypair can send signed Delete or Update activities referencing a mirrored entry's sourceUrl to delete or overwrite other actors' federated entries.

thehackerwire@mastodon.social at 2026-10-02T16:34:28.000Z ##

🟠 CVE-2026-104445 - High (8.2)

YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. Unauthenticated attackers with any ActivityPub keypair can send signed Delet...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104443
(8.1 HIGH)

EPSS: 0.36%

updated 2026-10-02T12:31:20

1 posts

YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic triples regardless of ownership. Attackers can send an empty filter to the triples delete endpoint to remove the admins-group membership triple, emptying the admin group and causing a site-wide authorization lockout.

thehackerwire@mastodon.social at 2026-10-02T16:34:19.000Z ##

🟠 CVE-2026-104443 - High (8.1)

YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic triples regardless of ownership. Attackers can send an empty filter to the triples delete...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104414
(8.1 HIGH)

EPSS: 0.28%

updated 2026-10-02T12:31:19

1 posts

Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post content via oEmbed photo responses. Attackers can host malicious oEmbed photo responses so that embedding their URL stores scripts that run in the Ghost editor, published site, and newsletter emails, compromising staff admin sessions.

thehackerwire@mastodon.social at 2026-10-02T17:04:02.000Z ##

🟠 CVE-2026-104414 - High (8.1)

Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post content via oEmbed photo responses. Attackers can host malicious oEmbed photo responses so that embeddi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104431
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-02T12:31:19

1 posts

Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sigop P2SH transactions that reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresp

thehackerwire@mastodon.social at 2026-10-02T16:48:07.000Z ##

🟠 CVE-2026-104431 - High (7.5)

Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sig...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86325(CVSS UNKNOWN)

EPSS: 0.34%

updated 2026-10-02T12:31:19

2 posts

A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the `account_name` parameter when processing account management requests. An attacker authenticated as a read-only user to the web management interface could supply a specially crafted account name that exceeds the size of the inter

DailyCyberSecurity@infosec.exchange at 2026-10-02T14:43:13.000Z ##

Moxa MGate vulnerabilities CVE-2026-86325 (CVSS 9.4) and CVE-2026-86326 hit MGate protocol gateway firmware. See affected versions and fixes.

#Moxa #MGate #CVE202686325 #CVE202686326 #ICSSecurity #OTSecurity #Vulnerability

securityonline.info/moxa-mgate

##

cR0w@infosec.exchange at 2026-10-02T13:28:30.000Z ##

moxa.com/en/support/product-su

CVE-2026-86325

A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the account_name parameter when processing account management requests. An attacker authenticated as a read-only user to the web management interface could supply a specially crafted account name that exceeds the size of the internal stack buffer, resulting in corruption of program execution flow. Successful exploitation could allow an attacker to read sensitive information from device memory, including credentials, modify arbitrary memory contents, and disrupt device availability.

CVE-2026-86326

An improper verification of cryptographic signature vulnerability exists in protocol gateways because the device does not properly verify the cryptographic authenticity of firmware images before installation. An attacker with high privileges and access to the firmware update interface could provide a specially crafted or modified firmware image, causing it to be installed on the device. Successful exploitation could allow the attacker to execute unauthorized code, compromise the integrity and availability of the device, and persist malicious modifications across subsequent firmware updates.

Given the high severity of these issues, users should apply the solutions immediately to reduce security risks.

##

CVE-2026-94541
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-10-02T12:31:19

2 posts

The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate password-reset URLs for arbitrary users, including administrators, mirrored into the p

1 repos

https://github.com/anoxhunterdump-ctrl/CVE-2026-94541-WPMobileApp-AuthBypass

thehackerwire@mastodon.social at 2026-10-02T10:46:11.000Z ##

🔴 CVE-2026-94541 - Critical (9.8)

The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-02T10:30:23.000Z ##

CVE-2026-94541: CRITICAL auth bypass in WPMobile.App plugin (<=11.82) exposes password-reset URLs via mail-to-push, risking admin account takeover. Disable mail-to-push until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202694541 #Infosec

##

CVE-2026-86326(CVSS UNKNOWN)

EPSS: 0.19%

updated 2026-10-02T12:31:13

2 posts

An improper verification of cryptographic signature vulnerability exists in protocol gateways because the device does not properly verify the cryptographic authenticity of firmware images before installation. An attacker with high privileges and access to the firmware update interface could provide a specially crafted or modified firmware image, causing it to be installed on the device. Successful

DailyCyberSecurity@infosec.exchange at 2026-10-02T14:43:13.000Z ##

Moxa MGate vulnerabilities CVE-2026-86325 (CVSS 9.4) and CVE-2026-86326 hit MGate protocol gateway firmware. See affected versions and fixes.

#Moxa #MGate #CVE202686325 #CVE202686326 #ICSSecurity #OTSecurity #Vulnerability

securityonline.info/moxa-mgate

##

cR0w@infosec.exchange at 2026-10-02T13:28:30.000Z ##

moxa.com/en/support/product-su

CVE-2026-86325

A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the account_name parameter when processing account management requests. An attacker authenticated as a read-only user to the web management interface could supply a specially crafted account name that exceeds the size of the internal stack buffer, resulting in corruption of program execution flow. Successful exploitation could allow an attacker to read sensitive information from device memory, including credentials, modify arbitrary memory contents, and disrupt device availability.

CVE-2026-86326

An improper verification of cryptographic signature vulnerability exists in protocol gateways because the device does not properly verify the cryptographic authenticity of firmware images before installation. An attacker with high privileges and access to the firmware update interface could provide a specially crafted or modified firmware image, causing it to be installed on the device. Successful exploitation could allow the attacker to execute unauthorized code, compromise the integrity and availability of the device, and persist malicious modifications across subsequent firmware updates.

Given the high severity of these issues, users should apply the solutions immediately to reduce security risks.

##

CVE-2026-104457
(8.6 HIGH)

EPSS: 0.28%

updated 2026-10-02T12:17:17.767000

1 posts

YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filtertags action, which wraps unescaped filterN attribute tokens in quotes and concatenates them into a raw tags.value IN (...) clause. Unauthenticated attackers on default installs can save filtertags markup in a page with a trailing-backslash token that breaks quote parity under MySQL backslash escaping. This lets them in

thehackerwire@mastodon.social at 2026-10-02T16:20:21.000Z ##

🟠 CVE-2026-104457 - High (8.6)

YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filtertags action, which wraps unescaped filterN attribute tokens in quotes and concatenates them into a raw tags.value IN (...) clause. Unauthenticated attackers on default...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97637
(9.8 CRITICAL)

EPSS: 0.64%

updated 2026-10-02T09:31:31

2 posts

The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent plugin caches controller dispatch results in transients keyed solely by URI and query string, ignoring HTTP method and POST body; this causes the `generate_auth_cookie()

thehackerwire@mastodon.social at 2026-10-02T09:31:15.000Z ##

🔴 CVE-2026-97637 - Critical (9.8)

