## Updated at UTC 2026-08-26T03:53:51.024324

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-80138 9.8 0.00% 2 0 2026-08-26T00:31:14 ClipBucket V5's web installer fails to properly validate or escape the php_cli_f
CVE-2026-79912 8.3 0.00% 2 0 2026-08-26T00:31:14 A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impac
CVE-2026-80186 7.6 0.00% 2 0 2026-08-26T00:31:09 A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth
CVE-2026-79911 10.0 0.00% 2 0 2026-08-26T00:31:04 A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210
CVE-2026-80104 9.8 0.00% 2 0 2026-08-25T21:31:58 DB-GPT builds the destination path for an uploaded skill from the multipart file
CVE-2026-65093 9.9 0.00% 2 0 2026-08-25T21:31:36 NVIDIA OpenShell for Linux contains a vulnerability where an attacker could caus
CVE-2026-65092 8.5 0.00% 2 0 2026-08-25T21:31:35 NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker co
CVE-2026-65091 8.8 0.00% 2 0 2026-08-25T21:31:35 NVIDIA OpenShell for all platforms contains a vulnerability where a malicious ga
CVE-2026-39113 None 0.00% 1 1 2026-08-25T21:31:35 Buffer Overflow vulnerability in SQLite affected version source snapshots/builds
CVE-2026-75501 7.5 0.37% 3 0 2026-08-25T20:17:04.150000 A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residentia
CVE-2026-66153 0 0.00% 2 0 2026-08-25T20:17:01.270000 The NEService auto-upgrade process insecurely handles temporary files in SonicWa
CVE-2026-66152 0 0.00% 2 0 2026-08-25T20:17:01.147000 A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Li
CVE-2026-0551 8.8 0.53% 2 0 2026-08-25T20:16:50.610000 The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Obje
CVE-2026-19568 7.8 0.13% 2 0 2026-08-25T19:16:48.483000 A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force
CVE-2026-75768 7.8 0.00% 2 0 2026-08-25T18:32:08 Substance3D - Painter is affected by an Untrusted Search Path vulnerability that
CVE-2026-79992 7.8 0.00% 2 0 2026-08-25T18:32:02 A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerabili
CVE-2026-19912 None 0.00% 2 0 2026-08-25T18:32:01 The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote
CVE-2026-19913 None 0.00% 2 0 2026-08-25T18:32:01 The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure v
CVE-2026-79774 8.4 0.00% 2 0 2026-08-25T18:32:00 Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox e
CVE-2026-79675 9.8 0.00% 2 0 2026-08-25T18:31:56 NLTK before 3.10.3 fails to validate JVM options passed through the per-call opt
CVE-2026-76197 10.0 0.00% 4 0 2026-08-25T18:18:05.110000 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CVE-2026-76193 10.0 0.00% 1 0 2026-08-25T18:18:04.813000 Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF)
CVE-2026-59309 9.8 8.18% 1 0 2026-08-25T18:12:14.410000 VMware vCenter contains an authentication bypass vulnerability in the VMware Dir
CVE-2026-79784 8.8 0.00% 2 0 2026-08-25T16:17:30.547000 Vocos instantiates a class named by a configuration file without restricting whi
CVE-2026-13214 9.8 0.51% 2 0 2026-08-25T16:16:45.770000 The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer over
CVE-2026-78284 8.6 0.35% 2 0 2026-08-25T15:16:45.160000 Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
CVE-2026-63586 9.8 0.52% 4 0 2026-08-25T15:16:37.107000 The web-based management interface uses a modified uhttpd server with CGI shell
CVE-2026-59769 9.1 0.33% 1 0 2026-08-25T15:16:35.427000 FA-50 all versions contain hard-coded credentials. An attacker, who knows the c
CVE-2026-57863 8.8 0.00% 2 0 2026-08-25T15:16:35.297000 Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self
CVE-2026-18798 7.5 0.00% 2 0 2026-08-25T15:16:31.207000 Issue summary: QUIC server may double free QRX (QUIC record layer RX) object whe
CVE-2026-55538 7.3 0.00% 1 0 2026-08-25T14:57:00 ### Summary `praisonai serve agents` exposes HTTP routes that invoke registered
CVE-2026-55540 7.1 0.00% 1 0 2026-08-25T14:54:57 ### Summary PraisonAI's `praisonai.code` tool wrappers (exported as `CODE_TOOLS`
CVE-2026-16687 9.6 0.21% 2 0 2026-08-25T14:31:59.517000 IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 thr
CVE-2026-78003 9.8 0.57% 2 0 2026-08-25T14:16:55.953000 The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Requ
CVE-2026-77136 0 0.55% 2 0 2026-08-25T14:16:54.297000 The extension passes the raw value of a form field configured as "This field con
CVE-2026-57910 0 0.00% 4 0 2026-08-25T13:19:24.810000 Improper authentication in the WatchGuard Agent allows an unauthenticated attack
CVE-2026-57909 0 0.00% 4 0 2026-08-25T13:19:24.590000 A path traversal vulnerability in WatchGuard Agent allows a remote, unauthentica
CVE-2026-78570 9.8 0.00% 2 0 2026-08-25T12:31:29 The Total Donations plugin for WordPress is vulnerable to Privilege Escalation i
CVE-2026-78563 7.2 0.19% 1 0 2026-08-25T09:30:48 The NotificationX Pro plugin for WordPress is vulnerable to Stored Cross-Site Sc
CVE-2026-78568 9.8 0.30% 2 0 2026-08-25T09:30:48 The Total Donations plugin for WordPress is vulnerable to SQL Injection in all v
CVE-2026-71366 7.7 0.33% 2 0 2026-08-25T09:30:36 A server-side request forgery (SSRF) vulnerability was found in multiple AWX not
CVE-2026-63587 8.6 0.27% 2 0 2026-08-25T09:17:32.057000 The SMS control function of IE-SR-2TX-WL-4G devices can require a password for S
CVE-2026-78477 9.8 0.30% 2 0 2026-08-25T06:31:36 The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versio
CVE-2026-41992 7.5 0.35% 2 0 2026-08-25T06:31:17 GNU gzip contains a global buffer overflow vulnerability in the LZH decompressio
CVE-2026-78541 0 0.96% 2 0 2026-08-25T04:18:21.310000 A stored OS command injection vulnerability exists in the parent-control module
CVE-2026-76904 9.8 0.52% 1 1 2026-08-25T04:18:20.870000 GeoTools is an open source Java library that provides tools for geospatial data.
CVE-2026-21962 10.0 42.02% 27 9 2026-08-25T04:18:11.067000 Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in pr
CVE-2026-17250 0 0.19% 2 0 2026-08-25T04:18:10.233000 A stack-based buffer overflow vulnerability exists in the firmware update functi
CVE-2026-10053 8.5 0.72% 2 1 2026-08-25T04:17:40.250000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8
CVE-2026-78676 9.8 0.40% 4 0 2026-08-25T03:32:20 GitPython before 3.1.59 fails to safely re-serialize multi-line git-config value
CVE-2026-72702 5.4 0.10% 2 0 2026-08-25T03:32:14 Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer
CVE-2026-78264 7.1 0.15% 1 0 2026-08-25T00:30:37 Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
CVE-2026-78265 9.8 0.31% 4 0 2026-08-25T00:30:37 Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
CVE-2026-32556 7.1 0.15% 2 0 2026-08-25T00:30:37 Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
CVE-2026-78267 9.8 0.27% 4 0 2026-08-25T00:30:37 Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
CVE-2026-78268 7.5 0.25% 2 0 2026-08-25T00:30:37 Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp;
CVE-2026-19685 9.8 0.14% 2 0 2026-08-24T21:34:43 NetworkManager did not apply the private_user restriction to the 802-1x.ca-path
CVE-2026-7455 7.8 0.13% 2 0 2026-08-24T21:33:53 A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force
CVE-2026-61419 7.8 0.09% 2 0 2026-08-24T21:33:52 Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Contr
CVE-2026-16783 7.8 0.13% 2 0 2026-08-24T21:33:46 A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force
CVE-2026-76835 9.1 0.35% 2 0 2026-08-24T20:17:19.623000 OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whet
CVE-2026-60084 8.7 0.35% 1 0 2026-08-24T20:16:51.410000 SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability i
CVE-2026-19874 9.1 0.73% 4 1 2026-08-24T20:16:42.277000 A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online
CVE-2026-76070 9.8 1.00% 2 1 2026-08-24T19:16:58.433000 Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow v
CVE-2026-71506 8.1 0.30% 1 1 2026-08-24T19:16:49.960000 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the p
CVE-2026-9254 None 2.35% 2 1 2026-08-24T18:32:04 An unauthenticated OS command injection vulnerability exists in the parental con
CVE-2026-16348 None 0.91% 2 1 2026-08-24T18:31:59 An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allo
CVE-2026-76071 9.8 1.06% 2 1 2026-08-24T18:31:59 Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow v
CVE-2026-76073 8.8 0.28% 2 0 2026-08-24T18:31:57 Label Studio does not scope the annotation detail endpoint to the requesting use
CVE-2026-9769 7.5 0.28% 1 0 2026-08-24T18:17:35.520000 justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion
CVE-2026-78167 10.0 1.03% 2 0 2026-08-24T18:17:26.737000 A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted eleme
CVE-2026-76838 8.5 0.31% 2 0 2026-08-24T18:17:22.363000 Hi.Events validates a webhook destination only when it is registered, never when
CVE-2026-78168 9.8 0.93% 4 0 2026-08-24T16:40:53.647000 A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0.
CVE-2026-59568 9.1 0.38% 3 0 2026-08-24T15:31:57 Multiple vulnerabilities on affected versions of Zscaler Client Connector allow
CVE-2026-77995 None 0.29% 2 0 2026-08-24T15:31:57 Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAu
CVE-2026-73570 8.9 1.51% 15 3 2026-08-24T13:19:17.577000 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor
CVE-2026-28171 8.6 0.34% 1 0 2026-08-24T12:31:46 Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 ver
CVE-2026-77994 None 0.23% 2 0 2026-08-24T09:33:52 Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK <
CVE-2026-8173 5.3 0.21% 2 0 2026-08-24T09:33:52 The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from t
CVE-2026-78211 9.8 1.54% 2 0 2026-08-24T06:30:35 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injec
CVE-2026-78170 8.8 0.44% 2 0 2026-08-24T03:31:14 A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the fu
CVE-2026-78169 9.9 0.44% 4 0 2026-08-24T03:31:14 A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This
CVE-2026-78207 9.4 0.44% 2 0 2026-08-24T03:31:14 exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in th
CVE-2026-78209 8.2 0.29% 2 0 2026-08-24T03:31:06 exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus,
CVE-2026-78208 7.5 0.37% 2 0 2026-08-24T01:16:58.280000 exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Wor
CVE-2026-18052 8.1 0.27% 2 0 2026-08-23T18:32:50 The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account bei
CVE-2026-76793 8.1 0.35% 2 0 2026-08-23T18:31:45 The Firebase Authentication WordPress plugin before 1.7.1 does not require the e
CVE-2026-77002 9.8 0.34% 2 0 2026-08-23T18:31:44 The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any s
CVE-2026-77001 9.8 0.42% 3 0 2026-08-23T18:31:44 The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin t
CVE-2026-77000 9.8 0.34% 2 0 2026-08-23T16:16:38.360000 The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a
CVE-2026-76789 8.8 0.34% 2 0 2026-08-23T16:16:38.043000 The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 d
CVE-2026-7808 9.8 0.35% 3 0 2026-08-23T15:33:12 justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that ca
CVE-2026-8445 9.8 0.38% 3 0 2026-08-23T15:33:12 justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-si
CVE-2026-4671 7.5 0.37% 1 1 2026-08-23T15:33:12 justhtml before 1.18.0 contains multiple low-severity denial-of-service issues i
CVE-2026-5388 9.8 0.34% 1 0 2026-08-23T15:33:04 justhtml before 1.15.0 contains multiple security issues in URL sanitization hel
CVE-2026-78155 9.9 0.27% 2 0 2026-08-23T12:31:11 privilege escalation in StackGres operator allows a low-privilege tenant who own
CVE-2026-13598 None 0.15% 1 0 2026-08-23T06:30:28 The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role
CVE-2026-78136 7.8 0.19% 3 0 2026-08-23T03:34:57 chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. Th
CVE-2026-16149 8.8 0.43% 3 0 2026-08-23T00:30:30 The Security Hardener plugin for WordPress is vulnerable to Missing Authorizatio
CVE-2026-78122 7.4 0.32% 2 1 2026-08-23T00:30:30 docker-socket-proxy fails to properly gate read endpoints in the /containers Doc
CVE-2026-78050 9.9 0.57% 2 0 2026-08-23T00:30:30 A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is th
CVE-2026-47895 7.5 0.67% 2 0 2026-08-23T00:30:22 In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-I
CVE-2026-4703 9.8 0.62% 2 0 2026-08-22T18:30:25 The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vuln
CVE-2026-68766 7.8 0.16% 2 0 2026-08-22T15:31:11 hashcat fails to restrict command-line options when parsing restore files, allow
CVE-2026-63312 7.5 0.49% 3 0 2026-08-22T15:31:11 NLTK before 3.10.0 contains an arbitrary local file read vulnerability in Stream
CVE-2026-63310 7.1 0.11% 3 0 2026-08-22T15:31:11 NLTK before 3.9.3 fails to verify file integrity after downloading packages and
CVE-2026-62384 7.5 0.49% 3 0 2026-08-22T15:31:11 NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCo
CVE-2026-66393 7.5 0.34% 2 0 2026-08-22T15:31:11 NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONT
CVE-2026-62243 7.5 0.15% 1 0 2026-08-22T15:31:11 Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final an
CVE-2026-2996 7.5 0.49% 1 0 2026-08-22T15:31:11 The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPres
CVE-2026-71513 8.8 0.78% 1 0 2026-08-22T15:31:11 NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUn
CVE-2026-62388 7.5 0.33% 1 0 2026-08-22T15:31:11 NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all
CVE-2026-59808 8.8 0.34% 1 0 2026-08-22T15:31:05 AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability w
CVE-2026-57998 7.8 0.14% 1 0 2026-08-22T15:31:02 better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm a
CVE-2026-59256 7.5 0.27% 1 0 2026-08-22T13:16:38.817000 WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerabili
CVE-2026-77946 10.0 0.62% 2 0 2026-08-22T12:30:34 A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by thi
CVE-2026-12710 0 0.32% 1 0 2026-08-22T09:16:53.340000 A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud App
CVE-2026-64531 7.8 0.38% 1 4 2026-08-22T06:31:25 In the Linux kernel, the following vulnerability has been resolved: net: openvs
CVE-2026-41451 7.8 0.72% 1 0 2026-08-21T18:35:08 UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command in
CVE-2026-27875 None 0.07% 2 0 2026-08-21T18:35:07 Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Co
CVE-2026-22681 8.5 0.28% 1 1 2026-08-21T18:35:01 OpenViking before 0.3.4 contains a server-side request forgery vulnerability tha
CVE-2026-47827 7.5 1.16% 1 0 2026-08-21T18:34:56 Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote a
CVE-2026-54795 8.8 2.39% 2 0 2026-08-21T17:57:13.800000 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutra
CVE-2026-48769 9.9 0.44% 1 0 2026-08-21T16:17:17.757000 Incus is a system container and virtual machine manager. Prior to version 7.2.0,
CVE-2026-48753 9.9 0.71% 1 0 2026-08-21T16:17:17.647000 Incus is a system container and virtual machine manager. Prior to version 7.1.0,
CVE-2026-48749 9.9 0.81% 1 0 2026-08-21T16:17:17.413000 Incus is a system container and virtual machine manager. Prior to version 7.2.0,
CVE-2026-77806 9.8 1.26% 1 1 2026-08-21T15:32:18 SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary
CVE-2026-63125 9.9 0.42% 1 0 2026-08-21T15:16:46.427000 Incus is a system container and virtual machine manager. Prior to version 7.3.0,
CVE-2026-77767 7.5 0.36% 1 0 2026-08-21T14:16:53.773000 Reconmap's API applies a fallback authorization policy in apps/api/app/Program.c
CVE-2026-77086 9.1 0.65% 1 0 2026-08-21T12:30:41 SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar insta
CVE-2026-77683 9.9 1.51% 1 0 2026-08-21T12:30:37 A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this
CVE-2026-72529 9.8 1.55% 2 0 2026-08-21T04:18:15.753000 A remote unauthorized attacker with network access via port 4307/TCP to the True
CVE-2026-69836 10.0 1.59% 4 2 2026-08-21T00:31:31 Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized a
CVE-2026-72843 9.8 0.59% 1 0 2026-08-21T00:31:24 The customer update route in EverShop is declared with "access": "public" in pac
CVE-2026-19586 None 5.04% 3 0 2026-08-20T21:31:30 A pre-authentication OS command injection vulnerability has been identified in O
CVE-2026-64849 9.3 16.41% 3 3 template 2026-08-20T19:16:57.867000 MLflow is an open source AI engineering platform for agents, large language mode
CVE-2026-72530 9.0 1.83% 2 1 2026-08-20T18:31:47 A remote unauthorized attacker with network access via port 4307/TCP to the True
CVE-2026-18264 8.8 1.24% 2 0 2026-08-20T18:30:55 NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vu
CVE-2026-76565 0 0.32% 2 1 2026-08-20T16:18:17.977000 Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter par
CVE-2026-75616 0 1.91% 2 1 2026-08-20T16:18:03.890000 An OS command injection vulnerability exists in the web management interface of
CVE-2026-19490 0 0.40% 2 0 2026-08-20T14:17:10.673000 Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: f
CVE-2026-20231 9.9 0.50% 1 0 2026-08-19T21:31:33 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-16835 9.6 0.23% 2 0 2026-08-19T21:30:30 IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 thr
CVE-2026-74480 9.8 0.53% 2 0 2026-08-19T18:33:34 In the Linux kernel, the following vulnerability has been resolved: net: bridge
CVE-2026-75149 8.8 0.64% 1 0 2026-08-19T18:33:02 marimo before 0.23.15 contains a code injection vulnerability in the notebook co
CVE-2026-71961 8.8 3.05% 2 0 2026-08-19T15:32:47 Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection
CVE-2026-54796 7.2 2.36% 2 0 2026-08-19T15:32:33 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutra
CVE-2026-18963 9.1 2.79% 18 8 template 2026-08-19T03:31:21 A flaw was found in the reset-credentials flow of the keycloak-services componen
CVE-2026-17084 0 0.48% 1 0 2026-08-19T01:16:56.650000 The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B
CVE-2026-59310 9.8 45.88% 1 2 2026-08-18T18:32:52 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-55040 9.1 5.58% 7 2 2026-08-18T18:32:50 Weak authentication in Microsoft Office SharePoint allows an unauthorized attack
CVE-2026-65400 7.1 10.43% 1 3 2026-08-18T18:31:47 An authentication issue was addressed with improved state management. This issue
CVE-2026-33824 9.8 72.69% 2 2 2026-08-18T18:31:46 Double free in Windows IKE Extension allows an unauthorized attacker to execute
CVE-2026-24301 8.8 2.22% 1 1 2026-08-18T15:31:45 Improper neutralization of special elements used in a command ('command injectio
CVE-2026-53365 5.5 0.17% 2 2 2026-08-18T15:31:16 In the Linux kernel, the following vulnerability has been resolved: vsock/virti
CVE-2026-73522 7.5 2.36% 2 0 2026-08-18T15:17:08.193000 COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability tha
CVE-2026-19478 9.4 6.00% 3 6 template 2026-08-18T14:57:10.630000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2
CVE-2026-15748 9.8 4.61% 2 3 2026-08-18T06:31:55 The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload
CVE-2026-75094 9.1 2.11% 2 0 2026-08-18T03:31:14 A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_
CVE-2026-19976 6.6 2.05% 2 0 2026-08-17T03:30:28 A security vulnerability has been detected in COMFAST CF-N1-S 2.6.0.1. Impacted
CVE-2026-68820 7.0 6.18% 2 4 2026-08-16T19:17:24.183000 Use after free in Windows Ancillary Function Driver for WinSock allows an author
CVE-2026-19598 9.8 2.46% 2 3 template 2026-08-15T18:31:24 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to
CVE-2026-61979 8.1 0.28% 4 0 2026-08-13T15:34:46 Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions
CVE-2026-14669 8.8 0.58% 2 1 2026-08-13T15:34:40 Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosin
CVE-2026-72898 10.0 79.22% 2 6 template 2026-08-12T15:18:30.347000 Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via t
CVE-2026-52923 7.8 0.13% 2 0 2026-08-12T12:19:41.090000 In the Linux kernel, the following vulnerability has been resolved: ipc: limit
CVE-2026-63520 8.1 2.93% 8 0 2026-08-11T18:31:39 Improper input validation in Microsoft Office SharePoint allows an unauthorized
CVE-2026-14540 6.1 0.11% 1 0 2026-08-08T00:32:15 A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP so
CVE-2026-63077 9.8 84.73% 3 4 template 2026-08-05T18:32:31 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-8508 6.5 0.70% 2 1 2026-08-04T03:31:16 An improper authentication vulnerability in the "social_login.cgi" CGI program i
CVE-2026-23479 8.8 1.36% 2 5 2026-07-25T11:10:00.100000 Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6
CVE-2026-15981 9.8 0.81% 4 1 2026-07-23T21:31:09 The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authen
CVE-2026-40575 9.1 0.48% 2 0 2026-07-21T13:50:16 ### Impact A configuration-dependent authentication bypass exists in OAuth2 Pro
CVE-2025-15467 9.8 47.62% 2 6 2026-07-14T15:32:45 Issue summary: Parsing CMS AuthEnvelopedData message with maliciously crafted AE
CVE-2026-52912 7.8 0.19% 2 0 2026-07-08T15:31:43 In the Linux kernel, the following vulnerability has been resolved: netfilter:
CVE-2026-52945 7.5 0.40% 1 0 2026-07-01T15:34:55 In the Linux kernel, the following vulnerability has been resolved: Revert "wir
CVE-2026-12077 7.5 0.46% 1 0 2026-06-29T20:17:32.607000 The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via
CVE-2026-48755 9.9 0.44% 1 0 2026-06-26T19:03:32 ### Summary Improper validation of user-provided backup compression algorithm l
CVE-2026-48752 9.9 0.81% 1 0 2026-06-26T18:46:32 ### Summary A specially crafted image or instance backup can be used to read or
CVE-2026-48751 9.9 0.70% 1 0 2026-06-26T18:33:56 ### Summary Instance snapshots ignore the `restricted.containers.lowlevel=block
CVE-2026-48750 9.9 0.78% 1 0 2026-06-26T18:32:53 ### Summary The `record-output` parameter of the `/instances/$name/exec` endpoi
CVE-2026-12569 9.8 40.59% 2 1 2026-06-26T15:33:15 A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
CVE-2025-69419 7.4 0.55% 2 1 2026-06-17T10:00:39.850000 Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously craft
CVE-2021-33045 9.8 99.56% 2 3 template 2026-06-17T03:54:04.020000 The identity authentication bypass vulnerability found in some Dahua products du
CVE-2025-9615 3.3 0.15% 4 0 2026-05-19T15:31:20 A flaw was found in NetworkManager. The NetworkManager package allows access to
CVE-2025-58187 6.5 0.38% 2 0 2026-01-29T18:31:31 Due to the design of the name constraint checking algorithm, the processing time
CVE-2026-0915 7.5 0.57% 2 1 2026-01-20T18:31:56 Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that spec
CVE-2021-33044 9.8 99.87% 2 9 template 2025-10-22T00:32:20 The identity authentication bypass vulnerability found in some Dahua products du
CVE-2020-14882 9.8 100.00% 2 42 template 2025-10-22T00:31:59 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware
CVE-2020-2551 9.8 93.17% 2 11 template 2025-10-22T00:31:50 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware
CVE-2017-10271 7.5 99.99% 2 33 template 2025-10-22T00:31:29 Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middlewar
CVE-2026-75604 0 0.00% 2 1 N/A
CVE-2026-18431 0 0.00% 1 0 N/A
CVE-2026-58090 0 0.00% 2 0 N/A
CVE-2026-60004 0 0.00% 8 9 template N/A
CVE-2026-18965 0 0.00% 2 0 N/A
CVE-2026-19632 0 0.00% 2 0 N/A
CVE-2026-59285 0 0.00% 1 0 N/A
CVE-2026-59270 0 0.00% 2 0 N/A
CVE-2026-76098 0 0.28% 2 0 N/A
CVE-2026-77567 0 0.30% 2 0 N/A
CVE-2026-66897 0 0.62% 2 0 N/A
CVE-2026-78251 0 0.39% 2 0 N/A
CVE-2026-55621 0 0.20% 1 0 N/A
CVE-2026-55622 0 0.20% 1 0 N/A
CVE-2026-63343 0 0.27% 1 0 N/A
CVE-2026-62941 0 0.25% 1 0 N/A
CVE-2026-62940 0 0.23% 1 0 N/A
CVE-2026-62867 0 0.29% 1 0 N/A
CVE-2026-55241 0 0.44% 1 0 N/A

CVE-2026-80138
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-26T00:31:14

2 posts

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary commands as the web server user.

thehackerwire@mastodon.social at 2026-08-26T00:01:13.000Z ##

🔴 CVE-2026-80138 - Critical (9.8)

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T00:01:13.000Z ##

🔴 CVE-2026-80138 - Critical (9.8)

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79912
(8.3 HIGH)

EPSS: 0.00%

updated 2026-08-26T00:31:14

2 posts

A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The attack can be initiated remotely. The exploit is now public and may be used.

thehackerwire@mastodon.social at 2026-08-26T00:01:04.000Z ##

🟠 CVE-2026-79912 - High (8.3)

A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The att...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T00:01:04.000Z ##

🟠 CVE-2026-79912 - High (8.3)

A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The att...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80186
(7.6 HIGH)

EPSS: 0.00%

updated 2026-08-26T00:31:09

2 posts

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for

thehackerwire@mastodon.social at 2026-08-25T22:59:49.000Z ##

🟠 CVE-2026-80186 - High (7.6)

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T22:59:49.000Z ##

🟠 CVE-2026-80186 - High (7.6)

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79911
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-08-26T00:31:04

2 posts

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

thehackerwire@mastodon.social at 2026-08-26T00:00:54.000Z ##

🔴 CVE-2026-79911 - Critical (10)

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname lea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-26T00:00:54.000Z ##

🔴 CVE-2026-79911 - Critical (10)

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname lea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80104
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-25T21:31:58

2 posts

DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename as given and writes the request body to upload_dir / filename. A path composed with that operator discards the left operand when the right one is absolute and fol

thehackerwire@mastodon.social at 2026-08-25T22:00:41.000Z ##

🔴 CVE-2026-80104 - Critical (9.8)

DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename as given ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T22:00:41.000Z ##

🔴 CVE-2026-80104 - Critical (9.8)

DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename as given ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65093
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-08-25T21:31:36

2 posts

NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

thehackerwire@mastodon.social at 2026-08-25T23:01:16.000Z ##

🔴 CVE-2026-65093 - Critical (9.9)

NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T23:01:16.000Z ##

🔴 CVE-2026-65093 - Critical (9.9)

NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65092
(8.5 HIGH)

EPSS: 0.00%

updated 2026-08-25T21:31:35

2 posts

NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering.

thehackerwire@mastodon.social at 2026-08-25T23:01:06.000Z ##

🟠 CVE-2026-65092 - High (8.5)

NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T23:01:06.000Z ##

🟠 CVE-2026-65092 - High (8.5)

NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65091
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-25T21:31:35

2 posts

NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

thehackerwire@mastodon.social at 2026-08-25T23:00:57.000Z ##

🟠 CVE-2026-65091 - High (8.8)

NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T23:00:57.000Z ##

🟠 CVE-2026-65091 - High (8.8)

NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39113(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-08-25T21:31:35

1 posts

Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11) and later snapshots/builds allows an attacker to cause a denial of service via the ext/misc/sqlar.c, sqlarUncompressFunc(), sqlar_uncompress(), sqlite3_value_int

1 repos

https://github.com/20000419/CVE-2026-39113

DarkWebInformer@infosec.exchange at 2026-08-22T18:43:39.000Z ##

‼️ CVE-2026-39113: Heap Buffer Overflow in SQLite's Optional SQLAR Extension

GitHub: github.com/20000419/CVE-2026-3

##

CVE-2026-75501
(7.5 HIGH)

EPSS: 0.37%

updated 2026-08-25T20:17:04.150000

3 posts

A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router allows unauthenticated remote attackers to modify NAT port‑forwarding rules via the UPnP WANIPConnection service. The device exposes the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls. A remote attacker can send crafted SOAP requests to add, delete, or enumerate port m

Byte0x90@mastodon.social at 2026-08-25T08:59:41.000Z ##

Eine ungepatchte Lücke (CVE-2026-75501) in Calix-Routern (GS5239XG) hebelt Firewall und NAT aus. Der UPnP-Dienst ist ungeschützt auf Port 5000 erreichbar, wodurch Angreifer aus der Ferne Port-Weiterleitungen anlegen können. So werden interne Heimnetz-Geräte wie NAS oder Kameras direkt im Internet exponiert. Da bisher kein Patch existiert, sollten Nutzer UPnP im Router deaktivieren oder ihren ISP kontaktieren.

