## Updated at UTC 2026-08-12T15:39:29.195355

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-20349 8.6 0.97% 17 0 2026-08-12T15:02:21.707000 A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall A
CVE-2026-68820 7.0 0.36% 28 0 2026-08-12T14:57:30.717000 Use after free in Windows Ancillary Function Driver for WinSock allows an author
CVE-2026-62832 7.8 2.39% 2 0 2026-08-12T14:18:23.150000 Improper link resolution before file access ('link following') in Windows User P
CVE-2026-61353 7.8 0.32% 1 0 2026-08-12T14:18:03.773000 Heap-based buffer overflow in Windows Telephony Service allows an authorized att
CVE-2026-19556 8.8 0.31% 2 0 2026-08-12T14:17:48.813000 Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote a
CVE-2026-70398 9.6 0.22% 4 0 2026-08-12T13:17:24.637000 A flaw was found in multicloud-integrations, a component of Red Hat Advanced Clu
CVE-2026-67282 0 0.57% 2 0 2026-08-12T13:17:24.073000 Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabri
CVE-2026-66875 8.8 0.24% 2 0 2026-08-12T13:17:23.933000 In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote u
CVE-2026-57858 8.9 0.00% 4 1 2026-08-12T13:17:22.943000 Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripti
CVE-2026-19426 8.2 0.30% 2 0 2026-08-12T09:31:30 POS System developed by FitSoft has a Missing Authentication vulnerability. Unau
CVE-2025-41771 4.3 0.16% 2 0 2026-08-12T09:31:30 An authenticated attacker with low privileges can access an endpoint in the cont
CVE-2025-41770 7.5 0.39% 4 0 2026-08-12T08:17:11.910000 An unauthenticated denial-of-service vulnerability in the device's PLCnext Engin
CVE-2025-41769 9.8 0.59% 6 0 2026-08-12T08:17:11.590000 The device's PROFINET service is affected by a buffer overflow vulnerability tha
CVE-2026-19594 8.1 0.40% 2 0 2026-08-12T06:31:00 Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versi
CVE-2026-66659 9.3 0.29% 4 0 2026-08-12T06:31:00 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-66807 7.8 0.36% 1 0 2026-08-12T05:19:35.273000 Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker
CVE-2026-64954 8.2 0.23% 2 0 2026-08-12T05:19:17.893000 Velociraptor allows scheduling new collections via VQL queries in notebooks. For
CVE-2026-53413 8.3 0.41% 1 0 2026-08-12T05:17:55.123000 Missing bounds check in the annotator function of Zoom Clients allows buffer ove
CVE-2026-18961 8.1 0.45% 2 0 2026-08-12T03:31:28 The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by Ventr
CVE-2026-73122 7.7 0.21% 2 0 2026-08-12T03:31:23 A flaw was found in the multicloud-operators-channel component of Red Hat Advanc
CVE-2026-6484 8.2 0.14% 2 0 2026-08-12T03:31:23 In an UEFI, Lack of verified boot to certain FV may cause arbitrary code executi
CVE-2026-72526 9.9 0.30% 4 0 2026-08-12T03:31:18 A flaw was found in the multicloud-integrations component. The Application propa
CVE-2026-66878 7.7 0.21% 2 0 2026-08-12T03:31:17 A flaw was found in multicloud-operators-subscription. A privileged user, specif
CVE-2026-68067 9.8 0.28% 4 0 2026-08-12T00:31:23 The login endpoint on the Mira cloud API accepts any format-valid string in the
CVE-2026-67568 9.1 0.24% 4 0 2026-08-12T00:31:23 The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access
CVE-2026-19560 None 0.31% 2 0 2026-08-12T00:31:11 Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remot
CVE-2026-66147 9.4 1.05% 2 0 2026-08-12T00:31:09 An unauthenticated command injection vulnerability was identified in the GMS Dis
CVE-2026-73247 8.6 0.30% 2 0 2026-08-11T22:19:05.417000 Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, K
CVE-2026-15562 7.5 0.44% 1 0 2026-08-11T21:33:39 A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who
CVE-2026-18948 9.9 0.69% 2 0 2026-08-11T21:33:39 A flaw was found in Feast. The system improperly deserializes user-defined funct
CVE-2026-18951 8.8 0.66% 1 0 2026-08-11T21:33:39 A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training op
CVE-2026-18947 8.5 0.43% 1 0 2026-08-11T21:33:35 A flaw was found in Feast. An authorization bypass vulnerability exists in the /
CVE-2026-73283 2.5 0.08% 2 0 2026-08-11T21:33:18 In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was su
CVE-2026-73282 4.8 0.16% 2 0 2026-08-11T21:33:18 In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a
CVE-2026-18949 8.8 0.41% 1 0 2026-08-11T21:32:33 A flaw was found in odh-dashboard. This vulnerability allows an attacker, who ha
CVE-2026-16985 8.8 0.41% 1 0 2026-08-11T21:32:30 The Squeeze WordPress plugin before 1.7.12 does not validate the file type or e
CVE-2026-73281 3.5 0.16% 2 0 2026-08-11T21:17:52.563000 In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were
CVE-2026-55676 8.8 0.30% 1 0 2026-08-11T21:17:37.560000 Malcolm is a network traffic analysis tool suite. The file-upload component (Fil
CVE-2026-10579 9.8 0.30% 1 0 2026-08-11T21:17:24.910000 A flaw was found in Picketlink Federation SAML; the unsolcited response handler
CVE-2026-73231 7.8 0.15% 1 0 2026-08-11T20:18:48.400000 Faker generates massive amounts of fake data in the browser and Node.js. Prior t
CVE-2026-18950 8.8 0.36% 1 0 2026-08-11T20:17:38.323000 A flaw was found in odh-dashboard. An authenticated user of the dashboard can ex
CVE-2021-44228 10.0 100.00% 1 100 template 2026-08-11T19:33:44.513000 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12
CVE-2026-73224 8.8 0.34% 1 0 2026-08-11T19:18:52.030000 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ft
CVE-2026-20338 7.5 0.33% 5 0 2026-08-11T18:54:19.877000 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat
CVE-2026-62901 7.5 1.08% 1 0 2026-08-11T18:53:42.910000 Unchecked input for loop condition in .NET allows an unauthorized attacker to de
CVE-2026-72971 5.5 0.36% 1 0 2026-08-11T18:32:00 Improper link resolution before file access ('link following') in Windows Contai
CVE-2026-58641 7.8 0.40% 1 0 2026-08-11T18:31:08 Integer overflow or wraparound in .NET allows an unauthorized attacker to elevat
CVE-2026-56721 8.8 0.36% 2 0 2026-08-11T18:30:54 CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerabil
CVE-2026-53414 6.5 0.28% 1 0 2026-08-11T18:30:54 Missing bounds check in the annotator function of Zoom Clients allows buffer ove
CVE-2026-53415 8.3 0.39% 1 0 2026-08-11T18:30:54 Use after Free in the annotator function of Zoom Clients may allow a meeting par
CVE-2026-67180 8.4 0.17% 1 0 2026-08-11T18:30:53 Google Turbinia allows arbitrary command execution via worker tasks. An attacker
CVE-2026-13738 None 0.53% 1 0 2026-08-11T18:30:43 CommServe contained an authorization bypass vulnerability affecting a limited se
CVE-2026-73079 8.5 0.31% 1 0 2026-08-11T17:19:15.747000 Sub2API is an AI API gateway platform designed to distribute and manage API quot
CVE-2026-72915 7.5 0.28% 3 0 2026-08-11T17:19:14.203000 Mastodon is a free, open-source social network server based on ActivityPub. From
CVE-2026-48161 0 0.42% 1 0 2026-08-11T17:17:59.513000 react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05
CVE-2026-13716 9.1 0.56% 1 0 2026-08-11T17:17:47.430000 Path traversal in server import and admin file upload in Crafty Controller. Allo
CVE-2026-72903 8.1 0.31% 1 0 2026-08-11T16:17:37.360000 Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1
CVE-2026-67179 7.8 0.14% 1 0 2026-08-11T16:17:34.113000 Genkit does not properly validate host request headers. Any host on the develope
CVE-2026-18786 8.8 0.29% 1 0 2026-08-11T16:17:31.037000 The CheckView WordPress plugin before 2.3.2 does not restrict its REST API auth
CVE-2026-73080 9.3 0.38% 1 0 2026-08-11T15:58:24 ### Impact `VolumeServer.FetchAndWriteNeedle` fetches a caller-supplied remote e
CVE-2026-18129 8.1 0.87% 2 0 2026-08-11T15:32:51 Cleartext transmission of sensitive information in the Core of Ivanti Endpoint M
CVE-2026-58115 10.0 0.65% 2 0 2026-08-11T15:32:40 A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1
CVE-2026-18972 9.6 0.33% 1 0 2026-08-11T15:32:40 An authenticated attacker can spoof another GUI user's identity by sending their
CVE-2026-72864 9.9 0.27% 1 0 2026-08-11T15:17:36.393000 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13,
CVE-2026-44763 7.6 0.28% 1 0 2026-08-11T15:17:29.830000 SAP Manufacturing Integration and Intelligence allows a privileged attacker to e
CVE-2026-58231 10.0 0.73% 6 0 2026-08-11T12:30:28 SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent
CVE-2026-71217 7.5 0.42% 1 0 2026-08-11T12:30:22 A flaw was found in iperf3. A remote attacker can exploit this vulnerability by
CVE-2026-72693 7.8 0.10% 1 0 2026-08-11T09:32:42 `openvt -u` is intended to identify the owner of the current VT and then execute
CVE-2026-19425 9.8 0.47% 1 0 2026-08-11T06:31:25 Travel Agency Management System developed by Win Men Intermational has a SQL Inj
CVE-2026-19516 9.1 0.23% 1 0 2026-08-11T06:31:25 A caller-supplied X-Grafana-URL request header controls the destination of mcp-g
CVE-2026-58243 8.8 0.31% 1 0 2026-08-11T03:32:04 SAP ABAP Development Tools does not perform necessary authorization checks for c
CVE-2026-66763 7.9 0.13% 1 0 2026-08-11T03:32:04 SAP BusinessObjects Business Intelligence Platform stores certain sensitive cred
CVE-2026-34265 9.8 0.44% 5 0 2026-08-11T03:31:57 SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to expl
CVE-2026-44758 9.1 0.51% 4 0 2026-08-11T03:31:55 SAP Manufacturing Integration and Intelligence (MII) allows an attacker with hig
CVE-2026-8917 0 0.11% 1 0 2026-08-11T03:18:01.900000 Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and
CVE-2026-73030 8.1 0.38% 1 0 2026-08-10T21:32:15 unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulne
CVE-2026-63622 7.8 0.13% 1 0 2026-08-10T21:32:08 A flaw was found in libvirt. A local attacker, specifically a process running as
CVE-2026-63106 9.8 0.29% 1 0 2026-08-10T21:17:23.437000 ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerabil
CVE-2026-72901 9.9 0.63% 1 0 2026-08-10T20:17:35.570000 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13,
CVE-2026-72689 7.5 0.32% 1 0 2026-08-10T19:17:33.103000 A broken object-level authorization vulnerability in OpenSignLabs opensignserver
CVE-2026-71576 8.5 0.12% 1 0 2026-08-10T17:17:36.060000 A flaw was found in multicluster-global-hub. The manager component improperly va
CVE-2026-66738 8.8 0.40% 1 0 2026-08-10T17:17:35.557000 SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed inst
CVE-2026-72691 7.5 0.39% 1 0 2026-08-10T15:33:59 An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.
CVE-2026-13206 9.8 1.27% 1 0 2026-08-10T15:33:42 Improper neutralization of special elements used in an OS command ('OS command i
CVE-2026-18933 7.2 0.28% 1 0 2026-08-10T12:17:14.430000 The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the
CVE-2026-19389 7.1 0.24% 1 0 2026-08-10T03:31:01 Multiple integer overflow and underflow vulnerabilities were found in the GStrea
CVE-2026-19387 7.6 0.24% 1 0 2026-08-10T03:31:01 A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-
CVE-2026-64564 9.8 0.48% 2 4 2026-08-09T06:31:34 In the Linux kernel, the following vulnerability has been resolved: sctp: don't
CVE-2026-67261 9.8 1.60% 2 0 2026-08-07T20:08:27.597000 Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.
CVE-2026-20339 7.5 0.33% 1 0 2026-08-07T18:31:54 A vulnerability in the PESpin file format parser of ClamAV could allow an unauth
CVE-2026-20337 7.5 0.36% 5 0 2026-08-07T18:31:52 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat
CVE-2026-8037 9.6 99.31% 2 2 template 2026-08-07T18:31:36 OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC
CVE-2026-5423 0 0.34% 1 0 2026-08-06T22:18:10.297000 @neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity o
CVE-2026-34966 7.6 0.31% 2 0 2026-08-05T21:31:47 Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that
CVE-2026-71319 9.6 0.32% 2 0 2026-08-05T21:27:39 ### Impact Nuxt DevTools (development mode only) exposes a bidirectional RPC ch
CVE-2026-63077 9.8 10.72% 1 4 template 2026-08-05T18:32:31 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-71249 6.1 0.15% 1 0 2026-08-05T12:31:36 299Ko's public contact form (plugin/contact/controllers/ContactController.php, h
CVE-2026-55739 8.3 0.27% 1 0 2026-08-05T09:31:26 Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense po
CVE-2026-10090 9.9 0.25% 1 0 2026-08-05T09:31:26 A flaw was found in the Application Subscription controller (multicluster-operat
CVE-2024-55591 9.8 98.26% 2 9 template 2026-08-05T05:16:42.380000 An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2
CVE-2026-61515 9.8 1.58% 2 0 2026-08-04T15:32:30 Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated c
CVE-2026-18577 8.1 4.10% 3 3 2026-08-04T14:27:12.530000 An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco
CVE-2026-59310 9.8 1.14% 4 0 2026-07-30T16:17:15.183000 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-59309 9.8 0.74% 1 0 2026-07-30T16:17:15.073000 VMware vCenter contains an authentication bypass vulnerability in the VMware Dir
CVE-2026-47876 9.3 0.28% 1 0 2026-07-30T14:16:58.467000 VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual
CVE-2026-64560 7.8 0.12% 2 1 2026-07-30T12:19:03.630000 In the Linux kernel, the following vulnerability has been resolved: posix-cpu-t
CVE-2026-64747 7.8 0.14% 2 1 2026-07-28T15:32:12 A buffer overflow was addressed with improved size validation. This issue is fix
CVE-2026-45659 8.8 9.12% 2 2 2026-07-23T11:10:00.120000 Deserialization of untrusted data in Microsoft Office SharePoint allows an autho
CVE-2026-63030 9.8 95.60% 1 81 2026-07-22T23:10:00.110000 WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API ba
CVE-2026-53360 8.8 0.18% 2 1 2026-07-22T21:32:53 In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: R
CVE-2026-53361 7.1 0.13% 3 1 2026-07-22T19:07:32.853000 In the Linux kernel, the following vulnerability has been resolved: af_unix: Se
CVE-2026-59765 None 0.00% 2 0 2026-07-21T21:55:32 ### Summary Gitea has robust SSRF protection via `hostmatcher.NewDialContext()`
CVE-2026-55040 9.1 1.63% 12 2 2026-07-14T18:32:38 Weak authentication in Microsoft Office SharePoint allows an unauthorized attack
CVE-2026-31431 7.8 99.91% 1 100 2026-07-14T15:32:55 In the Linux kernel, the following vulnerability has been resolved: crypto: alg
CVE-2026-12879 None 0.19% 1 0 2026-07-09T15:32:33 An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apige
CVE-2026-50656 7.8 10.75% 8 3 2026-07-09T00:17:26.607000 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect
CVE-1999-1587 0 0.95% 1 0 2026-06-16T21:50:46.783000 /usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, a
CVE-2026-34486 7.5 82.93% 1 6 template 2026-06-08T23:28:56 Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the f
CVE-2026-43074 7.8 0.48% 1 1 2026-06-01T18:32:35 In the Linux kernel, the following vulnerability has been resolved: eventpoll:
CVE-2026-48048 7.5 0.36% 1 0 2026-05-26T20:17:03 ### Impact XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insuffici
CVE-2026-46670 9.8 1.65% 1 0 template 2026-05-22T15:39:07 ### Summary An unauthenticated SQL injection in the Bazar form-import path (`Fo
CVE-2026-27912 8.0 0.24% 1 2 2026-04-14T18:30:50 Improper authorization in Windows Kerberos allows an authorized attacker to elev
CVE-2003-0190 None 76.75% 1 0 2026-03-22T05:08:29 OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediat
CVE-2026-22185 None 0.13% 2 0 2026-01-08T18:31:46 OpenLDAP Lightning Memory-Mapped Database (LMDB) mdb_load contains a heap buffer
CVE-2025-7771 None 6.83% 1 12 2025-08-06T12:31:25 ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow a
CVE-2026-26035 0 0.00% 2 0 N/A
CVE-2026-70468 0 0.00% 2 0 N/A
CVE-2026-72898 0 1.07% 5 1 template N/A
CVE-2026-73225 0 0.31% 2 0 N/A
CVE-2026-66058 0 0.22% 1 0 N/A
CVE-2026-66000 0 0.26% 1 0 N/A
CVE-2026-66059 0 0.27% 1 0 N/A
CVE-2026-44772 0 0.00% 2 0 N/A
CVE-2026-72914 0 0.45% 3 0 N/A
CVE-2026-72916 0 0.36% 2 0 N/A
CVE-2026-12234 0 0.08% 2 0 N/A
CVE-2026-48765 0 0.26% 3 0 N/A
CVE-2026-73249 0 0.25% 2 0 N/A
CVE-2026-73246 0 0.35% 1 0 N/A
CVE-2026-48763 0 0.31% 1 0 N/A
CVE-2026-73234 0 0.16% 1 0 N/A
CVE-2026-73232 0 0.45% 1 0 N/A
CVE-2026-73226 0 0.39% 1 0 N/A
CVE-2026-73069 0 0.36% 1 0 N/A
CVE-2026-72922 0 0.27% 1 0 N/A
CVE-2026-72921 0 0.24% 1 0 N/A
CVE-2026-72920 0 0.41% 1 0 N/A
CVE-2026-17106 0 0.00% 1 2 N/A
CVE-2026-44945 0 0.30% 1 0 N/A
CVE-2026-8718 0 0.12% 1 0 N/A
CVE-2026-72911 0 0.38% 1 0 N/A
CVE-2026-72886 0 0.36% 1 0 N/A
CVE-2026-72883 0 0.40% 1 0 N/A
CVE-2026-72872 0 0.37% 1 0 N/A
CVE-2026-72871 0 0.29% 1 0 N/A
CVE-2026-72730 0 0.24% 1 0 N/A
CVE-2026-47754 0 0.34% 1 0 N/A
CVE-2026-60137 0 73.10% 1 52 N/A
CVE-2026-64638 0 0.77% 1 21 N/A

CVE-2026-20349
(8.6 HIGH)

EPSS: 0.97%

updated 2026-08-12T15:02:21.707000

17 posts

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processin

netsecio@mastodon.social at 2026-08-12T15:06:39.000Z ##

📰 Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

Cisco patches an actively exploited zero-day (CVE-2026-20349) in ASA and FTD firewalls. The flaw allows a remote, unauthenticated attacker to cause a denial-of-service (DoS). Patch immediately to prevent network disruption. #Cisco #ZeroDay #CyberSecu...

🔗 cyber.netsecops.io/articles/ci

##

jbhall56 at 2026-08-12T12:57:51.990Z ##

CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. securityweek.com/cisco-patches

##

Matchbook3469@mastodon.social at 2026-08-12T11:00:57.000Z ##

⚠️ New security advisory:

CVE-2026-20349 affects multiple systems.

• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#CVE #ZeroDay #ThreatIntel

##

Analyst207@mastodon.social at 2026-08-12T08:04:38.000Z ##

Cisco ASA and FTD Flaw Exploited in Wild, Triggers Remote DoS

A high-severity vulnerability in Cisco Secure Firewall ASA and FTD software, known as CVE-2026-20349, is being actively exploited in the wild, allowing attackers to trigger a remote denial-of-service condition with a simple crafted HTTP request. This flaw, with a CVSS score of 8.6, can cause affected devices to reload, leaving networks…

osintsights.com/cisco-asa-and-

#CiscoAsa #Ftd #Cve202620349 #RemoteDos #VulnerabilityExploitation

##

thecybermind at 2026-08-12T07:44:11.997Z ##

🚨 THREAT ALERT: CISA adds CVE-2026-20349 (Cisco ASA/FTD Heap Inspection DoS) to the KEV catalog due to active exploitation. Unauthenticated remote actors can crash perimeter firewalls. Read our full TSUITE brief with SPL, KQL, AQL & Chronicle queries: thecybermind.co/jily

##

undercodenews@mastodon.social at 2026-08-12T06:59:20.000Z ##

Cisco Firewalls Under Pressure: CVE-2026-20349 Exposes a Dangerous Zero-Day Risk While Sandworm-Linked Hackers Weaponize Fake IT Jobs + Video

Introduction: Two Different Attacks, One Bigger Warning Cybersecurity defenders are facing a familiar but increasingly dangerous pattern: attackers do not need to break through every security control if they can find one exposed edge device or convince one trusted employee to install the wrong software. On August 12, 2026, two…

undercodenews.com/cisco-firewa

##

undercodenews@mastodon.social at 2026-08-12T06:58:48.000Z ##

Cisco Secure Firewall Under Active Attack: High-Severity CVE-2026-20349 Puts ASA and FTD Devices on Immediate Patch Alert + Video

A New Warning Has Turned a Firewall Bug Into an Active Security Emergency A firewall is supposed to be the wall between an organization and the hostile internet. When that wall can be forced to restart remotely, without authentication, the problem is no longer a theoretical weakness hidden inside a security scanner. It becomes an operational…

undercodenews.com/cisco-secure

##

ottoto2017@prattohome.com at 2026-08-12T05:39:38.000Z ##

「Ciscoは、ASAおよびFTD VPNの脆弱性が悪用され、デバイスがクラッシュする可能性があると警告している。 」: #BLEEPINGCOMPUTER

「シスコは、Secure Firewall ASAおよびThreat Defense(FTD)ソフトウェアに存在する深刻なサービス拒否攻撃の脆弱性が、影響を受けるデバイスをリモートからクラッシュさせる攻撃で積極的に悪用されていると警告している。

CVE-2026-20349として追跡されているこの脆弱性は、深刻度スコアが8.6であり、特定のリモートアクセスサービスが有効になっているCisco Secure Firewall Adaptive Security Appliance(ASA)またはSecure Firewall Threat Defense(FTD)ソフトウェアを実行しているデバイスに影響を与えます。

シスコは本日公開したセキュリティ勧告の中で、この脆弱性はHTTPリクエスト処理時のエラーチェックが不十分なことに起因すると述べた。 」

bleepingcomputer.com/news/secu

#prattohome

##

DailyCyberSecurity at 2026-08-12T00:37:09.921Z ##

Cisco confirms CVE-2026-20349, a Cisco ASA and FTD VPN vulnerability (CVSS 8.6), is exploited in the wild to crash firewalls. Patch now.

securityonline.info/cisco-asa-

##

jbhall56@infosec.exchange at 2026-08-12T12:57:51.000Z ##

CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. securityweek.com/cisco-patches

##

thecybermind@infosec.exchange at 2026-08-12T07:44:11.000Z ##

🚨 THREAT ALERT: CISA adds CVE-2026-20349 (Cisco ASA/FTD Heap Inspection DoS) to the KEV catalog due to active exploitation. Unauthenticated remote actors can crash perimeter firewalls. Read our full TSUITE brief with SPL, KQL, AQL & Chronicle queries: thecybermind.co/jily

#CyberSecurity

##

ottoto2017@prattohome.com at 2026-08-12T05:39:38.000Z ##

「Ciscoは、ASAおよびFTD VPNの脆弱性が悪用され、デバイスがクラッシュする可能性があると警告している。 」: #BLEEPINGCOMPUTER

「シスコは、Secure Firewall ASAおよびThreat Defense(FTD)ソフトウェアに存在する深刻なサービス拒否攻撃の脆弱性が、影響を受けるデバイスをリモートからクラッシュさせる攻撃で積極的に悪用されていると警告している。

CVE-2026-20349として追跡されているこの脆弱性は、深刻度スコアが8.6であり、特定のリモートアクセスサービスが有効になっているCisco Secure Firewall Adaptive Security Appliance(ASA)またはSecure Firewall Threat Defense(FTD)ソフトウェアを実行しているデバイスに影響を与えます。

シスコは本日公開したセキュリティ勧告の中で、この脆弱性はHTTPリクエスト処理時のエラーチェックが不十分なことに起因すると述べた。 」

bleepingcomputer.com/news/secu

#prattohome

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T00:37:09.000Z ##

Cisco confirms CVE-2026-20349, a Cisco ASA and FTD VPN vulnerability (CVSS 8.6), is exploited in the wild to crash firewalls. Patch now.

#Cisco #CVE #DoS #FirewallSecurity #VPN #InfoSec

securityonline.info/cisco-asa-

##

secdb@infosec.exchange at 2026-08-11T21:00:13.000Z ##

🚨 [CISA-2026:0811] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-20349 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-68820 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows Ancillary Function Driver for WinSock
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-72898 (secdb.nttzen.cloud/cve/detail/)
- Name: Metabase SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Metabase
- Product: Metabase
- Notes: metabase.com/blog/security-upd ; github.com/metabase/metabase/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260811 #cisa20260811 #cve_2026_20349 #cve_2026_68820 #cve_2026_72898 #cve202620349 #cve202668820 #cve202672898

##

Xavier@infosec.exchange at 2026-08-11T20:18:44.000Z ##

This is being actively exploited. CVE-2026-20349. Patch now. Like right now. #infosec #vpn #cisco #cve
bleepingcomputer.com/news/secu

##

cisakevtracker@mastodon.social at 2026-08-11T20:00:49.000Z ##

CVE ID: CVE-2026-20349
Vendor: Cisco
Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
Date Added: 2026-08-11
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-08-11T17:11:08.000Z ##

Broadcom has several new advisories that include two critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

CISA:

Industrial vulnerability: Johnson Controls C-CURE 9000 and Victor application server (Update A) cisa.gov/news-events/ics-advis

Blog post: Cyber Storm X: 20 Years of Readiness, Resilience, and Real‑World Impact cisa.gov/news-events/news/cybe #CISA

Cisco:

High-severity: CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco

Yesterday:

Tenable Research Advisories:

Medium-severity: CVE-2026-12879: Google Cloud Platform (GCP) Apigee Cross-Tenant Data Exfiltration via Confused Deputy tenable.com/security/research/ #infosec #Google #vulnerability

##

CVE-2026-68820
(7.0 HIGH)

EPSS: 0.36%

updated 2026-08-12T14:57:30.717000

28 posts

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

tugatech@masto.pt at 2026-08-12T15:07:31.000Z ##

Microsoft lança atualização de emergência para corrigir a CVE-2026-68820, uma falha de gravidade elevada no controlador Ancillary Function para WinSock. A vulnerabilidade, que afeta diversas versões do Windows, já está a ser explorada em ataques reais. 🚨

🔗 tugatech.com.pt/t89012-microso

#falha #lan #microsoft #windows 

##

netsecio@mastodon.social at 2026-08-12T15:06:54.000Z ##

📰 Lazarus Group Exploits Windows Zero-Day in Espionage Campaign

Microsoft patches actively exploited Windows zero-day (CVE-2026-68820) used by Lazarus Group. The bug allows SYSTEM-level access and was used in the 'Operation Dream Job' campaign to deploy rootkits against the defense sector. #CVE202668820 #Lazarus ...

🔗 cyber.netsecops.io/articles/la

##

threatnoir at 2026-08-12T13:05:54.489Z ##

⚠️ CRITICAL: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

Microsoft patched CVE-2026-68820, a zero-day use-after-free in afd.sys kernel driver actively exploited for SYSTEM privilege escalation. This is the fourth afd.sys zero-day since 2022, with historical links to nation-state actors. All Windows systems running unpatched afd.sys are at immediate risk…

threatnoir.com/focus

🤖 AI generated summary

##

CapTechGroup@mastodon.social at 2026-08-12T12:51:38.000Z ##

Microsoft's newest patch cycle closes nearly 400 security holes, among them CVE-2026-62832, CVE-2026-68820, and CVE-2026-72971. That volume makes triage the hard part, so plan which systems get updated first and confirm the rollout...

captechgroup.com/threat-intell

##

security_crawler_carl at 2026-08-12T12:39:41.495Z ##

🏆 New Achievement! CVE-2026-68820: The Lazarus Rises (Again)!

PHASE ONE BEGINS. Emerging from the shadows of Pyongyang's finest state-sponsored hacking collective, Lazarus has arrived — and they brought a use-after-free bug in afd.sys, the Windows kernel-mode driver, as their opening act. CVE-2026-68820 lets a low-privilege, locally authenticated attacker trigger a race condition, escalate straight to SYSTEM, and basically own the stage. (1/3)

##

offseq at 2026-08-12T09:00:32.200Z ##

CVE-2026-68820: CRITICAL Windows afd.sys zero-day exploited by Lazarus Group for SYSTEM access in defense/aerospace. Patch released 2026-08-11. Prioritize updates & check for ForestTiger/Troy backdoors. radar.offseq.com/threat/fresh-

##

VirusBulletin at 2026-08-12T08:50:09.841Z ##

Check Point researchers look into the latest variant of the Operation Dream Job campaign where the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of Lazarus’s kernel-mode rootkit FudModule. research.checkpoint.com/2026/s

##

thecybermind at 2026-08-12T08:49:26.242Z ##

🚨 THREAT ALERT: CISA adds CVE-2026-68820 (Windows WinSock AFD Use-After-Free) to the KEV catalog due to active exploitation. Local attackers can elevate privileges to system level. Access our TSUITE brief with CrowdStrike CQL telemetry queries: thecybermind.co/jily

##

ottoto2017@prattohome.com at 2026-08-12T06:07:08.000Z ##

「Microsoft 製品の脆弱性対策について(2026年8月)」: #IPA

「 2026年8月12日(日本時間)に Microsoft 製品に関するセキュリティ更新プログラム(月例)が公表されています。
これらの脆弱性を悪用された場合、アプリケーションプログラムが異常終了する、攻撃者によってパソコンを制御される、といった様々な被害が発生するおそれがあります。

この内 CVE-2026-68820 の脆弱性について、Microsoft 社では悪用の事実を確認済みと公表しており、今後被害が拡大するおそれがあるため、至急、セキュリティ更新プログラムを適用してください。 」

ipa.go.jp/security/security-al

#prattohome

##

sayzard@mastodon.sayzard.org at 2026-08-12T05:46:34.000Z ##

Bugs in MS' Patch Tuesday release and NK's Lazarus has hit one already

Microsoft의 2026년 8월 Patch Tuesday는 421개 취약점을 수정했으며, 그중 Windows WinSock Ancillary Function Driver(afd.sys)의 use-after-free 취약점 CVE-2026-68820은 Lazarus 그룹이 패치 전 실제 공격에 사용한 제로데이다. 로컬 인증 사용자가 경쟁 조건을 유발해 사용자 상호작용 없이 SYSTEM 권한 코드 실행을...

theregister.com/security/2026/

##

ottoto2017@prattohome.com at 2026-08-12T04:51:43.000Z ##

「マイクロソフトは、現在攻撃を受けているWindowsドライバーのゼロデイ脆弱性を含む398件の脆弱性を修正した。 」: #TheHackerNews

「マイクロソフトは火曜日に月例のセキュリティアップデートを公開したが、修正された脆弱性の1つが既に攻撃に悪用されている。

このバグは、ネットワークソケット操作を処理するWindowsカーネルの中核ドライバに存在します。既にマシン上でコードを実行している攻撃者は、このバグを利用してSYSTEM権限に昇格できます。このパッチが最初にリリースされます。

この脆弱性は CVE-2026-68820 (CVSSスコア:7.0)として追跡されており、今月のリリースでマイクロソフトが現在悪用されていると警告している唯一の脆弱性です。悪用は、ドライバーの競合状態をトリガーすることによって行われます。マイクロソフトは、この悪用を行った組織を公表していません。」

thehackernews.com/2026/08/micr

#prattohome

##

sayzard@mastodon.sayzard.org at 2026-08-12T03:43:20.000Z ##

Microsoft Plugs Nearly 400 Security Holes

Microsoft가 8월 Patch Tuesday에서 Windows 및 지원 소프트웨어의 취약점 최소 398건을 수정했으며, 이 중 42건은 원격 코드 실행 등으로 이어질 수 있는 Critical 등급이다. 이미 악용 중인 CVE-2026-68820은 거의 모든 Windows 엔드포인트의 소켓 연결에 관여하는 afd.sys의 권한 상승 취약점으로, 초기 침투 후 시스템 장악 체인에 사용될 수 있다. 또한 Windows User Profile Service의 CVE-2026-62832는 공개된 LegacyHive 이슈와 연관 가능성이 있으며 악용 가능성이 높은 것으로...

krebsonsecurity.com/2026/08/mi

##

DailyCyberSecurity at 2026-08-12T02:44:48.174Z ##

Lazarus exploited a Windows zero-day (CVE-2026-68820) in Operation Dream Job to hit defense firms with fake job offers and a new backdoor.

securityonline.info/lazarus-ze

##

DailyCyberSecurity at 2026-08-12T02:21:44.193Z ##

Microsoft August 2026 Patch Tuesday fixes 421 flaws, including CVE-2026-68820, a WinSock zero-day exploited in the wild, plus two disclosed bugs.

securityonline.info/microsoft-

##

sayzard@mastodon.sayzard.org at 2026-08-12T00:40:40.000Z ##

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Microsoft의 2026년 8월 Patch Tuesday는 총 400개 취약점(치명적 42개 포함)을 수정하며, 원격 코드 실행 110개와 권한 상승 176개가 포함된다. 특히 CVE-2026-68820은 Windows AFD.sys(WinSock Ancillary Function Driver)의 use-after-free 기반 로컬 권한 상승 취약점으로, Lazarus가 FudModule 커널 루트킷 배포에 실제 악용한 정황이 보고됐다. 공개된 Windows...

bleepingcomputer.com/news/micr

##

tugatech@masto.pt at 2026-08-12T15:07:31.000Z ##

Microsoft lança atualização de emergência para corrigir a CVE-2026-68820, uma falha de gravidade elevada no controlador Ancillary Function para WinSock. A vulnerabilidade, que afeta diversas versões do Windows, já está a ser explorada em ataques reais. 🚨

🔗 tugatech.com.pt/t89012-microso

#falha #lan #microsoft #windows 

##

threatnoir@infosec.exchange at 2026-08-12T13:05:54.000Z ##

⚠️ CRITICAL: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

Microsoft patched CVE-2026-68820, a zero-day use-after-free in afd.sys kernel driver actively exploited for SYSTEM privilege escalation. This is the fourth afd.sys zero-day since 2022, with historical links to nation-state actors. All Windows systems running unpatched afd.sys are at immediate risk…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

security_crawler_carl@infosec.exchange at 2026-08-12T12:39:41.000Z ##

🏆 New Achievement! CVE-2026-68820: The Lazarus Rises (Again)!

PHASE ONE BEGINS. Emerging from the shadows of Pyongyang's finest state-sponsored hacking collective, Lazarus has arrived — and they brought a use-after-free bug in afd.sys, the Windows kernel-mode driver, as their opening act. CVE-2026-68820 lets a low-privilege, locally authenticated attacker trigger a race condition, escalate straight to SYSTEM, and basically own the stage. (1/3)

##

offseq@infosec.exchange at 2026-08-12T09:00:32.000Z ##

CVE-2026-68820: CRITICAL Windows afd.sys zero-day exploited by Lazarus Group for SYSTEM access in defense/aerospace. Patch released 2026-08-11. Prioritize updates & check for ForestTiger/Troy backdoors. radar.offseq.com/threat/fresh- #OffSeq #ZeroDay #Windows #Cybersecurity

##

VirusBulletin@infosec.exchange at 2026-08-12T08:50:09.000Z ##

Check Point researchers look into the latest variant of the Operation Dream Job campaign where the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of Lazarus’s kernel-mode rootkit FudModule. research.checkpoint.com/2026/s

##

thecybermind@infosec.exchange at 2026-08-12T08:49:26.000Z ##

🚨 THREAT ALERT: CISA adds CVE-2026-68820 (Windows WinSock AFD Use-After-Free) to the KEV catalog due to active exploitation. Local attackers can elevate privileges to system level. Access our TSUITE brief with CrowdStrike CQL telemetry queries: thecybermind.co/jily

#CyberSecurity

##

ottoto2017@prattohome.com at 2026-08-12T06:07:08.000Z ##

「Microsoft 製品の脆弱性対策について(2026年8月)」: #IPA

「 2026年8月12日(日本時間)に Microsoft 製品に関するセキュリティ更新プログラム(月例)が公表されています。
これらの脆弱性を悪用された場合、アプリケーションプログラムが異常終了する、攻撃者によってパソコンを制御される、といった様々な被害が発生するおそれがあります。

この内 CVE-2026-68820 の脆弱性について、Microsoft 社では悪用の事実を確認済みと公表しており、今後被害が拡大するおそれがあるため、至急、セキュリティ更新プログラムを適用してください。 」

ipa.go.jp/security/security-al

#prattohome

##

ottoto2017@prattohome.com at 2026-08-12T04:51:43.000Z ##

「マイクロソフトは、現在攻撃を受けているWindowsドライバーのゼロデイ脆弱性を含む398件の脆弱性を修正した。 」: #TheHackerNews

「マイクロソフトは火曜日に月例のセキュリティアップデートを公開したが、修正された脆弱性の1つが既に攻撃に悪用されている。

このバグは、ネットワークソケット操作を処理するWindowsカーネルの中核ドライバに存在します。既にマシン上でコードを実行している攻撃者は、このバグを利用してSYSTEM権限に昇格できます。このパッチが最初にリリースされます。

この脆弱性は CVE-2026-68820 (CVSSスコア:7.0)として追跡されており、今月のリリースでマイクロソフトが現在悪用されていると警告している唯一の脆弱性です。悪用は、ドライバーの競合状態をトリガーすることによって行われます。マイクロソフトは、この悪用を行った組織を公表していません。」

thehackernews.com/2026/08/micr

#prattohome

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T02:44:48.000Z ##

Lazarus exploited a Windows zero-day (CVE-2026-68820) in Operation Dream Job to hit defense firms with fake job offers and a new backdoor.

#Lazarus #ZeroDay #CVE202668820 #OperationDreamJob #Cybersecurity #DPRK #FudModule #DefenseSector

securityonline.info/lazarus-ze

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T02:21:44.000Z ##

Microsoft August 2026 Patch Tuesday fixes 421 flaws, including CVE-2026-68820, a WinSock zero-day exploited in the wild, plus two disclosed bugs.

#PatchTuesday #Microsoft #ZeroDay #CVE #WindowsSecurity #InfoSec

securityonline.info/microsoft-

##

secdb@infosec.exchange at 2026-08-11T21:00:13.000Z ##

🚨 [CISA-2026:0811] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-20349 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-68820 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows Ancillary Function Driver for WinSock
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-72898 (secdb.nttzen.cloud/cve/detail/)
- Name: Metabase SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Metabase
- Product: Metabase
- Notes: metabase.com/blog/security-upd ; github.com/metabase/metabase/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260811 #cisa20260811 #cve_2026_20349 #cve_2026_68820 #cve_2026_72898 #cve202620349 #cve202668820 #cve202672898

##

cyberworldops@infosec.exchange at 2026-08-11T20:10:00.000Z ##

Microsoft Patch Tuesday August 2026 patches 421 CVEs including CVE-2026-68820, an actively exploited use-after-free in the kernel driver afd.sys that grants SYSTEM-level privileges. Attacks are ongoing and no operational details have been disclosed yet. Prioritize patching on exposed systems.

#PatchTuesday #ZeroDay #VulnerabilityManagement #Microsoft

cyberworldops.eu/en/microsoft-

##

cisakevtracker@mastodon.social at 2026-08-11T20:01:05.000Z ##

CVE ID: CVE-2026-68820
Vendor: Microsoft
Product: Windows Ancillary Function Driver for WinSock
Date Added: 2026-08-11
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-62832
(7.8 HIGH)

EPSS: 2.39%

updated 2026-08-12T14:18:23.150000

2 posts

Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.

CapTechGroup@mastodon.social at 2026-08-12T12:51:38.000Z ##

Microsoft's newest patch cycle closes nearly 400 security holes, among them CVE-2026-62832, CVE-2026-68820, and CVE-2026-72971. That volume makes triage the hard part, so plan which systems get updated first and confirm the rollout...

captechgroup.com/threat-intell

##

sayzard@mastodon.sayzard.org at 2026-08-12T03:43:20.000Z ##

Microsoft Plugs Nearly 400 Security Holes

Microsoft가 8월 Patch Tuesday에서 Windows 및 지원 소프트웨어의 취약점 최소 398건을 수정했으며, 이 중 42건은 원격 코드 실행 등으로 이어질 수 있는 Critical 등급이다. 이미 악용 중인 CVE-2026-68820은 거의 모든 Windows 엔드포인트의 소켓 연결에 관여하는 afd.sys의 권한 상승 취약점으로, 초기 침투 후 시스템 장악 체인에 사용될 수 있다. 또한 Windows User Profile Service의 CVE-2026-62832는 공개된 LegacyHive 이슈와 연관 가능성이 있으며 악용 가능성이 높은 것으로...

krebsonsecurity.com/2026/08/mi

##

CVE-2026-61353
(7.8 HIGH)

EPSS: 0.32%

updated 2026-08-12T14:18:03.773000

1 posts

Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

hugovalters@mastodon.social at 2026-08-12T15:12:11.000Z ##

CVE-2026-61353 - Heap buffer overflow in Windows Telephony Service. Local privilege escalation. CVSS 7.8. Patch reported, apply immediately. #CVE #Microsoft #infosec

valtersit.com/cve/CVE-2026-613

##

CVE-2026-19556
(8.8 HIGH)

EPSS: 0.31%

updated 2026-08-12T14:17:48.813000

2 posts

Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

DailyCyberSecurity at 2026-08-12T03:45:23.321Z ##

Google's new Chrome security update patches 5 high-severity use-after-free bugs, including CVE-2026-19556 and CVE-2026-19560. Update now.

securityonline.info/chrome-use

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T03:45:23.000Z ##

Google's new Chrome security update patches 5 high-severity use-after-free bugs, including CVE-2026-19556 and CVE-2026-19560. Update now.

#Chrome #Google #UseAfterFree #CVE #BrowserSecurity #PatchNow #Cybersecurity

securityonline.info/chrome-use

##

CVE-2026-70398
(9.6 CRITICAL)

EPSS: 0.22%

updated 2026-08-12T13:17:24.637000

4 posts

A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure locations to a namespace they control. This unauthorized access to tokens can lead to

thehackerwire@mastodon.social at 2026-08-12T04:00:28.000Z ##

🔴 CVE-2026-70398 - Critical (9.6)

A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a te...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-12T03:00:23.878Z ##

CRITICAL CVE-2026-70398 in Red Hat Advanced Cluster Management for Kubernetes 2: Authenticated tenants can redirect bearer tokens via GitOpsCluster controller. No official fix. Restrict privileges & monitor activity. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-12T04:00:28.000Z ##

🔴 CVE-2026-70398 - Critical (9.6)

A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a te...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-12T03:00:23.000Z ##

CRITICAL CVE-2026-70398 in Red Hat Advanced Cluster Management for Kubernetes 2: Authenticated tenants can redirect bearer tokens via GitOpsCluster controller. No official fix. Restrict privileges & monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #Kubernetes #RedHat #CVE202670398

##

CVE-2026-67282
(0 None)

EPSS: 0.57%

updated 2026-08-12T13:17:24.073000

2 posts

Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model.

offseq at 2026-08-12T12:00:27.314Z ##

CRITICAL: CVE-2026-67282 in Joomla Fabrik (v1.0.0 – 4.6.7) allows unauthenticated RCE (CWE-94). No patch yet — disable or restrict Fabrik use and monitor for updates. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-12T12:00:27.000Z ##

CRITICAL: CVE-2026-67282 in Joomla Fabrik (v1.0.0 – 4.6.7) allows unauthenticated RCE (CWE-94). No patch yet — disable or restrict Fabrik use and monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #Infosec #RCE #CVE202667282

##

CVE-2026-66875
(8.8 HIGH)

EPSS: 0.24%

updated 2026-08-12T13:17:23.933000

2 posts

In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or undocumented command opcodes, and passively track the user via a static random BLE address

thehackerwire@mastodon.social at 2026-08-12T00:01:15.000Z ##

🟠 CVE-2026-66875 - High (8.8)

In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measur...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T00:01:15.000Z ##

🟠 CVE-2026-66875 - High (8.8)

In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measur...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57858
(8.9 HIGH)

EPSS: 0.00%

updated 2026-08-12T13:17:22.943000

4 posts

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization. Attackers can close the inline script string literal with a crafted payload that executes in the browser of every visitor to

1 repos

https://github.com/zylideum/CVE-2026-57858

thehackerwire@mastodon.social at 2026-08-12T14:00:23.000Z ##

🟠 CVE-2026-57858 - High (8.9)

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracki...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-12T13:30:27.037Z ##

CVE-2026-57858: CRITICAL stored XSS in Cal.com Self-Hosted (v2.1.1 – 6.2.0). Exploited via BookingPageTagManager by authenticated event owners; affects all booking page visitors. Patch status unknown. Restrict privileges. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-12T14:00:23.000Z ##

🟠 CVE-2026-57858 - High (8.9)

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracki...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-12T13:30:27.000Z ##

CVE-2026-57858: CRITICAL stored XSS in Cal.com Self-Hosted (v2.1.1 – 6.2.0). Exploited via BookingPageTagManager by authenticated event owners; affects all booking page visitors. Patch status unknown. Restrict privileges. radar.offseq.com/threat/cve-20 #OffSeq #XSS #SecOps

##

CVE-2026-19426
(8.2 HIGH)

EPSS: 0.30%

updated 2026-08-12T09:31:30

2 posts

POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system.

thehackerwire@mastodon.social at 2026-08-12T11:01:24.000Z ##

🟠 CVE-2026-19426 - High (8.2)

POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T11:01:24.000Z ##

🟠 CVE-2026-19426 - High (8.2)

POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-41771
(4.3 MEDIUM)

EPSS: 0.16%

updated 2026-08-12T09:31:30

2 posts

An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLite database used only for storing notification messages. Therefore, the impact is limited to the system’s notification functionality.

certvde at 2026-08-12T08:07:13.931Z ##

VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-08-12T08:07:13.000Z ##

#OT #Advisory VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
#CVE CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2025-41770
(7.5 HIGH)

EPSS: 0.39%

updated 2026-08-12T08:17:11.910000

4 posts

An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.

thehackerwire@mastodon.social at 2026-08-12T11:01:45.000Z ##

🟠 CVE-2025-41770 - High (7.5)

An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde at 2026-08-12T08:07:13.931Z ##

VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

##

thehackerwire@mastodon.social at 2026-08-12T11:01:45.000Z ##

🟠 CVE-2025-41770 - High (7.5)

An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde@infosec.exchange at 2026-08-12T08:07:13.000Z ##

#OT #Advisory VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
#CVE CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2025-41769
(9.8 CRITICAL)

EPSS: 0.59%

updated 2026-08-12T08:17:11.590000

6 posts

The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.

cR0w at 2026-08-12T14:19:11.037Z ##

BoF in a PROFINET service?! I'm shocked. Shocked! Well, not that shocked.

nvd.nist.gov/vuln/detail/CVE-2

##

thehackerwire@mastodon.social at 2026-08-12T11:01:35.000Z ##

🔴 CVE-2025-41769 - Critical (9.8)

The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde at 2026-08-12T08:07:13.931Z ##

VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

##

cR0w@infosec.exchange at 2026-08-12T14:19:11.000Z ##

BoF in a PROFINET service?! I'm shocked. Shocked! Well, not that shocked.

nvd.nist.gov/vuln/detail/CVE-2

##

thehackerwire@mastodon.social at 2026-08-12T11:01:35.000Z ##

🔴 CVE-2025-41769 - Critical (9.8)

The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde@infosec.exchange at 2026-08-12T08:07:13.000Z ##

#OT #Advisory VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
#CVE CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-19594
(8.1 HIGH)

EPSS: 0.40%

updated 2026-08-12T06:31:00

2 posts

Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, and HTTP parameter pollution (CWE-141) via unencoded `&`/`#`/`=` characters in query string values. An attacker with access to a downstream application bu

thehackerwire@mastodon.social at 2026-08-12T12:00:23.000Z ##

🟠 CVE-2026-19594 - High (8.1)

Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T12:00:23.000Z ##

🟠 CVE-2026-19594 - High (8.1)

Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66659
(9.3 CRITICAL)

EPSS: 0.29%

updated 2026-08-12T06:31:00

4 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection. This issue affects Tablesome Table: from n/a through 1.2.9.

thehackerwire@mastodon.social at 2026-08-12T12:00:11.000Z ##

🔴 CVE-2026-66659 - Critical (9.3)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection.

This issue affects Tablesome Table: from n/a through 1.2.9.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-12T07:30:27.118Z ##

CVE-2026-66659: CRITICAL SQL Injection (CVSS 9.3) in Essekia Tablesome Table ≤1.2.9. Allows unauth’d blind SQLi & data disclosure. No patch yet — monitor vendor updates. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-12T12:00:11.000Z ##

🔴 CVE-2026-66659 - Critical (9.3)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection.

This issue affects Tablesome Table: from n/a through 1.2.9.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-12T07:30:27.000Z ##

CVE-2026-66659: CRITICAL SQL Injection (CVSS 9.3) in Essekia Tablesome Table ≤1.2.9. Allows unauth’d blind SQLi & data disclosure. No patch yet — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #SQLInjection #Vuln #Infosec

##

CVE-2026-66807
(7.8 HIGH)

EPSS: 0.36%

updated 2026-08-12T05:19:35.273000

1 posts

Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

hugovalters@mastodon.social at 2026-08-12T14:10:50.000Z ##

CVE-2026-66807 - High severity stack buffer overflow in Microsoft Office. Local code execution risk. CVSS 7.8. Patch reported—update immediately. #CVE #Microsoft #infosec

valtersit.com/cve/CVE-2026-668

##

CVE-2026-64954
(8.2 HIGH)

EPSS: 0.23%

updated 2026-08-12T05:19:17.893000

2 posts

Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "inve

thehackerwire@mastodon.social at 2026-08-12T06:00:25.000Z ##

🟠 CVE-2026-64954 - High (8.2)

Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the auth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T06:00:25.000Z ##

🟠 CVE-2026-64954 - High (8.2)

Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the auth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53413
(8.3 HIGH)

EPSS: 0.41%

updated 2026-08-12T05:17:55.123000

1 posts

Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.

571906@ap.podcastindex.org at 2026-08-12T02:00:02.000Z ##

New Episode: SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi

Shownotes:

Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236
Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415
https://a.security/blog/asecurity-zoomsday
Mozilla Revokes

Transcript

AntennaPod | Anytime Player | Apple Podcasts | Castamatic | CurioCaster | Fountain | gPodder | Overcast | Pocket Casts | Podcast Addict | Podcast Guru | Podnews | Podverse | Truefans

Or Listen right here.

##

CVE-2026-18961
(8.1 HIGH)

EPSS: 0.45%

updated 2026-08-12T03:31:28

2 posts

The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by Spotify's /v1/me endpoint as proof of mailbox ownership — Generic::normalize_common() copies this valu

thehackerwire@mastodon.social at 2026-08-12T04:00:18.000Z ##

🟠 CVE-2026-18961 - High (8.1)

The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the pl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T04:00:18.000Z ##

🟠 CVE-2026-18961 - High (8.1)

The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the pl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73122
(7.7 HIGH)

EPSS: 0.21%

updated 2026-08-12T03:31:23

2 posts

A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel namespace on the hub, potentially exposing credentials for other tenants' Git and Helm

thehackerwire@mastodon.social at 2026-08-12T06:00:48.000Z ##

🟠 CVE-2026-73122 - High (7.7)

A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T06:00:48.000Z ##

🟠 CVE-2026-73122 - High (7.7)

A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-6484
(8.2 HIGH)

EPSS: 0.14%

updated 2026-08-12T03:31:23

2 posts

In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.

thehackerwire@mastodon.social at 2026-08-12T01:59:50.000Z ##

🟠 CVE-2026-6484 - High (8.2)

In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T01:59:50.000Z ##

🟠 CVE-2026-6484 - High (8.2)

In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72526
(9.9 CRITICAL)

EPSS: 0.30%

updated 2026-08-12T03:31:18

4 posts

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attac

offseq at 2026-08-12T04:30:27.162Z ##

CVE-2026-72526 (CRITICAL, CVSS 9.9) in Red Hat Advanced Cluster Management for Kubernetes 2 lets low-priv hub users escalate to cluster-admin on managed clusters. No official fix. Restrict Application creation permissions now. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-12T04:00:39.000Z ##

🔴 CVE-2026-72526 - Critical (9.9)

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to creat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-12T04:30:27.000Z ##

CVE-2026-72526 (CRITICAL, CVSS 9.9) in Red Hat Advanced Cluster Management for Kubernetes 2 lets low-priv hub users escalate to cluster-admin on managed clusters. No official fix. Restrict Application creation permissions now. radar.offseq.com/threat/cve-20 #OffSeq #RedHat #Kubernetes #CVE2026_72526

##

thehackerwire@mastodon.social at 2026-08-12T04:00:39.000Z ##

🔴 CVE-2026-72526 - Critical (9.9)

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to creat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66878
(7.7 HIGH)

EPSS: 0.21%

updated 2026-08-12T03:31:17

2 posts

A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause the system to copy sensitive Secret contents from other namespaces into their own, leading to information disclosure.

thehackerwire@mastodon.social at 2026-08-12T12:00:33.000Z ##

🟠 CVE-2026-66878 - High (7.7)

A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Nam...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T12:00:33.000Z ##

🟠 CVE-2026-66878 - High (7.7)

A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Nam...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68067
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-08-12T00:31:23

4 posts

The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.

offseq at 2026-08-12T01:30:25.242Z ##

Mira Firmware v1.7.1.47 has a CRITICAL auth bug (CVE-2026-68067): login accepts any valid-format password, exposing hormone records. No patch yet; restrict access & monitor accounts. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-12T00:01:04.000Z ##

🔴 CVE-2026-68067 - Critical (9.8)

The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud acc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-12T01:30:25.000Z ##

Mira Firmware v1.7.1.47 has a CRITICAL auth bug (CVE-2026-68067): login accepts any valid-format password, exposing hormone records. No patch yet; restrict access & monitor accounts. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity #CVE202668067

##

thehackerwire@mastodon.social at 2026-08-12T00:01:04.000Z ##

🔴 CVE-2026-68067 - Critical (9.8)

The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud acc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67568
(9.1 CRITICAL)

EPSS: 0.24%

updated 2026-08-12T00:31:23

4 posts

The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.

thehackerwire@mastodon.social at 2026-08-12T00:01:26.000Z ##

🔴 CVE-2026-67568 - Critical (9.1)

The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-12T00:00:38.878Z ##

CVE-2026-67568 (CRITICAL, CVSS 9.3) in Mira Firmware 1.7.1.47: Hard-coded credentials let remote attackers read/write sensitive health data. No patch yet — restrict network access & monitor logs. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-12T00:01:26.000Z ##

🔴 CVE-2026-67568 - Critical (9.1)

The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-12T00:00:38.000Z ##

CVE-2026-67568 (CRITICAL, CVSS 9.3) in Mira Firmware 1.7.1.47: Hard-coded credentials let remote attackers read/write sensitive health data. No patch yet — restrict network access & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #CVE202667568 #infosec #medtech #vuln

##

CVE-2026-19560(CVSS UNKNOWN)

EPSS: 0.31%

updated 2026-08-12T00:31:11

2 posts

Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

DailyCyberSecurity at 2026-08-12T03:45:23.321Z ##

Google's new Chrome security update patches 5 high-severity use-after-free bugs, including CVE-2026-19556 and CVE-2026-19560. Update now.

securityonline.info/chrome-use

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T03:45:23.000Z ##

Google's new Chrome security update patches 5 high-severity use-after-free bugs, including CVE-2026-19556 and CVE-2026-19560. Update now.

#Chrome #Google #UseAfterFree #CVE #BrowserSecurity #PatchNow #Cybersecurity

securityonline.info/chrome-use

##

CVE-2026-66147
(9.4 CRITICAL)

EPSS: 1.05%

updated 2026-08-12T00:31:09

2 posts

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.

DailyCyberSecurity at 2026-08-12T00:45:54.822Z ##

SonicWall patched a critical GMS vulnerability, CVE-2026-66147 (CVSS 9.4), enabling unauthenticated remote code execution. Update to 9.5.2 now.

securityonline.info/sonicwall-

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T00:45:54.000Z ##

SonicWall patched a critical GMS vulnerability, CVE-2026-66147 (CVSS 9.4), enabling unauthenticated remote code execution. Update to 9.5.2 now.

#SonicWall #CVE #RCE #GMS #EmailSecurity #InfoSec

securityonline.info/sonicwall-

##

CVE-2026-73247
(8.6 HIGH)

EPSS: 0.30%

updated 2026-08-11T22:19:05.417000

2 posts

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the server-side HTTP client without restricting private, loopback, or link-local destinations, allowing an unauthenticated attacker to import and execute a flow that ac

thehackerwire@mastodon.social at 2026-08-12T00:00:12.000Z ##

🟠 CVE-2026-73247 - High (8.6)

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the server-side...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T00:00:12.000Z ##

🟠 CVE-2026-73247 - High (8.6)

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the server-side...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15562
(7.5 HIGH)

EPSS: 0.44%

updated 2026-08-11T21:33:39

1 posts

A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to denial of service.

thehackerwire@mastodon.social at 2026-08-11T10:00:39.000Z ##

🟠 CVE-2026-15562 - High (7.5)

A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to denial of ser...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18948
(9.9 CRITICAL)

EPSS: 0.69%

updated 2026-08-11T21:33:39

2 posts

A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated arbitrary code execution on the feature server in default configurations. An authenticated attacker can also achieve arbitrary code execution on the regis

offseq@infosec.exchange at 2026-08-11T04:30:24.000Z ##

CVE-2026-18948: CRITICAL in RHOAI Feast — unsafe UDF deserialization allows unauth RCE on feature-server. Auth attackers can bypass auth to run code on registry-server. Mitigate by enforcing `auth.type: kubernetes`. radar.offseq.com/threat/cve-20 #OffSeq #RedHat #CVE #infosec

##

thehackerwire@mastodon.social at 2026-08-10T22:01:31.000Z ##

🔴 CVE-2026-18948 - Critical (9.9)

A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18951
(8.8 HIGH)

EPSS: 0.66%

updated 2026-08-11T21:33:39

1 posts

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit ClusterRole` permissions in a namespace to create, modify, and delete `TrainJobs`. When combined with a separate vulnerability (TRN-01) that permits arbitrar

thehackerwire@mastodon.social at 2026-08-10T23:01:06.000Z ##

🟠 CVE-2026-18951 - High (8.8)

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit Clus...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18947
(8.5 HIGH)

EPSS: 0.43%

updated 2026-08-11T21:33:35

1 posts

A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omits the feature_views field, an attacker can bypass intended permission checks. This allows an unauthenticated remote attacker, or any authenticated user, to trigger a full re-materialization of all feature views. The cons

thehackerwire@mastodon.social at 2026-08-10T22:01:20.000Z ##

🟠 CVE-2026-18947 - High (8.5)

A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omits the feature_views field, an attacker can bypass intended permissi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73283
(2.5 LOW)

EPSS: 0.08%

updated 2026-08-11T21:33:18

2 posts

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

takmatsuoka@fedibird.com at 2026-08-12T12:28:03.000Z ##

OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG security.sios.jp/vulnerability

##

takmatsuoka@fedibird.com at 2026-08-12T12:28:03.000Z ##

OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG security.sios.jp/vulnerability

##

CVE-2026-73282
(4.8 MEDIUM)

EPSS: 0.16%

updated 2026-08-11T21:33:18

2 posts

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

takmatsuoka@fedibird.com at 2026-08-12T12:28:03.000Z ##

OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG security.sios.jp/vulnerability

##

takmatsuoka@fedibird.com at 2026-08-12T12:28:03.000Z ##

OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG security.sios.jp/vulnerability

##

CVE-2026-18949
(8.8 HIGH)

EPSS: 0.41%

updated 2026-08-11T21:32:33

1 posts

A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to cluster-administrator level, gain access to sensitive data like credentials and keys across the entire cluster, and disrupt multi-tenant isolation.

thehackerwire@mastodon.social at 2026-08-10T23:00:44.000Z ##

🟠 CVE-2026-18949 - High (8.8)

A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16985
(8.8 HIGH)

EPSS: 0.41%

updated 2026-08-11T21:32:30

1 posts

The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-update actions, allowing users with the upload_files capability (Author and above) to write an executable PHP file into the uploads directory and achieve remote code execution.

offseq@infosec.exchange at 2026-08-10T09:00:24.000Z ##

CVE-2026-16985: Squeeze WP plugin <1.7.12 has a CRITICAL vuln — users with upload_files can upload PHP files, enabling remote code execution. Restrict permissions, monitor uploads, and check for updates. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026_16985 #infosec

##

CVE-2026-73281
(3.5 LOW)

EPSS: 0.16%

updated 2026-08-11T21:17:52.563000

2 posts

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.

takmatsuoka@fedibird.com at 2026-08-12T12:28:03.000Z ##

OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG security.sios.jp/vulnerability

##

takmatsuoka@fedibird.com at 2026-08-12T12:28:03.000Z ##

OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース - SIOS SECURITY BLOG security.sios.jp/vulnerability

##

CVE-2026-55676
(8.8 HIGH)

EPSS: 0.30%

updated 2026-08-11T21:17:37.560000

1 posts

Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array by default (`file-upload/php/config.php:16`), so the type check is a no-op and every extension is ac

thehackerwire@mastodon.social at 2026-08-11T22:00:10.000Z ##

🟠 CVE-2026-55676 - High (8.8)

Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10579
(9.8 CRITICAL)

EPSS: 0.30%

updated 2026-08-11T21:17:24.910000

1 posts

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.

offseq@infosec.exchange at 2026-08-11T10:30:30.000Z ##

Red Hat JBoss EAP 7 hit by CVE-2026-10579 (CRITICAL, CVSS 9.8): SAML handler flaw lets unauthenticated attackers forge access as any user. Patch available — apply ASAP. Full details: radar.offseq.com/threat/cve-20 #OffSeq #RedHat #Vuln #CVE202610579

##

CVE-2026-73231
(7.8 HIGH)

EPSS: 0.15%

updated 2026-08-11T20:18:48.400000

1 posts

Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method in src/modules/helpers/eval.ts allows attacker-controlled fake templates to access the Function constructor through fakeEval.resolveProperty when a function returns another function, enabling arbitrary JavaScript code execution. This issue is fixed in version 10.5.0.

thehackerwire@mastodon.social at 2026-08-11T21:00:03.000Z ##

🟠 CVE-2026-73231 - High (7.8)

Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method in src/modules/helpers/eval.ts allows attacker-controlled fake templates to access the Function constructor through fakeEval.re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18950
(8.8 HIGH)

EPSS: 0.36%

updated 2026-08-11T20:17:38.323000

1 posts

A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role, including highly privileged ones like `cluster-admin`. This can lead to privilege escalation, where an attacker gains unauthorized elevated access withi

thehackerwire@mastodon.social at 2026-08-10T23:00:55.000Z ##

🟠 CVE-2026-18950 - High (8.8)

A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2021-44228
(10.0 CRITICAL)

EPSS: 100.00%

updated 2026-08-11T19:33:44.513000

1 posts

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is en

Nuclei template

100 repos

https://github.com/dwisiswant0/look4jar

https://github.com/fullhunt/log4j-scan

https://github.com/kubearmor/log4j-CVE-2021-44228

https://github.com/corretto/hotpatch-for-apache-log4j2

https://github.com/nccgroup/log4j-jndi-be-gone

https://github.com/corelight/cve-2021-44228

https://github.com/Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228

https://github.com/irgoncalves/f5-waf-quick-patch-cve-2021-44228

https://github.com/KosmX/CVE-2021-44228-example

https://github.com/puzzlepeaches/Log4jHorizon

https://github.com/Adikso/minecraft-log4j-honeypot

https://github.com/NS-Sp4ce/Vm4J

https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words

https://github.com/BinaryDefense/log4j-honeypot-flask

https://github.com/mzlogin/CVE-2021-44228-Demo

https://github.com/twseptian/spring-boot-log4j-cve-2021-44228-docker-lab

https://github.com/f0ng/log4j2burpscanner

https://github.com/NCSC-NL/log4shell

https://github.com/cyberxml/log4j-poc

https://github.com/bigsizeme/Log4j-check

https://github.com/CodeShield-Security/Log4JShell-Bytecode-Detector

https://github.com/tippexs/nginx-njs-waf-cve2021-44228

https://github.com/CERTCC/CVE-2021-44228_scanner

https://github.com/back2root/log4shell-rex

https://github.com/pedrohavay/exploit-CVE-2021-44228

https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce

https://github.com/mufeedvh/log4jail

https://github.com/HyCraftHD/Log4J-RCE-Proof-Of-Concept

https://github.com/RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs

https://github.com/christophetd/log4shell-vulnerable-app

https://github.com/mergebase/log4j-detector

https://github.com/aws-samples/kubernetes-log4j-cve-2021-44228-node-agent

https://github.com/MalwareTech/Log4jTools

https://github.com/Nanitor/log4fix

https://github.com/nu11secur1ty/CVE-2021-44228-VULN-APP

https://github.com/blake-fm/vcenter-log4j

https://github.com/giterlizzi/nmap-log4shell

https://github.com/HynekPetrak/log4shell-finder

https://github.com/0xDexter0us/Log4J-Scanner

https://github.com/claranet/ansible-role-log4shell

https://github.com/Labout/log4shell-rmi-poc

https://github.com/Jeromeyoung/log4j2burpscanner

https://github.com/sunnyvale-it/CVE-2021-44228-PoC

https://github.com/toramanemre/apache-solr-log4j-CVE-2021-44228

https://github.com/faisalfs10x/Log4j2-CVE-2021-44228-revshell

https://github.com/alexandre-lavoie/python-log4rce

https://github.com/roxas-tan/CVE-2021-44228

https://github.com/justakazh/Log4j-CVE-2021-44228

https://github.com/jas502n/Log4j2-CVE-2021-44228

https://github.com/hackinghippo/log4shell_ioc_ips

https://github.com/momos1337/Log4j-RCE

https://github.com/CreeperHost/Log4jPatcher

https://github.com/mr-vill4in/log4j-fuzzer

https://github.com/AlexandreHeroux/Fix-CVE-2021-44228

https://github.com/alexbakker/log4shell-tools

https://github.com/yahoo/check-log4j

https://github.com/leonjza/log4jpwn

https://github.com/greymd/CVE-2021-44228

https://github.com/Kadantte/CVE-2021-44228-poc

https://github.com/1lann/log4shelldetect

https://github.com/sec13b/CVE-2021-44228-POC

https://github.com/puzzlepeaches/Log4jCenter

https://github.com/rubo77/log4j_checker_beta

https://github.com/LiveOverflow/log4shell

https://github.com/mr-r3b00t/CVE-2021-44228

https://github.com/DragonSurvivalEU/RCE

https://github.com/cisagov/log4j-scanner

https://github.com/TaroballzChen/CVE-2021-44228-log4jVulnScanner-metasploit

https://github.com/marcourbano/CVE-2021-44228

https://github.com/stripe/log4j-remediation-tools

https://github.com/Azeemering/CVE-2021-44228-DFIR-Notes

https://github.com/wortell/log4j

https://github.com/qingtengyun/cve-2021-44228-qingteng-online-patch

https://github.com/lfama/log4j_checker

https://github.com/CrackerCat/CVE-2021-44228-Log4j-Payloads

https://github.com/takito1812/log4j-detect

https://github.com/r3kind1e/Log4Shell-obfuscated-payloads-generator

https://github.com/lucab85/log4j-cve-2021-44228

https://github.com/simonis/Log4jPatch

https://github.com/fireeye/CVE-2021-44228

https://github.com/redhuntlabs/Log4JHunt

https://github.com/toramanemre/log4j-rce-detect-waf-bypass

https://github.com/dtact/divd-2021-00038--log4j-scanner

https://github.com/fox-it/log4j-finder

https://github.com/boundaryx/cloudrasp-log4j2

https://github.com/0xInfection/LogMePwn

https://github.com/thomaspatzke/Log4Pot

https://github.com/logpresso/CVE-2021-44228-Scanner

https://github.com/NorthwaveSecurity/log4jcheck

https://github.com/ssl/scan4log4j

https://github.com/thecyberneh/Log4j-RCE-Exploiter

https://github.com/irgoncalves/f5-waf-enforce-sig-CVE-2021-44228

https://github.com/puzzlepeaches/Log4jUnifi

https://github.com/kozmer/log4j-shell-poc

https://github.com/infiniroot/nginx-mitigate-log4shell

https://github.com/Diverto/nse-log4shell

https://github.com/mubix/CVE-2021-44228-Log4Shell-Hashes

https://github.com/darkarnium/Log4j-CVE-Detect

https://github.com/future-client/CVE-2021-44228

https://github.com/qingtengyun/cve-2021-44228-qingteng-patch

cvedatabase@techhub.social at 2026-08-12T10:30:03.000Z ##

Securing your software supply chain shouldn't be manual work. 🤖 Our latest tutorial dives deep into automating dependency scanning within your CI/CD pipelines to block vulnerabilities like CVE-2021-44228. Elevate your DevSecOps game today! cvedatabase.com/blog/automatin #SCA #DevSecOps #CICD #InfoSec #CyberSecurity #Automation

##

CVE-2026-73224
(8.8 HIGH)

EPSS: 0.34%

updated 2026-08-11T19:18:52.030000

1 posts

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to execute arbitrary commands when a user downloads a crafted folder and invokes Properties and Calculate Size because calcLocal in src/client/components/sftp/file-info-modal.jsx inserts the server-controlled folder name into a du -sh shell com

thehackerwire@mastodon.social at 2026-08-11T20:00:08.000Z ##

🟠 CVE-2026-73224 - High (8.8)

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to execute arbitrary commands when a user downloads a crafted folder and invokes Properties...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20338
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-11T18:54:19.877000

5 posts

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to

ottoto2017@prattohome.com at 2026-08-12T05:43:02.000Z ##

「Cisco社、ClamAVの深刻な脆弱性と公開されているエクスプロイトについて警告 」: #BLEEPINGCOMPUTER

「Ciscoは、Secure Endpoint Connectorに影響を与える2つの深刻な脆弱性について警告を発した。これらの脆弱性により、攻撃者はサービス拒否(DoS)攻撃においてClamAVのスキャンプロセスをクラッシュさせることができる。

これらのセキュリティ上の欠陥( CVE-2026-20337 および CVE-2026-20338 として追跡)は、マルウェアのファイルスキャンに使用されるオープンソースかつクロスプラットフォームのエンジンであるClamAV(Clam AntiVirus)のZIPアーカイブパーサーで発見されました。

シスコが金曜日に発表した勧告によると、これら2つの脆弱性はそれぞれ不適切な境界チェックとメモリ処理に起因するものであり、認証されていないリモート攻撃者によって悪用される可能性がある。 」

bleepingcomputer.com/news/secu

#prattohome

##

ottoto2017@prattohome.com at 2026-08-12T05:43:02.000Z ##

「Cisco社、ClamAVの深刻な脆弱性と公開されているエクスプロイトについて警告 」: #BLEEPINGCOMPUTER

「Ciscoは、Secure Endpoint Connectorに影響を与える2つの深刻な脆弱性について警告を発した。これらの脆弱性により、攻撃者はサービス拒否(DoS)攻撃においてClamAVのスキャンプロセスをクラッシュさせることができる。

これらのセキュリティ上の欠陥( CVE-2026-20337 および CVE-2026-20338 として追跡)は、マルウェアのファイルスキャンに使用されるオープンソースかつクロスプラットフォームのエンジンであるClamAV(Clam AntiVirus)のZIPアーカイブパーサーで発見されました。

シスコが金曜日に発表した勧告によると、これら2つの脆弱性はそれぞれ不適切な境界チェックとメモリ処理に起因するものであり、認証されていないリモート攻撃者によって悪用される可能性がある。 」

bleepingcomputer.com/news/secu

#prattohome

##

jbhall56@infosec.exchange at 2026-08-11T13:59:35.000Z ##

The security flaws (tracked as CVE-2026-20337 and CVE-2026-20338) were found in the ZIP archive parser of ClamAV (Clam AntiVirus), the open-source and cross-platform engine used to scan files for malware. bleepingcomputer.com/news/secu

##

cyberworldops@infosec.exchange at 2026-08-10T20:10:00.000Z ##

Cisco disclosed seven high-severity vulnerabilities in ClamAV, the open-source antivirus engine used in Secure Endpoint Connector across Windows, macOS, and Linux. Two of the flaws (CVE-2026-20337 and CVE-2026-20338) already have public proof-of-concept exploits, elevating the risk. The vulnerabilities can trigger denial-of-service conditions.

#ClamAV #Cisco #CVE #InfoSec

cyberworldops.eu/en/cisco-repo

##

AAKL@infosec.exchange at 2026-08-10T16:26:02.000Z ##

New.

CISA: Gunra Ransomware Advisory cisa.gov/news-events/cybersecu

Cisco:

Advisory for a high-severity vulnerability first published on August 7:

CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #CISA #ransomware #cybercrime #vulnerability

##

CVE-2026-62901
(7.5 HIGH)

EPSS: 1.08%

updated 2026-08-11T18:53:42.910000

1 posts

Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.

us@newsbeep.org at 2026-08-11T23:40:13.000Z ##

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Tag
CVE ID
CVE Title
Severity
.NET
CVE-2026-58641
.NET Elevation of Privilege Vulnerability
Important
.NET
CVE-2026-62901
.NET Denial…
#NewsBeep #News #US #USA #UnitedStates #UnitedStatesOfAmerica #Technology
newsbeep.com/us/810540/

##

CVE-2026-72971
(5.5 MEDIUM)

EPSS: 0.36%

updated 2026-08-11T18:32:00

1 posts

Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.

CapTechGroup@mastodon.social at 2026-08-12T12:51:38.000Z ##

Microsoft's newest patch cycle closes nearly 400 security holes, among them CVE-2026-62832, CVE-2026-68820, and CVE-2026-72971. That volume makes triage the hard part, so plan which systems get updated first and confirm the rollout...

captechgroup.com/threat-intell

##

CVE-2026-58641
(7.8 HIGH)

EPSS: 0.40%

updated 2026-08-11T18:31:08

1 posts

Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

us@newsbeep.org at 2026-08-11T23:40:13.000Z ##

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Tag
CVE ID
CVE Title
Severity
.NET
CVE-2026-58641
.NET Elevation of Privilege Vulnerability
Important
.NET
CVE-2026-62901
.NET Denial…
#NewsBeep #News #US #USA #UnitedStates #UnitedStatesOfAmerica #Technology
newsbeep.com/us/810540/

##

CVE-2026-56721
(8.8 HIGH)

EPSS: 0.36%

updated 2026-08-11T18:30:54

2 posts

CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's credentials by exploiting a parameter confusion flaw between the authorization filter and action body in the UsersController. Attackers can send a PATCH request to the updated_ajax endpoint setting

hugovalters@mastodon.social at 2026-08-12T12:04:36.000Z ##

CVE-2026-56721 - Privilege escalation in CamaleonCMS ≤2.9.2 via IDOR. Authenticated low-priv users can overwrite any credentials. CVSS 8.8. Unpatched - update immediately. #CVE #CamaleonCMS #infosec

valtersit.com/cve/CVE-2026-567

##

thehackerwire@mastodon.social at 2026-08-11T17:01:48.000Z ##

🟠 CVE-2026-56721 - High (8.8)

CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's credentials by exploiting a parameter confus...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53414
(6.5 MEDIUM)

EPSS: 0.28%

updated 2026-08-11T18:30:54

1 posts

Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.

571906@ap.podcastindex.org at 2026-08-12T02:00:02.000Z ##

New Episode: SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi

Shownotes:

Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236
Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415
https://a.security/blog/asecurity-zoomsday
Mozilla Revokes

Transcript

AntennaPod | Anytime Player | Apple Podcasts | Castamatic | CurioCaster | Fountain | gPodder | Overcast | Pocket Casts | Podcast Addict | Podcast Guru | Podnews | Podverse | Truefans

Or Listen right here.

##

CVE-2026-53415
(8.3 HIGH)

EPSS: 0.39%

updated 2026-08-11T18:30:54

1 posts

Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.

571906@ap.podcastindex.org at 2026-08-12T02:00:02.000Z ##

New Episode: SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi

Shownotes:

Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236
Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415
https://a.security/blog/asecurity-zoomsday
Mozilla Revokes

Transcript

AntennaPod | Anytime Player | Apple Podcasts | Castamatic | CurioCaster | Fountain | gPodder | Overcast | Pocket Casts | Podcast Addict | Podcast Guru | Podnews | Podverse | Truefans

Or Listen right here.

##

CVE-2026-67180
(8.4 HIGH)

EPSS: 0.17%

updated 2026-08-11T18:30:53

1 posts

Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.

thehackerwire@mastodon.social at 2026-08-11T17:01:35.000Z ##

🟠 CVE-2026-67180 - High (8.4)

Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13738(CVSS UNKNOWN)

EPSS: 0.53%

updated 2026-08-11T18:30:43

1 posts

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.

offseq@infosec.exchange at 2026-08-11T12:00:31.000Z ##

CVE-2026-13738 (CRITICAL, CVSS 9.2) affects Commvault Cloud CommServe: authorization bypass enables unauthorized command execution. Affects v11.36.0 – 11.46.0. Upgrade all components. radar.offseq.com/threat/cve-20 #OffSeq #CVE #CloudSecurity #SysAdmin

##

CVE-2026-73079
(8.5 HIGH)

EPSS: 0.31%

updated 2026-08-11T17:19:15.747000

1 posts

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform API keys issued to tenants are exchanged for upstream requests made with shared provider accounts (ChatGPT/Codex OAuth, OpenAI platform keys, or an operator-configured base URL) that belong to the operator, not to the caller. The `POST /responses/*sub

thehackerwire@mastodon.social at 2026-08-11T17:00:18.000Z ##

🟠 CVE-2026-73079 - High (8.5)

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform API keys issued to tenants are exchanged for upstream requests made with shared provider accounts ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72915
(7.5 HIGH)

EPSS: 0.28%

updated 2026-08-11T17:19:14.203000

3 posts

Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user could use the show action in app/controllers/admin/collections_controller.rb to access personally identifying information about another local user in a collection because the controller used the general collection policy instead of the admin collectio

harald@mementomori.social at 2026-08-12T06:12:19.000Z ##

Vulnerabilities in #Mastodon
URL: github.com/mastodon/mastodon/s
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- github.com/mastodon/mastodon/s
- github.com/mastodon/mastodon/s

CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.

CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.

CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.

##

harald@mementomori.social at 2026-08-12T06:12:19.000Z ##

Vulnerabilities in #Mastodon
URL: github.com/mastodon/mastodon/s
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- github.com/mastodon/mastodon/s
- github.com/mastodon/mastodon/s

CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.

CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.

CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.

##

thehackerwire@mastodon.social at 2026-08-10T22:59:58.000Z ##

🟠 CVE-2026-72915 - High (7.5)

Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user could use the show action in app/controllers/admin/collections_controller.rb to access personally ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48161
(0 None)

EPSS: 0.42%

updated 2026-08-11T17:17:59.513000

1 posts

react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d1495a2505f9277da295a98cf176f4496 through 7b79148d1495a2505f9277da295a98cf176f4496 that executed remote attacker-controlled code on developer machines during `npm install`. The commits were removed by force-push, but local clones, forks, and direct-SHA

offseq@infosec.exchange at 2026-08-11T00:00:34.000Z ##

CVE-2026-48161 | CRITICAL: dai-shi react18-use had malicious postinstall script — RCE on dev machines via npm install. Not in npm registry, but local checkouts may be compromised. Rotate creds & reimage if affected. radar.offseq.com/threat/cve-20 #OffSeq #SupplyChain #CVE #npm #infosec

##

CVE-2026-13716
(9.1 CRITICAL)

EPSS: 0.56%

updated 2026-08-11T17:17:47.430000

1 posts

Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.

offseq@infosec.exchange at 2026-08-11T07:30:28.000Z ##

CRITICAL path traversal (CVE-2026-13716, CVSS 9.1) found in Crafty Controller v4.4.0 (Arcadia). Authenticated attackers can upload files to arbitrary paths, risking RCE. Restrict admin/file upload access & monitor activity. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CVE202613716

##

CVE-2026-72903
(8.1 HIGH)

EPSS: 0.31%

updated 2026-08-11T16:17:37.360000

1 posts

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _makeFile() use POSIX path processing that preserves the backslashes as ordinary filename characters. In tabby-ssh/src/components/sftpPanel.component.ts, downloadFold

thehackerwire@mastodon.social at 2026-08-10T22:00:28.000Z ##

🟠 CVE-2026-72903 - High (8.1)

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _makeFile() u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67179
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-11T16:17:34.113000

1 posts

Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registered Genkit action and read the result. Fixed on 2026-06-18.

thehackerwire@mastodon.social at 2026-08-11T17:01:23.000Z ##

🟠 CVE-2026-67179 - High (7.8)

Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registere...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18786
(8.8 HIGH)

EPSS: 0.29%

updated 2026-08-11T16:17:31.037000

1 posts

The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose URI merely contains a CheckView WordPress plugin before 2.3.2-specific string, making it possible for unauthenticated attackers to bypass the REST nonce check and perform any REST action available to

offseq@infosec.exchange at 2026-08-10T07:30:27.000Z ##

CVE-2026-18786: CRITICAL auth bypass in CheckView WP plugin ≤2.0.29. Attackers can exploit REST API via crafted links to perform admin actions if an admin clicks. Restrict plugin REST API & avoid suspicious links. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202618786

##

CVE-2026-73080
(9.3 CRITICAL)

EPSS: 0.38%

updated 2026-08-11T15:58:24

1 posts

### Impact `VolumeServer.FetchAndWriteNeedle` fetches a caller-supplied remote endpoint and writes the response into a needle. Before 4.24 this RPC performed no authentication and no validation of the target, so anyone able to reach a volume server's gRPC port could coerce the server into issuing requests to arbitrary hosts — including loopback, link-local, RFC 1918, and cloud metadata endpoints s

thehackerwire@mastodon.social at 2026-08-11T17:00:34.000Z ##

🔴 CVE-2026-73080 - Critical (9.3)

SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the response i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18129
(8.1 HIGH)

EPSS: 0.87%

updated 2026-08-11T15:32:51

2 posts

Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.

jbhall56 at 2026-08-12T12:52:08.597Z ##

Tracked as CVE-2026-18129, the first is described as a cleartext transmission of sensitive information issue that can be exploited by an attacker in a man-in-the-middle (MitM) position to leak credentials for external SQL connections. securityweek.com/ivanti-epm-up

##

jbhall56@infosec.exchange at 2026-08-12T12:52:08.000Z ##

Tracked as CVE-2026-18129, the first is described as a cleartext transmission of sensitive information issue that can be exploited by an attacker in a man-in-the-middle (MitM) position to leak credentials for external SQL connections. securityweek.com/ivanti-epm-up

##

CVE-2026-58115
(10.0 CRITICAL)

EPSS: 0.65%

updated 2026-08-11T15:32:40

2 posts

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attack

DailyCyberSecurity at 2026-08-12T07:32:31.690Z ##

CVE-2026-58115 is a CVSS 10 flaw letting unauthenticated attackers run code on SIMATIC IoT2050 via Node-RED. Siemens urges an immediate update.

securityonline.info/simatic-io

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T07:32:31.000Z ##

CVE-2026-58115 is a CVSS 10 flaw letting unauthenticated attackers run code on SIMATIC IoT2050 via Node-RED. Siemens urges an immediate update.

#CVE202658115 #Siemens #NodeRED #RCE #SIMATIC #ICS #Cybersecurity

securityonline.info/simatic-io

##

CVE-2026-18972
(9.6 CRITICAL)

EPSS: 0.33%

updated 2026-08-11T15:32:40

1 posts

An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.

offseq@infosec.exchange at 2026-08-11T13:30:32.000Z ##

CVE-2026-18972 (CRITICAL): Rapid7 Velociraptor <0.77.2 lets low-priv users escalate to admin by spoofing 'Grpc-Metadata-USER' header — full account takeover. No patch yet. Restrict GUI access, monitor requests. radar.offseq.com/threat/cve-20 #OffSeq #Velociraptor #CVE202618972

##

CVE-2026-72864
(9.9 CRITICAL)

EPSS: 0.27%

updated 2026-08-11T15:17:36.393000

1 posts

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/server/wss/docker-container-terminal.ts authenticates with validateRequest but does not authorize the attacker-controlled containerId against the caller's role, organization, or service access before passing it to `docker exec`, allowing any authenticated

thehackerwire@mastodon.social at 2026-08-10T20:00:44.000Z ##

🔴 CVE-2026-72864 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/server/wss/docker-container-terminal.ts authenticates with validateRequest but does not authorize the a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44763
(7.6 HIGH)

EPSS: 0.28%

updated 2026-08-11T15:17:29.830000

1 posts

SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker�s control. Successful exploitation could allow files to be written outside the i

thehackerwire@mastodon.social at 2026-08-11T03:00:45.000Z ##

🟠 CVE-2026-44763 - High (7.6)

SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58231
(10.0 CRITICAL)

EPSS: 0.73%

updated 2026-08-11T12:30:28

6 posts

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

jbhall56 at 2026-08-12T12:15:46.790Z ##

The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation. thehackernews.com/2026/08/sap-

##

undercodenews@mastodon.social at 2026-08-12T08:29:46.000Z ##

SAP Issues Emergency-Grade Patch for CVSS 100 Commerce Cloud Flaw That Could Enable Unauthenticated Code Execution + Video

A Critical Warning for SAP Enterprise Customers A maximum-severity vulnerability in SAP Commerce Cloud has put enterprise e-commerce environments under renewed security pressure. The newly identified flaw, tracked as CVE-2026-58231, carries the highest possible CVSS score of 10.0 and could allow an unauthenticated attacker to execute arbitrary code…

undercodenews.com/sap-issues-e

##

beyondmachines1 at 2026-08-12T08:01:15.265Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**

beyondmachines.net/event_detai

##

jbhall56@infosec.exchange at 2026-08-12T12:15:46.000Z ##

The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation. thehackernews.com/2026/08/sap-

##

beyondmachines1@infosec.exchange at 2026-08-12T08:01:15.000Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-08-11T12:43:35.000Z ##

SAP August 2026 Patch Day fixes CVE-2026-58231 (CVSS 10.0) and code injection RCE flaws scoring 9.9 and 9.8 across Commerce Cloud and NetWeaver.

#SAP #CVE #RCE #PatchTuesday #NetWeaver #InfoSec

securityonline.info/sap-august

##

CVE-2026-71217
(7.5 HIGH)

EPSS: 0.42%

updated 2026-08-11T12:30:22

1 posts

A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can

thehackerwire@mastodon.social at 2026-08-11T10:00:13.000Z ##

🟠 CVE-2026-71217 - High (7.5)

A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper inp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72693
(7.8 HIGH)

EPSS: 0.10%

updated 2026-08-11T09:32:42

1 posts

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc/<pid>/fd/0")`. `stat()` on `/proc/<pid>/fd/0` follows the symlink to the underlying TTY device node. As a result, `buf.st_uid` reflects the owner of the TTY node

thehackerwire@mastodon.social at 2026-08-11T10:00:27.000Z ##

🟠 CVE-2026-72693 - High (7.8)

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc//fd/0")`....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19425
(9.8 CRITICAL)

EPSS: 0.47%

updated 2026-08-11T06:31:25

1 posts

Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.

offseq@infosec.exchange at 2026-08-11T09:00:26.000Z ##

Win Men Intermational Travel Agency Management System has a CRITICAL SQL Injection flaw (CVE-2026-19425, CVSS 9.8). Unauthenticated attackers may fully compromise databases. No patch yet: restrict access & monitor for SQLi. radar.offseq.com/threat/cve-20 #OffSeq #CVE202619425 #SQLInjection #InfoSec

##

CVE-2026-19516
(9.1 CRITICAL)

EPSS: 0.23%

updated 2026-08-11T06:31:25

1 posts

A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance, a caller can direct requests at internal, loopback, and link-local network services (including metadata endpoints) and r

offseq@infosec.exchange at 2026-08-11T06:00:25.000Z ##

Grafana MCP Server hit by CRITICAL SSRF (CVE-2026-19516, CVSS 9.1) via X-Grafana-URL header. Attackers can access internal endpoints and metadata. Restrict access & monitor usage until patch available. radar.offseq.com/threat/cve-20 #OffSeq #Grafana #SSRF #Vuln

##

CVE-2026-58243
(8.8 HIGH)

EPSS: 0.31%

updated 2026-08-11T03:32:04

1 posts

SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality

thehackerwire@mastodon.social at 2026-08-11T02:00:11.000Z ##

🟠 CVE-2026-58243 - High (8.8)

SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66763
(7.9 HIGH)

EPSS: 0.13%

updated 2026-08-11T03:32:04

1 posts

SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected inform

thehackerwire@mastodon.social at 2026-08-11T02:00:02.000Z ##

🟠 CVE-2026-66763 - High (7.9)

SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-34265
(9.8 CRITICAL)

EPSS: 0.44%

updated 2026-08-11T03:31:57

5 posts

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application.

beyondmachines1 at 2026-08-12T08:01:15.265Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-12T08:01:15.000Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

se38@nrw.social at 2026-08-11T06:42:28.000Z ##

Time to patch your Kernel...
CVSS v3.0 Base Score: 9,8 / 10

3714806 - [CVE-2026-34265] Memory Corruption vulnerability in Application Server #ABAP for #SAP NetWeaver and ABAP Platform

me.sap.com/notes/3714806

##

thehackerwire@mastodon.social at 2026-08-11T03:00:26.000Z ##

🔴 CVE-2026-34265 - Critical (9.8)

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the sy...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-11T03:00:27.000Z ##

CVE-2026-34265: CRITICAL out-of-bounds write in SAP NetWeaver & ABAP Platform (CVSS 9.8) allows unauthenticated memory corruption. No patch yet — restrict access & monitor SAP advisories for updates. radar.offseq.com/threat/cve-20 #OffSeq #SAP #Vuln #Cybersecurity

##

CVE-2026-44758
(9.1 CRITICAL)

EPSS: 0.51%

updated 2026-08-11T03:31:55

4 posts

SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability

beyondmachines1 at 2026-08-12T08:01:15.265Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-12T08:01:15.000Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

thehackerwire@mastodon.social at 2026-08-11T03:00:35.000Z ##

🔴 CVE-2026-44758 - Critical (9.1)

SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-11T01:30:29.000Z ##

SAP MII 15.5 is exposed to CRITICAL code injection (CVE-2026-44758, CVSS 9.1). High-privilege users could execute arbitrary OS commands. No patch yet — restrict access & monitor for code injection. radar.offseq.com/threat/cve-20 #OffSeq #SAP #Infosec #CVE202644758

##

CVE-2026-8917
(0 None)

EPSS: 0.11%

updated 2026-08-11T03:18:01.900000

1 posts

Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an arbitrary memory address, potentially leading to privilege escalation. Refer to the '  Security Update for ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and Armoury Crate Security Bulletin   ' section on the ASUS Security Advisory fo

AAKL@infosec.exchange at 2026-08-11T19:02:36.000Z ##

Asus posted an advisory today. Scroll down for the full list:

CVE-2026-8917: Security Update for ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and Armoury Crate Security Bulletin asus.com/security-advisory/

PC Gamer: It's time to update Asus Armoury Crate and several other Asus software tools again, as another high severity security vulnerability has been discovered pcgamer.com/software/security/ #infosec #vulnerability #Asus

##

CVE-2026-73030
(8.1 HIGH)

EPSS: 0.38%

updated 2026-08-10T21:32:15

1 posts

unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.

thehackerwire@mastodon.social at 2026-08-10T22:00:06.000Z ##

🟠 CVE-2026-73030 - High (8.1)

unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63622
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-10T21:32:08

1 posts

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user. This allows for

thehackerwire@mastodon.social at 2026-08-10T22:01:09.000Z ##

🟠 CVE-2026-63622 - High (7.8)

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63106
(9.8 CRITICAL)

EPSS: 0.29%

updated 2026-08-10T21:17:23.437000

1 posts

ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause without parameterization in ProductController.php. Attackers can perform time-based blind SQL injection through the unsanitized rating parameter to extract the full database contents,

thehackerwire@mastodon.social at 2026-08-10T16:00:32.000Z ##

🔴 CVE-2026-63106 - Critical (9.8)

ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause without parameterization in Pr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72901
(9.9 CRITICAL)

EPSS: 0.63%

updated 2026-08-10T20:17:35.570000

1 posts

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbitrary commands on the control-plane host because the volumeName field accepted by volumeBackup.create and volumeBackup.runManually is interpolated without quoting in packages/server/src/utils/volume-backups/backup.ts and executed through child_process

thehackerwire@mastodon.social at 2026-08-10T21:00:31.000Z ##

🔴 CVE-2026-72901 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbitrary commands on the control-plane host because the volumeName field accepted by volumeBackup.cre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72689
(7.5 HIGH)

EPSS: 0.32%

updated 2026-08-10T19:17:33.103000

1 posts

A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents using useMasterKey, bypassing the object ACL, and returns full records including sender and signer PII and a pre-signed document download URL whenever the

thehackerwire@mastodon.social at 2026-08-10T16:00:43.000Z ##

🟠 CVE-2026-72689 - High (7.5)

A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents us...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71576
(8.5 HIGH)

EPSS: 0.12%

updated 2026-08-10T17:17:36.060000

1 posts

A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka client certificate, can manipulate the self-asserted source identity. This allows the attacker to falsify or delete critical data, such as compliance, inventory, and cl

thehackerwire@mastodon.social at 2026-08-10T18:00:01.000Z ##

🟠 CVE-2026-71576 - High (8.5)

A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka client certific...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66738
(8.8 HIGH)

EPSS: 0.40%

updated 2026-08-10T17:17:35.557000

1 posts

SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and allows the value to break out of an internal quoted string context when evaluated as PHP. An authenticated attacker with at minimum editor (redacteur) privileges can submit a single crafted GET reque

thehackerwire@mastodon.social at 2026-08-10T17:00:14.000Z ##

🔴 CVE-2026-66738 - Critical (9.8)

SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and allows the value to break out of an internal q...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72691
(7.5 HIGH)

EPSS: 0.39%

updated 2026-08-10T15:33:59

1 posts

An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud function. The function skips its isAuthenticated check whenever any docId parameter is supplied, even one corresponding to no real document, allowing the authentication

thehackerwire@mastodon.social at 2026-08-10T16:00:57.000Z ##

🟠 CVE-2026-72691 - High (7.5)

An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud function. The f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13206
(9.8 CRITICAL)

EPSS: 1.27%

updated 2026-08-10T15:33:42

1 posts

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection. This issue affects WAH7601: through 20072026.

offseq@infosec.exchange at 2026-08-10T13:30:24.000Z ##

CVE-2026-13206: CRITICAL OS command injection in Zyxel WAH7601 (≤20072026). Remote, unauthenticated code execution possible — no patch yet. Restrict access & monitor vendor updates. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #Zyxel #Vuln #InfoSec

##

CVE-2026-18933
(7.2 HIGH)

EPSS: 0.28%

updated 2026-08-10T12:17:14.430000

1 posts

The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation of any kind - no wp_check_filetype_and_ext, no validate_file, and no extension blocklist exist anywhere in the upload handler.

nyanbinary@infosec.exchange at 2026-08-11T14:38:03.000Z ##

Or this one - does that links actually document the vulnerability?

nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-19389
(7.1 HIGH)

EPSS: 0.24%

updated 2026-08-10T03:31:01

1 posts

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information

offseq@infosec.exchange at 2026-08-10T04:30:27.000Z ##

GStreamer gst-plugins-ugly (asfdemux) in Red Hat Enterprise Linux 10 is affected by CVE-2026-19389 (HIGH, CVSS 7.1). Parsing crafted ASF/WMV/WMA files may lead to DoS or info leaks. No patch yet — avoid untrusted media. radar.offseq.com/threat/cve-20 #OffSeq #Linux #CVE #GStreamer

##

CVE-2026-19387
(7.6 HIGH)

EPSS: 0.24%

updated 2026-08-10T03:31:01

1 posts

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code ex

thehackerwire@mastodon.social at 2026-08-10T03:59:51.000Z ##

🟠 CVE-2026-19387 - High (7.6)

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64564
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-08-09T06:31:34

2 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds

4 repos

https://github.com/ethanolgolf/CVE-2026-64564

https://github.com/suominen/sctphantom

https://github.com/HackSpeak/CVE-2026-64564

https://github.com/yandex-cloud-examples/yc-mk8s-sctphantom-mitigation

tugatech@masto.pt at 2026-08-11T10:46:33.000Z ##

Falha com 18 anos no Linux entrega controlo máximo de administrador. Uma falha de segurança identificada como CVE-2026-64564 permite que utilizadores com acesso local prévio escalarem privilégios até atingirem o estatuto máximo no sistema operativo. 🚨

🔗 tugatech.com.pt/t88893-falha-c

#administrador #controlo #entrega #falha #linux 

##

linuxse@friendica.helvetet.eu at 2026-08-10T05:40:52.000Z ## En 18 år gammal sårbarhet i Linuxkärnans SCTP-kod kan ge lokala angripare fullständig rootåtkomst. Säkerhetsforskarna bakom upptäckten har även visat att felet under vissa förutsättningar kan användas för att ta sig ur en container och angripa värdsystemet. Sårbarheten har fått namnet SCTPhantom och registrerats som CVE-2026-64564. Den finns i Linuxkärnans stöd för nätverksprotokollet SCTP och […]
SCTPhantom – 18 år gammal Linux-bugg kan ge angripare rootåtkomst ##

CVE-2026-67261
(9.8 CRITICAL)

EPSS: 1.60%

updated 2026-08-07T20:08:27.597000

2 posts

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete sys

CVE-2026-20339
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-07T18:31:54

1 posts

A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. An attacker could exploit this

AAKL@infosec.exchange at 2026-08-10T16:26:02.000Z ##

New.

CISA: Gunra Ransomware Advisory cisa.gov/news-events/cybersecu

Cisco:

Advisory for a high-severity vulnerability first published on August 7:

CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #CISA #ransomware #cybercrime #vulnerability

##

CVE-2026-20337
(7.5 HIGH)

EPSS: 0.36%

updated 2026-08-07T18:31:52

5 posts

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A success

ottoto2017@prattohome.com at 2026-08-12T05:43:02.000Z ##

「Cisco社、ClamAVの深刻な脆弱性と公開されているエクスプロイトについて警告 」: #BLEEPINGCOMPUTER

「Ciscoは、Secure Endpoint Connectorに影響を与える2つの深刻な脆弱性について警告を発した。これらの脆弱性により、攻撃者はサービス拒否(DoS)攻撃においてClamAVのスキャンプロセスをクラッシュさせることができる。

これらのセキュリティ上の欠陥( CVE-2026-20337 および CVE-2026-20338 として追跡)は、マルウェアのファイルスキャンに使用されるオープンソースかつクロスプラットフォームのエンジンであるClamAV(Clam AntiVirus)のZIPアーカイブパーサーで発見されました。

シスコが金曜日に発表した勧告によると、これら2つの脆弱性はそれぞれ不適切な境界チェックとメモリ処理に起因するものであり、認証されていないリモート攻撃者によって悪用される可能性がある。 」

bleepingcomputer.com/news/secu

#prattohome

##

ottoto2017@prattohome.com at 2026-08-12T05:43:02.000Z ##

「Cisco社、ClamAVの深刻な脆弱性と公開されているエクスプロイトについて警告 」: #BLEEPINGCOMPUTER

「Ciscoは、Secure Endpoint Connectorに影響を与える2つの深刻な脆弱性について警告を発した。これらの脆弱性により、攻撃者はサービス拒否(DoS)攻撃においてClamAVのスキャンプロセスをクラッシュさせることができる。

これらのセキュリティ上の欠陥( CVE-2026-20337 および CVE-2026-20338 として追跡)は、マルウェアのファイルスキャンに使用されるオープンソースかつクロスプラットフォームのエンジンであるClamAV(Clam AntiVirus)のZIPアーカイブパーサーで発見されました。

シスコが金曜日に発表した勧告によると、これら2つの脆弱性はそれぞれ不適切な境界チェックとメモリ処理に起因するものであり、認証されていないリモート攻撃者によって悪用される可能性がある。 」

bleepingcomputer.com/news/secu

#prattohome

##

jbhall56@infosec.exchange at 2026-08-11T13:59:35.000Z ##

The security flaws (tracked as CVE-2026-20337 and CVE-2026-20338) were found in the ZIP archive parser of ClamAV (Clam AntiVirus), the open-source and cross-platform engine used to scan files for malware. bleepingcomputer.com/news/secu

##

cyberworldops@infosec.exchange at 2026-08-10T20:10:00.000Z ##

Cisco disclosed seven high-severity vulnerabilities in ClamAV, the open-source antivirus engine used in Secure Endpoint Connector across Windows, macOS, and Linux. Two of the flaws (CVE-2026-20337 and CVE-2026-20338) already have public proof-of-concept exploits, elevating the risk. The vulnerabilities can trigger denial-of-service conditions.

#ClamAV #Cisco #CVE #InfoSec

cyberworldops.eu/en/cisco-repo

##

AAKL@infosec.exchange at 2026-08-10T16:26:02.000Z ##

New.

CISA: Gunra Ransomware Advisory cisa.gov/news-events/cybersecu

Cisco:

Advisory for a high-severity vulnerability first published on August 7:

CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #CISA #ransomware #cybercrime #vulnerability

##

CVE-2026-8037
(9.6 CRITICAL)

EPSS: 99.31%

updated 2026-08-07T18:31:36

2 posts

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

Nuclei template

2 repos

https://github.com/HORKimhab/CVE-2026-8037

https://github.com/Caster-chen/CVE-2026-8037-POC

thecybermind@infosec.exchange at 2026-08-10T14:09:10.000Z ##

🚨 CRITICAL THREAT ALERT: CVE-2026-8037 is under active exploitation per CISA KEV. Progress LoadMaster appliances face remote command injection risks. Secure your perimeter with our strategic C-Suite breakdown covering technical indicators, backdoor mechanics, and hardening protocols.
thecybermind.co/2j7b

##

threatnoir@infosec.exchange at 2026-08-10T12:06:17.000Z ##

⚠️ CRITICAL: CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability

Progress Kemp LoadMaster has a critical RCE vulnerability (CVE-2026-8037) that allows unauthenticated attackers to execute arbitrary commands. Active exploitation started around June 29. Any organization running affected LoadMaster versions needs to patch immediately or risk full appliance compromi…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

CVE-2026-5423
(0 None)

EPSS: 0.34%

updated 2026-08-06T22:18:10.297000

1 posts

@neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT object passed through GraphQL subscription connectionParams. As a result, any unauthenticated remote client that can open a GraphQL-over-WebSocket connection can forge arbitrary JWT claims (e.g. sub, roles) in connectionParams.jwt and have them accepted as authenticated identity for

CVE-2026-34966
(7.6 HIGH)

EPSS: 0.31%

updated 2026-08-05T21:31:47

2 posts

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arbitrary URLs through release asset download URLs, pull-request patch URLs, or OAuth avatar endpoints

nyanbinary@infosec.exchange at 2026-08-11T16:58:03.000Z ##

ACTUALLY...

CVE-2026-34966 -> github.com/go-gitea/gitea/secu -> CVE-2026-59765

... did they double assign without retraction?

##

nyanbinary@infosec.exchange at 2026-08-11T16:53:26.000Z ##

motherf... nvd.nist.gov/vuln/detail/cve-2

Why is this a vulncheck CVE, gitea got their own CNA!

##

CVE-2026-71319
(9.6 CRITICAL)

EPSS: 0.32%

updated 2026-08-05T21:27:39

2 posts

### Impact Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the `nuxt:devtools:rpc` plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (`ws://<host>:<port>/`, subprotocol `vite-hmr`) can call RPC methods, with no token, handshake, or origin check before the channel is established.

DailyCyberSecurity at 2026-08-12T13:19:37.895Z ##

CVE-2026-71319 lets attackers run arbitrary commands via unauthenticated Nuxt DevTools RPC. CVSS 9.6, 7.3M monthly downloads. Patch now.

securityonline.info/nuxt-devto

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T13:19:37.000Z ##

CVE-2026-71319 lets attackers run arbitrary commands via unauthenticated Nuxt DevTools RPC. CVSS 9.6, 7.3M monthly downloads. Patch now.

#Nuxt #VueJS #CVE #RCE #CyberSecurity

securityonline.info/nuxt-devto

##

CVE-2026-63077
(9.8 CRITICAL)

EPSS: 10.72%

updated 2026-08-05T18:32:31

1 posts

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Nuclei template

4 repos

https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap

https://github.com/AnggaTechI/CVE-2026-63077

https://github.com/sfewer-r7/CVE-2026-63077

https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation

CVE-2026-71249
(6.1 MEDIUM)

EPSS: 0.15%

updated 2026-08-05T12:31:36

1 posts

299Ko's public contact form (plugin/contact/controllers/ContactController.php, home()) sets raw POST field values (name, firstname, email, message) into the page template with no sanitization. The template engine's variable output function (common/Template.php, _show_var()) echoes values with no htmlspecialchars() call, and the sink template (contact.tpl) outputs these values unescaped into an HTM

CVE-2026-55739
(8.3 HIGH)

EPSS: 0.27%

updated 2026-08-05T09:31:26

1 posts

Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and $user->hasCompany($model->company_id). CustomerPolicy's view/update/delete methods omit the company-ownership check entirely, checking only the blanket ability. Route-model-bound customer lookups and the bulk Customer::deleteCustomers() method are similarly unscoped (self

nyanbinary@infosec.exchange at 2026-08-11T14:43:29.000Z ##

Like, please read this: cve.org/ResourcesSupport/AllRe

And then tell me that this CVE nvd.nist.gov/vuln/detail/CVE-2 is sufficiently documented by the one and only reference github.com/crater-invoice-inc/ , the landing page for a project that has not had a release in 4 years (years before the vulnerability was presumably assigned)

##

CVE-2026-10090
(9.9 CRITICAL)

EPSS: 0.25%

updated 2026-08-05T09:31:26

1 posts

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscription resource referencing it. The app-subscription controller fetches and applies t

CVE-2024-55591
(9.8 CRITICAL)

EPSS: 98.26%

updated 2026-08-05T05:16:42.380000

2 posts

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

Nuclei template

9 repos

https://github.com/virus-or-not/CVE-2024-55591

https://github.com/watchtowrlabs/fortios-auth-bypass-check-CVE-2024-55591

https://github.com/0x7556/CVE-2024-55591

https://github.com/UMChacker/CVE-2024-55591-POC

https://github.com/exfil0/CVE-2024-55591-POC

https://github.com/sysirq/fortios-auth-bypass-poc-CVE-2024-55591

https://github.com/binarywarm/exp-cmd-add-admin-vpn-CVE-2024-55591

https://github.com/watchtowrlabs/fortios-auth-bypass-poc-CVE-2024-55591

https://github.com/sysirq/fortios-auth-bypass-exploit-CVE-2024-55591

Analyst207@mastodon.social at 2026-08-12T14:03:19.000Z ##

Gunra Ransomware Targets Infrastructure via Fortinet Flaws

Gunra Ransomware is exploiting critical Fortinet flaws, including CVE-2024-55591, to gain super-admin privileges and infiltrate government and critical infrastructure networks. This alarming vulnerability allows remote attackers to craft requests and bypass authentication, putting sensitive systems at risk.

osintsights.com/gunra-ransomwa

#GunraRansomware #Fortinet #Cve202455591 #Ransomware #SupplyChain

##

Analyst207@mastodon.social at 2026-08-12T14:03:19.000Z ##

Gunra Ransomware Targets Infrastructure via Fortinet Flaws

Gunra Ransomware is exploiting critical Fortinet flaws, including CVE-2024-55591, to gain super-admin privileges and infiltrate government and critical infrastructure networks. This alarming vulnerability allows remote attackers to craft requests and bypass authentication, putting sensitive systems at risk.

osintsights.com/gunra-ransomwa

#GunraRansomware #Fortinet #Cve202455591 #Ransomware #SupplyChain

##

CVE-2026-61515
(9.8 CRITICAL)

EPSS: 1.58%

updated 2026-08-04T15:32:30

2 posts

Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary com

DailyCyberSecurity at 2026-08-12T12:45:44.778Z ##

PoC exploit code is public for CVE-2026-61515, an unauthenticated command injection in Puwell IP Camera firmware. CVSS 9.3. Details inside.

securityonline.info/puwell-ip-

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T12:45:44.000Z ##

PoC exploit code is public for CVE-2026-61515, an unauthenticated command injection in Puwell IP Camera firmware. CVSS 9.3. Details inside.

#IPCamera #IoT #CVE #CommandInjection #CyberSecurity

securityonline.info/puwell-ip-

##

CVE-2026-18577
(8.1 HIGH)

EPSS: 4.10%

updated 2026-08-04T14:27:12.530000

3 posts

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

3 repos

https://github.com/Yash-Dalvee/stormencryptor-ncentral-defense

https://github.com/CreamyG31337/ncentral-compromise-ioc-triage

https://github.com/HORKimhab/CVE-2026-18577

blog@insicurezzadigitale.com at 2026-08-11T12:21:10.000Z ##

StormEncryptor: come l’ex affiliato Medusa Storm-1175 ha trasformato N-central in un launchpad ransomware

Microsoft attribuisce a Storm-1175, gruppo legato alla Cina e già affiliato Medusa, lo sfruttamento della falla CVE-2026-18577 in N-able N-central per distribuire il nuovo ransomware StormEncryptor a cascata su decine di MSP e relativi clienti.

insicurezzadigitale.com/storme

##

security_crawler_carl@infosec.exchange at 2026-08-11T04:22:58.000Z ##

Like a fighting-game boss mid-match suddenly swapping movesets, it exploited CVE-2026-18577, an authentication-bypass zero-day in N-able's N-central RMM tool, to get inside.

N-able dropped a hotfix on August 2 — patch to build 2026.3.1.7 immediately, and hunt for rogue svchost.exe files in user Documents folders, a Cloudflared service, or suspicious inbound connections listed in the advisory.

Reward: You've received the Cursed Badge of the Late Patcher — equip it at your peril. (2/2)

##

cyberworldops@infosec.exchange at 2026-08-10T14:20:00.000Z ##

Storm-1175, a China-nexus financially motivated threat actor, is distributing the StormEncryptor ransomware by exploiting a critical zero-day in ConnectWise N-central (CVE-2026-18577). First exploitation was detected July 31, with ransomware deployment beginning August 2. Targeting MSPs amplifies downstream impact across hundreds of managed clients.

#Storm1175 #Ransomware #Ncentral #MSPSecurity

cyberworldops.eu/en/storm-1175

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 1.14%

updated 2026-07-30T16:17:15.183000

4 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

netsecio@mastodon.social at 2026-08-12T15:06:48.000Z ##

📰 VMware Patches Critical VM Escape Flaw (CVE-2026-47876) in ESXi

Broadcom patches critical VMware flaws, including a VM escape in ESXi (CVE-2026-47876) and unauthenticated RCE in vCenter (CVE-2026-59309, CVE-2026-59310). CVSS scores up to 9.8. Immediate patching is crucial. #VMware #CyberSecurity #PatchTuesday

🔗 cyber.netsecops.io/articles/vm

##

undercodenews@mastodon.social at 2026-08-12T12:34:48.000Z ##

VMware vCenter Under Attack: Critical CVE-2026-59310 Exploited in a Rapid Global Intrusion Campaign + Video

A New Warning for Virtualization Administrators Virtualization infrastructure has quietly become one of the most valuable targets in modern cyberattacks. A compromised workstation can expose one user or one endpoint, but a compromised virtualization-management server can potentially open a path toward dozens, hundreds, or even thousands of workloads. That is why…

undercodenews.com/vmware-vcent

##

jbhall56 at 2026-08-12T12:03:53.426Z ##

The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. thehackernews.com/2026/08/atta

##

jbhall56@infosec.exchange at 2026-08-12T12:03:53.000Z ##

The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. thehackernews.com/2026/08/atta

##

CVE-2026-59309
(9.8 CRITICAL)

EPSS: 0.74%

updated 2026-07-30T16:17:15.073000

1 posts

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

netsecio@mastodon.social at 2026-08-12T15:06:48.000Z ##

📰 VMware Patches Critical VM Escape Flaw (CVE-2026-47876) in ESXi

Broadcom patches critical VMware flaws, including a VM escape in ESXi (CVE-2026-47876) and unauthenticated RCE in vCenter (CVE-2026-59309, CVE-2026-59310). CVSS scores up to 9.8. Immediate patching is crucial. #VMware #CyberSecurity #PatchTuesday

🔗 cyber.netsecops.io/articles/vm

##

CVE-2026-47876
(9.3 CRITICAL)

EPSS: 0.28%

updated 2026-07-30T14:16:58.467000

1 posts

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

netsecio@mastodon.social at 2026-08-12T15:06:48.000Z ##

📰 VMware Patches Critical VM Escape Flaw (CVE-2026-47876) in ESXi

Broadcom patches critical VMware flaws, including a VM escape in ESXi (CVE-2026-47876) and unauthenticated RCE in vCenter (CVE-2026-59309, CVE-2026-59310). CVSS scores up to 9.8. Immediate patching is crucial. #VMware #CyberSecurity #PatchTuesday

🔗 cyber.netsecops.io/articles/vm

##

CVE-2026-64560
(7.8 HIGH)

EPSS: 0.12%

updated 2026-07-30T12:19:03.630000

2 posts

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sys_timer_delete() exec() posix_cpu_timer_del() // Observes old leader p = pid_task(pid, pid_type); de_thread() switch_leader(); release

1 repos

https://github.com/villager1314/CVE-2026-64560-Analysis

DailyCyberSecurity at 2026-08-12T01:02:34.386Z ##

CVE-2026-64560: Linux Kernel CPU Timer Use-After-Free Gives a Root Shell, PoC Exploit Code Publicly Disclosed

securityonline.info/linux-kern

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T01:02:34.000Z ##

CVE-2026-64560: Linux Kernel CPU Timer Use-After-Free Gives a Root Shell, PoC Exploit Code Publicly Disclosed

securityonline.info/linux-kern

##

CVE-2026-64747
(7.8 HIGH)

EPSS: 0.14%

updated 2026-07-28T15:32:12

2 posts

A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to execute arbitrary code with kernel privileges.

1 repos

https://github.com/jiuyi155/agxprobe

Mndell@mastodon.social at 2026-08-12T05:57:41.000Z ##

@jurjen_heeck @malwaretech it might be not so much agentic yet. There is however a growing number of CVE’s with AI, like CVE-2026-64747 and the early release by Apple recently of multiple fixes as a result reuters.com/business/apple-say

##

Mndell@mastodon.social at 2026-08-12T05:57:41.000Z ##

@jurjen_heeck @malwaretech it might be not so much agentic yet. There is however a growing number of CVE’s with AI, like CVE-2026-64747 and the early release by Apple recently of multiple fixes as a result reuters.com/business/apple-say

##

CVE-2026-45659
(8.8 HIGH)

EPSS: 9.12%

updated 2026-07-23T11:10:00.120000

2 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

2 repos

https://github.com/WismanSec/sharepoint-2026-poc

https://github.com/HORKimhab/CVE-2026-45659

cyberworldops@infosec.exchange at 2026-08-11T16:10:00.000Z ##

CISA has confirmed active ransomware exploitation of CVE-2026-45659, a remote code execution flaw in Microsoft SharePoint. The vulnerability was added to the Known Exploited Vulnerabilities catalog on July 1st with a mandatory 3-day remediation deadline for federal agencies.

#SharePoint #Ransomware #CISA #CVE202645659

cyberworldops.eu/en/sharepoint

##

kev_Stalker@infosec.exchange at 2026-08-11T09:26:34.000Z ##

CVE-2026-45659 - Changed to Known Ransomware Status

Microsoft SharePoint Server Deserialization of Untrusted Data VulnerabilityVendor: MicrosoftProduct: SharePoint ServerMicrosoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 10, 2026 at 17:08:17 UTCDate nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-63030
(9.8 CRITICAL)

EPSS: 95.60%

updated 2026-07-22T23:10:00.110000

1 posts

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

81 repos

https://github.com/rechandra/wp2exp-2026

https://github.com/0xBlackash/CVE-2026-63030

https://github.com/Ch4120N/CVE-2026-63030

https://github.com/47Cid/wp2shell-lab

https://github.com/Iqbalx7/wp2shell

https://github.com/kulichr/wp2shell

https://github.com/NULL200OK/WP2Shell

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/Lutfifakee-Project/wp2shell

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/imXur/WordPress-CVE-2026-63030-Analysis

https://github.com/shinthink/CVE-2026-63030

https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/ekomsSavior/wp2shell

https://github.com/CybersecSpirit/CVE-2026-63030

https://github.com/fullhunt/wp2shell-scan

https://github.com/mcipekci/wp2shell

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/minwunn/wp2shell-CVE-2026-63030

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/ebrasha/abdal-cve-2026-63030

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/TomorrowX6/CVE-2026-63030-poc

https://github.com/g0d150ne/WP2Shell

https://github.com/Crypto-Cat/wp2shell

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/x-znn/CVE-2026-63030

https://github.com/administrator-01001/CVE-2026-63030

https://github.com/johnlodan/wp2shell-rce

https://github.com/0xjessie21/wp2shell-checker

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/0xsha/wp2shell

https://github.com/c0gnit00/Wp2Shell

https://github.com/vulnquest58/PressVector

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/Procjevt/CVE-2026-63030

https://github.com/h4cd0c/wp2shell

https://github.com/yuag/wp2shell

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/ikow/wp2shell

https://github.com/gbrsh/CVE-2026-63030

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/attackercan/wp2shell-poc2

https://github.com/bahartanir/wp2shell-scanner

https://github.com/ChiefYoru/CVE-2026-63030_PoC

https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2026-63030-WP2Shell

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/0xWhoknows/wp2shell

https://github.com/ananay/wp2shell-lab

https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause

https://github.com/mverschu/CVE-2026-63030

https://github.com/securelayer7/WordPresShell

https://github.com/ZenithGenius/wordpress-batch-rce-lab

https://github.com/4B3R4M4-607D/CVE-2026-63030-POC

https://github.com/dinosn/wp2shell-lab

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t

https://github.com/AnggaTechI/CVE-2026-63030

https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030

https://github.com/raphy76/wp2shell-poc-fulljs

https://github.com/Icex0/wp2shell-poc

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/M4xSec/wp2shell-Exploit-Waf-Bypass

https://github.com/michael-kanda/Wp2shell-ioc-scanner

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/zi3lak/wp2shell_scanner

https://github.com/mrx-arafat/CVE-2026-63030-POC

https://github.com/mhtsec/CVE-2026-63030

https://github.com/4minx/CVE-2026-63030

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/0xh7ml/CVE-2026-63030

https://github.com/zeroc00I/CVE-2026-63030

https://github.com/InstaWP/wp2shell-scan

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/sowarma/wp2shell-PoC

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

bstnbuck@infosec.exchange at 2026-08-10T12:30:00.000Z ##

A #Wordpress site belonging to an friend (I’m not the admin...) was successfully hacked using #wp2shell (17.07.2026; CVE-2026-63030 + CVE-2026-60137), just 5 days after the first exploit published (20.07.). Another 5 days later, the website was abused for SEO spamming and for hosting phishing…

If you haven't already, update your Wordpress (preferably yesterday…; >=v7.0.2 or >= 6.9.5) and also enable automatic updates for themes and plug-ins!

I found several PHP backdoors/webshells (see @abuse_ch Malware Bazaar and #VirusTotal (hashes below)). Interestingly, not every sample was detected by the #YARA rules from @cyb3rops and github.com/ruppde/yara_rules.

tl;dr #wp2shell is being actively exploited, patch immediately and enable automatic updates.

Hashes:
1093b4045b45a8498d146e31788c25769f992056c8ffc582b5d8c06598598966
05e3884a478d3bc8fd7285dabb74107422f1615d2d7f80df9b8438d4beb663da
bb9136494a546368e7c9b6252c2e1c5af9327c07947908a9ba6fdd78fb4bf4cf
1e7ca9074cc2eca8d366022629f665d9ffaa79e0621bb579bf5aabe681cb07e8
8ebaf3ba0be7b62269aaf333cfaf66c1dea6e8ee495a917691beb550b4bbf0ab
e3fb920aa70c7ad5c67b4d9b8e60954f5e0c1a07c0eba09505816b966f4d1a3c
165e94c87ef17389c8de25ba2a6c31b348e3c916dab89d0dd3708156414f3de5
b55cf5af8b57e9d56c69d00e023e2384c7eb184614c2a2a283062ebeaf4a26c6
a46230a1638b9b341d15a640ead1b885548c1d1e5a149657e8e315540a068be8
7918f29993383e579ef33bd0d8e766fd2ce047dce83bac51efb5fe17578b6cdf
ae9ee9db7c41e04c531298782b908766c769a899aa92df3f64f4a83baa77ad09

##

CVE-2026-53360
(8.8 HIGH)

EPSS: 0.18%

updated 2026-07-22T21:32:53

2 posts

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use As per the GHCB spec, when using GHCB v2+ require the software scratch area to reside in the GHCB's shared buffer. Note, things like Page State Change (PSC) requests _rely_ on this behavior, as the guest can't provide a length when making the request, i.e. the size of

1 repos

https://github.com/0xCyberstan/CVE-2026-53360-POC

CVE-2026-53361
(7.1 HIGH)

EPSS: 0.13%

updated 2026-07-22T19:07:32.853000

3 posts

In the Linux kernel, the following vulnerability has been resolved: af_unix: Set gc_in_progress to true in unix_gc(). Igor Ushakov reported that unix_gc() could run with gc_in_progress being false if the work is scheduled while running: Thread 1 Thread 2 Thread 3 -------- -------- -------- unix_schedule_gc()

1 repos

https://github.com/sgkdev/bad_garbage

sayzard@mastodon.sayzard.org at 2026-08-12T07:41:56.000Z ##

CVE-2026-53361 AF_Unix GC vs. MSG_PEEK use-after-free container escape

공개 PoC 저장소는 Linux 커널 AF_UNIX 소켓 가비지 컬렉터와 `MSG_PEEK`의 경쟁 조건으로 발생하는 use-after-free(CVE-2026-53361)를 이용해 비권한 사용자 권한 상승 및 컨테이너 탈출이 가능하다고 주장합니다. 핵심은 GC가 순환 참조 소켓을 수집하는 동안 `MSG_PEEK`가 획득한 참조를 정확히 반영하지 못해, 살아 있는 소켓과 연결된 `sk_buff`가 해제되는 문제입니다. 저장소는 Debian trixie, RHEL/CentOS Stream 10, Ubuntu 24.04 HWE 등의 특정 커널 빌드가 영향을 받는다고 열거하며, Linux 6...

github.com/sgkdev/bad_garbage

##

CuratedHackerNews@mastodon.social at 2026-08-12T06:39:04.000Z ##

CVE-2026-53361 AF_Unix GC vs. MSG_PEEK use-after-free container escape

github.com/sgkdev/bad_garbage

#github

##

CuratedHackerNews@mastodon.social at 2026-08-12T06:39:04.000Z ##

CVE-2026-53361 AF_Unix GC vs. MSG_PEEK use-after-free container escape

github.com/sgkdev/bad_garbage

#github

##

CVE-2026-59765(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-07-21T21:55:32

2 posts

### Summary Gitea has robust SSRF protection via `hostmatcher.NewDialContext()` for webhook and migration clone URLs, which validates resolved IPs at the TCP dial level. However, three code paths use raw `http.Get()` (Go's `DefaultClient`) which completely bypasses this protection, enabling SSRF to internal services and local file read via the `file://` scheme. ### Vulnerable Code **File: `modu

nyanbinary@infosec.exchange at 2026-08-11T16:58:40.000Z ##

wait, the CVE-2026-59765 doesn't exist? wtf

##

nyanbinary@infosec.exchange at 2026-08-11T16:58:03.000Z ##

ACTUALLY...

CVE-2026-34966 -> github.com/go-gitea/gitea/secu -> CVE-2026-59765

... did they double assign without retraction?

##

CVE-2026-55040
(9.1 CRITICAL)

EPSS: 1.63%

updated 2026-07-14T18:32:38

12 posts

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

2 repos

https://github.com/sfewer-r7/CVE-2026-55040

https://github.com/l0ggg/CVE-2026-55040

undercodenews@mastodon.social at 2026-08-12T13:04:33.000Z ##

Microsoft SharePoint Under Attack: Critical JWT Authentication Flaw Exploited After Rapid7 Releases Public PoC

A Dangerous SharePoint Vulnerability Has Crossed a Critical Line Microsoft SharePoint administrators are facing another serious cybersecurity warning after a critical authentication-bypass vulnerability moved rapidly from public disclosure to observed exploitation. The flaw, tracked as CVE-2026-55040, affects the way SharePoint validates JSON Web Tokens (JWTs)…

undercodenews.com/microsoft-sh

##

jbhall56 at 2026-08-12T12:48:27.512Z ##

Tracked as CVE-2026-55040, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator. bleepingcomputer.com/news/micr

##

Analyst207@mastodon.social at 2026-08-12T12:31:45.000Z ##

Hackers Exploit New Microsoft SharePoint Vulnerability in Attacks

Hackers are already exploiting a newly discovered critical flaw in Microsoft SharePoint, with over 8,500 servers exposed online and vulnerable to attacks. This authentication bypass vulnerability, known as CVE-2026-55040, allows hackers to disclose files, modify data, and wreak havoc on your system.

osintsights.com/hackers-exploi

#MicrosoftSharepoint #Cve202655040 #AuthenticationBypass #VulnerabilityExploitation #EmergingThreats

##

cyberworldops at 2026-08-12T06:20:01.341Z ##

Researchers disclosed a full unauthenticated RCE chain in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS 9.1). The flaw in the authentication pipeline allows an attacker to impersonate any user, including admins, using only the target's AD SID or UPN. No credentials required.

cyberworldops.eu/en/sharepoint

##

DailyCyberSecurity at 2026-08-12T06:14:46.899Z ##

Rapid7 published full details and a PoC for CVE-2026-55040, a critical SharePoint authentication bypass that forges JWT tokens. Patch now.

securityonline.info/sharepoint

##

ottoto2017@prattohome.com at 2026-08-12T04:55:06.000Z ##

「研究者らが、認証不要のリモートコード実行(RCE)を実現するAI支援型SharePointエクスプロイトチェーンを公開 」: #TheHackerNews

「セキュリティ研究者らは、有効なアカウントを持たずに、管理者を含むあらゆるユーザーとしてMicrosoft SharePointサーバーに侵入する方法を発見した。この発見に大きく貢献したのが、AIエージェントを用いた作業だった。

CVE-2026-55040 (CVSS 9.1)として追跡されているこの脆弱性は 、SharePoint Server Subscription Edition、SharePoint Server 2019、およびSharePoint Server 2016に影響します。マイクロソフトの影響を受ける製品リストには、これら3つのオンプレミス版のみが含まれており、SharePoint Onlineは含まれていません。

この攻撃手法は、認証されていないリモート攻撃者が、選択したユーザーの身元を偽装することを可能にします。 」

thehackernews.com/2026/08/rese

#prattohome

##

jbhall56@infosec.exchange at 2026-08-12T12:48:27.000Z ##

Tracked as CVE-2026-55040, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator. bleepingcomputer.com/news/micr

##

cyberworldops@infosec.exchange at 2026-08-12T06:20:01.000Z ##

Researchers disclosed a full unauthenticated RCE chain in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS 9.1). The flaw in the authentication pipeline allows an attacker to impersonate any user, including admins, using only the target's AD SID or UPN. No credentials required.

#SharePointRCE #UnauthenticatedExploit #CVE2026 #CriticalVulnerability

cyberworldops.eu/en/sharepoint

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T06:14:46.000Z ##

Rapid7 published full details and a PoC for CVE-2026-55040, a critical SharePoint authentication bypass that forges JWT tokens. Patch now.

#CVE202655040 #SharePoint #AuthenticationBypass #JWT #Rapid7 #PoC #Cybersecurity

securityonline.info/sharepoint

##

ottoto2017@prattohome.com at 2026-08-12T04:55:06.000Z ##

「研究者らが、認証不要のリモートコード実行(RCE)を実現するAI支援型SharePointエクスプロイトチェーンを公開 」: #TheHackerNews

「セキュリティ研究者らは、有効なアカウントを持たずに、管理者を含むあらゆるユーザーとしてMicrosoft SharePointサーバーに侵入する方法を発見した。この発見に大きく貢献したのが、AIエージェントを用いた作業だった。

CVE-2026-55040 (CVSS 9.1)として追跡されているこの脆弱性は 、SharePoint Server Subscription Edition、SharePoint Server 2019、およびSharePoint Server 2016に影響します。マイクロソフトの影響を受ける製品リストには、これら3つのオンプレミス版のみが含まれており、SharePoint Onlineは含まれていません。

この攻撃手法は、認証されていないリモート攻撃者が、選択したユーザーの身元を偽装することを可能にします。 」

thehackernews.com/2026/08/rese

#prattohome

##

AAKL@infosec.exchange at 2026-08-11T17:25:10.000Z ##

New.

Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) rapid7.com/blog/post/ra-micros @Rapid7Official #Microsoft #infosec #threatresearch #SharePoint #vulnerability

##

obivan@infosec.exchange at 2026-08-11T13:37:38.000Z ##

Microsoft SharePoint JWT Authentication Bypass (CVE-2026-55040) github.com/sfewer-r7/CVE-2026-

##

CVE-2026-31431
(7.8 HIGH)

EPSS: 99.91%

updated 2026-07-14T15:32:55

1 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just

100 repos

https://github.com/diemoeve/copyfail-rs

https://github.com/0xShe/CVE-2026-31431

https://github.com/MrAriaNet/cPanel-Fix

https://github.com/badsectorlabs/copyfail-go

https://github.com/kadir/copy-fail-CVE-2026-31431-IOC

https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431

https://github.com/Boos4721/copyfail-rs

https://github.com/novysodope/copy-fail-CVE-2026-31431-C

https://github.com/jbnetwork-git/copy-fail-check

https://github.com/sgkdev/page_inject

https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit

https://github.com/st4rburn/public-passwd

https://github.com/bootsareme/copyfail-deconstructed

https://github.com/TheMalwareGuardian/CVE-2026-31431

https://github.com/Dabbleam/CVE-2026-31431-mitigation

https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell

https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431

https://github.com/wuwu001/CVE-2026-31431-exploit

https://github.com/rootsecdev/cve_2026_31431

https://github.com/kinryulabs/rootpacket-cve-2026-31431

https://github.com/luotian2/CVE-2026-31431

https://github.com/Smarttfoxx/copyfail

https://github.com/JnamerZ/CopyFail-CVE-2026-31431

https://github.com/SeanRickerd/cve-2026-31431

https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431

https://github.com/ExploitEoom/CVE-2026-31431

https://github.com/adysec/cve-2026-31431

https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation

https://github.com/povzayd/CVE-2026-31431

https://github.com/cyber-joker/copy-fail-python

https://github.com/gagaltotal/cve-2026-31431-copy-fail

https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail

https://github.com/XsanFlip/CVE-2026-31431-Patch

https://github.com/ErdemOzgen/copy-fail-cve-2026-31431

https://github.com/b5null/CVE-2026-31431-C

https://github.com/sec17br/CVE-2026-31431-Copy-Fail

https://github.com/erlangparasu/mitigate_cve_2026_31431-sh

https://github.com/mrunalp/block-copyfail

https://github.com/Xerxes-2/CVE-2026-31431-rs

https://github.com/Alfredooe/CVE-2026-31431

https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized

https://github.com/0xBlackash/CVE-2026-31431

https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

https://github.com/bigwario/copy-fail-CVE-2026-31431-C

https://github.com/malwarekid/CVE-2026-31431

https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite

https://github.com/atgreen/block-copyfail

https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit

https://github.com/sgkdev/ptrace_may_dream

https://github.com/cs8425/copy-fail-go

https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

https://github.com/kvakirsanov/CVE-2026-31431-live-process-code-injection

https://github.com/abdullaabdullazade/CVE-2026-31431

https://github.com/pedromizz/copy-fail

https://github.com/qi4L/CVE-2026-31431-Container-Escape

https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit

https://github.com/xeloxa/copyfail-exploit

https://github.com/JuanBindez/CVE-2026-31431

https://github.com/Sl4cK0TH/CVE-2026-31431-PoC

https://github.com/ZephrFish/CopyFail-CVE-2026-31431

https://github.com/MartinPham/copy-fail-CVE-2026-31431-php

https://github.com/Iamliuxiaozhen/copy_fail

https://github.com/insomnisec/Detections-CVE-2026-31431

https://github.com/sammwyy/copyfail-rs

https://github.com/yuspring/cve-2026-31431-poc

https://github.com/desultory/CVE-2026-31431

https://github.com/aestechno/cve-2026-31431-ansible

https://github.com/philfry/cve-2026-31431-ftrace

https://github.com/guiimoraes/CVE-2026-31431

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC

https://github.com/lonelyor/CVE-2026-31431-exp

https://github.com/haydenjames/CVE-2026-31431-check

https://github.com/rvzsec/CVE-2026-31431

https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape

https://github.com/Huchangzhi/autorootlinux

https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/theori-io/copy-fail-CVE-2026-31431

https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs

https://github.com/Qengineering/RK35xx-CopyFail-Hotfix

https://github.com/pascal-gujer/CVE-2026-31431

https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE

https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script

https://github.com/AdityaBhatt3010/CVE-2026-31431

https://github.com/ncmprbll/copy-fail-rs

https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431

https://github.com/4xura/CVE-2026-31431-Copy-Fail

https://github.com/cozystack/copy-fail-blocker

https://github.com/wgnet/wg.copyfail.patch

https://github.com/wesmar/CVE-2026-31431

https://github.com/tgies/copy-fail-c

https://github.com/Juguitos/copy-fail

https://github.com/samanzamani/copy-fail-checker

https://github.com/AliHzSec/CVE-2026-31431

https://github.com/ben-slates/CVE-2026-31431-Exploit

sigint@fosstodon.org at 2026-08-11T23:45:08.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-08-12

A 732-byte script reportedly roots any Linux since 2017 via a logic flaw, not memory corruption. If accurate this hits every homelab box and container host regardless of distro. Patch fast, verify your kernel version against the advisory.

🔗 bugcrowd.com/blog/what-we-know

#Ubuntu #Linux #infosec

##

CVE-2026-12879(CVSS UNKNOWN)

EPSS: 0.19%

updated 2026-07-09T15:32:33

1 posts

An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data. This vulnerability was patched on 12 June 2026 on the Apigee Servers, and no customer action is needed.

AAKL@infosec.exchange at 2026-08-11T17:11:08.000Z ##

Broadcom has several new advisories that include two critical vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

CISA:

Industrial vulnerability: Johnson Controls C-CURE 9000 and Victor application server (Update A) cisa.gov/news-events/ics-advis

Blog post: Cyber Storm X: 20 Years of Readiness, Resilience, and Real‑World Impact cisa.gov/news-events/news/cybe #CISA

Cisco:

High-severity: CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco

Yesterday:

Tenable Research Advisories:

Medium-severity: CVE-2026-12879: Google Cloud Platform (GCP) Apigee Cross-Tenant Data Exfiltration via Confused Deputy tenable.com/security/research/ #infosec #Google #vulnerability

##

CVE-2026-50656
(7.8 HIGH)

EPSS: 10.75%

updated 2026-07-09T00:17:26.607000

8 posts

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;RoguePlanet &quot;.

3 repos

https://github.com/0xBlackash/CVE-2026-50656

https://github.com/HORKimhab/CVE-2026-50656

https://github.com/g0thamRabb1t/CVE-2026-50656-rogueplanet-validation

cyberworldops at 2026-08-12T08:10:01.208Z ##

A proof-of-concept for ShieldBreak has been disclosed, showing how to bypass the patch Microsoft issued for CVE-2026-50656 (RoguePlanet). The flaw targets SYSTEM-level privilege escalation on Windows systems protected by Microsoft Defender.

cyberworldops.eu/en/shieldbrea

##

teezeh@ieji.de at 2026-08-12T05:27:04.000Z ##

„Microsoft hat mit dem August 2026-Patchday zwar einige Sicherheitskorrekturen ausgeliefert. Aber die RoguePlanet genannte Schwachstelle (CVE-2026-50656) soll nicht ausreichend abgeschwächt worden sein. Der als Nightmare Eclipse agierende Sicherheitsforscher hat einen ShieldBreak genannten Proof of Concept (PoC) veröffentlicht.“

borncity.com/blog/2026/08/12/s

##

DailyCyberSecurity at 2026-08-12T04:24:39.796Z ##

A public PoC named ShieldBreak bypasses Microsoft's CVE-2026-50656 patch, enabling Windows Defender privilege escalation to SYSTEM.

securityonline.info/shieldbrea

##

cyberworldops@infosec.exchange at 2026-08-12T08:10:01.000Z ##

A proof-of-concept for ShieldBreak has been disclosed, showing how to bypass the patch Microsoft issued for CVE-2026-50656 (RoguePlanet). The flaw targets SYSTEM-level privilege escalation on Windows systems protected by Microsoft Defender.

#ShieldBreak #CVE202650656 #PrivilegeEscalation #MicrosoftDefender

cyberworldops.eu/en/shieldbrea

##

teezeh@ieji.de at 2026-08-12T05:27:04.000Z ##

„Microsoft hat mit dem August 2026-Patchday zwar einige Sicherheitskorrekturen ausgeliefert. Aber die RoguePlanet genannte Schwachstelle (CVE-2026-50656) soll nicht ausreichend abgeschwächt worden sein. Der als Nightmare Eclipse agierende Sicherheitsforscher hat einen ShieldBreak genannten Proof of Concept (PoC) veröffentlicht.“

borncity.com/blog/2026/08/12/s

##

DailyCyberSecurity@infosec.exchange at 2026-08-12T04:24:39.000Z ##

A public PoC named ShieldBreak bypasses Microsoft's CVE-2026-50656 patch, enabling Windows Defender privilege escalation to SYSTEM.

#ShieldBreak #CVE202650656 #WindowsDefender #PrivilegeEscalation #PoC #RoguePlanet #Cybersecurity

securityonline.info/shieldbrea

##

AmmarSpaces@infosec.exchange at 2026-08-11T21:36:43.000Z ##

On another news NightmareEclipse (the goat?) returned with a new PoC, after Microsoft failed to fully patch RoguePlanet (CVE-2026-50656), the current PoC only made for latest Windows 11 release, but they said that Windows 10 also still vulnerable. And yeah, it works even after the latest update

github.com/MSNightmare/ShieldB

#cybersecurity #infosec #zeroday #vulnerability #windows #nightmareEclipse

##

DarkWebInformer@infosec.exchange at 2026-08-11T19:57:18.000Z ##

🚨Nightmare Eclipse has released a new zero-day PoC called ShieldBreak

Per the security researcher: "Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass."

GitHub: github.com/MSNightmare/ShieldB

##

CVE-1999-1587
(0 None)

EPSS: 0.95%

updated 2026-06-16T21:50:46.783000

1 posts

/usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option.

raptor@infosec.exchange at 2026-08-11T09:06:33.000Z ##

Finally, to close out our short #GitHub tour, a few vintage repositories 🍷 that have aged into historical curiosities and are now (mostly) harmless. Still worth a look as a learning resource, for humans and AI alike 🤖

github.com/0xdea/exploits - a collection of my public exploits from CVE-1999-1587 onwards
github.com/0xdea/shellcode - a small collection of my shellcode samples
github.com/0xdea/advisories - my public advisories starting from CAN-2003-0190, err..., CVE-2003-0190 up until today

Thanks for following along, and enjoy your summer break! ☀️

##

CVE-2026-34486
(7.5 HIGH)

EPSS: 82.93%

updated 2026-06-08T23:28:56

1 posts

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

Nuclei template

6 repos

https://github.com/404-src/CVE-2026-34486

https://github.com/razureink/cve-2026-34486-tomcat_encrypt_bypass_reproduction

https://github.com/punitdarji/tomcat-cve-2026-34486

https://github.com/striga-ai/CVE-2026-34486

https://github.com/anonmrc/CVE-2026-34486-e-Tomcat-Tribes

https://github.com/AirSkye/CVE-2026-34486-poc

thecybermind@infosec.exchange at 2026-08-10T18:21:57.000Z ##

🚨 CRITICAL THREAT ALERT: CVE-2026-34486 in Apache Tomcat is under active CISA KEV exploitation. Missing encryption allows intercept of sensitive corporate data. Review our strategic C-Suite brief on technical vectors, persistence checks, and endpoint hardening to protect your data streams. thecybermind.co/6dk1

##

CVE-2026-43074
(7.8 HIGH)

EPSS: 0.48%

updated 2026-06-01T18:32:35

1 posts

In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace period In certain situations, ep_free() in eventpoll.c will kfree the epi->ep eventpoll struct while it still being used by another concurrent thread. Defer the kfree() to an RCU callback to prevent UAF.

1 repos

https://github.com/PeronGH/badepoll-selinux-disabler

DailyCyberSecurity@infosec.exchange at 2026-08-10T12:56:45.000Z ##

CVE-2026-43074: Linux Kernel eventpoll Use-After-Free Gives a Root Shell, PoC Exploit Code Publicly Disclosed

securityonline.info/linux-kern

##

CVE-2026-48048
(7.5 HIGH)

EPSS: 0.36%

updated 2026-05-26T20:17:03

1 posts

### Impact XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient and with slightly modified parameters to the `LiveTableResults`, it is still possible to discover password hashes one bit at a time, so with 768 requests, the full password salt and hash can be retrieved of a user. ### Patches The check for password (and email properties) has been adjusted in XWiki 18.0.0RC1, 17.1

thehackerwire@mastodon.social at 2026-08-10T17:00:34.000Z ##

🟠 CVE-2026-48048 - High (7.5)

XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17, with slightly modified parameters to t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-46670
(9.8 CRITICAL)

EPSS: 1.65%

updated 2026-05-22T15:39:07

1 posts

### Summary An unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an `INSERT` statement and read the full database, including `yeswiki_users.password` hashes. Present in 4.6.1 / 4.6.2 / current `doryphore-dev`; analyzed against upstream commit `1f485c049db030b94c047ec219

Nuclei template

Matchbook3469@mastodon.social at 2026-08-12T08:02:20.000Z ##

🔴 New security advisory:

CVE-2026-46670 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#InfoSec #SecurityPatching #HackerNews

##

CVE-2026-27912
(8.0 HIGH)

EPSS: 0.24%

updated 2026-04-14T18:30:50

1 posts

Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.

2 repos

https://github.com/Semperis-Community/ResetNightmare

https://github.com/mihat2/ResetNightmare-impacket

CVE-2003-0190(CVSS UNKNOWN)

EPSS: 76.75%

updated 2026-03-22T05:08:29

1 posts

OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.

raptor@infosec.exchange at 2026-08-11T09:06:33.000Z ##

Finally, to close out our short #GitHub tour, a few vintage repositories 🍷 that have aged into historical curiosities and are now (mostly) harmless. Still worth a look as a learning resource, for humans and AI alike 🤖

github.com/0xdea/exploits - a collection of my public exploits from CVE-1999-1587 onwards
github.com/0xdea/shellcode - a small collection of my shellcode samples
github.com/0xdea/advisories - my public advisories starting from CAN-2003-0190, err..., CVE-2003-0190 up until today

Thanks for following along, and enjoy your summer break! ☀️

##

CVE-2026-22185(CVSS UNKNOWN)

EPSS: 0.13%

updated 2026-01-08T18:31:46

2 posts

OpenLDAP Lightning Memory-Mapped Database (LMDB) mdb_load contains a heap buffer underflow vulnerability in the readline() function. When processing malformed input, an unsigned offset calculation can underflow a heap pointer, resulting in an out-of-bounds read of one byte before the allocated heap buffer. This may allow a local attacker to cause a denial of service and potentially disclose limite

hyc@mastodon.social at 2026-08-12T11:57:12.000Z ##

As an example of how ridiculous the CVE ecosystem has become... researchers claimed a CVE this year against an LMDB commandline tool (not a server) for a bug fixed in 0.9.15, which was released 2015-06-19 - eleven years ago.

openeuler.org/zh/security/cve/

##

hyc@mastodon.social at 2026-08-12T11:57:12.000Z ##

As an example of how ridiculous the CVE ecosystem has become... researchers claimed a CVE this year against an LMDB commandline tool (not a server) for a bug fixed in 0.9.15, which was released 2015-06-19 - eleven years ago.

openeuler.org/zh/security/cve/

##

CVE-2025-7771(CVSS UNKNOWN)

EPSS: 6.83%

updated 2025-08-06T12:31:25

1 posts

ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function. This insecure implementation can be exploited by a malicious user-mode application to patch the running Windows kernel and invoke arbitrary kernel functions with ring-0 privileges. The vulnerability enables local attackers to execute arbit

12 repos

https://github.com/Gabriel-Lacorte/CVE-2025-7771

https://github.com/AmrHuss/throttlestop-exploit-rw

https://github.com/enessakircolak/CVE-2025-7771

https://github.com/Demoo1337/ThrottleStop

https://github.com/D4rkks/CVE-2025-7771-Vulnerability-Exploration

https://github.com/fxrstor/ThrottleStopPoC

https://github.com/mein-0/cve-2025-7771

https://github.com/xM0kht4r/CVE-2025-7771

https://github.com/I3r1h0n/Sigurd

https://github.com/v31l0x1/ThrottleStopPPL

https://github.com/DeathShotXD/0xKern3lCrush

https://github.com/lzty/CVE-2025-7771

obivan@infosec.exchange at 2026-08-11T15:13:19.000Z ##

CVE-2025-7771 — ThrottleStop.sys Arbitrary Physical Memory R/W github.com/enessakircolak/CVE-

##

CVE-2026-26035
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T14:00:13.000Z ##

🔴 CVE-2026-26035 - Critical (9.8)

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T14:00:13.000Z ##

🔴 CVE-2026-26035 - Critical (9.8)

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70468
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T14:00:02.000Z ##

🟠 CVE-2026-70468 - High (8.1)

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiMan...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T14:00:02.000Z ##

🟠 CVE-2026-70468 - High (8.1)

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiMan...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

undercodenews@mastodon.social at 2026-08-12T13:25:58.000Z ##

Metabase Hit by a Critical Zero-Day: CVE-2026-72898 Puts Business Intelligence Data at Risk

Introduction: When the Analytics Layer Becomes the Attack Path Metabase is often treated as the quiet engine behind dashboards, reports, business intelligence, and data-driven decision-making. It may not be the system employees think about every morning, but behind those charts and dashboards can sit connections to production databases, cloud warehouses, customer records,…

undercodenews.com/metabase-hit

##

thecybermind at 2026-08-12T11:45:00.075Z ##

🚨 CRITICAL THREAT: CISA adds CVE-2026-72898 (Metabase SQL Injection) to the KEV catalog due to active exploitation. Unauthenticated attackers can hijack admin rights and steal database credentials. Full TSUITE brief with SPL, KQL, AQL & YARA-L: thecybermind.co/jily

##

thecybermind@infosec.exchange at 2026-08-12T11:45:00.000Z ##

🚨 CRITICAL THREAT: CISA adds CVE-2026-72898 (Metabase SQL Injection) to the KEV catalog due to active exploitation. Unauthenticated attackers can hijack admin rights and steal database credentials. Full TSUITE brief with SPL, KQL, AQL & YARA-L: thecybermind.co/jily

#CyberSecurity

##

secdb@infosec.exchange at 2026-08-11T21:00:13.000Z ##

🚨 [CISA-2026:0811] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-20349 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-68820 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows Ancillary Function Driver for WinSock
- Notes: portal.msrc.microsoft.com/en-U ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-72898 (secdb.nttzen.cloud/cve/detail/)
- Name: Metabase SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Metabase
- Product: Metabase
- Notes: metabase.com/blog/security-upd ; github.com/metabase/metabase/s ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260811 #cisa20260811 #cve_2026_20349 #cve_2026_68820 #cve_2026_72898 #cve202620349 #cve202668820 #cve202672898

##

cisakevtracker@mastodon.social at 2026-08-11T20:01:25.000Z ##

CVE ID: CVE-2026-72898
Vendor: Metabase
Product: Metabase
Date Added: 2026-08-11
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-73225
(0 None)

EPSS: 0.31%

2 posts

N/A

hugovalters@mastodon.social at 2026-08-12T11:07:26.000Z ##

CVE-2026-73225 - Path traversal in electerm FTP/SFTP client. Malicious server writes files outside download dir. CVSS 8.1. Update to 3.15.120 now. #CVE #infosec #electerm

valtersit.com/cve/CVE-2026-732

##

thehackerwire@mastodon.social at 2026-08-11T20:00:22.000Z ##

🟠 CVE-2026-73225 - High (8.1)

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to write attacker-controlled content outside the selected download directory because recurs...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66058
(0 None)

EPSS: 0.22%

1 posts

N/A

sayzard@mastodon.sayzard.org at 2026-08-12T09:45:39.000Z ##

ERPNext's Document Follow feature exposed unauthorized data

Frappe/ERPNext의 Document Follow 기능에서 권한 검증이 누락된 취약점 체인 3건(CVE-2026-66058, CVE-2026-66059, CVE-2026-66000)이 공개됐다. 인증된 Desk 사용자는 읽기 권한이 없는 문서를 팔로우할 수 있었고, 이후 변경 시 민감한 필드가 포함된 diff 정보를 이메일로 지속 수신할 수 있었다. 또한 문서 권한이 사후 철회돼도 기존 팔로우 구독이 유지되는 문제가 있어 데이터 유출이 지속될 수 있었다. Frappe v16.23.0 및 v15.112.0에서 수정됐으므로 ERPNext/HRMS 운영자는...

robinroy.xyz/blog/frappe-docum

##

CVE-2026-66000
(0 None)

EPSS: 0.26%

1 posts

N/A

sayzard@mastodon.sayzard.org at 2026-08-12T09:45:39.000Z ##

ERPNext's Document Follow feature exposed unauthorized data

Frappe/ERPNext의 Document Follow 기능에서 권한 검증이 누락된 취약점 체인 3건(CVE-2026-66058, CVE-2026-66059, CVE-2026-66000)이 공개됐다. 인증된 Desk 사용자는 읽기 권한이 없는 문서를 팔로우할 수 있었고, 이후 변경 시 민감한 필드가 포함된 diff 정보를 이메일로 지속 수신할 수 있었다. 또한 문서 권한이 사후 철회돼도 기존 팔로우 구독이 유지되는 문제가 있어 데이터 유출이 지속될 수 있었다. Frappe v16.23.0 및 v15.112.0에서 수정됐으므로 ERPNext/HRMS 운영자는...

robinroy.xyz/blog/frappe-docum

##

CVE-2026-66059
(0 None)

EPSS: 0.27%

1 posts

N/A

sayzard@mastodon.sayzard.org at 2026-08-12T09:45:39.000Z ##

ERPNext's Document Follow feature exposed unauthorized data

Frappe/ERPNext의 Document Follow 기능에서 권한 검증이 누락된 취약점 체인 3건(CVE-2026-66058, CVE-2026-66059, CVE-2026-66000)이 공개됐다. 인증된 Desk 사용자는 읽기 권한이 없는 문서를 팔로우할 수 있었고, 이후 변경 시 민감한 필드가 포함된 diff 정보를 이메일로 지속 수신할 수 있었다. 또한 문서 권한이 사후 철회돼도 기존 팔로우 구독이 유지되는 문제가 있어 데이터 유출이 지속될 수 있었다. Frappe v16.23.0 및 v15.112.0에서 수정됐으므로 ERPNext/HRMS 운영자는...

robinroy.xyz/blog/frappe-docum

##

CVE-2026-44772
(0 None)

EPSS: 0.00%

2 posts

N/A

beyondmachines1 at 2026-08-12T08:01:15.265Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-08-12T08:01:15.000Z ##

SAP August 2026 Patch Day Fixes Critical Code Injection and Memory Corruption Flaws

SAP's August 2026 Security Patch Day addresses 31 vulnerabilities, including a critical CVSS 10.0 authentication bypass in Commerce Cloud and code injection flaws in Manufacturing Integration and Intelligence. These vulnerabilities allow remote attackers to execute arbitrary commands and gain unauthorized access to internal enterprise systems.

**If you run SAP products, especially Manufacturing Integration and Intelligence (MII) read the advisory in detail. First make sure these systems are isolated from the internet where possible and reachable only from trusted internal networks. Then apply SAP's August 2026 security notes ASAP starting with the critical fixes for Commerce Cloud (CVE-2026-58231) and MII (CVE-2026-44772, CVE-2026-44758), followed by the ABAP Platform patch (CVE-2026-34265).**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-72914
(0 None)

EPSS: 0.45%

3 posts

N/A

harald@mementomori.social at 2026-08-12T06:12:19.000Z ##

Vulnerabilities in #Mastodon
URL: github.com/mastodon/mastodon/s
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- github.com/mastodon/mastodon/s
- github.com/mastodon/mastodon/s

CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.

CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.

CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.

##

harald@mementomori.social at 2026-08-12T06:12:19.000Z ##

Vulnerabilities in #Mastodon
URL: github.com/mastodon/mastodon/s
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- github.com/mastodon/mastodon/s
- github.com/mastodon/mastodon/s

CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.

CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.

CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.

##

thehackerwire@mastodon.social at 2026-08-10T22:59:48.000Z ##

🟠 CVE-2026-72914 - High (7.5)

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative statistics endpoints handled by Api::V1::Admin::MeasuresController and Api::V1::Admin::RetentionContro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72916
(0 None)

EPSS: 0.36%

2 posts

N/A

harald@mementomori.social at 2026-08-12T06:12:19.000Z ##

Vulnerabilities in #Mastodon
URL: github.com/mastodon/mastodon/s
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- github.com/mastodon/mastodon/s
- github.com/mastodon/mastodon/s

CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.

CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.

CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.

##

harald@mementomori.social at 2026-08-12T06:12:19.000Z ##

Vulnerabilities in #Mastodon
URL: github.com/mastodon/mastodon/s
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
CVEs: CVE-2026-72914, CVE-2026-72915, CVE-2026-72916
See also:
- github.com/mastodon/mastodon/s
- github.com/mastodon/mastodon/s

CVE-2026-72914 (CVSS: 7.5): A Mastodon statistics endpoint intended for
instance administrators was checking for the appropriate permissions before
returning the results, but not before computing them, allowing anyone to issue
potentially expensive requests.

CVE-2026-72915 (CVSS: 7.5): Mastodon versions 4.6.0 to 4.6.4 allow any
logged-in local user to access personally-identifying information about other
local-users due to an incorrect access control validation.

CVE-2026-72916 (CVSS: 6.3): By nature, Mastodon performs a lot of outbound
requests to user-provided domains. Mastodon however has some protection
mechanism to disallow requests to local IP addresses (unless specified in
ALLOWED_PRIVATE_ADDRESSES) to avoid the “confused deputy” problem. The list of
disallowed IP address ranges was lacking the IPv4-compatible IPv6 address
range that can be used to reach local IP addresses on specific configurations.

##

CVE-2026-12234
(0 None)

EPSS: 0.08%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T06:00:36.000Z ##

🟠 CVE-2026-12234 - High (7.8)

The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c snapshot the caller-supplied struct net_msghdr into a kernel-side copy with k_usermode_from_copy(), but then re-read the still-li...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T06:00:36.000Z ##

🟠 CVE-2026-12234 - High (7.8)

The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c snapshot the caller-supplied struct net_msghdr into a kernel-side copy with k_usermode_from_copy(), but then re-read the still-li...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48765
(0 None)

EPSS: 0.26%

3 posts

N/A

offseq at 2026-08-12T06:00:27.764Z ##

CVE-2026-48765 (CRITICAL, CVSS 9.9): TypeBot.io <3.17.0 suffers from an auth bypass, letting read collaborators hijack OAuth credentials across workspaces. Upgrade to 3.17.0+ ASAP. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-12T06:00:27.000Z ##

CVE-2026-48765 (CRITICAL, CVSS 9.9): TypeBot.io <3.17.0 suffers from an auth bypass, letting read collaborators hijack OAuth credentials across workspaces. Upgrade to 3.17.0+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202648765 #TypeBot #OAuth #Security

##

thehackerwire@mastodon.social at 2026-08-11T22:01:20.000Z ##

🔴 CVE-2026-48765 - Critical (9.9)

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and then overwrite that credential through `handleUpdateOAuthCredent...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73249
(0 None)

EPSS: 0.25%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T00:00:22.000Z ##

🟠 CVE-2026-73249 - High (7.5)

calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/calibre/srv/books.py omits needs_db_write=True, causing Router.dispatch() to skip ctx.check_for_wr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-12T00:00:22.000Z ##

🟠 CVE-2026-73249 - High (7.5)

calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/calibre/srv/books.py omits needs_db_write=True, causing Router.dispatch() to skip ctx.check_for_wr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73246
(0 None)

EPSS: 0.35%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-12T00:00:02.000Z ##

🟠 CVE-2026-73246 - High (7.5)

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndpoint.java serves GET /worker without authentication and serializes the complete live Task object, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48763
(0 None)

EPSS: 0.31%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T22:00:20.000Z ##

🟠 CVE-2026-48763 - High (8.2)

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url` that accepts an attacker-controlled `filePath` and returns a presigned...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73234
(0 None)

EPSS: 0.16%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T21:00:33.000Z ##

🟠 CVE-2026-73234 - High (7.8)

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() in src/App/PropertyFile.cpp concatenates an attacker-controlled file or data attribute from Document.xml with the document trans...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73232
(0 None)

EPSS: 0.45%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T21:00:15.000Z ##

🟠 CVE-2026-73232 - High (7.5)

ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service because the response size guard in pkg/runner/simple.go checks only the compressed Content-Length while io.R...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73226
(0 None)

EPSS: 0.39%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T20:00:34.000Z ##

🟠 CVE-2026-73226 - High (8.8)

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions through client-controlled func values in upgrade...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73069
(0 None)

EPSS: 0.36%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T17:00:46.000Z ##

🔴 CVE-2026-73069 - Critical (9.1)

Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply settings.asExpression for the system TS_VECTOR field searchVector through ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72922
(0 None)

EPSS: 0.27%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T16:01:34.000Z ##

🟠 CVE-2026-72922 - High (8.2)

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api/features/integrations/router.py webhook_ingress_generic rout...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72921
(0 None)

EPSS: 0.24%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T16:01:19.000Z ##

🟠 CVE-2026-72921 - High (8.1)

SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling paths suc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72920
(0 None)

EPSS: 0.41%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-11T16:01:00.000Z ##

🔴 CVE-2026-72920 - Critical (9.8)

SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

_r_netsec@infosec.exchange at 2026-08-11T15:43:04.000Z ##

CopyEscape: Container-to-host arbitrary file write via docker cp (CVE-2026-17106) imperva.com/blog/copyescape-ta

##

CVE-2026-44945
(0 None)

EPSS: 0.30%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-08-11T01:03:45.000Z ##

CVE-2026-44945: Rancher Cross-Cluster Impersonation Flaw Enables Full Privilege Escalation, Rated CVSS 9.1

securityonline.info/rancher-pr

##

CVE-2026-8718
(0 None)

EPSS: 0.12%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T23:59:54.000Z ##

🟠 CVE-2026-8718 - High (8.4)

tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72911
(0 None)

EPSS: 0.38%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T22:00:16.000Z ##

🔴 CVE-2026-72911 - Critical (9.9)

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72886
(0 None)

EPSS: 0.36%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T21:00:20.000Z ##

🔴 CVE-2026-72886 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive serviceId from applicationId or composeId and execute the owner/adm...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72883
(0 None)

EPSS: 0.40%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T21:00:09.000Z ##

🟠 CVE-2026-72883 - High (8.8)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/server/wss/terminal.ts, apps/dokploy/server/wss/docker-container-terminal.ts, apps/dokploy/server/wss/docker-container-logs.ts,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72872
(0 None)

EPSS: 0.37%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T20:00:30.000Z ##

🔴 CVE-2026-72872 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucketRepository without validation and cloneBitbucketRepository in packages/server/src/utils/providers...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72871
(0 None)

EPSS: 0.29%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T20:00:08.000Z ##

🟠 CVE-2026-72871 - High (7.5)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/github/setup route in apps/dokploy/pages/api/providers/github/setup.ts trusts gh_init organizationId and userId values from the sta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-72730
(0 None)

EPSS: 0.24%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T17:59:51.000Z ##

🟠 CVE-2026-72730 - High (8.7)

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scripting. This issue is fixed in versions 2026.1.6,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47754
(0 None)

EPSS: 0.34%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T17:00:24.000Z ##

🔴 CVE-2026-47754 - Critical (9.3)

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path traversal in the `archiveEntryName` parameter of the `action=read` endp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-60137
(0 None)

EPSS: 73.10%

1 posts

N/A

52 repos

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/mcipekci/wp2shell

https://github.com/bahartanir/wp2shell-scanner

https://github.com/M4xSec/wp2shell-Exploit-Waf-Bypass

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/AbdullahMaqbool22/CVE-2026-60137-WordPress-Core-SQL-Injection-PoC

https://github.com/michael-kanda/Wp2shell-ioc-scanner

https://github.com/47Cid/wp2shell-lab

https://github.com/Iqbalx7/wp2shell

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/kulichr/wp2shell

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/0xWhoknows/wp2shell

https://github.com/NULL200OK/WP2Shell

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/ananay/wp2shell-lab

https://github.com/zi3lak/wp2shell_scanner

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/g0d150ne/WP2Shell

https://github.com/ebrasha/abdal-cve-2026-60137

https://github.com/Crypto-Cat/wp2shell

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/AdarshThakur14777-cyber/CVE-2026-60137

https://github.com/securelayer7/WordPresShell

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/johnlodan/wp2shell-rce

https://github.com/0xjessie21/wp2shell-checker

https://github.com/0xsha/wp2shell

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/dinosn/wp2shell-lab

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/vulnquest58/PressVector

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/h4cd0c/wp2shell

https://github.com/yuag/wp2shell

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/shinthink/CVE-2026-63030

https://github.com/Icex0/wp2shell-poc

https://github.com/sowarma/wp2shell-PoC

https://github.com/ikow/wp2shell

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/northsia/CVE-2026-60137-With-Skip-SSL

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/ekomsSavior/wp2shell

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

bstnbuck@infosec.exchange at 2026-08-10T12:30:00.000Z ##

A #Wordpress site belonging to an friend (I’m not the admin...) was successfully hacked using #wp2shell (17.07.2026; CVE-2026-63030 + CVE-2026-60137), just 5 days after the first exploit published (20.07.). Another 5 days later, the website was abused for SEO spamming and for hosting phishing…

If you haven't already, update your Wordpress (preferably yesterday…; >=v7.0.2 or >= 6.9.5) and also enable automatic updates for themes and plug-ins!

I found several PHP backdoors/webshells (see @abuse_ch Malware Bazaar and #VirusTotal (hashes below)). Interestingly, not every sample was detected by the #YARA rules from @cyb3rops and github.com/ruppde/yara_rules.

tl;dr #wp2shell is being actively exploited, patch immediately and enable automatic updates.

Hashes:
1093b4045b45a8498d146e31788c25769f992056c8ffc582b5d8c06598598966
05e3884a478d3bc8fd7285dabb74107422f1615d2d7f80df9b8438d4beb663da
bb9136494a546368e7c9b6252c2e1c5af9327c07947908a9ba6fdd78fb4bf4cf
1e7ca9074cc2eca8d366022629f665d9ffaa79e0621bb579bf5aabe681cb07e8
8ebaf3ba0be7b62269aaf333cfaf66c1dea6e8ee495a917691beb550b4bbf0ab
e3fb920aa70c7ad5c67b4d9b8e60954f5e0c1a07c0eba09505816b966f4d1a3c
165e94c87ef17389c8de25ba2a6c31b348e3c916dab89d0dd3708156414f3de5
b55cf5af8b57e9d56c69d00e023e2384c7eb184614c2a2a283062ebeaf4a26c6
a46230a1638b9b341d15a640ead1b885548c1d1e5a149657e8e315540a068be8
7918f29993383e579ef33bd0d8e766fd2ce047dce83bac51efb5fe17578b6cdf
ae9ee9db7c41e04c531298782b908766c769a899aa92df3f64f4a83baa77ad09

##

decio@infosec.exchange at 2026-08-10T08:17:55.000Z ##

Dans la suite de wp2shell, encore une jolie chaîne WordPress : #XSS2Shell — CVE-2026-64638.

Au départ, on a “juste” une Reflected XSS pré-auth sur wp-login.php.

Sauf qu’en la chaînant avec plusieurs briques déjà présentes dans WordPress, on arrive à quelque chose de beaucoup moins sympa :

XSS → contexte admin → Application Password → REST API → upload de plugin → RCE 🐚

⚠️ À noter quand même : ce n’est pas du pre-auth zero-click.
Il faut qu’un admin déjà connecté clique sur un lien contrôlé par l’attaquant.

Encore un bon rappel : une “simple XSS” peut devenir franchement méchante une fois mise dans la bonne chaîne.

🩹 Corrigé dans WordPress 7.0.3.
👇
wordpress.org/news/2026/08/wor

En cas de doute sur une exploitation passée : petit coup d’œil aux Application Passwords, aux plugins récemment ajoutés et aux fichiers PHP inhabituels.

"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
👇
pwn.ai/blog/xss2shell

#WordPress #XSS2Shell #CyberVeille

##

Visit counter For Websites