The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent plugin caches co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-02T09:00:26.000Z ##

CVE-2026-97637: CRITICAL auth bypass in parorrey JSON API Auth plugin for WordPress (≤3.1.2). Attackers can steal admin session cookies via cached API responses. Disable affected plugins or controllers now. Details: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Security #CVE2026_97637

##

CVE-2026-93698
(9.9 CRITICAL)

EPSS: 0.46%

updated 2026-10-02T09:31:25

2 posts

Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.

cR0w@infosec.exchange at 2026-10-02T13:31:31.000Z ##

cPanel vulns are fun, right? IDK what Adminbin is but I'm sure some of you do. Have fun.

support.cpanel.net/hc/en-us/ar

sev:CRIT 9.9 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.

nvd.nist.gov/vuln/detail/cve-2

##

thehackerwire@mastodon.social at 2026-10-02T09:46:20.000Z ##

🔴 CVE-2026-93698 - Critical (9.9)

Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93697
(9.0 None)

EPSS: 0.40%

updated 2026-10-02T09:31:25

1 posts

There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.

thehackerwire@mastodon.social at 2026-10-02T09:46:41.000Z ##

🔴 CVE-2026-93697 - Critical (9)

There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93029
(9.0 None)

EPSS: 0.40%

updated 2026-10-02T09:31:25

2 posts

There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.

thehackerwire@mastodon.social at 2026-10-02T09:46:31.000Z ##

🔴 CVE-2026-93029 - Critical (9)

There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-02T07:30:24.000Z ##

CVE-2026-93029: CRITICAL stored XSS in Webpros cPanel (WHM Manage SSL Hosts). Attackers with low privilege can execute malicious code. Restrict access & monitor systems. Patch status: unconfirmed. radar.offseq.com/threat/cve-20 #OffSeq #cPanel #XSS #Vuln

##

CVE-2026-92820
(8.1 HIGH)

EPSS: 0.52%

updated 2026-10-02T06:31:04

1 posts

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used without validation to attach a file to the form's notification email (arbitrary file

thehackerwire@mastodon.social at 2026-10-02T07:02:47.000Z ##

🟠 CVE-2026-92820 - High (8.1)

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form su...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92174
(7.5 HIGH)

EPSS: 0.56%

updated 2026-10-02T06:31:03

1 posts

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to by

thehackerwire@mastodon.social at 2026-10-02T07:02:37.000Z ##

🟠 CVE-2026-92174 - High (7.5)

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter parameter. This makes it possible for authenticated attackers, with contributor-level a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14378
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-10-02T06:30:58

2 posts

The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by

3 repos

https://github.com/murrez/CVE-2026-14378

https://github.com/anoxhunterdump-ctrl/CVE-2026-14378-DevKit-Pro-Auth-Bypass

https://github.com/MRdark-ops/CVE-2026-19660-exploit

thehackerwire@mastodon.social at 2026-10-02T10:17:53.000Z ##

🔴 CVE-2026-14378 - Critical (9.8)

The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-02T04:30:23.000Z ##

CVE-2026-14378 | CRITICAL vuln in dplugins DevKit Pro (<=2.3.0): Improper authentication lets unauth attackers gain admin access via crafted cookies & nonce. Immediate action: disable or restrict plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #Infosec

##

CVE-2026-15896
(9.1 CRITICAL)

EPSS: 0.88%

updated 2026-10-02T06:30:55

2 posts

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'file_upload_auth' setting defaults to empty, meaning no au

thehackerwire@mastodon.social at 2026-10-02T10:17:35.000Z ##

🔴 CVE-2026-15896 - Critical (9.1)

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-02T06:00:24.000Z ##

CVE-2026-15896 (CRITICAL): Path traversal in WebRehab Super Forms – Drag & Drop Form Builder <=6.3.316 lets unauthenticated users read arbitrary files via vulnerable uploads. Enable 'file_upload_auth' for some mitigation. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #AppSec

##

CVE-2026-103096
(7.5 HIGH)

EPSS: 0.15%

updated 2026-10-02T03:31:14

1 posts

API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.

thehackerwire@mastodon.social at 2026-10-02T02:47:32.000Z ##

🟠 CVE-2026-103096 - High (7.5)

API
key is hardcoded and retrievable from the application package. Since Android
applications can be reverse engineered, embedding sensitive API credentials
directly in the client application may allow unauthorized users to extract and
misuse the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104480(CVSS UNKNOWN)

EPSS: 0.40%

updated 2026-10-02T03:31:10

1 posts

Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media sess

offseq@infosec.exchange at 2026-10-02T03:00:24.000Z ##

Discord libdave CRITICAL vuln (CVE-2026-104480, CVSS 9.4): Affected versions 1.1.0 – <1.2.0 let attackers inject unauthorized members into encrypted sessions. Patch status unconfirmed — check radar.offseq.com/threat/cve-20 #OffSeq #Discord #CVE2026104480 #infosec

##

CVE-2026-103097
(7.5 HIGH)

EPSS: 0.15%

updated 2026-10-02T03:31:10

1 posts

An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.

thehackerwire@mastodon.social at 2026-10-02T02:47:13.000Z ##

🟠 CVE-2026-103097 - High (7.5)

An API key is
hardcoded and retrievable from the application package. Since Android
applications can be reverse engineered, embedding sensitive API credentials
directly in the client application may allow unauthorized users to extract and
misuse t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86345
(9.0 None)

EPSS: 0.38%

updated 2026-10-02T00:31:40

1 posts

A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a cl

offseq@infosec.exchange at 2026-10-02T01:30:27.000Z ##

Red Hat Directory Server 11: CVE-2026-86345 (CRITICAL, CVSS 9) allows on-path attackers to inject LDAP messages post-StartTLS, risking auth bypass. Restrict access, check Red Hat advisory radar.offseq.com/threat/cve-20 #OffSeq #CVE202686345 #RedHat #LDAP #infosec

##

CVE-2026-103765
(9.4 CRITICAL)

EPSS: 0.50%

updated 2026-10-02T00:31:39

1 posts

Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners, or exhaust server

thehackerwire@mastodon.social at 2026-10-02T00:46:33.000Z ##

🔴 CVE-2026-103765 - Critical (9.4)

Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57941
(9.8 CRITICAL)

EPSS: 0.44%

updated 2026-10-01T21:33:58

1 posts

Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

thehackerwire@mastodon.social at 2026-10-02T19:00:39.000Z ##

🔴 CVE-2026-57941 - Critical (9.8)

Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63686
(7.5 HIGH)

EPSS: 0.33%

updated 2026-10-01T21:33:58

1 posts

A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

thehackerwire@mastodon.social at 2026-10-02T18:32:17.000Z ##

🟠 CVE-2026-63686 - High (7.5)

A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partia...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63292
(7.5 HIGH)

EPSS: 0.58%

updated 2026-10-01T21:33:58

2 posts

Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default. Users ar

1 repos

https://github.com/0xBlackash/CVE-2026-63292

thehackerwire@mastodon.social at 2026-10-02T18:32:08.000Z ##

🟠 CVE-2026-63292 - High (7.5)

Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Ho...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T02:38:30.000Z ##

Apache HTTP Server 2.4.69 fixes 20 flaws, including CVE-2026-63292, a mod_vhost_alias stack overflow that may enable code execution.

#Apache #ApacheHTTPServer #httpd #CVE202663292 #CVE202657941 #CVE202659685 #PatchNow

securityonline.info/apache-htt

##

CVE-2026-59685
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-01T21:33:58

1 posts

Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

thehackerwire@mastodon.social at 2026-10-02T18:01:04.000Z ##

🟠 CVE-2026-59685 - High (7.5)

Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded.

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73636
(8.1 HIGH)

EPSS: 0.37%

updated 2026-10-01T21:33:58

1 posts

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to versi

thehackerwire@mastodon.social at 2026-10-02T18:00:55.000Z ##

🟠 CVE-2026-73636 - High (8.1)

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63718
(7.5 HIGH)

EPSS: 0.32%

updated 2026-10-01T21:33:58

1 posts

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68.

thehackerwire@mastodon.social at 2026-10-02T17:45:54.000Z ##

🟠 CVE-2026-63718 - High (7.5)

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding.

This issue affects Apache HTTP Serv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56449
(7.5 HIGH)

EPSS: 0.42%

updated 2026-10-01T21:33:57

1 posts

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

thehackerwire@mastodon.social at 2026-10-02T19:15:32.000Z ##

🟠 CVE-2026-56449 - High (7.5)

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies.

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56154
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-10-01T21:33:57

1 posts

Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

thehackerwire@mastodon.social at 2026-10-02T19:00:57.000Z ##

🔴 CVE-2026-56154 - Critical (9.8)

Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103484
(8.8 HIGH)

EPSS: 0.42%

updated 2026-10-01T21:33:02

1 posts

IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.

thehackerwire@mastodon.social at 2026-10-02T17:30:39.000Z ##

🟠 CVE-2026-103484 - High (8.8)

IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93546
(8.8 HIGH)

EPSS: 0.34%

updated 2026-10-01T21:17:26.023000

1 posts

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.

thehackerwire@mastodon.social at 2026-10-02T17:45:44.000Z ##

🟠 CVE-2026-93546 - High (8.8)

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XM...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63045
(7.5 HIGH)

EPSS: 0.33%

updated 2026-10-01T21:17:23.433000

1 posts

Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

thehackerwire@mastodon.social at 2026-10-02T18:31:59.000Z ##

🟠 CVE-2026-63045 - High (7.5)

Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data conn...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59797
(9.8 CRITICAL)

EPSS: 0.39%

updated 2026-10-01T21:17:23.263000

1 posts

Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

thehackerwire@mastodon.social at 2026-10-02T18:01:13.000Z ##

🔴 CVE-2026-59797 - Critical (9.8)

Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102628
(9.3 CRITICAL)

EPSS: 0.28%

updated 2026-10-01T20:37:52.400000

1 posts

The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, causing Laravel to expose the entire server environment, including all .env configuration variables, in plaintext. Fixed on or before 2026-09-02.

thehackerwire@mastodon.social at 2026-10-02T17:30:48.000Z ##

🔴 CVE-2026-102628 - Critical (9.3)

The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102369
(0 None)

EPSS: 0.24%

updated 2026-10-01T20:36:38.330000

1 posts

Tapo C120 v1 and C200 V5 do not adequately protect login challenge data or sanitize attacker-controlled input processed by the MacTool handler. An unauthenticated attacker on the same local network can replay login challenge data to obtain an administrative session, enable a privileged service that becomes accessible after a reboot, and submit crafted input to execute arbitrary commands within the

CVE-2026-96760
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-10-01T15:31:30

1 posts

Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.

1 repos

https://github.com/uziii2208/CVE-2026-96760

DailyCyberSecurity@infosec.exchange at 2026-10-02T13:21:28.000Z ##

Explore Authlib CVE-2026-96760, an authentication bypass vulnerability involving empty JSON Web Signature arrays in Python. Learn how to secure your apps.

#Authlib #Cybersecurity #CVE202696760 #AuthenticationBypass #PythonSecurity

meterpreter.org/authlib-cve-20

##

CVE-2026-79901
(9.9 CRITICAL)

EPSS: 0.27%

updated 2026-10-01T15:30:49

2 posts

In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.

offseq at 2026-10-03T12:00:25.649Z ##

Fortra BoKS faces 3 CRITICAL vulns (CVE-2026-79901, - 79898, - 12627): auth bypass, command injection as root, and remote memory corruption. No active exploits seen. Patch now to secure privileged environments! radar.offseq.com/threat/fortra

##

offseq@infosec.exchange at 2026-10-03T12:00:25.000Z ##

Fortra BoKS faces 3 CRITICAL vulns (CVE-2026-79901, - 79898, - 12627): auth bypass, command injection as root, and remote memory corruption. No active exploits seen. Patch now to secure privileged environments! radar.offseq.com/threat/fortra #OffSeq #Fortra #BoKS #Vulnerability

##

CVE-2024-58388
(7.5 HIGH)

EPSS: 0.81%

updated 2026-10-01T15:30:42

1 posts

Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, inclu

CVE-2026-71972
(5.9 MEDIUM)

EPSS: 0.22%

updated 2026-09-30T00:32:46

1 posts

U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the video_display_rle8_bitmap function in drivers/video/video_bmp.c. Attackers can supply a crafted RLE8-compressed BMP image to corrupt memory adjacent to the framebuffer and crash the bootloader.

_r_netsec@infosec.exchange at 2026-10-02T17:03:21.000Z ##

Bypassing Secure Boot via Unbounded RLE8 Splash Images in U-Boot (CVE-2026-71972) pop.byteray.co.uk/advisory/BYT

##

CVE-2026-86950
(8.8 HIGH)

EPSS: 1.24%

updated 2026-09-29T15:32:17

2 posts

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions o

3 repos

https://github.com/DeAurity/CVE-2026-86950-POC

https://github.com/decalage2/detect_CVE-2026-86950

https://github.com/msuiche/hotcell

decalage@mastodon.social at 2026-10-02T21:12:38.000Z ##

How to detect the Apple iOS/macOS recent 0-day CVE-2026-86950 in PDF files?
I developed a python tool for that, based on the PoC published two days ago:
decalage.info/CVE-2026-86950/

##

hackmag@infosec.exchange at 2026-10-02T16:07:55.000Z ##

⚪️ Apple fixes CoreGraphics zero-day vulnerability exploited in attacks

🗨️ Apple developers have released updates for iOS, iPadOS, and macOS that fix the zero-day vulnerability CVE-2026-86950. The CoreGraphics bug may already have been exploited in “extremely sophisticated” targeted attacks against specific iPhone users. The issue was reportedly discovered by researchers…

🔗 hackmag.com/news/cve-2026-8695

#news

##

CVE-2026-102437
(7.8 HIGH)

EPSS: 0.99%

updated 2026-09-29T15:31:45

2 posts

OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer.

beyondmachines1 at 2026-10-03T11:01:13.145Z ##

DeepSeek-Reasonix Patches ConfigPoisoning Command Injection Flaw

DeepSeek-Reasonix fixed a vulnerability (CVE-2026-102437) that allowed attackers to execute arbitrary commands via poisoned git configuration files when a user viewed file diffs. The flaw is caused by an inadequate neutralization of git filter mechanisms in the tool's internal git wrapper.

**If you use DeepSeek-Reasonix Studio or the Reasonix npm package, update ASAP to Studio 2.21.0 or npm 1.39.3. Until you've updated, don't open or view changes in code projects you got from archives, shared folders, or other people; only work with projects you downloaded yourself from a trusted source.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-10-03T11:01:13.000Z ##

DeepSeek-Reasonix Patches ConfigPoisoning Command Injection Flaw

DeepSeek-Reasonix fixed a vulnerability (CVE-2026-102437) that allowed attackers to execute arbitrary commands via poisoned git configuration files when a user viewed file diffs. The flaw is caused by an inadequate neutralization of git filter mechanisms in the tool's internal git wrapper.

**If you use DeepSeek-Reasonix Studio or the Reasonix npm package, update ASAP to Studio 2.21.0 or npm 1.39.3. Until you've updated, don't open or view changes in code projects you got from archives, shared folders, or other people; only work with projects you downloaded yourself from a trusted source.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-88771
(9.8 CRITICAL)

EPSS: 1.06%

updated 2026-09-29T04:18:01.603000

6 posts

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

11 repos

https://github.com/SwiftSecur/CVE-2026-88771-HuntScript

https://github.com/technion/netscaler_scanner

https://github.com/techupdate24/citrix-netscaler-cve-2026-88771-rce

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

https://github.com/securekomodo/citrixInspector

https://github.com/orjanj/netscaler_threat_hunt_helper

https://github.com/emilstahl/pitscaler

https://github.com/craigsblackie/cve-2026-88771-netscaler

https://github.com/bkchaudhari/NetScaler-CTX697096-Assessment-Script

https://github.com/EXEcution-py/CVE-2026-88771-POC

netsecio@mastodon.social at 2026-10-03T19:05:03.000Z ##

📰 Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack

Critical Alert: Two Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are under active global attack. Flaws allow unauthenticated RCE. CISA KEV listed. Patch and hunt for compromise now! #Citrix #NetScaler #CyberSecurity #CVE

🔗 cyber.netsecops.io/articles/ci

##

ssvc at 2026-10-03T15:15:53.539Z ##

Looking for additional Citrix NetScaler IOC? Sygnia has novel and credible indicators from CVE-2026-88771 exploitation (published 9/30):

sygnia.co/threat-reports-and-a

##

ssvc@infosec.exchange at 2026-10-03T15:15:53.000Z ##

Looking for additional Citrix NetScaler IOC? Sygnia has novel and credible indicators from CVE-2026-88771 exploitation (published 9/30):

sygnia.co/threat-reports-and-a

#threatintel #citrix #netscaler

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T21:32:40.000Z ##

Citrix flags a NetScaler SAML authentication issue as patched NetScaler appliances reboot after CVE-2026-88771 attacks. Check your config.

#Citrix #NetScaler #SAML #CVE202688771 #CVE202688772 #ZeroDay #Vulnerability

securityonline.info/netscaler-

##

DarkWebInformer@infosec.exchange at 2026-10-02T16:51:46.000Z ##

🚨 Reports of NetScaler Incidents After Latest Patch Raise Concerns Over Continued Exploitation

Multiple Citrix administrators are reporting suspicious activity affecting NetScaler appliances even after updating to version 14.1-73.37.

The reports surfaced on Reddit, where one administrator said multiple customers experienced incidents that caused externally accessible NetScaler appliances to repeatedly reboot.

Other administrators reported similar behavior on newly rebuilt appliances, including systems where Enhanced ISN Generation had already been enabled. Several affected organizations said they collected forensic data and opened cases with Citrix.

It is currently unclear whether the activity represents successful exploitation of a new or existing vulnerability, residual compromise, vulnerability scanning, or an issue with the updated firmware.

The reports come days after Citrix disclosed active exploitation of CVE-2026-88771 and CVE-2026-88772, two critical vulnerabilities affecting NetScaler ADC and NetScaler Gateway.

The latest post-patch activity has not yet been confirmed by Citrix as exploitation.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

Source: reddit.com/r/Citrix/comments/1

##

threatnoir@infosec.exchange at 2026-10-02T09:05:50.000Z ##

⚠️ CRITICAL: Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

NetScaler ADC and Gateway instances are being actively exploited via CVE-2026-88771 and CVE-2026-88772 to achieve root access and deploy web shells. Government and finance organizations have been targeted since early September, with attackers moving laterally post-compromise. State-sponsored actors…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

CVE-2026-93355
(8.1 HIGH)

EPSS: 0.27%

updated 2026-09-28T21:31:26

2 posts

LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting an email-based fallback lookup in the JWT authentication flow without verifying the email_verified claim. Attackers can present a token with an unverified email address matching a victim's account to inherit the vi

hasamba at 2026-10-03T17:46:42.993Z ##

----------------

🎯 AI
===================

Unpatched account takeover in LiteLLM (CVE-2026-93355) allows authentication as any user, including proxy_admin, via a single JWT request with an unverified email claim.

Technical Details
• Vulnerability: JWT authentication fallback bypass (CWE-290).
• CVSS: 8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
• Affected Versions: LiteLLM up to 1.100.1 (PyPI).
• Mechanism: LiteLLM proxies authenticate JWTs by matching user_id or sso_user_id. When this fails, it falls back to the email claim. It trusts this claim without checking email_verified. If a match is found, it returns the matched account as the authenticated caller and overwrites the victim's sso_user_id with the attacker's token subject in a background write.

Impact
The attacker does not need the victim's credentials or any interaction. A validly signed JWT from a trusted IdP carrying the victim's email is sufficient. Many IdP and self-service signup flows populate the email claim before or without verifying it. Since LiteLLM is an AI gateway holding upstream API keys and spend history, compromising a proxy_admin account grants access to all organizational LLM credentials.

Status
OX Research reported the issue on May 18, 2026. After a follow-up on July 27 with no response, the issue remains unpatched in the latest release (1.100.1).

🔹 LiteLLM

🔗 Source: ox.security/blog/litellm-an-or

##

hasamba@infosec.exchange at 2026-10-03T17:46:42.000Z ##

----------------

🎯 AI
===================

Unpatched account takeover in LiteLLM (CVE-2026-93355) allows authentication as any user, including proxy_admin, via a single JWT request with an unverified email claim.

Technical Details
• Vulnerability: JWT authentication fallback bypass (CWE-290).
• CVSS: 8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
• Affected Versions: LiteLLM up to 1.100.1 (PyPI).
• Mechanism: LiteLLM proxies authenticate JWTs by matching user_id or sso_user_id. When this fails, it falls back to the email claim. It trusts this claim without checking email_verified. If a match is found, it returns the matched account as the authenticated caller and overwrites the victim's sso_user_id with the attacker's token subject in a background write.

Impact
The attacker does not need the victim's credentials or any interaction. A validly signed JWT from a trusted IdP carrying the victim's email is sufficient. Many IdP and self-service signup flows populate the email claim before or without verifying it. Since LiteLLM is an AI gateway holding upstream API keys and spend history, compromising a proxy_admin account grants access to all organizational LLM credentials.

Status
OX Research reported the issue on May 18, 2026. After a follow-up on July 27 with no response, the issue remains unpatched in the latest release (1.100.1).

🔹 LiteLLM #CVE_2026_93355 #AppSec #JWT #AI

🔗 Source: ox.security/blog/litellm-an-or

##

CVE-2026-88772
(8.1 HIGH)

EPSS: 1.30%

updated 2026-09-28T12:26:47.670000

3 posts

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

8 repos

https://github.com/technion/netscaler_scanner

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

https://github.com/securekomodo/citrixInspector

https://github.com/orjanj/netscaler_threat_hunt_helper

https://github.com/emilstahl/pitscaler

https://github.com/FollowerSeize/CVE-2026-88772-POC

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772

https://github.com/murrez/CVE-2026-88772

netsecio@mastodon.social at 2026-10-03T19:05:03.000Z ##

📰 Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack

Critical Alert: Two Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are under active global attack. Flaws allow unauthenticated RCE. CISA KEV listed. Patch and hunt for compromise now! #Citrix #NetScaler #CyberSecurity #CVE

🔗 cyber.netsecops.io/articles/ci

##

DarkWebInformer@infosec.exchange at 2026-10-02T16:51:46.000Z ##

🚨 Reports of NetScaler Incidents After Latest Patch Raise Concerns Over Continued Exploitation

Multiple Citrix administrators are reporting suspicious activity affecting NetScaler appliances even after updating to version 14.1-73.37.

The reports surfaced on Reddit, where one administrator said multiple customers experienced incidents that caused externally accessible NetScaler appliances to repeatedly reboot.

Other administrators reported similar behavior on newly rebuilt appliances, including systems where Enhanced ISN Generation had already been enabled. Several affected organizations said they collected forensic data and opened cases with Citrix.

It is currently unclear whether the activity represents successful exploitation of a new or existing vulnerability, residual compromise, vulnerability scanning, or an issue with the updated firmware.

The reports come days after Citrix disclosed active exploitation of CVE-2026-88771 and CVE-2026-88772, two critical vulnerabilities affecting NetScaler ADC and NetScaler Gateway.

The latest post-patch activity has not yet been confirmed by Citrix as exploitation.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

Source: reddit.com/r/Citrix/comments/1

##

threatnoir@infosec.exchange at 2026-10-02T09:05:50.000Z ##

⚠️ CRITICAL: Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

NetScaler ADC and Gateway instances are being actively exploited via CVE-2026-88771 and CVE-2026-88772 to achieve root access and deploy web shells. Government and finance organizations have been targeted since early September, with attackers moving laterally post-compromise. State-sponsored actors…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

CVE-2026-85706
(10.0 CRITICAL)

EPSS: 92.96%

updated 2026-09-24T12:52:28.143000

2 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Nuclei template

14 repos

https://github.com/EQSTLab/CVE-2026-85706

https://github.com/FlowerWitch/CVE-2026-85706_docker_exp

https://github.com/ynsmroztas/GitLabSniper

https://github.com/solivaquaant/CVE-2026-85706

https://github.com/wuyou6956-glitch/cve-2026-85706

https://github.com/plur1bu5/gitread

https://github.com/gagaltotal/CVE-2026-85706-gitlab-poc

https://github.com/gabrielunknown/CVE-2026-85706

https://github.com/guneykabel/cve-2026-85706

https://github.com/mhtsec/CVE-2026-85706

https://github.com/jithinkrishnanrs/gitlab-cve-2026-85706-ioc

https://github.com/tc4dy/CVE-2026-85706-PoC-Toolkit

https://github.com/0xlyvio/cve-2026-85706-poc-exploit-gitlab

https://github.com/unh00k3d/cve-2026-85706

beyondmachines1 at 2026-10-03T10:01:13.520Z ##

GitLab Issues Emergency Patches for Actively Exploited Critical AI Gateway and Path Traversal Flaws

GitLab released emergency security updates to fix a critical remote code execution vulnerability in its AI Gateway (CVE-2026-90970) and a maximum-severity path traversal flaw (CVE-2026-85706) that allows unauthenticated attackers to steal sensitive server data.

**If you run self-hosted GitLab (Community or Enterprise Edition) or a self-hosted GitLab AI Gateway for Duo, patch now: upgrade the AI Gateway to 19.2.4, 19.3.2 or 19.4.1 and apply GitLab's latest security release. One of the flaws is already actively exploited. After patching, check your logs for strange flow configurations or file access, and rotate all AI provider API keys and other secrets on those servers.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-10-03T10:01:13.000Z ##

GitLab Issues Emergency Patches for Actively Exploited Critical AI Gateway and Path Traversal Flaws

GitLab released emergency security updates to fix a critical remote code execution vulnerability in its AI Gateway (CVE-2026-90970) and a maximum-severity path traversal flaw (CVE-2026-85706) that allows unauthenticated attackers to steal sensitive server data.

**If you run self-hosted GitLab (Community or Enterprise Edition) or a self-hosted GitLab AI Gateway for Duo, patch now: upgrade the AI Gateway to 19.2.4, 19.3.2 or 19.4.1 and apply GitLab's latest security release. One of the flaws is already actively exploited. After patching, check your logs for strange flow configurations or file access, and rotate all AI provider API keys and other secrets on those servers.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-75791
(8.6 HIGH)

EPSS: 1.71%

updated 2026-09-22T19:32:25.730000

1 posts

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.

hugovalters@mastodon.social at 2026-10-03T15:40:20.000Z ##

CVE-2026-75791 ManageEngine ADSelfService Plus auth bypass in REST API. CVSS 8.6, unpatched. Restrict API access and update to build 7001 now. valtersit.com/cve/CVE-2026-757 #CVE #infosec #ManageEngine

##

CVE-2026-63278
(0 None)

EPSS: 0.15%

updated 2026-09-22T19:09:32.273000

1 posts

URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-12426 did not recognise every way of naming the package content provider, so a URL that named it differently still reached the expansion. In fixed versions the package

hugovalters@mastodon.social at 2026-10-03T18:50:23.000Z ##

CVE-2026-63278: info disclosure via crafted URLs that expand env or INI values, leaking secrets to remote servers. Incomplete fix for CVE-2024-12426. CVSS 7.4, no patch yet. Restrict document links and monitor outbound valtersit.com/cve/CVE-2026-632 #CVE #infosec #cybersecurity

##

CVE-2026-18345
(4.3 MEDIUM)

EPSS: 0.20%

updated 2026-09-22T19:04:55.677000

1 posts

The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Connect::complete() function in versions up to, and including, 2.9.18. The function is registered on the admin_init hook (which fires for every authenticated user that reaches /wp-admin/, including Subscribers) and performs no current_user_can() or nonce verification

hugovalters@mastodon.social at 2026-10-03T03:50:22.000Z ##

CVE-2026-18345: WP User Manager plugin, unauthorized data modification via missing capability check. CVSS 4.3. Unpatched. Patch now if available. valtersit.com/cve/CVE-2026-183 #CVE #WordPress #infosec

##

CVE-2026-87080
(9.1 CRITICAL)

EPSS: 0.63%

updated 2026-09-22T18:34:36

1 posts

Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads one digit at a time with four-argument substr and tests the result with defined to detect the end of the input. substr on an exhausted string returns the empty string rather than undef, so decoding continues past the end.

hugovalters@mastodon.social at 2026-10-03T07:50:01.000Z ##

CVE-2026-87080 Net::IDN::Punycode CVSS 9.1: truncated label decodes to unencoded chars, enabling spoofing. Patch under review - update Perl module now. valtersit.com/cve/CVE-2026-870 #CVE #infosec #Perl

##

CVE-2026-95619
(7.7 HIGH)

EPSS: 0.36%

updated 2026-09-22T18:34:31

1 posts

A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the C++ `new` operator. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.

hugovalters@mastodon.social at 2026-10-03T12:30:03.000Z ##

CVE-2026-95619 GNU libstdc++ integer overflow in the C++ new operator allows undersized allocations, leading to memory corruption. CVSS 7.7. Patch available, update now. valtersit.com/cve/CVE-2026-956 #CVE #infosec #GNU

##

CVE-2026-87078
(9.1 CRITICAL)

EPSS: 0.65%

updated 2026-09-22T18:33:29

2 posts

Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode. The XS backend allocates the scalar it returns before it validates the input, sizing the buffer at twice the input length. The scalar is released only on the success path, so each of the three croaks that reject a label leaves the scalar and its buffer allocated. Nothing

hugovalters@mastodon.social at 2026-10-03T09:20:02.000Z ##

CVE-2026-87078 Net::IDN::Punycode for Perl leaks its output buffer on every rejected label in decode_punycode. Unbounded labels mean memory exhaustion and DoS. CVSS 9.1. Patch still under review, so pin versions or limit input now. valtersit.com/cve/CVE-2026-870 #CVE #infosec #Perl

##

hugovalters@mastodon.social at 2026-10-03T09:20:02.000Z ##

CVE-2026-87078 Net::IDN::Punycode for Perl leaks its output buffer on every rejected label in decode_punycode. Unbounded labels mean memory exhaustion and DoS. CVSS 9.1. Patch still under review, so pin versions or limit input now. valtersit.com/cve/CVE-2026-870 #CVE #infosec #Perl

##

CVE-2026-95271
(7.3 HIGH)

EPSS: 0.65%

updated 2026-09-22T15:32:34

1 posts

A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_authentication of the file changedetectionio/flask_app.py of the component Authentication Hook. Such manipulation leads to improper authentication. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early

hugovalters@mastodon.social at 2026-10-03T14:10:14.000Z ##

CVE-2026-95271: improper auth in changedetection.io up to 0.60.7 lets remote attackers bypass login. CVSS 7.3, exploit public, no patch yet. Isolate or restrict access now. valtersit.com/cve/CVE-2026-952 #CVE #infosec

##

CVE-2026-92882
(0 None)

EPSS: 0.35%

updated 2026-09-22T14:17:17.950000

1 posts

Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read stored SNMP community strings, SNMPv3 auth and privacy pass phrases and IPMI passwords in clear text from GET responses, although the setup GUI never displays these val

hugovalters@mastodon.social at 2026-10-03T11:00:24.000Z ##

CVE-2026-92882 Checkmk: credentialed API user can read SNMP community strings, SNMPv3 passphrases and IPMI passwords in cleartext from REST GET responses. CVSS 6.5. No patch yet. Restrict API access and monitor now. valtersit.com/cve/CVE-2026-928 #CVE #infosec #Checkmk

##

CVE-2026-90990
(0 None)

EPSS: 0.42%

updated 2026-09-22T14:17:17.830000

1 posts

Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional Livestatus query headers, bypassing object visibility restrictions in count queries to infer information about hosts and services outside their contact groups and occupying web server and Livestatus workers for an attacker-controll

hugovalters@mastodon.social at 2026-10-03T03:10:00.000Z ##

CVE-2026-90990 Checkmk <2.5.0p14 CVSS 7.1. Authenticated users can inject Livestatus headers to bypass visibility and leak host/service info. No patch yet. Restrict access and monitor. valtersit.com/cve/CVE-2026-909 #CVE #infosec #Checkmk

##

CVE-2026-63276(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-09-22T12:30:32

1 posts

LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The converted operators were written into a fixed size buffer with no check that they still fit, so a glyph emitting many operators wrote past the end of the buffer. In fixed versions the r

hugovalters@mastodon.social at 2026-10-03T17:10:04.000Z ##

CVE-2026-63276 LibreOffice stack buffer overflow, CVSS 7.8, triggered by exporting a malicious document to PDF. No patch yet. Avoid untrusted files until fixed. valtersit.com/cve/CVE-2026-632 #CVE #infosec #LibreOffice

##

CVE-2026-87119(CVSS UNKNOWN)

EPSS: 0.57%

updated 2026-09-22T12:30:32

1 posts

Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly. The payer signs a Tempo KeyAuthorization over the chain id, key type, key id, expiry, limits and scopes only, with nothing tying it to the challenge that prompted it. MPP.Methods.Tempo.KeyAuthorization.verify/3 in lib/mpp/methods/tempo/key

hugovalters@mastodon.social at 2026-10-03T04:40:35.000Z ##

CVE-2026-87119 ZenHive auth bypass by capture-replay, CVSS 6.1. A captured subscription credential can be replayed to charge payers repeatedly. No patch yet, review is under way. Track it and apply mitigations now: valtersit.com/cve/CVE-2026-871 #CVE #infosec #cybersecurity

##

CVE-2026-95270
(3.7 LOW)

EPSS: 0.44%

updated 2026-09-22T12:30:32

1 posts

A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password of the file changedetectionio/flask_app.py of the component Hash Comparison. This manipulation of the argument Password causes observable timing discrepancy. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitability

hugovalters@mastodon.social at 2026-10-03T04:30:06.000Z ##

CVE-2026-95270 dgtlmoon changedetection.io up to 0.60.7 timing side-channel in check_password, remote. CVSS 3.7, exploit public, no patch yet. Update when fixed. valtersit.com/cve/CVE-2026-952 #CVE #infosec #cybersecurity

##

CVE-2026-4123
(4.3 MEDIUM)

EPSS: 0.35%

updated 2026-09-22T09:31:17

1 posts

The RW Elephant Rental Inventory plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.3.13. This is due to a missing capability check on the toggle_cache() function which is hooked to the wp_ajax_toggle_cache AJAX action. The function also lacks nonce verification. This makes it possible for authenticated attackers, with Subscriber-level access and abov

hugovalters@mastodon.social at 2026-10-03T03:40:02.000Z ##

CVE-2026-4123: Missing authorization in RW Elephant Rental Inventory for WordPress up to 2.3.13, CVSS 4.3. Subscriber-level users can toggle cache settings. Patch under review, so apply mitigations now. valtersit.com/cve/CVE-2026-412 #CVE #WordPress #infosec

##

CVE-2026-9004
(4.3 MEDIUM)

EPSS: 0.37%

updated 2026-09-22T09:31:17

1 posts

The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.6 via the 'contact_id' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to extract full names, email addresses, phone numbers, mobile numbers, fax numbers, and physical address informati

hugovalters@mastodon.social at 2026-10-02T17:40:02.000Z ##

CVE-2026-9004: WP-CRM System plugin for WordPress leaks CRM contact names, emails, phones and addresses via the contact_id parameter. CVSS 4.3, no patch yet. Restrict contributor access or remove the plugin. valtersit.com/cve/CVE-2026-900 #CVE #WordPress #infosec

##

CVE-2026-54049
(8.7 HIGH)

EPSS: 0.26%

updated 2026-08-24T19:37:55

1 posts

### Summary The Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's `unsafeHTML()` directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversations tool enabled can inject arbitrary HTML and JavaScript that executes in the browsers of all other users wh

thehackerwire@mastodon.social at 2026-10-02T17:20:29.000Z ##

🟠 CVE-2026-54049 - High (8.7)

Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them usin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73570
(8.9 HIGH)

EPSS: 11.74%

updated 2026-08-24T13:19:17.577000

2 posts

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands a

Nuclei template

10 repos

https://github.com/0xBlackash/CVE-2026-73570

https://github.com/alsyundawy/eradicate-zimbra-malware

https://github.com/gabrielunknown/CVE-2026-73570

https://github.com/BiuTrap/CVE-2026-73570

https://github.com/HORKimhab/CVE-2026-73570

https://github.com/jishino567/CVE-2026-73570

https://github.com/dahnutz/zimbra-cve-2026-73570-ir

https://github.com/juanpoch/CVE-2026-73570

https://github.com/hainhc/CVE-2026-73570

https://github.com/INFOKOM-KI/Zimbra-CVE-2026-73570-Rules

CVE-2026-73916
(9.1 CRITICAL)

EPSS: 0.43%

updated 2026-08-19T15:32:19

1 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data o

beyondmachines1@infosec.exchange at 2026-10-02T16:01:13.000Z ##

Critical Oracle Helidon Flaw Allows Unauthenticated Data Access and Modification

Oracle disclosed CVE-2026-73916, a critical vulnerability in Helidon’s Imperative Web Server that can be exploited remotely over HTTP without authentication. Successful exploitation can allow attackers to access, create, modify, or delete data available to the affected application.

**Check your Helidon version and apply Oracle’s latest security update as soon as possible. Until remediation is complete, restrict network access to affected Helidon web services and avoid exposing them directly to untrusted networks.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-61500
(9.8 CRITICAL)

EPSS: 0.86%

updated 2026-07-13T18:31:00

2 posts

Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full admi

1 repos

https://github.com/aramosf/CVE-2026-61500

sayzard@mastodon.sayzard.org at 2026-10-03T18:39:26.000Z ##

Anthropic's super bug-hunting model Mythos is hardcore good at math

Anthropic의 취약점 탐색 모델 Mythos가 Rejetto HTTP File Server(HFS)의 인증 우회 및 원격 코드 실행(RCE) 취약점 CVE-2026-61500을 찾아냈고, 공개 다음 날 실제 공격 시도가 관측됐다. 취약점은 V8의 비암호학적 `Math.random()` 출력이 애플리케이션에서 노출되는 경로와 결합돼, 공격자가 xorshift128+ 내부 상태를...

theregister.com/security/2026/

##

Analyst207@mastodon.social at 2026-10-03T15:51:09.000Z ##

Mythos Exposes New Vulnerability in Rejetto HTTP File Server

A critical vulnerability, CVE-2026-61500, has been uncovered in Rejetto HTTP File Server (HFS), allowing for full administrator access and remote code execution. This flaw was discovered using Anthropic's bug-hunting model Mythos and can be exploited with alarming ease.

osintsights.com/mythos-exposes

#RejettoHttpFileServer #Cve202661500 #AuthenticationBypass #RemoteCodeExecution #Vulnerability

##

CVE-2024-12426
(6.5 MEDIUM)

EPSS: 0.55%

updated 2026-06-17T06:59:41.900000

1 posts

Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice. URLs could be constructed which expanded environmental variables or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. This issue affects LibreOffice: from 24.8

hugovalters@mastodon.social at 2026-10-03T18:50:23.000Z ##

CVE-2026-63278: info disclosure via crafted URLs that expand env or INI values, leaking secrets to remote servers. Incomplete fix for CVE-2024-12426. CVSS 7.4, no patch yet. Restrict document links and monitor outbound valtersit.com/cve/CVE-2026-632 #CVE #infosec #cybersecurity

##

CVE-2021-35394
(9.8 CRITICAL)

EPSS: 99.86%

updated 2026-06-17T03:57:29.187000

1 posts

Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.

Nuclei template

undercodenews@mastodon.social at 2026-10-03T05:15:59.000Z ##

Cling IoT Botnet Hides Malicious Commands Inside Google-Like STUN Traffic + Video

Cling IoT Botnet Hides Malicious Commands Inside Google-Like STUN Traffic A New Layer of Stealth A newly identified IoT botnet called Cling is using an unusual technique to hide malicious command-and-control traffic in legitimate-looking STUN communications. Researchers at Nozomi Networks Labs discovered the activity while investigating exploitation attempts targeting CVE-2021-35394, a…

undercodenews.com/cling-iot-bo

##

CVE-2026-8695
(7.5 HIGH)

EPSS: 1.07%

updated 2026-05-15T18:30:46

1 posts

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo response. Attackers can exploit this vulnerability through GDB remote debugging to cause a denial of service or potentially achieve code execution by manipulating thread list

2 repos

https://github.com/DeAurity/CVE-2026-86950-POC

https://github.com/decalage2/detect_CVE-2026-86950

hackmag@infosec.exchange at 2026-10-02T16:07:55.000Z ##

⚪️ Apple fixes CoreGraphics zero-day vulnerability exploited in attacks

🗨️ Apple developers have released updates for iOS, iPadOS, and macOS that fix the zero-day vulnerability CVE-2026-86950. The CoreGraphics bug may already have been exploited in “extremely sophisticated” targeted attacks against specific iPhone users. The issue was reportedly discovered by researchers…

🔗 hackmag.com/news/cve-2026-8695

#news

##

CVE-2026-3323
(7.5 HIGH)

EPSS: 0.52%

updated 2026-04-28T12:31:36

4 posts

An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes.

1 repos

https://github.com/pavanchow/CVE-2026-33234

certvde@infosec.exchange at 2026-10-02T09:23:22.000Z ##

🔄 CSAF advisory updated (version 1.0.3)

VDE-2026-048
VEGA: Missing Authentication for critical function in VEGAPULS Bluetooth products
CVE-2026-3323

Changes: Fixed version range name and vendor name

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: vega.csaf-tp.certvde.com/.well

#OT #Advisory

##

certvde@infosec.exchange at 2026-10-02T09:21:49.000Z ##

🔄 CSAF advisory updated (version 1.0.3)

VDE-2026-047
VEGA: Missing Authentication for critical function in VEGAPULS Air products
CVE-2026-3323

Changes: Fixed version range name and vendor name

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: vega.csaf-tp.certvde.com/.well

#OT #Advisory

##

certvde@infosec.exchange at 2026-10-02T09:21:40.000Z ##

🔄 CSAF advisory updated (version 1.0.3)

VDE-2026-046
VEGA: Missing Authentication for critical function in VEGAPULS two- and four-wire products
CVE-2026-3323

Changes: Fixed version range name and vendor name

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: vega.csaf-tp.certvde.com/.well

#OT #Advisory

##

certvde@infosec.exchange at 2026-10-02T09:09:20.000Z ##

🔄 CSAF advisory updated (version 1.0.2)

VDE-2026-016
VEGA: Unsecured Configuration Interface Allows Unauthorized Access Leading to Privilege Escalation
CVE-2026-3323

Changes: Fixed version range name and vendor name

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: vega.csaf-tp.certvde.com/.well

#OT #Advisory

##

CVE-2026-20700
(7.8 HIGH)

EPSS: 1.37%

updated 2026-02-12T21:31:27

1 posts

A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, visionOS 26.3, iOS 26.3 and iPadOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals

2 repos

https://github.com/notthemystery/CVE-2026-20700-POC-that-ll-never-work

https://github.com/R3n3r0/CVE-2026-20700

security_crawler_carl@infosec.exchange at 2026-10-02T12:55:32.000Z ##

🏆 New Achievement! Out-of-Bounds Loot Drop!

Item acquired: [CURSED] CoreGraphics Zero-Day. Rarity: Extremely Sophisticated. Stats: -40 Device Integrity, +9999 Attacker Code Execution. Discovered by Meta Product Security and tracked as CVE-2026-20700, this out-of-bounds write flaw lurked inside Apple's CoreGraphics framework — the engine painting pixels across iOS, macOS, iPadOS, watchOS, and tvOS — and was actively exploited in targeted attacks before the patch dropped September 29th. (1/2)

##

CVE-2026-103956
(0 None)

EPSS: 0.47%

3 posts

N/A

thehackerwire@mastodon.social at 2026-10-03T18:45:31.000Z ##

🔴 CVE-2026-103956 - Critical (10)

Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:45:31.000Z ##

🔴 CVE-2026-103956 - Critical (10)

Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T22:09:53.000Z ##

AWS fixes Loom for AWS admin takeover CVE-2026-103956 and a SageMaker Unified Studio code execution bug, CVE-2026-104019. Patch now.

#AWS #LoomForAWS #SageMaker #CVE2026103956 #CVE2026104019 #AISecurity #CloudSecurity #Vulnerability

securityonline.info/loom-for-a

##

CVE-2026-103958
(0 None)

EPSS: 0.33%

2 posts

N/A

thehackerwire@mastodon.social at 2026-10-03T18:30:49.000Z ##

🟠 CVE-2026-103958 - High (7.6)

Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the credentials of the application's own container role and to read responses from ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:30:49.000Z ##

🟠 CVE-2026-103958 - High (7.6)

Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the credentials of the application's own container role and to read responses from ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104019
(0 None)

EPSS: 1.42%

5 posts

N/A

thehackerwire@mastodon.social at 2026-10-03T18:30:30.000Z ##

🔴 CVE-2026-104019 - Critical (9)

OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-10-03T06:00:26.340Z ##

CVE-2026-104019: CRITICAL OS command injection in AWS SageMaker Distribution (CVSS 9.0) can let project contributors run arbitrary code & steal credentials. Upgrade to fixed versions or restart supported Spaces for auto-patch. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-10-03T18:30:30.000Z ##

🔴 CVE-2026-104019 - Critical (9)

OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-03T06:00:26.000Z ##

CVE-2026-104019: CRITICAL OS command injection in AWS SageMaker Distribution (CVSS 9.0) can let project contributors run arbitrary code & steal credentials. Upgrade to fixed versions or restart supported Spaces for auto-patch. radar.offseq.com/threat/cve-20 #OffSeq #AWS #CVE #CloudSec

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T22:09:53.000Z ##

AWS fixes Loom for AWS admin takeover CVE-2026-103956 and a SageMaker Unified Studio code execution bug, CVE-2026-104019. Patch now.

#AWS #LoomForAWS #SageMaker #CVE2026103956 #CVE2026104019 #AISecurity #CloudSecurity #Vulnerability

securityonline.info/loom-for-a

##

CVE-2026-65634
(0 None)

EPSS: 0.42%

1 posts

N/A

hugovalters@mastodon.social at 2026-10-03T06:20:19.000Z ##

CVE-2026-65634 Erlang/OTP DoS: crafted OID in TLS handshake triggers unbounded integer growth in the asn1 decoder CVSS 7.5. No patch yet. Limit OID parsing or update as soon as the fix lands. valtersit.com/cve/CVE-2026-656 #CVE #infosec #Erlang

##

CVE-2026-10426
(0 None)

EPSS: 0.00%

1 posts

N/A

censys@infosec.exchange at 2026-10-02T21:42:21.000Z ##

🚨 Fortinet reports active exploitation of CVE-2026-104286, a critical path traversal vulnerability affecting FortiMail.

Censys observes roughly 2,800 Internet-exposed FortiMail hosts after excluding honeypots. This is an exposure count, not a confirmed-vulnerable count.

No fixed builds have been released as of October 2. Censys ARC covers affected versions, Fortinet’s current workarounds, indicators, and remediation guidance: censys.com/advisory/cve-2026-1

#CensysARC #Fortinet #FortiMail #Cybersecurity #Vulnerability

##

CVE-2026-104851
(0 None)

EPSS: 0.32%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-02T17:19:22.000Z ##

🟠 CVE-2026-104851 - High (8.8)

fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.implementations.reference.ReferenceFileSystem evaluates fields from Kerchunk reference JSON documents through unrestricted j...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104846
(0 None)

EPSS: 0.34%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-02T16:18:58.000Z ##

🔴 CVE-2026-104846 - Critical (9.8)

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass a plugin-produced callable-bearing thenab...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94422
(0 None)

EPSS: 0.69%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-02T15:17:32.000Z ##

🟠 CVE-2026-94422 - High (8.8)

An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85714
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-86360
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-63692
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-63688
(0 None)

EPSS: 0.00%

1 posts

N/A

Visit counter For Websites