#Calix #ITSecurity #CyberSecurity #Sicherheitslücke #Router #InfoSec

##

undercodenews@mastodon.social at 2026-08-25T02:12:45.000Z ##

Calix GS7 XGS Routers Face a Dangerous Unpatched Flaw That Could Open Home Networks to the Internet + Video

A Quiet Router Vulnerability With Serious Consequences A newly disclosed security flaw in Calix GS7 XGS residential routers is raising concern because it can allow a remote attacker to manipulate network port-forwarding rules without authenticating to the device. Tracked as CVE-2026-75501, the vulnerability affects Calix GS7 XGS (GS5239XG) routers running…

undercodenews.com/calix-gs7-xg

##

Analyst207@mastodon.social at 2026-08-24T21:25:41.000Z ##

Unpatched Calix Routers Expose Internal Devices to Internet Threats

A single, unauthorized request can create a permanent vulnerability in your Calix router's firewall, exposing internal devices to internet threats - no password or prompt required. This shocking flaw, tracked as CVE-2026-75501, leaves devices running EXOS/6.6.47 firmware alarmingly susceptible to attack.

osintsights.com/unpatched-cali

#Cve202675501 #CalixRouterVulnerability #Exos #Upnp #Wanipconnection

##

CVE-2026-66153
(0 None)

EPSS: 0.00%

updated 2026-08-25T20:17:01.270000

2 posts

The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths.

DailyCyberSecurity at 2026-08-26T01:42:46.453Z ##

Two critical SonicWall NetExtender vulnerabilities (CVE-2026-66152, CVE-2026-66153) affect the NetExtender Linux Client. Update to version 10.3.6 now.

securityonline.info/sonicwall-

##

DailyCyberSecurity@infosec.exchange at 2026-08-26T01:42:46.000Z ##

Two critical SonicWall NetExtender vulnerabilities (CVE-2026-66152, CVE-2026-66153) affect the NetExtender Linux Client. Update to version 10.3.6 now.

#SonicWall #NetExtender #CyberSecurity #CVE202666152 #CVE202666153

securityonline.info/sonicwall-

##

CVE-2026-66152
(0 None)

EPSS: 0.00%

updated 2026-08-25T20:17:01.147000

2 posts

A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Linux client allows an attacker to write arbitrary file as root.

DailyCyberSecurity at 2026-08-26T01:42:46.453Z ##

Two critical SonicWall NetExtender vulnerabilities (CVE-2026-66152, CVE-2026-66153) affect the NetExtender Linux Client. Update to version 10.3.6 now.

securityonline.info/sonicwall-

##

DailyCyberSecurity@infosec.exchange at 2026-08-26T01:42:46.000Z ##

Two critical SonicWall NetExtender vulnerabilities (CVE-2026-66152, CVE-2026-66153) affect the NetExtender Linux Client. Update to version 10.3.6 now.

#SonicWall #NetExtender #CyberSecurity #CVE202666152 #CVE202666153

securityonline.info/sonicwall-

##

CVE-2026-0551
(8.8 HIGH)

EPSS: 0.53%

updated 2026-08-25T20:16:50.610000

2 posts

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerable parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable sof

offseq@infosec.exchange at 2026-08-23T09:00:23.000Z ##

CVE-2026-0551: HIGH severity deserialization vulnerability in buildwps PPWP – Password Protect Pages (<=1.9.18). Contributor+ users can inject PHP objects if a POP chain exists in other plugins/themes. Review access & patch status. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

thehackerwire@mastodon.social at 2026-08-23T01:00:37.000Z ##

🟠 CVE-2026-0551 - High (8.8)

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerable parameter. This makes it...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19568
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-25T19:16:48.483000

2 posts

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

thehackerwire@mastodon.social at 2026-08-24T22:01:42.000Z ##

🟠 CVE-2026-19568 - High (7.8)

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-24T22:01:42.000Z ##

🟠 CVE-2026-19568 - High (7.8)

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75768
(7.8 HIGH)

EPSS: 0.00%

updated 2026-08-25T18:32:08

2 posts

Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

thehackerwire@mastodon.social at 2026-08-25T19:00:54.000Z ##

🟠 CVE-2026-75768 - High (7.8)

Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T19:00:54.000Z ##

🟠 CVE-2026-75768 - High (7.8)

Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79992
(7.8 HIGH)

EPSS: 0.00%

updated 2026-08-25T18:32:02

2 posts

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.

thehackerwire@mastodon.social at 2026-08-25T19:00:35.000Z ##

🟠 CVE-2026-79992 - High (7.8)

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local sh...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T19:00:35.000Z ##

🟠 CVE-2026-79992 - High (7.8)

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local sh...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19912(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-08-25T18:32:01

2 posts

The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php accepts a user‑controlled ServiceUrl, whose response is passed to unserialize(), and the resulting object’s fields are written to a cache path derived from attacker‑supplied uiconf_id with

DailyCyberSecurity at 2026-08-25T16:35:05.614Z ##

Two unpatched Kaltura server flaws (CVE-2026-19912, CVE-2026-19913) allow attackers to execute code and read files. Learn how to mitigate these risks.

securityonline.info/kaltura-se

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T16:35:05.000Z ##

Two unpatched Kaltura server flaws (CVE-2026-19912, CVE-2026-19913) allow attackers to execute code and read files. Learn how to mitigate these risks.

#Kaltura #CyberSecurity #CVE202619912 #CVE202619913 #InfoSec

securityonline.info/kaltura-se

##

CVE-2026-19913(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-08-25T18:32:01

2 posts

The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter is used as the base URL for a backend request and accepts non‑HTTP schemes such as file://. When an exception or error occurs, the response is subsequently deserialized and its raw contents are reflected to the clie

DailyCyberSecurity at 2026-08-25T16:35:05.614Z ##

Two unpatched Kaltura server flaws (CVE-2026-19912, CVE-2026-19913) allow attackers to execute code and read files. Learn how to mitigate these risks.

securityonline.info/kaltura-se

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T16:35:05.000Z ##

Two unpatched Kaltura server flaws (CVE-2026-19912, CVE-2026-19913) allow attackers to execute code and read files. Learn how to mitigate these risks.

#Kaltura #CyberSecurity #CVE202619912 #CVE202619913 #InfoSec

securityonline.info/kaltura-se

##

CVE-2026-79774
(8.4 HIGH)

EPSS: 0.00%

updated 2026-08-25T18:32:00

2 posts

Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers can exploit method forwarding through Eloquent models and query builders using methods like saveQuietly(), deleteQuietly(), increment(), decrement(), an

thehackerwire@mastodon.social at 2026-08-25T17:00:14.000Z ##

🟠 CVE-2026-79774 - High (8.4)

Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T17:00:14.000Z ##

🟠 CVE-2026-79774 - High (8.4)

Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79675
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-25T18:31:56

2 posts

NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfile to Stanford wrapper classes to achieve arbitrary code execution.

thehackerwire@mastodon.social at 2026-08-25T17:00:27.000Z ##

🔴 CVE-2026-79675 - Critical (9.8)

NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfil...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T17:00:27.000Z ##

🔴 CVE-2026-79675 - Critical (9.8)

NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfil...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76197
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-08-25T18:18:05.110000

4 posts

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

DailyCyberSecurity at 2026-08-26T02:43:27.407Z ##

Three critical Adobe Campaign Classic flaws (CVE-2026-76197, CVSS 10.0) allow arbitrary code execution. Update to build 9401 now.

securityonline.info/adobe-camp

##

thehackerwire@mastodon.social at 2026-08-25T19:00:44.000Z ##

🔴 CVE-2026-76197 - Critical (10)

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-08-26T02:43:27.000Z ##

Three critical Adobe Campaign Classic flaws (CVE-2026-76197, CVSS 10.0) allow arbitrary code execution. Update to build 9401 now.

#Adobe #CyberSecurity #CVE202676197 #RCE #Infosec

securityonline.info/adobe-camp

##

thehackerwire@mastodon.social at 2026-08-25T19:00:44.000Z ##

🔴 CVE-2026-76197 - Critical (10)

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76193
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-08-25T18:18:04.813000

1 posts

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

hugovalters@mastodon.social at 2026-08-26T01:05:14.000Z ##

CVE-2026-76193 - Critical SSRF to RCE in Adobe Campaign Classic. Zero-click exploit. CVSS 10.0. Apply mitigations immediately. #CVE #Adobe #infosec

valtersit.com/cve/CVE-2026-761

##

CVE-2026-59309
(9.8 CRITICAL)

EPSS: 8.18%

updated 2026-08-25T18:12:14.410000

1 posts

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

sekurakbot@mastodon.com.pl at 2026-08-23T15:32:00.000Z ##

Chińskie grupy APT wykorzystują podatność CVE-2026-59310 do masowych ataków na środowiska VMware vCenter

Zespół reagowania na incydenty firmy QUIRSO podczas analizy powłamaniowej serwera VMware vCenter natrafił na ślady globalnej kampanii, sterowanej najprawdopodobniej przez chińską grupę APT. Badania wykazały, że cyberprzestępcy wykorzystali krytyczną podatność CVE-2026-59310 (CVSS 9.8) w usłudze Syslog Server. Równolegle zidentyfikowali próby użycia drugiej luki CVE-2026-59309 (CVSS 9.8) jednak analitycy nie powiązali...

#WBiegu #Apt #Chiny #Cve #DirectoryTraversal #Rce #Vmware

sekurak.pl/chinskie-grupy-apt-

##

CVE-2026-79784
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-25T16:17:30.547000

2 posts

Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiate_class in vocos/pretrained.py takes the class_path value from the configuration, splits it into a module and an attribute, imports the module with __import__, resolves the attribute with getattr, and calls the result as args_class(*args, **kwargs) where kwargs is the config's own init_

thehackerwire@mastodon.social at 2026-08-25T17:00:02.000Z ##

🟠 CVE-2026-79784 - High (8.8)

Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiate_class in vocos/pretrained.py takes the class_path value from the configuration, splits it into a module and an attribute, imports th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T17:00:02.000Z ##

🟠 CVE-2026-79784 - High (8.8)

Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiate_class in vocos/pretrained.py takes the class_path value from the configuration, splits it into a module and an attribute, imports th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13214
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-08-25T16:16:45.770000

2 posts

The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When handling a GetConfiguration request from the central system, the handler copied the attacker-controlled JSON "key" string into the caller's fixed 50-byte stack buffer (skey[CISTR50], declared in subsys/net/lib/ocpp/ocpp.c) using an unbounded strcpy(). The parsed key value points dire

offseq at 2026-08-25T07:30:25.487Z ##

CVE-2026-13214 (CRITICAL, CVSS 9.8) in Zephyr OCPP 1.6 client: Unbounded strcpy() in parse_getconfig_msg() enables RCE/DoS via stack overflow. Affects =4.3.0, >=4.3.0 <4.4.2. Restrict untrusted WebSocket access. Patch status pending. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-25T07:30:25.000Z ##

CVE-2026-13214 (CRITICAL, CVSS 9.8) in Zephyr OCPP 1.6 client: Unbounded strcpy() in parse_getconfig_msg() enables RCE/DoS via stack overflow. Affects =4.3.0, >=4.3.0 <4.4.2. Restrict untrusted WebSocket access. Patch status pending. radar.offseq.com/threat/cve-20 #OffSeq #Zephyr #CVE202613214 #IoTSec

##

CVE-2026-78284
(8.6 HIGH)

EPSS: 0.35%

updated 2026-08-25T15:16:45.160000

2 posts

Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.

thehackerwire@mastodon.social at 2026-08-24T23:00:00.000Z ##

🟠 CVE-2026-78284 - High (8.6)

Unauthenticated Arbitrary File Deletion in MasterStudy LMS &lt;= 3.7.42 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-24T23:00:00.000Z ##

🟠 CVE-2026-78284 - High (8.6)

Unauthenticated Arbitrary File Deletion in MasterStudy LMS &lt;= 3.7.42 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63586
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-08-25T15:16:37.107000

4 posts

The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By submitting a specially crafted username containing shell metacharacters, an unauthenticated attacker with network access to t

DailyCyberSecurity at 2026-08-25T09:47:33.416Z ##

A critical Weidmueller router flaw, CVE-2026-63586 (CVSS 9.8), lets attackers execute arbitrary commands with root privileges. Patch devices immediately.

securityonline.info/weidmuelle

##

certvde at 2026-08-25T08:55:43.635Z ##

🔒 New CSAF advisory published

VDE-2026-083
Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities
CVE-2026-63586, CVE-2026-63587

Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execu…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: weidmueller.csaf-tp.certvde.co

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T09:47:33.000Z ##

A critical Weidmueller router flaw, CVE-2026-63586 (CVSS 9.8), lets attackers execute arbitrary commands with root privileges. Patch devices immediately.

#Weidmueller #Vulnerability #CVE202663586 #CyberSecurity

securityonline.info/weidmuelle

##

certvde@infosec.exchange at 2026-08-25T08:55:43.000Z ##

🔒 New CSAF advisory published

VDE-2026-083
Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities
CVE-2026-63586, CVE-2026-63587

Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execu…

HTML: weidmueller.csaf-tp.certvde.co
CSAF JSON: weidmueller.csaf-tp.certvde.co

#OT #Advisory

##

CVE-2026-59769
(9.1 CRITICAL)

EPSS: 0.33%

updated 2026-08-25T15:16:35.427000

1 posts

FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen using that credentials to alter the identification number.

hugovalters@mastodon.social at 2026-08-25T15:10:37.000Z ##

CVE-2026-59769 - Hard-coded credentials in FA-50 allow unauthorized settings access and vessel ID alteration. CVSS 9.1. Restrict network access now. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-597

##

CVE-2026-57863
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-25T15:16:35.297000

2 posts

Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory by supplying crafted ZIP archives with ../ sequences to the unzip endpoint. Attackers can exploit unsanitized ZIP entry names passed to PHP's ZipArchive::extractTo() to write arbitrary PHP files into

thehackerwire@mastodon.social at 2026-08-25T14:00:11.000Z ##

🟠 CVE-2026-57863 - High (8.8)

Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory by supplying crafted ZIP archives with ../ sequ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T14:00:11.000Z ##

🟠 CVE-2026-57863 - High (8.8)

Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory by supplying crafted ZIP archives with ../ sequ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18798
(7.5 HIGH)

EPSS: 0.00%

updated 2026-08-25T15:16:31.207000

2 posts

Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly impro

DailyCyberSecurity at 2026-08-25T15:59:01.497Z ##

The August 2026 OpenSSL security update fixes 9 flaws, including a QUIC double free (CVE-2026-18798) and a CMS heap overflow. Patch now.

securityonline.info/openssl-se

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T15:59:01.000Z ##

The August 2026 OpenSSL security update fixes 9 flaws, including a QUIC double free (CVE-2026-18798) and a CMS heap overflow. Patch now.

#OpenSSL #CyberSecurity #CVE #DenialOfService #InfoSec

securityonline.info/openssl-se

##

CVE-2026-55538
(7.3 HIGH)

EPSS: 0.00%

updated 2026-08-25T14:57:00

1 posts

### Summary `praisonai serve agents` exposes HTTP routes that invoke registered agents. The CLI advertises `--api-key` with help text "API key for authentication", parses it, and forwards it into `ServeHandler`. But `_create_agents_app()` **never reads `config["api_key"]` again** and installs no auth dependency or middleware on its direct routes. The configured key is a no-op flag. As a result,

hugovalters@mastodon.social at 2026-08-25T17:02:43.000Z ##

CVE-2026-55538 - Auth bypass in PraisonAI allows unauthorized API execution on agent endpoints. CVSS 7.3. Update to v4.6.58 immediately. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-555

##

CVE-2026-55540
(7.1 HIGH)

EPSS: 0.00%

updated 2026-08-25T14:54:57

1 posts

### Summary PraisonAI's `praisonai.code` tool wrappers (exported as `CODE_TOOLS` for agents) expose a `workspace` setting that the module itself treats as a path-traversal **security boundary** — `read_file`, `write_file`, `apply_diff`, and `search_replace` explicitly call `is_path_within_directory()` and return `"… is outside the workspace"` on violations. That boundary is enforced **unsoundly an

hugovalters@mastodon.social at 2026-08-25T18:13:47.000Z ##

CVE-2026-55540 - Arbitrary File Read in PraisonAI via symlink path traversal. CVSS 7.1. Update to version 4.6.58 immediately. #CVE #PraisonAI #infosec

valtersit.com/cve/CVE-2026-555

##

CVE-2026-16687
(9.6 CRITICAL)

EPSS: 0.21%

updated 2026-08-25T14:31:59.517000

2 posts

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker with network access can send the FSP a malformed request, allowing arbitrary code execution, giving the attacker full control over the managed system, resulting in a confidentiality, inte

DailyCyberSecurity at 2026-08-24T13:16:53.853Z ##

IBM patches two Power Systems Firmware flaws, CVE-2026-16687 and CVE-2026-16835, both CVSS 9.6, that grant full control of the managed system.

securityonline.info/ibm-power-

##

DailyCyberSecurity@infosec.exchange at 2026-08-24T13:16:53.000Z ##

IBM patches two Power Systems Firmware flaws, CVE-2026-16687 and CVE-2026-16835, both CVSS 9.6, that grant full control of the managed system.

#IBM #PowerSystems #Firmware #CVE #RCE #AuthBypass #InfoSec #PatchNow

securityonline.info/ibm-power-

##

CVE-2026-78003
(9.8 CRITICAL)

EPSS: 0.57%

updated 2026-08-25T14:16:55.953000

2 posts

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_POST['addresses'], passes them through sanitize_text_field(). This makes it possible for unauthenticated attackers to make

thehackerwire@mastodon.social at 2026-08-22T09:59:53.000Z ##

🔴 CVE-2026-78003 - Critical (9.8)

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts use...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-22T09:00:24.000Z ##

CRITICAL: Mailgun for WordPress ≤2.2.0 vulnerable to SSRF (CVE-2026-78003). Attackers can exploit input validation in add_list() to hijack admin resets & compromise sites. Update/disable plugin now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #SSRF

##

CVE-2026-77136
(0 None)

EPSS: 0.55%

updated 2026-08-25T14:16:54.297000

2 posts

The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as template source, without any sanitization, and renders it. An anonymous, unauthenticated user can submit Fluid template syntax in that field to execute arbitrary Fluid ViewHelpers leading to disclosure of server configuration, environment variables and applica

DailyCyberSecurity at 2026-08-25T10:28:28.607Z ##

A critical TYPO3 Powermail RCE flaw (CVE-2026-77136) is actively exploited in the wild. Update immediately to prevent server compromise and data leaks.

securityonline.info/cve-2026-7

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T10:28:28.000Z ##

A critical TYPO3 Powermail RCE flaw (CVE-2026-77136) is actively exploited in the wild. Update immediately to prevent server compromise and data leaks.

#TYPO3 #Powermail #Vulnerability #CyberSecurity #CVE202677136

securityonline.info/cve-2026-7

##

CVE-2026-57910
(0 None)

EPSS: 0.00%

updated 2026-08-25T13:19:24.810000

4 posts

Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.

CVE-2026-57909
(0 None)

EPSS: 0.00%

updated 2026-08-25T13:19:24.590000

4 posts

A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.

DailyCyberSecurity at 2026-08-26T01:47:28.637Z ##

Two critical WatchGuard Agent flaws (CVE-2026-57909, CVE-2026-57910) allow unauthenticated remote code execution. Update to 1.25.13.0000 now.

securityonline.info/watchguard

##

cR0w at 2026-08-25T14:07:01.584Z ##

sev:CRIT ../ in WatchGuard Agent. Once again, INFOSEC increasing that attack surface instead of decreasing it.

nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-08-26T01:47:28.000Z ##

Two critical WatchGuard Agent flaws (CVE-2026-57909, CVE-2026-57910) allow unauthenticated remote code execution. Update to 1.25.13.0000 now.

#WatchGuard #RCE #CyberSecurity #CVE202657909 #Infosec

securityonline.info/watchguard

##

cR0w@infosec.exchange at 2026-08-25T14:07:01.000Z ##

sev:CRIT ../ in WatchGuard Agent. Once again, INFOSEC increasing that attack surface instead of decreasing it.

nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-78570
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-25T12:31:29

2 posts

The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to elevate their privileges to that of an adminsitrator.

offseq at 2026-08-25T10:30:23.560Z ##

KlbTheme Total Donations <=2.0.5 has a CRITICAL privilege escalation vuln (CVE-2026-78570, CVSS 9.8). Unauthenticated attackers can gain admin access. No patch yet — disable/remove plugin & monitor for advisories. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-25T10:30:23.000Z ##

KlbTheme Total Donations <=2.0.5 has a CRITICAL privilege escalation vuln (CVE-2026-78570, CVSS 9.8). Unauthenticated attackers can gain admin access. No patch yet — disable/remove plugin & monitor for advisories. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE #Vuln

##

CVE-2026-78563
(7.2 HIGH)

EPSS: 0.19%

updated 2026-08-25T09:30:48

1 posts

The NotificationX Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

hugovalters@mastodon.social at 2026-08-25T12:01:22.000Z ##

CVE-2026-78563 - Stored XSS in NotificationX Pro plugin for WordPress (<= 3.1.4). Unauthenticated script injection. CVSS 7.2. Audit sites now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-785

##

CVE-2026-78568
(9.8 CRITICAL)

EPSS: 0.30%

updated 2026-08-25T09:30:48

2 posts

The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive informa

offseq at 2026-08-25T09:00:26.074Z ##

CVE-2026-78568: CRITICAL SQL Injection in KlbTheme Total Donations ≤2.0.5. Unauthenticated attackers can extract sensitive DB data via improper input handling. No fix yet — disable the plugin. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-25T09:00:26.000Z ##

CVE-2026-78568: CRITICAL SQL Injection in KlbTheme Total Donations ≤2.0.5. Unauthenticated attackers can extract sensitive DB data via improper input handling. No fix yet — disable the plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #SQLi #Vuln

##

CVE-2026-71366
(7.7 HIGH)

EPSS: 0.33%

updated 2026-08-25T09:30:36

2 posts

A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without validating the target address against private, loopback, or reserved IP ranges. An organization notification administrator can create notification templates p

thehackerwire@mastodon.social at 2026-08-24T17:00:39.000Z ##

🟠 CVE-2026-71366 - High (7.7)

A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without valid...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-24T17:00:39.000Z ##

🟠 CVE-2026-71366 - High (7.7)

A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without valid...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63587
(8.6 HIGH)

EPSS: 0.27%

updated 2026-08-25T09:17:32.057000

2 posts

The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliber

certvde at 2026-08-25T08:55:43.635Z ##

🔒 New CSAF advisory published

VDE-2026-083
Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities
CVE-2026-63586, CVE-2026-63587

Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execu…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-08-25T08:55:43.000Z ##

🔒 New CSAF advisory published

VDE-2026-083
Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities
CVE-2026-63586, CVE-2026-63587

Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execu…

HTML: weidmueller.csaf-tp.certvde.co
CSAF JSON: weidmueller.csaf-tp.certvde.co

#OT #Advisory

##

CVE-2026-78477
(9.8 CRITICAL)

EPSS: 0.30%

updated 2026-08-25T06:31:36

2 posts

The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.

offseq at 2026-08-25T06:00:24.365Z ##

Privilege escalation vuln (CRITICAL, CVSS 9.8) in MVPThemes Jawn WordPress theme (≤1.4.2): CVE-2026-78477 lets unauth users elevate to admin. Review deployments & monitor for fixes. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-25T06:00:24.000Z ##

Privilege escalation vuln (CRITICAL, CVSS 9.8) in MVPThemes Jawn WordPress theme (≤1.4.2): CVE-2026-78477 lets unauth users elevate to admin. Review deployments & monitor for fixes. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #PrivilegeEscalation

##

CVE-2026-41992
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-25T06:31:17

2 posts

GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a spe

certvde at 2026-08-25T10:45:02.867Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-08-25T10:45:02.000Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2026-78541
(0 None)

EPSS: 0.96%

updated 2026-08-25T04:18:21.310000

2 posts

A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during daily cloud report generation and may result in arbitrary command execution. Successful exploitation may allow comman

DailyCyberSecurity at 2026-08-25T01:49:25.678Z ##

TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.

securityonline.info/cve-2026-9

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T01:49:25.000Z ##

TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.

#TPLink #CyberSecurity #CVE20269254 #CommandInjection

securityonline.info/cve-2026-9

##

CVE-2026-76904
(9.8 CRITICAL)

EPSS: 0.52%

updated 2026-08-25T04:18:20.870000

1 posts

GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataStore implementation: `jsonArrayContains` function; Requires PostGIS 12 or greater with a String or JSON field. For PostGIS 12 and greater `jsonArrayContains(<colum

1 repos

https://github.com/YonLiud/CVE-2026-76904

sayzard@mastodon.sayzard.org at 2026-08-23T22:38:27.000Z ##

AI scanner AgentGG found GeoServer SQL injection before zero-day

GeoServer/GeoTools의 `jsonArrayContains` 필터에서 인증 없이 도달 가능한 SQL 인젝션(CVE-2026-76904, CVSS 9.8)이 공개됐으며, PostGIS 12 이상 구성에서는 입력값이 SQL 문자열에 적절히 이스케이프되지 않는 것이 원인이다. 공개 직후 인터넷 노출 GeoServer 인스턴스를 대상으로 대규모 스캔·탐색 시도가 관측됐고, GeoServer는 긴급 패치를 배포했다. 이는 2023...

medium.com/@philipgarabandic/a

##

CVE-2026-21962
(10.0 CRITICAL)

EPSS: 42.02%

updated 2026-08-25T04:18:11.067000

27 posts

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to c

9 repos

https://github.com/gglessner/cve_2026_21962_scanner

https://github.com/naozibuhao/CVE-2026-21962_Java_GUI_Exploit_Tool

https://github.com/George0Papasotiriou/CVE-2026-21962-Oracle-HTTP-Server-WebLogic-Proxy-Plug-in-Critical-

https://github.com/samael0x4/CVE-2026-21962

https://github.com/boroeurnprach/Ashwesker-CVE-2026-21962

https://github.com/ThumpBo/CVE-2026-21962

https://github.com/gregk4sec/CVE-2026-21962-o

https://github.com/gregk4sec/cve-2026-21962

https://github.com/0xBlackash/CVE-2026-21962

thecybermind at 2026-08-25T22:49:03.835Z ##

🚨 Critical Threat Intel: CVE-2026-21962 impacts Oracle HTTP Server & Weblogic Proxy Plug-in via access control bypass. Review exploitation patterns, web access detection queries, and active endpoint hardening actions.
thecybermind.co/jily

##

cyberworldops at 2026-08-25T22:20:00.700Z ##

CISA has added Oracle CVE-2026-21962 to the KEV catalog. CVSS 10.0. This critical flaw in WebLogic Server allows unauthenticated access and is confirmed actively exploited. Federal remediation deadline is August 27, but every WebLogic deployment should be treated as urgent. Patch or isolate immediately.

cyberworldops.eu/en/oracle-cve

##

undercodenews@mastodon.social at 2026-08-25T18:53:17.000Z ##

CISA Confirms Active Exploitation of Critical Oracle Vulnerability — CVE-2026-21962 Carries a 100 Severity Score + Video

A Critical Oracle Flaw Has Crossed Into the Real-World Threat Landscape A critical vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in has moved from a serious patching concern to an active cybersecurity threat. On August 24, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added…

undercodenews.com/cisa-confirm

##

sayzard@mastodon.sayzard.org at 2026-08-25T18:42:41.000Z ##

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

CISA가 실제 악용 중인 CVSS 10.0 취약점 CVE-2026-21962에 대해 연방 기관에 최단 수준인 3일 이내 패치 기한을 부여했습니다. 이 취약점은 Oracle HTTP Server와 WebLogic Server Proxy Plug-in의 부적절한 접근 제어 문제로, 공격자가 중요 데이터를 생성·삭제·변조하거나 영향받는 시스템의 모든 데이터에 완전 접근할 수 있습니다. 영향을 받는 버전은 12...

theregister.com/security/2026/

##

Matchbook3469@mastodon.social at 2026-08-25T16:39:25.000Z ##

🔵 THREAT INTELLIGENCE

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

Vulnerability | CRITICAL
CVEs: CVE-2026-21962

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and...

Full analysis:
yazoul.net/news/article/active

by Yazoul AI

#CyberSecurity #CVE #ThreatHunting

##

netsecio@mastodon.social at 2026-08-25T14:22:08.000Z ##

📰 CISA Adds Actively Exploited Oracle Flaw to KEV Catalog

CISA adds actively exploited Oracle vulnerability CVE-2026-21962 to its KEV catalog. Flaw affects Oracle HTTP Server & WebLogic Server Proxy Plug-in. Federal agencies must patch. #CVE #Oracle #CISA #KEV #PatchNow

🔗 cyber.netsecops.io/articles/ci

##

cyberveille@mastobot.ping.moi at 2026-08-25T12:00:05.000Z ##

📢 Exploitation active de CVE-2026-21962 dans Oracle HTTP Server — ajout au catalogue KEV de la CISA

GBHackers, publié le 25 août 2026. La CISA (U.S. Cybersecurity and Infrastructure Security Agency) a officiellement ajouté CVE-2026-21962 à son catalogue Known Exploited Vulnerabilities (KEV), confirmant une exploitation active dans la nature.

📖 cyberveille : cyberveille.ch/posts/2026-08-2
🌐 source : gbhackers.com/hackers-exploit-
🟡 vérification factuelle moyenne
#OracleHTTPServer #CISAKEV #Cyberveille

##

undercodenews@mastodon.social at 2026-08-25T11:23:19.000Z ##

CISA Sounds the Alarm as Critical Oracle WebLogic Flaw Faces Active Exploitation + Video

A Critical Warning That Oracle Administrators Cannot Ignore A new cybersecurity warning is putting Oracle infrastructure under intense pressure after the U.S. Cybersecurity and Infrastructure Security Agency, CISA, ordered organizations to urgently address CVE-2026-21962, a critical vulnerability affecting Oracle HTTP Server and the WebLogic Server Proxy plugin. The danger is not…

undercodenews.com/cisa-sounds-

##

youranonnewsirc@nerdculture.de at 2026-08-25T10:26:18.000Z ##

Geopolitical tensions escalate as the US launches "Operation Economic Outcast" against Iran, imposing new sanctions amidst Strait of Hormuz disputes (Aug 25). Canada is set to announce retaliatory tariffs against the US (Aug 25). The UK and Ukraine formalized an AI defense partnership (Aug 24).

In technology, Nvidia's AI chips remain a focal point, with Taiwan indicting nine individuals for illegal AI server exports to China (Aug 24). Hybrid bonding is advancing as a foundational technology for enhanced semiconductor performance (Aug 25).

Cybersecurity: CISA issued a warning regarding the active exploitation of an Oracle WebLogic vulnerability (CVE-2026-21962), urging immediate patching (Aug 25). ReliaQuest also confirmed an employee fell victim to a social engineering attack (Aug 25).

#AnonNews_irc #Cybersecurity #News

##

security_crawler_carl at 2026-08-25T09:45:06.059Z ##

CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.

Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.

Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.

(2/2)

##

security_crawler_carl at 2026-08-25T09:45:05.905Z ##

🏆 New Achievement! Ten Point Oh, Your Honor!

This court finds Oracle WebLogic Server and Oracle HTTP Server guilty of harboring CVE-2026-21962 — a CVSS 10.0, maximum-severity flaw allowing unauthenticated attackers full network access via HTTP to seize instances and tamper with critical data. The defendant offered no authentication requirement whatsoever. CISA has entered the verdict into its Known Exploited Vulnerabilities catalog. (1/2)

##

undercodenews@mastodon.social at 2026-08-25T09:28:04.000Z ##

Oracle WebLogic Faces a Maximum-Severity Threat as CISA Flags CVE-2026-21962 for Immediate Action + Video

A Critical Warning for Oracle Administrators A vulnerability with the highest possible CVSS severity has moved from a technical security advisory into a much more urgent category: CISA’s Known Exploited Vulnerabilities catalog. The flaw, tracked as CVE-2026-21962, affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, creating a potentially…

undercodenews.com/oracle-weblo

##

undercodenews@mastodon.social at 2026-08-25T07:11:21.000Z ##

CISA Sounds the Alarm as Maximum-Severity Oracle Flaw CVE-2026-21962 Faces Active Exploitation + Video

Introduction: When a Critical Oracle Server Becomes an Open Door A critical vulnerability does not always become a cybersecurity emergency the moment it is discovered. Sometimes the real danger begins later, when proof-of-concept activity spreads, attackers start scanning the internet, and defenders realize that systems which should have been patched months ago are…

undercodenews.com/cisa-sounds-

##

Analyst207@mastodon.social at 2026-08-25T06:55:40.000Z ##

CISA Warns of Actively Exploited Oracle WebLogic Flaw

A critical Oracle WebLogic flaw, CVE-2026-21962, is being actively exploited, allowing hackers to wreak havoc on your system by creating, deleting, or modifying sensitive data. This severe vulnerability has a CVSS score of 10.0, making it a high-priority threat that demands immediate attention.

osintsights.com/cisa-warns-of-

#OracleWeblogic #Cve202621962 #ImproperAccessControl #EmergingThreats #Cybersecurity

##

youranonnewsirc@nerdculture.de at 2026-08-25T04:26:31.000Z ##

Here's a summary of recent geopolitical, technology, and cybersecurity news:

Geopolitical: The US has launched "Operation Economic Outcast" against Iran (Aug 25) and plans 7.5% tariffs on Chinese goods over excess manufacturing capacity before a September summit (Aug 25).

Technology: Google is reorganizing DeepMind and acquired Spirit Airlines' data for AI model development (Aug 24). Fujitsu is trialing AI for construction process and risk management (Aug 25).

Cybersecurity: CISA added an Oracle HTTP Server vulnerability (CVE-2026-21962) to its Known Exploited Vulnerabilities Catalog (Aug 24). Critical GitLab (CVE-2026-19478) and Cisco vulnerabilities (CVSS 10.0) are under active exploitation (Aug 24).

#AnonNews_irc #Cybersecurity #News

##

DailyCyberSecurity at 2026-08-25T01:41:50.903Z ##

CISA warned that the CVE-2026-21962 Oracle flaw with a CVSS 10 score is actively exploited in the wild. Patch Oracle Fusion Middleware systems now.

securityonline.info/cve-2026-2

##

secdb at 2026-08-24T21:00:17.132Z ##

🚨 [CISA-2026:0824] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-21962 (secdb.nttzen.cloud/cve/detail/)
- Name: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Oracle
- Product: HTTP Server and Oracle Weblogic Server Proxy Plug-in
- Notes: oracle.com/security-alerts/cpu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-08-24T19:00:45.000Z ##

CVE ID: CVE-2026-21962
Vendor: Oracle
Product: HTTP Server and Oracle Weblogic Server Proxy Plug-in
Date Added: 2026-08-24
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

thecybermind@infosec.exchange at 2026-08-25T22:49:03.000Z ##

🚨 Critical Threat Intel: CVE-2026-21962 impacts Oracle HTTP Server & Weblogic Proxy Plug-in via access control bypass. Review exploitation patterns, web access detection queries, and active endpoint hardening actions.
thecybermind.co/jily

##

cyberworldops@infosec.exchange at 2026-08-25T22:20:00.000Z ##

CISA has added Oracle CVE-2026-21962 to the KEV catalog. CVSS 10.0. This critical flaw in WebLogic Server allows unauthenticated access and is confirmed actively exploited. Federal remediation deadline is August 27, but every WebLogic deployment should be treated as urgent. Patch or isolate immediately.

#OracleCVE202621962 #WebLogic #CISA #KnownExploitedVulnerabilities

cyberworldops.eu/en/oracle-cve

##

youranonnewsirc@nerdculture.de at 2026-08-25T10:26:18.000Z ##

Geopolitical tensions escalate as the US launches "Operation Economic Outcast" against Iran, imposing new sanctions amidst Strait of Hormuz disputes (Aug 25). Canada is set to announce retaliatory tariffs against the US (Aug 25). The UK and Ukraine formalized an AI defense partnership (Aug 24).

In technology, Nvidia's AI chips remain a focal point, with Taiwan indicting nine individuals for illegal AI server exports to China (Aug 24). Hybrid bonding is advancing as a foundational technology for enhanced semiconductor performance (Aug 25).

Cybersecurity: CISA issued a warning regarding the active exploitation of an Oracle WebLogic vulnerability (CVE-2026-21962), urging immediate patching (Aug 25). ReliaQuest also confirmed an employee fell victim to a social engineering attack (Aug 25).

#AnonNews_irc #Cybersecurity #News

##

security_crawler_carl@infosec.exchange at 2026-08-25T09:45:06.000Z ##

CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.

Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.

Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.

#CyberSecurity #Oracle #WebLogic #ZeroDay #Vulnerability #CriticalHit (2/2)

##

security_crawler_carl@infosec.exchange at 2026-08-25T09:45:05.000Z ##

🏆 New Achievement! Ten Point Oh, Your Honor!

This court finds Oracle WebLogic Server and Oracle HTTP Server guilty of harboring CVE-2026-21962 — a CVSS 10.0, maximum-severity flaw allowing unauthenticated attackers full network access via HTTP to seize instances and tamper with critical data. The defendant offered no authentication requirement whatsoever. CISA has entered the verdict into its Known Exploited Vulnerabilities catalog. (1/2)

##

youranonnewsirc@nerdculture.de at 2026-08-25T04:26:31.000Z ##

Here's a summary of recent geopolitical, technology, and cybersecurity news:

Geopolitical: The US has launched "Operation Economic Outcast" against Iran (Aug 25) and plans 7.5% tariffs on Chinese goods over excess manufacturing capacity before a September summit (Aug 25).

Technology: Google is reorganizing DeepMind and acquired Spirit Airlines' data for AI model development (Aug 24). Fujitsu is trialing AI for construction process and risk management (Aug 25).

Cybersecurity: CISA added an Oracle HTTP Server vulnerability (CVE-2026-21962) to its Known Exploited Vulnerabilities Catalog (Aug 24). Critical GitLab (CVE-2026-19478) and Cisco vulnerabilities (CVSS 10.0) are under active exploitation (Aug 24).

#AnonNews_irc #Cybersecurity #News

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T01:41:50.000Z ##

CISA warned that the CVE-2026-21962 Oracle flaw with a CVSS 10 score is actively exploited in the wild. Patch Oracle Fusion Middleware systems now.

#Oracle #CVE202621962 #CyberSecurity #CISA #Vulnerability

securityonline.info/cve-2026-2

##

secdb@infosec.exchange at 2026-08-24T21:00:17.000Z ##

🚨 [CISA-2026:0824] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-21962 (secdb.nttzen.cloud/cve/detail/)
- Name: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Oracle
- Product: HTTP Server and Oracle Weblogic Server Proxy Plug-in
- Notes: oracle.com/security-alerts/cpu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260824 #cisa20260824 #cve_2026_21962 #cve202621962

##

cisakevtracker@mastodon.social at 2026-08-24T19:00:45.000Z ##

CVE ID: CVE-2026-21962
Vendor: Oracle
Product: HTTP Server and Oracle Weblogic Server Proxy Plug-in
Date Added: 2026-08-24
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-17250
(0 None)

EPSS: 0.19%

updated 2026-08-25T04:18:10.233000

2 posts

A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL-MR6400 v7 due to unsafe processing of attacker-controlled metadata within a firmware image. Successful exploitation may allow an authenticated attacker to trigger memory corruption and execute arbitrary code on the affected device.

CVE-2026-10053
(8.5 HIGH)

EPSS: 0.72%

updated 2026-08-25T04:17:40.250000

2 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.

1 repos

https://github.com/dinosn/CVE-2026-10053-lab

Matchbook3469@mastodon.social at 2026-08-24T07:41:25.000Z ##

🟠 New security advisory:

CVE-2026-10053 affects multiple systems.

• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#InfoSec #SecurityPatching #HackerNews

##

thehackerwire@mastodon.social at 2026-08-23T11:02:00.000Z ##

🟠 CVE-2026-10053 - High (8.5)

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78676
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-08-25T03:32:20

4 posts

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

beyondmachines1 at 2026-08-25T15:01:41.789Z ##

GitPython Patches Critical RCE Vulnerability in Config Parser

GitPython version 3.1.59 patches a critical remote code execution vulnerability (CVE-2026-78676) caused by improper handling of multi-line configuration values. The flaw allows attackers to inject malicious Git directives that execute arbitrary code during routine repository operations.

**If you use GitPython in any application or CI/CD pipeline, update it to version 3.1.59 or later. Еvery version up to 3.1.58 is vulnerable to CVE-2026-78676. Until you can update, don't let GitPython read or write config files from cloned repos, shared configs, or workspace caches you don't fully control. Тreat any repository from an outside source as untrusted.**

beyondmachines.net/event_detai

##

offseq at 2026-08-25T03:00:25.721Z ##

CVE-2026-78676 | GitPython <3.1.59 has a CRITICAL argument injection flaw: multi-line git-config values can become active directives, enabling arbitrary code execution via git hooks. Patch status unknown — avoid untrusted configs. radar.offseq.com/threat/cve-20

##

beyondmachines1@infosec.exchange at 2026-08-25T15:01:41.000Z ##

GitPython Patches Critical RCE Vulnerability in Config Parser

GitPython version 3.1.59 patches a critical remote code execution vulnerability (CVE-2026-78676) caused by improper handling of multi-line configuration values. The flaw allows attackers to inject malicious Git directives that execute arbitrary code during routine repository operations.

**If you use GitPython in any application or CI/CD pipeline, update it to version 3.1.59 or later. Еvery version up to 3.1.58 is vulnerable to CVE-2026-78676. Until you can update, don't let GitPython read or write config files from cloned repos, shared configs, or workspace caches you don't fully control. Тreat any repository from an outside source as untrusted.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

offseq@infosec.exchange at 2026-08-25T03:00:25.000Z ##

CVE-2026-78676 | GitPython <3.1.59 has a CRITICAL argument injection flaw: multi-line git-config values can become active directives, enabling arbitrary code execution via git hooks. Patch status unknown — avoid untrusted configs. radar.offseq.com/threat/cve-20 #OffSeq #CVE202678676 #git #infosec

##

CVE-2026-72702
(5.4 MEDIUM)

EPSS: 0.10%

updated 2026-08-25T03:32:14

2 posts

Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix match (str_starts_with($referrer, $base)) with no trailing delimiter. An attacker who controls a domain that begins with the victim site's origin (e.g. https://example.com.attacker.tld) can send a request with suc

offseq at 2026-08-25T04:30:23.315Z ##

CVE-2026-72702 | Grav CMS <2.0.16 | CRITICAL (CVSS 9.3): Origin validation bypass via weak Referer checks lets attackers defeat CSRF defenses. No fix confirmed — use extra controls, monitor vendor updates. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-25T04:30:23.000Z ##

CVE-2026-72702 | Grav CMS <2.0.16 | CRITICAL (CVSS 9.3): Origin validation bypass via weak Referer checks lets attackers defeat CSRF defenses. No fix confirmed — use extra controls, monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202672702 #GravCMS #WebSecurity

##

CVE-2026-78264
(7.1 HIGH)

EPSS: 0.15%

updated 2026-08-25T00:30:37

1 posts

Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.

hugovalters@mastodon.social at 2026-08-25T14:04:05.000Z ##

CVE-2026-78264 - Unauthenticated XSS in Toolset Blocks <= 1.6.26. CVSS 7.1. Update immediately. #CVE #XSS #infosec

valtersit.com/cve/CVE-2026-782

##

CVE-2026-78265
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-08-25T00:30:37

4 posts

Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.

offseq at 2026-08-25T01:30:23.183Z ##

CRITICAL CVE-2026-78265: Nexcess The Events Calendar <=6.17.2 has unauthenticated PHP Object Injection (CWE-502). Full system compromise possible. No patch yet — remove or disable plugin for now. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-24T23:00:10.000Z ##

🔴 CVE-2026-78265 - Critical (9.8)

Unauthenticated PHP Object Injection in The Events Calendar &lt;= 6.17.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-25T01:30:23.000Z ##

CRITICAL CVE-2026-78265: Nexcess The Events Calendar <=6.17.2 has unauthenticated PHP Object Injection (CWE-502). Full system compromise possible. No patch yet — remove or disable plugin for now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #CVE2026_78265

##

thehackerwire@mastodon.social at 2026-08-24T23:00:10.000Z ##

🔴 CVE-2026-78265 - Critical (9.8)

Unauthenticated PHP Object Injection in The Events Calendar &lt;= 6.17.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-32556
(7.1 HIGH)

EPSS: 0.15%

updated 2026-08-25T00:30:37

2 posts

Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.

hugovalters@mastodon.social at 2026-08-25T01:01:34.000Z ##

CVE-2026-32556 - Unauthenticated XSS in Boost <= 2.0.4. CVSS 7.1. Currently unpatched. Audit systems and mitigate risk immediately. #CVE #XSS #infosec

valtersit.com/cve/CVE-2026-325

##

hugovalters@mastodon.social at 2026-08-25T01:01:34.000Z ##

CVE-2026-32556 - Unauthenticated XSS in Boost <= 2.0.4. CVSS 7.1. Currently unpatched. Audit systems and mitigate risk immediately. #CVE #XSS #infosec

valtersit.com/cve/CVE-2026-325

##

CVE-2026-78267
(9.8 CRITICAL)

EPSS: 0.27%

updated 2026-08-25T00:30:37

4 posts

Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.

offseq at 2026-08-25T00:00:35.189Z ##

CVE-2026-78267 (CRITICAL, CVSS 9.8): Cozmoslabs TranslatePress <=3.3.2 is vulnerable to unauthenticated privilege escalation (CWE-266). No patch yet — monitor vendor advisories for updates. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-24T23:00:21.000Z ##

🔴 CVE-2026-78267 - Critical (9.8)

Unauthenticated Privilege Escalation in TranslatePress &lt;= 3.3.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-25T00:00:35.000Z ##

CVE-2026-78267 (CRITICAL, CVSS 9.8): Cozmoslabs TranslatePress <=3.3.2 is vulnerable to unauthenticated privilege escalation (CWE-266). No patch yet — monitor vendor advisories for updates. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #PrivilegeEscalation

##

thehackerwire@mastodon.social at 2026-08-24T23:00:21.000Z ##

🔴 CVE-2026-78267 - Critical (9.8)

Unauthenticated Privilege Escalation in TranslatePress &lt;= 3.3.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78268
(7.5 HIGH)

EPSS: 0.25%

updated 2026-08-25T00:30:37

2 posts

Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.

thehackerwire@mastodon.social at 2026-08-25T00:00:16.000Z ##

🟠 CVE-2026-78268 - High (7.5)

Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads &lt;= 1.2.0 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-25T00:00:16.000Z ##

🟠 CVE-2026-78268 - High (7.5)

Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads &lt;= 1.2.0 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19685
(9.8 CRITICAL)

EPSS: 0.14%

updated 2026-08-24T21:34:43

2 posts

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogu

cR0w at 2026-08-24T18:50:25.704Z ##

i uSe lInUx bEcAuSe iT'S SeCuRe.

access.redhat.com/security/cve

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

##

cR0w@infosec.exchange at 2026-08-24T18:50:25.000Z ##

i uSe lInUx bEcAuSe iT'S SeCuRe.

access.redhat.com/security/cve

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

##

CVE-2026-7455
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-24T21:33:53

2 posts

A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

thehackerwire@mastodon.social at 2026-08-24T21:59:55.000Z ##

🟠 CVE-2026-7455 - High (7.8)

A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the conte...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-24T21:59:55.000Z ##

🟠 CVE-2026-7455 - High (7.8)

A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the conte...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61419
(7.8 HIGH)

EPSS: 0.09%

updated 2026-08-24T21:33:52

2 posts

Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

thehackerwire@mastodon.social at 2026-08-24T22:02:00.000Z ##

🟠 CVE-2026-61419 - High (7.8)

Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-24T22:02:00.000Z ##

🟠 CVE-2026-61419 - High (7.8)

Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16783
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-24T21:33:46

2 posts

A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

thehackerwire@mastodon.social at 2026-08-24T22:00:14.000Z ##

🟠 CVE-2026-16783 - High (7.8)

A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the conte...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-24T22:00:14.000Z ##

🟠 CVE-2026-16783 - High (7.8)

A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the conte...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76835
(9.1 CRITICAL)

EPSS: 0.35%

updated 2026-08-24T20:17:19.623000

2 posts

OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/util/util.go prefers that header over the real request URI whenever CanTrustForwardedHeaders returns true, and isAllowedPath in oauthproxy.go matches the s

thehackerwire@mastodon.social at 2026-08-24T19:01:19.000Z ##

🔴 CVE-2026-76835 - Critical (9.1)

OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/ut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-24T19:01:19.000Z ##

🔴 CVE-2026-76835 - Critical (9.1)

OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/ut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-60084
(8.7 HIGH)

EPSS: 0.35%

updated 2026-08-24T20:16:51.410000

1 posts

SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll. Authenticated admin attackers can supply absolute filesystem paths to recursively delete any file or directory the kernel process has permission to remove, anywhere on the host filesystem.

thehackerwire@mastodon.social at 2026-08-22T23:00:32.000Z ##

🟠 CVE-2026-60084 - High (8.7)

SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll. Authenticated admin attackers can supply absolute...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19874
(9.1 CRITICAL)

EPSS: 0.73%

updated 2026-08-24T20:16:42.277000

4 posts

A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The affected function processes a list of kicked player identifiers using the lobby data key "kick_num" to determine the number of entries, and individual kicked player IDs supplied via keys in the format "kicked_id_%i". The functio

1 repos

https://github.com/alicealys/mgo3-rce

CVE-2026-76070
(9.8 CRITICAL)

EPSS: 1.00%

updated 2026-08-24T19:16:58.433000

2 posts

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler in /bin/netis.cgi. Attackers can exploit the custom Base64 decoder's lack of output length validation against the fixed-size stack buffer to achieve remote cod

1 repos

https://github.com/ozcanpng/CVE-2026-76070

thehackerwire@mastodon.social at 2026-08-24T17:00:49.000Z ##

🔴 CVE-2026-76070 - Critical (9.8)

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler in /bi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-24T17:00:49.000Z ##

🔴 CVE-2026-76070 - Critical (9.8)

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler in /bi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71506
(8.1 HIGH)

EPSS: 0.30%

updated 2026-08-24T19:16:49.960000

1 posts

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the intended payment-issuance rights check. Attackers can exploit this misconfigured permission check to zero paid amounts on invoices and remove entries from accountin

1 repos

https://github.com/CyberWarrior9/dolibarr

hugovalters@mastodon.social at 2026-08-25T11:06:42.000Z ##

CVE-2026-71506 - Broken Access Control in Dolibarr REST API allows unauthorized deletion of payment records. CVSS 8.1. Restrict API access immediately. #CVE #Dolibarr #infosec

valtersit.com/cve/CVE-2026-715

##

CVE-2026-9254(CVSS UNKNOWN)

EPSS: 2.35%

updated 2026-08-24T18:32:04

2 posts

An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges. Successful exploitation may result in complete device compromise and imp

1 repos

https://github.com/Slagzz/CVE-2026-9254

DailyCyberSecurity at 2026-08-25T01:49:25.678Z ##

TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.

securityonline.info/cve-2026-9

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T01:49:25.000Z ##

TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.

#TPLink #CyberSecurity #CVE20269254 #CommandInjection

securityonline.info/cve-2026-9

##

CVE-2026-16348(CVSS UNKNOWN)

EPSS: 0.91%

updated 2026-08-24T18:31:59

2 posts

An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.  Successful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices.

1 repos

https://github.com/Slagzz/CVE-2026-16348

DailyCyberSecurity at 2026-08-25T01:49:25.678Z ##

TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.

securityonline.info/cve-2026-9

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T01:49:25.000Z ##

TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.

#TPLink #CyberSecurity #CVE20269254 #CommandInjection

securityonline.info/cve-2026-9

##

CVE-2026-76071
(9.8 CRITICAL)

EPSS: 1.06%

updated 2026-08-24T18:31:59

2 posts

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in netis.cgi. Attackers can exploit widthless sscanf conversions that copy user-supplied input into fixed-size stack buffers before authentication is verif

1 repos

https://github.com/ozcanpng/CVE-2026-76071

thehackerwire@mastodon.social at 2026-08-24T17:00:29.000Z ##

🔴 CVE-2026-76071 - Critical (9.8)

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-24T17:00:29.000Z ##

🔴 CVE-2026-76071 - Critical (9.8)

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76073
(8.8 HIGH)

EPSS: 0.28%

updated 2026-08-24T18:31:57

2 posts

Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup retrieves any annotation by primary key. The view's permission_required entries name annotations.view, annotations.change and annotations.delete, and lab

thehackerwire@mastodon.social at 2026-08-24T19:01:07.000Z ##

🟠 CVE-2026-76073 - High (8.8)

Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-24T19:01:07.000Z ##

🟠 CVE-2026-76073 - High (8.8)

Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9769
(7.5 HIGH)

EPSS: 0.28%

updated 2026-08-24T18:17:35.520000

1 posts

justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which recursively traverses the DOM tree via _find_elements()/_find_element() without a depth bound. An attacker who can supply HTML for parsing can provide deeply nested elements (e.g.

thehackerwire@mastodon.social at 2026-08-23T15:00:07.000Z ##

🟠 CVE-2026-9769 - High (7.5)

justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which recursively traverses the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78167
(10.0 CRITICAL)

EPSS: 1.03%

updated 2026-08-24T18:17:26.737000

2 posts

A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure

thehackerwire@mastodon.social at 2026-08-24T03:00:32.000Z ##

🔴 CVE-2026-78167 - Critical (10)

A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-24T03:00:32.000Z ##

🔴 CVE-2026-78167 - Critical (10)

A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76838
(8.5 HIGH)

EPSS: 0.31%

updated 2026-08-24T18:17:22.363000

2 posts

Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethostbyname() and rejects private and reserved ranges, which any public hostname passes. At dispatch, WebhookDispatchService takes the stored URL and calls it through spatie/laravel-webhook-server without r

thehackerwire@mastodon.social at 2026-08-24T19:00:56.000Z ##

🟠 CVE-2026-76838 - High (8.5)

Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethostbyname() and rejects private and reserved ranges...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-24T19:00:56.000Z ##

🟠 CVE-2026-76838 - High (8.5)

Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethostbyname() and rejects private and reserved ranges...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78168
(9.8 CRITICAL)

EPSS: 0.93%

updated 2026-08-24T16:40:53.647000

4 posts

A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in a

offseq at 2026-08-24T06:00:24.272Z ##

CRITICAL vuln (CVE-2026-78168) in EFM ipTIME T24000M ≤14.20.0: improper authentication in httpcon_check_session_url enables remote exploit. Public exploit disclosed, no vendor fix. Review access controls now. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-24T03:00:41.000Z ##

🔴 CVE-2026-78168 - Critical (9.8)

A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-24T06:00:24.000Z ##

CRITICAL vuln (CVE-2026-78168) in EFM ipTIME T24000M ≤14.20.0: improper authentication in httpcon_check_session_url enables remote exploit. Public exploit disclosed, no vendor fix. Review access controls now. radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoTSecurity #Exploit

##

thehackerwire@mastodon.social at 2026-08-24T03:00:41.000Z ##

🔴 CVE-2026-78168 - Critical (9.8)

A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59568
(9.1 CRITICAL)

EPSS: 0.38%

updated 2026-08-24T15:31:57

3 posts

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.

undercodenews@mastodon.social at 2026-08-25T12:13:23.000Z ##

Critical Zscaler Client Connector Vulnerability Could Give Attackers Remote Code Execution Without Credentials + Video

Introduction: A Trusted Security Agent Can Become an Attacker’s Doorway Security software is supposed to be one of the strongest layers protecting an enterprise endpoint. But when a vulnerability strikes the security agent itself, the risk can become far more serious than an ordinary application flaw. That is the concern surrounding CVE-2026-59568, a…

undercodenews.com/critical-zsc

##

cR0w at 2026-08-24T18:12:33.649Z ##

nvd.nist.gov/vuln/detail/CVE-2

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.

##

cR0w@infosec.exchange at 2026-08-24T18:12:33.000Z ##

nvd.nist.gov/vuln/detail/CVE-2

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.

##

CVE-2026-77995(CVSS UNKNOWN)

EPSS: 0.29%

updated 2026-08-24T15:31:57

2 posts

Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.

offseq at 2026-08-24T13:30:27.026Z ##

CVE-2026-77995 (CRITICAL, CVSS 10): miniOrange OAuth Client for Joomla (v1.0.0 – 3.1.9) allows arbitrary account takeover via cookie manipulation. Patch to 3.2.0+ required. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-24T13:30:27.000Z ##

CVE-2026-77995 (CRITICAL, CVSS 10): miniOrange OAuth Client for Joomla (v1.0.0 – 3.1.9) allows arbitrary account takeover via cookie manipulation. Patch to 3.2.0+ required. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #Vuln #OAuth

##

CVE-2026-73570
(8.9 HIGH)

EPSS: 1.51%

updated 2026-08-24T13:19:17.577000

15 posts

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands a

3 repos

https://github.com/jishino567/CVE-2026-73570

https://github.com/BiuTrap/CVE-2026-73570

https://github.com/HORKimhab/CVE-2026-73570

undercodenews@mastodon.social at 2026-08-25T17:04:58.000Z ##

Zimbra Servers Under Active Attack as a Critical RCE Flaw Turns Into a Real-World Security Emergency + Video

A New Warning for Zimbra Administrators A serious cybersecurity incident is unfolding around Zimbra Collaboration Suite, with organizations facing active exploitation of a high-severity vulnerability that can allow unauthenticated attackers to execute operating-system commands remotely. The vulnerability, tracked as CVE-2026-73570, affects Zimbra Collaboration…

undercodenews.com/zimbra-serve

##

youranonnewsirc@nerdculture.de at 2026-08-25T16:26:22.000Z ##

Here's a concise overview of recent geopolitical, technology, and cybersecurity developments:

Geopolitical: The US has declared an "economic D-Day" against Iran, which is now threatening Strait of Hormuz disruption. China completed its largest South China Sea naval base at Antelope Reef.

Cybersecurity: Norway's public services were hit by a major DDoS attack on August 25. Iran-linked cyberattacks are increasingly targeting critical infrastructure in the UK and US. Over 270 Zimbra servers have been compromised via a high-severity RCE flaw (CVE-2026-73570).

Technology: Apple unveiled its M6 and M5 Ultra chips on August 25, significantly boosting AI performance in new Macs.

#AnonNews_irc #Cybersecurity #Anonymous #News

##

undercodenews@mastodon.social at 2026-08-25T12:48:55.000Z ##

Zimbra Under Siege: Hackers Have Already Breached Hundreds of Servers Through a High-Severity RCE Flaw

A New Zimbra Crisis Is Already Moving Beyond the Patch Window A dangerous Zimbra Collaboration Suite vulnerability has moved from a security advisory into an active compromise campaign, with hundreds of Internet-exposed servers reportedly showing evidence of exploitation. The vulnerability, tracked as CVE-2026-73570, enables unauthenticated remote command execution on…

undercodenews.com/zimbra-under

##

Analyst207@mastodon.social at 2026-08-25T12:25:47.000Z ##

Hackers Breach 270 Zimbra Servers in Remote Code Execution Attacks

A massive wave of hacking attacks has hit 270 Zimbra servers, exploiting a vulnerability that lets attackers inject malicious code remotely, with fixes available since July 20. The attacks, tracked as CVE-2026-73570, have been spreading rapidly, sparking urgent security warnings.

osintsights.com/hackers-breach

#RemoteCodeExecution #Zimbra #Cve202673570 #SnmpCommandInjection #EmergingThreats

##

tierrasapiens@mastodon.social at 2026-08-25T11:48:09.000Z ##

🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ Exploited Zimbra Flaw Highlights Shrinking Window to Patch
🔗 darkreading.com/vulnerabilitie

CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.

##

undercodenews@mastodon.social at 2026-08-24T18:38:33.000Z ##

CISA Sounds the Alarm: Actively Exploited Zimbra Vulnerability Puts Mail Servers at Risk + Video

A Critical Warning for Zimbra Administrators A serious cybersecurity warning has emerged for organizations running Zimbra Collaboration Suite, as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-73570 to its Known Exploited Vulnerabilities catalog. The vulnerability is reportedly being exploited in the wild, turning what might otherwise be…

undercodenews.com/cisa-sounds-

##

threatnoir at 2026-08-24T18:06:18.790Z ##

⚠️ CRITICAL: CISA orders urgent patching of actively exploited Zimbra flaw

Zimbra Collaboration Suite (ZCS) has a critical unauthenticated RCE vulnerability (CVE-2026-73570) that is actively exploited in the wild. Any organization running ZCS is at immediate risk of full system compromise. CISA has mandated U.S. government agencies patch within three days.

threatnoir.com/focus

🤖 AI generated summary

##

cyberworldops at 2026-08-24T16:20:00.385Z ##

CVE-2026-73570 is an OS command injection in Zimbra Collaboration Suite being actively exploited. CISA added it to the KEV catalog with a 72-hour remediation window. This class of flaw allows full remote code execution, making it one of the most severe issues in any mail and collaboration platform.

cyberworldops.eu/en/zimbra-und

##

offseq at 2026-08-24T12:00:31.513Z ##

CVE-2026-73570: Actively exploited CRITICAL RCE in Zimbra Collaboration Suite <10.1.20 via SNMP command injection. Patch to 10.1.20 now. Watch for suspicious service restarts & files in /opt/zimbra/jetty/webapps/. Details: radar.offseq.com/threat/cisa-o

##

Analyst207@mastodon.social at 2026-08-24T10:56:03.000Z ##

CISA Mandates Emergency Patching for Exploited Zimbra Flaw

A critical Zimbra flaw, CVE-2026-73570, allows hackers to inject malicious code, and the CISA is mandating emergency patching to prevent devastating attacks - don't wait, get protected now!

osintsights.com/cisa-mandates-

#Cve202673570 #Zimbra #CommandInjection #RemoteCodeExecution #Snmp

##

youranonnewsirc@nerdculture.de at 2026-08-25T16:26:22.000Z ##

Here's a concise overview of recent geopolitical, technology, and cybersecurity developments:

Geopolitical: The US has declared an "economic D-Day" against Iran, which is now threatening Strait of Hormuz disruption. China completed its largest South China Sea naval base at Antelope Reef.

Cybersecurity: Norway's public services were hit by a major DDoS attack on August 25. Iran-linked cyberattacks are increasingly targeting critical infrastructure in the UK and US. Over 270 Zimbra servers have been compromised via a high-severity RCE flaw (CVE-2026-73570).

Technology: Apple unveiled its M6 and M5 Ultra chips on August 25, significantly boosting AI performance in new Macs.

#AnonNews_irc #Cybersecurity #Anonymous #News

##

threatnoir@infosec.exchange at 2026-08-24T18:06:18.000Z ##

⚠️ CRITICAL: CISA orders urgent patching of actively exploited Zimbra flaw

Zimbra Collaboration Suite (ZCS) has a critical unauthenticated RCE vulnerability (CVE-2026-73570) that is actively exploited in the wild. Any organization running ZCS is at immediate risk of full system compromise. CISA has mandated U.S. government agencies patch within three days.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

cyberworldops@infosec.exchange at 2026-08-24T16:20:00.000Z ##

CVE-2026-73570 is an OS command injection in Zimbra Collaboration Suite being actively exploited. CISA added it to the KEV catalog with a 72-hour remediation window. This class of flaw allows full remote code execution, making it one of the most severe issues in any mail and collaboration platform.

#Zimbra #CVE202673570 #CISA #KnownExploitedVulnerabilities

cyberworldops.eu/en/zimbra-und

##

offseq@infosec.exchange at 2026-08-24T12:00:31.000Z ##

CVE-2026-73570: Actively exploited CRITICAL RCE in Zimbra Collaboration Suite <10.1.20 via SNMP command injection. Patch to 10.1.20 now. Watch for suspicious service restarts & files in /opt/zimbra/jetty/webapps/. Details: radar.offseq.com/threat/cisa-o #OffSeq #Zimbra #Infosec #RCE

##

youranonnewsirc@nerdculture.de at 2026-08-22T10:26:23.000Z ##

Geopolitical tensions rise as the US escalates economic pressure on Iran, which labels new sanctions as a "declaration of war". Ukraine faces critical missile shortages amid intensified Russian strikes. In technology, major investments continue in AI infrastructure, with Google backing Marvell's custom AI chips. Cybersecurity sees CISA adding a critical Zimbra vulnerability (CVE-2026-73570) to its KEV catalog and new banking Trojans actively exploited globally.

#AnonNews_irc #Cybersecurity #News

##

CVE-2026-28171
(8.6 HIGH)

EPSS: 0.34%

updated 2026-08-24T12:31:46

1 posts

Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.

hugovalters@mastodon.social at 2026-08-24T18:14:25.000Z ##

CVE-2026-28171 - Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7. CVSS 8.6. Currently unpatched. Deactivate plugin now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-281

##

CVE-2026-77994(CVSS UNKNOWN)

EPSS: 0.23%

updated 2026-08-24T09:33:52

2 posts

Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the loadStyles method of the frontend page model.

offseq at 2026-08-24T09:00:26.468Z ##

CVE-2026-77994: CRITICAL SQL injection in Joomla Page Builder CK (v1.0.0-3.6.4). Unauthenticated remote SQL execution possible. No official fix yet — disable/remove vulnerable versions. CVSS 9.3. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-24T09:00:26.000Z ##

CVE-2026-77994: CRITICAL SQL injection in Joomla Page Builder CK (v1.0.0-3.6.4). Unauthenticated remote SQL execution possible. No official fix yet — disable/remove vulnerable versions. CVSS 9.3. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #SQLInjection #Infosec

##

CVE-2026-8173
(5.3 MEDIUM)

EPSS: 0.21%

updated 2026-08-24T09:33:52

2 posts

The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.

certvde at 2026-08-24T06:50:50.186Z ##

VDE-2026-061
Vulnerability in 'Copy learned MAC Addresses' function enables MAC Spoofing on Xelity Switches

An information disclosure vulnerability in the web GUI of Murrelektronik Xelity switches causes MAC addresses from the device's MAC address table to be written into a server-side log that is exposed via the device's web interface to unauthenticated users. The leak is triggered when an authenticated administrator invokes the 'Copy learned MAC Addresses' function, which causes a syslog error that inserts the affected MAC addresses into the log output. Once the error has been triggered, any unauthenticated attacker with network access to the web interface can retrieve the leaked MAC addresses via common browser developer tools. The vulnerable functionality was introduced in version 2.1.0 and is fixed in version 2.1.1.
CVE-2026-8173

certvde.com/en/advisories/vde-

murrelektronik.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-08-24T06:50:50.000Z ##

#OT #Advisory VDE-2026-061
Vulnerability in 'Copy learned MAC Addresses' function enables MAC Spoofing on Xelity Switches

An information disclosure vulnerability in the web GUI of Murrelektronik Xelity switches causes MAC addresses from the device's MAC address table to be written into a server-side log that is exposed via the device's web interface to unauthenticated users. The leak is triggered when an authenticated administrator invokes the 'Copy learned MAC Addresses' function, which causes a syslog error that inserts the affected MAC addresses into the log output. Once the error has been triggered, any unauthenticated attacker with network access to the web interface can retrieve the leaked MAC addresses via common browser developer tools. The vulnerable functionality was introduced in version 2.1.0 and is fixed in version 2.1.1.
#CVE CVE-2026-8173

certvde.com/en/advisories/vde-

#CSAF murrelektronik.csaf-tp.certvde

##

CVE-2026-78211
(9.8 CRITICAL)

EPSS: 1.54%

updated 2026-08-24T06:30:35

2 posts

4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter, thereby executing arbitrary system commands on the server.

offseq at 2026-08-24T04:30:23.159Z ##

4MOSAn GCB Doctor faces a CRITICAL OS Command Injection (CVE-2026-78211, CVSS 9.8). Unauthenticated attackers can execute arbitrary system commands via ADOdb test page parameter. No patch — restrict access & monitor closely. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-24T04:30:23.000Z ##

4MOSAn GCB Doctor faces a CRITICAL OS Command Injection (CVE-2026-78211, CVSS 9.8). Unauthenticated attackers can execute arbitrary system commands via ADOdb test page parameter. No patch — restrict access & monitor closely. radar.offseq.com/threat/cve-20 #OffSeq #CVE202678211 #Vuln #BlueTeam

##

CVE-2026-78170
(8.8 HIGH)

EPSS: 0.44%

updated 2026-08-24T03:31:14

2 posts

A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. Executing a manipulation of the argument ssid can lead to buffer overflow. The attack may be performed from remote. The exploit has been published and may be used.

thehackerwire@mastodon.social at 2026-08-24T04:00:01.000Z ##

🟠 CVE-2026-78170 - High (8.8)

A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. Executing a manipulation of the argument ssid can lead to buffer overflow. The attack may be performed from...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-24T04:00:01.000Z ##

🟠 CVE-2026-78170 - High (8.8)

A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. Executing a manipulation of the argument ssid can lead to buffer overflow. The attack may be performed from...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78169
(9.9 CRITICAL)

EPSS: 0.44%

updated 2026-08-24T03:31:14

4 posts

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.

thehackerwire@mastodon.social at 2026-08-24T03:00:51.000Z ##

🔴 CVE-2026-78169 - Critical (9.9)

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile resul...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-24T03:00:25.953Z ##

CRITICAL: Stack-based buffer overflow (CVE-2026-78169) in UTT HiPER 1250GW v3.2.7-210907-180535. Public exploit code available — no patch yet. Restrict device access & monitor /goform/aspRemoteApConfTempSend traffic. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-24T03:00:51.000Z ##

🔴 CVE-2026-78169 - Critical (9.9)

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile resul...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-24T03:00:25.000Z ##

CRITICAL: Stack-based buffer overflow (CVE-2026-78169) in UTT HiPER 1250GW v3.2.7-210907-180535. Public exploit code available — no patch yet. Restrict device access & monitor /goform/aspRemoteApConfTempSend traffic. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec #IoT

##

CVE-2026-78207
(9.4 CRITICAL)

EPSS: 0.44%

updated 2026-08-24T03:31:14

2 posts

exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto__ property to cell notes, modifying Object.prototype and affecting all plain objects created in the process.

thehackerwire@mastodon.social at 2026-08-24T02:00:05.000Z ##

🔴 CVE-2026-78207 - Critical (9.4)

exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-24T02:00:05.000Z ##

🔴 CVE-2026-78207 - Critical (9.4)

exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78209
(8.2 HIGH)

EPSS: 0.29%

updated 2026-08-24T03:31:06

2 posts

exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened in a spreadsheet application, potentially exfiltrating data or performing other malicious actions.

thehackerwire@mastodon.social at 2026-08-24T02:00:27.000Z ##

🟠 CVE-2026-78209 - High (8.2)

exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-24T02:00:27.000Z ##

🟠 CVE-2026-78209 - High (8.2)

exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78208
(7.5 HIGH)

EPSS: 0.37%

updated 2026-08-24T01:16:58.280000

2 posts

exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed it in the generated workbook.

thehackerwire@mastodon.social at 2026-08-24T02:00:15.000Z ##

🟠 CVE-2026-78208 - High (7.5)

exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed it ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-24T02:00:15.000Z ##

🟠 CVE-2026-78208 - High (7.5)

exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed it ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18052
(8.1 HIGH)

EPSS: 0.27%

updated 2026-08-23T18:32:50

2 posts

The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the site, including an administrator.

thehackerwire@mastodon.social at 2026-08-23T22:00:10.000Z ##

🟠 CVE-2026-18052 - High (8.1)

The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T22:00:10.000Z ##

🟠 CVE-2026-18052 - High (8.1)

The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76793
(8.1 HIGH)

EPSS: 0.35%

updated 2026-08-23T18:31:45

2 posts

The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administrators.

thehackerwire@mastodon.social at 2026-08-23T21:59:59.000Z ##

🟠 CVE-2026-76793 - High (8.1)

The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T21:59:59.000Z ##

🟠 CVE-2026-76793 - High (8.1)

The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77002
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-08-23T18:31:44

2 posts

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.

thehackerwire@mastodon.social at 2026-08-23T18:00:30.000Z ##

🔴 CVE-2026-77002 - Critical (9.8)

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T18:00:30.000Z ##

🔴 CVE-2026-77002 - Critical (9.8)

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77001
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-08-23T18:31:44

3 posts

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators. In the default case a session as the site's original administrator account is obt

thehackerwire@mastodon.social at 2026-08-23T18:00:21.000Z ##

🔴 CVE-2026-77001 - Critical (9.8)

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T18:00:21.000Z ##

🔴 CVE-2026-77001 - Critical (9.8)

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-22T13:30:23.000Z ##

CVE-2026-77001: CRITICAL vuln in Social Login & Sharing buttons with Analytics By SoClever (≤1.2.0). No auth checks — attackers can hijack any user session, including admin. Remove/disable plugin pending fix. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202677001 #Vulnerability

##

CVE-2026-77000
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-08-23T16:16:38.360000

2 posts

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplying that user's email address.

thehackerwire@mastodon.social at 2026-08-23T18:00:11.000Z ##

🔴 CVE-2026-77000 - Critical (9.8)

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, incl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T18:00:11.000Z ##

🔴 CVE-2026-77000 - Critical (9.8)

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, incl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-76789
(8.8 HIGH)

EPSS: 0.34%

updated 2026-08-23T16:16:38.043000

2 posts

The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users to store malicious JavaScript which will be executed in the context of an administrator viewing the Slider Hero with Video Background, Animation WordPress

thehackerwire@mastodon.social at 2026-08-23T21:59:49.000Z ##

🟠 CVE-2026-76789 - High (8.8)

The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-23T21:59:49.000Z ##

🟠 CVE-2026-76789 - High (8.8)

The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-7808
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-08-23T15:33:12

3 posts

justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues primarily affect advanced usage rather than the default JustHTML(..., sanitize=True) path for ordinary parsed HTML: mutating or reusing sanitization policy objects (including exporte

offseq at 2026-08-24T01:30:25.778Z ##

CVE-2026-7808 | justhtml <1.16.0 faces CRITICAL XSS risk via HTML sanitization bypass in advanced use cases. Upgrade to 1.16.0+ to fix. Impacts apps with custom/mutated policies. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-24T01:30:25.000Z ##

CVE-2026-7808 | justhtml <1.16.0 faces CRITICAL XSS risk via HTML sanitization bypass in advanced use cases. Upgrade to 1.16.0+ to fix. Impacts apps with custom/mutated policies. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE20267808 #infosec #XSS

##

thehackerwire@mastodon.social at 2026-08-23T15:00:18.000Z ##

🔴 CVE-2026-7808 - Critical (9.8)

justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues primarily affect advanced usa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8445
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-08-23T15:33:12

3 posts

justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). While a small set of Markdown metacharacters are escaped, characters such as < and > are preserved, so untrusted input that is safe in to_html() — including entity-decoded text (e.g. &lt;script&gt;) or t

offseq at 2026-08-24T00:00:35.979Z ##

CVE-2026-8445: EmilStenstrom justhtml <=1.11.0 suffers CRITICAL XSS due to improper escaping in Markdown output. Remote attackers can inject scripts. Update to v1.12.0 now. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-24T00:00:35.000Z ##

CVE-2026-8445: EmilStenstrom justhtml <=1.11.0 suffers CRITICAL XSS due to improper escaping in Markdown output. Remote attackers can inject scripts. Update to v1.12.0 now. radar.offseq.com/threat/cve-20 #OffSeq #XSS #AppSec #CVE20268445

##

thehackerwire@mastodon.social at 2026-08-23T15:00:30.000Z ##

🔴 CVE-2026-8445 - Critical (9.8)

justhtml versions &lt;= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). While a small set of Markdown metacharacters ar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-4671
(7.5 HIGH)

EPSS: 0.37%

updated 2026-08-23T15:33:12

1 posts

justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query(), matches(), or selector-based transforms), run selector matching over very large untrusted documents, construct DOM trees from untrusted structure, or enable linkification over attacker-controlled tex

1 repos

https://github.com/HAERIN-L/POC_CVE-2026-46716

thehackerwire@mastodon.social at 2026-08-23T15:01:03.000Z ##

🟠 CVE-2026-4671 - High (7.5)

justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query(), matches(), or selector-based transforms), run ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5388
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-08-23T15:33:04

1 posts

justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Depending on configuration, an attacker can bypass sanitization to inject active HTML and JavaScript — for example via encoded javascript: URLs, backslash-b

thehackerwire@mastodon.social at 2026-08-23T15:01:13.000Z ##

🔴 CVE-2026-5388 - Critical (9.8)

justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Dep...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78155
(9.9 CRITICAL)

EPSS: 0.27%

updated 2026-08-23T12:31:11

2 posts

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

thehackerwire@mastodon.social at 2026-08-23T11:01:51.000Z ##

🔴 CVE-2026-78155 - Critical (9.9)

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-23T10:30:24.000Z ##

CVE-2026-78155: OnGres StackGres operator has a critical (CVSS 9.9) priv esc vuln via untrusted search path (CWE-426). No patch yet. Restrict tenant privileges & monitor for escalation attempts. More info: radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #PrivilegeEscalation

##

CVE-2026-13598(CVSS UNKNOWN)

EPSS: 0.15%

updated 2026-08-23T06:30:28

1 posts

The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leading to full site takeover.

offseq@infosec.exchange at 2026-08-23T07:30:23.000Z ##

CVE-2026-13598: RestrictMate <1.3.0 (WordPress) CRITICAL vuln lets unauthenticated users create admin accounts via improper privilege management. Disable user registration or validate roles until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202613598 #Infosec

##

CVE-2026-78136
(7.8 HIGH)

EPSS: 0.19%

updated 2026-08-23T03:34:57

3 posts

chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.

hugovalters@mastodon.social at 2026-08-24T01:03:05.000Z ##

CVE-2026-78136 - High-severity Eval Injection in CHIRP via crafted CSV data. CVSS 7.8. Update to the latest build immediately. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-781

##

offseq@infosec.exchange at 2026-08-23T06:00:24.000Z ##

CVE-2026-78136: HIGH severity eval injection in chirpmyradio CHIRP (<39178db). Malicious CSV data can trigger arbitrary code execution. No patch yet — avoid untrusted files. Full details: radar.offseq.com/threat/cve-20 #OffSeq #chirpmyradio #Vulnerability #InfoSec

##

thehackerwire@mastodon.social at 2026-08-23T01:59:48.000Z ##

🟠 CVE-2026-78136 - High (7.8)

chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16149
(8.8 HIGH)

EPSS: 0.43%

updated 2026-08-23T00:30:30

3 posts

The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protection, which is enabled by default, hooks the rest_endpoints filter via secure_user_endpoints() and overwrites every registered handler's permission_callback on both the /wp/v2/users and /wp/v2/users/(?P<i

hugovalters@mastodon.social at 2026-08-24T17:08:24.000Z ##

CVE-2026-16149 - Missing Authorization in WordPress Security Hardener plugin (<=2.4.4). Bypasses REST API protections. CVSS 8.8. Monitor for patch now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-161

##

offseq@infosec.exchange at 2026-08-23T12:00:23.000Z ##

CVE-2026-16149 (HIGH, CVSS 8.8): marc4 Security Hardener <=2.4.4 allows Subscriber-level users to create Admin accounts or reset passwords via REST API. Disable plugin or limit API access pending patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vulnerability #Infosec

##

thehackerwire@mastodon.social at 2026-08-23T01:00:14.000Z ##

🟠 CVE-2026-16149 - High (8.8)

The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protection, which is enabled by default, hooks the rest_e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78122
(7.4 HIGH)

EPSS: 0.32%

updated 2026-08-23T00:30:30

2 posts

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs, and /containers/{id}/top to read arbitrary files and download entire container filesystems as tar archives.

1 repos

https://github.com/Legendile7/CVE-2026-78122-POC

hugovalters@mastodon.social at 2026-08-24T15:05:21.000Z ##

CVE-2026-78122 - Arbitrary file read in docker-socket-proxy allows leaks of container filesystems and logs. CVSS 7.4. Review and restrict proxy access now. #CVE #Docker #infosec

valtersit.com/cve/CVE-2026-781

##

offseq@infosec.exchange at 2026-08-23T13:30:23.000Z ##

CVE-2026-78122: HIGH severity in Tecnativa docker-socket-proxy (CVSS 8.3). Insufficient access control enables attackers to read files & export entire container filesystems via Docker API. Restrict access, check vendor guidance. radar.offseq.com/threat/cve-20 #OffSeq #Docker #Infosec #Vuln

##

CVE-2026-78050
(9.9 CRITICAL)

EPSS: 0.57%

updated 2026-08-23T00:30:30

2 posts

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management. The manipulation of the argument timestr/ntp_client_enabled results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used.

thehackerwire@mastodon.social at 2026-08-23T01:00:26.000Z ##

🔴 CVE-2026-78050 - Critical (9.9)

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management. The manipulation of the argument timestr/ntp_cl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-23T00:00:34.000Z ##

CRITICAL: CVE-2026-78050 in Comfast CF-N1-S (2.6.0.1) enables remote code execution via stack-based buffer overflow in web mgmt (/cgi-bin/mbox-config). Public exploit out, no patch yet. Restrict access! radar.offseq.com/threat/cve-20 #OffSeq #CVE202678050 #infosec #IoT

##

CVE-2026-47895
(7.5 HIGH)

EPSS: 0.67%

updated 2026-08-23T00:30:22

2 posts

In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.

hugovalters@mastodon.social at 2026-08-23T18:07:24.000Z ##

CVE-2026-47895 - Double-Free vulnerability in strongSwan EAP identity parsing. CVSS 7.5. Update to version 6.0.7 immediately. #CVE #strongSwan #infosec

valtersit.com/cve/CVE-2026-478

##

thehackerwire@mastodon.social at 2026-08-22T22:59:52.000Z ##

🟠 CVE-2026-47895 - High (7.5)

In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-4703
(9.8 CRITICAL)

EPSS: 0.62%

updated 2026-08-22T18:30:25

2 posts

The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has

offseq@infosec.exchange at 2026-08-23T01:30:26.000Z ##

CVE-2026-4703: WS Form LITE ≤1.10.80 has a CRITICAL PHP Object Injection vuln via form meta deserialization. Exploitable if a POP chain exists in another plugin/theme — possible RCE, file deletion, or data leak. Audit plugins/themes. radar.offseq.com/threat/the-ws #OffSeq #WordPress #CVE20264703

##

thehackerwire@mastodon.social at 2026-08-22T20:59:49.000Z ##

🔴 CVE-2026-4703 - Critical (9.8)

The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68766
(7.8 HIGH)

EPSS: 0.16%

updated 2026-08-22T15:31:11

2 posts

hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-controlled content to arbitrary files, enabling code execution when targeting shell startup files.

hugovalters@mastodon.social at 2026-08-24T14:06:30.000Z ##

CVE-2026-68766 - Code execution in hashcat. Command-line option injection via restore files enables arbitrary file writes. CVSS 7.8. Avoid untrusted restore files. #CVE #hashcat #infosec

valtersit.com/cve/CVE-2026-687

##

thehackerwire@mastodon.social at 2026-08-22T20:59:59.000Z ##

🟠 CVE-2026-68766 - High (7.8)

hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-contr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63312
(7.5 HIGH)

EPSS: 0.49%

updated 2026-08-22T15:31:11

3 posts

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.

hugovalters@mastodon.social at 2026-08-24T12:11:33.000Z ##

CVE-2026-63312 - Arbitrary local file read in NLTK StreamBackedCorpusView bypasses pathsec. CVSS 7.5. Exposes sensitive system files. Update to NLTK 3.10.0+. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-633

##

hugovalters@mastodon.social at 2026-08-24T12:11:33.000Z ##

CVE-2026-63312 - Arbitrary local file read in NLTK StreamBackedCorpusView bypasses pathsec. CVSS 7.5. Exposes sensitive system files. Update to NLTK 3.10.0+. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-633

##

thehackerwire@mastodon.social at 2026-08-22T21:00:09.000Z ##

🟠 CVE-2026-63312 - High (7.5)

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63310
(7.1 HIGH)

EPSS: 0.11%

updated 2026-08-22T15:31:11

3 posts

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

hugovalters@mastodon.social at 2026-08-24T11:08:40.000Z ##

CVE-2026-63310 - MITM package injection flaw in NLTK downloader module. CVSS 7.1. Update NLTK to 3.9.3+ immediately. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-633

##

hugovalters@mastodon.social at 2026-08-24T11:08:40.000Z ##

CVE-2026-63310 - MITM package injection flaw in NLTK downloader module. CVSS 7.1. Update NLTK to 3.9.3+ immediately. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-633

##

offseq@infosec.exchange at 2026-08-23T04:30:25.000Z ##

CVE-2026-63310: NLTK <3.9.3 has a CRITICAL flaw where package integrity isn't checked post-download in the downloader module. Exposes users to MITM & DNS poisoning attacks. Upgrade to 3.9.3+ or avoid insecure networks. radar.offseq.com/threat/nltk-b #OffSeq #NLTK #CVE202663310 #infosec

##

CVE-2026-62384
(7.5 HIGH)

EPSS: 0.49%

updated 2026-08-22T15:31:11

3 posts

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass the path validation guard and are resolved to files outside the intended corpus root when accessed via frame_by_name(), _

hugovalters@mastodon.social at 2026-08-23T17:07:03.000Z ##

CVE-2026-62384 - Symlink sandbox bypass in NLTK leads to arbitrary file read. CVSS 7.5. Update to version 3.10.2 now. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-623

##

hugovalters@mastodon.social at 2026-08-23T17:07:03.000Z ##

CVE-2026-62384 - Symlink sandbox bypass in NLTK leads to arbitrary file read. CVSS 7.5. Update to version 3.10.2 now. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-623

##

thehackerwire@mastodon.social at 2026-08-22T22:00:00.000Z ##

🟠 CVE-2026-62384 - High (7.5)

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66393
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-22T15:31:11

2 posts

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the recursion limit to trigger an unhandled RecursionError that crashes the Python process.

hugovalters@mastodon.social at 2026-08-23T15:14:53.000Z ##

CVE-2026-66393 - DoS vulnerability in NLTK. Deeply nested JSON triggers unhandled recursion crash in Python. CVSS 7.5. Update to 3.9.4 immediately. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-663

##

thehackerwire@mastodon.social at 2026-08-22T21:59:51.000Z ##

🟠 CVE-2026-66393 - High (7.5)

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62243
(7.5 HIGH)

EPSS: 0.15%

updated 2026-08-22T15:31:11

1 posts

Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsafe-based trust-manager wrapping is unavailable (Java 25+). In this configuration the OpenSSL client does not perform hostname verification, allowing a ma

thehackerwire@mastodon.social at 2026-08-22T23:59:49.000Z ##

🟠 CVE-2026-62243 - High (7.5)

Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-2996
(7.5 HIGH)

EPSS: 0.49%

updated 2026-08-22T15:31:11

1 posts

The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated attackers to bypass required paid addons and complete purchases at the base product price only, effectively stealing pro

thehackerwire@mastodon.social at 2026-08-22T23:00:22.000Z ##

🟠 CVE-2026-2996 - High (7.5)

The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71513
(8.8 HIGH)

EPSS: 0.78%

updated 2026-08-22T15:31:11

1 posts

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the allowlisted namespace. Attackers can craft untrusted transition-parser models that execute arbitrary commands when TransitionParser.parse loads the mod

thehackerwire@mastodon.social at 2026-08-22T23:00:11.000Z ##

🟠 CVE-2026-71513 - High (8.8)

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62388
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-22T15:31:11

1 posts

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.

thehackerwire@mastodon.social at 2026-08-22T22:00:10.000Z ##

🟠 CVE-2026-62388 - High (7.5)

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59808
(8.8 HIGH)

EPSS: 0.34%

updated 2026-08-22T15:31:05

1 posts

AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() converts this hash into passwordless login as the video owner. Attackers with upload permission can retrieve an administrator's video_id_hash by omitting the v

thehackerwire@mastodon.social at 2026-08-23T01:01:14.000Z ##

🟠 CVE-2026-59808 - High (8.8)

AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() conver...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57998
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-22T15:31:02

1 posts

better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then passes that string to child_process.exec() in index.ts, which spawns a shell. A registry value containing shell metacharacters such as a semicolon, pipe, or command

thehackerwire@mastodon.social at 2026-08-22T23:59:58.000Z ##

🟠 CVE-2026-57998 - High (7.8)

better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then passes that ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59256
(7.5 HIGH)

EPSS: 0.27%

updated 2026-08-22T13:16:38.817000

1 posts

WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. Attackers can retrieve a token from the Gallery endpoint and use it to bypass authorization checks in other subsystems like view/hls.php to access restric

thehackerwire@mastodon.social at 2026-08-23T00:00:09.000Z ##

🟠 CVE-2026-59256 - High (7.5)

WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. A...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77946
(10.0 CRITICAL)

EPSS: 0.62%

updated 2026-08-22T12:30:34

2 posts

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation of the argument system.ntp.server/system.ntp.enable_server/cameo.time.time_zone/cameo.cameo.syslog_server can lead to stack-based buffer overflow. The attack may

offseq@infosec.exchange at 2026-08-22T12:00:23.000Z ##

CVE-2026-77946: Stack-based buffer overflow in TRENDnet TEW-821DAP v2.2.01b05 (CRITICAL, CVSS 10). Remote code execution possible via NTP config. No patch — limit exposure & monitor traffic. radar.offseq.com/threat/cve-20 #OffSeq #CVE202677946 #infosec #vulnerability

##

thehackerwire@mastodon.social at 2026-08-22T12:00:03.000Z ##

🔴 CVE-2026-77946 - Critical (10)

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation of the a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12710
(0 None)

EPSS: 0.32%

updated 2026-08-22T09:16:53.340000

1 posts

A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data. The issue was patched on April 4, 2026; no customer action is required.

offseq@infosec.exchange at 2026-08-22T10:30:22.000Z ##

CRITICAL (CVSS 9.3): CVE-2026-12710 in Google Cloud Application Integration (QueryEngineTask) enabled unauthorized data access. Patched by Google on 2026-04-04 — no customer action needed. Details: radar.offseq.com/threat/cve-20 #OffSeq #CloudSecurity #CVE #Vuln

##

CVE-2026-64531
(7.8 HIGH)

EPSS: 0.38%

updated 2026-08-22T06:31:25

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guar

4 repos

https://github.com/mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool

https://github.com/0xBlackash/CVE-2026-64531

https://github.com/suominen/ovswrap

https://github.com/HackSpeak/CVE-2026-64531

sigint@fosstodon.org at 2026-08-25T23:45:08.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-08-26

Critical HWE kernel flaw on 24.04 means reboot plus DKMS rebuilds for anyone running ZFS, VFIO passthrough, or Nvidia drivers on the 6.14 HWE stack. Check module status before you reboot blind.

🔗 securityarsenal.com/blog/cve-2

#Ubuntu #Linux #infosec

##

CVE-2026-41451
(7.8 HIGH)

EPSS: 0.72%

updated 2026-08-21T18:35:08

1 posts

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories from /etc/passwd are substituted directly into command strings without escaping before execution via eval. Attackers can inject shell metacharacters such as command substitution syntax or semicolons throug

thehackerwire@mastodon.social at 2026-08-22T08:01:56.000Z ##

🟠 CVE-2026-41451 - High (7.8)

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories from /etc/passwd are substituted directly into comma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-27875(CVSS UNKNOWN)

EPSS: 0.07%

updated 2026-08-21T18:35:07

2 posts

Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data. This issue affects Simplex Incident Manager / Autocall Fire Administrator: before 2.01.05.

cyberworldops at 2026-08-25T18:30:00.568Z ##

Johnson Controls resolved a medium-severity flaw (CVE-2026-27875) in Simplex Incident Manager. The application stored user credentials in cleartext in system memory during runtime, allowing local actors to extract passwords and authentication tokens. CISA published advisory ICSA-26-232-01 on August 20, 2026.

cyberworldops.eu/en/cleartext-

##

cyberworldops@infosec.exchange at 2026-08-25T18:30:00.000Z ##

Johnson Controls resolved a medium-severity flaw (CVE-2026-27875) in Simplex Incident Manager. The application stored user credentials in cleartext in system memory during runtime, allowing local actors to extract passwords and authentication tokens. CISA published advisory ICSA-26-232-01 on August 20, 2026.

#CVE202627875 #ICSACyberAdvisory #CleartextStorage

cyberworldops.eu/en/cleartext-

##

CVE-2026-22681
(8.5 HIGH)

EPSS: 0.28%

updated 2026-08-21T18:35:01

1 posts

OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the resources API endpoint. Attackers can POST a crafted URL to /api/v1/resources, causing the server to issue outbound HEAD and GET requests with redirects enabled to loopback, RFC 1918, link-local, or cl

1 repos

https://github.com/pcrosby-1990/cip-security-poc

thehackerwire@mastodon.social at 2026-08-22T10:00:23.000Z ##

🟠 CVE-2026-22681 - High (8.5)

OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the resources API endpoint. Attackers can POST a cr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47827
(7.5 HIGH)

EPSS: 1.16%

updated 2026-08-21T18:34:56

1 posts

Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities

thehackerwire@mastodon.social at 2026-08-23T09:00:17.000Z ##

🟠 CVE-2026-47827 - High (7.5)

Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54795
(8.8 HIGH)

EPSS: 2.39%

updated 2026-08-21T17:57:13.800000

2 posts

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

secdb at 2026-08-24T00:01:16.947Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-48769
(9.9 CRITICAL)

EPSS: 0.44%

updated 2026-08-21T16:17:17.757000

1 posts

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Version 7.2.0 patches the issue.

thehackerwire@mastodon.social at 2026-08-23T01:01:34.000Z ##

🔴 CVE-2026-48769 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48753
(9.9 CRITICAL)

EPSS: 0.71%

updated 2026-08-21T16:17:17.647000

1 posts

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.

thehackerwire@mastodon.social at 2026-08-23T06:00:21.000Z ##

🔴 CVE-2026-48753 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command exec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48749
(9.9 CRITICAL)

EPSS: 0.81%

updated 2026-08-21T16:17:17.413000

1 posts

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fixes the issue.

thehackerwire@mastodon.social at 2026-08-23T02:00:28.000Z ##

🔴 CVE-2026-48749 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fixes the is...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77806
(9.8 CRITICAL)

EPSS: 1.26%

updated 2026-08-21T15:32:18

1 posts

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.

1 repos

https://github.com/CuteeCat/CVE-2026-77806

thehackerwire@mastodon.social at 2026-08-23T07:00:30.000Z ##

🔴 CVE-2026-77806 - Critical (9.8)

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63125
(9.9 CRITICAL)

EPSS: 0.42%

updated 2026-08-21T15:16:46.427000

1 posts

Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on the host. A crafted image ships `backup.yaml` as a symlink to a host file. When the root daemon writes the instance's backup file, it follows the symlin

thehackerwire@mastodon.social at 2026-08-22T12:00:36.000Z ##

🔴 CVE-2026-63125 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77767
(7.5 HIGH)

EPSS: 0.36%

updated 2026-08-21T14:16:53.773000

1 posts

Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires an authenticated user holding the administrator role, so controllers without their own attribute reject anonymous callers. The report preview action in apps/api/app/Controllers/ReportsController.cs carries [AllowAnonymous] and therefore opts out of that policy. PreviewReport loads the Project row named

thehackerwire@mastodon.social at 2026-08-23T07:00:41.000Z ##

🟠 CVE-2026-77767 - High (7.5)

Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires an authenticated user holding the administrator role, so controllers without their own attribute reject anonymous callers. The report preview action in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77086
(9.1 CRITICAL)

EPSS: 0.65%

updated 2026-08-21T12:30:41

1 posts

SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. Attackers with admin access can write arbitrary files to any location via install operations or recursively delete directories via uninstall operations by supplying crafted packageName values.

thehackerwire@mastodon.social at 2026-08-23T07:00:53.000Z ##

🔴 CVE-2026-77086 - Critical (9.1)

SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. Attackers with admin access can write ar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77683
(9.9 CRITICAL)

EPSS: 1.51%

updated 2026-08-21T12:30:37

1 posts

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone. The manipulation of the argument timestr results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

thehackerwire@mastodon.social at 2026-08-23T09:00:03.000Z ##

🔴 CVE-2026-77683 - Critical (9.9)

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone. The manipulation of the argument timestr results in command injection. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72529
(9.8 CRITICAL)

EPSS: 1.55%

updated 2026-08-21T04:18:15.753000

2 posts

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

security_crawler_carl@infosec.exchange at 2026-08-22T20:01:20.000Z ##

🏆 New Achievement! Port 4307 Is Not a Safe Harbor!

Conducting inventory audit on your TrueConf Server installation. Status: compromised. Line items include two unauthenticated RCE vulnerabilities — CVE-2026-72529 and CVE-2026-72530 — currently checked out under the name Head Mare, a hacktivist group who used them to swap a server file for a web shell and deploy PhantomCore malware. Item condition: cursed. (1/2)

##

threatnoir@infosec.exchange at 2026-08-22T17:05:48.000Z ##

⚠️ CRITICAL: CISA orders feds to patch actively exploited TrueConf Server flaws

Two critical unauthenticated RCE vulnerabilities (CVE-2026-72529, CVE-2026-72530) in TrueConf Server are being actively exploited by Head Mare group to deploy backdoor malware via trojanized installers. Any organization running TrueConf Server is at immediate risk of compromise.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

CVE-2026-69836
(10.0 CRITICAL)

EPSS: 1.59%

updated 2026-08-21T00:31:31

4 posts

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

2 repos

https://github.com/HORKimhab/CVE-2026-69836

https://github.com/sentinel-aidefense/CVE-2026-69836-EXP

PC_Fluesterer@social.tchncs.de at 2026-08-24T13:16:56.000Z ##

Mysterien um Microsofts kritisches Sicherheitsloch in Entra ID

Am vorigen Donnerstag macht Microsoft (MS) ein riesiges Trara um eine höchst gefährliche Sicherheitslücke CVE-2026-69836 (Risiko 10 von 10) in Entra ID*. Ein entfernter, nicht autorisierter Angreifer könne durch Ausnutzung dieser Sicherheitslücke beliebigen Programmcode ausführen (RCE). Und die Lücke würde bereits für Angriffe ausgenutzt. Meldungen beispielsweise hier oder hier. Wie die Ausnutzung entdeckt wurde und wer vielleicht betroffen ist, verlautet MS nicht. Einen Tag später zieht MS die Auskunft "wird bereits ausgenutzt" zurück. Hä? Interessant ist auch, dass ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #backdoor #cloud #exploits #identität #Microsoft #sicherheit #unplugMicrosoft #UnplugTrump

##

cyberworldops at 2026-08-24T02:20:01.033Z ##

Microsoft released 22 security patches including a zero-day in Entra ID (CVE-2026-69836) actively exploited for remote code execution. The critical identity-layer flaw was weaponized before a fix became available. ShieldBreak remains unpatched, leaving a documented gap in the security posture of affected organizations.

cyberworldops.eu/en/microsoft-

##

undercodenews@mastodon.social at 2026-08-23T17:06:18.000Z ##

Microsoft Entra ID Faces Maximum-Severity Security Emergency as CVE-2026-69836 Reportedly Comes Under Active Exploitation + Video

A Critical Warning for Organizations That Depend on Cloud Identity Identity infrastructure has become the front door to the modern enterprise. Employees sign in through it, administrators manage systems through it, cloud services trust it, and security teams depend on it to decide who should and should not have access. That is why a newly…

undercodenews.com/microsoft-en

##

cyberworldops@infosec.exchange at 2026-08-24T02:20:01.000Z ##

Microsoft released 22 security patches including a zero-day in Entra ID (CVE-2026-69836) actively exploited for remote code execution. The critical identity-layer flaw was weaponized before a fix became available. ShieldBreak remains unpatched, leaving a documented gap in the security posture of affected organizations.

#MicrosoftPatches #EntraIDZeroDay #ShieldBreak #CVE202669836

cyberworldops.eu/en/microsoft-

##

CVE-2026-72843
(9.8 CRITICAL)

EPSS: 0.59%

updated 2026-08-21T00:31:24

1 posts

The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the caller, and no customer-session middleware guards the route; the only middleware in the chain parses the JSON body. The handler in updateCustomer.js then loads the cust

DailyCyberSecurity@infosec.exchange at 2026-08-23T06:30:49.000Z ##

A critical EverShop account takeover flaw, CVE-2026-72843, exposes systems to an eCommerce platform vulnerability. Update to version 2.2.1 immediately.

#EverShop #CyberSecurity #CVE202672843 #Vulnerability #eCommerce

securityonline.info/evershop-c

##

CVE-2026-19586(CVSS UNKNOWN)

EPSS: 5.04%

updated 2026-08-20T21:31:30

3 posts

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requir

Byte0x90@mastodon.social at 2026-08-25T09:26:35.000Z ##

In TP-Link Omada Business-Gateways klafft eine kritische Lücke (CVE-2026-19586) bei aktivierter OpenVPN-Funktion. Per Command Injection können Angreifer beim VPN-Verbindungsaufbau ohne Zugangsdaten eigenen Code ausführen und das Gerät kompromittieren. Firmware-Updates stehen bereit!

#TPLink #Omada #VPN #CyberSecurity #ITSecurity #Sicherheitslücke #Patchday #InfoSec

##

secdb at 2026-08-24T00:01:16.947Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-64849
(9.3 CRITICAL)

EPSS: 16.41%

updated 2026-08-20T19:16:57.867000

3 posts

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated addr

Nuclei template

3 repos

https://github.com/BiuTrap/CVE-2026-64849

https://github.com/zavisco/CVE-2026-64849.yaml

https://github.com/codeb0ssx/CVE-2026-64849-PoC

secdb at 2026-08-24T00:01:16.947Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

Hackread@mstdn.social at 2026-08-22T11:59:25.000Z ##

Attackers are exploiting a critical MLflow bug to reach internal systems and cloud metadata, putting cloud secrets at risk. CISA has added CVE-2026-64849 to its KEV catalog.

Listen/Read: hackread.com/attackers-exploit

#CyberSecurity #MLflow #AI #Vulnerability #CISA

##

CVE-2026-72530
(9.0 None)

EPSS: 1.83%

updated 2026-08-20T18:31:47

2 posts

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

1 repos

https://github.com/fevar54/CVE-2026-72530-TrueConf-Sandbox-Escape-

security_crawler_carl@infosec.exchange at 2026-08-22T20:01:20.000Z ##

🏆 New Achievement! Port 4307 Is Not a Safe Harbor!

Conducting inventory audit on your TrueConf Server installation. Status: compromised. Line items include two unauthenticated RCE vulnerabilities — CVE-2026-72529 and CVE-2026-72530 — currently checked out under the name Head Mare, a hacktivist group who used them to swap a server file for a web shell and deploy PhantomCore malware. Item condition: cursed. (1/2)

##

threatnoir@infosec.exchange at 2026-08-22T17:05:48.000Z ##

⚠️ CRITICAL: CISA orders feds to patch actively exploited TrueConf Server flaws

Two critical unauthenticated RCE vulnerabilities (CVE-2026-72529, CVE-2026-72530) in TrueConf Server are being actively exploited by Head Mare group to deploy backdoor malware via trojanized installers. Any organization running TrueConf Server is at immediate risk of compromise.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

CVE-2026-18264
(8.8 HIGH)

EPSS: 1.24%

updated 2026-08-20T18:30:55

2 posts

NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NoMachine. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4000 by default. The issue results from the lack of proper validation of a user-supp

secdb at 2026-08-24T00:01:16.947Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-76565
(0 None)

EPSS: 0.32%

updated 2026-08-20T16:18:17.977000

2 posts

Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7

1 repos

https://github.com/toanln-cov/CVE-2026-76565

DarkWebInformer at 2026-08-24T18:16:26.280Z ##

‼️ CVE PoC Published: CVE-2026-76565 - Reflected XSS in PhocaCart

GitHub: github.com/toanln-cov/CVE-2026

A proof-of-concept has been released for CVE-2026-76565, a reflected cross-site scripting (XSS) vulnerability affecting PhocaCart ≤ 6.1.7 for Joomla.

The vulnerability exists in the price_from and price_to filter parameters within the mod_phocacart_filter module. Due to improper output encoding, unauthenticated attackers can craft a malicious URL that injects JavaScript into the page when viewed by a victim.

The PoC demonstrates:

• Reflected XSS through crafted GET parameters
• Exploitation of vulnerable price filter inputs
• Attribute-context injection caused by missing htmlspecialchars() encoding
• No authentication requirement for exploitation
• Affected versions: PhocaCart ≤ 6.1.7
• Fixed version: PhocaCart 6.1.8

💥 No delays. No guessing. No redactions. Get the intel before everyone else with Dark Web Informer.

##

DarkWebInformer@infosec.exchange at 2026-08-24T18:16:26.000Z ##

‼️ CVE PoC Published: CVE-2026-76565 - Reflected XSS in PhocaCart

GitHub: github.com/toanln-cov/CVE-2026

A proof-of-concept has been released for CVE-2026-76565, a reflected cross-site scripting (XSS) vulnerability affecting PhocaCart ≤ 6.1.7 for Joomla.

The vulnerability exists in the price_from and price_to filter parameters within the mod_phocacart_filter module. Due to improper output encoding, unauthenticated attackers can craft a malicious URL that injects JavaScript into the page when viewed by a victim.

The PoC demonstrates:

• Reflected XSS through crafted GET parameters
• Exploitation of vulnerable price filter inputs
• Attribute-context injection caused by missing htmlspecialchars() encoding
• No authentication requirement for exploitation
• Affected versions: PhocaCart ≤ 6.1.7
• Fixed version: PhocaCart 6.1.8

💥 No delays. No guessing. No redactions. Get the intel before everyone else with Dark Web Informer.

##

CVE-2026-75616
(0 None)

EPSS: 1.91%

updated 2026-08-20T16:18:03.890000

2 posts

An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations. An authenticated administrator may exploit insufficient input validation to execute arbitrary system commands, potentially resulting in full device compromise. Successful exploitation may allow arbitrary command execution with el

1 repos

https://github.com/totekuh/CVE-2026-75616

CVE-2026-19490
(0 None)

EPSS: 0.40%

updated 2026-08-20T14:17:10.673000

2 posts

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

security_crawler_carl@infosec.exchange at 2026-08-22T21:32:42.000Z ##

🏆 New Achievement! No Password? No Problem!

Welcome, new player, to the Authentication Bypass Tutorial! This mandatory segment introduces CVE-2026-19490, a CVSS 9.3 critical flaw in Citrix NetScaler ADC and NetScaler Gateway. No account required. No user interaction needed. No elevated privileges. The game just... lets attackers in. Think of it as a permanent debuff applied to your enterprise perimeter. (1/2)

##

benzogaga33@mamot.fr at 2026-08-22T09:40:03.000Z ##

Citrix NetScaler (CVE-2026-19490) : cette faille critique permet de contourner l’authentification it-connect.fr/citrix-netscaler #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

CVE-2026-20231
(9.9 CRITICAL)

EPSS: 0.50%

updated 2026-08-19T21:31:33

1 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. &nbsp; The vulnerabilities tracked by CVE-2026-20231 are related to improper neutralization of special e

nyanbinary@infosec.exchange at 2026-08-22T20:23:15.000Z ##

Fuck it, CVE dumpster diving.

CVE-2026-20231 - this is one of a batch of Cisco CVEs that stood out to me because they have multiple descriptions: One by the CNA, one by an ADP, "CVE" itself. The ADP one is just "please please please dont do this (bundling multiple vulns into a single cve) :neobot_angel_pleading: ". Cisco dont care, they put out 9 of those over the last 7 days.

##

CVE-2026-16835
(9.6 CRITICAL)

EPSS: 0.23%

updated 2026-08-19T21:30:30

2 posts

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration,

DailyCyberSecurity at 2026-08-24T13:16:53.853Z ##

IBM patches two Power Systems Firmware flaws, CVE-2026-16687 and CVE-2026-16835, both CVSS 9.6, that grant full control of the managed system.

securityonline.info/ibm-power-

##

DailyCyberSecurity@infosec.exchange at 2026-08-24T13:16:53.000Z ##

IBM patches two Power Systems Firmware flaws, CVE-2026-16687 and CVE-2026-16835, both CVSS 9.6, that grant full control of the managed system.

#IBM #PowerSystems #Firmware #CVE #RCE #AuthBypass #InfoSec #PatchNow

securityonline.info/ibm-power-

##

CVE-2026-74480
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-08-19T18:33:34

2 posts

In the Linux kernel, the following vulnerability has been resolved: net: bridge: stop fast-leave after deleting a port group br_multicast_leave_group() iterates mp->ports with pp = &p->next in its fast-leave path. After br_multicast_del_pg() removes p, continuing the loop advances pp through the deleted entry. If multicast-to-unicast was enabled, the bridge can hold multiple port groups for the

DailyCyberSecurity at 2026-08-24T07:46:39.663Z ##

CVE-2026-74480 (CVSS 9.8) is a Linux kernel bridge flaw enabling root privilege escalation. Exploit code and a demo video are now public.

securityonline.info/linux-cve-

##

DailyCyberSecurity@infosec.exchange at 2026-08-24T07:46:39.000Z ##

CVE-2026-74480 (CVSS 9.8) is a Linux kernel bridge flaw enabling root privilege escalation. Exploit code and a demo video are now public.

#Linux #CVE202674480 #PrivilegeEscalation #KernelSecurity #CyberSecurity #InfoSec

securityonline.info/linux-cve-

##

CVE-2026-75149
(8.8 HIGH)

EPSS: 0.64%

updated 2026-08-19T18:33:02

1 posts

marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a notebook. When the notebook is opened in edit mode, marimo launches the specified command as a local subprocess before any notebook cell is executed, re

Analyst207@mastodon.social at 2026-08-25T13:57:00.000Z ##

Marimo Notebook Flaw Exposes Users to Pre-Execution Code Injection

A high-severity flaw in Marimo Notebook software, tracked as CVE-2026-75149, could allow attackers to inject malicious code on a user's machine simply by opening a specially crafted notebook in edit mode. This vulnerability, rated 8.7 out of 10 in severity, requires no authentication - just a click.

osintsights.com/marimo-noteboo

#MarimoNotebook #CodeInjection #Cve202675149 #ModelContextProtocol #Preexecution

##

CVE-2026-71961
(8.8 HIGH)

EPSS: 3.05%

updated 2026-08-19T15:32:47

2 posts

Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges by sending unsanitized input through the mesh MQTT command interface. The sync_command binary forwards unsanitized input directly to a shell execution sink in command.lua, enabling attackers with access to the MQTT b

secdb at 2026-08-24T00:01:16.947Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-54796
(7.2 HIGH)

EPSS: 2.36%

updated 2026-08-19T15:32:33

2 posts

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

secdb at 2026-08-24T00:01:16.947Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18963
(9.1 CRITICAL)

EPSS: 2.79%

updated 2026-08-19T03:31:21

18 posts

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user

Nuclei template

8 repos

https://github.com/debugactiveprocess/CVE-2026-18963

https://github.com/Red-Darkin/CVE-2026-18963-keycloak

https://github.com/gman0x00/keycloak-CVE-2026-18963

https://github.com/Snizi/CVE-2026-18963-Exploit

https://github.com/T0w0T/POC-CVE-2026-18963

https://github.com/prot0tw/Keycloak_CVE-2026-18963_PoC

https://github.com/minh3102011/CVE-2026-18963_analyst

https://github.com/kyos-public/keycloak-cve-2026-18963-hunt

F30@chaos.social at 2026-08-25T10:12:47.000Z ##

CVE-2026-18963: #Keycloak arbitrary account takeover via session confusion using simple HTTP requests. 😱

Nice find and (allegedly) not even AI-powered at its core.
A working exploit is publicly available. Given Keycloak's widespread use in critical auth systems, this appears to be flying a bit under the radar so far.

If you run Keycloak, it needs your attention *now*.

github.com/Red-Darkin/CVE-2026

##

inw@mastodon.social at 2026-08-25T08:50:00.000Z ##

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

thehackernews.com/2026/08/crit

> Keycloak CVE-2026-18963 could let unauthenticated attackers skip the emailed action token and reset any user's password.

#keycloak

##

undercodenews@mastodon.social at 2026-08-25T04:22:14.000Z ##

Critical Keycloak Flaw Opens the Door to Silent Account Takeovers, and Identity Infrastructure Is Now the Target + Video

Introduction: When the Password Reset Button Becomes the Attack Vector A password reset feature is supposed to be one of the last lines of defense protecting a user who has lost access to an account. In the case of CVE-2026-18963, however, a flaw in the credential recovery process could turn that protective mechanism into the attacker's path to…

undercodenews.com/critical-key

##

alien@fosstodon.org at 2026-08-24T20:01:50.000Z ##

Note the recently disclosed CVE-2026-18963 for #Keycloak OIDC: thehackernews.com/2026/08/crit . It allows unauthorized users to take over any account on your server.
On the #Slackware #Forgejo instance forge.slackware.nl/ I have upgraded Keycloak to 26.7.2 to address this vulnerability.

##

threatnoir at 2026-08-24T18:06:21.146Z ##

⚠️ CRITICAL: Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Critical flaw in Keycloak (CVE-2026-18963, CVSS 9.1) allows unauthenticated attackers to reset any user password and take over accounts due to improper state validation in the password recovery flow. Any organization running Keycloak without patches is immediately at risk of account takeover on all…

threatnoir.com/focus

🤖 AI generated summary

##

ransomnews@poliversity.it at 2026-08-24T17:37:00.000Z ##

⚠️ Critical Keycloak flaw enables account takeover

CVE-2026-18963 lets unauthenticated attackers reset any user's password, bypassing email verification.

🔗 read more: thehackernews.com/2026/08/crit

#ransomNews #cyberthreats #Keycloak

##

security_crawler_carl at 2026-08-24T16:56:45.640Z ##

🏆 New Achievement! Exhibit A: Your Password Reset Button!

Counsel will direct the court's attention to CVE-2026-18963, rated a damning 9.1 out of 10, wherein Keycloak's reset-credentials authentication flow failed to properly validate state — legally speaking, an open invitation any unauthenticated remote party was fully entitled to accept. No user interaction required. The attacker needed nothing. No account, no session, no strongly-worded letter. (1/2)

##

youranonnewsirc@nerdculture.de at 2026-08-24T16:26:26.000Z ##

Geopolitical tensions rise as US-Iran dispute over Strait of Hormuz escalates; UK pledges long-range missile tech to Ukraine. Nvidia increases AI server prices over 15% due to memory costs. Critical Keycloak flaw (CVE-2026-18963) found allowing account takeovers, while Apple warns of mercenary spyware.

#AnonNews_irc #Cybersecurity #News

##

beyondmachines1 at 2026-08-24T15:01:16.959Z ##

Critical Keycloak Password Reset Flaw Allows Unauthenticated Account Takeover

Red Hat and Keycloak patched a critical vulnerability (CVE-2026-18963) that allows unauthenticated attackers to bypass email verification and take over any account via the password reset flow. The update also addresses over 20 other security flaws, including account-linking bypasses and administrative permission leaks.

**If you run Keycloak or Red Hat Build of Keycloak, update immediately to Keycloak 26.7.2 or RHBK 26.4.15 / 26.6.6 since the older versions let anyone reset the password of any account, including admins. If you cannot patch right away, turn off the "Forgot password" option in every realm (Realm settings → Login → Forgot password) until the update is applied.**

beyondmachines.net/event_detai

##

netsecio@mastodon.social at 2026-08-24T14:18:09.000Z ##

📰 Critical Keycloak Flaw (CVE-2026-18963) Allows Account Takeover

🚨 CRITICAL FLAW: Keycloak is vulnerable to CVE-2026-18963 (CVSS 9.1), allowing unauthenticated remote attackers to take over any account. Patches are available—update immediately! #Keycloak #Cybersecurity #Vulnerability #CVE #IAM

🔗 cyber.netsecops.io/articles/cr

##

Analyst207@mastodon.social at 2026-08-24T12:56:43.000Z ##

Keycloak Flaw Exposes Accounts to Unauthenticated Takeover

A critical flaw in Keycloak, rated 9.1 by Red Hat, allows hackers to hijack any account, including admin ones, by manipulating the password reset process. This vulnerability, CVE-2026-18963, lets attackers take control without even logging in.

osintsights.com/keycloak-flaw-

#Cve202618963 #Keycloak #AccountTakeover #AuthenticationBypass #RedHat

##

F30@chaos.social at 2026-08-25T10:12:47.000Z ##

CVE-2026-18963: #Keycloak arbitrary account takeover via session confusion using simple HTTP requests. 😱

Nice find and (allegedly) not even AI-powered at its core.
A working exploit is publicly available. Given Keycloak's widespread use in critical auth systems, this appears to be flying a bit under the radar so far.

If you run Keycloak, it needs your attention *now*.

github.com/Red-Darkin/CVE-2026

##

inw@mastodon.social at 2026-08-25T08:50:00.000Z ##

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

thehackernews.com/2026/08/crit

> Keycloak CVE-2026-18963 could let unauthenticated attackers skip the emailed action token and reset any user's password.

#keycloak

##

alien@fosstodon.org at 2026-08-24T20:01:50.000Z ##

Note the recently disclosed CVE-2026-18963 for #Keycloak OIDC: thehackernews.com/2026/08/crit . It allows unauthorized users to take over any account on your server.
On the #Slackware #Forgejo instance forge.slackware.nl/ I have upgraded Keycloak to 26.7.2 to address this vulnerability.

##

threatnoir@infosec.exchange at 2026-08-24T18:06:21.000Z ##

⚠️ CRITICAL: Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Critical flaw in Keycloak (CVE-2026-18963, CVSS 9.1) allows unauthenticated attackers to reset any user password and take over accounts due to improper state validation in the password recovery flow. Any organization running Keycloak without patches is immediately at risk of account takeover on all…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

security_crawler_carl@infosec.exchange at 2026-08-24T16:56:45.000Z ##

🏆 New Achievement! Exhibit A: Your Password Reset Button!

Counsel will direct the court's attention to CVE-2026-18963, rated a damning 9.1 out of 10, wherein Keycloak's reset-credentials authentication flow failed to properly validate state — legally speaking, an open invitation any unauthenticated remote party was fully entitled to accept. No user interaction required. The attacker needed nothing. No account, no session, no strongly-worded letter. (1/2)

##

youranonnewsirc@nerdculture.de at 2026-08-24T16:26:26.000Z ##

Geopolitical tensions rise as US-Iran dispute over Strait of Hormuz escalates; UK pledges long-range missile tech to Ukraine. Nvidia increases AI server prices over 15% due to memory costs. Critical Keycloak flaw (CVE-2026-18963) found allowing account takeovers, while Apple warns of mercenary spyware.

#AnonNews_irc #Cybersecurity #News

##

beyondmachines1@infosec.exchange at 2026-08-24T15:01:16.000Z ##

Critical Keycloak Password Reset Flaw Allows Unauthenticated Account Takeover

Red Hat and Keycloak patched a critical vulnerability (CVE-2026-18963) that allows unauthenticated attackers to bypass email verification and take over any account via the password reset flow. The update also addresses over 20 other security flaws, including account-linking bypasses and administrative permission leaks.

**If you run Keycloak or Red Hat Build of Keycloak, update immediately to Keycloak 26.7.2 or RHBK 26.4.15 / 26.6.6 since the older versions let anyone reset the password of any account, including admins. If you cannot patch right away, turn off the "Forgot password" option in every realm (Realm settings → Login → Forgot password) until the update is applied.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-17084
(0 None)

EPSS: 0.48%

updated 2026-08-19T01:16:56.650000

1 posts

The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of the "stringprep" module. This only affects domain names containing characters

sayzard@mastodon.sayzard.org at 2026-08-26T02:43:38.000Z ##

When str.lower() is a security vulnerability in Python – Seth Larson

Python의 IDNA 2003/StringPrep 구현에서 `str.lower()`가 인터프리터에 내장된 최신 Unicode 데이터에 의존해 RFC 3454가 요구하는 Unicode 3.2.0 규칙과 달라질 수 있었던 취약점(CVE-2026-17084)이다. 이 차이로 일부 유니코드 도메인 문자열의 정규화 및 Punycode 결과가 Python/Unicode 버전별로 달라져, IDNA 기반 식별자 비교·검증에서 일관성이 깨질 수 있다. 수정은 최신 Unicode의 `lower()` 결과가 Unicode 3.2.0과 다른 코드포인트를 예외...

sethmlarson.dev/when-str-lower

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 45.88%

updated 2026-08-18T18:32:52

1 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

2 repos

https://github.com/BiuTrap/CVE-2026-59310

https://github.com/HORKimhab/CVE-2026-59310

sekurakbot@mastodon.com.pl at 2026-08-23T15:32:00.000Z ##

Chińskie grupy APT wykorzystują podatność CVE-2026-59310 do masowych ataków na środowiska VMware vCenter

Zespół reagowania na incydenty firmy QUIRSO podczas analizy powłamaniowej serwera VMware vCenter natrafił na ślady globalnej kampanii, sterowanej najprawdopodobniej przez chińską grupę APT. Badania wykazały, że cyberprzestępcy wykorzystali krytyczną podatność CVE-2026-59310 (CVSS 9.8) w usłudze Syslog Server. Równolegle zidentyfikowali próby użycia drugiej luki CVE-2026-59309 (CVSS 9.8) jednak analitycy nie powiązali...

#WBiegu #Apt #Chiny #Cve #DirectoryTraversal #Rce #Vmware

sekurak.pl/chinskie-grupy-apt-

##

CVE-2026-55040
(9.1 CRITICAL)

EPSS: 5.58%

updated 2026-08-18T18:32:50

7 posts

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

2 repos

https://github.com/sfewer-r7/CVE-2026-55040

https://github.com/l0ggg/CVE-2026-55040

undercodenews@mastodon.social at 2026-08-25T19:00:05.000Z ##

Microsoft SharePoint Under Attack: Critical Authentication Bypass Exposes a Potential Pool of 14,000 Internet-Facing Systems + Video

A Dangerous New Chapter for SharePoint Security Microsoft SharePoint has become the focus of a fresh cybersecurity warning after an underground threat actor reportedly published targeting information connected to CVE-2026-55040, a critical authentication-bypass vulnerability affecting Microsoft SharePoint Server. The development is…

undercodenews.com/microsoft-sh

##

DailyCyberSecurity at 2026-08-25T14:19:20.830Z ##

A public SharePoint RCE vulnerability PoC is actively probed in the wild. Patch CVE-2026-63520 and CVE-2026-55040 now to protect your servers.

securityonline.info/sharepoint

##

AAKL at 2026-08-24T17:42:16.040Z ##

New.

VulnCheck: Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain vulncheck.com/blog/cve-2026-63 @vulncheck

##

catc0n at 2026-08-24T14:01:24.840Z ##

Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: vulncheck.com/blog/cve-2026-63

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T14:19:20.000Z ##

A public SharePoint RCE vulnerability PoC is actively probed in the wild. Patch CVE-2026-63520 and CVE-2026-55040 now to protect your servers.

#SharePoint #CVE202663520 #CVE202655040 #CyberSecurity #Exploit

securityonline.info/sharepoint

##

AAKL@infosec.exchange at 2026-08-24T17:42:16.000Z ##

New.

VulnCheck: Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain vulncheck.com/blog/cve-2026-63 @vulncheck #infosec #threatresearch #Microsoft #SharePoint #vulnerability

##

catc0n@infosec.exchange at 2026-08-24T14:01:24.000Z ##

Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: vulncheck.com/blog/cve-2026-63

##

CVE-2026-65400
(7.1 HIGH)

EPSS: 10.43%

updated 2026-08-18T18:31:47

1 posts

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

3 repos

https://github.com/panchocosil/CVE-2026-65400-poc

https://github.com/HORKimhab/CVE-2026-65400

https://github.com/acheong08/CVE-2026-65400

undercodenews@mastodon.social at 2026-08-25T02:15:11.000Z ##

Apple macOS Screen Sharing Under Attack: Someone Claims a Dark Web List Exposes 24,000 Potentially Vulnerable Hosts + Video

A New Warning for Mac Users A disturbing development surrounding a recently disclosed Apple macOS vulnerability has pushed Screen Sharing security back into the spotlight. A threat actor on an underground forum has reportedly distributed a list containing approximately 24,000 internet-accessible hosts that may be relevant to CVE-2026-65400, a…

undercodenews.com/apple-macos-

##

CVE-2026-33824
(9.8 CRITICAL)

EPSS: 72.69%

updated 2026-08-18T18:31:46

2 posts

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

2 repos

https://github.com/kaleth4/CVE-2026-33824

https://github.com/EpSiLoNPoInTOrI/IKEV2-POC

security_crawler_carl at 2026-08-24T18:58:32.084Z ##

🏆 New Achievement! UDP Knocking, Nobody's Dropping!

COMPLIANCE MODE ENGAGED. Action item detected: patch CVE-2026-33824. Executing optimal response: notifying you that Microsoft patched this in April 2026 and that Palo Alto Networks Unit 42 has observed a Chinese-speaking threat actor actively exploiting it anyway, on every supported Windows 10, 11, and Server release, via maliciously crafted packets on UDP ports 500 or 4500, requiring zero privileges. Patch applied? No? Logging that. (1/2)

##

security_crawler_carl@infosec.exchange at 2026-08-24T18:58:32.000Z ##

🏆 New Achievement! UDP Knocking, Nobody's Dropping!

COMPLIANCE MODE ENGAGED. Action item detected: patch CVE-2026-33824. Executing optimal response: notifying you that Microsoft patched this in April 2026 and that Palo Alto Networks Unit 42 has observed a Chinese-speaking threat actor actively exploiting it anyway, on every supported Windows 10, 11, and Server release, via maliciously crafted packets on UDP ports 500 or 4500, requiring zero privileges. Patch applied? No? Logging that. (1/2)

##

CVE-2026-24301
(8.8 HIGH)

EPSS: 2.22%

updated 2026-08-18T15:31:45

1 posts

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

1 repos

https://github.com/CSOAI-ORG/memory-poisoning-axis

sekurakbot@mastodon.com.pl at 2026-08-25T15:19:00.000Z ##

CoSnitch: jedno kliknięcie wystarczyło, aby wysłać złośliwego prompta w Microsoft Copilot

Badacze bezpieczeństwa z Varonis odkryli podatność typu one-click w Microsoft Copilot. Otrzymała ona numer CVE-2026-24301 i została nazwana “CoSnitch”. Luka umożliwia wykradnięcie danych użytkownika bez żadnej szczególnej interakcji z jego strony – wystarczy kliknięcie odpowiednio spreparowanego linku. TLDR: Podatność została zgłoszona firmie Microsoft w grudniu 2025 r., a 18 sierpnia...

#Aktualności #Ai #Copilot #Cosnitch #Injection #Podatność

sekurak.pl/cosnitch-jedno-klik

##

CVE-2026-53365
(5.5 MEDIUM)

EPSS: 0.17%

updated 2026-08-18T15:31:16

2 posts

In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix zerocopy completion for multi-skb sends When a large message is fragmented into multiple skbs, the zerocopy uarg is only allocated and attached to the last skb in the loop. Non-final skbs carry pinned user pages with no completion tracking, so the kernel has no way to notify userspace when those pages are safe

2 repos

https://github.com/HackSpeak/CVE-2026-53365

https://github.com/HORKimhab/CVE-2026-53365

CVE-2026-73522
(7.5 HIGH)

EPSS: 2.36%

updated 2026-08-18T15:17:08.193000

2 posts

COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to write past the end of a fixed 15-slot stack array by sending a crafted UDP datagram containing more than 15 ACF-CAN messages. The avtp_to_can() function increments its write index without bounding it against the caller-supplied array size, and because the listener accepts da

secdb at 2026-08-24T00:01:16.947Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-19478
(9.4 CRITICAL)

EPSS: 6.00%

updated 2026-08-18T14:57:10.630000

3 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Nuclei template

6 repos

https://github.com/HORKimhab/CVE-2026-19650-CVE-2026-19478

https://github.com/punitdarji/Gitlab-CVE-2026-19478

https://github.com/renzi25031469/CVE-2026-19478

https://github.com/davkharrr/CVE-2026-19478-PoC

https://github.com/dinosn/gitlab-cve-2026-19478-lab

https://github.com/n0xdaemon/cve-2026-19478

youranonnewsirc@nerdculture.de at 2026-08-25T04:26:31.000Z ##

Here's a summary of recent geopolitical, technology, and cybersecurity news:

Geopolitical: The US has launched "Operation Economic Outcast" against Iran (Aug 25) and plans 7.5% tariffs on Chinese goods over excess manufacturing capacity before a September summit (Aug 25).

Technology: Google is reorganizing DeepMind and acquired Spirit Airlines' data for AI model development (Aug 24). Fujitsu is trialing AI for construction process and risk management (Aug 25).

Cybersecurity: CISA added an Oracle HTTP Server vulnerability (CVE-2026-21962) to its Known Exploited Vulnerabilities Catalog (Aug 24). Critical GitLab (CVE-2026-19478) and Cisco vulnerabilities (CVSS 10.0) are under active exploitation (Aug 24).

#AnonNews_irc #Cybersecurity #News

##

youranonnewsirc@nerdculture.de at 2026-08-25T04:26:31.000Z ##

Here's a summary of recent geopolitical, technology, and cybersecurity news:

Geopolitical: The US has launched "Operation Economic Outcast" against Iran (Aug 25) and plans 7.5% tariffs on Chinese goods over excess manufacturing capacity before a September summit (Aug 25).

Technology: Google is reorganizing DeepMind and acquired Spirit Airlines' data for AI model development (Aug 24). Fujitsu is trialing AI for construction process and risk management (Aug 25).

Cybersecurity: CISA added an Oracle HTTP Server vulnerability (CVE-2026-21962) to its Known Exploited Vulnerabilities Catalog (Aug 24). Critical GitLab (CVE-2026-19478) and Cisco vulnerabilities (CVSS 10.0) are under active exploitation (Aug 24).

#AnonNews_irc #Cybersecurity #News

##

DailyCyberSecurity@infosec.exchange at 2026-08-23T14:00:39.000Z ##

Critical GitLab vulnerability CVE-2026-19478 lets unauthenticated attackers delete public projects. It is exploited in the wild with public PoC.

#GitLab #CVE202619478 #Vulnerability #InfoSec #CyberSecurity #PatchNow

securityonline.info/gitlab-cve

##

CVE-2026-15748
(9.8 CRITICAL)

EPSS: 4.61%

updated 2026-08-18T06:31:55

2 posts

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler th

3 repos

https://github.com/yora1928/cve-2026-15748

https://github.com/ubaydev/CVE-2026-15748

https://github.com/HORKimhab/CVE-2026-15826-CVE-2026-15748

secdb at 2026-08-24T00:01:16.947Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-75094
(9.1 CRITICAL)

EPSS: 2.11%

updated 2026-08-18T03:31:14

2 posts

A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.

secdb at 2026-08-24T00:01:16.947Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-19976
(6.6 MEDIUM)

EPSS: 2.05%

updated 2026-08-17T03:30:28

2 posts

A security vulnerability has been detected in COMFAST CF-N1-S 2.6.0.1. Impacted is the function sub_44A968 of the file /cgi-bin/mbox-config?method=SET&section=ptest_macaddress. Such manipulation of the argument macaddress leads to command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but

secdb at 2026-08-24T00:01:16.947Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-24T00:01:16.000Z ##

📈 CVE Published in last 7 days (2026-08-17 - 2026-08-17)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 515
- High: 1465
- Medium: 1011
- Low: 196
- None: 372

Status:
- : 66
- Analyzed: 407
- Awaiting Analysis: 323
- Deferred: 288
- Modified: 30
- Received: 1755
- Rejected: 84
- Undergoing Analysis: 606

CISA KEVs:
- CISA-2026:0817 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0818 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0819 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0820 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0821 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 889
- GitHub, Inc.: 540
- VulnCheck: 339
- IBM Corporation: 183
- Patchstack: 181
- kernel.org: 155
- VulDB: 141
- Cisco Systems, Inc.: 125
- MITRE: 87
- WPScan: 85

Top Affected Products:
- UNKNOWN: 2691
- Oracle Helidon: 84
- Splunk: 60
- Oracle Hyperion Financial Management: 48
- Mozilla Firefox: 40
- Ibm Vios: 40
- Ibm Aix: 40
- Mozilla Thunderbird: 40
- Commerce Guided Search / Oracle Commerce Experience Manager: 33
- Apple Iphone Os: 32

Top EPSS Score:
- CVE-2026-64849 - 8.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19586 - 5.03 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-15748 - 3.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-71961 - 3.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54795 - 2.39 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-73522 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-54796 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18264 - 2.27 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75094 - 2.09 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19976 - 2.05 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-68820
(7.0 HIGH)

EPSS: 6.18%

updated 2026-08-16T19:17:24.183000

2 posts

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

4 repos

https://github.com/fevar54/CVE-2026-68820-Mitigation-PoC-

https://github.com/ubitquity/Windows-WinSock-UAF-Mitigation

https://github.com/HORKimhab/CVE-2026-68820

https://github.com/maxprog-svg/CVE-2026-68820_Mass_Exploit

daniel1820815 at 2026-08-24T15:24:01.536Z ##

From Check Point Research:

Check Point Research has exposed a new wave of the -linked Operation Dream Job targeting defense organizations in Europe, India and Brazil. Attackers used fraudulent job opportunities and trojanized PDF software to deploy , while exploiting Windows zero-day CVE-2026-68820 to obtain SYSTEM privileges and disable security visibility.

research.checkpoint.com/2026/s

##

daniel1820815@infosec.exchange at 2026-08-24T15:24:01.000Z ##

From Check Point Research:

Check Point Research has exposed a new wave of the #Lazarus-linked Operation Dream Job targeting defense organizations in Europe, India and Brazil. Attackers used fraudulent job opportunities and trojanized PDF software to deploy #malware, while exploiting Windows zero-day CVE-2026-68820 to obtain SYSTEM privileges and disable security visibility.

research.checkpoint.com/2026/s

#CheckPoint #CheckPointSoftwareTechnologies

##

CVE-2026-19598
(9.8 CRITICAL)

EPSS: 2.46%

updated 2026-08-15T18:31:24

2 posts

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON met

Nuclei template

3 repos

https://github.com/DeadExpl0it/CVE-2026-19598-PoC

https://github.com/sag-asab/CVE-2026-19598

https://github.com/ksotaria1337/CVE-2026-19598

beyondmachines1 at 2026-08-24T16:01:16.949Z ##

Critical Authorization Bypass in Pods Plugin Allows Full WordPress Site Takeover

A critical vulnerability in the Pods WordPress plugin (CVE-2026-19598) allows unauthenticated attackers to bypass security checks and gain administrator access. The flaw enables full site takeover by letting attackers reset administrator passwords through an exposed AJAX router.

**If you use the Pods Custom Content Types and Fields plugin on WordPress, update it ASAP to version 3.3.9.1 (or the patched release matching your branch: 2.8.23.4, 2.9.19.4, 3.0.10.4, 3.1.4.2, or 3.2.8.3). Then check your user list for admin accounts you don't recognise and reset your administrator passwords, since attackers could already have taken over the site.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-24T16:01:16.000Z ##

Critical Authorization Bypass in Pods Plugin Allows Full WordPress Site Takeover

A critical vulnerability in the Pods WordPress plugin (CVE-2026-19598) allows unauthenticated attackers to bypass security checks and gain administrator access. The flaw enables full site takeover by letting attackers reset administrator passwords through an exposed AJAX router.

**If you use the Pods Custom Content Types and Fields plugin on WordPress, update it ASAP to version 3.3.9.1 (or the patched release matching your branch: 2.8.23.4, 2.9.19.4, 3.0.10.4, 3.1.4.2, or 3.2.8.3). Then check your user list for admin accounts you don't recognise and reset your administrator passwords, since attackers could already have taken over the site.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-61979
(8.1 HIGH)

EPSS: 0.28%

updated 2026-08-13T15:34:46

4 posts

Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.

Byte0x90@mastodon.social at 2026-08-25T08:58:33.000Z ##

Angreifer nutzen zwei kritische Lücken im WordPress-Plugin miniOrange SAML SSO aus. Durch die Kombination von CVE-2026-61979 und CVE-2026-15981 lassen sich SAML-Antworten fälschen und Admin-Konten komplett übernehmen. Da der Hersteller Patches für Bezahlversionen kaum kommuniziert hat, sind viele Seiten ungepatcht. Scans laufen bereits – Admins sollten installierte Plugins sofort aktualisieren!

#WordPress #CyberSecurity #ITSecurity #Sicherheitslücke #Patchday #InfoSec

##

cyberworldops at 2026-08-25T00:20:00.394Z ##

Two critical authentication bypass flaws in the miniOrange SAML SSO WordPress plugin can be chained to forge SAML responses and obtain admin access without credentials. Both CVE-2026-61979 and CVE-2026-15981 affect a family of seven plugins, including a free version. Exploitation attempts are already in the wild.

cyberworldops.eu/en/wordpress-

##

Analyst207@mastodon.social at 2026-08-24T19:55:55.000Z ##

Hackers Exploit WordPress Sites in miniOrange Auth Bypass Attacks

Hackers are actively exploiting WordPress sites using a clever combination of two vulnerabilities, CVE-2026-61979 and CVE-2026-15981, to bypass authentication and gain administrator access. This stealthy attack uses the miniOrange SAML 2.0 Single Sign On plugin to forge SAML responses and hijack user sessions.

osintsights.com/hackers-exploi

#Wordpress #AuthBypass #Saml #Miniorange #Cve202661979

##

cyberworldops@infosec.exchange at 2026-08-25T00:20:00.000Z ##

Two critical authentication bypass flaws in the miniOrange SAML SSO WordPress plugin can be chained to forge SAML responses and obtain admin access without credentials. Both CVE-2026-61979 and CVE-2026-15981 affect a family of seven plugins, including a free version. Exploitation attempts are already in the wild.

#WordPressSecurity #AuthenticationBypass #CriticalVulnerability #SAMLAttacks

cyberworldops.eu/en/wordpress-

##

CVE-2026-14669
(8.8 HIGH)

EPSS: 0.58%

updated 2026-08-13T15:34:40

2 posts

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

1 repos

https://github.com/HackSpeak/CVE-2026-14669

DailyCyberSecurity at 2026-08-24T12:53:59.308Z ##

A PostgreSQL vulnerability (CVE-2026-14669, CVSS 8.8) with public PoC exploit code allows remote code execution via to_char. Update now.

securityonline.info/postgresql

##

DailyCyberSecurity@infosec.exchange at 2026-08-24T12:53:59.000Z ##

A PostgreSQL vulnerability (CVE-2026-14669, CVSS 8.8) with public PoC exploit code allows remote code execution via to_char. Update now.

#PostgreSQL #CVE202614669 #RCE #HeapOverflow #Database #InfoSec

securityonline.info/postgresql

##

CVE-2026-72898
(10.0 CRITICAL)

EPSS: 79.22%

updated 2026-08-12T15:18:30.347000

2 posts

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

Nuclei template

6 repos

https://github.com/4minx/CVE-2026-72898

https://github.com/Franc-Zar/CVE-2026-72898-safe-detection

https://github.com/VuxNx/CVE-2026-72898

https://github.com/0xBlackash/CVE-2026-72898

https://github.com/codeb0ssx/CVE-2026-72898-PoC

https://github.com/ubitquity/Metabase-Setup-Endpoint-SQLi-Fix

guru@thecybersecguru.com at 2026-08-25T18:30:39.000Z ##

CVE-2026-72898: Critical Metabase SQL Injection Is Being Actively Exploited, Allowing Unauthenticated Admin Takeover

CVE-2026-72898 is a critical Metabase SQL injection flaw actively exploited in the wild. Learn affected versions, attack path, impact, detection and mitigation

thecybersecguru.com/exploits/c

##

DarkWebInformer@infosec.exchange at 2026-08-22T17:52:48.000Z ##

🚨🇫🇷 iMapper allegedly breached through critical Metabase vulnerability, account data and database access leaked on a cybercrime forum

A forum actor claims to have compromised iMapper, a French web-connected 2D laser measurement platform for building professionals, using a vulnerability identified in the listing as CVE-2026-72898 with a claimed CVSS score of 10.0.

The exposed account dataset reportedly contains 2,463 records and includes:

• User IDs and usernames
• Password hashes
• Account roles
• Email addresses
• Phone numbers
• Professions
• MFA status and related metadata
• Language preferences
• Stripe customer IDs
• Stripe tax-related identifiers
• Measurement and display configuration fields

The data is being distributed in XLSX format. The listing also claims the compromised environment contains additional database tables and offers credentials that could provide access to those systems.

The claims, exploitation method and authenticity, availability and scope of the allegedly exposed data and database access have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

##

CVE-2026-52923
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-12T12:19:41.090000

2 posts

In the Linux kernel, the following vulnerability has been resolved: ipc: limit next_id allocation to the valid ID range The checkpoint/restore sysctl path can request the next SysV IPC id through ids->next_id. ipc_idr_alloc() currently forwards that request to idr_alloc() with an open-ended upper bound. If the valid tail of the SysV IPC id space is full, the allocation can spill beyond ipc_mni

DailyCyberSecurity at 2026-08-25T12:49:12.039Z ##

A public PoC for the Linux kernel flaw CVE-2026-52923 allows local attackers to escalate to root privilege. Learn about the patch and technical details.

securityonline.info/cve-2026-5

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T12:49:12.000Z ##

A public PoC for the Linux kernel flaw CVE-2026-52923 allows local attackers to escalate to root privilege. Learn about the patch and technical details.

#Linux #CVE202652923 #CyberSecurity #PrivilegeEscalation #KernelFlaw

securityonline.info/cve-2026-5

##

CVE-2026-63520
(8.1 HIGH)

EPSS: 2.93%

updated 2026-08-11T18:31:39

8 posts

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

DailyCyberSecurity at 2026-08-25T14:19:20.830Z ##

A public SharePoint RCE vulnerability PoC is actively probed in the wild. Patch CVE-2026-63520 and CVE-2026-55040 now to protect your servers.

securityonline.info/sharepoint

##

AAKL at 2026-08-24T17:42:16.040Z ##

New.

VulnCheck: Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain vulncheck.com/blog/cve-2026-63 @vulncheck

##

AAKL at 2026-08-24T17:33:40.985Z ##

New.

Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520) rapid7.com/blog/post/ra-micros @Rapid7Official

##

catc0n at 2026-08-24T14:01:24.840Z ##

Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: vulncheck.com/blog/cve-2026-63

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T14:19:20.000Z ##

A public SharePoint RCE vulnerability PoC is actively probed in the wild. Patch CVE-2026-63520 and CVE-2026-55040 now to protect your servers.

#SharePoint #CVE202663520 #CVE202655040 #CyberSecurity #Exploit

securityonline.info/sharepoint

##

AAKL@infosec.exchange at 2026-08-24T17:42:16.000Z ##

New.

VulnCheck: Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain vulncheck.com/blog/cve-2026-63 @vulncheck #infosec #threatresearch #Microsoft #SharePoint #vulnerability

##

AAKL@infosec.exchange at 2026-08-24T17:33:40.000Z ##

New.

Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520) rapid7.com/blog/post/ra-micros @Rapid7Official #infosec #Microsoft #vulnerability #threatresearch #SharePoint

##

catc0n@infosec.exchange at 2026-08-24T14:01:24.000Z ##

Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: vulncheck.com/blog/cve-2026-63

##

CVE-2026-14540
(6.1 MEDIUM)

EPSS: 0.11%

updated 2026-08-08T00:32:15

1 posts

A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (internal/sources/http/http.go) fails to safely regulate request redirection boundaries. Specifically, the client is initialize

sayzard@mastodon.sayzard.org at 2026-08-25T07:39:04.000Z ##

I found an SSRF in Google's official AI tooling, and how Google reacted

Google의 공식 에이전트 연동 서버인 MCP Toolbox에서 리디렉션 후 대상 주소를 재검증하지 않아 클라우드 메타데이터 엔드포인트 등으로 접근할 수 있는 SSRF 취약점(CVE-2026-14540, CVSS 8.0)이 수정됐다. 공격자는 모델이 제어 가능한 URL을 통해 리디렉션을 유도하고, 서버 워크로드의 자격 증명이 노출될 수 있었다. 수정안은 모든 리디렉션 홉의 목적지 검증, DNS rebinding 방어, private/link-local 및 IPv6 우회 주소 차단, 초기 base URL 검증을 포함한다. MCP 기반 에이전트는 비신뢰 웹·문서·DB 내용...

news.ycombinator.com/item?id=4

##

CVE-2026-63077
(9.8 CRITICAL)

EPSS: 84.73%

updated 2026-08-05T18:32:31

3 posts

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Nuclei template

4 repos

https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation

https://github.com/sfewer-r7/CVE-2026-63077

https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap

https://github.com/AnggaTechI/CVE-2026-63077

undercodenews@mastodon.social at 2026-08-25T11:44:07.000Z ##

Critical TeamCity Flaw Is Now Under Active Attack: Why CVE-2026-63077 Puts CI/CD Infrastructure at Serious Risk

Introduction: The Security Alarm Around TeamCity Is Getting Louder A critical vulnerability in JetBrains TeamCity On-Premises has moved from a serious patching concern to an active exploitation problem. Tracked as CVE-2026-63077, the flaw can allow an unauthenticated remote attacker to bypass authentication and execute arbitrary operating-system commands on a…

undercodenews.com/critical-tea

##

DailyCyberSecurity at 2026-08-24T07:34:43.264Z ##

CVE-2026-63077 is a TeamCity unauthenticated RCE, now exploited in the wild with a public PoC. Australia's ACSC confirms active attacks.

securityonline.info/teamcity-c

##

DailyCyberSecurity@infosec.exchange at 2026-08-24T07:34:43.000Z ##

CVE-2026-63077 is a TeamCity unauthenticated RCE, now exploited in the wild with a public PoC. Australia's ACSC confirms active attacks.

#TeamCity #CVE202663077 #RCE #CyberSecurity #JetBrains #CISAKEV

securityonline.info/teamcity-c

##

CVE-2026-8508
(6.5 MEDIUM)

EPSS: 0.70%

updated 2026-08-04T03:31:16

2 posts

An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.

1 repos

https://github.com/minanagehsalalma/zyxel-social-login-bypass-cve-2026-8508

_r_netsec at 2026-08-25T13:43:05.200Z ##

CVE-2026-8508: Trust-Boundary Bypass in Zyxel social_login.cgi Facebook Identity Handling minanagehsalalma.github.io/zyx

##

_r_netsec@infosec.exchange at 2026-08-25T13:43:05.000Z ##

CVE-2026-8508: Trust-Boundary Bypass in Zyxel social_login.cgi Facebook Identity Handling minanagehsalalma.github.io/zyx

##

CVE-2026-23479
(8.8 HIGH)

EPSS: 1.36%

updated 2026-07-25T11:10:00.100000

2 posts

Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.

5 repos

https://github.com/rizlmaulanaa/CVE-2026-23479-Redis-UAF-Proof-of-Concept

https://github.com/pduggusa/redis-cve-2026-23479-check

https://github.com/v1c0mmrt/redis-cve-2026-23479-scanner

https://github.com/mgiay/CVE-2026-25589-25588-25243-23631-23479-REDIS

https://github.com/HackSpeak/CVE-2026-23479

DailyCyberSecurity at 2026-08-26T00:59:20.268Z ##

A public PoC exploits a Redis RCE use-after-free flaw tied to CVE-2026-23479, running system commands as the Redis server. Update to 8.8.2.

securityonline.info/redis-rce-

##

DailyCyberSecurity@infosec.exchange at 2026-08-26T00:59:20.000Z ##

A public PoC exploits a Redis RCE use-after-free flaw tied to CVE-2026-23479, running system commands as the Redis server. Update to 8.8.2.

#Redis #RCE #UseAfterFree #CVE202623479 #InfoSec

securityonline.info/redis-rce-

##

CVE-2026-15981
(9.8 CRITICAL)

EPSS: 0.81%

updated 2026-07-23T21:31:09

4 posts

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful sign

1 repos

https://github.com/Nxploited/CVE-2026-15981

Byte0x90@mastodon.social at 2026-08-25T08:58:33.000Z ##

Angreifer nutzen zwei kritische Lücken im WordPress-Plugin miniOrange SAML SSO aus. Durch die Kombination von CVE-2026-61979 und CVE-2026-15981 lassen sich SAML-Antworten fälschen und Admin-Konten komplett übernehmen. Da der Hersteller Patches für Bezahlversionen kaum kommuniziert hat, sind viele Seiten ungepatcht. Scans laufen bereits – Admins sollten installierte Plugins sofort aktualisieren!

#WordPress #CyberSecurity #ITSecurity #Sicherheitslücke #Patchday #InfoSec

##

cyberworldops at 2026-08-25T00:20:00.394Z ##

Two critical authentication bypass flaws in the miniOrange SAML SSO WordPress plugin can be chained to forge SAML responses and obtain admin access without credentials. Both CVE-2026-61979 and CVE-2026-15981 affect a family of seven plugins, including a free version. Exploitation attempts are already in the wild.

cyberworldops.eu/en/wordpress-

##

Analyst207@mastodon.social at 2026-08-24T19:55:55.000Z ##

Hackers Exploit WordPress Sites in miniOrange Auth Bypass Attacks

Hackers are actively exploiting WordPress sites using a clever combination of two vulnerabilities, CVE-2026-61979 and CVE-2026-15981, to bypass authentication and gain administrator access. This stealthy attack uses the miniOrange SAML 2.0 Single Sign On plugin to forge SAML responses and hijack user sessions.

osintsights.com/hackers-exploi

#Wordpress #AuthBypass #Saml #Miniorange #Cve202661979

##

cyberworldops@infosec.exchange at 2026-08-25T00:20:00.000Z ##

Two critical authentication bypass flaws in the miniOrange SAML SSO WordPress plugin can be chained to forge SAML responses and obtain admin access without credentials. Both CVE-2026-61979 and CVE-2026-15981 affect a family of seven plugins, including a free version. Exploitation attempts are already in the wild.

#WordPressSecurity #AuthenticationBypass #CriticalVulnerability #SAMLAttacks

cyberworldops.eu/en/wordpress-

##

CVE-2026-40575
(9.1 CRITICAL)

EPSS: 0.48%

updated 2026-07-21T13:50:16

2 posts

### Impact A configuration-dependent authentication bypass exists in OAuth2 Proxy. Deployments are affected when all of the following are true: * OAuth2 Proxy is configured with `--reverse-proxy` * and at least one rule is defined with `--skip_auth_routes` or the legacy `--skip-auth-regex` OAuth2 Proxy may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is enabled and `

thehackerwire@mastodon.social at 2026-08-24T19:01:19.000Z ##

🔴 CVE-2026-76835 - Critical (9.1)

OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/ut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-24T19:01:19.000Z ##

🔴 CVE-2026-76835 - Critical (9.1)

OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/ut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-15467
(9.8 CRITICAL)

EPSS: 47.62%

updated 2026-07-14T15:32:45

2 posts

Issue summary: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 para

6 repos

https://github.com/balgan/CVE-2025-15467

https://github.com/guiimoraes/CVE-2025-15467

https://github.com/WostGit/cve-2025-15467-crash

https://github.com/x-stp/cves-2025-11187_15467_69418

https://github.com/materaj2/cve-2025-15467

https://github.com/mr-r3b00t/CVE-2025-15467

certvde at 2026-08-25T10:45:02.867Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-08-25T10:45:02.000Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2026-52912
(7.8 HIGH)

EPSS: 0.19%

updated 2026-07-08T15:31:43

2 posts

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: hold bridge skb->dev while queued br_pass_frame_up() rewrites skb->dev from the ingress port to the bridge master before queueing bridge LOCAL_IN packets. NFQUEUE only holds references on state.in/out and bridge physdevs, so a queued bridge packet can retain a freed bridge master in skb->dev until reinjectio

CVE-2026-52945
(7.5 HIGH)

EPSS: 0.40%

updated 2026-07-01T15:34:55

1 posts

In the Linux kernel, the following vulnerability has been resolved: Revert "wireguard: device: enable threaded NAPI" This reverts commit 933466fc50a8e4eb167acbd0d8ec96a078462e9c which is commit db9ae3b6b43c79b1ba87eea849fd65efa05b4b2e upstream. We have had three independent production user reports in combination with Cilium utilizing WireGuard as encryption underneath that k8s Pod E/W traffic t

kini@maro.xyz at 2026-08-25T22:51:03.000Z ##

>We have had three independent production user reports in combination with Cilium utilizing WireGuard as encryption underneath that k8s Pod E/W traffic to certain peer nodes fully stalled. The situation appears as follows: - Occurs very rarely but at random times under heavy networking load. - Once the issue triggers the decryption side stops working completely for that WireGuard peer, other peers keep working fine.

nvd.nist.gov/vuln/detail/CVE-2

Yeah pretty I just found out the source of the curse.

##

CVE-2026-12077
(7.5 HIGH)

EPSS: 0.46%

updated 2026-06-29T20:17:32.607000

1 posts

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' parameters in all versions up to, and including, 5.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existin

cybercases8.wordpress.com@cybercases8.wordpress.com at 2026-08-25T01:10:39.000Z ##

دليل شامل لثغرة SQL Injection في إضافة Dokan Pro

ثغرة حقن SQL في إضافة Dokan Pro (CVE-2026-12077)1. الملخص التنفيذي ثغرة من نوع SQL Injection تعتمد على التأخير الزمني (Time-Based Blind SQL Injection) تم اكتشافها في إضافة Dokan Pro لأنظمة ووردبريس، والتي تُستخدم لإنشاء متاجر متعددة البائعين (Multi-Vendor Marketplaces). تؤثر على جميع الإصدارات حتى 5.0.4، وتسمح لمهاجم غير […]

cybercases8.wordpress.com/2026

##

CVE-2026-48755
(9.9 CRITICAL)

EPSS: 0.44%

updated 2026-06-26T19:03:32

1 posts

### Summary Improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to arbitrary command execution. ### Details Incus validates `compression_algorithm` by parsing it into fields and checking only the first token against an allowlist: ```go fields, err := s

thehackerwire@mastodon.social at 2026-08-23T01:01:24.000Z ##

🔴 CVE-2026-48755 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48752
(9.9 CRITICAL)

EPSS: 0.81%

updated 2026-06-26T18:46:32

1 posts

### Summary A specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. ### Details For container images, `internal/server/storage/utils.go` calls `archive.Unpack(imageFile, destPath, ...)`. The tar extraction path in `shared/archive/archive.go` excludes device nodes, but it does not reject a top

thehackerwire@mastodon.social at 2026-08-23T06:00:06.000Z ##

🔴 CVE-2026-48752 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48751
(9.9 CRITICAL)

EPSS: 0.70%

updated 2026-06-26T18:33:56

1 posts

### Summary Instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks such as `raw.lxc` and `raw.qemu`. ### Details Instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks such as

thehackerwire@mastodon.social at 2026-08-23T05:59:55.000Z ##

🔴 CVE-2026-48751 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48750
(9.9 CRITICAL)

EPSS: 0.78%

updated 2026-06-26T18:32:53

1 posts

### Summary The `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec-output` is a symlink, file named `exec_UUID.stdout` and `exec_UUID.stderr` can be written to an arbitrary location where the `.stdout` file will contain arbitrary content. This behavior can be abused for arbitrary command execu

thehackerwire@mastodon.social at 2026-08-23T02:00:42.000Z ##

🔴 CVE-2026-48750 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec-output...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12569
(9.8 CRITICAL)

EPSS: 40.59%

updated 2026-06-26T15:33:15

2 posts

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

1 repos

https://github.com/west-wind/Threat-Hunting-With-Splunk

DailyCyberSecurity at 2026-08-25T08:01:56.825Z ##

The Clop web shell targets PTC Windchill via CVE-2026-12569, stealing credentials and engineering data in a mass-extortion campaign.

securityonline.info/clop-web-s

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T08:01:56.000Z ##

The Clop web shell targets PTC Windchill via CVE-2026-12569, stealing credentials and engineering data in a mass-extortion campaign.

#Clop #Windchill #WebShell #Ransomware #DataExfiltration

securityonline.info/clop-web-s

##

CVE-2025-69419
(7.4 HIGH)

EPSS: 0.55%

updated 2026-06-17T10:00:39.850000

2 posts

Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer. Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service. The OPENSSL_uni2utf8() functi

1 repos

https://github.com/Kha-Beleh/PoC-CVE-2025-69419

certvde at 2026-08-25T10:45:02.867Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-08-25T10:45:02.000Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2021-33045
(9.8 CRITICAL)

EPSS: 99.56%

updated 2026-06-17T03:54:04.020000

2 posts

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Nuclei template

3 repos

https://github.com/umair-aziz025/dahua-cve-research

https://github.com/bp2008/DahuaLoginBypass

https://github.com/dongpohezui/cve-2021-33045

niebezpiecznikbot@mastodon.com.pl at 2026-08-24T11:43:00.000Z ##

Ktoś przejął 14 530 kamer Dahua

W okresie od 17 czerwca do 22 lipca 2026r. ktoś zhackował co najmniej 14 530 kamer IP (i innych urządzeń) marki Dahua. Ale popełnił jeden błąd, dzięki czemu cała operacja wyszła na jaw — narzędzia włamywaczy wykorzystane do tej operacji, wraz z dodatkowymi informacjami zostały znalezione na jednym z hostów wykorzystywanych do ataków.
Operacja CameraSwarm
Jak ustalili badacze, atak na kamery realizowano głównie na terytorium Ukrainy i Rosji, a włamywacze wykorzystywali 3 techniki:

zgadywanie loginów i haseł na porcie TCP/37777 (skutek: 12324 przejętych urządzeń)
wykorzystanie podatności CVE-2021-33044 i CVE-2021-33045 (umożliwiły dostęp do niezałatanych urządzeń i instaloacje konta-backdoora p2pwn na 1923 kamerach. Tak, to podatność załatana 5 lat temu…)
mechanizm P2P Dahua (dostęp do 283 kamer za NAT-em przy użyciu numeru seryjnego i danych zaszytych w klientach Dahua).

Analiza narzędzi opublikowanych przez włamywaczy ujawniła też, że z przejętych kamer odrzucali ciemne/nieużyteczne klatki a resztę (plus ewentualne dane logowania) wysyłali na Telegram.
Mam kamerę Dahua, co robić, jak żyć?
Choć raport badaczy nie wymienia Polski wśród głównych obszarów potwierdzonych przejęć, to skanowanie miało zasięg globalny. Marka ma w Polsce oficjalnych dystrybutorów i szeroką ofertę sprzętu do domu i firm, dlatego powinniście sprawdzić swoje urządzenia, nawet jeśli nie otrzymaliście żadnego alertu.
Jeśli kamera Dahua była dostępna z internetu na porcie 37777/tcp w czerwcu lub lipcu 2026r., potraktujcie ją jako potencjalnie przejętą i:

sprawdź listę użytkowników i usuń konto p2pwn, jeśli istnieje;
zaktualizuj firmware do najnowszej wersji właściwej dla konkretnego modelu;
wyłącz P2P, jeśli go nie potrzebujesz, oraz nie wystawiaj portu 37777 do internetu;
zmień hasła kamery, [...]

#CCTV #Dahua #Kamery #Monitoring #Rosja #Ukraina

niebezpiecznik.pl/post/ktos-pr

##

niebezpiecznikbot@mastodon.com.pl at 2026-08-24T11:43:00.000Z ##

Ktoś przejął 14 530 kamer Dahua

W okresie od 17 czerwca do 22 lipca 2026r. ktoś zhackował co najmniej 14 530 kamer IP (i innych urządzeń) marki Dahua. Ale popełnił jeden błąd, dzięki czemu cała operacja wyszła na jaw — narzędzia włamywaczy wykorzystane do tej operacji, wraz z dodatkowymi informacjami zostały znalezione na jednym z hostów wykorzystywanych do ataków.
Operacja CameraSwarm
Jak ustalili badacze, atak na kamery realizowano głównie na terytorium Ukrainy i Rosji, a włamywacze wykorzystywali 3 techniki:

zgadywanie loginów i haseł na porcie TCP/37777 (skutek: 12324 przejętych urządzeń)
wykorzystanie podatności CVE-2021-33044 i CVE-2021-33045 (umożliwiły dostęp do niezałatanych urządzeń i instaloacje konta-backdoora p2pwn na 1923 kamerach. Tak, to podatność załatana 5 lat temu…)
mechanizm P2P Dahua (dostęp do 283 kamer za NAT-em przy użyciu numeru seryjnego i danych zaszytych w klientach Dahua).

Analiza narzędzi opublikowanych przez włamywaczy ujawniła też, że z przejętych kamer odrzucali ciemne/nieużyteczne klatki a resztę (plus ewentualne dane logowania) wysyłali na Telegram.
Mam kamerę Dahua, co robić, jak żyć?
Choć raport badaczy nie wymienia Polski wśród głównych obszarów potwierdzonych przejęć, to skanowanie miało zasięg globalny. Marka ma w Polsce oficjalnych dystrybutorów i szeroką ofertę sprzętu do domu i firm, dlatego powinniście sprawdzić swoje urządzenia, nawet jeśli nie otrzymaliście żadnego alertu.
Jeśli kamera Dahua była dostępna z internetu na porcie 37777/tcp w czerwcu lub lipcu 2026r., potraktujcie ją jako potencjalnie przejętą i:

sprawdź listę użytkowników i usuń konto p2pwn, jeśli istnieje;
zaktualizuj firmware do najnowszej wersji właściwej dla konkretnego modelu;
wyłącz P2P, jeśli go nie potrzebujesz, oraz nie wystawiaj portu 37777 do internetu;
zmień hasła kamery, [...]

#CCTV #Dahua #Kamery #Monitoring #Rosja #Ukraina

niebezpiecznik.pl/post/ktos-pr

##

CVE-2025-9615
(3.3 LOW)

EPSS: 0.15%

updated 2026-05-19T15:31:20

4 posts

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.

cR0w at 2026-08-24T18:55:29.991Z ##

@agowa338 It's an incomplete fix for CVE-2025-9615:

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.

##

cR0w at 2026-08-24T18:50:25.704Z ##

i uSe lInUx bEcAuSe iT'S SeCuRe.

access.redhat.com/security/cve

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

##

cR0w@infosec.exchange at 2026-08-24T18:55:29.000Z ##

@agowa338 It's an incomplete fix for CVE-2025-9615:

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.

##

cR0w@infosec.exchange at 2026-08-24T18:50:25.000Z ##

i uSe lInUx bEcAuSe iT'S SeCuRe.

access.redhat.com/security/cve

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

##

CVE-2025-58187
(6.5 MEDIUM)

EPSS: 0.38%

updated 2026-01-29T18:31:31

2 posts

Due to the design of the name constraint checking algorithm, the processing time of some inputs scals non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains.

certvde at 2026-08-25T10:45:02.867Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-08-25T10:45:02.000Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2026-0915
(7.5 HIGH)

EPSS: 0.57%

updated 2026-01-20T18:31:56

2 posts

Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.

1 repos

https://github.com/cyberwulfy200-dev/CVE-2026-0915-json-Patch.-V2.0

certvde at 2026-08-25T10:45:02.867Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-08-25T10:45:02.000Z ##

🔒 New CSAF advisory published

VDE-2026-088
METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.4
CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2025-58187, CVE-2026-41992 (+37 more)

Multiple vulnerabilities have been discovered in LabX Standard versions 21.3.22 - 21.4.23. The vulnerabilities CVE-2025…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

niebezpiecznikbot@mastodon.com.pl at 2026-08-24T11:43:00.000Z ##

Ktoś przejął 14 530 kamer Dahua

W okresie od 17 czerwca do 22 lipca 2026r. ktoś zhackował co najmniej 14 530 kamer IP (i innych urządzeń) marki Dahua. Ale popełnił jeden błąd, dzięki czemu cała operacja wyszła na jaw — narzędzia włamywaczy wykorzystane do tej operacji, wraz z dodatkowymi informacjami zostały znalezione na jednym z hostów wykorzystywanych do ataków.
Operacja CameraSwarm
Jak ustalili badacze, atak na kamery realizowano głównie na terytorium Ukrainy i Rosji, a włamywacze wykorzystywali 3 techniki:

zgadywanie loginów i haseł na porcie TCP/37777 (skutek: 12324 przejętych urządzeń)
wykorzystanie podatności CVE-2021-33044 i CVE-2021-33045 (umożliwiły dostęp do niezałatanych urządzeń i instaloacje konta-backdoora p2pwn na 1923 kamerach. Tak, to podatność załatana 5 lat temu…)
mechanizm P2P Dahua (dostęp do 283 kamer za NAT-em przy użyciu numeru seryjnego i danych zaszytych w klientach Dahua).

Analiza narzędzi opublikowanych przez włamywaczy ujawniła też, że z przejętych kamer odrzucali ciemne/nieużyteczne klatki a resztę (plus ewentualne dane logowania) wysyłali na Telegram.
Mam kamerę Dahua, co robić, jak żyć?
Choć raport badaczy nie wymienia Polski wśród głównych obszarów potwierdzonych przejęć, to skanowanie miało zasięg globalny. Marka ma w Polsce oficjalnych dystrybutorów i szeroką ofertę sprzętu do domu i firm, dlatego powinniście sprawdzić swoje urządzenia, nawet jeśli nie otrzymaliście żadnego alertu.
Jeśli kamera Dahua była dostępna z internetu na porcie 37777/tcp w czerwcu lub lipcu 2026r., potraktujcie ją jako potencjalnie przejętą i:

sprawdź listę użytkowników i usuń konto p2pwn, jeśli istnieje;
zaktualizuj firmware do najnowszej wersji właściwej dla konkretnego modelu;
wyłącz P2P, jeśli go nie potrzebujesz, oraz nie wystawiaj portu 37777 do internetu;
zmień hasła kamery, [...]

#CCTV #Dahua #Kamery #Monitoring #Rosja #Ukraina

niebezpiecznik.pl/post/ktos-pr

##

niebezpiecznikbot@mastodon.com.pl at 2026-08-24T11:43:00.000Z ##

Ktoś przejął 14 530 kamer Dahua

W okresie od 17 czerwca do 22 lipca 2026r. ktoś zhackował co najmniej 14 530 kamer IP (i innych urządzeń) marki Dahua. Ale popełnił jeden błąd, dzięki czemu cała operacja wyszła na jaw — narzędzia włamywaczy wykorzystane do tej operacji, wraz z dodatkowymi informacjami zostały znalezione na jednym z hostów wykorzystywanych do ataków.
Operacja CameraSwarm
Jak ustalili badacze, atak na kamery realizowano głównie na terytorium Ukrainy i Rosji, a włamywacze wykorzystywali 3 techniki:

zgadywanie loginów i haseł na porcie TCP/37777 (skutek: 12324 przejętych urządzeń)
wykorzystanie podatności CVE-2021-33044 i CVE-2021-33045 (umożliwiły dostęp do niezałatanych urządzeń i instaloacje konta-backdoora p2pwn na 1923 kamerach. Tak, to podatność załatana 5 lat temu…)
mechanizm P2P Dahua (dostęp do 283 kamer za NAT-em przy użyciu numeru seryjnego i danych zaszytych w klientach Dahua).

Analiza narzędzi opublikowanych przez włamywaczy ujawniła też, że z przejętych kamer odrzucali ciemne/nieużyteczne klatki a resztę (plus ewentualne dane logowania) wysyłali na Telegram.
Mam kamerę Dahua, co robić, jak żyć?
Choć raport badaczy nie wymienia Polski wśród głównych obszarów potwierdzonych przejęć, to skanowanie miało zasięg globalny. Marka ma w Polsce oficjalnych dystrybutorów i szeroką ofertę sprzętu do domu i firm, dlatego powinniście sprawdzić swoje urządzenia, nawet jeśli nie otrzymaliście żadnego alertu.
Jeśli kamera Dahua była dostępna z internetu na porcie 37777/tcp w czerwcu lub lipcu 2026r., potraktujcie ją jako potencjalnie przejętą i:

sprawdź listę użytkowników i usuń konto p2pwn, jeśli istnieje;
zaktualizuj firmware do najnowszej wersji właściwej dla konkretnego modelu;
wyłącz P2P, jeśli go nie potrzebujesz, oraz nie wystawiaj portu 37777 do internetu;
zmień hasła kamery, [...]

#CCTV #Dahua #Kamery #Monitoring #Rosja #Ukraina

niebezpiecznik.pl/post/ktos-pr

##

CVE-2020-14882
(9.8 CRITICAL)

EPSS: 100.00%

updated 2025-10-22T00:31:59

2 posts

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeove

Nuclei template

42 repos

https://github.com/Ormicron/CVE-2020-14882-GUI-Test

https://github.com/XTeam-Wing/CVE-2020-14882

https://github.com/jas502n/CVE-2020-14882

https://github.com/b1g-b33f/CVE-2020-14882

https://github.com/kk98kk0/CVE-2020-14882

https://github.com/alexfrancow/CVE-2020-14882

https://github.com/pwn3z/CVE-2020-14882-WebLogic

https://github.com/Root-Shells/CVE-2020-14882

https://github.com/s1kr10s/CVE-2020-14882

https://github.com/ludy-dev/Weblogic_Unauthorized-bypass-RCE

https://github.com/tpdlshdmlrkfmcla/WebLogic_CVE_2020_14882

https://github.com/qianniaoge/CVE-2020-14882_Exploit_Gui

https://github.com/nik0nz7/CVE-2020-14882

https://github.com/mmioimm/cve-2020-14882

https://github.com/pprietosanchez/CVE-2020-14750

https://github.com/0xn0ne/weblogicScanner

https://github.com/zhzyker/vulmap

https://github.com/exploitblizzard/CVE-2020-14882-WebLogic

https://github.com/N0Coriander/CVE-2020-14882-14883

https://github.com/0thm4n3/cve-2020-14882

https://github.com/LucasPDiniz/CVE-2020-14882

https://github.com/KKC73/weblogic-cve-2020-14882

https://github.com/xMr110/CVE-2020-14882

https://github.com/ovProphet/CVE-2020-14882-checker

https://github.com/GGyao/CVE-2020-14882_POC

https://github.com/NS-Sp4ce/CVE-2020-14882

https://github.com/murataydemir/CVE-2020-14883

https://github.com/wsfengfan/cve-2020-14882

https://github.com/milo2012/CVE-2020-14882

https://github.com/Danny-LLi/CVE-2020-14882

https://github.com/QmF0c3UK/CVE-2020-14882

https://github.com/zhzyker/exphub

https://github.com/GGyao/CVE-2020-14882_ALL

https://github.com/BabyTeam1024/CVE-2020-14882

https://github.com/corelight/CVE-2020-14882-weblogicRCE

https://github.com/zesnd/CVE-2020-14882-POC

https://github.com/VelesSecurity/CVE-2020-14882-WebLogic-Analysis

https://github.com/murataydemir/CVE-2020-14882

https://github.com/1n7erface/PocList

https://github.com/xfiftyone/CVE-2020-14882

https://github.com/adm1in/CodeTest

https://github.com/AleksaZatezalo/CVE-2020-14882

security_crawler_carl at 2026-08-25T09:45:06.059Z ##

CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.

Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.

Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.

(2/2)

##

security_crawler_carl@infosec.exchange at 2026-08-25T09:45:06.000Z ##

CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.

Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.

Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.

#CyberSecurity #Oracle #WebLogic #ZeroDay #Vulnerability #CriticalHit (2/2)

##

CVE-2020-2551
(9.8 CRITICAL)

EPSS: 93.17%

updated 2025-10-22T00:31:50

2 posts

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeove

Nuclei template

11 repos

https://github.com/hktalent/CVE-2020-2551

https://github.com/LTiDi2000/CVE-2020-2551

https://github.com/Dido1960/Weblogic-CVE-2020-2551-To-Internet

https://github.com/Y4er/CVE-2020-2551

https://github.com/0xn0ne/weblogicScanner

https://github.com/zzwlpx/weblogicPoc

https://github.com/jas502n/CVE-2020-2551

https://github.com/abbarhissarh/CVE-Exploit

https://github.com/DaMinGshidashi/CVE-2020-2551

https://github.com/DSO-Lab/defvul

https://github.com/zhzyker/exphub

security_crawler_carl at 2026-08-25T09:45:06.059Z ##

CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.

Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.

Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.

(2/2)

##

security_crawler_carl@infosec.exchange at 2026-08-25T09:45:06.000Z ##

CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.

Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.

Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.

#CyberSecurity #Oracle #WebLogic #ZeroDay #Vulnerability #CriticalHit (2/2)

##

CVE-2017-10271
(7.5 HIGH)

EPSS: 99.99%

updated 2025-10-22T00:31:29

2 posts

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of

Nuclei template

33 repos

https://github.com/bigsizeme/weblogic-XMLDecoder

https://github.com/shahdawadfallah-sys/Cybersecurity-Capstone-Project

https://github.com/peterpeter228/Oracle-WebLogic-CVE-2017-10271

https://github.com/JackyTsuuuy/weblogic_wls_rce_poc-exp

https://github.com/1337g/CVE-2017-10271

https://github.com/Cymmetria/weblogic_honeypot

https://github.com/ZH3FENG/PoCs-Weblogic_2017_10271

https://github.com/XHSecurity/Oracle-WebLogic-CVE-2017-10271

https://github.com/0xn0ne/weblogicScanner

https://github.com/testwc/CVE-2017-10271

https://github.com/lonehand/Oracle-WebLogic-CVE-2017-10271-master

https://github.com/kbsec/Weblogic_Wsat_RCE

https://github.com/pizza-power/weblogic-CVE-2019-2729-POC

https://github.com/ianxtianxt/-CVE-2017-10271-

https://github.com/Dungsocool/CVE-2017-10271

https://github.com/r4b3rt/CVE-2017-10271

https://github.com/seoyoung-kang/CVE-2017-10271

https://github.com/SuperHacker-liuan/cve-2017-10271-poc

https://github.com/cjjduck/weblogic_wls_wsat_rce

https://github.com/cved-sources/cve-2017-10271

https://github.com/s3xy/CVE-2017-10271

https://github.com/Yuusuke4/WebLogic_CNVD_C_2019_48814

https://github.com/KKsdall/7kbstormq

https://github.com/kkirsche/CVE-2017-10271

https://github.com/SkyBlueEternal/CNVD-C-2019-48814-CNNVD-201904-961

https://github.com/ETOCheney/JavaDeserialization

https://github.com/shack2/javaserializetools

https://github.com/c0mmand3rOpSec/CVE-2017-10271

https://github.com/Al1ex/CVE-2017-10271

https://github.com/Luffin/CVE-2017-10271

https://github.com/7kbstorm/WebLogic_CNVD_C2019_48814

https://github.com/rambleZzz/weblogic_CVE_2017_10271

https://github.com/pssss/CVE-2017-10271

security_crawler_carl at 2026-08-25T09:45:06.059Z ##

CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.

Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.

Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.

(2/2)

##

security_crawler_carl@infosec.exchange at 2026-08-25T09:45:06.000Z ##

CloudSEK honeypots confirm active attacks, with threat actors also recycling ancient WebLogic RCE charges dating back to 2017 and 2020.

Sentence is immediate: patch CVE-2026-21962 now and audit your exposure to CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271 before this court loses what little patience remains.

Reward: You've received the Gavel of Grudging Compliance — equip it or face contempt charges.

#CyberSecurity #Oracle #WebLogic #ZeroDay #Vulnerability #CriticalHit (2/2)

##

CVE-2026-75604
(0 None)

EPSS: 0.00%

2 posts

N/A

1 repos

https://github.com/rafabd1/CVE-2026-75604-poc

DailyCyberSecurity at 2026-08-26T01:58:20.310Z ##

Two critical Next.js vulnerabilities, including CVE-2026-75604 (CVSS 9.0), enable unauthenticated remote code execution. Patch to 15.5.24 or 16.3.3 now.

securityonline.info/nextjs-rce

##

DailyCyberSecurity@infosec.exchange at 2026-08-26T01:58:20.000Z ##

Two critical Next.js vulnerabilities, including CVE-2026-75604 (CVSS 9.0), enable unauthenticated remote code execution. Patch to 15.5.24 or 16.3.3 now.

#NextJS #RCE #CyberSecurity #CVE202675604 #WebSecurity

securityonline.info/nextjs-rce

##

CVE-2026-18431
(0 None)

EPSS: 0.00%

1 posts

N/A

sayzard@mastodon.sayzard.org at 2026-08-26T00:45:55.000Z ##

Wordfence Argus Finds 6 Step Critical RCE in Avada Theme with 1M Sales

Wordfence가 Avada 테마(7.16 이하)와 Fusion Builder 플러그인(3.16 이하)의 6단계 취약점 체인을 이용하는 인증 불필요 원격 코드 실행(CVE-2026-18431, CVSS 9.8)을 공개했습니다. 두 구성요소가 활성화되고 특정 관리자 작성 콘텐츠가 존재할 경우 공격자는 임의 PHP 파일을 작성·실행해 웹 서버 권한으로 사이트를 완전히 장악할 수 있습니다. 패치는 Avada 7.16.1 및 Fusion...

wordfence.com/blog/2026/08/wor

##

CVE-2026-58090
(0 None)

EPSS: 0.00%

2 posts

N/A

thecybermind at 2026-08-25T22:12:37.598Z ##

🚨 Critical Threat Intel: CVE-2026-60004 targets Gitea via diffpatch API code injection. Review execution vectors, persistence mechanics, and active endpoint hardening actions to secure your version control infrastructure. thecybermind.co/jily

##

AAKL at 2026-08-25T19:18:50.900Z ##

CISA has updated the KEV catalogue.

- CVE-2026-60004: Gitea Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- Industrial vulnerability: Rently Smart Home cisa.gov/news-events/ics-advis

Also:

Press release: CISA Advisory Highlights Red Team Findings to Help Organizations Assess Risk, Identify Threats and Enable Effective Incident Response cisa.gov/news-events/news/cisa

The advisory: A Tale of Two SOCs: Insights From Two Red Team Assessments cisa.gov/news-events/cybersecu

##

cisakevtracker@mastodon.social at 2026-08-25T18:00:55.000Z ##

CVE ID: CVE-2026-60004
Vendor: Gitea
Product: Gitea
Date Added: 2026-08-25
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb at 2026-08-25T18:00:17.922Z ##

🚨 [CISA-2026:0825] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-60004 (secdb.nttzen.cloud/cve/detail/)
- Name: Gitea Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Gitea
- Product: Gitea
- Notes: github.com/go-gitea/gitea/secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

thecybermind@infosec.exchange at 2026-08-25T22:12:37.000Z ##

🚨 Critical Threat Intel: CVE-2026-60004 targets Gitea via diffpatch API code injection. Review execution vectors, persistence mechanics, and active endpoint hardening actions to secure your version control infrastructure. thecybermind.co/jily

##

AAKL@infosec.exchange at 2026-08-25T19:18:50.000Z ##

CISA has updated the KEV catalogue.

- CVE-2026-60004: Gitea Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- Industrial vulnerability: Rently Smart Home cisa.gov/news-events/ics-advis

Also:

Press release: CISA Advisory Highlights Red Team Findings to Help Organizations Assess Risk, Identify Threats and Enable Effective Incident Response cisa.gov/news-events/news/cisa

The advisory: A Tale of Two SOCs: Insights From Two Red Team Assessments cisa.gov/news-events/cybersecu #CISA #infosec #vulnerability

##

cisakevtracker@mastodon.social at 2026-08-25T18:00:55.000Z ##

CVE ID: CVE-2026-60004
Vendor: Gitea
Product: Gitea
Date Added: 2026-08-25
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-08-25T18:00:17.000Z ##

🚨 [CISA-2026:0825] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-60004 (secdb.nttzen.cloud/cve/detail/)
- Name: Gitea Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Gitea
- Product: Gitea
- Notes: github.com/go-gitea/gitea/secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260825 #cisa20260825 #cve_2026_60004 #cve202660004

##

CVE-2026-18965
(0 None)

EPSS: 0.00%

2 posts

N/A

cyberworldops at 2026-08-25T20:20:01.202Z ##

CVE-2026-18965 discloses a missing authorization flaw in the PayRange API (CWE-862). All versions are affected. The vulnerability allows unauthenticated remote access to payment devices, exposing fleets of vending machines and kiosks to unauthorized interaction.

cyberworldops.eu/en/payrange-a

##

cyberworldops@infosec.exchange at 2026-08-25T20:20:01.000Z ##

CVE-2026-18965 discloses a missing authorization flaw in the PayRange API (CWE-862). All versions are affected. The vulnerability allows unauthenticated remote access to payment devices, exposing fleets of vending machines and kiosks to unauthorized interaction.

#CVE202618965 #MissingAuthorization #PayRangeAPI #CriticalVulnerability

cyberworldops.eu/en/payrange-a

##

CVE-2026-19632
(0 None)

EPSS: 0.00%

2 posts

N/A

DailyCyberSecurity at 2026-08-25T15:43:39.038Z ##

A critical TranslatePress vulnerability (CVE-2026-19632) lets attackers steal admin reset links and take over 400,000 WordPress sites. Update to 3.3.2 now.

securityonline.info/translatep

##

DailyCyberSecurity@infosec.exchange at 2026-08-25T15:43:39.000Z ##

A critical TranslatePress vulnerability (CVE-2026-19632) lets attackers steal admin reset links and take over 400,000 WordPress sites. Update to 3.3.2 now.

#WordPress #TranslatePress #CyberSecurity #CVE202619632 #WebSecurity

securityonline.info/translatep

##

CVE-2026-59285
(0 None)

EPSS: 0.00%

1 posts

N/A

undercodenews@mastodon.social at 2026-08-25T10:15:20.000Z ##

Spring GraphQL Security Alert: CVE-2026-59285 Creates a Dangerous Path to Remote Code Execution

A New Warning for Spring-Based Applications A newly disclosed vulnerability in Spring for GraphQL is putting developers and security teams on notice. CVE-2026-59285 affects specific Spring GraphQL applications that combine Jackson 2.x deserialization, paginated GraphQL fields, and certain classes available on the application's classpath. The vulnerability is particularly…

undercodenews.com/spring-graph

##

CVE-2026-59270
(0 None)

EPSS: 0.00%

2 posts

N/A

beyondmachines1 at 2026-08-25T08:01:17.240Z ##

Broadcom Patches 91 Spring CVEs, Including a Critical LDAP Flaw

Broadcom's Tanzu division released one of Spring's largest-ever security batches on August 20, 2026, patching 91 CVEs across Spring Security, Spring AI, Spring GraphQL and related projects, including the critical CVE-2026-59270 (CVSS 9.8) in Spring Security's embedded UnboundID LDAP server and a critical deserialization/RCE flaw in Spring GraphQL.

**If you run Java applications built on Spring, update Spring Security to 7.1.1, 7.0.7 (or 6.5.12 / 5.8.28 on older supported branches) and upgrade Spring AI and Spring GraphQL to their patched versions. CheckUntil you can patch, block access to the LDAP listener ports with firewall rules so they can only be reached from trusted networks.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-25T08:01:17.000Z ##

Broadcom Patches 91 Spring CVEs, Including a Critical LDAP Flaw

Broadcom's Tanzu division released one of Spring's largest-ever security batches on August 20, 2026, patching 91 CVEs across Spring Security, Spring AI, Spring GraphQL and related projects, including the critical CVE-2026-59270 (CVSS 9.8) in Spring Security's embedded UnboundID LDAP server and a critical deserialization/RCE flaw in Spring GraphQL.

**If you run Java applications built on Spring, update Spring Security to 7.1.1, 7.0.7 (or 6.5.12 / 5.8.28 on older supported branches) and upgrade Spring AI and Spring GraphQL to their patched versions. CheckUntil you can patch, block access to the LDAP listener ports with firewall rules so they can only be reached from trusted networks.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-76098
(0 None)

EPSS: 0.28%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-24T22:01:51.000Z ##

🟠 CVE-2026-76098 - High (7.5)

Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-24T22:01:51.000Z ##

🟠 CVE-2026-76098 - High (7.5)

Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77567
(0 None)

EPSS: 0.30%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-24T22:00:04.000Z ##

🟠 CVE-2026-77567 - High (8.1)

Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-24T22:00:04.000Z ##

🟠 CVE-2026-77567 - High (8.1)

Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66897
(0 None)

EPSS: 0.62%

2 posts

N/A

offseq at 2026-08-24T10:30:26.215Z ##

CVE-2026-66897: Canonical LXD CRITICAL path traversal (CVSS 9.9). Attackers with container edit rights or crafted images can overwrite host files as root. Restrict permissions & avoid untrusted images. Patch status unknown. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-24T10:30:26.000Z ##

CVE-2026-66897: Canonical LXD CRITICAL path traversal (CVSS 9.9). Attackers with container edit rights or crafted images can overwrite host files as root. Restrict permissions & avoid untrusted images. Patch status unknown. radar.offseq.com/threat/cve-20 #OffSeq #LXD #CVE #Linux

##

CVE-2026-78251
(0 None)

EPSS: 0.39%

2 posts

N/A

offseq at 2026-08-24T07:30:24.487Z ##

CVE-2026-78251 (CRITICAL): DJI Neo & related drones have hard-coded FTP creds, letting attackers fill storage & disrupt logging/updates via network or USB. Patch required! radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-24T07:30:24.000Z ##

CVE-2026-78251 (CRITICAL): DJI Neo & related drones have hard-coded FTP creds, letting attackers fill storage & disrupt logging/updates via network or USB. Patch required! radar.offseq.com/threat/cve-20 #OffSeq #CVE2026_78251 #DJI #DroneSec

##

CVE-2026-55621
(0 None)

EPSS: 0.20%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-23T02:00:12.000Z ##

🟠 CVE-2026-55621 - High (7.7)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of a custom v...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55622
(0 None)

EPSS: 0.20%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-22T13:00:01.000Z ##

🟠 CVE-2026-55622 - High (7.7)

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63343
(0 None)

EPSS: 0.27%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-22T12:00:47.000Z ##

🔴 CVE-2026-63343 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62941
(0 None)

EPSS: 0.25%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-22T12:00:26.000Z ##

🔴 CVE-2026-62941 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62940
(0 None)

EPSS: 0.23%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-22T10:00:44.000Z ##

🔴 CVE-2026-62940 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys like `security.privileged` and `raw.lxc`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62867
(0 None)

EPSS: 0.29%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-22T10:00:33.000Z ##

🔴 CVE-2026-62867 - Critical (9.9)

Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55241
(0 None)

EPSS: 0.44%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-22T08:02:06.000Z ##

🟠 CVE-2026-55241 - High (7.5)

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to 3.9.1, the public POST /api/v1/auth/register route in server/sr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites