## Updated at UTC 2026-08-02T19:57:46.688246

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-68579 9.6 0.00% 2 0 2026-08-02T15:30:25 FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the W
CVE-2026-68578 7.5 0.00% 2 0 2026-08-02T15:30:25 ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the
CVE-2026-67356 8.8 0.00% 2 0 2026-08-02T15:30:25 ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigg
CVE-2026-68581 8.1 0.00% 2 0 2026-08-02T15:30:25 Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API
CVE-2026-68582 6.5 0.00% 2 0 2026-08-02T15:30:25 Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorizat
CVE-2025-71399 8.6 0.00% 2 0 2026-08-02T15:30:21 Better Auth relies on better-call, which uses the rou3 router library. In affect
CVE-2026-68580 7.5 0.00% 2 0 2026-08-02T13:16:53.950000 FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio inp
CVE-2026-67357 7.5 0.00% 2 0 2026-08-02T13:16:53.520000 ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability
CVE-2026-67308 0 0.56% 2 0 2026-08-02T12:16:46.647000 Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub
CVE-2026-16232 9.1 71.39% 1 2 template 2026-08-02T09:31:30 An authentication bypass vulnerability in the Check Point SmartConsole login pro
CVE-2026-8457 9.8 0.40% 4 0 2026-08-02T00:31:17 The WooCommerce - Social Login plugin for WordPress is vulnerable to Authenticat
CVE-2026-18352 7.5 0.68% 2 0 2026-08-02T00:31:17 The User Access Manager plugin for WordPress is vulnerable to Directory Traversa
CVE-2026-13339 7.5 0.64% 2 0 2026-08-02T00:16:22.760000 The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal i
CVE-2026-18556 None 0.27% 3 0 2026-08-01T21:31:32 Authentication bypass using an alternate path or channel vulnerability in N-able
CVE-2026-67325 8.8 1.48% 2 0 2026-08-01T15:30:37 GitPython before 3.1.51 contains an incomplete command injection blocklist that
CVE-2026-67304 7.5 0.35% 3 0 2026-08-01T15:30:36 FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smart
CVE-2026-67331 8.3 0.24% 3 0 2026-08-01T15:30:36 better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organi
CVE-2026-67333 7.2 0.16% 1 0 2026-08-01T15:30:36 better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-bet
CVE-2026-67294 5.9 0.27% 2 0 2026-08-01T15:30:36 FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose
CVE-2026-67292 6.5 0.26% 2 0 2026-08-01T15:30:36 FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gat
CVE-2026-67305 None 0.49% 2 0 2026-08-01T15:30:36 FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerabili
CVE-2026-67290 7.5 0.43% 2 0 2026-08-01T15:30:36 FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TS
CVE-2026-67336 8.7 0.16% 4 0 2026-08-01T15:30:36 better-auth versions before 1.6.11 contain insecure cryptographic defaults in th
CVE-2026-67291 7.5 0.34% 2 0 2026-08-01T15:30:36 FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bound
CVE-2026-67301 7.5 0.34% 2 0 2026-08-01T15:30:36 FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async u
CVE-2026-67299 7.5 0.33% 2 0 2026-08-01T15:30:36 FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async up
CVE-2026-67298 7.5 0.38% 2 0 2026-08-01T15:30:36 FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server
CVE-2026-67323 8.4 1.02% 2 0 2026-08-01T15:30:36 GitPython before 3.1.51 fails to guard against dangerous Git options passed as k
CVE-2026-67328 8.1 0.28% 2 0 2026-08-01T15:30:36 @better-auth/sso versions before 1.6.21 contain multiple authentication bypass v
CVE-2026-67327 8.3 0.23% 2 0 2026-08-01T15:30:36 better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-be
CVE-2026-67343 8.8 0.30% 2 0 2026-08-01T15:30:31 ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the
CVE-2026-67342 9.8 0.32% 4 0 2026-08-01T15:30:30 ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in
CVE-2026-67340 9.8 0.52% 4 0 2026-08-01T15:30:30 ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host
CVE-2026-67324 9.8 0.38% 2 0 2026-08-01T15:30:28 GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value>
CVE-2026-67289 9.8 0.38% 4 0 2026-08-01T15:30:26 FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and c
CVE-2026-66402 9.8 0.29% 4 0 2026-08-01T15:30:25 FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certif
CVE-2026-67288 7.5 0.35% 2 0 2026-08-01T15:30:25 FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smart
CVE-2026-67352 7.6 0.21% 3 0 2026-08-01T13:17:05.860000 luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in
CVE-2026-67341 9.8 0.32% 4 0 2026-08-01T13:17:05.273000 ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks o
CVE-2026-67330 9.9 0.35% 2 0 2026-08-01T13:17:03.677000 @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.
CVE-2026-67322 7.5 0.27% 2 0 2026-08-01T13:17:02.493000 GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Re
CVE-2026-67300 7.5 0.33% 2 0 2026-08-01T13:16:59.393000 FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities i
CVE-2026-67297 7.5 0.34% 3 0 2026-08-01T13:16:58.967000 FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing T
CVE-2026-67296 7.5 0.34% 2 0 2026-08-01T13:16:58.830000 FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI se
CVE-2026-16635 8.8 0.31% 2 0 2026-08-01T09:30:37 The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in a
CVE-2026-16144 8.1 0.69% 2 0 2026-08-01T09:30:37 The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vu
CVE-2026-15964 9.8 0.49% 2 1 2026-08-01T09:30:37 The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication
CVE-2026-15988 8.8 0.22% 2 0 2026-08-01T09:30:36 The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPre
CVE-2026-15450 8.1 0.38% 1 0 2026-08-01T09:30:36 The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable
CVE-2026-14561 None 0.14% 1 0 2026-08-01T09:30:36 The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does n
CVE-2026-64531 7.8 0.13% 1 3 2026-08-01T08:16:29.920000 In the Linux kernel, the following vulnerability has been resolved: net: openvs
CVE-2026-15368 0 0.14% 1 0 2026-08-01T07:16:31.477000 The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind
CVE-2026-3141 9.1 0.47% 2 1 2026-08-01T06:16:26.030000 The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file d
CVE-2026-20316 5.3 0.79% 9 0 2026-08-01T05:16:55.973000 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-17566 9.9 0.43% 2 0 2026-08-01T05:16:55.827000 pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by in
CVE-2026-15006 7.5 0.83% 2 0 2026-08-01T03:31:19 The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email
CVE-2026-15414 8.8 0.34% 2 0 2026-08-01T03:16:25.757000 The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privileg
CVE-2026-34641 7.8 0.14% 2 0 2026-08-01T00:31:02 Premiere Pro is affected by an out-of-bounds write vulnerability that could resu
CVE-2026-68771 9.8 0.62% 3 0 2026-08-01T00:30:56 ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrai
CVE-2026-63223 9.8 0.49% 4 0 2026-08-01T00:17:17.750000 CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and
CVE-2026-53500 8.2 0.29% 1 0 2026-08-01T00:17:16.713000 Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0,
CVE-2026-14319 7.5 0.32% 2 0 2026-07-31T21:32:56 The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to
CVE-2026-68770 9.8 0.52% 2 0 2026-07-31T21:32:05 sentence-transformers contains a security control bypass vulnerability that allo
CVE-2026-67822 9.8 0.29% 2 0 2026-07-31T21:31:55 Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in
CVE-2026-14930 7.5 0.24% 2 0 2026-07-31T21:31:54 The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorizati
CVE-2026-62999 7.5 0.29% 1 0 2026-07-31T20:16:53.523000 Copier is a library and CLI app for rendering project templates. From 9.5.0 thro
CVE-2026-56673 7.5 0.43% 2 0 2026-07-31T20:16:52.487000 ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node
CVE-2026-18358 7.5 0.43% 1 0 2026-07-31T20:16:49.663000 A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux.
CVE-2026-17561 9.8 0.31% 3 0 2026-07-31T20:16:49.313000 Improper Control of Generation of Code ('Code Injection') vulnerability in Innot
CVE-2026-15258 8.1 0.22% 2 0 2026-07-31T20:16:48.207000 The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not
CVE-2026-15048 7.5 0.26% 2 0 2026-07-31T20:16:47.790000 The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization c
CVE-2026-53599 7.5 0.31% 1 0 2026-07-31T19:43:51 ## Summary `rex_mediapool::isAllowedExtension` in `redaxo/src/addons/mediapool
CVE-2026-53510 8.1 0.40% 1 0 2026-07-31T19:38:26 ### Impact `Savon::Model` generated SOAP operation methods by interpolating ope
CVE-2026-54725 9.6 0.32% 3 0 2026-07-31T19:17:10.833000 vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret
CVE-2026-52856 7.5 0.34% 2 0 2026-07-31T19:17:09.120000 Wings is the server control plane for Pterodactyl, a free, open-source game serv
CVE-2026-18141 8.2 0.25% 1 0 2026-07-31T19:17:08.053000 A flaw was found in aap-gateway, a component of Ansible Automation Platform's Ev
CVE-2026-53505 7.5 0.34% 2 0 2026-07-31T19:00:45 ### Summary Thumbor's `filters:proportion(<value>)` filter does not enforce an u
CVE-2026-53504 7.5 0.34% 2 0 2026-07-31T18:58:29 ### Summary The regular expression used to parse the `convolution` filter exhibi
CVE-2026-53503 7.5 0.42% 2 0 2026-07-31T18:54:57 ### Summary Thumbor's `filters:convolution(<matrix>, <columns>, <should_normaliz
CVE-2026-53501 8.2 0.21% 2 0 2026-07-31T18:51:54 # HMAC validation bypass via multiple `.replace()` calls when removing URL signa
CVE-2026-62391 8.1 0.40% 2 0 2026-07-31T18:33:21 The security fix for CVE-2025-66518 is incomplete. Any client who can access to
CVE-2026-12695 8.1 0.29% 2 0 2026-07-31T18:33:20 The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitte
CVE-2026-12251 8.1 0.23% 2 0 2026-07-31T18:33:20 The Ultimate Member WordPress plugin before 2.12.1 does not filter administrato
CVE-2026-12721 8.6 0.26% 2 0 2026-07-31T18:33:20 The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape
CVE-2026-17349 9.6 0.30% 2 0 2026-07-31T18:32:25 /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced
CVE-2026-17346 8.8 0.43% 2 0 2026-07-31T18:32:24 The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched six
CVE-2026-17351 9.0 0.45% 2 1 2026-07-31T18:32:24 The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query pas
CVE-2026-17347 7.5 0.27% 1 0 2026-07-31T18:32:24 The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administr
CVE-2026-13609 8.8 0.25% 2 0 2026-07-31T18:32:17 The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML ent
CVE-2026-14919 9.8 0.28% 2 0 2026-07-31T18:32:17 The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its
CVE-2026-18446 7.5 0.22% 2 0 2026-07-31T18:17:13.383000 fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash
CVE-2026-12720 7.5 0.30% 2 0 2026-07-31T18:17:10.337000 The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be
CVE-2026-10685 7.6 0.18% 3 0 2026-07-31T18:17:09.510000 The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp()
CVE-2026-65310 7.5 0.32% 2 0 2026-07-31T17:16:34.750000 ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affecte
CVE-2026-68500 7.5 0.38% 1 0 2026-07-31T16:52:41 ### Impact The shop payment webhook `POST /{_locale}/update-payment` (route
CVE-2026-67594 9.8 0.46% 1 0 2026-07-31T16:17:11.793000 Spikster through commit e1cdf8c contains a missing authentication vulnerability
CVE-2026-66420 8.8 0.17% 1 0 2026-07-31T16:17:10.740000 MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass v
CVE-2026-65423 8.8 0.60% 1 0 2026-07-31T16:17:09.560000 An integer overflow in the UA_Variant arrayDimensions product computation in op
CVE-2026-63559 7.5 0.43% 1 0 2026-07-31T16:17:09.290000 An integer overflow in the UA_Variant arrayDimensions product computation in op
CVE-2026-63222 7.5 0.45% 3 0 2026-07-31T16:17:08.903000 CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedF
CVE-2026-52855 9.9 0.27% 2 0 2026-07-31T16:16:48 ### Impact **Type:** Exposure of sensitive information / insufficiently protect
CVE-2026-14830 7.5 0.21% 2 0 2026-07-31T15:33:52 The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment proces
CVE-2026-14333 7.5 0.30% 2 0 2026-07-31T15:33:51 The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in
CVE-2026-68502 9.8 0.53% 1 0 2026-07-31T15:18:01.563000 LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framew
CVE-2026-63221 9.4 0.38% 3 0 2026-07-31T14:16:50.873000 CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query B
CVE-2026-10079 8.5 0.17% 1 0 2026-07-31T12:30:30 A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Wh
CVE-2026-11770 7.5 0.51% 1 0 2026-07-31T12:30:30 A flaw was found in 389 Directory Server. An unauthenticated remote attacker can
CVE-2026-56672 8.2 0.24% 2 0 2026-07-31T11:17:10.903000 ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0,
CVE-2026-15722 7.5 0.51% 1 0 2026-07-31T11:17:04.833000 A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). Th
CVE-2026-18452 10.0 0.43% 2 0 2026-07-31T09:31:30 DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials v
CVE-2026-16236 8.8 0.63% 2 0 2026-07-31T09:31:30 The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Up
CVE-2026-65309 7.5 0.15% 2 0 2026-07-31T09:31:30 ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmit
CVE-2026-14483 9.8 0.61% 2 1 2026-07-31T09:31:25 The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulner
CVE-2026-65313 8.1 0.18% 1 0 2026-07-31T09:31:19 A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engin
CVE-2026-18157 7.8 0.24% 1 0 2026-07-31T03:31:17 A flaw was found in yggdrasil-worker-package-manager. A local attacker with exis
CVE-2026-66421 9.3 0.36% 1 0 2026-07-31T00:30:29 OpenClaw Dashboard contains a stored cross-site scripting vulnerability that all
CVE-2026-66360 7.5 0.28% 1 0 2026-07-31T00:30:29 The ISO Presentation layer contains a flaw in the handling of specific paramete
CVE-2026-18064 7.5 0.34% 1 0 2026-07-31T00:30:29 An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Healt
CVE-2026-63035 8.1 0.57% 1 0 2026-07-31T00:30:22 A heap use-after-free vulnerability in the TransferSubscriptions service in ope
CVE-2026-66803 10.0 0.49% 1 0 2026-07-30T21:31:57 Improper access control in Azure Cosmos DB allows an unauthorized attacker to ex
CVE-2026-67207 8.8 0.30% 1 0 2026-07-30T21:31:57 Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in Backu
CVE-2026-67206 8.8 0.44% 1 1 2026-07-30T21:31:57 Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileM
CVE-2026-66416 8.8 0.16% 1 0 2026-07-30T21:31:57 Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows u
CVE-2026-66415 8.5 0.28% 1 0 2026-07-30T21:31:57 Leantime 3.6.2 contains a server-side request forgery and local file inclusion v
CVE-2026-13435 9.9 0.29% 1 0 2026-07-30T21:31:56 IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vuln
CVE-2026-17657 8.3 0.36% 1 0 2026-07-30T21:31:32 Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a r
CVE-2026-18140 7.5 0.44% 1 0 2026-07-30T20:17:03.400000 Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runti
CVE-2026-66013 0 0.39% 1 0 2026-07-30T20:11:09.180000 OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the
CVE-2026-9322 7.5 0.30% 1 0 2026-07-30T19:18:37.363000 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
CVE-2026-28323 9.8 0.64% 2 0 2026-07-30T18:31:47 SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass
CVE-2026-12940 9.8 0.48% 1 0 2026-07-30T18:31:47 IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote
CVE-2026-66066 None 1.70% 10 5 2026-07-30T18:23:34 ### Impact In its default configuration, a Rails application that displays image
CVE-2026-67595 8.1 0.42% 1 1 2026-07-30T16:45:00.353000 VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript p
CVE-2026-15435 9.8 0.73% 2 0 2026-07-30T15:31:59 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.
CVE-2026-59309 9.8 0.74% 1 0 2026-07-30T15:31:54 VMware vCenter contains an authentication bypass vulnerability in the VMware Dir
CVE-2026-47876 9.3 0.28% 2 0 2026-07-30T15:31:54 VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual
CVE-2026-59310 9.8 1.14% 1 0 2026-07-30T15:31:51 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-18363 0 0.30% 1 0 2026-07-30T14:12:18.697000 A logic vulnerability in the password reset token validation routine implemented
CVE-2026-14529 9.4 0.33% 1 0 2026-07-30T14:08:40.373000 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
CVE-2026-64560 7.8 0.12% 1 0 2026-07-30T12:32:18 In the Linux kernel, the following vulnerability has been resolved: posix-cpu-t
CVE-2026-48449 10.0 0.54% 2 0 2026-07-30T03:31:28 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CVE-2026-20079 10.0 37.67% 3 1 template 2026-07-29T17:16:51.683000 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-65883 None 0.50% 1 1 2026-07-29T12:31:30 Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Ca
CVE-2026-14512 9.8 0.54% 1 0 2026-07-28T21:31:44 IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-a
CVE-2026-16347 8.8 0.23% 1 0 2026-07-28T21:31:39 MikroTik RouterOS contains a weakness in its API authentication handling that la
CVE-2026-16771 8.8 0.25% 1 0 2026-07-28T21:31:32 In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to en
CVE-2026-5674 8.8 0.12% 1 0 2026-07-28T18:33:47 A flaw was found in PipeWire, a multimedia server. This vulnerability allows an
CVE-2026-63077 9.8 0.65% 3 1 2026-07-27T18:31:56 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-62379 9.8 0.00% 1 0 2026-07-24T21:11:10 ## Summary A pre-authentication remote code execution vulnerability affects Open
CVE-2026-46135 9.8 0.40% 1 0 2026-07-24T15:33:33 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp:
CVE-2026-43499 7.8 0.73% 1 63 2026-07-24T15:33:29 In the Linux kernel, the following vulnerability has been resolved: rtmutex: Us
CVE-2026-65694 7.5 2.46% 1 1 2026-07-24T00:32:40 Microweber CMS through 2.0.20 contains a path traversal vulnerability in the sta
CVE-2026-10697 7.5 0.29% 1 0 2026-07-23T21:31:09 Improper Authentication vulnerability in Progress MOVEit Transfer. This issue a
CVE-2026-50522 9.8 75.76% 1 5 2026-07-23T15:44:10.873000 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-46243 7.1 0.38% 1 4 2026-07-23T12:18:16.790000 In the Linux kernel, the following vulnerability has been resolved: smb: client
CVE-2026-10702 4.3 0.72% 4 2 2026-07-22T19:10:00.120000 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w
CVE-2026-20896 9.8 31.81% 1 6 2026-07-21T20:28:59 # Summary The Gitea Docker images ship an `app.ini` template that hard-codes:
CVE-2026-52887 10.0 0.59% 1 0 2026-07-20T16:17:05.020000 NocoBase is an AI-powered no-code/low-code platform for building business applic
CVE-2026-27771 8.2 43.07% 1 2 template 2026-07-17T19:04:38 ### CVE Description Gitea versions up to and including 1.26.1 have insufficient
CVE-2026-15352 7.5 0.43% 1 0 2026-07-16T21:30:45 A vulnerability exists in the Health & Safety (HS) application of NASA's Core Fl
CVE-2026-42530 8.1 3.68% 1 3 2026-07-16T12:33:31 NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGI
CVE-2026-15410 7.2 76.35% 1 3 2026-07-16T05:16:18.470000 Post-authentication improper control of generation of code ('Code Injection') vu
CVE-2026-15409 10.0 78.44% 1 5 template 2026-07-16T05:16:18.293000 A Server-side request forgery (SSRF) vulnerability has been identified in the SM
CVE-2026-48319 9.1 32.29% 1 0 2026-07-14T21:32:32 ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted D
CVE-2026-49176 7.8 0.47% 1 2 2026-07-14T18:32:01 Improper privilege management in Windows WalletService allows an authorized atta
CVE-2026-56291 9.8 76.07% 1 4 template 2026-07-10T18:33:13 The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary
CVE-2026-58025 9.8 0.33% 1 1 2026-07-09T21:31:14 Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWik
CVE-2026-12045 9.0 0.48% 2 0 2026-07-01T19:26:30.593000 Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker wh
CVE-2026-12044 8.8 0.71% 2 0 2026-06-19T00:31:46 SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT O
CVE-2025-15435 7.3 0.36% 1 0 2026-06-17T08:37:46.203000 A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an u
CVE-2013-4786 7.5 78.57% 2 1 2026-06-16T23:57:53.617000 The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (R
CVE-2026-42897 8.1 5.64% 4 1 2026-05-15T18:30:32 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2025-66376 7.2 21.62% 2 0 2026-03-18T18:31:10 Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Clas
CVE-2025-66518 None 0.89% 2 0 2026-01-29T03:42:38 Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols
CVE-2026-65321 0 0.00% 2 0 N/A
CVE-2026-4941 0 0.00% 2 2 N/A
CVE-2026-49413 0 0.15% 2 1 N/A
CVE-2026-60137 0 79.03% 1 46 N/A
CVE-2026-63030 0 98.42% 1 72 template N/A
CVE-2026-18420 0 0.00% 1 0 N/A
CVE-2026-62261 0 0.00% 1 0 N/A
CVE-2026-46648 0 0.00% 1 0 N/A
CVE-2026-46647 0 0.00% 1 0 N/A
CVE-2026-63220 0 0.14% 1 0 N/A
CVE-2026-59726 0 0.48% 2 1 N/A
CVE-2026-17543 0 0.39% 1 0 N/A
CVE-2026-62246 0 0.27% 1 0 N/A
CVE-2026-68503 0 0.40% 1 0 N/A
CVE-2026-18245 0 0.52% 1 0 N/A
CVE-2026-61536 0 0.30% 1 0 N/A
CVE-2026-62663 0 0.34% 1 0 N/A

CVE-2026-68579
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-08-02T15:30:25

2 posts

FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a fixed-size buffer of cb bytes, CliprdrStream_Read requests file contents from the RDP server and then copies the response into the caller's buffer using the serv

thehackerwire@mastodon.social at 2026-08-02T14:01:21.000Z ##

🔴 CVE-2026-68579 - Critical (9.6)

FreeRDP before 3.30.0 (&lt;= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client&#039;s CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T14:01:21.000Z ##

🔴 CVE-2026-68579 - Critical (9.6)

FreeRDP before 3.30.0 (&lt;= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client&#039;s CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68578
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-02T15:30:25

2 posts

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary JavaScript code via the query tool.

thehackerwire@mastodon.social at 2026-08-02T14:01:12.000Z ##

🟠 CVE-2026-68578 - High (7.5)

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema muta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T14:01:12.000Z ##

🟠 CVE-2026-68578 - High (7.5)

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema muta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67356
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-02T15:30:25

2 posts

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can create triggers that execute JavaScript to create server-wide admin users, escalating privileges beyond their authorization level.

thehackerwire@mastodon.social at 2026-08-02T14:00:26.000Z ##

🟠 CVE-2026-67356 - High (8.8)

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can creat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T14:00:26.000Z ##

🟠 CVE-2026-67356 - High (8.8)

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can creat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68581
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-02T15:30:25

2 posts

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a target user's ID is treated as that user by the /api/v1/tokens endpoints. An authenticated attacker can obtain a target's num

thehackerwire@mastodon.social at 2026-08-02T14:00:17.000Z ##

🟠 CVE-2026-68581 - High (8.1)

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JW...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T14:00:17.000Z ##

🟠 CVE-2026-68581 - High (8.1)

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JW...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68582
(6.5 MEDIUM)

EPSS: 0.00%

updated 2026-08-02T15:30:25

2 posts

Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads the requested project view from the URL path without verifying the caller is authorized for it. For a link-share token holder, the task scope is pinned to the share's own project, but the vie

offseq at 2026-08-02T13:30:24.018Z ##

CVE-2026-68582 (CRITICAL): go-vikunja vikunja ≤2.3.0 allows attackers with a share link to read kanban bucket titles & user info from other tenants due to broken object auth at /projects/{project}/views/{view}/tasks. Update to 2.4.0+! radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-02T13:30:24.000Z ##

CVE-2026-68582 (CRITICAL): go-vikunja vikunja ≤2.3.0 allows attackers with a share link to read kanban bucket titles & user info from other tenants due to broken object auth at /projects/{project}/views/{view}/tasks. Update to 2.4.0+! radar.offseq.com/threat/cve-20 #OffSeq #CVE202668582 #Vulnerability

##

CVE-2025-71399
(8.6 HIGH)

EPSS: 0.00%

updated 2026-08-02T15:30:21

2 posts

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass disabledPaths configuration and path-based rate limits by submitting requests with extr

thehackerwire@mastodon.social at 2026-08-02T15:00:06.000Z ##

🟠 CVE-2025-71399 - High (8.6)

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T15:00:06.000Z ##

🟠 CVE-2025-71399 - High (8.6)

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68580
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-02T13:16:53.950000

2 posts

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all pl

thehackerwire@mastodon.social at 2026-08-02T14:01:32.000Z ##

🟠 CVE-2026-68580 - High (7.5)

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can su...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T14:01:32.000Z ##

🟠 CVE-2026-68580 - High (7.5)

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can su...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67357
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-02T13:16:53.520000

2 posts

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and achieve full server compromise.

thehackerwire@mastodon.social at 2026-08-02T14:00:37.000Z ##

🟠 CVE-2026-67357 - High (7.5)

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-Ar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T14:00:37.000Z ##

🟠 CVE-2026-67357 - High (7.5)

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-Ar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67308
(0 None)

EPSS: 0.56%

updated 2026-08-02T12:16:46.647000

2 posts

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into environment variables that are directly interpolated into run steps, enabling command execution and exfiltration of secrets including GITHUB_TOKEN and

thehackerwire@mastodon.social at 2026-08-01T21:00:33.000Z ##

🔴 CVE-2026-67308 - Critical (10)

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters int...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T21:00:33.000Z ##

🔴 CVE-2026-67308 - Critical (10)

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters int...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16232
(9.1 CRITICAL)

EPSS: 71.39%

updated 2026-08-02T09:31:30

1 posts

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server I

Nuclei template

2 repos

https://github.com/sfewer-r7/CVE-2026-16232

https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-8457
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-08-02T00:31:17

4 posts

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's public keys or validating the issuer, audience, or expiry claims, combined with the security nonce r

offseq at 2026-08-02T01:30:26.098Z ##

CVE-2026-8457: WPWeb WooCommerce - Social Login (<=2.8.7) suffers CRITICAL auth bypass. Forged Apple id_tokens + exposed nonce = attacker can access any WordPress user, even admins. Disable Apple login or plugin ASAP. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-02T01:00:03.000Z ##

🔴 CVE-2026-8457 - Critical (9.8)

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-02T01:30:26.000Z ##

CVE-2026-8457: WPWeb WooCommerce - Social Login (<=2.8.7) suffers CRITICAL auth bypass. Forged Apple id_tokens + exposed nonce = attacker can access any WordPress user, even admins. Disable Apple login or plugin ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

thehackerwire@mastodon.social at 2026-08-02T01:00:03.000Z ##

🔴 CVE-2026-8457 - Critical (9.8)

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18352
(7.5 HIGH)

EPSS: 0.68%

updated 2026-08-02T00:31:17

2 posts

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. This is possible because when attachment_url_to_postid() returns 0 for a traversal

thehackerwire@mastodon.social at 2026-08-02T01:00:23.000Z ##

🟠 CVE-2026-18352 - High (7.5)

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T01:00:23.000Z ##

🟠 CVE-2026-18352 - High (7.5)

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13339
(7.5 HIGH)

EPSS: 0.64%

updated 2026-08-02T00:16:22.760000

2 posts

The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. This is exploitable by unauthenticated attackers because the required nonce is publi

thehackerwire@mastodon.social at 2026-08-02T01:00:13.000Z ##

🟠 CVE-2026-13339 - High (7.5)

The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the contents of arb...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T01:00:13.000Z ##

🟠 CVE-2026-13339 - High (7.5)

The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the contents of arb...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18556(CVSS UNKNOWN)

EPSS: 0.27%

updated 2026-08-01T21:31:32

3 posts

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

security_crawler_carl at 2026-08-02T15:39:21.092Z ##

🏆 New Achievement! Management Remotely Destroyed!

Today's dungeon crawl is brought to you by Deferred Patch Tuesdays — when you're too busy managing clients to manage yourself. N-able N-central, the RMM platform MSPs trust to run everyone else's networks, is harboring CVE-2026-18556, a CVSS 9.8 authentication bypass being actively exploited in the wild. Attackers are waltzing — no, sorry — strolling right through, dropping Cloudflare tunnels for cozy, persistent access. (1/2)

##

netsecio@mastodon.social at 2026-08-02T15:09:52.000Z ##

📰 N-able N-central Flaw (CVE-2026-18556) Actively Exploited in Attacks

🚨 ACTIVE EXPLOITATION: A critical auth bypass flaw (CVE-2026-18556, CVSS 9.8) in N-able N-central RMM is being used to compromise MSPs. Attackers install CloudFlare tunnels for persistence. Patch to version 2026.3 NOW. #CVE #RMM #MSP

🔗 cyber.netsecops.io/articles/n-

##

security_crawler_carl@infosec.exchange at 2026-08-02T15:39:21.000Z ##

🏆 New Achievement! Management Remotely Destroyed!

Today's dungeon crawl is brought to you by Deferred Patch Tuesdays — when you're too busy managing clients to manage yourself. N-able N-central, the RMM platform MSPs trust to run everyone else's networks, is harboring CVE-2026-18556, a CVSS 9.8 authentication bypass being actively exploited in the wild. Attackers are waltzing — no, sorry — strolling right through, dropping Cloudflare tunnels for cozy, persistent access. (1/2)

##

CVE-2026-67325
(8.8 HIGH)

EPSS: 1.48%

updated 2026-08-01T15:30:37

2 posts

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git resolves to dangerous options and executes arbitrary commands.

thehackerwire@mastodon.social at 2026-08-01T21:00:14.000Z ##

🟠 CVE-2026-67325 - High (8.8)

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p inste...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T21:00:14.000Z ##

🟠 CVE-2026-67325 - High (8.8)

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p inste...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67304
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-01T15:30:36

3 posts

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-state data to crash the process via null pointer access in free_reader_states functions.

hugovalters@mastodon.social at 2026-08-02T17:06:53.000Z ##

CVE-2026-67304 - DoS via null ptr deref in FreeRDP smartcard cleanup. CVSS 7.5. Unpatched. Patch when 3.29.0 available. #CVE #FreeRDP #infosec

valtersit.com/cve/CVE-2026-673

##

thehackerwire@mastodon.social at 2026-08-02T00:00:17.000Z ##

🟠 CVE-2026-67304 - High (7.5)

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T00:00:17.000Z ##

🟠 CVE-2026-67304 - High (7.5)

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67331
(8.3 HIGH)

EPSS: 0.24%

updated 2026-08-01T15:30:36

3 posts

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the attacker-controlled token.

hugovalters@mastodon.social at 2026-08-02T15:07:16.000Z ##

CVE-2026-67331 - Critical auth flaw in Better-Auth SCIM. Unbound providers let attackers steal tokens, hijack SCIM API access. CVSS 8.3. Unpatched - update immediately if affected. #CVE #infosec #BetterAuth

valtersit.com/cve/CVE-2026-673

##

thehackerwire@mastodon.social at 2026-08-01T20:00:07.000Z ##

🟠 CVE-2026-67331 - High (8.3)

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalida...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T20:00:07.000Z ##

🟠 CVE-2026-67331 - High (8.3)

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalida...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67333
(7.2 HIGH)

EPSS: 0.16%

updated 2026-08-01T15:30:36

1 posts

better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the deprecated oidc-provider plugin and the mcp plugin (which wraps the same provider). An attacker can register an OAuth client with a javascript: redirect_uri, which the authorization server later returns unchanged in the consent response. If the deploy

hugovalters@mastodon.social at 2026-08-02T14:09:42.000Z ##

CVE-2026-67333 - High sev URL scheme bypass in Better-Auth. javascript: redirect_uri allows XSS on consent pages. CVSS 7.2. No patch yet, block untrusted clients now. #CVE #BetterAuth #infosec

valtersit.com/cve/CVE-2026-673

##

CVE-2026-67294
(5.9 MEDIUM)

EPSS: 0.27%

updated 2026-08-01T15:30:36

2 posts

FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication. In x509_utils_verify(), when server-purpose (X509_PURPOSE_SSL_SERVER) verification fails, the code falls back to client-purpose and any-purpose verification, so a trusted, hostname-matching certificate valid only for clientAuth can be accepted as the

offseq at 2026-08-02T12:00:23.646Z ##

CVE-2026-67294 | FreeRDP <3.29.0: Improper EKU validation lets trusted clientAuth certs be accepted as server certs in TLS, enabling RDP server impersonation. Severity: CRITICAL. Patch pending. radar.offseq.com/threat/freerd

##

offseq@infosec.exchange at 2026-08-02T12:00:23.000Z ##

CVE-2026-67294 | FreeRDP <3.29.0: Improper EKU validation lets trusted clientAuth certs be accepted as server certs in TLS, enabling RDP server impersonation. Severity: CRITICAL. Patch pending. radar.offseq.com/threat/freerd #OffSeq #FreeRDP #TLS #infosec

##

CVE-2026-67292
(6.5 MEDIUM)

EPSS: 0.26%

updated 2026-08-01T15:30:36

2 posts

FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a fixed 1024-byte response stream whose length is not sealed to the actual received Ping payload, so a malicious gateway/WebSocket peer sending a non-empty Ping control frame causes the client to reply with an overlong Pong t

offseq at 2026-08-02T10:30:23.695Z ##

FreeRDP <3.29.0 has a CRITICAL buffer over-disclosure (CVE-2026-67292). Malicious WebSocket peers can leak memory or crash clients via crafted Ping frames. No patch confirmed — avoid unknown gateways. Details: radar.offseq.com/threat/freerd

##

offseq@infosec.exchange at 2026-08-02T10:30:23.000Z ##

FreeRDP <3.29.0 has a CRITICAL buffer over-disclosure (CVE-2026-67292). Malicious WebSocket peers can leak memory or crash clients via crafted Ping frames. No patch confirmed — avoid unknown gateways. Details: radar.offseq.com/threat/freerd #OffSeq #FreeRDP #CVE202667292 #AppSec

##

CVE-2026-67305(CVSS UNKNOWN)

EPSS: 0.49%

updated 2026-08-01T15:30:36

2 posts

FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buffer. A malicious RDP server can send a response with a data payload significantly larger than requested, causing arbitrary heap memory corruption that may enable

offseq at 2026-08-02T06:00:25.892Z ##

FreeRDP Windows client <3.29.0 has a CRITICAL heap buffer overflow in clipboard virtual channel (CVE-2026-67305). Malicious RDP servers can trigger remote code execution. Upgrade to 3.29.0+ ASAP. radar.offseq.com/threat/freerd

##

offseq@infosec.exchange at 2026-08-02T06:00:25.000Z ##

FreeRDP Windows client <3.29.0 has a CRITICAL heap buffer overflow in clipboard virtual channel (CVE-2026-67305). Malicious RDP servers can trigger remote code execution. Upgrade to 3.29.0+ ASAP. radar.offseq.com/threat/freerd #OffSeq #FreeRDP #CVE202667305 #infosec

##

CVE-2026-67290
(7.5 HIGH)

EPSS: 0.43%

updated 2026-08-01T15:30:36

2 posts

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length.

thehackerwire@mastodon.social at 2026-08-02T03:00:09.000Z ##

🟠 CVE-2026-67290 - High (7.5)

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T03:00:09.000Z ##

🟠 CVE-2026-67290 - High (7.5)

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67336
(8.7 HIGH)

EPSS: 0.16%

updated 2026-08-01T15:30:36

4 posts

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned tokens or intercept authorization codes when PKCE plain is used instead of the required S256 method.

offseq at 2026-08-02T00:00:36.782Z ##

CVE-2026-67336: better-auth <1.6.11 uses insecure crypto defaults in oidcProvider & mcp, advertising 'none' algo & accepting plain PKCE. Exploitation can lead to unsigned tokens & code interception. Severity: CRITICAL. Patch to 1.6.11+ radar.offseq.com/threat/better

##

thehackerwire@mastodon.social at 2026-08-01T15:01:20.000Z ##

🟠 CVE-2026-67336 - High (8.7)

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned token...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-02T00:00:36.000Z ##

CVE-2026-67336: better-auth <1.6.11 uses insecure crypto defaults in oidcProvider & mcp, advertising 'none' algo & accepting plain PKCE. Exploitation can lead to unsigned tokens & code interception. Severity: CRITICAL. Patch to 1.6.11+ radar.offseq.com/threat/better #OffSeq #CVE202667336 #OAuth #Security

##

thehackerwire@mastodon.social at 2026-08-01T15:01:20.000Z ##

🟠 CVE-2026-67336 - High (8.7)

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned token...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67291
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-01T15:30:36

2 posts

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes.

thehackerwire@mastodon.social at 2026-08-02T00:00:28.000Z ##

🟠 CVE-2026-67291 - High (7.5)

FreeRDP before 3.29.0 (affected versions &lt;= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T00:00:28.000Z ##

🟠 CVE-2026-67291 - High (7.5)

FreeRDP before 3.29.0 (affected versions &lt;= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67301
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-01T15:30:36

2 posts

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and update_message_PolygonCB() allocate a fresh points array but copy point data from the address of the order structure instead of from polygonSC->points /

thehackerwire@mastodon.social at 2026-08-02T00:00:06.000Z ##

🟠 CVE-2026-67301 - High (7.5)

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T00:00:06.000Z ##

🟠 CVE-2026-67301 - High (7.5)

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67299
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-01T15:30:36

2 posts

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a freshly allocated lParam->iconInfo with the parser-owned windowIcon->iconInfo pointer. After the parser callback returns, update_recv_window_info_order()

thehackerwire@mastodon.social at 2026-08-01T23:00:11.000Z ##

🟠 CVE-2026-67299 - High (7.5)

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T23:00:11.000Z ##

🟠 CVE-2026-67299 - High (7.5)

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67298
(7.5 HIGH)

EPSS: 0.38%

updated 2026-08-01T15:30:36

2 posts

FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PDU_HEADER_LENGTH from the peer-controlled orderLength field without first verifying orderLength is at least the header length. For orderLength values 0..3 this caus

thehackerwire@mastodon.social at 2026-08-01T23:00:01.000Z ##

🟠 CVE-2026-67298 - High (7.5)

FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PDU_HEADER_L...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T23:00:01.000Z ##

🟠 CVE-2026-67298 - High (7.5)

FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PDU_HEADER_L...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67323
(8.4 HIGH)

EPSS: 1.02%

updated 2026-08-01T15:30:36

2 posts

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leading-dash revision arguments, so a revision like --output=<path> can cause Git to o

thehackerwire@mastodon.social at 2026-08-01T20:00:41.000Z ##

🟠 CVE-2026-67323 - High (8.4)

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). A...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T20:00:41.000Z ##

🟠 CVE-2026-67323 - High (8.4)

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). A...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67328
(8.1 HIGH)

EPSS: 0.28%

updated 2026-08-01T15:30:36

2 posts

@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domain verification parsing mismatches, orphaned provider accounts, unbound SAML assertions, or reflected XSS on logout endpoints to gain unauthorized session access and account takeover.

thehackerwire@mastodon.social at 2026-08-01T18:00:17.000Z ##

🟠 CVE-2026-67328 - High (8.1)

@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domain verification parsing mismatches, orphaned prov...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T18:00:17.000Z ##

🟠 CVE-2026-67328 - High (8.1)

@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domain verification parsing mismatches, orphaned prov...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67327
(8.3 HIGH)

EPSS: 0.23%

updated 2026-08-01T15:30:36

2 posts

better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registration is enabled. An attacker registers an account with the victim's email address and an attacker-chosen password; the account remains unverified. When the legitima

thehackerwire@mastodon.social at 2026-08-01T18:00:04.000Z ##

🟠 CVE-2026-67327 - High (8.3)

better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and &lt; 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registration is ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T18:00:04.000Z ##

🟠 CVE-2026-67327 - High (8.3)

better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and &lt; 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registration is ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67343
(8.8 HIGH)

EPSS: 0.30%

updated 2026-08-01T15:30:31

2 posts

ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and execute administrative actions including user creation, database operatio

thehackerwire@mastodon.social at 2026-08-01T15:00:59.000Z ##

🟠 CVE-2026-67343 - High (8.8)

ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-Arcad...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T15:00:59.000Z ##

🟠 CVE-2026-67343 - High (8.8)

ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-Arcad...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67342
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-08-01T15:30:30

4 posts

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases they are not authorized to use by directly calling affected endpoints with arbitrary database parameters.

offseq at 2026-08-02T03:00:24.971Z ##

ArcadeDB <26.7.2 hit by CRITICAL CVE-2026-67342: Auth bypass via unvalidated HTTP endpoints (time series, batch, Prometheus, Grafana). Attackers can access & modify DBs. Restrict endpoints, monitor logs. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-01T15:00:24.000Z ##

🔴 CVE-2026-67342 - Critical (9.8)

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-02T03:00:24.000Z ##

ArcadeDB <26.7.2 hit by CRITICAL CVE-2026-67342: Auth bypass via unvalidated HTTP endpoints (time series, batch, Prometheus, Grafana). Attackers can access & modify DBs. Restrict endpoints, monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #ArcadeDB #Vuln #Infosec

##

thehackerwire@mastodon.social at 2026-08-01T15:00:24.000Z ##

🔴 CVE-2026-67342 - Critical (9.8)

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67340
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-08-01T15:30:30

4 posts

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can create a JavaScript trigger that invokes java.lang.Runtime.getRuntime().exec() (or ProcessBuilder), achieving OS command execution when the trigger fires

thehackerwire@mastodon.social at 2026-08-01T15:00:03.000Z ##

🔴 CVE-2026-67340 - Critical (9.8)

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-01T13:30:26.249Z ##

CVE-2026-67340: CRITICAL RCE in ArcadeDB <26.7.2. Users w/ UPDATE_SCHEMA can exploit JavaScript triggers to run OS commands. Patch status pending — restrict permissions & audit triggers. Details: radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-01T15:00:03.000Z ##

🔴 CVE-2026-67340 - Critical (9.8)

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-01T13:30:26.000Z ##

CVE-2026-67340: CRITICAL RCE in ArcadeDB <26.7.2. Users w/ UPDATE_SCHEMA can exploit JavaScript triggers to run OS commands. Patch status pending — restrict permissions & audit triggers. Details: radar.offseq.com/threat/cve-20 #OffSeq #ArcadeDB #RCE #infosec

##

CVE-2026-67324
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-08-01T15:30:28

2 posts

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi_options=..., allow_unsafe_options=False), an attacker can supply -u<helper> to bypass the gate that blocks --upload-pack/-u, causing Git t

thehackerwire@mastodon.social at 2026-08-01T21:00:03.000Z ##

🔴 CVE-2026-67324 - Critical (9.8)

GitPython 3.1.50 fails to recognize joined short-option forms such as -u (the short form of --upload-pack=) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T21:00:03.000Z ##

🔴 CVE-2026-67324 - Critical (9.8)

GitPython 3.1.50 fails to recognize joined short-option forms such as -u (the short form of --upload-pack=) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67289
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-08-01T15:30:26

4 posts

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or

offseq at 2026-08-02T07:30:23.695Z ##

CVE-2026-67289: FreeRDP ≤3.28.0 has a CRITICAL flaw (CVSS 9.8) in RDP redirection — improper CRLF/control character validation exposes clients to HTTP header injection via proxies. Upgrade to 3.29.0+ now. radar.offseq.com/threat/freerd

##

thehackerwire@mastodon.social at 2026-08-02T02:59:59.000Z ##

🔴 CVE-2026-67289 - Critical (9.8)

FreeRDP before 3.29.0 (affected versions &lt;= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client&#039;s ServerHostname and, when the client c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-02T07:30:23.000Z ##

CVE-2026-67289: FreeRDP ≤3.28.0 has a CRITICAL flaw (CVSS 9.8) in RDP redirection — improper CRLF/control character validation exposes clients to HTTP header injection via proxies. Upgrade to 3.29.0+ now. radar.offseq.com/threat/freerd #OffSeq #FreeRDP #CVE202667289 #infosec

##

thehackerwire@mastodon.social at 2026-08-02T02:59:59.000Z ##

🔴 CVE-2026-67289 - Critical (9.8)

FreeRDP before 3.29.0 (affected versions &lt;= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client&#039;s ServerHostname and, when the client c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66402
(9.8 CRITICAL)

EPSS: 0.29%

updated 2026-08-01T15:30:25

4 posts

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name and DNS SAN string matching instead of using OpenSSL's length-aware identity validation APIs, it (1) truncates DNS SAN values at embedded NUL bytes (accepti

offseq at 2026-08-02T09:00:24.530Z ##

CVE-2026-66402: FreeRDP <=3.28.0 suffers CRITICAL TLS cert validation flaws. Attackers can bypass server identity checks — risk of MITM & impersonation. Patch to 3.29.0 ASAP. 🔒 radar.offseq.com/threat/freerd

##

thehackerwire@mastodon.social at 2026-08-02T02:00:39.000Z ##

🔴 CVE-2026-66402 - Critical (9.8)

FreeRDP before 3.29.0 (affected versions &lt;= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-02T09:00:24.000Z ##

CVE-2026-66402: FreeRDP <=3.28.0 suffers CRITICAL TLS cert validation flaws. Attackers can bypass server identity checks — risk of MITM & impersonation. Patch to 3.29.0 ASAP. 🔒 radar.offseq.com/threat/freerd #OffSeq #Vulnerability #TLS #FreeRDP

##

thehackerwire@mastodon.social at 2026-08-02T02:00:39.000Z ##

🔴 CVE-2026-66402 - Critical (9.8)

FreeRDP before 3.29.0 (affected versions &lt;= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67288
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-01T15:30:25

2 posts

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process

thehackerwire@mastodon.social at 2026-08-02T02:59:50.000Z ##

🟠 CVE-2026-67288 - High (7.5)

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T02:59:50.000Z ##

🟠 CVE-2026-67288 - High (7.5)

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67352
(7.6 HIGH)

EPSS: 0.21%

updated 2026-08-01T13:17:05.860000

3 posts

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is rendered as raw HTML and executes JavaScript in the administrator's browser origin.

hugovalters@mastodon.social at 2026-08-02T18:06:08.000Z ##

CVE-2026-67352 - Stored XSS in Luci-App-Https-Dns-Proxy. Resolver_url injects HTML, runs JS in admin's browser. CVSS 7.6. No patch yet; restrict access. #CVE #infosec #XSS

valtersit.com/cve/CVE-2026-673

##

thehackerwire@mastodon.social at 2026-08-01T15:01:10.000Z ##

🟠 CVE-2026-67352 - High (7.6)

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is ren...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T15:01:10.000Z ##

🟠 CVE-2026-67352 - High (7.6)

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is ren...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67341
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-08-01T13:17:05.273000

4 posts

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, bypassing security controls intended to restrict scripting to administrators.

offseq at 2026-08-02T04:30:24.317Z ##

ArcadeDB (<26.7.2) hit by CRITICAL vuln (CVE-2026-67341, CVSS 9.3). Improper auth lets users with DB access execute arbitrary JS via DEFINE FUNCTION, bypassing admin-only restrictions. Restrict access, monitor usage, check for patches. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-01T15:00:14.000Z ##

🔴 CVE-2026-67341 - Critical (9.8)

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, by...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-02T04:30:24.000Z ##

ArcadeDB (<26.7.2) hit by CRITICAL vuln (CVE-2026-67341, CVSS 9.3). Improper auth lets users with DB access execute arbitrary JS via DEFINE FUNCTION, bypassing admin-only restrictions. Restrict access, monitor usage, check for patches. radar.offseq.com/threat/cve-20 #OffSeq #CVE #infosec

##

thehackerwire@mastodon.social at 2026-08-01T15:00:14.000Z ##

🔴 CVE-2026-67341 - Critical (9.8)

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, by...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67330
(9.9 CRITICAL)

EPSS: 0.35%

updated 2026-08-01T13:17:03.677000

2 posts

@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic OAuth, or social account providers, and the same logical provider ID was used for both SCIM provider configuration and account ownership. An

thehackerwire@mastodon.social at 2026-08-01T18:00:31.000Z ##

🔴 CVE-2026-67330 - Critical (9.9)

@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through = 1.7.0-beta.0 through &lt;= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T18:00:31.000Z ##

🔴 CVE-2026-67330 - Critical (9.9)

@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through = 1.7.0-beta.0 through &lt;= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67322
(7.5 HIGH)

EPSS: 0.27%

updated 2026-08-01T13:17:02.493000

2 posts

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking git clone. An attacker who controls the clone URL can embed $NAME or ${NAME} tokens that are expanded to the values of the hosting process's environment

thehackerwire@mastodon.social at 2026-08-01T20:00:18.000Z ##

🟠 CVE-2026-67322 - High (7.5)

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T20:00:18.000Z ##

🟠 CVE-2026-67322 - High (7.5)

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67300
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-01T13:16:59.393000

2 posts

FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends crafted update orders, the message proxy shallow-copies structures containing nested parser-owned pointers (e.g., titleInfo.string, windowRects, visibili

thehackerwire@mastodon.social at 2026-08-01T23:00:21.000Z ##

🟠 CVE-2026-67300 - High (7.5)

FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-01T23:00:21.000Z ##

🟠 CVE-2026-67300 - High (7.5)

FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67297
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-01T13:16:58.967000

3 posts

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.

hugovalters@mastodon.social at 2026-08-02T12:06:48.000Z ##

CVE-2026-67297 - DoS in FreeRDP before 3.29.0. Malicious RD Gateway can send oversized chunked HTTP responses, exhausting client memory. CVSS 7.5. Unpatched - monitor for updates. #CVE #FreeRDP #infosec

valtersit.com/cve/CVE-2026-672

##

thehackerwire@mastodon.social at 2026-08-02T02:00:29.000Z ##

🟠 CVE-2026-67297 - High (7.5)

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T02:00:29.000Z ##

🟠 CVE-2026-67297 - High (7.5)

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67296
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-01T13:16:58.830000

2 posts

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.

thehackerwire@mastodon.social at 2026-08-02T02:00:20.000Z ##

🟠 CVE-2026-67296 - High (7.5)

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T02:00:20.000Z ##

🟠 CVE-2026-67296 - High (7.5)

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16635
(8.8 HIGH)

EPSS: 0.31%

updated 2026-08-01T09:30:37

2 posts

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed->user_role_field_id]`) directly into `WP_User::set_role()` without any allowlist validation, capability comparison, or permission check to constrain whic

hugovalters@mastodon.social at 2026-08-02T11:12:03.000Z ##

CVE-2026-16635 - Privilege Escalation in Pronamic Pay WordPress plugin. Auth Subscriber+ can set any role via Gravity Forms. CVSS 8.8. Unpatched - disable or restrict until fix. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-166

##

thehackerwire@mastodon.social at 2026-08-01T11:00:53.000Z ##

🟠 CVE-2026-16635 - High (8.8)

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed-...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16144
(8.1 HIGH)

EPSS: 0.69%

updated 2026-08-01T09:30:37

2 posts

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder, allowing attacker-controlled strings to reach call_user_func() in _save_data(). This

hugovalters@mastodon.social at 2026-08-01T23:03:24.000Z ##

CVE-2026-16144 - Critical RCE in Kali Forms WordPress plugin. Unauthenticated code execution via call_user_func. CVSS 8.1. No patch available - disable plugin now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-161

##

thehackerwire@mastodon.social at 2026-08-01T11:00:42.000Z ##

🟠 CVE-2026-16144 - High (8.1)

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15964
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-08-01T09:30:37

2 posts

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopriv_ssoprocess_ajax` and therefore reachable without authentication — accepting an attacker-supplied `email` parameter with the `setnewpassword` operation an

1 repos

https://github.com/Instructor-Admin/CVE-2026-15964-PoC

thehackerwire@mastodon.social at 2026-08-01T10:59:52.000Z ##

🔴 CVE-2026-15964 - Critical (9.8)

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-01T10:30:25.000Z ##

CRITICAL: CVE-2026-15964 in britcoder Single Sign On For TNG <=2.0.0 lets unauthenticated attackers reset any WP user password via exposed AJAX. Full site takeover possible. Disable or restrict access now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE #Vuln

##

CVE-2026-15988
(8.8 HIGH)

EPSS: 0.22%

updated 2026-08-01T09:30:36

2 posts

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_authorize function. This makes it possible for unauthenticated attackers to create new administrator accounts with attacker-supplied credentials via a CSRF-ba

hugovalters@mastodon.social at 2026-08-01T18:06:37.000Z ##

CVE-2026-15988 - CSRF in AI Engine WordPress plugin enables attacker to create admin accounts via REST auth bypass. CVSS 8.8. Unpatched - disable plugin now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-159

##

thehackerwire@mastodon.social at 2026-08-01T13:00:08.000Z ##

🟠 CVE-2026-15988 - High (8.8)

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_aut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15450
(8.1 HIGH)

EPSS: 0.38%

updated 2026-08-01T09:30:36

1 posts

The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from the database and passing it directly to unlink() with no validation (no realpath(), basename(), or allowlist check), combined with the insert_record() AJAX han

thehackerwire@mastodon.social at 2026-08-01T11:01:04.000Z ##

🟠 CVE-2026-15450 - High (8.1)

The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14561(CVSS UNKNOWN)

EPSS: 0.14%

updated 2026-08-01T09:30:36

1 posts

The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidential, returning the code and a valid verification token in the response of an unauthenticated action, allowing unauthenticated attackers to log in as any user whose registered mobile number they know (including administrators) or to create arbitrary accounts.

offseq@infosec.exchange at 2026-08-01T07:30:25.000Z ##

CVE-2026-14561 | CRITICAL | Authora: Easy login with mobile number (WordPress <1.7.7) suffers from improper authentication — attackers can log in as any user if they know a mobile number. Restrict plugin endpoints & monitor logins. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

CVE-2026-64531
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-01T08:16:29.920000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guar

3 repos

https://github.com/suominen/ovswrap

https://github.com/mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool

https://github.com/0xBlackash/CVE-2026-64531

tugatech@masto.pt at 2026-07-31T09:36:37.000Z ##

Falha OVSwrap ameaça servidores Linux com acesso root e já tem exploit público. Uma vulnerabilidade crítica no kernel do Linux, batizada de OVSwrap (CVE-2026-64531), permite que utilizadores locais sem privilégios obtenham acesso total de root. 🚨

🔗 tugatech.com.pt/t88334-falha-o

#exploit #falha #linux #root 

##

CVE-2026-15368
(0 None)

EPSS: 0.14%

updated 2026-08-01T07:16:31.477000

1 posts

The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly created account, allowing unauthenticated attackers to obtain an authenticated session for an arbitrary existing user, including administrators, on sites using a supported but non-default configuration.

offseq@infosec.exchange at 2026-08-01T09:00:23.000Z ##

CVE-2026-15368: User Profile Builder WP plugin (CRITICAL) allows session hijack as any user — including admins — if using specific non-default configs. Review settings, restrict auto-login, and monitor for fixes. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #CVE202615368 🔒

##

CVE-2026-3141
(9.1 CRITICAL)

EPSS: 0.47%

updated 2026-08-01T06:16:26.030000

2 posts

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to the REST API route being registered without any authentication middleware in routes/rest/api.php. This makes it possible for unauthenticated attackers to

1 repos

https://github.com/Rat5ak/CVE-2026-31413-BPF-Container-Escape

thehackerwire@mastodon.social at 2026-08-01T13:00:18.000Z ##

🔴 CVE-2026-3141 - Critical (9.1)

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-01T06:00:23.000Z ##

CVE-2026-3141 (CRITICAL, CVSS 9.1): wpwax FormGent for WordPress lets unauthenticated users delete arbitrary files via REST API. Linux servers risk full takeover if wp-config.php is deleted. Patch or restrict access now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE20263141

##

CVE-2026-20316
(5.3 MEDIUM)

EPSS: 0.79%

updated 2026-08-01T05:16:55.973000

9 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vu

cyberveille@mastobot.ping.moi at 2026-08-02T18:00:06.000Z ##

📢 CISA ajoute CVE-2026-20316 (Cisco FMC) à son catalogue KEV — exploitation active confirmée

Le 30 juillet 2026, le site Security Affairs (Pierluigi Paganini) rapporte que la CISA (Cybersecurity and Infrastructure Security Agency) a ajouté la vulnérabilité CVE-2026-20316 au catalogue Known Exploited Vulnerabilities (KEV). Cisco a confirmé une…

📖 cyberveille : cyberveille.ch/posts/2026-08-0
🌐 source : securityaffairs.com/196289/sec
🟡 vérification factuelle moyenne
#CiscoFMC #CISAKEV #Cyberveille

##

cyberveille@mastobot.ping.moi at 2026-08-02T18:00:06.000Z ##

📢 Cisco FMC : vulnérabilité zero-day CVE-2026-20316 activement exploitée et CVE-2026-20079 critique patchée

📰 Source : BleepingComputer, publié le 29 juillet 2026. Cisco émet une alerte concernant deux vulnérabilités affectant son produit Cisco Secure Firewall Management Center (FMC). 🔴 CVE-2026-20316 — Credentials statiques (CVSS 5.3, sévérité High) Une…

📖 cyberveille : cyberveille.ch/posts/2026-08-0
🌐 source : bleepingcomputer.com/news/secu
🟡 vérification factuelle moyenne
#CiscoFMC #ZeroDay #Cyberveille

##

i_ball at 2026-08-01T14:55:34.473Z ##

What year is it?:

nvd.nist.gov/vuln/detail/CVE-2

##

i_ball@infosec.exchange at 2026-08-01T14:55:34.000Z ##

What year is it?:

nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-07-31T16:19:58.000Z ##

There are two new advisories from Cisco, one addressing a critical vulnerability that was first published on March 4:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

The second is a high-severity vulnerability that was first published yesterday:

CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #vulnerability #Cisco

##

thecybermind@infosec.exchange at 2026-07-31T13:34:04.000Z ##

Executive alert: CVE-2026-20316 exposes Cisco Secure Firewall Management Center to active exploitation via hard-coded credentials. Review enterprise exposure metrics, zero-trust segmentation, and board-level risk mitigation strategies today. thecybermind.co/jily

##

oversecurity@mastodon.social at 2026-07-31T10:12:18.000Z ##

CVE-2026-20316 Zero-Day Actively Exploited, Cisco Releases Fix

Cisco has released security updates for an actively exploited zero-day vulnerability, CVE-2026-20316, affecting Cisco Secure FMC (Secure Firewall...

🔗️ [Thecyberexpress] link.is.it/FLOu9T

##

thecybermind@infosec.exchange at 2026-07-31T07:21:09.000Z ##

Critical advisory: CVE-2026-20316 exposes Cisco Secure Firewall Management Center to hard-coded credential abuse. Review active threat vectors, network access lockdowns, and system hardening playbooks to protect your perimeter. thecybermind.co/bkur

##

Bied@digitalhub.social at 2026-07-30T19:33:28.000Z ##

#Cisco - "We Never Learn". 🔥

Warum ein Konzern es noch immer notwendig findet eine #Backdoor in seine Produkte einzubauen ist mir völlig schleierhaft. 🙈

"Da CVE-2026-20316 bereits aktiv ausgenutzt wird, rät Cisco Administratoren, ihre FMC-Instanzen dringend zu aktualisieren."

"Gibt es Abhilfe?

"Die genannten Hotfix-Updates bessern auch bezüglich einer seit März bekannten kritischen Lücke (CVSS: 10) nach, mit der sich die Authentifizierung im Web-Interface von FMC umgehen lässt. Diese Lücke ist als CVE-2026-20079 registriert und verleiht Angreifern sogar einen direkten Root-Zugriff auf das zugrundeliegende Betriebssystem. "

Klar, eine Firewall ist ja nur zum Schutz der Kunden vorhanden, da kann man schon mal auch Kriminelle einladen, oder? 🤢

So eine persönliche Haftung des CEO und eine Strafe ab 5 % vom Konzernumsatz könnte möglicherweise zu einer Änderungen führen:

So stelle ich mir die Anweisung des CEO vor: 👍

"Ab sofort ist die Nutzung (auch während der Entwicklung) von Backdoors untersagt. Wer sich nicht daran hält wird fristlos entlassen und haftet für Schäden."

Und, natürlich sollte die Qualitätssicherung vorab prüfen ob die Entwickler sich auch daran halten. 😁

Es gibt erfahrene Spezialisten die gerne bei der Auswahl der Geräte helfen und für mehr Sicherheit sorgen. Einfach anfragen, dann weiß man mehr. 🙂

golem.de/news/kodierte-zugangs

#Backdoor

##

CVE-2026-17566
(9.9 CRITICAL)

EPSS: 0.43%

updated 2026-08-01T05:16:55.827000

2 posts

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wrapper, create_import_export_job() (route POST /import_export/job/<sid>, gated only by the ordinary, commonly-granted tools_import_export_data permission)

hugovalters@mastodon.social at 2026-08-01T15:04:27.000Z ##

CVE-2026-17566 - Critical RCE in pgAdmin 4. Import/Export Data tool allows command injection via crafted SQL. CVSS 9.9. Unpatched - restrict access immediately. #CVE #pgAdmin #infosec

valtersit.com/cve/CVE-2026-175

##

thehackerwire@mastodon.social at 2026-07-31T17:00:30.000Z ##

🔴 CVE-2026-17566 - Critical (9.9)

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15006
(7.5 HIGH)

EPSS: 0.83%

updated 2026-08-01T03:31:19

2 posts

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

thehackerwire@mastodon.social at 2026-08-01T13:00:29.000Z ##

🟠 CVE-2026-15006 - High (7.5)

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-01T04:30:24.000Z ##

CVE-2026-15006: Bit integrations plugin ≤2.9.0 for WordPress has a HIGH severity path traversal flaw (CVSS 7.5). Unauthenticated attackers can read arbitrary server files. No patch yet — disable or restrict plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

CVE-2026-15414
(8.8 HIGH)

EPSS: 0.34%

updated 2026-08-01T03:16:25.757000

2 posts

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$_POST` without an allowlist that excludes privileged roles — the only validations applied, `sanitize_key()` and `wp_roles()->is_role()`, both accept `'ad

thehackerwire@mastodon.social at 2026-08-02T03:59:48.000Z ##

🟠 CVE-2026-15414 - High (8.8)

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T03:59:48.000Z ##

🟠 CVE-2026-15414 - High (8.8)

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-34641
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-01T00:31:02

2 posts

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

thehackerwire@mastodon.social at 2026-08-02T03:59:57.000Z ##

🟠 CVE-2026-34641 - High (7.8)

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T03:59:57.000Z ##

🟠 CVE-2026-34641 - High (7.8)

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68771
(9.8 CRITICAL)

EPSS: 0.62%

updated 2026-08-01T00:30:56

3 posts

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via the unauthenticated POST /upload/image endpoint and then queue a workflow graph via POST /prompt ref

hugovalters@mastodon.social at 2026-08-01T17:11:42.000Z ##

CVE-2026-68771 - Critical RCE in ComfyUI. Unsafe deserialization in LoadTrainingDataset. CVSS 9.8. No patch; stop using /upload/image and /prompt. #CVE #ComfyUI #infosec

valtersit.com/cve/CVE-2026-687

##

thehackerwire@mastodon.social at 2026-07-31T23:00:42.000Z ##

🔴 CVE-2026-68771 - Critical (9.8)

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. A...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-31T22:30:29.000Z ##

CVE-2026-68771: CRITICAL RCE in ComfyUI v0.23.0. Unauthenticated remote attackers can exploit unsafe pickle deserialization via /upload/image, leading to code execution as the process user. Restrict access & monitor endpoints. radar.offseq.com/threat/cve-20 #OffSeq #CVE202668771 #infosec

##

CVE-2026-63223
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-08-01T00:17:17.750000

4 posts

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads in a web-accessible script-enabled directory. Applications are impacted when they validate uploads u

thehackerwire@mastodon.social at 2026-08-02T17:59:58.000Z ##

🔴 CVE-2026-63223 - Critical (9.8)

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an applicat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T17:59:58.000Z ##

🔴 CVE-2026-63223 - Critical (9.8)

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an applicat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

AmmarSpaces@infosec.exchange at 2026-07-31T10:51:10.000Z ##

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

#cybersecurity #infosec #codeigniter #vulnerability

##

DailyCyberSecurity@infosec.exchange at 2026-07-31T09:19:52.000Z ##

CVE-2026-63223: CodeIgniter4 RCE Vulnerability Rated CVSS 9.8

securityonline.info/codeignite

##

CVE-2026-53500
(8.2 HIGH)

EPSS: 0.29%

updated 2026-08-01T00:17:16.713000

1 posts

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. This issue is fixed in 7.8.0.

thehackerwire@mastodon.social at 2026-07-31T23:01:00.000Z ##

🟠 CVE-2026-53500 - High (8.2)

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. This issu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14319
(7.5 HIGH)

EPSS: 0.32%

updated 2026-07-31T21:32:56

2 posts

The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their name and subscription details.

thehackerwire@mastodon.social at 2026-08-02T16:00:39.000Z ##

🟠 CVE-2026-14319 - High (7.5)

The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their n...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T16:00:39.000Z ##

🟠 CVE-2026-14319 - High (7.5)

The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their n...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68770
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-07-31T21:32:05

2 posts

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guard condition includes an 'or os.path.exists(model_name_or_path)' clause that satisfies the trust gate whenever the supplied path exists on the local files

offseq@infosec.exchange at 2026-08-01T00:00:35.000Z ##

CVE-2026-68770: Hugging Face sentence-transformers (all versions) impacted by CRITICAL code injection vuln. Local model dirs with malicious files can bypass trust_remote_code=False — arbitrary Python execution possible. Awaiting patch. radar.offseq.com/threat/cve-20 #OffSeq #CVE #AIsecurity

##

thehackerwire@mastodon.social at 2026-07-31T22:00:02.000Z ##

🔴 CVE-2026-68770 - Critical (9.8)

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67822
(9.8 CRITICAL)

EPSS: 0.29%

updated 2026-07-31T21:31:55

2 posts

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.

thehackerwire@mastodon.social at 2026-08-02T06:59:50.000Z ##

🔴 CVE-2026-67822 - Critical (9.8)

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without leng...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T06:59:50.000Z ##

🔴 CVE-2026-67822 - Critical (9.8)

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without leng...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14930
(7.5 HIGH)

EPSS: 0.24%

updated 2026-07-31T21:31:54

2 posts

The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users' support tickets.

thehackerwire@mastodon.social at 2026-08-02T13:00:42.000Z ##

🟠 CVE-2026-14930 - High (7.5)

The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T13:00:42.000Z ##

🟠 CVE-2026-14930 - High (7.5)

The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62999
(7.5 HIGH)

EPSS: 0.29%

updated 2026-07-31T20:16:53.523000

1 posts

Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an HTTP server or Git transport decodes the path, allowing unsafe template features from a repository outside the trusted prefix to run after user interaction. This

thehackerwire@mastodon.social at 2026-07-31T20:59:51.000Z ##

🟠 CVE-2026-62999 - High (7.5)

Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an HTTP serv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56673
(7.5 HIGH)

EPSS: 0.43%

updated 2026-07-31T20:16:52.487000

2 posts

ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without a containment check, allowing an unauthenticated crafted POST /prompt workflow using LoadImage or sibling nodes to probe arbitrary host paths and exfilt

thehackerwire@mastodon.social at 2026-08-02T19:00:09.000Z ##

🟠 CVE-2026-56673 - High (7.5)

ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T19:00:09.000Z ##

🟠 CVE-2026-56673 - High (7.5)

ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18358
(7.5 HIGH)

EPSS: 0.43%

updated 2026-07-31T20:16:49.663000

1 posts

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations

thehackerwire@mastodon.social at 2026-07-31T14:00:26.000Z ##

🟠 CVE-2026-18358 - High (7.5)

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17561
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-07-31T20:16:49.313000

3 posts

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.108.

offseq@infosec.exchange at 2026-08-01T03:00:26.000Z ##

CVE-2026-17561: CRITICAL code injection vuln in Logsign SIEM <6.4.108 (CVSS 9.8). Allows unauthenticated RCE — full compromise possible. No patch confirmed. Restrict mgmt access pending fix. radar.offseq.com/threat/improp #OffSeq #infosec #SIEM #vuln

##

thehackerwire@mastodon.social at 2026-07-31T14:00:16.000Z ##

🔴 CVE-2026-17561 - Critical (9.8)

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection.

This issue affects Logsign SIEM: before 6.4.108.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-31T14:00:25.000Z ##

CVE-2026-17561: Logsign SIEM <6.4.108 faces CRITICAL code injection (CWE-94, CVSS 9.8). Exploitable remotely, no patch yet. Full system compromise possible. Monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202617561 #SIEM #Vuln #BlueTeam

##

CVE-2026-15258
(8.1 HIGH)

EPSS: 0.22%

updated 2026-07-31T20:16:48.207000

2 posts

The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.

thehackerwire@mastodon.social at 2026-08-02T12:00:07.000Z ##

🟠 CVE-2026-15258 - High (8.1)

The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL inje...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T12:00:07.000Z ##

🟠 CVE-2026-15258 - High (8.1)

The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL inje...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15048
(7.5 HIGH)

EPSS: 0.26%

updated 2026-07-31T20:16:47.790000

2 posts

The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.

thehackerwire@mastodon.social at 2026-08-02T13:00:52.000Z ##

🟠 CVE-2026-15048 - High (7.5)

The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T13:00:52.000Z ##

🟠 CVE-2026-15048 - High (7.5)

The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53599
(7.5 HIGH)

EPSS: 0.31%

updated 2026-07-31T19:43:51

1 posts

## Summary `rex_mediapool::isAllowedExtension` in `redaxo/src/addons/mediapool/lib/mediapool.php` accepts filenames that contain a blocked extension as a non-terminal segment of a longer extension chain, for example `shell.php.any.jpg`. The check only catches the blocked extension when it appears at the end of the filename or immediately before the final extension. An authenticated backend user

thehackerwire@mastodon.social at 2026-07-31T21:00:10.000Z ##

🟠 CVE-2026-53599 - High (7.5)

REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/PHP polygl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53510
(8.1 HIGH)

EPSS: 0.40%

updated 2026-07-31T19:38:26

1 posts

### Impact `Savon::Model` generated SOAP operation methods by interpolating operation names into Ruby source passed to `module_eval`. An attacker who can control the operation names of a WSDL, can inject Ruby code that executes in the application process. This affects only the `.all_operations` class method provided by `Savon::Model` to automatically register all operations provided by the WSDL.

thehackerwire@mastodon.social at 2026-07-31T21:00:01.000Z ##

🟠 CVE-2026-53510 - High (8.1)

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54725
(9.6 CRITICAL)

EPSS: 0.32%

updated 2026-07-31T19:17:10.833000

3 posts

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in pkg/webhook/webhook.go, and vault.security.banzaicloud.io/vault-serviceaccount can cause a ServiceAccount JW

thehackerwire@mastodon.social at 2026-08-02T05:00:14.000Z ##

🔴 CVE-2026-54725 - Critical (9.6)

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T05:00:14.000Z ##

🔴 CVE-2026-54725 - Critical (9.6)

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-31T19:30:25.000Z ##

bank-vaults vault-secrets-webhook is impacted by CVE-2026-54725 (CRITICAL, CVSS 9.6). SSRF flaw lets attackers exfiltrate ServiceAccount JWTs via attacker-controlled Vault addresses. Update to 1.23.1 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Kubernetes #SSRF #CloudSecurity

##

CVE-2026-52856
(7.5 HIGH)

EPSS: 0.34%

updated 2026-07-31T19:17:09.120000

2 posts

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.

thehackerwire@mastodon.social at 2026-08-02T07:00:09.000Z ##

🟠 CVE-2026-52856 - High (7.5)

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T07:00:09.000Z ##

🟠 CVE-2026-52856 - High (7.5)

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18141
(8.2 HIGH)

EPSS: 0.25%

updated 2026-07-31T19:17:08.053000

1 posts

A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The system also inadvertently discloses the expected certificate subject in error me

thehackerwire@mastodon.social at 2026-07-31T17:00:21.000Z ##

🟠 CVE-2026-18141 - High (8.2)

A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by ma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53505
(7.5 HIGH)

EPSS: 0.34%

updated 2026-07-31T19:00:45

2 posts

### Summary Thumbor's `filters:proportion(<value>)` filter does not enforce an upper bound on `<value>` and runs in the post-transform phase. An attacker can trigger extremely large resizes (CPU/memory exhaustion) and cause denial of service. ### Details - Filter implementation: `thumbor/filters/proportion.py` - `value` is parsed as a float (`BaseFilter.DecimalNumber`) with no maximum. - The

hugovalters@mastodon.social at 2026-08-01T14:11:07.000Z ##

CVE-2026-53505 - DoS in Thumbor. Unbounded proportion filter causes CPU/memory exhaustion. CVSS 7.5. Update to 7.8.0 immediately. #CVE #Thumbor #infosec

valtersit.com/cve/CVE-2026-535

##

thehackerwire@mastodon.social at 2026-07-31T23:00:51.000Z ##

🟠 CVE-2026-53505 - High (7.5)

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion() filter does not enforce an upper bound on and runs in the post-transform phase. An attacker can trigger extremely large resizes (CPU/me...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53504
(7.5 HIGH)

EPSS: 0.34%

updated 2026-07-31T18:58:29

2 posts

### Summary The regular expression used to parse the `convolution` filter exhibits exponential-time backtracking for certain inputs, enabling a Regular Expression Denial of Service (ReDoS). ### Details The RegExp for `convolution` is defined as `convolution\((?:\s*((?:[-]?[\d]+\.?[\d]*[;])*(?:[-]?[\d]+\.?[\d]*))\s*)(?:,\s*([\d]+)\s*)(?:,\s*([Tt]rue|[Ff]alse|1|0)\s*)?\)`. Within this expression a

thehackerwire@mastodon.social at 2026-08-02T05:00:05.000Z ##

🟠 CVE-2026-53504 - High (7.5)

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time. This ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T05:00:05.000Z ##

🟠 CVE-2026-53504 - High (7.5)

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time. This ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53503
(7.5 HIGH)

EPSS: 0.42%

updated 2026-07-31T18:54:57

2 posts

### Summary Thumbor's `filters:convolution(<matrix>, <columns>, <should_normalize>)` filter passes the user-controlled `<columns>` value to a C extension (`thumbor/ext/filters/_convolution.c`) where it is used as a divisor (for `%` and `/`) without validating `columns > 0`. When `columns=0`, the C code triggers undefined behavior; on x86_64 this reliably results in a fatal divide-by-zero trap (SIG

thehackerwire@mastodon.social at 2026-08-02T04:59:54.000Z ##

🟠 CVE-2026-53503 - High (7.5)

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(, , ) filter passes the user-controlled value to a C extension (thumbor/ext/filters/_convolution.c) where it is used as a divisor (for %...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T04:59:54.000Z ##

🟠 CVE-2026-53503 - High (7.5)

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(, , ) filter passes the user-controlled value to a C extension (thumbor/ext/filters/_convolution.c) where it is used as a divisor (for %...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53501
(8.2 HIGH)

EPSS: 0.21%

updated 2026-07-31T18:51:54

2 posts

# HMAC validation bypass via multiple `.replace()` calls when removing URL signature ## Summary Thumbor’s HMAC validation can be bypassed due to the use of Python’s `.replace()` when removing the signature from the URL before validation. Since `.replace()` removes **all occurrences** of the substring, an attacker can insert the same signature multiple times in the URL and manipulate the final UR

thehackerwire@mastodon.social at 2026-08-02T04:00:08.000Z ##

🟠 CVE-2026-53501 - High (8.2)

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() remove...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T04:00:08.000Z ##

🟠 CVE-2026-53501 - High (8.2)

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() remove...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62391
(8.1 HIGH)

EPSS: 0.40%

updated 2026-07-31T18:33:21

2 posts

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. This issue affects Apache Kyuubi: from 1.6.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which fixes the issue.

thehackerwire@mastodon.social at 2026-08-02T11:00:04.000Z ##

🟠 CVE-2026-62391 - High (8.1)

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.

This issue ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T11:00:04.000Z ##

🟠 CVE-2026-62391 - High (8.1)

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.

This issue ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12695
(8.1 HIGH)

EPSS: 0.29%

updated 2026-07-31T18:33:20

2 posts

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's password to bypass two-factor authentication and gain access to the victim's account, including administrators.

thehackerwire@mastodon.social at 2026-08-02T17:00:32.000Z ##

🟠 CVE-2026-12695 - High (8.1)

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T17:00:32.000Z ##

🟠 CVE-2026-12695 - High (8.1)

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12251
(8.1 HIGH)

EPSS: 0.23%

updated 2026-07-31T18:33:20

2 posts

The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default, allowing unauthenticated users to register with a site-defined role that carries administrator capabilities and gain administrative access, when such a

thehackerwire@mastodon.social at 2026-08-02T17:00:22.000Z ##

🟠 CVE-2026-12251 - High (8.1)

The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T17:00:22.000Z ##

🟠 CVE-2026-12251 - High (8.1)

The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12721
(8.6 HIGH)

EPSS: 0.26%

updated 2026-07-31T18:33:20

2 posts

The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

thehackerwire@mastodon.social at 2026-08-02T15:00:53.000Z ##

🟠 CVE-2026-12721 - High (8.6)

The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T15:00:53.000Z ##

🟠 CVE-2026-12721 - High (8.6)

The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17349
(9.6 CRITICAL)

EPSS: 0.30%

updated 2026-07-31T18:32:25

2 posts

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, shared, shared_username, and the stored credential fields password, save_password, and tunnel_password. When a non-owner triggered an adhoc connect against

thehackerwire@mastodon.social at 2026-08-02T07:59:54.000Z ##

🔴 CVE-2026-17349 - Critical (9.6)

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, sh...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T07:59:54.000Z ##

🔴 CVE-2026-17349 - Critical (9.6)

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, sh...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17346
(8.8 HIGH)

EPSS: 0.43%

updated 2026-07-31T18:32:24

2 posts

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorrect assumption that schema, table, publication, and subscription names sourced from pg_catalog via the browser tree could never contain an apostrophe. Po

thehackerwire@mastodon.social at 2026-08-02T08:00:13.000Z ##

🟠 CVE-2026-17346 - High (8.8)

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T08:00:13.000Z ##

🟠 CVE-2026-17346 - High (8.8)

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17351
(9.0 None)

EPSS: 0.45%

updated 2026-07-31T18:32:24

2 posts

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's string-literal lexing can disagree with PostgreSQL's own parser: under standard_conforming_strings = on (PostgreSQL's defau

1 repos

https://github.com/Hunt-Benito/pgadmin-ai-assistant-sql-injection-cve-2026-17351-lexer-differential-bypass

thehackerwire@mastodon.social at 2026-08-02T08:00:03.000Z ##

🔴 CVE-2026-17351 - Critical (9)

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T08:00:03.000Z ##

🔴 CVE-2026-17351 - Critical (9)

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17347
(7.5 HIGH)

EPSS: 0.27%

updated 2026-07-31T18:32:24

1 posts

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username directly into the command string and executed the result with subprocess.Popen(..., shell=True). Because the username can

thehackerwire@mastodon.social at 2026-07-31T17:00:41.000Z ##

🟠 CVE-2026-17347 - High (7.5)

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implement...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13609
(8.8 HIGH)

EPSS: 0.25%

updated 2026-07-31T18:32:17

2 posts

The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthenticated visitor is therefore stored as a live tag and later output without escaping on the Frontend Admin by DynamiApps WordPress plugin before 3.29.9'

thehackerwire@mastodon.social at 2026-08-02T16:00:29.000Z ##

🟠 CVE-2026-13609 - High (8.8)

The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T16:00:29.000Z ##

🟠 CVE-2026-13609 - High (8.8)

The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14919
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-07-31T18:32:17

2 posts

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control and take over the administrator account.

thehackerwire@mastodon.social at 2026-08-02T15:00:43.000Z ##

🔴 CVE-2026-14919 - Critical (9.8)

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to red...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T15:00:43.000Z ##

🔴 CVE-2026-14919 - Critical (9.8)

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to red...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18446
(7.5 HIGH)

EPSS: 0.22%

updated 2026-07-31T18:17:13.383000

2 posts

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward slash) is parsed with no authority and folds into the path. Node's native WHATWG URL parser instead treats a backslash as interchangeable with a forward

thehackerwire@mastodon.social at 2026-08-02T10:59:54.000Z ##

🟠 CVE-2026-18446 - High (7.5)

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T10:59:54.000Z ##

🟠 CVE-2026-18446 - High (7.5)

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12720
(7.5 HIGH)

EPSS: 0.30%

updated 2026-07-31T18:17:10.337000

2 posts

The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. With a suitable gadget chain present on the site (via another installed Kirki WordPress plugin before 6.0.13, , or an outdated WordPress v

thehackerwire@mastodon.social at 2026-08-02T17:59:49.000Z ##

🟠 CVE-2026-12720 - High (7.5)

The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T17:59:49.000Z ##

🟠 CVE-2026-12720 - High (7.5)

The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10685
(7.6 HIGH)

EPSS: 0.18%

updated 2026-07-31T18:17:09.510000

3 posts

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called params->notify(conn, params, NULL, 0). Per the public GATT API, a notify callback with NULL data is the documented signal that the subscription has terminated and the bt_gatt_subscribe_params struct may

thehackerwire@mastodon.social at 2026-08-02T08:59:50.000Z ##

🟠 CVE-2026-10685 - High (7.6)

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called params->notify(conn, params, NULL, 0).

Per the pub...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T08:59:50.000Z ##

🟠 CVE-2026-10685 - High (7.6)

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called params->notify(conn, params, NULL, 0).

Per the pub...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-31T15:30:25.000Z ##

Zephyr Bluetooth GATT client (versions 2.4.0 to <4.5.0) faces a HIGH severity use-after-free (CVE-2026-10685) in gatt_write_ccc_rsp(). Risk: memory corruption, crash, or attacker-driven flow. Patch pending — apply mitigations. radar.offseq.com/threat/cve-20 #OffSeq #Zephyr #Bluetooth #CVE

##

CVE-2026-65310
(7.5 HIGH)

EPSS: 0.32%

updated 2026-07-31T17:16:34.750000

2 posts

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values and server configuration.

thehackerwire@mastodon.social at 2026-08-02T11:00:17.000Z ##

🟠 CVE-2026-65310 - High (7.5)

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration
of affected versions, exposes its data and configuration endpoint
without any authentication and permissive CORS on every response. An
unauthenticated attacker with network acce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T11:00:17.000Z ##

🟠 CVE-2026-65310 - High (7.5)

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration
of affected versions, exposes its data and configuration endpoint
without any authentication and permissive CORS on every response. An
unauthenticated attacker with network acce...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68500
(7.5 HIGH)

EPSS: 0.38%

updated 2026-07-31T16:52:41

1 posts

### Impact The shop payment webhook `POST /{_locale}/update-payment` (route `sylius_mollie_shop_payment_webhook`) accepts two independent, attacker-controlled parameters: `id` (the Mollie payment ID, verified against Mollie's API) and `orderId` (the Sylius order ID, read directly from the database). The handler never verifies that the Mollie payment belongs to the referenced order. An

thehackerwire@mastodon.social at 2026-07-30T22:00:19.000Z ##

🟠 CVE-2026-68500 - High (7.5)

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but doe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67594
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-07-31T16:17:11.793000

1 posts

Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any route in the API routing configuration. Attackers can invoke approximately 50 unprotected API endpoints to enumerate and provision servers, reset root pass

thehackerwire@mastodon.social at 2026-07-30T20:59:58.000Z ##

🔴 CVE-2026-67594 - Critical (9.8)

Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any ro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66420
(8.8 HIGH)

EPSS: 0.17%

updated 2026-07-31T16:17:10.740000

1 posts

MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within webserver.js when self-signed certificates are in use. Attackers can open cross-origin WebSocket connections to any of th

thehackerwire@mastodon.social at 2026-07-31T01:00:14.000Z ##

🟠 CVE-2026-66420 - High (8.8)

MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebSer...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65423
(8.8 HIGH)

EPSS: 0.60%

updated 2026-07-31T16:17:09.560000

1 posts

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write.

thehackerwire@mastodon.social at 2026-07-31T04:00:36.000Z ##

🟠 CVE-2026-65423 - High (8.8)

An integer overflow in the UA_Variant arrayDimensions product
computation in open62541 may allow a remote attacker to trigger an
out-of-bounds write.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63559
(7.5 HIGH)

EPSS: 0.43%

updated 2026-07-31T16:17:09.290000

1 posts

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information.

thehackerwire@mastodon.social at 2026-07-30T23:00:12.000Z ##

🟠 CVE-2026-63559 - High (7.5)

An integer overflow in the UA_Variant arrayDimensions product
computation in open62541 may allow a remote attacker to read
out-of-bounds heap memory, potentially disclosing sensitive information.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63222
(7.5 HIGH)

EPSS: 0.45%

updated 2026-07-31T16:17:08.903000

3 posts

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploaded content outside the intended directory when the application exposes an upload path. This issue is fixed in version 4.7.4.

thehackerwire@mastodon.social at 2026-08-02T18:59:49.000Z ##

🟠 CVE-2026-63222 - High (7.5)

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T18:59:49.000Z ##

🟠 CVE-2026-63222 - High (7.5)

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

AmmarSpaces@infosec.exchange at 2026-07-31T10:51:10.000Z ##

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

#cybersecurity #infosec #codeigniter #vulnerability

##

CVE-2026-52855
(9.9 CRITICAL)

EPSS: 0.27%

updated 2026-07-31T16:16:48

2 posts

### Impact **Type:** Exposure of sensitive information / insufficiently protected credentials leading to privilege escalation and full node compromise. Wings exposes its **entire** daemon configuration to the egg configuration-file templating engine. When Wings renders a server's configuration files, any `{{config.<path>}}` placeholder in a replacement value is resolved against the full marshall

thehackerwire@mastodon.social at 2026-08-02T06:59:59.000Z ##

🔴 CVE-2026-52855 - Critical (9.9)

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T06:59:59.000Z ##

🔴 CVE-2026-52855 - Critical (9.9)

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14830
(7.5 HIGH)

EPSS: 0.21%

updated 2026-07-31T15:33:52

2 posts

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without paying.

thehackerwire@mastodon.social at 2026-08-02T15:00:32.000Z ##

🟠 CVE-2026-14830 - High (7.5)

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without pa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T15:00:32.000Z ##

🟠 CVE-2026-14830 - High (7.5)

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without pa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14333
(7.5 HIGH)

EPSS: 0.30%

updated 2026-07-31T15:33:51

2 posts

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes.

thehackerwire@mastodon.social at 2026-08-02T16:00:52.000Z ##

🟠 CVE-2026-14333 - High (7.5)

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T16:00:52.000Z ##

🟠 CVE-2026-14333 - High (7.5)

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68502
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-07-31T15:18:01.563000

1 posts

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches data.get('value') to LazyOwnShell.one_cmd, reaching LazyOwnShell.do_cmd and subprocess.call(command, shell=True), allowing unauthenticated remote code execution in the C2 process. This issue is fixed in

thehackerwire@mastodon.social at 2026-07-30T22:00:28.000Z ##

🔴 CVE-2026-68502 - Critical (9.8)

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches data.get('value') to LazyOwnShell.one_cmd, reachi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63221
(9.4 CRITICAL)

EPSS: 0.38%

updated 2026-07-31T14:16:50.873000

3 posts

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values to be interpreted as SQL. This affects only the deleteBatch() code path. Regular delete() operations escape where() binds correctly. This issue is fixed i

thehackerwire@mastodon.social at 2026-08-02T18:00:08.000Z ##

🔴 CVE-2026-63221 - Critical (9.4)

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T18:00:08.000Z ##

🔴 CVE-2026-63221 - Critical (9.4)

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

AmmarSpaces@infosec.exchange at 2026-07-31T10:51:10.000Z ##

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

#cybersecurity #infosec #codeigniter #vulnerability

##

CVE-2026-10079
(8.5 HIGH)

EPSS: 0.17%

updated 2026-07-31T12:30:30

1 posts

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the workload as having empty UID, name and labels and namespace "default". This bypas

thehackerwire@mastodon.social at 2026-07-31T12:00:33.000Z ##

🟠 CVE-2026-10079 - High (8.5)

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to cr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11770
(7.5 HIGH)

EPSS: 0.51%

updated 2026-07-31T12:30:30

1 posts

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication

thehackerwire@mastodon.social at 2026-07-31T12:00:13.000Z ##

🟠 CVE-2026-11770 - High (7.5)

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56672
(8.2 HIGH)

EPSS: 0.24%

updated 2026-07-31T11:17:10.903000

2 posts

ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and access to browser-stored API tokens, settings, workflows, and authenticated-equivalent API calls. The handler used web.FileResponse(path), so an uploaded .h

thehackerwire@mastodon.social at 2026-08-02T18:59:58.000Z ##

🟠 CVE-2026-56672 - High (8.2)

ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and acc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T18:59:58.000Z ##

🟠 CVE-2026-56672 - High (8.2)

ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and acc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15722
(7.5 HIGH)

EPSS: 0.51%

updated 2026-07-31T11:17:04.833000

1 posts

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a repl

thehackerwire@mastodon.social at 2026-07-31T12:00:23.000Z ##

🟠 CVE-2026-15722 - High (7.5)

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds chec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18452
(10.0 CRITICAL)

EPSS: 0.43%

updated 2026-07-31T09:31:30

2 posts

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.

thehackerwire@mastodon.social at 2026-08-02T13:00:32.000Z ##

🔴 CVE-2026-18452 - Critical (10)

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T13:00:32.000Z ##

🔴 CVE-2026-18452 - Critical (10)

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16236
(8.8 HIGH)

EPSS: 0.63%

updated 2026-07-31T09:31:30

2 posts

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing authentication check on the REST API import endpoint. This makes it possible for auth

thehackerwire@mastodon.social at 2026-08-02T12:00:27.000Z ##

🟠 CVE-2026-16236 - High (8.8)

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficie...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T12:00:27.000Z ##

🟠 CVE-2026-16236 - High (8.8)

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficie...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65309
(7.5 HIGH)

EPSS: 0.15%

updated 2026-07-31T09:31:30

2 posts

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords.

thehackerwire@mastodon.social at 2026-08-02T11:59:58.000Z ##

🟠 CVE-2026-65309 - High (7.5)

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores
and transmits user passwords using a reversible format instead of a
one-way password hash. This allows an attacker able to read the
credential store or capture network traffic to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T11:59:58.000Z ##

🟠 CVE-2026-65309 - High (7.5)

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores
and transmits user passwords using a reversible format instead of a
one-way password hash. This allows an attacker able to read the
credential store or capture network traffic to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14483
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-07-31T09:31:25

2 posts

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly accessible I/O endpoint authenticated solely by static, plugin-seeded API credentials that are identical across all installation

1 repos

https://github.com/MadExploits/CVE-2026-14483

thehackerwire@mastodon.social at 2026-08-02T17:00:12.000Z ##

🔴 CVE-2026-14483 - Critical (9.8)

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T17:00:12.000Z ##

🔴 CVE-2026-14483 - Critical (9.8)

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65313
(8.1 HIGH)

EPSS: 0.18%

updated 2026-07-31T09:31:19

1 posts

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.

thehackerwire@mastodon.social at 2026-07-31T14:00:39.000Z ##

🟠 CVE-2026-65313 - High (8.1)

A provisioning script used when installing HIPASE-250 (formerly 250
SCALA) engineering workstations sets a fixed, hard-coded x11vnc
password. Because the same credential is applied to every workstation
provisioned this way, an attacker with adjace...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18157
(7.8 HIGH)

EPSS: 0.24%

updated 2026-07-31T03:31:17

1 posts

A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the

thehackerwire@mastodon.social at 2026-07-31T04:00:13.000Z ##

🟠 CVE-2026-18157 - High (7.8)

A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66421
(9.3 CRITICAL)

EPSS: 0.36%

updated 2026-07-31T00:30:29

1 posts

OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message containing inline event handler payloads such as an img tag with an onerror attribute with

thehackerwire@mastodon.social at 2026-07-31T01:00:25.000Z ##

🔴 CVE-2026-66421 - Critical (9.3)

OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages pro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66360
(7.5 HIGH)

EPSS: 0.28%

updated 2026-07-31T00:30:29

1 posts

The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero length value to trigger a bounded heap over read. This condition occurs before MMS session establishment, a crafted TCP/102 connection attempt can trigger the

thehackerwire@mastodon.social at 2026-07-31T01:00:02.000Z ##

🟠 CVE-2026-66360 - High (7.5)

The ISO Presentation layer contains a flaw in the handling of specific
parameters during normal mode negotiation. A missing length check in the
processing of the encoded presentation data allows an attacker
controlled field with a zero length v...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18064
(7.5 HIGH)

EPSS: 0.34%

updated 2026-07-31T00:30:29

1 posts

An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a denial-of-service condition and processor reset.

thehackerwire@mastodon.social at 2026-07-30T23:00:23.000Z ##

🟠 CVE-2026-18064 - High (7.5)

An incomplete fix for CVE-2026-15352 in the NASA core Flight System
(cFS) Health and Safety (HS) application leaves a separate NULL pointer
dereference reachable in versions through 7.0.1. An attacker who can
trigger the affected command under ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63035
(8.1 HIGH)

EPSS: 0.57%

updated 2026-07-31T00:30:22

1 posts

A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code.

thehackerwire@mastodon.social at 2026-07-31T04:00:24.000Z ##

🟠 CVE-2026-63035 - High (8.1)

A heap use-after-free vulnerability in the TransferSubscriptions service
in open62541 may allow an authenticated attacker to cause a denial of
service or potentially execute arbitrary code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66803
(10.0 CRITICAL)

EPSS: 0.49%

updated 2026-07-30T21:31:57

1 posts

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

offseq@infosec.exchange at 2026-07-31T01:30:24.000Z ##

Azure Cosmos DB suffers a CRITICAL improper access control vulnerability (CVE-2026-66803) allowing unauthorized remote code execution. No patch yet — restrict network access & monitor Microsoft advisories. radar.offseq.com/threat/improp #OffSeq #Azure #Vuln #CyberSecurity

##

CVE-2026-67207
(8.8 HIGH)

EPSS: 0.30%

updated 2026-07-30T21:31:57

1 posts

Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission check expression. Attackers can exploit the incorrect evaluation of the access control expression to create, download, and restore backups without admin

thehackerwire@mastodon.social at 2026-07-30T21:00:17.000Z ##

🟠 CVE-2026-67207 - High (8.8)

Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67206
(8.8 HIGH)

EPSS: 0.44%

updated 2026-07-30T21:31:57

1 posts

Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() functions. Attackers with the file_manager_mkfile capability can write malicious PHP content into the web-accessible FILES_DIR directory and trigger executio

1 repos

https://github.com/anirbala98/CVE-2026-67206

thehackerwire@mastodon.social at 2026-07-30T21:00:08.000Z ##

🟠 CVE-2026-67206 - High (8.8)

Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() func...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66416
(8.8 HIGH)

EPSS: 0.16%

updated 2026-07-30T21:31:57

1 posts

Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel VerifyCsrfToken middleware from the global middleware stack in app/Http/Kernel.php. Attackers can craft malicious pages delivered via phishing emails or malicious websites to trigger unauthorized POST, P

thehackerwire@mastodon.social at 2026-07-30T20:00:11.000Z ##

🟠 CVE-2026-66416 - High (8.8)

Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel VerifyCsrfToken middleware from the global middlew...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66415
(8.5 HIGH)

EPSS: 0.28%

updated 2026-07-30T21:31:57

1 posts

Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::import() method without path validation. Attackers can submit crafted filenames containing URL wrappers or path traversal sequences through the JSON-RPC AP

thehackerwire@mastodon.social at 2026-07-30T20:00:00.000Z ##

🟠 CVE-2026-66415 - High (8.5)

Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::im...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13435
(9.9 CRITICAL)

EPSS: 0.29%

updated 2026-07-30T21:31:56

1 posts

IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.

thehackerwire@mastodon.social at 2026-07-30T20:01:35.000Z ##

🔴 CVE-2026-13435 - Critical (9.9)

IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17657
(8.3 HIGH)

EPSS: 0.36%

updated 2026-07-30T21:31:32

1 posts

Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

hrbrmstr@mastodon.social at 2026-07-31T12:22:30.000Z ##

Chrome CVE Report for the 2026-07-29 Stable channel: tbljrmp60k.joplinusercontent.c

Top vulnerability types: Inappropriate Implementation (34.5%), Insufficient Input Validation (19%), Use After Free (13.4%)

Most affected components: XR (36), Chrome for iOS (35), Input Handling (33), ANGLE Graphics (30)

Largest bounty: $36,000 — CVE-2026-17657 (Use after free in Navigation)

##

CVE-2026-18140
(7.5 HIGH)

EPSS: 0.44%

updated 2026-07-30T20:17:03.400000

1 posts

Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial of service (process abort via stack exhaustion) via a single small HTTP request containing deeply nested JSON to a smithy-rs generated server. To rem

thehackerwire@mastodon.social at 2026-07-30T20:01:11.000Z ##

🟠 CVE-2026-18140 - High (7.5)

Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66013
(0 None)

EPSS: 0.39%

updated 2026-07-30T20:11:09.180000

1 posts

OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consol

DailyCyberSecurity@infosec.exchange at 2026-07-31T01:39:37.000Z ##

An OpenRemote vulnerability, CVE-2026-66013 (CVSS 9.3), enables unauthenticated asset takeover. Full advisory details are now public. Patch to 1.26.2.

#OpenRemote #CVE202666013 #IoTSecurity #AssetTakeover

securityonline.info/openremote

##

CVE-2026-9322
(7.5 HIGH)

EPSS: 0.30%

updated 2026-07-30T19:18:37.363000

1 posts

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.

thehackerwire@mastodon.social at 2026-07-30T18:00:27.000Z ##

🟠 CVE-2026-9322 - High (7.5)

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-28323
(9.8 CRITICAL)

EPSS: 0.64%

updated 2026-07-30T18:31:47

2 posts

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

beyondmachines1@infosec.exchange at 2026-08-01T08:01:04.000Z ##

SolarWinds Patches Critical SAML Bypass and pgAdmin4 RCE in Web Help Desk

SolarWinds released Web Help Desk 2026.2.1 to address eight vulnerabilities, including a critical SAML authentication bypass (CVE-2026-28323) and multiple remote code execution flaws in pgAdmin4.

**Update SolarWinds Web Help Desk to version 2026.2.1 ASAP to fix a critical authentication bypass and multiple remote code execution flaws that could give attackers full control of your help desk and connected databases. Before upgrading, switch from Servlet authentication to SAML 2.0 or HTTP Header authentication. If possible for your process, keep the platform isolated on trusted internal networks.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-07-31T02:53:50.000Z ##

A SolarWinds Web Help Desk SAML authentication bypass, CVE-2026-28323, scores a critical CVSS 9.8. Update to 2026.2.1 to stay protected.

#SolarWinds #WebHelpDesk #CVE202628323 #SAML #InfoSec

securityonline.info/solarwinds

##

CVE-2026-12940
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-07-30T18:31:47

1 posts

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables.

thehackerwire@mastodon.social at 2026-07-30T18:00:48.000Z ##

🔴 CVE-2026-12940 - Critical (9.8)

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py whe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66066(CVSS UNKNOWN)

EPSS: 1.70%

updated 2026-07-30T18:23:34

10 posts

### Impact In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process environment. That environment typically holds `secret_key_base` and often credentials for external systems, which may in turn allow escalation to remote code execution or lateral movement to those systems. ##

5 repos

https://github.com/0xBlackash/CVE-2026-66066

https://github.com/paveg/rails-activestorage-vips-audit

https://github.com/rails/rails-forensics-CVE-2026-66066

https://github.com/0xsha/KindaRails2Shell

https://github.com/Zer0SumGam3/CVE-2026-66066-POC

netsecio@mastodon.social at 2026-08-02T15:09:59.000Z ##

📰 Ruby on Rails Patches Critical RCE Flaw (CVE-2026-66066)

Ruby on Rails patches critical RCE vulnerability CVE-2026-66066 (CVSS 9.5). The flaw in Active Storage allows arbitrary file read via crafted image uploads, leading to potential RCE. Update immediately. #RubyOnRails #CVE #CyberSecurity

🔗 cyber.netsecops.io/articles/ru

##

undercodenews@mastodon.social at 2026-08-01T15:04:10.000Z ##

Critical Ruby on Rails Flaw CVE-2026-66066 Exposes Sensitive Files, Secret Keys, and the Hidden Risks Inside Modern Web Frameworks + Video

Introduction: A New Warning Sign for Web Application Security Modern web frameworks have transformed software development by making it faster and easier to build powerful applications. However, every additional feature, plugin, and integrated component also creates new security challenges. The discovery of CVE-2026-66066, a critical…

undercodenews.com/critical-rub

##

Analyst207@mastodon.social at 2026-08-01T14:54:41.000Z ##

Rails patches Active Storage flaw with RCE potential

A critical vulnerability in Rails' Active Storage, known as CVE-2026-66066, can allow an unauthenticated attacker to read sensitive files and potentially execute remote code, putting your application at risk. This flaw can be exploited under specific conditions, making it crucial to patch immediately.

osintsights.com/rails-patches-

#Rails #ActiveStorage #Cve202666066 #RemoteCodeExecution #FileUploadVulnerability

##

DailyCyberSecurity@infosec.exchange at 2026-08-01T10:18:30.000Z ##

CVE-2026-66066 (CVSS 9.5) enables Rails Active Storage RCE via libvips. A Metasploit module is now public. Upgrade Rails and rotate secrets.

#RubyOnRails #CVE202666066 #RCE #ActiveStorage #CyberSecurity #Metasploit

securityonline.info/cve-2026-6

##

flavorjones@ruby.social at 2026-07-31T01:01:12.000Z ##

RE: ruby.social/@flavorjones/11700

The Rails security team published attack details and -- more importantly -- tools and agent skills to run a forensic investigation to help you determine if you were exploited. Be careful out there.

discuss.rubyonrails.org/t/cve-

##

threatcodex@infosec.exchange at 2026-07-30T20:34:49.000Z ##

KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
#CVE_2026_66066
rapid7.com/blog/post/etr-kinda

##

AAKL@infosec.exchange at 2026-07-30T16:38:45.000Z ##

New.

Rapaid7: KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails rapid7.com/blog/post/etr-kinda @Rapid7Official

The related Ruby on Rails advisory was published yesterday: Possible arbitrary file read and remote code execution in Active Storage variant processing github.com/rails/rails/securit #infosec #vulnerability #Ruby

##

lobsters@mastodon.social at 2026-07-30T15:10:13.000Z ##

KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) lobste.rs/s/kkobew #ruby #security
ethiack.com/info-hub/research/

##

_r_netsec@infosec.exchange at 2026-07-30T14:13:05.000Z ##

KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066) ethiack.com/info-hub/research/

##

jbhall56@infosec.exchange at 2026-07-30T12:07:40.000Z ##

Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials, and API tokens. thehackernews.com/2026/07/crit

##

CVE-2026-67595
(8.1 HIGH)

EPSS: 0.42%

updated 2026-07-30T16:45:00.353000

1 posts

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, install

1 repos

https://github.com/IlhomjonR/CVE-2026-67595

DarkWebInformer@infosec.exchange at 2026-07-30T19:58:19.000Z ##

🚨 CVE-2026-67595: VaahCMS 2.0.0-2.3.4 contains malicious obfuscated JavaScript in an OTP email template that can connect to a C2 server, log passwords, scrape WhatsApp Web, and remotely alter pages.

Published: 2026-07-29

CVSS 4.0: 9.2
CVSS 3.1: 8.1
Exploitability Score: 2.2

Commit: github.com/webreinvent/vaahcms

##

CVE-2026-15435
(9.8 CRITICAL)

EPSS: 0.73%

updated 2026-07-30T15:31:59

2 posts

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.

beyondmachines1@infosec.exchange at 2026-08-01T09:01:03.000Z ##

IBM Patches Critical File Write and Command Injection Flaws in App Connect Enterprise

IBM fixed three vulnerabilities in App Connect Enterprise, including a critical path traversal flaw (CVE-2026-15435) that allows remote attackers to write arbitrary files and compromise systems. The updates also address OS command injection and unauthorized file read risks.

**If you run IBM App Connect Enterprise (versions 12.0.1.0–12.0.12.27 or 13.0.1.0–13.0.7.2), first make sure the system is isolated from the internet and reachable only from trusted networks. Then upgrade ASAP to v13 Fix Pack 13.0.8.0 or v12 Fix Pack 12.0.12.28.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

phillip@social.lol at 2026-07-30T20:04:23.000Z ##

@nuintari I was curious how the results differed between Kagi and Startpage (and by proxy, Google) on this. Holy shit, @da_667 is right to be so upset.

Nothing on Startpage or Google’s first page is at all related. Ctrl + F for the CVE returns only the query in the search bar, and Google’s AI overview, which somehow has the right CVE and description, despite the fact that only one of its cited websites even mentions the actual CVE?

For their part, at least @kagihq has CVE Feed’s actual listing for CVE-2026-15435 as their second result, with Tenable and Feedly further down, but still on the first page of results. It’s still crazy that those aren’t the top three results and this should be better, but given how atrocious the competition is, at least it even found the right CVE at all

##

CVE-2026-59309
(9.8 CRITICAL)

EPSS: 0.74%

updated 2026-07-30T15:31:54

1 posts

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

security_crawler_carl@infosec.exchange at 2026-08-01T02:24:33.000Z ##

🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!

Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)

##

CVE-2026-47876
(9.3 CRITICAL)

EPSS: 0.28%

updated 2026-07-30T15:31:54

2 posts

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

security_crawler_carl@infosec.exchange at 2026-08-01T02:24:33.000Z ##

🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!

Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)

##

offseq@infosec.exchange at 2026-07-30T13:30:31.000Z ##

CRITICAL vuln: CVE-2026-47876 in VMware Cloud Foundation (9.1.x.x/9.0.x.x/5.x) allows VM admin to execute code on host via VMXNET3 adapter. Restrict admin access, use other adapters if possible. Patch not yet available. radar.offseq.com/threat/cve-20 #OffSeq #VMware #InfoSec #CVE202647876

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 1.14%

updated 2026-07-30T15:31:51

1 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

security_crawler_carl@infosec.exchange at 2026-08-01T02:24:33.000Z ##

🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!

Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)

##

CVE-2026-18363
(0 None)

EPSS: 0.30%

updated 2026-07-30T14:12:18.697000

1 posts

A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the timestamp associated with the provided token and checks whether the configured validity period has expired. Consequently, the expiry check is only performed if the timestamp lookup fails, allowing tok

offseq@infosec.exchange at 2026-07-30T12:00:27.000Z ##

CVE-2026-18363: osTicket <1.17.8 & <1.18.4 has a CRITICAL flaw (CVSS 9.1) in password reset logic — tokens can be reused, risking account takeover. Upgrade when patch is available, monitor resets, and restrict token access. radar.offseq.com/threat/cve-20 #OffSeq #osTicket #CVE202618363

##

CVE-2026-14529
(9.4 CRITICAL)

EPSS: 0.33%

updated 2026-07-30T14:08:40.373000

1 posts

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.

CVE-2026-64560
(7.8 HIGH)

EPSS: 0.12%

updated 2026-07-30T12:32:18

1 posts

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sys_timer_delete() exec() posix_cpu_timer_del() // Observes old leader p = pid_task(pid, pid_type); de_thread() switch_leader(); release

CVE-2026-48449
(10.0 CRITICAL)

EPSS: 0.54%

updated 2026-07-30T03:31:28

2 posts

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

netsecio@mastodon.social at 2026-08-02T15:09:55.000Z ##

📰 Adobe Patches CVSS 10.0 RCE Flaw in Campaign Classic

Adobe patches a critical CVSS 10.0 unauthenticated RCE vulnerability (CVE-2026-48449) in Campaign Classic. The flaw allows for arbitrary code execution with no user interaction. Users are urged to update to build 9398 immediately. #CVE #Adobe

🔗 cyber.netsecops.io/articles/ad

##

DailyCyberSecurity@infosec.exchange at 2026-07-31T02:41:48.000Z ##

Adobe Campaign Classic flaw CVE-2026-48449 scores a perfect CVSS 10.0 and allows arbitrary code execution. Update to build 9398 now.

#AdobeCampaignClassic #CVE202648449 #RCE #Adobe #InfoSec

securityonline.info/adobe-camp

##

CVE-2026-20079
(10.0 CRITICAL)

EPSS: 37.67%

updated 2026-07-29T17:16:51.683000

3 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.&nbsp; This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this v

Nuclei template

1 repos

https://github.com/0xBlackash/CVE-2026-20079

cyberveille@mastobot.ping.moi at 2026-08-02T18:00:06.000Z ##

📢 Cisco FMC : vulnérabilité zero-day CVE-2026-20316 activement exploitée et CVE-2026-20079 critique patchée

📰 Source : BleepingComputer, publié le 29 juillet 2026. Cisco émet une alerte concernant deux vulnérabilités affectant son produit Cisco Secure Firewall Management Center (FMC). 🔴 CVE-2026-20316 — Credentials statiques (CVSS 5.3, sévérité High) Une…

📖 cyberveille : cyberveille.ch/posts/2026-08-0
🌐 source : bleepingcomputer.com/news/secu
🟡 vérification factuelle moyenne
#CiscoFMC #ZeroDay #Cyberveille

##

AAKL@infosec.exchange at 2026-07-31T16:19:58.000Z ##

There are two new advisories from Cisco, one addressing a critical vulnerability that was first published on March 4:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

The second is a high-severity vulnerability that was first published yesterday:

CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #vulnerability #Cisco

##

Bied@digitalhub.social at 2026-07-30T19:33:28.000Z ##

#Cisco - "We Never Learn". 🔥

Warum ein Konzern es noch immer notwendig findet eine #Backdoor in seine Produkte einzubauen ist mir völlig schleierhaft. 🙈

"Da CVE-2026-20316 bereits aktiv ausgenutzt wird, rät Cisco Administratoren, ihre FMC-Instanzen dringend zu aktualisieren."

"Gibt es Abhilfe?

"Die genannten Hotfix-Updates bessern auch bezüglich einer seit März bekannten kritischen Lücke (CVSS: 10) nach, mit der sich die Authentifizierung im Web-Interface von FMC umgehen lässt. Diese Lücke ist als CVE-2026-20079 registriert und verleiht Angreifern sogar einen direkten Root-Zugriff auf das zugrundeliegende Betriebssystem. "

Klar, eine Firewall ist ja nur zum Schutz der Kunden vorhanden, da kann man schon mal auch Kriminelle einladen, oder? 🤢

So eine persönliche Haftung des CEO und eine Strafe ab 5 % vom Konzernumsatz könnte möglicherweise zu einer Änderungen führen:

So stelle ich mir die Anweisung des CEO vor: 👍

"Ab sofort ist die Nutzung (auch während der Entwicklung) von Backdoors untersagt. Wer sich nicht daran hält wird fristlos entlassen und haftet für Schäden."

Und, natürlich sollte die Qualitätssicherung vorab prüfen ob die Entwickler sich auch daran halten. 😁

Es gibt erfahrene Spezialisten die gerne bei der Auswahl der Geräte helfen und für mehr Sicherheit sorgen. Einfach anfragen, dann weiß man mehr. 🙂

golem.de/news/kodierte-zugangs

#Backdoor

##

CVE-2026-65883(CVSS UNKNOWN)

EPSS: 0.50%

updated 2026-07-29T12:31:30

1 posts

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.

1 repos

https://github.com/shinthink/CVE-2026-65883

AAKL@infosec.exchange at 2026-07-30T16:44:07.000Z ##

New. This is in reference to CVE-2026-65883.

VulnCheck: Aimy Captcha-Less Form Guard: The Anti-Bot Plugin That Hands Bots the Keys vulncheck.com/blog/aimy-captch @vulncheck #infosec #vulnerability

##

CVE-2026-14512
(9.8 CRITICAL)

EPSS: 0.54%

updated 2026-07-28T21:31:44

1 posts

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.

CVE-2026-16347
(8.8 HIGH)

EPSS: 0.23%

updated 2026-07-28T21:31:39

1 posts

MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive response. In some versions, a fixed per-connection delay is present, but it can be bypass

DailyCyberSecurity@infosec.exchange at 2026-08-01T01:02:50.000Z ##

MikroTik RouterOS Flaw CVE-2026-16347 Helps Attackers Gain Unauthorized System Access

CVE-2026-16347 lets attackers brute-force MikroTik RouterOS logins for unauthorized system access. Rated CVSS 8.8, with no fix yet. Apply mitigations. #MikroTik #RouterOS #CVE202616347 #BruteForce #CISA #CyberSecurity TL;DR CISA warned of a brute-force weakness in MikroTik RouterOS and Cloud Hosted Router. Tracked as CVE-2026-16347, it scores a CVSS of 8.8. The flaw helps attackers guess passwords and gain unauthorized system access to admin services.

securityonline.info/mikrotik-r

##

CVE-2026-16771
(8.8 HIGH)

EPSS: 0.25%

updated 2026-07-28T21:31:32

1 posts

In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent device settings, or trigger backend diagno

CVE-2026-5674
(8.8 HIGH)

EPSS: 0.12%

updated 2026-07-28T18:33:47

1 posts

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.

CVE-2026-63077
(9.8 CRITICAL)

EPSS: 0.65%

updated 2026-07-27T18:31:56

3 posts

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

1 repos

https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation

tugatech@masto.pt at 2026-07-31T09:45:10.000Z ##

JetBrains emitiu um aviso urgente sobre uma vulnerabilidade crítica no TeamCity que permite execução remota de código. A falha, classificada como CVE-2026-63077, pode ser explorada por atacantes para alcançar a execução remota de código nos sistemas vulneráveis.

🔗 tugatech.com.pt/t88336-jetbrai

#alerta #falha #teamcity 

##

offseq@infosec.exchange at 2026-07-31T00:00:37.000Z ##

CRITICAL: JetBrains TeamCity On-Premises (all versions) vulnerable to CVE-2026-63077 — auth bypass enables remote code execution via HTTPS. Patch to 2025.11.7/2026.1.3 or apply plugin for 2017.1+. TeamCity Cloud unaffected. radar.offseq.com/threat/jetbra
#OffSeq #Vuln #TeamCity #CVE202663077

##

oversecurity@mastodon.social at 2026-07-30T12:31:32.000Z ##

CVE-2026-63077 Exposes TeamCity Servers to Unauthenticated RCE

A critical security flaw affecting TeamCity On-Premises has prompted administrators to update their servers immediately after researchers disclosed...

🔗️ [Thecyberexpress] link.is.it/Uo0klI

##

CVE-2026-62379
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-07-24T21:11:10

1 posts

## Summary A pre-authentication remote code execution vulnerability affects OpenAM. The remote authentication endpoint (`/authservice`, PLL) accepts an XML element that names an arbitrary Java class, which the server then loads and instantiates without validation. On a default configuration this is reachable **without authentication** and allows an attacker to run code on the server. ## Impact Un

DailyCyberSecurity@infosec.exchange at 2026-07-31T13:41:47.000Z ##

Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9.

#OpenAM #RCE #IAM #CVE202662379

securityonline.info/openam-cve

##

CVE-2026-46135
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-07-24T15:33:33

1 posts

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix race between ICReq handling and queue teardown nvmet_tcp_handle_icreq() updates queue->state after sending an Initialization Connection Response (ICResp), but it does so without serializing against target-side queue teardown. If an NVMe/TCP host sends an Initialization Connection Request (ICReq) and immediately c

sigint@fosstodon.org at 2026-08-01T23:45:05.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-08-02

Two more kernel CVEs patched (CVE-2026-46135, CVE-2026-46243). If you run 22.04/24.04 with local users or containers, reboot into the new kernel promptly rather than waiting for the next maintenance window.

🔗 linuxsecurity.com/advisories/u

#Ubuntu #Linux #infosec

##

CVE-2026-43499
(7.8 HIGH)

EPSS: 0.73%

updated 2026-07-24T15:33:29

1 posts

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue oper

63 repos

https://github.com/alex193a/Root-My-Pixel

https://github.com/boxiaolanya2008/CVE-2026-43499-Neo11Plus

https://github.com/HYCQAQ/Logitech-G-Cloud-GhostLock-CVE-2026-43499

https://github.com/fancyzll/CVE-2026-43499_OPPO-MT6835

https://github.com/2932796375github/CVE-2026-43499_OPPO-MT6835

https://github.com/JoinChang/ghostlock-oneplus

https://github.com/BuSung-dev/Root-My-Galaxy

https://github.com/Bailan766/rmx3888-cve-2026-43499-config

https://github.com/HORKimhab/CVE-2026-43499

https://github.com/veygax/HORiZonstack

https://github.com/gagaltotal/CVE-2026-43499-PoC-Scanner

https://github.com/CakesTwix/Android-CVE-2026-43499

https://github.com/MiaPatsune/cve-2026-43499

https://github.com/MobiusM/CVE-2026-43499

https://github.com/onesmiledx/CVE-2026-43499

https://github.com/woshimaniubi8/CVE-2026-43499-root-KernelSU

https://github.com/Thiasap/oppo-pgem10-ghostlock

https://github.com/fusiondrive/CVE-2026-43499-S24U

https://github.com/soralis0912/CVE-2026-43499-aristotle-apk

https://github.com/1ndevelopment/CVE-2026-43499-S26

https://github.com/xianwan1314/CVE-2026-43499-Poc-Analysis

https://github.com/PeronGH/ghostlock-selinux-disabler

https://github.com/Yakayna/SpringPeace

https://github.com/sorrow404Null/CVE-2026-43499-RMX5200

https://github.com/caspy123/CVE-2026-43499

https://github.com/ctn-Qvo/auto_extract_offsets

https://github.com/soralis0912/CVE-2026-43499-warhol-root

https://github.com/inforcqb/CVE-2026-43499-pja110

https://github.com/pubglite55/oppo-ghostlock

https://github.com/No-22-Github/UnPlus

https://github.com/Petalrain224/CVE-2026-43499-Redmi-Turbo5

https://github.com/fusiondrive/CVE-2026-43499-A36

https://github.com/p2p3p/GhostLock-for-OnePlus

https://github.com/Bartixxx32/CVE-2026-43499-OnePlus15

https://github.com/ayyy7128/CVE-2026-43499-jinghu

https://github.com/soralis0912/CVE-2026-43499-pmg110-root

https://github.com/qsvggff-spec/oppo-A5-PRO-5G-CVE-2026-43499

https://github.com/233laoliu/mt6985-CVE-2026-43499

https://github.com/Wtrwx/smt878u-ionstack-poc

https://github.com/soralis0912/CVE-2026-43499-aristotle

https://github.com/Cxyofficial/x200-cve-2026-43499

https://github.com/suominen/ghostlock

https://github.com/WitAqua-tools/Root-My-Device

https://github.com/BuSung-dev/CVE-2026-43499-S25U

https://github.com/ctn-Qvo/CVE-2026-43499-so-build

https://github.com/x-spy/CVE-2026-43499-popsicle

https://github.com/tc3650/CVE-2026-43499-armv7

https://github.com/cuteaplane/GhostLock-for-OnePlus15T

https://github.com/0xBlackash/CVE-2026-43499

https://github.com/dmcdtc/openvz-cve-patch-2026

https://github.com/NothingFumo/ghostlock-aresin

https://github.com/geecjdj/CVE-2026-43499

https://github.com/Kananosa/CVE-2026-43499-For-Xiaomi-17T-chagall

https://github.com/Linuxoid-cn/Mi8E5-Unlocker-by-CVE-2026-43499

https://github.com/Colorful-glassblock/duchamp-root

https://github.com/dnlid/CVE-2026-43499

https://github.com/joehquak/Mi8E5-Unlocker-by-CVE-2026-43499

https://github.com/mumaosong/cve-2026-43499-CyberMeowfia

https://github.com/CatXiaoShi/cve-2026-43499

https://github.com/justsoman/CyberMeowfia-ace3

https://github.com/LuZe0y/pd2425-cve-2026-43499-config

https://github.com/Linuxoid-cn/CVE-2026-43499-Poc-Analysis

https://github.com/datfooldive/ghostlock-emerald

JulianOliver@mastodon.social at 2026-07-31T01:30:52.000Z ##

Update Firefox, the Tor browser, and other derivatives if you are still running FF versions 147 through to 151.0.2.

Some interesting attacks exploiting CVE-2026-10702 are shoring up:

thehackernews.com/2026/07/rese

Note that thanks to Android's lazy sandbox,
this attack can be used as the entry point of a complete browser-to-kernel chain, giving the attacker root (CVE-2026-43499).

(Unclear if/how Firefox-ESR is affected)

#infosec

##

CVE-2026-65694
(7.5 HIGH)

EPSS: 2.46%

updated 2026-07-24T00:32:40

1 posts

Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query parameter. Attackers can send a single unauthenticated HTTP GET request exploiting the failure of normalize_path() to strip traversal sequences, disclosing sensitive file

1 repos

https://github.com/abdugafforov-bobur/CVE-2026-65694-PoC

halildeniz@mastodon.social at 2026-08-01T18:42:03.000Z ##

🚨 NEW VULNERABILITY ALERT 🚨

CVE-2026-65694 reveals an Unauthenticated Arbitrary File Read flaw in Microweber CMS <= 2.0.20 via ServeStaticFileController. Remote attackers can extract sensitive files (.env).

Read full research:
denizhalil.com/2026/08/01/cve-

#CVE202665694 #CyberSecurity #infosec

##

CVE-2026-10697
(7.5 HIGH)

EPSS: 0.29%

updated 2026-07-23T21:31:09

1 posts

Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

cyberveille@mastobot.ping.moi at 2026-08-02T16:00:06.000Z ##

📢 [VULN] Multiples vulnérabilités dans Progress MOVEit Transfer - CVE-2026-10697

De multiples vulnérabilités ont été découvertes dans Progress MOVEit Transfer. Elles permettent à un attaquant de provoquer une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.

🔗 cert.ssi.gouv.fr/avis/CERTFR-2
💬 discussion : infosec.pub/post/50367400
#Vulnérabilité #CVE #Cyberveille

##

CVE-2026-50522
(9.8 CRITICAL)

EPSS: 75.76%

updated 2026-07-23T15:44:10.873000

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

5 repos

https://github.com/4minx/CVE-2026-50522

https://github.com/ChPratik/CVE-2026-50522

https://github.com/HORKimhab/CVE-2026-50522

https://github.com/darses/CVE-2026-50522

https://github.com/webshellseo8/CVE-2026-50522-Proof-of-Concept

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-46243
(7.1 HIGH)

EPSS: 0.38%

updated 2026-07-23T12:18:16.790000

1 posts

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that cifs.upcall treats as kernel-originating inputs. However, userspace can also create keys of this type through request_key(2) or add_key(2), allowing those fields t

4 repos

https://github.com/liamromanis101/cifswitch-check

https://github.com/cumakurt/linuxpi

https://github.com/suominen/cifswitch

https://github.com/MrForkBomb/CIFSwitch-Checker-CVE-2026-46243

sigint@fosstodon.org at 2026-08-01T23:45:05.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-08-02

Two more kernel CVEs patched (CVE-2026-46135, CVE-2026-46243). If you run 22.04/24.04 with local users or containers, reboot into the new kernel promptly rather than waiting for the next maintenance window.

🔗 linuxsecurity.com/advisories/u

#Ubuntu #Linux #infosec

##

CVE-2026-10702
(4.3 MEDIUM)

EPSS: 0.72%

updated 2026-07-22T19:10:00.120000

4 posts

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.

2 repos

https://github.com/HORKimhab/CVE-2026-10702

https://github.com/raihants/cve-2026-10702

cyberveille@mastobot.ping.moi at 2026-08-02T17:30:05.000Z ##

📢 CVE-2026-10702 : Miscompilation JIT dans SpiderMonkey IonMonkey permettant une exécution de code arbitraire

Cet article présente une analyse technique approfondie de CVE-2026-10702, une vulnérabilité découverte par leur agent d'IA VEGA dans le compilateur JIT IonMonkey de SpiderMonkey, le moteur JavaScript de Firefox. La vulnérabilité est une…

📖 cyberveille : cyberveille.ch/posts/2026-08-0
🌐 source : nebusec.ai/research/ionstack-p
🟡 vérification factuelle moyenne
#SpiderMonkey #Firefox #Cyberveille

##

DailyCyberSecurity@infosec.exchange at 2026-07-31T12:09:47.000Z ##

Firefox CVE-2026-10702 Exploit: Android Flaw Exposed

meterpreter.org/firefox-cve-20

##

JulianOliver@mastodon.social at 2026-07-31T01:30:52.000Z ##

Update Firefox, the Tor browser, and other derivatives if you are still running FF versions 147 through to 151.0.2.

Some interesting attacks exploiting CVE-2026-10702 are shoring up:

thehackernews.com/2026/07/rese

Note that thanks to Android's lazy sandbox,
this attack can be used as the entry point of a complete browser-to-kernel chain, giving the attacker root (CVE-2026-43499).

(Unclear if/how Firefox-ESR is affected)

#infosec

##

jbhall56@infosec.exchange at 2026-07-30T12:34:28.000Z ##

Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. thehackernews.com/2026/07/rese

##

CVE-2026-20896
(9.8 CRITICAL)

EPSS: 31.81%

updated 2026-07-21T20:28:59

1 posts

# Summary The Gitea Docker images ship an `app.ini` template that hard-codes: ``` REVERSE_PROXY_TRUSTED_PROXIES = * ``` The documented default for this setting, in `custom/conf/app.example.ini`, is `127.0.0.0/8,::1/128`, i.e. only loopback is trusted. When an admin enables `ENABLE_REVERSE_PROXY_AUTHENTICATION = true` to put Gitea behind an authenticating reverse proxy and leaves the trusted-pr

6 repos

https://github.com/szybnev/cve-2026-20896-gitea-poc

https://github.com/EQSTLab/CVE-2026-20896

https://github.com/XaocZenon/CVE-2026-20896

https://github.com/kaleth4/CVE-2026-20896

https://github.com/rz1027/CVE-2026-20896

https://github.com/Lite-os15/Lab-001-Gitea-CVE-2026-20896-

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-52887
(10.0 CRITICAL)

EPSS: 0.59%

updated 2026-07-20T16:17:05.020000

1 posts

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal() template string without escaping or parameter binding, allowing a signed-up authen

offseq@infosec.exchange at 2026-08-01T01:30:26.000Z ##

CVE-2026-52887: @nocobase/plugin-notification-in-app-message <2.0.61 suffers CRITICAL SQL injection in /api/myInAppChannels:list, enabling RCE as PG superuser 🛡️. Patch to 2.0.61+, disable anonymous signup, restrict DB roles. radar.offseq.com/threat/plugin #OffSeq #CVE202652887 #AppSec

##

CVE-2026-27771
(8.2 HIGH)

EPSS: 43.07%

updated 2026-07-17T19:04:38

1 posts

### CVE Description Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information. ### Summary A critical vulnerability has been discovered in Gitea. It was already reported via (security@gitea.io) from (dev@noscope.com), and submitted an encrypted report.

Nuclei template

2 repos

https://github.com/portbuster1337/CVE-2026-27771

https://github.com/HORKimhab/CVE-2026-27771

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-15352
(7.5 HIGH)

EPSS: 0.43%

updated 2026-07-16T21:30:45

1 posts

A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service.

thehackerwire@mastodon.social at 2026-07-30T23:00:23.000Z ##

🟠 CVE-2026-18064 - High (7.5)

An incomplete fix for CVE-2026-15352 in the NASA core Flight System
(cFS) Health and Safety (HS) application leaves a separate NULL pointer
dereference reachable in versions through 7.0.1. An attacker who can
trigger the affected command under ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-42530
(8.1 HIGH)

EPSS: 3.68%

updated 2026-07-16T12:33:31

1 posts

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers

3 repos

https://github.com/HORKimhab/CVE-2026-42530

https://github.com/0xBlackash/CVE-2026-42530

https://github.com/v4ltonn/CVE-2026-42530

CVE-2026-15410
(7.2 HIGH)

EPSS: 76.35%

updated 2026-07-16T05:16:18.470000

1 posts

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

3 repos

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

https://github.com/HORKimhab/CVE-2026-15410

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-15409
(10.0 CRITICAL)

EPSS: 78.44%

updated 2026-07-16T05:16:18.293000

1 posts

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

Nuclei template

5 repos

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

https://github.com/remmons-r7/rapid7-CVE-2026-15409

https://github.com/0xBlackash/CVE-2026-15409

https://github.com/HORKimhab/CVE-2026-15409

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-48319
(9.1 CRITICAL)

EPSS: 32.29%

updated 2026-07-14T21:32:32

1 posts

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-49176
(7.8 HIGH)

EPSS: 0.47%

updated 2026-07-14T18:32:01

1 posts

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

2 repos

https://github.com/DavidCarliez/CVE-2026-49176_LPE_POC

https://github.com/777erp/CVE-2026-49176_BOF

DarkWebInformer@infosec.exchange at 2026-07-31T17:33:23.000Z ##

🚨 A Cobalt Strike BOF targeting CVE-2026-49176 adds another exploitation method for the CVSS 7.8 Windows WalletService local privilege escalation vulnerability.

GitHub: github.com/777erp/CVE-2026-491

The flaw can allow a standard user to execute commands with SYSTEM privileges on unpatched Windows systems.

##

CVE-2026-56291
(9.8 CRITICAL)

EPSS: 76.07%

updated 2026-07-10T18:33:13

1 posts

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Nuclei template

4 repos

https://github.com/rimbadirgantara/CVE-2026-56291.yaml

https://github.com/shinthink/CVE-2026-56291

https://github.com/0xdenis77/CVE-2026-56291

https://github.com/ChiefYoru/CVE-2026-56291_PoC

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-58025
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-07-09T21:31:14

1 posts

Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/Import/WikiRevision.Php, includes/Logging/LogEntryBase.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

1 repos

https://github.com/shinthink/CVE-2026-58025

DarkWebInformer@infosec.exchange at 2026-07-30T19:21:53.000Z ##

🚨 PoC for CVE-2026-58025, a CVSS 9.8 MediaWiki deserialization flaw that could enable RCE through malicious log entry imports.

Exploitation requires import permissions. Upgrade to 1.43.9, 1.44.6, 1.45.4, or 1.46.0.

GitHub: github.com/shinthink/CVE-2026-

##

CVE-2026-12045
(9.0 CRITICAL)

EPSS: 0.48%

updated 2026-07-01T19:26:30.593000

2 posts

Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin user's database role. The AI Assistant's execute_sql_query tool runs LLM-generated SQL inside a BEGIN TRANSACTION READ ONLY wrapper to prevent data modification. The LLM-supplied query was forwarded to

thehackerwire@mastodon.social at 2026-08-02T08:00:03.000Z ##

🔴 CVE-2026-17351 - Critical (9)

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T08:00:03.000Z ##

🔴 CVE-2026-17351 - Critical (9)

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12044
(8.8 HIGH)

EPSS: 0.71%

updated 2026-06-19T00:31:46

2 posts

SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-supplied description field. The Jinja templates for Domains (and their constraints), Foreign Tables, Languages, and Event Triggers, plus the Views OID-lookup query, interpolated the description directly inside a single-quoted SQL literal -- ``'{{ data.description }}'`` -- instead o

thehackerwire@mastodon.social at 2026-08-02T08:00:13.000Z ##

🟠 CVE-2026-17346 - High (8.8)

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T08:00:13.000Z ##

🟠 CVE-2026-17346 - High (8.8)

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-15435
(7.3 HIGH)

EPSS: 0.36%

updated 2026-06-17T08:37:46.203000

1 posts

A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_update.jsp. This manipulation of the argument Report causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

jyasskin@hachyderm.io at 2026-07-30T18:14:29.000Z ##

@fugueish Was going to shill Kagi, but their first result is CVE-2025-15435 (i.e. wrong year). The second result is correct. Quotes don't uprank that second result for some reason. It's still the first day, so maybe their crawls aren't as aggressive?

##

CVE-2013-4786
(7.5 HIGH)

EPSS: 78.57%

updated 2026-06-16T23:57:53.617000

2 posts

The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.

1 repos

https://github.com/fin3ss3g0d/CosmicRakp

marzlberger@neander.social at 2026-08-01T14:19:27.000Z ##

Also wirklich, niemand, wirklich niemand sollte ein #BMC ohne ein VPN/SSL frei ins Internet stellen! Das war schon 2004 fahrlässig.

@gborn : "Mehr als 24.000 Server mit BMC per #Schwachstelle CVE-2013-4786 gefährdet. .... Diese besteht wohl seit 2004 und kann den Password-Hash zur Authentifizierung leaken. Die Server wären dann per Internet öffentlich angreifbar, und die Passwort-Hashes sind in vielen Fällen knackbar"

borncity.com/blog/2026/08/01/m

#sicherheit #security

##

marzlberger@neander.social at 2026-08-01T14:19:27.000Z ##

Also wirklich, niemand, wirklich niemand sollte ein #BMC ohne ein VPN/SSL frei ins Internet stellen! Das war schon 2004 fahrlässig.

@gborn : "Mehr als 24.000 Server mit BMC per #Schwachstelle CVE-2013-4786 gefährdet. .... Diese besteht wohl seit 2004 und kann den Password-Hash zur Authentifizierung leaken. Die Server wären dann per Internet öffentlich angreifbar, und die Passwort-Hashes sind in vielen Fällen knackbar"

borncity.com/blog/2026/08/01/m

#sicherheit #security

##

CVE-2026-42897
(8.1 HIGH)

EPSS: 5.64%

updated 2026-05-15T18:30:32

4 posts

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

1 repos

https://github.com/atiilla/CVE-2026-42897

threatnoir@infosec.exchange at 2026-07-31T08:06:41.000Z ##

⚠️ CRITICAL: Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

Russian state-sponsored group Laundry Bear is actively exploiting a zero-day XSS vulnerability (CVE-2026-42897) in Exchange OWA to deploy OWAReaper backdoor. Targets include U.S. and European government entities and private sector organizations. Successful exploitation grants persistent mailbox acc…

threatnoir.com/focus

#infosec #cybersecurity

##

security_crawler_carl@infosec.exchange at 2026-07-30T20:06:31.000Z ##

🏆 New Achievement! Inbox: One New Backdoor (Unread)!

Conducting inventory audit of your Microsoft Exchange installation. Status: CVE-2026-42897, one cross-site scripting flaw in Outlook Web Access — present, unpatched, actively exploited. OWAReaper backdoor — installed, compliments of Laundry Bear (also filed under: Void Blizzard). Long-term mailbox access — granted, unauthorized, ongoing. Affected sectors listed: government, telecom, financial, hospitality, aerospace. (1/2)

##

security_crawler_carl@infosec.exchange at 2026-07-30T20:06:31.000Z ##

HTML sanitization — missing. Proofpoint's report — filed July 29, one week after the activity was detected.

Summary column: your email server is carrying significant negative-value assets. Patch CVE-2026-42897 immediately and audit OWA logs for suspicious JavaScript execution and unauthorized mailbox access.

Reward: A cursed Rusty Audit Clipboard. It changes nothing. The backdoor is still there.

#CyberSecurity #ZeroDay #Exchange #Ransomware #APT #AchievementUnlocked (2/2)

##

jbhall56@infosec.exchange at 2026-07-30T12:09:26.000Z ##

The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026. thehackernews.com/2026/07/russ

##

CVE-2025-66376
(7.2 HIGH)

EPSS: 21.62%

updated 2026-03-18T18:31:10

2 posts

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

cyberveille@mastobot.ping.moi at 2026-08-02T11:30:26.000Z ##

📢 TA488 exploite une zero-day Zimbra (CVE-2025-66376) pour espionner des gouvernements via half-click
📝 ## 🔍 Contexte

Publié le 23 juillet 2026 par l'équipe Threat Research...
📖 cyberveille : cyberveille.ch/posts/2026-08-0
🌐 source : proofpoint.com/us/blog/threat-
#CVE_2025_66376 #IOC #Cyberveille

##

cyberveille@mastobot.ping.moi at 2026-08-02T11:30:26.000Z ##

📢 TA488 exploite une zero-day Zimbra (CVE-2025-66376) pour espionner des gouvernements via half-click
📝 ## 🔍 Contexte

Publié le 23 juillet 2026 par l'équipe Threat Research...
📖 cyberveille : cyberveille.ch/posts/2026-08-0
🌐 source : proofpoint.com/us/blog/threat-
#CVE_2025_66376 #IOC #Cyberveille

##

CVE-2025-66518(CVSS UNKNOWN)

EPSS: 0.89%

updated 2026-01-29T03:42:38

2 posts

Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2. Users are recommended to upgrade to version 1.10.3 or upper, which fixes the issue.

thehackerwire@mastodon.social at 2026-08-02T11:00:04.000Z ##

🟠 CVE-2026-62391 - High (8.1)

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.

This issue ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T11:00:04.000Z ##

🟠 CVE-2026-62391 - High (8.1)

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.

This issue ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65321
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-02T16:00:01.000Z ##

🔴 CVE-2026-65321 - Critical (9.8)

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-02T16:00:01.000Z ##

🔴 CVE-2026-65321 - Critical (9.8)

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49413
(0 None)

EPSS: 0.15%

2 posts

N/A

1 repos

https://github.com/ii4gsp/CVE-2026-49413

CVE-2026-60137
(0 None)

EPSS: 79.03%

1 posts

N/A

46 repos

https://github.com/ananay/wp2shell-lab

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/47Cid/wp2shell-lab

https://github.com/ebrasha/abdal-cve-2026-60137

https://github.com/northsia/CVE-2026-60137-With-Skip-SSL

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/0xWhoknows/wp2shell

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/Iqbalx7/wp2shell

https://github.com/vulnquest58/PressVector

https://github.com/0xsha/wp2shell

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/h4cd0c/wp2shell

https://github.com/shinthink/CVE-2026-63030

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/dinosn/wp2shell-lab

https://github.com/zi3lak/wp2shell_scanner

https://github.com/mcipekci/wp2shell

https://github.com/yuag/wp2shell

https://github.com/bahartanir/wp2shell-scanner

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/ikow/wp2shell

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/michael-kanda/Wp2shell-ioc-scanner

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/NULL200OK/WP2Shell

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/kulichr/wp2shell

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/securelayer7/WordPresShell

https://github.com/0xjessie21/wp2shell-checker

https://github.com/Crypto-Cat/wp2shell

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/ekomsSavior/wp2shell

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/Icex0/wp2shell-poc

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-63030
(0 None)

EPSS: 98.42%

1 posts

N/A

Nuclei template

72 repos

https://github.com/ananay/wp2shell-lab

https://github.com/Ch4120N/CVE-2026-63030

https://github.com/mhtsec/CVE-2026-63030

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/47Cid/wp2shell-lab

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/0xWhoknows/wp2shell

https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/4B3R4M4-607D/CVE-2026-63030-POC

https://github.com/administrator-01001/CVE-2026-63030

https://github.com/raphy76/wp2shell-poc-fulljs

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/attackercan/wp2shell-poc2

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/4minx/CVE-2026-63030

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/Iqbalx7/wp2shell

https://github.com/vulnquest58/PressVector

https://github.com/0xsha/wp2shell

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/h4cd0c/wp2shell

https://github.com/0xh7ml/CVE-2026-63030

https://github.com/shinthink/CVE-2026-63030

https://github.com/CybersecSpirit/CVE-2026-63030

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/dinosn/wp2shell-lab

https://github.com/ebrasha/abdal-cve-2026-63030

https://github.com/mcipekci/wp2shell

https://github.com/zi3lak/wp2shell_scanner

https://github.com/Lutfifakee-Project/wp2shell

https://github.com/yuag/wp2shell

https://github.com/imXur/WordPress-CVE-2026-63030-Analysis

https://github.com/mrx-arafat/CVE-2026-63030-POC

https://github.com/TomorrowX6/CVE-2026-63030-poc

https://github.com/bahartanir/wp2shell-scanner

https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030

https://github.com/zeroc00I/CVE-2026-63030

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/ikow/wp2shell

https://github.com/gbrsh/CVE-2026-63030

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/michael-kanda/Wp2shell-ioc-scanner

https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/mverschu/CVE-2026-63030

https://github.com/NULL200OK/WP2Shell

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/c0gnit00/Wp2Shell

https://github.com/kulichr/wp2shell

https://github.com/ChiefYoru/CVE-2026-63030_PoC

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/securelayer7/WordPresShell

https://github.com/0xjessie21/wp2shell-checker

https://github.com/Crypto-Cat/wp2shell

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/ekomsSavior/wp2shell

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/0xBlackash/CVE-2026-63030

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/ZenithGenius/wordpress-batch-rce-lab

https://github.com/Icex0/wp2shell-poc

https://github.com/fullhunt/wp2shell-scan

https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030

https://github.com/InstaWP/wp2shell-scan

https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2026-63030-WP2Shell

secdb@infosec.exchange at 2026-08-01T00:02:58.000Z ##

📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799

Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677

CISA KEVs:
- CISA-2026:0701 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0707 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0710 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0713 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0714 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0715 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0716 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329

Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311

Top EPSS Score:
- CVE-2026-63030 - 98.42 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-60137 - 79.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15409 - 78.44 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15410 - 76.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-56291 - 76.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 69.97 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50522 - 62.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-27771 - 43.07 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48319 - 32.29 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20896 - 31.81 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18420
(0 None)

EPSS: 0.00%

1 posts

N/A

offseq@infosec.exchange at 2026-07-31T21:00:29.000Z ##

CVE-2026-18420: CRITICAL RCE via prototype pollution in OpenSearch Dashboards TSVB plugin. Full system compromise possible. No patch yet — check AWS Security Bulletin, limit plugin access, monitor updates. radar.offseq.com/threat/cve-20 #OffSeq #OpenSearch #Infosec #RCE

##

CVE-2026-62261
(0 None)

EPSS: 0.00%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-07-31T13:41:47.000Z ##

Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9.

#OpenAM #RCE #IAM #CVE202662379

securityonline.info/openam-cve

##

CVE-2026-46648
(0 None)

EPSS: 0.00%

1 posts

N/A

moltenbit@infosec.exchange at 2026-07-31T12:33:17.000Z ##

two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.

CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.

CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.

github.com/globaleaks/globalea and github.com/globaleaks/globalea

#GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security

##

CVE-2026-46647
(0 None)

EPSS: 0.00%

1 posts

N/A

moltenbit@infosec.exchange at 2026-07-31T12:33:17.000Z ##

two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.

CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.

CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.

github.com/globaleaks/globalea and github.com/globaleaks/globalea

#GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security

##

CVE-2026-63220
(0 None)

EPSS: 0.14%

1 posts

N/A

AmmarSpaces@infosec.exchange at 2026-07-31T10:51:10.000Z ##

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

#cybersecurity #infosec #codeigniter #vulnerability

##

CVE-2026-59726
(0 None)

EPSS: 0.48%

2 posts

N/A

1 repos

https://github.com/HORKimhab/CVE-2026-59726

threatnoir@infosec.exchange at 2026-07-31T09:06:06.000Z ##

⚠️ CRITICAL: Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

CVE-2026-59726 in Ruflo AI orchestration platform allows unauthenticated remote code execution via an exposed Model Context Protocol bridge. Attackers can steal API keys, access user conversations, and corrupt AI memory without any credentials. Any organization running Ruflo is immediately exploita…

threatnoir.com/focus

#infosec #cybersecurity

##

beyondmachines1@infosec.exchange at 2026-07-31T09:01:05.000Z ##

Critical RufRoot Flaw Allows Full Takeover of Ruflo AI Agent Environments

Ruflo patched a CVSS 10.0 vulnerability (CVE-2026-59726) that allowed unauthenticated attackers to execute code and steal API keys via an exposed MCP bridge. The flaw, named RufRoot, also enabled AI memory poisoning that persists even after software updates.

**If you run Ruflo (formerly Claude Flow), first make sure your instances are isolated from the internet and reachable only from trusted networks, then update to version 3.16.3 immediately to fix the RufRoot flaw (CVE-2026-59726) and firewall ports 3001 and 27017 to block outside access from the local network. Because a simple update won't undo damage already done, rotate all your LLM provider API keys (OpenAI, Anthropic, etc.) and audit the AgentDB memory store for any malicious entries left behind by attackers.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-17543
(0 None)

EPSS: 0.39%

1 posts

N/A

CVE-2026-62246
(0 None)

EPSS: 0.27%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-30T23:00:02.000Z ##

🟠 CVE-2026-62246 - High (8.5)

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68503
(0 None)

EPSS: 0.40%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-30T22:00:38.000Z ##

🔴 CVE-2026-68503 - Critical (9.8)

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.py HTTP ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18245
(0 None)

EPSS: 0.52%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-30T20:01:24.000Z ##

🔴 CVE-2026-18245 - Critical (9)

Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61536
(0 None)

EPSS: 0.30%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-30T20:00:25.000Z ##

🟠 CVE-2026-61536 - High (7.5)

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resolves their import_path field through importlib.impo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62663
(0 None)

EPSS: 0.34%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-30T18:00:38.000Z ##

🟠 CVE-2026-62663 - High (7.5)

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks accept untrusted user input as file paths via Path(value) and pass them directly t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites