## Updated at UTC 2026-09-14T13:11:21.293843

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-90919 9.8 0.00% 2 0 2026-09-14T12:17:51.807000 LightLLM through 1.2.0 contains a remote code execution vulnerability in the Con
CVE-2026-73324 4.3 0.33% 5 0 2026-09-14T11:17:04.280000 Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memor
CVE-2026-85706 10.0 1.16% 37 12 template 2026-09-14T10:59:38.933000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7
CVE-2026-90703 9.1 0.00% 2 0 2026-09-14T10:17:05.610000 A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element i
CVE-2026-90680 9.9 0.00% 2 0 2026-09-14T06:31:26 A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The im
CVE-2026-23789 7.8 0.00% 2 0 2026-09-14T03:30:29 An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processo
CVE-2026-33963 7.5 0.00% 2 0 2026-09-14T03:30:29 An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380,
CVE-2026-31278 7.7 0.00% 2 1 2026-09-14T02:17:14.080000 An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 be
CVE-2026-90608 9.9 0.00% 4 0 2026-09-14T01:16:28.130000 A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected elemen
CVE-2026-90607 9.9 0.00% 4 0 2026-09-14T01:16:27.870000 A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is
CVE-2026-90606 9.9 0.00% 6 0 2026-09-14T00:31:35 A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046
CVE-2026-90605 9.9 0.00% 2 0 2026-09-14T00:16:57.447000 A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulne
CVE-2026-82078 9.1 1.69% 1 2 2026-09-14T00:16:56.777000 An unsafe dynamic class loading vulnerability exists in the database connection
CVE-2026-81578 9.8 1.62% 1 2 2026-09-14T00:16:56.207000 An improper access control vulnerability exists in the web management interface
CVE-2026-15891 7.5 0.00% 2 0 2026-09-13T23:16:27.870000 The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mq
CVE-2026-88793 8.8 0.00% 2 0 2026-09-13T21:31:54 The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any author
CVE-2026-88802 7.5 0.00% 2 0 2026-09-13T21:17:02.323000 The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events
CVE-2026-85129 8.8 0.00% 2 0 2026-09-13T21:17:02.063000 The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or vali
CVE-2026-81648 10.0 0.00% 2 0 2026-09-13T21:17:01.930000 The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an
CVE-2026-74933 8.8 0.00% 2 0 2026-09-13T21:17:01.800000 The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisatio
CVE-2026-37008 8.1 0.00% 2 0 2026-09-13T21:17:01.303000 CrewAI before fb2323b offers a Python blocklist approach that operates at the wr
CVE-2026-29811 7.7 0.00% 2 0 2026-09-13T20:16:51.020000 CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second dom
CVE-2026-90783 7.8 0.00% 2 0 2026-09-13T13:16:29.560000 MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib l
CVE-2026-90778 7.5 0.00% 2 0 2026-09-13T12:31:19 SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() fu
CVE-2026-90777 8.8 0.00% 2 0 2026-09-13T12:31:19 ESPnet before 202609 deserializes pretrained model checkpoints using torch.load
CVE-2026-90774 7.5 0.00% 2 0 2026-09-13T12:31:19 rustypaste before 0.18.1 validates the destination path before applying the opti
CVE-2026-90770 8.8 0.00% 2 0 2026-09-13T12:31:12 Spug through 3.4.0 contains a remote code execution vulnerability in the ping_ch
CVE-2026-90768 8.1 0.00% 2 0 2026-09-13T12:31:12 CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpo
CVE-2026-90561 8.7 0.00% 4 0 2026-09-13T12:31:11 Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-
CVE-2026-90562 8.1 0.00% 4 0 2026-09-13T12:31:11 LangBot before 4.10.11 generates password recovery keys with only 24 bits of ent
CVE-2026-86406 7.5 0.00% 2 0 2026-09-13T12:31:09 The User Registration & Membership WordPress plugin before 5.2.8 does not check
CVE-2026-90780 7.5 0.00% 2 0 2026-09-13T12:17:17.093000 SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header()
CVE-2026-90779 7.5 0.00% 2 0 2026-09-13T12:17:16.960000 SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthH
CVE-2026-90776 7.5 0.00% 2 0 2026-09-13T12:17:16.547000 Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vul
CVE-2026-90775 6.5 0.00% 2 0 2026-09-13T12:17:16.400000 PostGIS address_standardizer through 3.7.0 fails to validate the Weight paramete
CVE-2026-90772 7.6 0.00% 2 0 2026-09-13T11:17:01.780000 Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptio
CVE-2026-90769 7.7 0.00% 2 0 2026-09-13T11:17:01.270000 Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sou
CVE-2026-90510 8.3 0.00% 2 0 2026-09-13T11:16:59.827000 A security vulnerability has been detected in dromara orion-visor up to 2.5.7. T
CVE-2026-89080 7.5 0.00% 2 0 2026-09-13T11:16:59.650000 The Really Simple Security WordPress plugin before 9.8.1 does not prevent an un
CVE-2026-89690 7.8 0.16% 2 0 2026-09-13T09:33:34 In the Linux kernel, the following vulnerability has been resolved: nfsd: defer
CVE-2026-89696 7.5 0.67% 2 0 2026-09-13T09:33:32 In the Linux kernel, the following vulnerability has been resolved: nfsd: block
CVE-2026-89612 9.8 0.55% 2 0 2026-09-13T09:33:31 In the Linux kernel, the following vulnerability has been resolved: ntfs: rejec
CVE-2026-89611 9.8 0.38% 2 0 2026-09-13T09:33:31 In the Linux kernel, the following vulnerability has been resolved: ntfs: valid
CVE-2026-89697 9.1 0.60% 2 0 2026-09-13T09:33:30 In the Linux kernel, the following vulnerability has been resolved: nfsd: add f
CVE-2026-80981 9.8 0.59% 1 0 2026-09-13T09:33:25 In the Linux kernel, the following vulnerability has been resolved: net/smc: fi
CVE-2026-89750 7.8 0.16% 2 0 2026-09-13T09:32:30 In the Linux kernel, the following vulnerability has been resolved: tracing/use
CVE-2026-89744 8.4 0.14% 2 0 2026-09-13T09:32:30 In the Linux kernel, the following vulnerability has been resolved: device prop
CVE-2026-89758 7.8 0.14% 2 0 2026-09-13T09:32:30 In the Linux kernel, the following vulnerability has been resolved: mm/mempolic
CVE-2026-89754 7.8 0.12% 2 0 2026-09-13T09:32:30 In the Linux kernel, the following vulnerability has been resolved: mm/pagewalk
CVE-2026-89762 7.8 0.12% 2 0 2026-09-13T09:32:30 In the Linux kernel, the following vulnerability has been resolved: apparmor: f
CVE-2026-89761 7.8 0.12% 2 0 2026-09-13T09:32:30 In the Linux kernel, the following vulnerability has been resolved: apparmor: f
CVE-2026-89736 7.8 0.12% 2 0 2026-09-13T09:32:29 In the Linux kernel, the following vulnerability has been resolved: usb: gadget
CVE-2026-89685 7.5 0.43% 2 0 2026-09-13T09:32:28 In the Linux kernel, the following vulnerability has been resolved: nfsd: fix c
CVE-2026-89771 7.8 0.12% 2 0 2026-09-13T07:17:41.310000 In the Linux kernel, the following vulnerability has been resolved: ring-buffer
CVE-2026-89767 7.8 0.15% 2 0 2026-09-13T07:17:41.050000 In the Linux kernel, the following vulnerability has been resolved: ovl: fix do
CVE-2026-89764 7.8 0.14% 2 0 2026-09-13T07:17:40.843000 In the Linux kernel, the following vulnerability has been resolved: rust: devre
CVE-2026-89763 7.8 0.11% 2 0 2026-09-13T07:17:40.717000 In the Linux kernel, the following vulnerability has been resolved: KEYS: trust
CVE-2026-89760 7.8 0.11% 2 0 2026-09-13T07:17:40.307000 In the Linux kernel, the following vulnerability has been resolved: mm, swap: d
CVE-2026-89755 7.8 0.14% 2 0 2026-09-13T07:17:39.983000 In the Linux kernel, the following vulnerability has been resolved: mm/migrate_
CVE-2026-89748 7.8 0.15% 2 0 2026-09-13T07:17:39.493000 In the Linux kernel, the following vulnerability has been resolved: tracing: Fi
CVE-2026-89747 7.8 0.16% 2 0 2026-09-13T07:17:39.363000 In the Linux kernel, the following vulnerability has been resolved: tracing: Fi
CVE-2026-89746 7.8 0.16% 2 0 2026-09-13T07:17:39.220000 In the Linux kernel, the following vulnerability has been resolved: tracing: Fi
CVE-2026-89706 7.5 0.44% 2 0 2026-09-13T07:17:36.240000 In the Linux kernel, the following vulnerability has been resolved: nfsd: Reset
CVE-2026-89704 7.5 0.44% 2 0 2026-09-13T07:17:35.990000 In the Linux kernel, the following vulnerability has been resolved: nfsd: sampl
CVE-2026-89695 7.5 0.49% 2 0 2026-09-13T07:17:35.230000 In the Linux kernel, the following vulnerability has been resolved: nfsd: cap d
CVE-2026-89692 7.5 0.43% 2 0 2026-09-13T07:17:35.107000 In the Linux kernel, the following vulnerability has been resolved: nfsd: clear
CVE-2026-89689 9.8 0.60% 2 0 2026-09-13T07:17:34.723000 In the Linux kernel, the following vulnerability has been resolved: nfsd: don't
CVE-2026-89688 9.8 0.61% 2 0 2026-09-13T07:17:34.600000 In the Linux kernel, the following vulnerability has been resolved: nfsd: drop
CVE-2026-89687 7.5 0.47% 2 0 2026-09-13T07:17:34.493000 In the Linux kernel, the following vulnerability has been resolved: nfsd: ensur
CVE-2026-89686 9.8 0.67% 2 0 2026-09-13T07:17:34.367000 In the Linux kernel, the following vulnerability has been resolved: nfsd: fix B
CVE-2026-89684 7.5 0.45% 2 0 2026-09-13T07:17:34.130000 In the Linux kernel, the following vulnerability has been resolved: nfsd: fix c
CVE-2026-89682 8.1 0.40% 2 0 2026-09-13T07:17:34.003000 In the Linux kernel, the following vulnerability has been resolved: nfsd: fix f
CVE-2026-89613 9.8 0.55% 2 0 2026-09-13T07:17:26.840000 In the Linux kernel, the following vulnerability has been resolved: ntfs: rejec
CVE-2026-81000 7.8 0.16% 1 0 2026-09-13T07:17:06.600000 In the Linux kernel, the following vulnerability has been resolved: net: tun: b
CVE-2026-80995 7.8 0.12% 1 0 2026-09-13T07:17:06.230000 In the Linux kernel, the following vulnerability has been resolved: net: mctp:
CVE-2026-80980 9.8 0.60% 1 0 2026-09-13T07:17:04.887000 In the Linux kernel, the following vulnerability has been resolved: net/smc: st
CVE-2026-90678 7.5 0.00% 2 0 2026-09-13T04:17:25.227000 An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3
CVE-2026-90668 7.5 0.00% 3 0 2026-09-13T03:30:22 The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the
CVE-2026-90493 8.8 0.00% 4 0 2026-09-13T03:16:27.370000 A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build
CVE-2026-90648 None 0.00% 2 0 2026-09-13T00:31:26 wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situatio
CVE-2026-90651 8.1 0.00% 4 0 2026-09-13T00:31:26 Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0
CVE-2026-90647 7.4 0.00% 2 0 2026-09-12T23:17:01.490000 ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows con
CVE-2026-90616 7.4 0.00% 2 0 2026-09-12T21:31:19 In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read an
CVE-2026-75800 9.8 0.42% 2 0 2026-09-12T18:31:28 The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signatu
CVE-2026-77006 9.6 0.18% 2 0 2026-09-12T18:31:28 The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-sup
CVE-2026-87842 7.5 0.29% 2 0 2026-09-12T18:31:28 The Zonify WordPress plugin before 1.0.5 does not perform any capability or aut
CVE-2026-90558 9.8 0.00% 4 0 2026-09-12T18:30:33 sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attri
CVE-2026-90560 8.2 0.00% 2 0 2026-09-12T18:30:33 zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerabi
CVE-2026-81742 8.8 0.28% 2 0 2026-09-12T18:30:22 The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any author
CVE-2026-80494 8.6 0.32% 2 0 2026-09-12T18:30:22 The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-suppli
CVE-2026-82845 9.9 0.35% 2 0 2026-09-12T18:30:22 The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied
CVE-2026-87888 8.0 0.23% 2 0 2026-09-12T18:30:22 The YayPricing WordPress plugin before 3.5.7 does not perform an authorization
CVE-2026-84099 8.1 0.27% 2 0 2026-09-12T18:30:22 The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthen
CVE-2026-81402 9.8 0.45% 2 0 2026-09-12T18:30:21 The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability c
CVE-2026-80491 8.6 0.32% 2 0 2026-09-12T18:30:21 The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and esc
CVE-2026-90559 7.5 0.00% 2 0 2026-09-12T18:16:44.743000 snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Sn
CVE-2026-90556 7.8 0.00% 2 0 2026-09-12T18:16:44.193000 Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load()
CVE-2026-87759 8.8 0.23% 3 0 2026-09-12T16:16:42.473000 The Add User Autocomplete WordPress plugin before 1.2 does not perform any capab
CVE-2026-85681 9.8 0.28% 3 0 2026-09-12T16:16:42.170000 The WP Component WordPress plugin through 2.2.4 does not have any capability or
CVE-2026-84171 9.8 0.37% 3 0 2026-09-12T16:16:41.897000 The WP images upload on piclect WordPress plugin through 1.0 does not validate t
CVE-2026-84047 8.6 0.26% 2 0 2026-09-12T16:16:41.527000 The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize
CVE-2026-77005 9.6 0.30% 2 0 2026-09-12T16:16:38.523000 The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a u
CVE-2026-90553 7.8 0.21% 1 0 2026-09-12T15:31:56 vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOn
CVE-2026-90537 8.2 0.21% 1 0 2026-09-12T13:16:51.667000 WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a m
CVE-2026-15451 8.8 0.25% 1 0 2026-09-12T13:16:50.940000 The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privile
CVE-2026-85200 7.5 0.76% 1 0 2026-09-12T09:33:36 The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all
CVE-2026-78175 8.8 0.59% 1 0 2026-09-12T08:16:24.507000 The Tutor LMS – eLearning and online course solution plugin for WordPress is vul
CVE-2026-78159 9.8 0.76% 4 0 2026-09-12T08:16:24.377000 The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execut
CVE-2026-78006 9.8 0.78% 4 2 2026-09-12T08:16:24.240000 The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execut
CVE-2026-16482 7.5 0.34% 1 0 2026-09-12T08:16:23.797000 The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulner
CVE-2026-84869 9.9 0.69% 7 0 2026-09-12T04:16:42.757000 A condition in the ScreenConnect client may allow files to be transferred and ex
CVE-2026-42018 7.5 0.92% 7 1 2026-09-12T04:16:33.587000 JFrog Artifactory could return an internal anonymous-user token to an unauthenti
CVE-2026-42016 8.1 0.89% 6 0 2026-09-12T04:16:32.483000 JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a pri
CVE-2026-87719 9.9 0.61% 2 0 2026-09-12T03:16:31.477000 GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 bef
CVE-2026-90460 None 0.34% 1 0 2026-09-12T00:31:35 An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via
CVE-2026-89266 8.2 0.47% 1 0 2026-09-12T00:31:35 stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where
CVE-2026-90456 0 0.25% 1 0 2026-09-11T22:16:47.993000 An example environment-configuration file for a bundled inventory-management com
CVE-2026-79395 9.8 0.41% 1 0 2026-09-11T21:31:23 An improper authentication vulnerability in the WS-Security (wsse:UsernameToken)
CVE-2026-78488 6.5 3.25% 2 0 2026-09-11T21:22:54.260000 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application
CVE-2026-54174 8.3 0.10% 1 0 2026-09-11T21:17:11.403000 melange allows users to build apk packages using declarative pipelines. Apko pri
CVE-2026-49464 8.1 0.20% 1 0 2026-09-11T21:17:10.523000 NL Portal Backend Libraries provide backend components for Dutch government port
CVE-2026-62112 7.6 0.28% 1 0 2026-09-11T21:17:02.457000 Editor SQL Injection in Amelia <= 2.4.9 versions.
CVE-2026-89502 0 0.20% 1 0 2026-09-11T20:19:32.423000 In the Linux kernel, the following vulnerability has been resolved: ring-buffer
CVE-2026-54135 7.5 0.55% 1 0 2026-09-11T20:17:14.330000 AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan p
CVE-2026-53952 9.8 0.33% 1 0 2026-09-11T20:17:14.060000 GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the
CVE-2026-79393 7.5 0.53% 1 0 2026-09-11T19:17:46.070000 A heap-based buffer overflow vulnerability in the WS-Addressing Action transform
CVE-2026-89262 7.5 0.31% 1 0 2026-09-11T18:31:32 MoguBlog through 6.2 contains an authorization bypass vulnerability in the comme
CVE-2026-89260 7.5 0.43% 1 0 2026-09-11T18:31:31 MoguBlog through 6.2 contains an XML external entity injection vulnerability in
CVE-2026-89066 7.8 0.16% 1 0 2026-09-11T18:24:59.400000 Improper neutralization of special elements used in an OS command in the task sy
CVE-2026-89010 9.8 2.85% 2 0 2026-09-11T17:35:21.440000 WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 cont
CVE-2026-69827 8.1 0.53% 1 0 2026-09-11T16:17:43.143000 Concurrent execution using shared resource with improper synchronization ('race
CVE-2026-87020 8.1 0.56% 2 0 2026-09-11T15:32:49 An integer overflow in a specified pitch and buffer-size computation leads to a
CVE-2026-89212 8.6 0.33% 1 0 2026-09-11T15:32:48 A flaw resulting in XML external entity (XXE) was found in Akana API Platform in
CVE-2026-71416 8.8 0.17% 1 0 2026-09-11T15:17:03.373000 Headroom compresses data before the data reaches a large language model. Prior t
CVE-2026-81467 9.8 3.84% 2 0 2026-09-11T13:18:18.543000 Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutraliza
CVE-2026-80462 10.0 0.30% 2 0 2026-09-11T13:18:18.300000 A vulnerability in the Chef Automate API gateway and identity validation path ma
CVE-2026-0310 0 0.34% 1 0 2026-09-11T04:17:13.060000 A buffer overflow vulnerability in the XML processing functionality of Palo Alto
CVE-2026-17176 None 3.59% 2 0 2026-09-11T00:31:16 An OS command injection vulnerability in the TDDP module of Deco BE11000 allows
CVE-2026-89094 9.9 0.50% 1 0 2026-09-10T21:31:46 Forgejo before 16.0.4 allows remote code execution via a crafted template reposi
CVE-2026-65638 0 3.20% 3 0 2026-09-10T19:54:25.810000 Improper escaping of a request URL in ConfigServer Security & Firewall allows a
CVE-2026-89049 9.9 0.36% 1 0 2026-09-10T19:44:21.980000 A server-side request forgery issue due to improper validation of equivalent add
CVE-2026-80352 9.8 0.33% 1 0 2026-09-10T18:33:12 Improper Control of Generation of Code ('Code Injection') vulnerability in Apach
CVE-2026-81468 9.1 2.28% 2 0 2026-09-10T18:33:03 Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutraliza
CVE-2026-20079 10.0 75.75% 7 3 2026-09-10T12:48:17.580000 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-19490 9.8 5.60% 2 2 2026-09-10T12:48:10.453000 Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: f
CVE-2025-25249 8.1 2.40% 3 0 2026-09-10T12:47:59.933000 A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6
CVE-2026-69730 9.8 1.05% 2 0 2026-09-10T04:18:14.773000 Use after free in Windows DNS allows an unauthorized attacker to execute code ov
CVE-2026-50894 9.8 0.48% 1 0 2026-09-09T21:32:24 easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous T
CVE-2026-75166 8.8 0.49% 1 0 2026-09-09T21:32:23 Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_0
CVE-2026-53758 0 0.26% 1 0 2026-09-09T18:16:59.010000 Emlog is an open source website building system. In versions 2.6.29 and prior, a
CVE-2026-50768 8.8 0.45% 1 0 2026-09-09T16:04:24.933000 File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9
CVE-2026-78745 9.8 0.72% 1 1 2026-09-09T16:04:24.933000 An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote
CVE-2026-85103 9.8 0.36% 9 0 2026-09-09T15:35:15 A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unau
CVE-2026-85102 9.8 0.33% 9 0 2026-09-09T15:35:15 Improper certificate trust validation during VPN negotiation in Check Point Quan
CVE-2026-56711 8.8 0.30% 5 0 2026-09-09T15:35:15 VLC media player computes the size of a picture buffer with 32-bit arithmetic an
CVE-2026-86218 9.8 0.74% 4 2 2026-09-09T05:18:19.490000 N-central is vulnerable to a pre-auth remote code execution This issue affects N
CVE-2026-85880 7.8 0.57% 1 0 2026-09-09T05:18:19.193000 Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elev
CVE-2026-75650 10.0 2.15% 2 5 2026-09-09T05:18:07.237000 Adobe Commerce is affected by an Improper Neutralization of Special Elements Use
CVE-2026-12745 9.8 2.09% 2 0 2026-09-09T05:17:19.467000 A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM bef
CVE-2026-18073 4.4 0.10% 1 0 2026-09-08T19:44:49.527000 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to injec
CVE-2026-85636 5.3 0.43% 1 0 2026-09-08T18:21:12.550000 A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerabi
CVE-2026-13297 7.5 0.25% 1 0 2026-09-08T18:17:35.057000 IBM Verify Identity Access Advanced Access Control may be vulnerable to an infor
CVE-2026-12744 9.8 2.17% 2 0 2026-09-08T15:32:04 A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM bef
CVE-2026-79697 9.9 3.35% 2 0 2026-09-07T09:31:46 A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-661
CVE-2026-85046 8.8 1.26% 1 8 2026-09-06T03:30:24 Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote at
CVE-2026-86100 6.4 0.19% 1 0 2026-09-05T00:31:15 Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when
CVE-2026-80897 None 0.17% 1 0 2026-09-04T18:31:46 In the Linux kernel, the following vulnerability has been resolved: netfs: rele
CVE-2026-80912 None 0.16% 1 0 2026-09-04T18:31:46 In the Linux kernel, the following vulnerability has been resolved: selinux: re
CVE-2026-80904 None 0.16% 1 0 2026-09-04T18:31:46 In the Linux kernel, the following vulnerability has been resolved: net/tls: Fa
CVE-2026-80909 None 0.17% 1 0 2026-09-04T18:31:46 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu:
CVE-2026-80901 None 0.16% 1 0 2026-09-04T18:31:46 In the Linux kernel, the following vulnerability has been resolved: ipvs: fix t
CVE-2026-80883 None 0.16% 1 0 2026-09-04T18:31:41 In the Linux kernel, the following vulnerability has been resolved: drm/tegra:
CVE-2026-17273 6.5 0.35% 1 0 2026-09-04T18:31:40 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to caus
CVE-2026-16693 4.4 0.13% 1 0 2026-09-04T18:31:40 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obta
CVE-2026-80880 None 0.16% 1 0 2026-09-04T18:31:40 In the Linux kernel, the following vulnerability has been resolved: IB/mlx5: Pr
CVE-2026-80913 0 0.17% 1 0 2026-09-04T18:18:01.200000 In the Linux kernel, the following vulnerability has been resolved: selinux: re
CVE-2026-80894 0 0.17% 1 0 2026-09-04T18:17:57.603000 In the Linux kernel, the following vulnerability has been resolved: iommufd: Fi
CVE-2026-80890 0 0.18% 1 0 2026-09-04T18:17:57.077000 In the Linux kernel, the following vulnerability has been resolved: sctp: rejec
CVE-2026-80871 0 0.15% 1 0 2026-09-04T17:16:59.027000 In the Linux kernel, the following vulnerability has been resolved: crypto: xil
CVE-2026-20212 9.8 0.53% 1 1 2026-09-03T13:04:38.177000 A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switc
CVE-2026-82329 9.8 7.67% 3 7 template 2026-09-02T18:31:57 JFrog Artifactory contains an authentication weakness that, under default config
CVE-2026-59310 9.8 45.88% 1 2 2026-08-19T04:17:24.940000 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-61511 9.8 70.77% 3 5 template 2026-08-07T06:16:56.993000 vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vul
CVE-2026-46331 7.8 0.58% 2 14 2026-07-23T12:33:27 In the Linux kernel, the following vulnerability has been resolved: net/sched:
CVE-2026-4986 5.3 0.20% 2 2 2026-07-23T08:10:00.137000 The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity o
CVE-2026-49176 7.8 0.47% 2 2 2026-07-22T16:17:28.753000 Improper privilege management in Windows WalletService allows an authorized atta
CVE-2026-15409 10.0 84.54% 1 6 2026-07-14T21:32:22 A Server-side request forgery (SSRF) vulnerability has been identified in the SM
CVE-2026-50458 7.8 0.26% 2 0 2026-07-14T18:32:25 Use after free in Microsoft Brokering File System allows an authorized attacker
CVE-2026-50013 7.5 0.27% 1 0 2026-07-14T18:03:10 ### Summary: When Hoverfly is running in Diff mode, the `AddDiff()` function wr
CVE-2026-57239 8.2 0.17% 2 1 2026-07-09T15:33:27 The user-controllable executable files will be directly executed by high-privile
CVE-2026-4201 7.3 0.28% 1 0 2026-06-17T10:56:10.603000 A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040f
CVE-2024-3094 10.0 85.97% 1 89 template 2026-06-17T07:43:17.830000 Malicious code was discovered in the upstream tarballs of xz, starting with vers
CVE-2024-1813 9.8 1.22% 2 1 2026-06-17T07:05:03.993000 The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection
CVE-2026-2275 9.6 0.44% 2 0 2026-03-31T18:32:38 The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach
CVE-2026-51990 0 0.00% 10 1 N/A
CVE-2026-61797 0 0.00% 1 0 N/A
CVE-2026-63030 0 97.27% 3 85 template N/A
CVE-2026-53761 0 0.34% 1 0 N/A
CVE-2026-49846 0 0.34% 1 0 N/A

CVE-2026-90919
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-14T12:17:51.807000

2 posts

LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads(). Attackers can reach the Config Server port and send a malicious serialized payload with a __reduce__ method to execute arbitrary code with Config Server process privileges.

offseq at 2026-09-14T12:00:27.236Z ##

CVE-2026-90919: ModelTC LightLLM <=1.2.0 faces CRITICAL RCE risk. Unauthenticated /visual_register WebSocket lets attackers send malicious pickle data, leading to code execution. Patch or restrict access fast. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-14T12:00:27.000Z ##

CVE-2026-90919: ModelTC LightLLM <=1.2.0 faces CRITICAL RCE risk. Unauthenticated /visual_register WebSocket lets attackers send malicious pickle data, leading to code execution. Patch or restrict access fast. radar.offseq.com/threat/cve-20 #OffSeq #CVE202690919 #RCE #LightLLM

##

CVE-2026-73324
(4.3 MEDIUM)

EPSS: 0.33%

updated 2026-09-14T11:17:04.280000

5 posts

Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build configuration.

beyondmachines1 at 2026-09-13T17:01:13.011Z ##

VLC Media Player Flaws Allow Heap Corruption and Sensitive Data Disclosure

VideoLAN reports two vulnerabilities in VLC Media Player (CVE-2026-56711 and CVE-2026-73324) that allow attackers to corrupt heap memory or leak sensitive data via crafted PNG files and RTSP streams.

**If you use VLC Media Player (any version from 3.0.0 to 3.0.23), update it to the latest patched version as soon as VideoLAN releases it. Until you've updated, don't open media files, playlists, or RTSP streaming links that come from people or websites you don't know and trust.**

beyondmachines.net/event_detai

##

guru@thecybersecguru.com at 2026-09-12T17:11:54.000Z ##

VLC Media Player hit by two critical security flaws: heap corruption and memory disclosure putting millions at risk

Two critical VLC Media Player vulnerabilities, CVE-2026-56711 and CVE-2026-73324, expose users to heap corruption and memory disclosure. Here’s what to do

thecybersecguru.com/news/vlc-m

##

beyondmachines1@infosec.exchange at 2026-09-13T17:01:13.000Z ##

VLC Media Player Flaws Allow Heap Corruption and Sensitive Data Disclosure

VideoLAN reports two vulnerabilities in VLC Media Player (CVE-2026-56711 and CVE-2026-73324) that allow attackers to corrupt heap memory or leak sensitive data via crafted PNG files and RTSP streams.

**If you use VLC Media Player (any version from 3.0.0 to 3.0.23), update it to the latest patched version as soon as VideoLAN releases it. Until you've updated, don't open media files, playlists, or RTSP streaming links that come from people or websites you don't know and trust.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

guru@thecybersecguru.com at 2026-09-12T17:11:54.000Z ##

VLC Media Player hit by two critical security flaws: heap corruption and memory disclosure putting millions at risk

Two critical VLC Media Player vulnerabilities, CVE-2026-56711 and CVE-2026-73324, expose users to heap corruption and memory disclosure. Here’s what to do

thecybersecguru.com/news/vlc-m

##

DarkWebInformer@infosec.exchange at 2026-09-11T16:37:27.000Z ##

🚨 Two VLC Media Player flaws can allow code execution and leak sensitive memory

Security researchers have disclosed two vulnerabilities affecting VLC Media Player versions 3.0.0 through 3.0.23.

CVE-2026-56711, rated 8.6, is a heap out-of-bounds write caused by an integer overflow in VLC's picture buffer allocation.

An attacker can craft a malicious PNG with manipulated dimensions that causes VLC to allocate an undersized memory buffer before writing beyond its boundaries.

The flaw can potentially lead to arbitrary code execution when the malicious image is opened directly or loaded through a playlist.

CVE-2026-73324, rated 6.9, affects VLC's RealRTSP handling.

A malicious RTSP server can send an oversized response that causes VLC to read beyond an allocated buffer and return adjacent heap memory to the attacker, potentially exposing sensitive information.

The vulnerable RealRTSP component is enabled in official VideoLAN builds, although some Linux distribution packages may compile VLC without it.

As of September 11, VLC 3.0.23 remains the current stable desktop release listed by VideoLAN and is affected by both vulnerabilities.

Users should avoid opening untrusted image files or RealRTSP playlist links until an updated release addressing the flaws becomes available.

Source: securityonline.info/vlc-media-

##

CVE-2026-85706
(10.0 CRITICAL)

EPSS: 1.16%

updated 2026-09-14T10:59:38.933000

37 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Nuclei template

12 repos

https://github.com/mhtsec/CVE-2026-85706

https://github.com/plur1bu5/gitread

https://github.com/gagaltotal/CVE-2026-85706-gitlab-poc

https://github.com/gabrielunknown/CVE-2026-85706

https://github.com/jithinkrishnanrs/gitlab-cve-2026-85706-ioc

https://github.com/0xlyvio/cve-2026-85706-poc-exploit-gitlab

https://github.com/brigadeops32/CVE-2026-85706

https://github.com/0xenesbayram/cve-2026-85706

https://github.com/solivaquaant/CVE-2026-85706

https://github.com/guneykabel/cve-2026-85706

https://github.com/ynsmroztas/GitLabSniper

https://github.com/FlowerWitch/CVE-2026-85706_docker_exp

threatcodex at 2026-09-14T12:31:48.619Z ##

CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

rapid7.com/blog/post/etr-cve-2

##

undercodenews@mastodon.social at 2026-09-14T10:29:53.000Z ##

GitLab Faces a Critical Security Emergency as CVE-2026-85706 Enters the CISA Exploited Vulnerabilities List + Video

Introduction: A GitLab Warning That Administrators Cannot Afford to Ignore A maximum-severity vulnerability in self-hosted GitLab installations has moved from a serious security concern to an urgent patching priority after researchers detected apparent exploitation attempts in the wild. The flaw, tracked as CVE-2026-85706, can allow an unauthenticated…

undercodenews.com/gitlab-faces

##

youranonnewsirc@nerdculture.de at 2026-09-14T10:26:20.000Z ##

Recent reports confirm a critical GitLab zero-day (CVE-2026-85706) exploited within 24 hours, alongside new EU Cyber Resilience Act mandates for 24-hour vulnerability reporting. Operational technology (OT) sectors face emerging ransomware threats. Meanwhile, leading AI developers advocate for a slowdown in development due to safety concerns, prompting market shifts. Geopolitically, the BRICS summit addressed rising global tensions and the "weaponization of technology."

#Cybersecurity #TechNews #Geopolitics

##

Analyst207@mastodon.social at 2026-09-14T10:03:11.000Z ##

GitLab Flaw Exploited in Wild, Prompting Urgent Patch Push

A critical GitLab bug, CVE-2026-85706, is under active exploitation, putting sensitive files at risk of exposure due to a path traversal vulnerability that allows unauthenticated users to access arbitrary files. GitLab has urgently pushed a patch to fix the flaw, affecting versions CE/EE 18.7 to 19.3.2.

osintsights.com/gitlab-flaw-ex

#Gitlab #Cve202685706 #PathTraversal #VulnerabilityExploitation #EmergingThreats

##

cyberveille@mastobot.ping.moi at 2026-09-14T09:30:07.000Z ##

📢 [VULN] GitLab : mise à jour de sécurité critique CVE-2026-85706

GitLab a publié le 10 septembre des mises à jour de sécurité. Ce patch critique concerne les versions enterprise et communautaire. Les versions 19.3.2, 19.2.8 et 19.1.8 corrigent un important bug et plusieurs failles de sécurité. GitLab recommande la mise à jour.

🔗 programmez.com/actualites/gitl
💬 discussion : infosec.pub/post/52275402
#CVE #Cyberveille

##

hugovalters@mastodon.social at 2026-09-14T08:40:01.000Z ##

CVE-2026-85706 GitLab CE/EE: unauthenticated arbitrary file read via commits API, CVSS 10. Affects 18.7 up to 19.1.8, 19.2.6, 19.3.2. No patch confirmed yet, restrict access now. valtersit.com/cve/CVE-2026-857 #CVE #GitLab #infosec

##

Analyst207@mastodon.social at 2026-09-14T07:33:15.000Z ##

Hackers Exploit GitLab Flaw in Active Attacks

Hackers are actively exploiting a critical GitLab flaw, CVE-2026-85706, that allows them to read sensitive information like credentials and secrets with just a single HTTP request. This vulnerability enables attackers to access arbitrary files, potentially exposing long-lived secrets and confidential data.

osintsights.com/hackers-exploi

#Gitlab #Cve202685706 #PathTraversal #VulnerabilityExploitation #EmergingThreats

##

netsecio@mastodon.social at 2026-09-13T16:23:52.000Z ##

📰 GitLab Patches Critical CVSS 10.0 Path Traversal Vulnerability

GitLab releases emergency patches for a critical CVSS 10.0 path traversal flaw (CVE-2026-85706). Unauthenticated attackers can read arbitrary files. Active scanning detected. Upgrade self-managed instances NOW. #GitLab #CVE #CyberSecurity #PatchNow

🔗 cyber.netsecops.io/articles/gi

##

undercodenews@mastodon.social at 2026-09-13T12:50:13.000Z ##

GitLab CVE-2026-85706: Critical CVSS 100 Flaw Is Already Being Probed in the Wild + Video

GitLab CVE-2026-85706: Critical CVSS 10.0 Path Traversal Flaw Puts Sensitive Files at Risk A Maximum-Severity Warning for GitLab Administrators A dangerous new GitLab vulnerability has moved from disclosure to real-world reconnaissance with remarkable speed. Tracked as CVE-2026-85706, the flaw carries the maximum CVSS score of 10.0 and affects the repository commits API in…

undercodenews.com/gitlab-cve-2

##

threatnoir at 2026-09-13T05:15:08.200Z ##

2026-W37 — Weekly Threat Roundup

🤖 AI is no longer just a defender's tool: state-sponsored groups and criminals weaponized Claude, ChatGPT, and OpenAI agents to automate exploitation, rebuild malware, and generate one million personalized phishing emails in three days.
🔓 GitLab's CVSS 10.0 path traversal flaw (CVE-2026-85706) wa…

threatnoir.com/weekly/2026-w37

🤖 AI generated summary

##

cyberworldops at 2026-09-12T20:20:00.745Z ##

GitLab CVE-2026-85706 is a maximum-severity path traversal in the repository commits API enabling unauthenticated arbitrary file read on self-managed servers. CISA added it to KEV with a three-day deadline, signaling active exploitation risk. Patch immediately and review for anomalous access to credentials and secrets.

cyberworldops.eu/en/gitlab-pat

##

security_crawler_carl at 2026-09-12T20:01:23.523Z ##

That is a faster turnaround than most people's pizza delivery.

Patch GitLab immediately to remediate CVE-2026-85706 — your self-managed server is the featured product in someone else's highlight reel.

Reward: Complimentary sponsorship credit from Deferred Maintenance Inc. Your inaction keeps them in business.

securityweek.com/gitlab-vulner

(2/2)

##

security_crawler_carl at 2026-09-12T20:01:23.359Z ##

🏆 New Achievement! Speed-Run Sponsored by Your Unpatched GitLab!

This achievement is brought to you by Deferred Maintenance Inc. — when you absolutely, positively need unauthenticated strangers reading every file on your server within a single HTTP request. CVE-2026-85706 scored a perfect ten out of ten on the CVSS scale, because some bugs don't do half measures. GitLab dropped patches on a Thursday. By Friday, WatchTowr was already watching wild exploitation probes roll in. One day. (1/2)

##

undercodenews@mastodon.social at 2026-09-12T18:44:35.000Z ##

GitLab CVSS 100 Vulnerability Reportedly Exploited Within 24 Hours, Leaving Self-Managed Servers Under Immediate Threat + Video

A Critical GitLab Warning for Defenders A critical security vulnerability in GitLab has reportedly moved from public disclosure to active exploitation in roughly a single day. Tracked as CVE-2026-85706, the flaw carries the highest possible CVSS score of 10.0, making it one of the most urgent vulnerabilities facing organizations operating…

undercodenews.com/gitlab-cvss-

##

Matchbook3469@mastodon.social at 2026-09-12T18:12:02.000Z ##

🔵 THREAT INTELLIGENCE

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

Vulnerability | CRITICAL
CVEs: CVE-2026-85706

GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes...

Full analysis:
yazoul.net/news/article/gitlab

by Yazoul AI

#CyberSecurity #CVE #SecurityOps

##

netsecio@mastodon.social at 2026-09-12T17:43:52.000Z ##

📰 GitLab Patches Critical CVSS 10.0 Path Traversal Vulnerability

GitLab releases emergency patches for a critical CVSS 10.0 path traversal flaw (CVE-2026-85706). Unauthenticated attackers can read arbitrary files. Active scanning detected. Upgrade self-managed instances NOW. #GitLab #CVE #CyberSecurity #PatchNow

🔗 cyber.netsecops.io/articles/gi

##

rxerium at 2026-09-12T16:36:01.746Z ##

🚨 Detection for the actively exploited GitLab vulnerability tagged as CVE-2026-85706 (CVSS 10.0) available here:
github.com/projectdiscovery/nu

##

threatcodex@infosec.exchange at 2026-09-14T12:31:48.000Z ##

CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild
#CVE_2026_85706
rapid7.com/blog/post/etr-cve-2

##

youranonnewsirc@nerdculture.de at 2026-09-14T10:26:20.000Z ##

Recent reports confirm a critical GitLab zero-day (CVE-2026-85706) exploited within 24 hours, alongside new EU Cyber Resilience Act mandates for 24-hour vulnerability reporting. Operational technology (OT) sectors face emerging ransomware threats. Meanwhile, leading AI developers advocate for a slowdown in development due to safety concerns, prompting market shifts. Geopolitically, the BRICS summit addressed rising global tensions and the "weaponization of technology."

#Cybersecurity #TechNews #Geopolitics

##

threatnoir@infosec.exchange at 2026-09-13T05:15:08.000Z ##

2026-W37 — Weekly Threat Roundup

🤖 AI is no longer just a defender's tool: state-sponsored groups and criminals weaponized Claude, ChatGPT, and OpenAI agents to automate exploitation, rebuild malware, and generate one million personalized phishing emails in three days.
🔓 GitLab's CVSS 10.0 path traversal flaw (CVE-2026-85706) wa…

threatnoir.com/weekly/2026-w37

#infosec #cybersecurity #threatintel

🤖 AI generated summary

##

cyberworldops@infosec.exchange at 2026-09-12T20:20:00.000Z ##

GitLab CVE-2026-85706 is a maximum-severity path traversal in the repository commits API enabling unauthenticated arbitrary file read on self-managed servers. CISA added it to KEV with a three-day deadline, signaling active exploitation risk. Patch immediately and review for anomalous access to credentials and secrets. #GitLab #CisaKev #InfoSec

cyberworldops.eu/en/gitlab-pat

##

security_crawler_carl@infosec.exchange at 2026-09-12T20:01:23.000Z ##

That is a faster turnaround than most people's pizza delivery.

Patch GitLab immediately to remediate CVE-2026-85706 — your self-managed server is the featured product in someone else's highlight reel.

Reward: Complimentary sponsorship credit from Deferred Maintenance Inc. Your inaction keeps them in business.

securityweek.com/gitlab-vulner

#GitLab #CyberSecurity #ZeroDay #PathTraversal #CVE #PatchedOrPerish (2/2)

##

security_crawler_carl@infosec.exchange at 2026-09-12T20:01:23.000Z ##

🏆 New Achievement! Speed-Run Sponsored by Your Unpatched GitLab!

This achievement is brought to you by Deferred Maintenance Inc. — when you absolutely, positively need unauthenticated strangers reading every file on your server within a single HTTP request. CVE-2026-85706 scored a perfect ten out of ten on the CVSS scale, because some bugs don't do half measures. GitLab dropped patches on a Thursday. By Friday, WatchTowr was already watching wild exploitation probes roll in. One day. (1/2)

##

netsecio@mastodon.social at 2026-09-12T17:43:52.000Z ##

📰 GitLab Patches Critical CVSS 10.0 Path Traversal Vulnerability

GitLab releases emergency patches for a critical CVSS 10.0 path traversal flaw (CVE-2026-85706). Unauthenticated attackers can read arbitrary files. Active scanning detected. Upgrade self-managed instances NOW. #GitLab #CVE #CyberSecurity #PatchNow

🔗 cyber.netsecops.io/articles/gi

##

rxerium@infosec.exchange at 2026-09-12T16:36:01.000Z ##

🚨 Detection for the actively exploited GitLab vulnerability tagged as CVE-2026-85706 (CVSS 10.0) available here:
github.com/projectdiscovery/nu

##

obivan@infosec.exchange at 2026-09-12T08:46:52.000Z ##

PoC for unauthenticated arbitrary file read on Gitlab github.com/guneykabel/cve-2026

##

beyondmachines1@infosec.exchange at 2026-09-12T08:01:13.000Z ##

GitLab Patches Critical Path Traversal Flaw Under Active Exploitation

GitLab released emergency patches for 18 vulnerabilities, including a CVSS 10.0 path traversal flaw (CVE-2026-85706) that allows unauthenticated attackers to read sensitive server files and is currently seeing active probes.

**If you run a self-hosted GitLab instance, update it now to version 19.3.2, 19.2.6, or 19.1.8. One of these flaws is already being exploited and lets anyone read files off your server without logging in. All it takes is one public project to exist on the instance. If you can't patch right away, take the instance off the public internet and check your logs for POST requests to the repository commits API containing a "file.path" parameter to see if you've already been probed.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-09-12T04:20:00.000Z ##

GitLab path-traversal CVE-2026-85706 (CVSS 10.0) is being exploited in the wild one day after disclosure. It allows unauthenticated arbitrary file read with a single HTTP request, exposing secrets and enabling further compromise. Prioritize immediate patching and review logs. #GitLab #PathTraversal #ThreatIntel

cyberworldops.eu/en/critical-g

##

thehackerwire@mastodon.social at 2026-09-12T04:00:22.000Z ##

🔴 CVE-2026-85706 - Critical (10)

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab serve...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

threatnoir@infosec.exchange at 2026-09-12T01:05:48.000Z ##

⚠️ CRITICAL: GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

GitLab patched a CVSS 10.0 unauthenticated file-read vulnerability (CVE-2026-85706) in the repository commits API that allows attackers to read arbitrary files from affected servers. In-the-wild probes are already active. Attackers can extract credentials, SSH keys, and other sensitive data without…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

secdb@infosec.exchange at 2026-09-11T21:00:27.000Z ##

🚨 [CISA-2026:0911] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-42016 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-42018 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-84869 (secdb.nttzen.cloud/cve/detail/)
- Name: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ConnectWise
- Product: ScreenConnect
- Notes: connectwise.com/company/trust/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-85706 (secdb.nttzen.cloud/cve/detail/)
- Name: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: GitLab
- Product: Community Edition and Enterprise Edition
- Notes: docs.gitlab.com/releases/patch ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260911 #cisa20260911 #cve_2026_42016 #cve_2026_42018 #cve_2026_84869 #cve_2026_85706 #cve202642016 #cve202642018 #cve202684869 #cve202685706

##

ssvc@infosec.exchange at 2026-09-11T20:20:10.000Z ##

@cR0w no mention of exploitation from CNA GitLab

CVE-2026-85706 - Path Traversal issue in repository commits API impacts GitLab CE/EE

GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Impacted Versions: GitLab CE/EE: all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2
CVSS 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N)

Thanks s3ntago for reporting this vulnerability through our HackerOne bug bounty program.

docs.gitlab.com/releases/patch

##

cisakevtracker@mastodon.social at 2026-09-11T20:00:54.000Z ##

CVE ID: CVE-2026-85706
Vendor: GitLab
Product: Community Edition and Enterprise Edition
Date Added: 2026-09-11
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cR0w@infosec.exchange at 2026-09-11T19:55:48.000Z ##

CVE-2026-85706 is now in the KEV but the CVE still isn't published. LMAO. Go hack and patch more GitLab shit.

##

DarkWebInformer@infosec.exchange at 2026-09-11T17:30:12.000Z ##

🚨 CVE-2026-85706: An unauthenticated arbitrary file read on Gitlab CE-EE affecting versions: 18.7–19.1.7; 19.2.0–19.2.5; 19.3.0–19.3.1

PoC: github.com/guneykabel/cve-2026

##

DarkWebInformer@infosec.exchange at 2026-09-11T17:24:17.000Z ##

🚨 GitLab CVSS 10 vulnerability exploited just one day after disclosure

Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances.

The flaw allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server using a single HTTP request.

Affected versions include:

• GitLab 18.7 through versions before 19.1.8
• GitLab 19.2 through versions before 19.2.6
• GitLab 19.3 through versions before 19.3.2

GitLab disclosed and patched the vulnerability on September 10.

Just one day later, watchTowr began observing in-the-wild exploitation attempts and warns that mass exploitation is likely to follow.

Administrators should upgrade immediately to GitLab 19.1.8, 19.2.6, 19.3.2, or a newer supported release.

GitLab.com is already patched.

Source: docs.gitlab.com/releases/patch

##

jbhall56@infosec.exchange at 2026-09-11T14:05:07.000Z ##

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. bleepingcomputer.com/news/secu

##

CVE-2026-90703
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-14T10:17:05.610000

2 posts

A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

offseq at 2026-09-14T10:30:25.122Z ##

D-Link DWR-M921 v1.1.52 is vulnerable to CRITICAL OS command injection (CVE-2026-90703, CVSS 9.4). No patch yet, public exploit out. Restrict access & monitor logs. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-14T10:30:25.000Z ##

D-Link DWR-M921 v1.1.52 is vulnerable to CRITICAL OS command injection (CVE-2026-90703, CVSS 9.4). No patch yet, public exploit out. Restrict access & monitor logs. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #RouterSecurity #Infosec

##

CVE-2026-90680
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-14T06:31:26

2 posts

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer overflow. The attack can be launched remotely.

thehackerwire@mastodon.social at 2026-09-14T05:00:51.000Z ##

🔴 CVE-2026-90680 - Critical (9.9)

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T05:00:51.000Z ##

🔴 CVE-2026-90680 - Critical (9.9)

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-23789
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-14T03:30:29

2 posts

An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driver (due to improper cleanup of dma_buf references during error handling) leads to kernel memory corruption and potential arbitrary code execution.

thehackerwire@mastodon.social at 2026-09-14T03:00:10.000Z ##

🟠 CVE-2026-23789 - High (7.8)

An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T03:00:10.000Z ##

🟠 CVE-2026-23789 - High (7.8)

An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-33963
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-14T03:30:29

2 posts

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.

thehackerwire@mastodon.social at 2026-09-14T02:59:57.000Z ##

🟠 CVE-2026-33963 - High (7.5)

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T02:59:57.000Z ##

🟠 CVE-2026-33963 - High (7.5)

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-31278
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-14T02:17:14.080000

2 posts

An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.

1 repos

https://github.com/mda1r/CVE-2026-31278

thehackerwire@mastodon.social at 2026-09-14T02:59:48.000Z ##

🟠 CVE-2026-31278 - High (7.7)

An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T02:59:48.000Z ##

🟠 CVE-2026-31278 - High (7.7)

An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90608
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-14T01:16:28.130000

4 posts

A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.

thehackerwire@mastodon.social at 2026-09-14T03:01:32.000Z ##

🔴 CVE-2026-90608 - Critical (9.9)

A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-14T01:30:25.024Z ##

CVE-2026-90608: Totolink A3002MU routers have a CRITICAL buffer overflow (CVSS 9.4) in /boafrm/formPortFw. Exploit code is public; RCE possible. No patch — restrict external access & monitor vendor updates. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-14T03:01:32.000Z ##

🔴 CVE-2026-90608 - Critical (9.9)

A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-14T01:30:25.000Z ##

CVE-2026-90608: Totolink A3002MU routers have a CRITICAL buffer overflow (CVSS 9.4) in /boafrm/formPortFw. Exploit code is public; RCE possible. No patch — restrict external access & monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202690608 #RouterSecurity

##

CVE-2026-90607
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-14T01:16:27.870000

4 posts

A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.

thehackerwire@mastodon.social at 2026-09-14T03:01:46.000Z ##

🔴 CVE-2026-90607 - Critical (9.9)

A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-14T03:00:25.088Z ##

Totolink A3002MU routers hit by CRITICAL (CVSS 9.4) buffer overflow (CVE-2026-90607) in formNewSchedule. Public exploit code available. Restrict remote access & monitor systems until a patch is released. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-14T03:01:46.000Z ##

🔴 CVE-2026-90607 - Critical (9.9)

A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-14T03:00:25.000Z ##

Totolink A3002MU routers hit by CRITICAL (CVSS 9.4) buffer overflow (CVE-2026-90607) in formNewSchedule. Public exploit code available. Restrict remote access & monitor systems until a patch is released. radar.offseq.com/threat/cve-20 #OffSeq #CVE202690607 #RouterSecurity #Infosec

##

CVE-2026-90606
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-14T00:31:35

6 posts

A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

offseq at 2026-09-14T06:00:25.301Z ##

CVE-2026-90606: HIGH-severity buffer overflow in Totolink A3002MU Hh-B20211125.1046 (boa/formIpv6Setup). Public exploit disclosed. RCE or DoS possible. Restrict access & monitor IPv6 setup. No patch yet. radar.offseq.com/threat/a-secu

##

thehackerwire@mastodon.social at 2026-09-14T01:01:03.000Z ##

🔴 CVE-2026-90606 - Critical (9.9)

A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer ov...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-14T00:00:35.339Z ##

CVE-2026-90606: CRITICAL buffer overflow in Totolink A3002MU (Hh-B20211125.1046). Remote attackers can exploit static_ipv6 in /boafrm/formIpv6Setup. Exploit is public — review device exposure now. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-14T06:00:25.000Z ##

CVE-2026-90606: HIGH-severity buffer overflow in Totolink A3002MU Hh-B20211125.1046 (boa/formIpv6Setup). Public exploit disclosed. RCE or DoS possible. Restrict access & monitor IPv6 setup. No patch yet. radar.offseq.com/threat/a-secu #OffSeq #Vuln #IoTSecurity #BufferOverflow

##

thehackerwire@mastodon.social at 2026-09-14T01:01:03.000Z ##

🔴 CVE-2026-90606 - Critical (9.9)

A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer ov...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-14T00:00:35.000Z ##

CVE-2026-90606: CRITICAL buffer overflow in Totolink A3002MU (Hh-B20211125.1046). Remote attackers can exploit static_ipv6 in /boafrm/formIpv6Setup. Exploit is public — review device exposure now. radar.offseq.com/threat/cve-20 #OffSeq #CVE202690606 #RouterSecurity #NetSec

##

CVE-2026-90605
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-14T00:16:57.447000

2 posts

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

thehackerwire@mastodon.social at 2026-09-14T01:00:54.000Z ##

🔴 CVE-2026-90605 - Critical (9.9)

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T01:00:54.000Z ##

🔴 CVE-2026-90605 - Critical (9.9)

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82078
(9.1 CRITICAL)

EPSS: 1.69%

updated 2026-09-14T00:16:56.777000

1 posts

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on

2 repos

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

https://github.com/virologi-info/papercut-toolkit

sayzard@mastodon.sayzard.org at 2026-09-14T12:46:09.000Z ##

PaperCut Attacker (Russian Linked) Uses AI Agents to Compromise 440 Instances

러시아어권으로 추정되는 공격자가 PaperCut NG/MF의 인증 우회·RCE 체인(CVE-2026-81578, CVE-2026-82078)을 악용해 48개국 395개 조직의 최소 440개 인스턴스를 침해한 것으로 보고됐다. 공격자는 OpenAI Codex, DeepSeek 모델, Hindsight의 지속 메모리, AionUi 멀티 에이전트 작업 공간을 결합해 취약점 분석부터 익스플로잇 수정, 표적 분류, 재시도, AD 정찰까지 자동화했으며, 실제 공격 개시 후 2...

swapupdate.in/papercut-attacke

##

CVE-2026-81578
(9.8 CRITICAL)

EPSS: 1.62%

updated 2026-09-14T00:16:56.207000

1 posts

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

2 repos

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

https://github.com/virologi-info/papercut-toolkit

sayzard@mastodon.sayzard.org at 2026-09-14T12:46:09.000Z ##

PaperCut Attacker (Russian Linked) Uses AI Agents to Compromise 440 Instances

러시아어권으로 추정되는 공격자가 PaperCut NG/MF의 인증 우회·RCE 체인(CVE-2026-81578, CVE-2026-82078)을 악용해 48개국 395개 조직의 최소 440개 인스턴스를 침해한 것으로 보고됐다. 공격자는 OpenAI Codex, DeepSeek 모델, Hindsight의 지속 메모리, AionUi 멀티 에이전트 작업 공간을 결합해 취약점 분석부터 익스플로잇 수정, 표적 분류, 재시도, AD 정찰까지 자동화했으며, 실제 공격 개시 후 2...

swapupdate.in/papercut-attacke

##

CVE-2026-15891
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-13T23:16:27.870000

2 posts

The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result. That macro is a pure expression that does not assign to gw, so gw retained its NULL initializer regardless of the list contents. The code then derefere

thehackerwire@mastodon.social at 2026-09-13T23:59:47.000Z ##

🟠 CVE-2026-15891 - High (7.5)

The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T23:59:47.000Z ##

🟠 CVE-2026-15891 - High (7.5)

The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88793
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-13T21:31:54

2 posts

The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing unauthenticated attackers to store arbitrary web scripts which will execute in the session of any user viewing the affected content, including an adminis

thehackerwire@mastodon.social at 2026-09-14T03:02:00.000Z ##

🟠 CVE-2026-88793 - High (8.8)

The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T03:02:00.000Z ##

🟠 CVE-2026-88793 - High (8.8)

The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88802
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-13T21:17:02.323000

2 posts

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to destroy arbitrary posts, pages and media attachments, bypassing the trash.

thehackerwire@mastodon.social at 2026-09-14T04:00:04.000Z ##

🟠 CVE-2026-88802 - High (7.5)

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T04:00:04.000Z ##

🟠 CVE-2026-88802 - High (7.5)

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85129
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-13T21:17:02.063000

2 posts

The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web scripts which will execute for anyone viewing the site, including administrators. The same request destroys the site's

thehackerwire@mastodon.social at 2026-09-13T23:59:58.000Z ##

🟠 CVE-2026-85129 - High (8.8)

The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T23:59:58.000Z ##

🟠 CVE-2026-85129 - High (8.8)

The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81648
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-09-13T21:17:01.930000

2 posts

The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wallet credentials in cleartext.

thehackerwire@mastodon.social at 2026-09-14T05:03:02.000Z ##

🔴 CVE-2026-81648 - Critical (10)

The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T05:03:02.000Z ##

🔴 CVE-2026-81648 - Critical (10)

The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74933
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-13T21:17:01.800000

2 posts

The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page.

thehackerwire@mastodon.social at 2026-09-14T04:00:26.000Z ##

🟠 CVE-2026-74933 - High (8.8)

The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T04:00:26.000Z ##

🟠 CVE-2026-74933 - High (8.8)

The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-37008
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-13T21:17:01.303000

2 posts

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling ctypes.CDLL(None) loads the C library without relying in any import statements. In other words, a within-process sandbox

thehackerwire@mastodon.social at 2026-09-14T04:00:15.000Z ##

🟠 CVE-2026-37008 - High (8.1)

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete obj...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T04:00:15.000Z ##

🟠 CVE-2026-37008 - High (8.1)

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete obj...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-29811
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-13T20:16:51.020000

2 posts

CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.

thehackerwire@mastodon.social at 2026-09-13T20:59:49.000Z ##

🟠 CVE-2026-29811 - High (7.7)

CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T20:59:49.000Z ##

🟠 CVE-2026-29811 - High (7.7)

CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90783
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-13T13:16:29.560000

2 posts

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.

thehackerwire@mastodon.social at 2026-09-13T13:59:47.000Z ##

🟠 CVE-2026-90783 - High (7.8)

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an unde...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T13:59:47.000Z ##

🟠 CVE-2026-90783 - High (7.8)

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an unde...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90778
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-13T12:31:19

2 posts

SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static buffer and crash the process.

thehackerwire@mastodon.social at 2026-09-13T13:01:05.000Z ##

🟠 CVE-2026-90778 - High (7.5)

SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag para...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T13:01:05.000Z ##

🟠 CVE-2026-90778 - High (7.5)

SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag para...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90777
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-13T12:31:19

2 posts

ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code during deserialization when loaded through the initialization or fine-tuning path.

thehackerwire@mastodon.social at 2026-09-13T13:00:25.000Z ##

🟠 CVE-2026-90777 - High (8.8)

ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code during deseri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T13:00:25.000Z ##

🟠 CVE-2026-90777 - High (8.8)

ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code during deseri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90774
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-13T12:31:19

2 posts

rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write files outside the configured upload directory to arbitrary locations.

thehackerwire@mastodon.social at 2026-09-13T12:00:58.000Z ##

🟠 CVE-2026-90774 - High (7.5)

rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T12:00:58.000Z ##

🟠 CVE-2026-90774 - High (7.5)

rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90770
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-13T12:31:12

2 posts

Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters via the /monitor/run_test/ endpoint to execute arbitrary commands as the Spug process user.

thehackerwire@mastodon.social at 2026-09-13T12:02:32.000Z ##

🟠 CVE-2026-90770 - High (8.8)

Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T12:02:32.000Z ##

🟠 CVE-2026-90770 - High (8.8)

Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90768
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-13T12:31:12

2 posts

CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses by sending requests to task view and delete endpoints without ownership verification.

thehackerwire@mastodon.social at 2026-09-13T12:01:09.000Z ##

🟠 CVE-2026-90768 - High (8.1)

CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T12:01:09.000Z ##

🟠 CVE-2026-90768 - High (8.1)

CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90561
(8.7 HIGH)

EPSS: 0.00%

updated 2026-09-13T12:31:11

4 posts

Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious script tags in rich text fields that execute in an Editor or Super Admin's session when the preview pane is expanded, enabling account takeover.

offseq at 2026-09-14T04:30:23.727Z ##

Strapi 4.x – 4.26.2 & 5.x<5.48.1: CRITICAL stored XSS (CVE-2026-90561, CVSS 8.7) in WYSIWYG preview lets Author roles execute malicious scripts in higher-privileged sessions. Restrict roles & monitor vendor updates. radar.offseq.com/threat/strapi

##

thehackerwire@mastodon.social at 2026-09-13T12:02:51.000Z ##

🟠 CVE-2026-90561 - High (8.7)

Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-14T04:30:23.000Z ##

Strapi 4.x – 4.26.2 & 5.x<5.48.1: CRITICAL stored XSS (CVE-2026-90561, CVSS 8.7) in WYSIWYG preview lets Author roles execute malicious scripts in higher-privileged sessions. Restrict roles & monitor vendor updates. radar.offseq.com/threat/strapi #OffSeq #Strapi #XSS #Infosec

##

thehackerwire@mastodon.social at 2026-09-13T12:02:51.000Z ##

🟠 CVE-2026-90561 - High (8.7)

Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90562
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-13T12:31:11

4 posts

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access.

thehackerwire@mastodon.social at 2026-09-13T13:01:27.000Z ##

🟠 CVE-2026-90562 - High (8.1)

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-13T12:00:24.616Z ##

LangBot <4.10.11 is affected by CRITICAL CVE-2026-90562: password reset keys generated with only 24 bits of entropy & no rate limiting let attackers brute-force admin resets. Upgrade to 4.10.11+! radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-13T13:01:27.000Z ##

🟠 CVE-2026-90562 - High (8.1)

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-13T12:00:24.000Z ##

LangBot <4.10.11 is affected by CRITICAL CVE-2026-90562: password reset keys generated with only 24 bits of entropy & no rate limiting let attackers brute-force admin resets. Upgrade to 4.10.11+! radar.offseq.com/threat/cve-20 #OffSeq #CVE202690562 #infosec #AppSec

##

CVE-2026-86406
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-13T12:31:09

2 posts

The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan without paying for it. Where the site owner has mapped a plan to a privileged ro

thehackerwire@mastodon.social at 2026-09-13T14:00:58.000Z ##

🟠 CVE-2026-86406 - High (7.5)

The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T14:00:58.000Z ##

🟠 CVE-2026-86406 - High (7.5)

The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90780
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-13T12:17:17.093000

2 posts

SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages with oversized headers to overflow the static buffer and crash the process.

thehackerwire@mastodon.social at 2026-09-13T13:00:04.000Z ##

🟠 CVE-2026-90780 - High (7.5)

SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T13:00:04.000Z ##

🟠 CVE-2026-90780 - High (7.5)

SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90779
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-13T12:17:16.960000

2 posts

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client process.

thehackerwire@mastodon.social at 2026-09-13T13:01:17.000Z ##

🟠 CVE-2026-90779 - High (7.5)

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T13:01:17.000Z ##

🟠 CVE-2026-90779 - High (7.5)

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90776
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-13T12:17:16.547000

2 posts

Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and block the Node.js event loop for several seconds, causing denial of service.

thehackerwire@mastodon.social at 2026-09-13T13:00:15.000Z ##

🟠 CVE-2026-90776 - High (7.5)

Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T13:00:15.000Z ##

🟠 CVE-2026-90776 - High (7.5)

Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90775
(6.5 MEDIUM)

EPSS: 0.00%

updated 2026-09-13T12:17:16.400000

2 posts

PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, causing the PostgreSQL backend process to crash and terminate all cluster sessions.

offseq at 2026-09-13T13:30:23.119Z ##

CVE-2026-90775: HIGH severity vuln in PostGIS address_standardizer (≤3.7.0) allows out-of-bounds read via unvalidated Weight parameter, crashing PostgreSQL backend (DoS). Patch status pending — monitor vendor updates. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-13T13:30:23.000Z ##

CVE-2026-90775: HIGH severity vuln in PostGIS address_standardizer (≤3.7.0) allows out-of-bounds read via unvalidated Weight parameter, crashing PostgreSQL backend (DoS). Patch status pending — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #PostGIS #Vuln

##

CVE-2026-90772
(7.6 HIGH)

EPSS: 0.00%

updated 2026-09-13T11:17:01.780000

2 posts

Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing JavaScript in every user's browser that views search results.

thehackerwire@mastodon.social at 2026-09-13T12:02:42.000Z ##

🟠 CVE-2026-90772 - High (7.6)

Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T12:02:42.000Z ##

🟠 CVE-2026-90772 - High (7.6)

Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90769
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-13T11:17:01.270000

2 posts

Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bound services through the application server's direct HTTP requests.

thehackerwire@mastodon.social at 2026-09-13T12:01:20.000Z ##

🟠 CVE-2026-90769 - High (7.7)

Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T12:01:20.000Z ##

🟠 CVE-2026-90769 - High (7.7)

Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90510
(8.3 HIGH)

EPSS: 0.00%

updated 2026-09-13T11:16:59.827000

2 posts

A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java. The manipulation leads to use of hard-coded cryptographic key . The attack is possible to b

thehackerwire@mastodon.social at 2026-09-13T14:00:49.000Z ##

🟠 CVE-2026-90510 - High (8.3)

A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/drom...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T14:00:49.000Z ##

🟠 CVE-2026-90510 - High (8.3)

A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/drom...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89080
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-13T11:16:59.650000

2 posts

The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.

thehackerwire@mastodon.social at 2026-09-13T14:01:09.000Z ##

🟠 CVE-2026-89080 - High (7.5)

The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the sec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T14:01:09.000Z ##

🟠 CVE-2026-89080 - High (7.5)

The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the sec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89690
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-13T09:33:34

2 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: defer vfree of compound ops to fix rpc_status UAF The rpc_status netlink dumpit walks every in-flight svc_rqst under rcu_read_lock and, for NFSv4 requests, reads opnums out of args->ops[]. But args->ops is a separate vmalloc buffer freed synchronously by vfree() in nfsd4_release_compoundargs() at the end of every compound.

thehackerwire@mastodon.social at 2026-09-13T18:00:20.000Z ##

🟠 CVE-2026-89690 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: defer vfree of compound ops to fix rpc_status UAF

The rpc_status netlink dumpit walks every in-flight svc_rqst under
rcu_read_lock and, for NFSv4 requests, reads opnums ou...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T18:00:20.000Z ##

🟠 CVE-2026-89690 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: defer vfree of compound ops to fix rpc_status UAF

The rpc_status netlink dumpit walks every in-flight svc_rqst under
rcu_read_lock and, for NFSv4 requests, reads opnums ou...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89696
(7.5 HIGH)

EPSS: 0.67%

updated 2026-09-13T09:33:32

2 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref When CONFIG_NFSD_V4_2_INTER_SSC is enabled, nfsd4_putfh() can return success with fh_dentry and fh_export both NULL if fh_verify() returns nfserr_stale and putfh->no_verify is true. The NFSD4_FH_FOREIGN flag is set, but the compound dispatch loop only uses this

thehackerwire@mastodon.social at 2026-09-13T19:00:21.000Z ##

🟠 CVE-2026-89696 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref

When CONFIG_NFSD_V4_2_INTER_SSC is enabled, nfsd4_putfh() can return
success with fh_dentry and fh_export bo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T19:00:21.000Z ##

🟠 CVE-2026-89696 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref

When CONFIG_NFSD_V4_2_INTER_SSC is enabled, nfsd4_putfh() can return
success with fh_dentry and fh_export bo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89612
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-09-13T09:33:31

2 posts

In the Linux kernel, the following vulnerability has been resolved: ntfs: reject invalid MFT LCNs from boot sector The NTFS boot sector stores the MFT and MFTMirr locations as unsigned 64-bit LCNs, but parse_ntfs_boot_sector() decoded them into an s64. A crafted high-bit value could therefore become negative and pass the existing upper-bound check. The invalid value then propagated into the MFT

thehackerwire@mastodon.social at 2026-09-13T23:00:01.000Z ##

🔴 CVE-2026-89612 - Critical (9.8)

In the Linux kernel, the following vulnerability has been resolved:

ntfs: reject invalid MFT LCNs from boot sector

The NTFS boot sector stores the MFT and MFTMirr locations as unsigned
64-bit LCNs, but parse_ntfs_boot_sector() decoded them into ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T23:00:01.000Z ##

🔴 CVE-2026-89612 - Critical (9.8)

In the Linux kernel, the following vulnerability has been resolved:

ntfs: reject invalid MFT LCNs from boot sector

The NTFS boot sector stores the MFT and MFTMirr locations as unsigned
64-bit LCNs, but parse_ntfs_boot_sector() decoded them into ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89611
(9.8 CRITICAL)

EPSS: 0.38%

updated 2026-09-13T09:33:31

2 posts

In the Linux kernel, the following vulnerability has been resolved: ntfs: validate non-resident attribute offsets ntfs_attr_update_meta() shifts the attribute name when converting between non-sparse and sparse attributes. Converting to sparse also adds the compressed_size field before the name and mapping pairs, requiring eight additional bytes in the attribute record. However, the validator do

thehackerwire@mastodon.social at 2026-09-13T22:59:51.000Z ##

🔴 CVE-2026-89611 - Critical (9.8)

In the Linux kernel, the following vulnerability has been resolved:

ntfs: validate non-resident attribute offsets

ntfs_attr_update_meta() shifts the attribute name when converting between
non-sparse and sparse attributes. Converting to sparse al...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T22:59:51.000Z ##

🔴 CVE-2026-89611 - Critical (9.8)

In the Linux kernel, the following vulnerability has been resolved:

ntfs: validate non-resident attribute offsets

ntfs_attr_update_meta() shifts the attribute name when converting between
non-sparse and sparse attributes. Converting to sparse al...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89697
(9.1 CRITICAL)

EPSS: 0.60%

updated 2026-09-13T09:33:30

2 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() The BOTH_TIME_SET branch calls fh_verify() early so setattr_prepare() can inspect the dentry. This causes nfsd_setattr() to skip fh_want_write(), so notify_change() runs without a mount write reference. Add the missing fh_want_write() call after the ear

thehackerwire@mastodon.social at 2026-09-13T19:59:53.000Z ##

🔴 CVE-2026-89697 - Critical (9.1)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()

The BOTH_TIME_SET branch calls fh_verify() early so setattr_prepare()
can inspect the dentry. This ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T19:59:53.000Z ##

🔴 CVE-2026-89697 - Critical (9.1)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()

The BOTH_TIME_SET branch calls fh_verify() early so setattr_prepare()
can inspect the dentry. This ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80981
(9.8 CRITICAL)

EPSS: 0.59%

updated 2026-09-13T09:33:25

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() smc_llc_srv_add_link() keeps add_llc pointing into the queue entry: add_llc = &qentry->msg.add_link; smc_llc.c:1482 ... smc_llc_save_add_link_info(link_new, add_llc); smc_llc.c:1494 smc_llc_flow_qentry_del(&lgr->llc_flow_lcl); smc_llc.c:1495 ..

offseq@infosec.exchange at 2026-09-12T06:00:24.000Z ##

CVE-2026-80981: Linux kernel net/smc HIGH severity use-after-free in smc_llc_srv_add_link(). Risk of memory corruption & escalation. Patch when available! Details: radar.offseq.com/threat/in-the #OffSeq #Linux #Infosec #Vulnerability

##

CVE-2026-89750
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-13T09:32:30

2 posts

In the Linux kernel, the following vulnerability has been resolved: tracing/user_events: Clear copied tracing state before fork duplication dup_task_struct() copies user_event_mm from the parent into the child, without grabbing a reference to it. user_event_mm_dup() should replace it, but it leaves that copied pointer unmodified if user_event_mm_alloc() fails. When the child exits, user_event_m

thehackerwire@mastodon.social at 2026-09-13T16:01:19.000Z ##

🟠 CVE-2026-89750 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

tracing/user_events: Clear copied tracing state before fork duplication

dup_task_struct() copies user_event_mm from the parent into the child,
without grabbing a reference to it...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T16:01:19.000Z ##

🟠 CVE-2026-89750 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

tracing/user_events: Clear copied tracing state before fork duplication

dup_task_struct() copies user_event_mm from the parent into the child,
without grabbing a reference to it...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89744
(8.4 HIGH)

EPSS: 0.14%

updated 2026-09-13T09:32:30

2 posts

In the Linux kernel, the following vulnerability has been resolved: device property: fix infinite loop in fwnode_for_each_child_node() When iterate over children of a fwnode that has a secondary fwnode, fwnode_get_next_child_node() can enter an infinite loop if the secondary fwnode has more than one child. Parent Child (Primary fwnode) FWa: {FWa1, FWa2, F

thehackerwire@mastodon.social at 2026-09-13T15:00:42.000Z ##

🟠 CVE-2026-89744 - High (8.4)

In the Linux kernel, the following vulnerability has been resolved:

device property: fix infinite loop in fwnode_for_each_child_node()

When iterate over children of a fwnode that has a secondary fwnode,
fwnode_get_next_child_node() can enter an ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T15:00:42.000Z ##

🟠 CVE-2026-89744 - High (8.4)

In the Linux kernel, the following vulnerability has been resolved:

device property: fix infinite loop in fwnode_for_each_child_node()

When iterate over children of a fwnode that has a secondary fwnode,
fwnode_get_next_child_node() can enter an ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89758
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-13T09:32:30

2 posts

In the Linux kernel, the following vulnerability has been resolved: mm/mempolicy: skip non-present PMDs when queueing folios Patch series "mm: handle device-private PMDs in walk callbacks", v3. Since commit 368076f52ebe ("mm/huge_memory: add device-private THP support to PMD operations") a PMD may hold a device-private swap entry whenever an HMM-based GPU driver migrates an anonymous THP folio

thehackerwire@mastodon.social at 2026-09-13T15:00:31.000Z ##

🟠 CVE-2026-89758 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

mm/mempolicy: skip non-present PMDs when queueing folios

Patch series "mm: handle device-private PMDs in walk callbacks", v3.

Since commit 368076f52ebe ("mm/huge_memory: add de...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T15:00:31.000Z ##

🟠 CVE-2026-89758 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

mm/mempolicy: skip non-present PMDs when queueing folios

Patch series "mm: handle device-private PMDs in walk callbacks", v3.

Since commit 368076f52ebe ("mm/huge_memory: add de...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89754
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-13T09:32:30

2 posts

In the Linux kernel, the following vulnerability has been resolved: mm/pagewalk: fix stale walk->action escaping walk_pmd_range() If ->pmd_entry() sets walk->action = ACTION_AGAIN, the pmd_none() check is retried. The PMD entry may be cleared at the point of retry. In this case, if walk->ops->install_pte is not specified, the code continues to the next PMD entry in the range without resetting

thehackerwire@mastodon.social at 2026-09-13T10:00:06.000Z ##

🟠 CVE-2026-89754 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

mm/pagewalk: fix stale walk->action escaping walk_pmd_range()

If ->pmd_entry() sets walk->action = ACTION_AGAIN, the pmd_none() check is
retried. The PMD entry may be cleared a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T10:00:06.000Z ##

🟠 CVE-2026-89754 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

mm/pagewalk: fix stale walk->action escaping walk_pmd_range()

If ->pmd_entry() sets walk->action = ACTION_AGAIN, the pmd_none() check is
retried. The PMD entry may be cleared a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89762
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-13T09:32:30

2 posts

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix cred UAF caused by begin_current_label_crit_section() AppArmor's begin_current_label_crit_section() is a scary function called from lots of LSM hooks (in particular VFS/socket-related ones) that checks if the label referenced by the current creds is marked FLAG_STALE, and if so, attempts to use aa_replace_current_l

thehackerwire@mastodon.social at 2026-09-13T09:00:24.000Z ##

🟠 CVE-2026-89762 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

apparmor: fix cred UAF caused by begin_current_label_crit_section()

AppArmor's begin_current_label_crit_section() is a scary function called
from lots of LSM hooks (in particula...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T09:00:24.000Z ##

🟠 CVE-2026-89762 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

apparmor: fix cred UAF caused by begin_current_label_crit_section()

AppArmor's begin_current_label_crit_section() is a scary function called
from lots of LSM hooks (in particula...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89761
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-13T09:32:30

2 posts

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix out-of-bounds write when null terminating a label vec aa_vec_unique() null terminates at vec[n - dups] when VEC_FLAG_TERMINATE is passed. If the components are all distinct no duplicates are dropped, dups is 0 and the terminator goes to vec[n], so the caller has to provide room for n + 1 entries. aa_label_strn_par

thehackerwire@mastodon.social at 2026-09-13T08:00:11.000Z ##

🟠 CVE-2026-89761 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

apparmor: fix out-of-bounds write when null terminating a label vec

aa_vec_unique() null terminates at vec[n - dups] when VEC_FLAG_TERMINATE
is passed. If the components are all...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T08:00:11.000Z ##

🟠 CVE-2026-89761 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

apparmor: fix out-of-bounds write when null terminating a label vec

aa_vec_unique() null terminates at vec[n - dups] when VEC_FLAG_TERMINATE
is passed. If the components are all...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89736
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-13T09:32:29

2 posts

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_audio: Fix use-after-free on sound card disconnect g_audio_cleanup() invokes snd_card_free_when_closed() to initiate sound card teardown and immediately frees the underlying struct snd_uac_chip context. However, snd_card_free_when_closed() returns asynchronously while ALSA control elements (kctls) remain open in u

thehackerwire@mastodon.social at 2026-09-13T17:00:05.000Z ##

🟠 CVE-2026-89736 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: u_audio: Fix use-after-free on sound card disconnect

g_audio_cleanup() invokes snd_card_free_when_closed() to initiate sound
card teardown and immediately frees the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T17:00:05.000Z ##

🟠 CVE-2026-89736 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: u_audio: Fix use-after-free on sound card disconnect

g_audio_cleanup() invokes snd_card_free_when_closed() to initiate sound
card teardown and immediately frees the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89685
(7.5 HIGH)

EPSS: 0.43%

updated 2026-09-13T09:32:28

2 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix clock domain mismatch in clients_still_reclaiming() clients_still_reclaiming() computes a deadline from nn->boot_time (CLOCK_REALTIME, ~1.7 billion) but compares it against ktime_get_boottime_seconds() (CLOCK_BOOTTIME, seconds since boot). The comparison is always false — it would take ~54 years of uptime for BOOTTIME

thehackerwire@mastodon.social at 2026-09-14T05:03:12.000Z ##

🟠 CVE-2026-89685 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix clock domain mismatch in clients_still_reclaiming()

clients_still_reclaiming() computes a deadline from nn->boot_time
(CLOCK_REALTIME, ~1.7 billion) but compares it ag...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T05:03:12.000Z ##

🟠 CVE-2026-89685 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix clock domain mismatch in clients_still_reclaiming()

clients_still_reclaiming() computes a deadline from nn->boot_time
(CLOCK_REALTIME, ~1.7 billion) but compares it ag...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89771
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-13T07:17:41.310000

2 posts

In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix subbuf resize race with ring buffer readers trace_buffer subbuf_size is read lockless in ring_buffer_read_page() and ring_buffer_read_start(), while it can simultaneously be resized with ring_buffer_subbuf_order_set(). Instead of trace_buffer::subbuf_size, use bpage::order in ring_buffer_read_start() and ring_b

thehackerwire@mastodon.social at 2026-09-13T07:59:52.000Z ##

🟠 CVE-2026-89771 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

ring-buffer: Fix subbuf resize race with ring buffer readers

trace_buffer subbuf_size is read lockless in ring_buffer_read_page() and
ring_buffer_read_start(), while it can simu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T07:59:52.000Z ##

🟠 CVE-2026-89771 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

ring-buffer: Fix subbuf resize race with ring buffer readers

trace_buffer subbuf_size is read lockless in ring_buffer_read_page() and
ring_buffer_read_start(), while it can simu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89767
(7.8 HIGH)

EPSS: 0.15%

updated 2026-09-13T07:17:41.050000

2 posts

In the Linux kernel, the following vulnerability has been resolved: ovl: fix double end_creating() on the casefold-mismatch path ovl_create_real() releases the new dentry twice when the casefold consistency check fails. The S_IFDIR branch calls end_creating() and sets err, then falls through to the common out: label which calls end_creating() on the same dentry again: case S_IFDIR: newdentr

thehackerwire@mastodon.social at 2026-09-13T09:59:56.000Z ##

🟠 CVE-2026-89767 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

ovl: fix double end_creating() on the casefold-mismatch path

ovl_create_real() releases the new dentry twice when the casefold
consistency check fails. The S_IFDIR branch calls...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T09:59:56.000Z ##

🟠 CVE-2026-89767 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

ovl: fix double end_creating() on the casefold-mismatch path

ovl_create_real() releases the new dentry twice when the casefold
consistency check fails. The S_IFDIR branch calls...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89764
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-13T07:17:40.843000

2 posts

In the Linux kernel, the following vulnerability has been resolved: rust: devres: fix race between concurrent revokers There is a potential race condition when two paths try to revoke a Devres concurrently. The driver core's devres_release_all() calls Revocable::revoke() via the release callback, while Devres::drop() calls revoke_nosync() on another CPU. The revoker that does not claim the is_

thehackerwire@mastodon.social at 2026-09-13T09:00:51.000Z ##

🟠 CVE-2026-89764 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

rust: devres: fix race between concurrent revokers

There is a potential race condition when two paths try to revoke a
Devres concurrently.

The driver core's devres_release_all(...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T09:00:51.000Z ##

🟠 CVE-2026-89764 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

rust: devres: fix race between concurrent revokers

There is a potential race condition when two paths try to revoke a
Devres concurrently.

The driver core's devres_release_all(...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89763
(7.8 HIGH)

EPSS: 0.11%

updated 2026-09-13T07:17:40.717000

2 posts

In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix TPM teardown ordering trusted_tpm_exit() drops the TPM chip reference and frees the digest array before unregistering the trusted key type. key_type_lookup() holds key_types_sem for reading until the key operation finishes, while unregister_key_type() takes it for writing. It therefore provides the synchroniza

thehackerwire@mastodon.social at 2026-09-13T09:00:39.000Z ##

🟠 CVE-2026-89763 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

KEYS: trusted: Fix TPM teardown ordering

trusted_tpm_exit() drops the TPM chip reference and frees the digest
array before unregistering the trusted key type. key_type_lookup()
...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T09:00:39.000Z ##

🟠 CVE-2026-89763 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

KEYS: trusted: Fix TPM teardown ordering

trusted_tpm_exit() drops the TPM chip reference and frees the digest
array before unregistering the trusted key type. key_type_lookup()
...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89760
(7.8 HIGH)

EPSS: 0.11%

updated 2026-09-13T07:17:40.307000

2 posts

In the Linux kernel, the following vulnerability has been resolved: mm, swap: don't free a hibernation slot that is in the swap cache A slot with a folio in the swap cache is freed when the folio leaves the cache, not when its count drops. swap_put_entries_cluster() follows that rule. swap_free_hibernation_slot() does not, it calls __swap_cluster_free_entries() whether or not a folio sits on t

thehackerwire@mastodon.social at 2026-09-13T08:00:01.000Z ##

🟠 CVE-2026-89760 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

mm, swap: don't free a hibernation slot that is in the swap cache

A slot with a folio in the swap cache is freed when the folio leaves the
cache, not when its count drops. swap...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T08:00:01.000Z ##

🟠 CVE-2026-89760 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

mm, swap: don't free a hibernation slot that is in the swap cache

A slot with a folio in the swap cache is freed when the folio leaves the
cache, not when its count drops. swap...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89755
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-13T07:17:39.983000

2 posts

In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: clear stale mapping after freeing swapcache __migrate_device_pages() reads the folio mapping before calling folio_free_swap(). When folio_free_swap() succeeds, the folio is removed from the swap cache, but the saved mapping still points to swap_space. Passing the stale mapping to folio_migrate_mapping() make

thehackerwire@mastodon.social at 2026-09-13T10:00:16.000Z ##

🟠 CVE-2026-89755 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

mm/migrate_device: clear stale mapping after freeing swapcache

__migrate_device_pages() reads the folio mapping before calling
folio_free_swap(). When folio_free_swap() succeed...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T10:00:16.000Z ##

🟠 CVE-2026-89755 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

mm/migrate_device: clear stale mapping after freeing swapcache

__migrate_device_pages() reads the folio mapping before calling
folio_free_swap(). When folio_free_swap() succeed...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89748
(7.8 HIGH)

EPSS: 0.15%

updated 2026-09-13T07:17:39.493000

2 posts

In the Linux kernel, the following vulnerability has been resolved: tracing: Fix retry exhaustion in simple ring buffer reader swap simple_ring_buffer_swap_reader_page() starts with retry set to 8 and post-decrements it only after a failed link replacement. On the final attempt, a successful replacement leaves retry at zero, while a failed replacement leaves it at -1. The current !retry test re

thehackerwire@mastodon.social at 2026-09-13T16:01:07.000Z ##

🟠 CVE-2026-89748 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix retry exhaustion in simple ring buffer reader swap

simple_ring_buffer_swap_reader_page() starts with retry set to 8 and
post-decrements it only after a failed link ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T16:01:07.000Z ##

🟠 CVE-2026-89748 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix retry exhaustion in simple ring buffer reader swap

simple_ring_buffer_swap_reader_page() starts with retry set to 8 and
post-decrements it only after a failed link ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89747
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-13T07:17:39.363000

2 posts

In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free in trace_pipe read on sub-buffer order change Writing to buffer_subbuf_size_kb calls ring_buffer_subbuf_order_set(), which frees every sub-buffer of the ring buffer, including the reader page, and replaces them with newly allocated ones. Readers of trace_pipe hold pointers into those pages. ring_buff

thehackerwire@mastodon.social at 2026-09-13T16:00:55.000Z ##

🟠 CVE-2026-89747 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix use-after-free in trace_pipe read on sub-buffer order change

Writing to buffer_subbuf_size_kb calls ring_buffer_subbuf_order_set(),
which frees every sub-buffer of ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T16:00:55.000Z ##

🟠 CVE-2026-89747 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix use-after-free in trace_pipe read on sub-buffer order change

Writing to buffer_subbuf_size_kb calls ring_buffer_subbuf_order_set(),
which frees every sub-buffer of ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89746
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-13T07:17:39.220000

2 posts

In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free with same-name named triggers When two hist triggers on different events are registered with the same name=, the second one reuses the first as named_data. Both are added to tr->hist_vars by save_hist_vars() during event_hist_trigger_parse(), because save_hist_vars() is called before event_trigger_re

thehackerwire@mastodon.social at 2026-09-13T15:00:53.000Z ##

🟠 CVE-2026-89746 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix use-after-free with same-name named triggers

When two hist triggers on different events are registered with the same
name=, the second one reuses the first as named...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T15:00:53.000Z ##

🟠 CVE-2026-89746 - High (7.8)

In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix use-after-free with same-name named triggers

When two hist triggers on different events are registered with the same
name=, the second one reuses the first as named...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89706
(7.5 HIGH)

EPSS: 0.44%

updated 2026-09-13T07:17:36.240000

2 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: Reset write verifier when async COPY writeback fails Async COPY captures nn->writeverf at request time and reports it to the client via CB_OFFLOAD after the worker kthread completes. When the post-copy vfs_fsync_range() or filemap_check_wb_err() in _nfsd_copy_file_range() reports an error, the worker correctly leaves NFSD4

thehackerwire@mastodon.social at 2026-09-13T18:00:07.000Z ##

🟠 CVE-2026-89706 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: Reset write verifier when async COPY writeback fails

Async COPY captures nn->writeverf at request time and reports it to
the client via CB_OFFLOAD after the worker kthread...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T18:00:07.000Z ##

🟠 CVE-2026-89706 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: Reset write verifier when async COPY writeback fails

Async COPY captures nn->writeverf at request time and reports it to
the client via CB_OFFLOAD after the worker kthread...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89704
(7.5 HIGH)

EPSS: 0.44%

updated 2026-09-13T07:17:35.990000

2 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: sample writeback error cursor before async COPY loop _nfsd_copy_file_range() samples dst->f_wb_err into "since" after the copy loop, then uses it to detect writeback errors via filemap_check_wb_err() once vfs_fsync_range() returns. Because the nfsd_file cache reuses a single struct file across requests targeting the same i

thehackerwire@mastodon.social at 2026-09-13T17:59:56.000Z ##

🟠 CVE-2026-89704 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: sample writeback error cursor before async COPY loop

_nfsd_copy_file_range() samples dst->f_wb_err into "since"
after the copy loop, then uses it to detect writeback error...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T17:59:56.000Z ##

🟠 CVE-2026-89704 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: sample writeback error cursor before async COPY loop

_nfsd_copy_file_range() samples dst->f_wb_err into "since"
after the copy loop, then uses it to detect writeback error...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89695
(7.5 HIGH)

EPSS: 0.49%

updated 2026-09-13T07:17:35.230000

2 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: cap decoded POSIX ACL count to bound sort cost nfsd4_decode_posixacl() reads a u32 entry count off the wire and passes it straight to posix_acl_alloc() and sort_pacl_range(). The latter is an O(n^2) bubble sort, so a client-chosen count drives unbounded CPU in the server's compound processing path. nfsd4_decode_posixa

thehackerwire@mastodon.social at 2026-09-13T19:00:11.000Z ##

🟠 CVE-2026-89695 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: cap decoded POSIX ACL count to bound sort cost

nfsd4_decode_posixacl() reads a u32 entry count off the wire and passes
it straight to posix_acl_alloc() and sort_pacl_range...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T19:00:11.000Z ##

🟠 CVE-2026-89695 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: cap decoded POSIX ACL count to bound sort cost

nfsd4_decode_posixacl() reads a u32 entry count off the wire and passes
it straight to posix_acl_alloc() and sort_pacl_range...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89692
(7.5 HIGH)

EPSS: 0.43%

updated 2026-09-13T07:17:35.107000

2 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: clear CALLBACK_RUNNING on failed delegation recall queue nfsd_break_one_deleg() sets NFSD4_CALLBACK_RUNNING via test_and_set_bit at entry to serialize recall work, then calls nfsd4_run_cb() to queue the recall. When the queue attempt fails the refcount bump is undone, but the RUNNING bit is left set. The only site that c

thehackerwire@mastodon.social at 2026-09-13T19:00:01.000Z ##

🟠 CVE-2026-89692 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: clear CALLBACK_RUNNING on failed delegation recall queue

nfsd_break_one_deleg() sets NFSD4_CALLBACK_RUNNING via test_and_set_bit
at entry to serialize recall work, then ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T19:00:01.000Z ##

🟠 CVE-2026-89692 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: clear CALLBACK_RUNNING on failed delegation recall queue

nfsd_break_one_deleg() sets NFSD4_CALLBACK_RUNNING via test_and_set_bit
at entry to serialize recall work, then ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89689
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-09-13T07:17:34.723000

2 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: don't free session slots that are still in use nfsd4_sequence() can free the very slot it is currently processing. When the session shrinker has reduced se_target_maxslots below se_fchannel.maxreqs, the shrink path checks three conditions before calling free_session_slots(): 1. se_target_maxslots < maxreqs (shrink was

thehackerwire@mastodon.social at 2026-09-14T07:00:31.000Z ##

🔴 CVE-2026-89689 - Critical (9.8)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: don't free session slots that are still in use

nfsd4_sequence() can free the very slot it is currently processing.
When the session shrinker has reduced se_target_maxslots...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T07:00:31.000Z ##

🔴 CVE-2026-89689 - Critical (9.8)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: don't free session slots that are still in use

nfsd4_sequence() can free the very slot it is currently processing.
When the session shrinker has reduced se_target_maxslots...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89688
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-09-13T07:17:34.600000

2 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: drop the stateid, not the stateowner, on seqid_op replay retry In nfs4_preprocess_seqid_op() the stateid is obtained from nfsd4_lookup_stateid(), which holds a reference on the nfs4_stid (sc_count) but takes no reference on the stateowner. openlockstateid() merely casts that stid and likewise takes no reference. When nfsd

thehackerwire@mastodon.social at 2026-09-14T07:00:20.000Z ##

🔴 CVE-2026-89688 - Critical (9.8)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: drop the stateid, not the stateowner, on seqid_op replay retry

In nfs4_preprocess_seqid_op() the stateid is obtained from
nfsd4_lookup_stateid(), which holds a reference o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T07:00:20.000Z ##

🔴 CVE-2026-89688 - Critical (9.8)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: drop the stateid, not the stateowner, on seqid_op replay retry

In nfs4_preprocess_seqid_op() the stateid is obtained from
nfsd4_lookup_stateid(), which holds a reference o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89687
(7.5 HIGH)

EPSS: 0.47%

updated 2026-09-13T07:17:34.493000

2 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file ->atomic_open is permitted to return success without actually opening the file. It indicates this by calling finish_no_open(). This means dentry_create() can return a file which hasn't been opened. This is extremely unlikely as ->atomic_open handlers typically u

thehackerwire@mastodon.social at 2026-09-14T07:00:09.000Z ##

🟠 CVE-2026-89687 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file

->atomic_open is permitted to return success without actually opening
the file. It indicates this by calling ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T07:00:09.000Z ##

🟠 CVE-2026-89687 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file

->atomic_open is permitted to return success without actually opening
the file. It indicates this by calling ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89686
(9.8 CRITICAL)

EPSS: 0.67%

updated 2026-09-13T07:17:34.367000

2 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke nfsd4_alloc_layout_stateid reads fp->fi_deleg_file without holding fi_lock when the parent stateid is a delegation. A concurrent delegation revoke via the laundromat can clear fi_deleg_file under fi_lock, causing nfsd_file_get() to return NULL and trigger

thehackerwire@mastodon.social at 2026-09-14T05:03:22.000Z ##

🔴 CVE-2026-89686 - Critical (9.8)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke

nfsd4_alloc_layout_stateid reads fp->fi_deleg_file without holding
fi_lock when the parent stateid is ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T05:03:22.000Z ##

🔴 CVE-2026-89686 - Critical (9.8)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke

nfsd4_alloc_layout_stateid reads fp->fi_deleg_file without holding
fi_lock when the parent stateid is ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89684
(7.5 HIGH)

EPSS: 0.45%

updated 2026-09-13T07:17:34.130000

2 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix cpntf publish race in nfs4_init_cp_state nfs4_alloc_init_cpntf_state() published the new cpntf entry into the s2s_cp_stateids IDR (with cs_type set) in one s2s_cp_lock section, then took the lock again to list_add() it onto p_stid->sc_cp_list. In the gap the entry is reachable by so_id but cp_list is still {NULL,NULL}

thehackerwire@mastodon.social at 2026-09-13T20:00:13.000Z ##

🟠 CVE-2026-89684 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix cpntf publish race in nfs4_init_cp_state

nfs4_alloc_init_cpntf_state() published the new cpntf entry into the
s2s_cp_stateids IDR (with cs_type set) in one s2s_cp_lock...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T20:00:13.000Z ##

🟠 CVE-2026-89684 - High (7.5)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix cpntf publish race in nfs4_init_cp_state

nfs4_alloc_init_cpntf_state() published the new cpntf entry into the
s2s_cp_stateids IDR (with cs_type set) in one s2s_cp_lock...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89682
(8.1 HIGH)

EPSS: 0.40%

updated 2026-09-13T07:17:34.003000

2 posts

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net nfsd_file_dispose_list_delayed() defers fput() to nfsd service threads via a per-net freeme queue, preventing the shrinker and GC worker from bearing the cost of closing files (see ffb402596147). However, the queue lives in a separately-allocated struct nfsd_

thehackerwire@mastodon.social at 2026-09-13T20:00:03.000Z ##

🟠 CVE-2026-89682 - High (8.1)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net

nfsd_file_dispose_list_delayed() defers fput() to nfsd service threads
via a per-net freeme queue, preventi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T20:00:03.000Z ##

🟠 CVE-2026-89682 - High (8.1)

In the Linux kernel, the following vulnerability has been resolved:

nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net

nfsd_file_dispose_list_delayed() defers fput() to nfsd service threads
via a per-net freeme queue, preventi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89613
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-09-13T07:17:26.840000

2 posts

In the Linux kernel, the following vulnerability has been resolved: ntfs: reject invalid empty mapping pairs Reject an attribute with empty mapping pairs if it has inconsistent highest VCN and size.

thehackerwire@mastodon.social at 2026-09-13T23:00:11.000Z ##

🔴 CVE-2026-89613 - Critical (9.8)

In the Linux kernel, the following vulnerability has been resolved:

ntfs: reject invalid empty mapping pairs

Reject an attribute with empty mapping pairs if it has inconsistent
highest VCN and size.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T23:00:11.000Z ##

🔴 CVE-2026-89613 - Critical (9.8)

In the Linux kernel, the following vulnerability has been resolved:

ntfs: reject invalid empty mapping pairs

Reject an attribute with empty mapping pairs if it has inconsistent
highest VCN and size.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81000
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-13T07:17:06.600000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to TUN or TAP. When align is larger than the usable space in a one-page skb head, SKB_MAX_HEAD(align) underflows and the re

offseq@infosec.exchange at 2026-09-12T01:30:23.000Z ##

CVE-2026-81000: Linux kernel TUN driver HIGH severity vulnerability fixed. Flaw in skb headroom calculation could trigger memory corruption. Update to patched kernel ASAP. 🐧 radar.offseq.com/threat/in-the #OffSeq #Linux #Vulnerability #BlueTeam

##

CVE-2026-80995
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-13T07:17:06.230000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: mctp: hold a reference to the route device in mctp_route_lookup() mctp_route_lookup() uses rt->dev without holding a reference on it. mctp_route_lookup_single() returns the route under RCU only, so the route's device can be torn down concurrently: mctp_dev_put() drops the last reference and synchronously kfree()s mdev->addr

offseq@infosec.exchange at 2026-09-12T04:30:24.000Z ##

CVE-2026-80995: HIGH severity use-after-free in Linux kernel MCTP code lets unprivileged users trigger memory corruption or DoS. Fix: update to patched kernel when released. Details: radar.offseq.com/threat/in-the #OffSeq #Linux #Infosec #CVE #Vulnerability

##

CVE-2026-80980
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-09-13T07:17:04.887000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/smc: stop killed, freed and out_of_sync sharing a byte The three connection state flags are single-bit bitfields, so they occupy one byte of struct smc_connection and every store to one is a read-modify-write of the other two: u8 killed : 1; u8 freed : 1; u8 out_of_sync : 1; They are not written under a comm

hugovalters@mastodon.social at 2026-09-14T11:50:01.000Z ##

CVE-2026-80980 Linux kernel net/smc bitfield race - killed, freed, out_of_sync share one byte without a common lock, a data race that can corrupt connection state. CVSS N/A, patch status unknown/unpatched. Audit valtersit.com/cve/CVE-2026-809 #CVE #Linux #infosec

##

CVE-2026-90678
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-13T04:17:25.227000

2 posts

An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic must reach a backend over HTTP/1.1 using chunked transfer coding on a reused connection. Under those conditions, when an HTTP/3 request carries no Content-Length

thehackerwire@mastodon.social at 2026-09-13T05:00:08.000Z ##

🟠 CVE-2026-90678 - High (7.5)

An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic must reac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T05:00:08.000Z ##

🟠 CVE-2026-90678 - High (7.5)

An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic must reac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90668
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-13T03:30:22

3 posts

The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request with an unlimited number of headers, if a websocket or JSON-RPC listener is enabled (disabled by default).

unrealircd@fosstodon.org at 2026-09-13T14:23:39.000Z ##

The UnrealIRCd security issue from yesterday was assigned CVE-2026-90668. Admins on older versions could apply a hot-patch to fix the issue without restart.

We have been doing that at UnrealIRCd for more than 20 years now, so I wrote a story on my personal blog about how effective it is, and the times it did not work: vulnscan.org/why-hot-patching-

#IRC #infosec

##

thehackerwire@mastodon.social at 2026-09-13T02:59:48.000Z ##

🟠 CVE-2026-90668 - High (7.5)

The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request with an unl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T02:59:48.000Z ##

🟠 CVE-2026-90668 - High (7.5)

The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request with an unl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90493
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-13T03:16:27.370000

4 posts

A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a requirement. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond

thehackerwire@mastodon.social at 2026-09-13T05:00:17.000Z ##

🟠 CVE-2026-90493 - High (8.8)

A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-13T04:30:23.428Z ##

Tonec Internet Download Manager <=6.42.63 hit by CRITICAL vuln (CVE-2026-90493) in idmwfp.sys — improper access controls enable local privilege escalation. Public exploit code, no patch yet. Restrict local access & monitor. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-13T05:00:17.000Z ##

🟠 CVE-2026-90493 - High (8.8)

A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-13T04:30:23.000Z ##

Tonec Internet Download Manager <=6.42.63 hit by CRITICAL vuln (CVE-2026-90493) in idmwfp.sys — improper access controls enable local privilege escalation. Public exploit code, no patch yet. Restrict local access & monitor. radar.offseq.com/threat/cve-20 #OffSeq #CVE202690493 #Vuln #Cybersecurity

##

CVE-2026-90648(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-13T00:31:26

2 posts

wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a "table flip" attack. It does not check the return value of calloc() in wasm_rt_allocate_funcref_table() (wasm2c/wasm-rt-impl-tableops.inc). When the funcref table allocation fails, table->data is left NULL while table->size keeps the guest-declared element count; thus,

offseq at 2026-09-13T09:00:26.724Z ##

CVE-2026-90648: HIGH severity vuln in wasm2c (WebAssembly wabt <=1.0.41). Unchecked calloc() return enables sandbox escape & code exec if allocation fails — mainly on 32-bit/memory-limited systems. Patch status pending. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-13T09:00:26.000Z ##

CVE-2026-90648: HIGH severity vuln in wasm2c (WebAssembly wabt <=1.0.41). Unchecked calloc() return enables sandbox escape & code exec if allocation fails — mainly on 32-bit/memory-limited systems. Patch status pending. radar.offseq.com/threat/cve-20 #OffSeq #WebAssembly #CVE202690648

##

CVE-2026-90651
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-13T00:31:26

4 posts

Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from socket.yml, the generated configuration sets SOCKET_API_SSL_VERIFY='false' and UPSTREAM_SSL_VERIFY='false', and the OpenResty/Lua HTTP client used for outbound requests accepts an

offseq at 2026-09-13T07:30:23.959Z ##

CVE-2026-90651 | HIGH severity in Socket Socket Firewall <2.0.0: TLS certs not validated by default — MITM risk. Set api_ssl_verify and upstream_ssl_verify to true & patch configs or upgrade to 2.0.0+. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-13T00:59:47.000Z ##

🟠 CVE-2026-90651 - High (8.1)

Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from socket.yml, the generated ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-13T07:30:23.000Z ##

CVE-2026-90651 | HIGH severity in Socket Socket Firewall <2.0.0: TLS certs not validated by default — MITM risk. Set api_ssl_verify and upstream_ssl_verify to true & patch configs or upgrade to 2.0.0+. radar.offseq.com/threat/cve-20 #OffSeq #vuln #infosec #supplychain

##

thehackerwire@mastodon.social at 2026-09-13T00:59:47.000Z ##

🟠 CVE-2026-90651 - High (8.1)

Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from socket.yml, the generated ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90647
(7.4 HIGH)

EPSS: 0.00%

updated 2026-09-12T23:17:01.490000

2 posts

ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications.

offseq at 2026-09-13T00:00:35.847Z ##

CVE-2026-90647 (CRITICAL, CVSS 9.1) affects Kalkitech ASE2000 V2 (2.35 – 2.37): improper TLS certificate validation in IEC 60870-5-104 enables MitM attacks. No patch confirmed. Restrict access & monitor. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-13T00:00:35.000Z ##

CVE-2026-90647 (CRITICAL, CVSS 9.1) affects Kalkitech ASE2000 V2 (2.35 – 2.37): improper TLS certificate validation in IEC 60870-5-104 enables MitM attacks. No patch confirmed. Restrict access & monitor. radar.offseq.com/threat/cve-20 #OffSeq #ICS #CVE202690647 #TLS

##

CVE-2026-90616
(7.4 HIGH)

EPSS: 0.00%

updated 2026-09-12T21:31:19

2 posts

In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925. Flatpak creates a few app data directories (e.g., /var/cache, /var/data, /var/config, and /var/tmp) in every sandbox on every app launch where, in some cases, components of

offseq at 2026-09-13T10:30:24.719Z ##

CVE-2026-90616: Flatpak <1.18.1 has a HIGH severity vuln — malicious sandboxed apps can use symlinks to gain arbitrary read/write host access, risking code execution. Update to 1.18.1+ now. radar.offseq.com/threat/in-fla

##

offseq@infosec.exchange at 2026-09-13T10:30:24.000Z ##

CVE-2026-90616: Flatpak <1.18.1 has a HIGH severity vuln — malicious sandboxed apps can use symlinks to gain arbitrary read/write host access, risking code execution. Update to 1.18.1+ now. radar.offseq.com/threat/in-fla #OffSeq #Flatpak #Linux #Security

##

CVE-2026-75800
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-09-12T18:31:28

2 posts

The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts.

thehackerwire@mastodon.social at 2026-09-13T01:00:10.000Z ##

🔴 CVE-2026-75800 - Critical (9.8)

The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as wel...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-13T01:00:10.000Z ##

🔴 CVE-2026-75800 - Critical (9.8)

The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as wel...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77006
(9.6 CRITICAL)

EPSS: 0.18%

updated 2026-09-12T18:31:28

2 posts

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.

thehackerwire@mastodon.social at 2026-09-12T23:00:13.000Z ##

🔴 CVE-2026-77006 - Critical (9.6)

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T23:00:13.000Z ##

🔴 CVE-2026-77006 - Critical (9.6)

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87842
(7.5 HIGH)

EPSS: 0.29%

updated 2026-09-12T18:31:28

2 posts

The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.

thehackerwire@mastodon.social at 2026-09-12T18:00:02.000Z ##

🟠 CVE-2026-87842 - High (7.5)

The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T18:00:02.000Z ##

🟠 CVE-2026-87842 - High (7.5)

The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90558
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-12T18:30:33

4 posts

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute arbitrary code during packet parsing and rendering.

offseq at 2026-09-13T01:30:24.952Z ##

CVE-2026-90558: CRITICAL stack buffer overflow in irontec sngrep (<=1.8.4). Malicious SIP headers can crash or allow code execution. Patch status pending — filter untrusted SIP traffic. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-12T19:00:23.000Z ##

🔴 CVE-2026-90558 - Critical (9.8)

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other hea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-13T01:30:24.000Z ##

CVE-2026-90558: CRITICAL stack buffer overflow in irontec sngrep (<=1.8.4). Malicious SIP headers can crash or allow code execution. Patch status pending — filter untrusted SIP traffic. radar.offseq.com/threat/cve-20 #OffSeq #CVE202690558 #vuln #SIPrisk

##

thehackerwire@mastodon.social at 2026-09-12T19:00:23.000Z ##

🔴 CVE-2026-90558 - Critical (9.8)

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other hea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90560
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-12T18:30:33

2 posts

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.

thehackerwire@mastodon.social at 2026-09-12T19:01:24.000Z ##

🟠 CVE-2026-90560 - High (8.2)

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T19:01:24.000Z ##

🟠 CVE-2026-90560 - High (8.2)

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81742
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-12T18:30:22

2 posts

The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any user visiting the site.

thehackerwire@mastodon.social at 2026-09-12T22:59:51.000Z ##

🟠 CVE-2026-81742 - High (8.8)

The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T22:59:51.000Z ##

🟠 CVE-2026-81742 - High (8.8)

The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80494
(8.6 HIGH)

EPSS: 0.32%

updated 2026-09-12T18:30:22

2 posts

The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials.

thehackerwire@mastodon.social at 2026-09-12T20:00:24.000Z ##

🟠 CVE-2026-80494 - High (8.6)

The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T20:00:24.000Z ##

🟠 CVE-2026-80494 - High (8.6)

The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82845
(9.9 CRITICAL)

EPSS: 0.35%

updated 2026-09-12T18:30:22

2 posts

The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the s

thehackerwire@mastodon.social at 2026-09-12T19:01:35.000Z ##

🔴 CVE-2026-82845 - Critical (9.9)

The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T19:01:35.000Z ##

🔴 CVE-2026-82845 - Critical (9.9)

The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87888
(8.0 HIGH)

EPSS: 0.23%

updated 2026-09-12T18:30:22

2 posts

The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing WordPress plugin before 3.5.7's settings page.

thehackerwire@mastodon.social at 2026-09-12T18:00:16.000Z ##

🟠 CVE-2026-87888 - High (8)

The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T18:00:16.000Z ##

🟠 CVE-2026-87888 - High (8)

The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84099
(8.1 HIGH)

EPSS: 0.27%

updated 2026-09-12T18:30:22

2 posts

The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site.

thehackerwire@mastodon.social at 2026-09-12T16:59:52.000Z ##

🟠 CVE-2026-84099 - High (8.1)

The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T16:59:52.000Z ##

🟠 CVE-2026-84099 - High (8.1)

The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81402
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-09-12T18:30:21

2 posts

The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can lead to remote code execution.

thehackerwire@mastodon.social at 2026-09-12T20:00:36.000Z ##

🔴 CVE-2026-81402 - Critical (9.8)

The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-ac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T20:00:36.000Z ##

🔴 CVE-2026-81402 - Critical (9.8)

The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-ac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80491
(8.6 HIGH)

EPSS: 0.32%

updated 2026-09-12T18:30:21

2 posts

The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.

thehackerwire@mastodon.social at 2026-09-12T20:00:13.000Z ##

🟠 CVE-2026-80491 - High (8.6)

The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T20:00:13.000Z ##

🟠 CVE-2026-80491 - High (8.6)

The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90559
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-12T18:16:44.743000

2 posts

snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compressed data that decompresses larger than the destination buffer, causing writes past buffer boundaries and JVM termination.

thehackerwire@mastodon.social at 2026-09-12T19:00:34.000Z ##

🟠 CVE-2026-90559 - High (7.5)

snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compressed data th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T19:00:34.000Z ##

🟠 CVE-2026-90559 - High (7.5)

snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compressed data th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90556
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-12T18:16:44.193000

2 posts

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into adjacent heap-allocated struct fields, potentially corrupting memory when a user or server operator loads the file.

thehackerwire@mastodon.social at 2026-09-12T19:00:13.000Z ##

🟠 CVE-2026-90556 - High (7.8)

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T19:00:13.000Z ##

🟠 CVE-2026-90556 - High (7.8)

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87759
(8.8 HIGH)

EPSS: 0.23%

updated 2026-09-12T16:16:42.473000

3 posts

The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber, to grant themselves the administrator role on a multisite installation.

thehackerwire@mastodon.social at 2026-09-12T17:59:53.000Z ##

🟠 CVE-2026-87759 - High (8.8)

The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber, to gr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T17:59:53.000Z ##

🟠 CVE-2026-87759 - High (8.8)

The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber, to gr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-12T07:30:24.000Z ##

CVE-2026-87759 (CRITICAL): Add User Autocomplete plugin (<1.2) for WordPress allows authenticated users to self-assign admin on multisite via improper privilege checks. Upgrade to 1.2+ or restrict user roles. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Security #CVE202687759

##

CVE-2026-85681
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-09-12T16:16:42.170000

3 posts

The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing unauthenticated attackers to overwrite any of the site's options. On a single site installation this leads to a full takeover, as registration can be enabled

thehackerwire@mastodon.social at 2026-09-12T17:00:14.000Z ##

🔴 CVE-2026-85681 - Critical (9.8)

The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing unaut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T17:00:14.000Z ##

🔴 CVE-2026-85681 - Critical (9.8)

The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing unaut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-12T12:00:24.000Z ##

CVE-2026-85681 (CRITICAL): WP Component plugin ≤2.2.4 allows unauthenticated option overwrites, risking full WordPress site takeover. Single-site installs are exposed. Check vendor advisory for mitigation steps: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #BlueTeam

##

CVE-2026-84171
(9.8 CRITICAL)

EPSS: 0.37%

updated 2026-09-12T16:16:41.897000

3 posts

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.

thehackerwire@mastodon.social at 2026-09-12T17:00:02.000Z ##

🔴 CVE-2026-84171 - Critical (9.8)

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T17:00:02.000Z ##

🔴 CVE-2026-84171 - Critical (9.8)

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-12T13:30:24.000Z ##

WP images upload on piclect (≤1.0) suffers from CRITICAL CVE-2026-84171: Unauthenticated attackers can upload arbitrary files, risking code execution. Restrict uploads & monitor activity until a fix is released. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202684171 #Vuln

##

CVE-2026-84047
(8.6 HIGH)

EPSS: 0.26%

updated 2026-09-12T16:16:41.527000

2 posts

The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

thehackerwire@mastodon.social at 2026-09-12T19:01:45.000Z ##

🟠 CVE-2026-84047 - High (8.6)

The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T19:01:45.000Z ##

🟠 CVE-2026-84047 - High (8.6)

The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77005
(9.6 CRITICAL)

EPSS: 0.30%

updated 2026-09-12T16:16:38.523000

2 posts

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.

thehackerwire@mastodon.social at 2026-09-12T23:00:01.000Z ##

🔴 CVE-2026-77005 - Critical (9.6)

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-12T23:00:01.000Z ##

🔴 CVE-2026-77005 - Critical (9.6)

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90553
(7.8 HIGH)

EPSS: 0.21%

updated 2026-09-12T15:31:56

1 posts

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.

thehackerwire@mastodon.social at 2026-09-12T13:59:48.000Z ##

🟠 CVE-2026-90553 - High (7.8)

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90537
(8.2 HIGH)

EPSS: 0.21%

updated 2026-09-12T13:16:51.667000

1 posts

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide daily token. Attackers can enumerate scheduler jobs, read private live titles and email addresses, and trigger email sending by supplying any valid dail

thehackerwire@mastodon.social at 2026-09-12T14:00:13.000Z ##

🟠 CVE-2026-90537 - High (8.2)

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15451
(8.8 HIGH)

EPSS: 0.25%

updated 2026-09-12T13:16:50.940000

1 posts

The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'userdata' array to 'wp_insert_user' without filtering dangerous keys like role or ID. This makes it possible for authenticated attackers, with subscriber-lev

thehackerwire@mastodon.social at 2026-09-12T14:00:24.000Z ##

🟠 CVE-2026-15451 - High (8.8)

The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'user...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85200
(7.5 HIGH)

EPSS: 0.76%

updated 2026-09-12T09:33:36

1 posts

The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sen

thehackerwire@mastodon.social at 2026-09-12T09:00:45.000Z ##

🟠 CVE-2026-85200 - High (7.5)

The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78175
(8.8 HIGH)

EPSS: 0.59%

updated 2026-09-12T08:16:24.507000

1 posts

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. This is due to the handler lacking any capability or role check, relying solely on a nonce, while also passing attacker-supplied values through `esc_sq

thehackerwire@mastodon.social at 2026-09-12T09:00:09.000Z ##

🟠 CVE-2026-78175 - High (8.8)

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78159
(9.8 CRITICAL)

EPSS: 0.76%

updated 2026-09-12T08:16:24.377000

4 posts

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it p

offseq at 2026-09-13T06:00:25.530Z ##

CVE-2026-78159: The Events Calendar <=6.17.3 for WordPress has a CRITICAL RCE flaw via parse_array(). Unauthenticated code execution if comments on tribe_events posts are enabled. Disable comments as interim mitigation. radar.offseq.com/threat/the-th

##

offseq@infosec.exchange at 2026-09-13T06:00:25.000Z ##

CVE-2026-78159: The Events Calendar <=6.17.3 for WordPress has a CRITICAL RCE flaw via parse_array(). Unauthenticated code execution if comments on tribe_events posts are enabled. Disable comments as interim mitigation. radar.offseq.com/threat/the-th #OffSeq #WordPress #RCE #CVE202678159

##

offseq@infosec.exchange at 2026-09-12T09:00:24.000Z ##

CVE-2026-78159: CRITICAL RCE in The Events Calendar (<=6.17.3). Unauthenticated attackers can run arbitrary code via crafted comments. Disable comments on tribe_events posts to mitigate. CVSS 9.8. Details: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #RCE

##

thehackerwire@mastodon.social at 2026-09-12T08:59:59.000Z ##

🔴 CVE-2026-78159 - Critical (9.8)

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-arr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78006
(9.8 CRITICAL)

EPSS: 0.78%

updated 2026-09-12T08:16:24.240000

4 posts

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attri

2 repos

https://github.com/user445213/CVE-2026-78006

https://github.com/DeadExpl0it/CVE-2026-78006-POC

offseq at 2026-09-13T03:00:23.504Z ##

CVE-2026-78006: The Events Calendar plugin ≤6.17.4 has a CRITICAL RCE flaw. Unauthenticated attackers can run code via comment handling — disable event comments until patched. Review vendor advisories. radar.offseq.com/threat/the-th

##

offseq@infosec.exchange at 2026-09-13T03:00:23.000Z ##

CVE-2026-78006: The Events Calendar plugin ≤6.17.4 has a CRITICAL RCE flaw. Unauthenticated attackers can run code via comment handling — disable event comments until patched. Review vendor advisories. radar.offseq.com/threat/the-th #OffSeq #WordPress #CVE202678006 #RCE

##

offseq@infosec.exchange at 2026-09-12T10:30:24.000Z ##

CVE-2026-78006: CRITICAL RCE in The Events Calendar plugin (<=6.17.4) for WordPress. Unauthenticated attackers can exploit comments to run code on the server. Disable event comments now & check for patches. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #RCE #Vuln

##

thehackerwire@mastodon.social at 2026-09-12T08:59:50.000Z ##

🔴 CVE-2026-78006 - Critical (9.8)

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16482
(7.5 HIGH)

EPSS: 0.34%

updated 2026-09-12T08:16:23.797000

1 posts

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and including, 4.7.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries

thehackerwire@mastodon.social at 2026-09-12T09:00:55.000Z ##

🟠 CVE-2026-16482 - High (7.5)

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and including, 4.7.11 due to insufficient escaping on the user supplied param...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84869
(9.9 CRITICAL)

EPSS: 0.69%

updated 2026-09-12T04:16:42.757000

7 posts

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

cyberworldops at 2026-09-14T10:20:01.106Z ##

ConnectWise patched CVE-2026-84869, a critical ScreenConnect authorization flaw allowing file transfer and execution via active sessions. Huntress reports worm-like exploitation since August 20. It enables lateral spread without host confirmation, requiring immediate patching and session review.

cyberworldops.eu/en/critical-s

##

offseq at 2026-09-14T09:00:25.800Z ##

ConnectWise ScreenConnect CRITICAL vuln (CVE-2026-84869) exploited in worm-like attacks — unauthorized file transfer & execution via remote sessions in versions <26.6.5. Patch to 26.6.5 now or disable TransferFiles. radar.offseq.com/threat/connec

##

cyberworldops@infosec.exchange at 2026-09-14T10:20:01.000Z ##

ConnectWise patched CVE-2026-84869, a critical ScreenConnect authorization flaw allowing file transfer and execution via active sessions. Huntress reports worm-like exploitation since August 20. It enables lateral spread without host confirmation, requiring immediate patching and session review. #ScreenConnect #CyberSecurity #InfoSec

cyberworldops.eu/en/critical-s

##

offseq@infosec.exchange at 2026-09-14T09:00:25.000Z ##

ConnectWise ScreenConnect CRITICAL vuln (CVE-2026-84869) exploited in worm-like attacks — unauthorized file transfer & execution via remote sessions in versions <26.6.5. Patch to 26.6.5 now or disable TransferFiles. radar.offseq.com/threat/connec #OffSeq #Cybersecurity #Vuln #CISA

##

DailyCyberSecurity@infosec.exchange at 2026-09-12T07:12:00.000Z ##

A critical ConnectWise ScreenConnect vulnerability, CVE-2026-84869, is actively exploited in the wild. Patch your servers now to stop remote attacks.

#ConnectWise #ScreenConnect #CVE202684869 #Cybersecurity #Vulnerability

securityonline.info/connectwis

##

secdb@infosec.exchange at 2026-09-11T21:00:27.000Z ##

🚨 [CISA-2026:0911] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-42016 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-42018 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-84869 (secdb.nttzen.cloud/cve/detail/)
- Name: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ConnectWise
- Product: ScreenConnect
- Notes: connectwise.com/company/trust/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-85706 (secdb.nttzen.cloud/cve/detail/)
- Name: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: GitLab
- Product: Community Edition and Enterprise Edition
- Notes: docs.gitlab.com/releases/patch ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260911 #cisa20260911 #cve_2026_42016 #cve_2026_42018 #cve_2026_84869 #cve_2026_85706 #cve202642016 #cve202642018 #cve202684869 #cve202685706

##

cisakevtracker@mastodon.social at 2026-09-11T19:00:57.000Z ##

CVE ID: CVE-2026-84869
Vendor: ConnectWise
Product: ScreenConnect
Date Added: 2026-09-11
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-42018
(7.5 HIGH)

EPSS: 0.92%

updated 2026-09-12T04:16:33.587000

7 posts

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

1 repos

https://github.com/BL0odz/JFrog_CVE-2026-65615-ByGLM

sayzard@mastodon.sayzard.org at 2026-09-14T02:41:08.000Z ##

Artifactory: In-the-Wild Exploitation of CVE-2026-42016,CVE-2026-42018

Wiz Research는 JFrog Artifactory의 CVE-2026-42016, CVE-2026-42018, CVE-2026-82329가 실제 환경에서 활발히 악용되고 있음을 확인했다. 공격자는 익명 사용자 토큰 노출과 토큰 스코프 검증 결함을 연쇄해 인증 없이 관리자 권한 토큰을 획득하거나, CVE-2026-82329의 인증 우회로 직접 관리자 권한을 얻을 수 있다. 침해 후에는 지속성 관리자 계정 생성, Groovy 플러그인을 통한 서버 명령 실행, 클러스...

wiz.io/blog/artifactory-under-

##

thecybermind@infosec.exchange at 2026-09-12T14:40:36.000Z ##

CRITICAL SOC ALERT: CVE-2026-42018 exposes JFrog Artifactory via improper auth and token leakage. Active KEV exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to neutralize attacker persistence. thecybermind.co/9t6b

##

thecybermind@infosec.exchange at 2026-09-12T13:46:54.000Z ##

CRITICAL CISA KEV ALERT: CVE-2026-42018 targets JFrog Artifactory via improper auth and token leakage. Active exploitation verified. Access our CSUITE Brief for technical execution vectors, asset integrity rules, and endpoint hardening steps to protect your enterprise perimeter. thecybermind.co/22sa

##

threatnoir@infosec.exchange at 2026-09-12T01:05:51.000Z ##

⚠️ CRITICAL: Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers are chaining multiple JFrog Artifactory vulnerabilities (CVE-2026-42018, CVE-2026-42016, CVE-2026-82329) to escalate from anonymous users to administrator control on self-hosted instances. This grants them ability to plant backdoors and execute arbitrary shell commands in your build pipel…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

secdb@infosec.exchange at 2026-09-11T21:00:27.000Z ##

🚨 [CISA-2026:0911] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-42016 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-42018 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-84869 (secdb.nttzen.cloud/cve/detail/)
- Name: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ConnectWise
- Product: ScreenConnect
- Notes: connectwise.com/company/trust/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-85706 (secdb.nttzen.cloud/cve/detail/)
- Name: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: GitLab
- Product: Community Edition and Enterprise Edition
- Notes: docs.gitlab.com/releases/patch ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260911 #cisa20260911 #cve_2026_42016 #cve_2026_42018 #cve_2026_84869 #cve_2026_85706 #cve202642016 #cve202642018 #cve202684869 #cve202685706

##

cisakevtracker@mastodon.social at 2026-09-11T19:01:28.000Z ##

CVE ID: CVE-2026-42018
Vendor: JFrog
Product: Artifactory
Date Added: 2026-09-11
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cyberworldops@infosec.exchange at 2026-09-11T18:30:01.000Z ##

Active exploitation chains CVE-2026-42018 and CVE-2026-42016 to bypass authentication on self-hosted JFrog Artifactory and deploy a Rust backdoor with C2. CVE-2026-82329 is also abused to create admin tokens. This enables full server takeover and supply chain compromise. #JFrog #Artifactory #SupplyChainSecurity

cyberworldops.eu/en/attackers-

##

CVE-2026-42016
(8.1 HIGH)

EPSS: 0.89%

updated 2026-09-12T04:16:32.483000

6 posts

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

sayzard@mastodon.sayzard.org at 2026-09-14T02:41:08.000Z ##

Artifactory: In-the-Wild Exploitation of CVE-2026-42016,CVE-2026-42018

Wiz Research는 JFrog Artifactory의 CVE-2026-42016, CVE-2026-42018, CVE-2026-82329가 실제 환경에서 활발히 악용되고 있음을 확인했다. 공격자는 익명 사용자 토큰 노출과 토큰 스코프 검증 결함을 연쇄해 인증 없이 관리자 권한 토큰을 획득하거나, CVE-2026-82329의 인증 우회로 직접 관리자 권한을 얻을 수 있다. 침해 후에는 지속성 관리자 계정 생성, Groovy 플러그인을 통한 서버 명령 실행, 클러스...

wiz.io/blog/artifactory-under-

##

Matchbook3469@mastodon.social at 2026-09-13T18:36:28.000Z ##

🔵 THREAT INTELLIGENCE

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

Vulnerability | CRITICAL
CVEs: CVE-2026-42016

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise...

Full analysis:
yazoul.net/news/article/cisa-a

by Yazoul AI

#ThreatIntel #SecurityNews #IncidentResponse

##

threatnoir@infosec.exchange at 2026-09-12T01:05:51.000Z ##

⚠️ CRITICAL: Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers are chaining multiple JFrog Artifactory vulnerabilities (CVE-2026-42018, CVE-2026-42016, CVE-2026-82329) to escalate from anonymous users to administrator control on self-hosted instances. This grants them ability to plant backdoors and execute arbitrary shell commands in your build pipel…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

secdb@infosec.exchange at 2026-09-11T21:00:27.000Z ##

🚨 [CISA-2026:0911] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-42016 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Incorrect Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-42018 (secdb.nttzen.cloud/cve/detail/)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: docs.jfrog.com/releases/docs/j ; docs.jfrog.com/releases/docs/a ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-84869 (secdb.nttzen.cloud/cve/detail/)
- Name: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ConnectWise
- Product: ScreenConnect
- Notes: connectwise.com/company/trust/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-85706 (secdb.nttzen.cloud/cve/detail/)
- Name: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: GitLab
- Product: Community Edition and Enterprise Edition
- Notes: docs.gitlab.com/releases/patch ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260911 #cisa20260911 #cve_2026_42016 #cve_2026_42018 #cve_2026_84869 #cve_2026_85706 #cve202642016 #cve202642018 #cve202684869 #cve202685706

##

cisakevtracker@mastodon.social at 2026-09-11T19:01:13.000Z ##

CVE ID: CVE-2026-42016
Vendor: JFrog
Product: Artifactory
Date Added: 2026-09-11
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cyberworldops@infosec.exchange at 2026-09-11T18:30:01.000Z ##

Active exploitation chains CVE-2026-42018 and CVE-2026-42016 to bypass authentication on self-hosted JFrog Artifactory and deploy a Rust backdoor with C2. CVE-2026-82329 is also abused to create admin tokens. This enables full server takeover and supply chain compromise. #JFrog #Artifactory #SupplyChainSecurity

cyberworldops.eu/en/attackers-

##

CVE-2026-87719
(9.9 CRITICAL)

EPSS: 0.61%

updated 2026-09-12T03:16:31.477000

2 posts

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server objec

hugovalters@mastodon.social at 2026-09-14T07:00:13.000Z ##

CVE-2026-87719 GitLab EE: authed Duo Chat user can leak Advanced Search configs and credentials via crafted GraphQL subscription, CVSS 9.9. No patch confirmed. Update now.
valtersit.com/cve/CVE-2026-877
#CVE #GitLab #infosec

##

thehackerwire@mastodon.social at 2026-09-12T04:00:11.000Z ##

🔴 CVE-2026-87719 - Critical (9.9)

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90460(CVSS UNKNOWN)

EPSS: 0.34%

updated 2026-09-12T00:31:35

1 posts

An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or deleting credentials via the /v3/credentials API. EC2-derived tokens can additionally read credential blobs, exposing TOTP MFA seeds and other secrets. Also, PATCH

offseq@infosec.exchange at 2026-09-12T03:00:25.000Z ##

CVE-2026-90460: OpenStack Keystone <29.0.3 HIGH risk flaw allows delegated tokens to manage credentials & read sensitive data (MFA seeds) via /v3/credentials. Limit delegated token use & monitor access. Patch status pending. radar.offseq.com/threat/an-iss #OffSeq #OpenStack #Infosec

##

CVE-2026-89266
(8.2 HIGH)

EPSS: 0.47%

updated 2026-09-12T00:31:35

1 posts

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, causing process crashes or heap corruption.

thehackerwire@mastodon.social at 2026-09-12T00:59:49.000Z ##

🟠 CVE-2026-89266 - High (8.2)

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90456
(0 None)

EPSS: 0.25%

updated 2026-09-11T22:16:47.993000

1 posts

An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.

offseq@infosec.exchange at 2026-09-12T00:00:35.000Z ##

CISA Malcolm (<=26.05.x) faces CRITICAL risk: CVE-2026-90456 allows admin takeover via default creds in inventory component if setup isn't run. Ensure unique passwords! radar.offseq.com/threat/cve-20 #OffSeq #CISAMalcolm #CVE202690456 #infosec

##

CVE-2026-79395
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-09-11T21:31:23

1 posts

An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged ONVIF actions (including PTZ control, stream URL retrieval, and system reboot) via a crafted SOAP request supplying the admin

thehackerwire@mastodon.social at 2026-09-11T22:02:03.000Z ##

🔴 CVE-2026-79395 - Critical (9.8)

An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentica...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78488
(6.5 MEDIUM)

EPSS: 3.25%

updated 2026-09-11T21:22:54.260000

2 posts

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to command execution.

secdb at 2026-09-14T00:02:28.608Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-54174
(8.3 HIGH)

EPSS: 0.10%

updated 2026-09-11T21:17:11.403000

1 posts

melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package f

thehackerwire@mastodon.social at 2026-09-11T21:59:51.000Z ##

🟠 CVE-2026-54174 - High (8.3)

melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never ver...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49464
(8.1 HIGH)

EPSS: 0.20%

updated 2026-09-11T21:17:10.523000

1 posts

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:taak` package from version 1.5.0 through 3.0.0 fails to verify ownership when processing the `submitTaakV2` GraphQL mutation, allowing an authenticated user who knows or guesses another user’s task ID to read its form d

thehackerwire@mastodon.social at 2026-09-11T22:00:00.000Z ##

🟠 CVE-2026-49464 - High (8.1)

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:taak` package from version 1.5.0 through 3.0.0 fails to verify own...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62112
(7.6 HIGH)

EPSS: 0.28%

updated 2026-09-11T21:17:02.457000

1 posts

Editor SQL Injection in Amelia <= 2.4.9 versions.

CVE-2026-89502
(0 None)

EPSS: 0.20%

updated 2026-09-11T20:19:32.423000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Free cpu_buffer::free_page with subbuf_order When sub-buffers use an order greater than 0, cpu_buffer->free_page is allocated with subbuf_order. Use the correct order for cpu_buffer->free_page.

hugovalters@mastodon.social at 2026-09-14T10:10:01.000Z ##

CVE-2026-89502 Linux kernel ring-buffer memory flaw. Patch status unknown, no CVSS yet. Update your kernels immediately. valtersit.com/cve/CVE-2026-895 #CVE #infosec #Linux

##

CVE-2026-54135
(7.5 HIGH)

EPSS: 0.55%

updated 2026-09-11T20:17:14.330000

1 posts

AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP server implementation of AirSane that allows a remote unauthenticated attacker to cause a Denial of Service (DoS) via memory exhaustion (OOM). In httpserver.cpp, the HttpServer::Request::content function reads the Content-Length header and direct

thehackerwire@mastodon.social at 2026-09-11T22:01:54.000Z ##

🟠 CVE-2026-54135 - High (7.5)

AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP server implementation of AirSane that allows a remote unauthenticated attacker to cause a Den...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53952
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-09-11T20:17:14.060000

1 posts

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The application features an automated security control designed to delete the sensitive `admin/setup.php` file post-installatio

thehackerwire@mastodon.social at 2026-09-11T22:01:43.000Z ##

🔴 CVE-2026-53952 - Critical (9.8)

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a n...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79393
(7.5 HIGH)

EPSS: 0.53%

updated 2026-09-11T19:17:46.070000

1 posts

A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially execute arbitrary code via a crafted SOAP request containing a wsa5:Action string exceeding 128 bytes.

thehackerwire@mastodon.social at 2026-09-11T19:59:46.000Z ##

🟠 CVE-2026-79393 - High (7.5)

A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a deni...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89262
(7.5 HIGH)

EPSS: 0.31%

updated 2026-09-11T18:31:32

1 posts

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints.

thehackerwire@mastodon.social at 2026-09-11T17:00:37.000Z ##

🟠 CVE-2026-89262 - High (7.5)

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89260
(7.5 HIGH)

EPSS: 0.43%

updated 2026-09-11T18:31:31

1 posts

MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened dom4j SAXReader without DTD or external-entity restrictions. Unauthenticated remote attackers can submit DOCTYPE declarations with external parameter ent

thehackerwire@mastodon.social at 2026-09-11T17:00:27.000Z ##

🟠 CVE-2026-89260 - High (7.5)

MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89066
(7.8 HIGH)

EPSS: 0.16%

updated 2026-09-11T18:24:59.400000

1 posts

Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration runner via shell metacharacters in project configuration values and repository file names that are interpolated into generated task definitions. To rem

thehackerwire@mastodon.social at 2026-09-11T17:00:48.000Z ##

🟠 CVE-2026-89066 - High (7.8)

Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89010
(9.8 CRITICAL)

EPSS: 2.85%

updated 2026-09-11T17:35:21.440000

2 posts

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to the sync_server daemon on TCP port 13136. The daemon interpolates attacker-controlled filename input containing shell metacharacters into a shell command string vi

secdb at 2026-09-14T00:02:28.608Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-69827
(8.1 HIGH)

EPSS: 0.53%

updated 2026-09-11T16:17:43.143000

1 posts

Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.

shaknais@mastodon.social at 2026-09-11T23:11:45.000Z ##

@hrbrmstr

MS selling "MDASH" as having fixed their TCP/IP stack, a day after a critical DNS CVE comes out without a fix.

cve.org/CVERecord?id=CVE-2026-

##

CVE-2026-87020
(8.1 HIGH)

EPSS: 0.56%

updated 2026-09-11T15:32:49

2 posts

An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.

cyberworldops at 2026-09-13T18:50:01.251Z ##

Orthanc DICOM Server is affected by CVE-2026-87020, an integer overflow in image pitch calculation enabling authenticated heap out-of-bounds write via malicious PNG. It matters for clinical environments where exploitation risks service disruption and imaging integrity.

cyberworldops.eu/en/orthanc-di

##

cyberworldops@infosec.exchange at 2026-09-13T18:50:01.000Z ##

Orthanc DICOM Server is affected by CVE-2026-87020, an integer overflow in image pitch calculation enabling authenticated heap out-of-bounds write via malicious PNG. It matters for clinical environments where exploitation risks service disruption and imaging integrity. #OrthancServer #DicomSecurity #HeapCorruption

cyberworldops.eu/en/orthanc-di

##

CVE-2026-89212
(8.6 HIGH)

EPSS: 0.33%

updated 2026-09-11T15:32:48

1 posts

A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions of Akana) and has been fixed as a security patch in the latest release of supported versions.

thehackerwire@mastodon.social at 2026-09-11T15:00:05.000Z ##

🟠 CVE-2026-89212 - High (8.6)

A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (includ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71416
(8.8 HIGH)

EPSS: 0.17%

updated 2026-09-11T15:17:03.373000

1 posts

Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket

thehackerwire@mastodon.social at 2026-09-11T15:00:16.000Z ##

🟠 CVE-2026-71416 - High (8.8)

Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81467
(9.8 CRITICAL)

EPSS: 3.84%

updated 2026-09-11T13:18:18.543000

2 posts

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

secdb at 2026-09-14T00:02:28.608Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-80462
(10.0 CRITICAL)

EPSS: 0.30%

updated 2026-09-11T13:18:18.300000

2 posts

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.

DailyCyberSecurity@infosec.exchange at 2026-09-12T01:42:24.000Z ##

Progress patched a critical Chef Automate vulnerability tracked as CVE-2026-80462. Fix this Chef Automate vulnerability to stop DevOps account takeovers.

#ChefAutomate #CVE202680462 #DevOpsSecurity #Cybersecurity #InfoSec

securityonline.info/chef-autom

##

thehackerwire@mastodon.social at 2026-09-11T15:00:28.000Z ##

🔴 CVE-2026-80462 - Critical (10)

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-0310
(0 None)

EPSS: 0.34%

updated 2026-09-11T04:17:13.060000

1 posts

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimiz

GossiTheDog@cyberplace.social at 2026-09-11T22:47:49.000Z ##

Palo-Alto are calling resellers and asking them to call customers to tell them to update their Palo-Alto PA and VM firewalls to cover CVE-2026-0310 - an unauthenticated XML parsing vulneraility which causes a buffer overflow leading to code execution, on the PA (physical) firewalls via the dataplane.
security.paloaltonetworks.com/

HT @databeestje

##

CVE-2026-17176(CVSS UNKNOWN)

EPSS: 3.59%

updated 2026-09-11T00:31:16

2 posts

An OS command injection vulnerability in the TDDP module of Deco BE11000 allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation may lead to complete device compromise, including unauthorized command execution, modification of device settings, and loss of confidentiality, integrity, and availability

secdb at 2026-09-14T00:02:28.608Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-89094
(9.9 CRITICAL)

EPSS: 0.50%

updated 2026-09-10T21:31:46

1 posts

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

DarkWebInformer@infosec.exchange at 2026-09-11T21:37:54.000Z ##

🚨 CVE-2026-89094: Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

CVSS: 9.9

Foregejo Update/Notes: codeberg.org/forgejo/forgejo/s

##

CVE-2026-65638
(0 None)

EPSS: 3.20%

updated 2026-09-10T19:54:25.810000

3 posts

Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed t

secdb at 2026-09-14T00:02:28.608Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

beyondmachines1@infosec.exchange at 2026-09-12T09:01:13.000Z ##

Critical ConfigServer Firewall Flaw Allows Unauthenticated Remote Command Execution

ConfigServer Security & Firewall (CSF) patched a critical shell injection vulnerability (CVE-2026-65638) in its MESSENGER service that allows unauthenticated remote code execution.

**If you run ConfigServer Security & Firewall (CSF) on your Linux or cPanel/WHM servers, update to version 16.30 right away (on cPanel systems run `yum clean all` then `/scripts/update-packages`) to close CVE-2026-65638. If you can't update immediately, turn the vulnerable feature off by setting `MESSENGER = 0` in `/etc/csf/csf.conf`, restart with `systemctl restart csf lfd`. Then check your logs for any unexpected commands run under the CSF service account.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-89049
(9.9 CRITICAL)

EPSS: 0.36%

updated 2026-09-10T19:44:21.980000

1 posts

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role cre

undercodenews@mastodon.social at 2026-09-14T06:58:02.000Z ##

Critical AWS Systems Manager Flaw Could Turn EC2 Instances Into Credential Theft Gateways

Introduction: A Trusted AWS Tool With a Dangerous Blind Spot A critical vulnerability in the AWS Systems Manager Agent has exposed a particularly dangerous weakness in cloud environments: an attacker who already has authorized Session Manager access may be able to turn an EC2 instance into a bridge toward services that were supposed to be unreachable. Tracked as CVE-2026-89049,…

undercodenews.com/critical-aws

##

CVE-2026-80352
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-09-10T18:33:12

1 posts

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation with the privileges of the operator. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before

DailyCyberSecurity@infosec.exchange at 2026-09-11T14:13:15.000Z ##

Three critical Apache Camel K vulnerabilities, including CVE-2026-80352, allow code injection and eval injection. Patch these critical flaws immediately.

#ApacheCamel #CamelK #Cybersecurity #CVE202680352 #InfoSec

securityonline.info/apache-cam

##

CVE-2026-81468
(9.1 CRITICAL)

EPSS: 2.28%

updated 2026-09-10T18:33:03

2 posts

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

secdb at 2026-09-14T00:02:28.608Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-20079
(10.0 CRITICAL)

EPSS: 75.75%

updated 2026-09-10T12:48:17.580000

7 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.&nbsp; This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this v

3 repos

https://github.com/DiegoArias008/CVE-2026-20079-checker

https://github.com/0xBlackash/CVE-2026-20079

https://github.com/CyberAuth/CVE-2026-20079

8bitsecurity@mastodon.social at 2026-09-14T07:05:00.000Z ##

🔎 NEXUS8 WEEKLY DIGEST · 💥 EXPLOIT

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. The vulnerability…

Also tracked this week: Hackers exploit Sangoma Switchvox flaw to deploy reverse… · Microsoft Plugs Nearly 1,000…

nexus8.8bitsecurity.com/entity

##

dgchultaeiz@hachyderm.io at 2026-09-13T13:26:24.000Z ##

¿Seguimos confiando demasiado?

Anderson hablaba de confianza en seguridad informática a comienzos de los años 70.

Más de cincuenta años después tenemos Cloud, SaaS, Zero Trust, MFA, PAM, EDR y tecnologías que en aquella época hubieran parecido ciencia ficción.

Entonces me hice una pregunta:

¿El problema también cambió?

En lugar de buscar la respuesta en otro paper, decidí mirar algunas vulnerabilidades recientes:

CVE-2026-20079
CVE-2026-19490
CVE-2025-25249
CVE-2026-20212

Authentication bypass, problemas de memoria, componentes de infraestructura...

Vulnerabilidades técnicamente muy diferentes.

Pero hay una pregunta interesante que podemos hacerle a cada una:

¿Qué tuvo que asumir el sistema para que esa vulnerabilidad pudiera existir?

De eso hablaremos próximamente

¿Seguimos confiando demasiado? —
De Anderson a la Inteligencia Artificial

##

netsecio@mastodon.social at 2026-09-12T17:43:34.000Z ##

📰 Cisco Firewall Flaws Actively Exploited by Ransomware & State Actors

Cisco warns multiple threat groups, including Qilin ransomware and state actors, are exploiting a critical auth bypass flaw (CVE-2026-20079) in Secure Firewall Management Center (FMC). CVSS 10.0. Patch now! #CVE202620079 #Cisco #Ransomware

🔗 cyber.netsecops.io/articles/ci

##

8bitsecurity@mastodon.social at 2026-09-14T07:05:00.000Z ##

🔎 NEXUS8 WEEKLY DIGEST · 💥 EXPLOIT

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. The vulnerability…

Also tracked this week: Hackers exploit Sangoma Switchvox flaw to deploy reverse… · Microsoft Plugs Nearly 1,000…

nexus8.8bitsecurity.com/entity

##

thenewoil@mastodon.thenewoil.org at 2026-09-11T20:00:01.000Z ##

#Cisco confirms CVE-2026-20079 #SecureFMC flaw exploited in attacks

bleepingcomputer.com/news/secu

#cybersecurity

##

security_crawler_carl@infosec.exchange at 2026-09-11T16:34:15.000Z ##

Reward: You've unlocked the Mandatory Remediation Sprint — a stackable negative buff. Enjoy your weekend.

tech-insider.org/cisco-fmc-cve

#CiscoFMC #CyberSecurity #CriticalVulnerability #Ransomware #CVSS10 #BudgetJustified (3/3)

##

security_crawler_carl@infosec.exchange at 2026-09-11T16:34:14.000Z ##

🏆 New Achievement! Perfect Score, Wrong Test!

Welcome, new player, to the Management Plane Tutorial. This is a mandatory segment. You cannot skip it. Your Cisco Firepower Management Console, CVE-2026-20079, has just rolled a CVSS 10.0 — a perfect score — and approximately 700 exposed instances are now enrolled in this questline whether they opted in or not. (1/3)

##

CVE-2026-19490
(9.8 CRITICAL)

EPSS: 5.60%

updated 2026-09-10T12:48:10.453000

2 posts

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

2 repos

https://github.com/BishopFox/CVE-2026-19490-check

https://github.com/TarPeg007/CVE-2026-19490

sayzard@mastodon.sayzard.org at 2026-09-14T04:38:48.000Z ##

Detecting and Weaponizing NetScaler

Citrix NetScaler ADC/Gateway의 SAML 처리 인증 우회 취약점 CVE-2026-19490(CVSS 9.3)이 공개됐다. 공격자는 인증 없이 특수한 RelayState 길이를 이용해 사후 로그인 처리 경로로 진입할 수 있으며, 구성에 따라 서비스 크래시(약 45초), 내부망 프록시 접근, 장비 root 명령 실행까지 이어질 수 있다. SAML이 설정된 Gateway·AAA 가상 서버가 주 대상이며, 특히 전역 VPN 기본 권한이 ALLOW이면 익명 세션이 내부 리소스에 접근할 위험이 커진다. 13.1-63.21 또는 14.1-7...

bishopfox.com/blog/mind-the-co

##

dgchultaeiz@hachyderm.io at 2026-09-13T13:26:24.000Z ##

¿Seguimos confiando demasiado?

Anderson hablaba de confianza en seguridad informática a comienzos de los años 70.

Más de cincuenta años después tenemos Cloud, SaaS, Zero Trust, MFA, PAM, EDR y tecnologías que en aquella época hubieran parecido ciencia ficción.

Entonces me hice una pregunta:

¿El problema también cambió?

En lugar de buscar la respuesta en otro paper, decidí mirar algunas vulnerabilidades recientes:

CVE-2026-20079
CVE-2026-19490
CVE-2025-25249
CVE-2026-20212

Authentication bypass, problemas de memoria, componentes de infraestructura...

Vulnerabilidades técnicamente muy diferentes.

Pero hay una pregunta interesante que podemos hacerle a cada una:

¿Qué tuvo que asumir el sistema para que esa vulnerabilidad pudiera existir?

De eso hablaremos próximamente

¿Seguimos confiando demasiado? —
De Anderson a la Inteligencia Artificial

##

CVE-2025-25249
(8.1 HIGH)

EPSS: 2.40%

updated 2026-09-10T12:47:59.933000

3 posts

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

DailyCyberSecurity at 2026-09-14T07:16:02.728Z ##

Discover how the PivotC2 FortiGate RAT uses CVE-2025-25249 exploitation to harvest credentials and tunnel traffic across corporate network environments.

securityonline.info/pivotc2-fo

##

dgchultaeiz@hachyderm.io at 2026-09-13T13:26:24.000Z ##

¿Seguimos confiando demasiado?

Anderson hablaba de confianza en seguridad informática a comienzos de los años 70.

Más de cincuenta años después tenemos Cloud, SaaS, Zero Trust, MFA, PAM, EDR y tecnologías que en aquella época hubieran parecido ciencia ficción.

Entonces me hice una pregunta:

¿El problema también cambió?

En lugar de buscar la respuesta en otro paper, decidí mirar algunas vulnerabilidades recientes:

CVE-2026-20079
CVE-2026-19490
CVE-2025-25249
CVE-2026-20212

Authentication bypass, problemas de memoria, componentes de infraestructura...

Vulnerabilidades técnicamente muy diferentes.

Pero hay una pregunta interesante que podemos hacerle a cada una:

¿Qué tuvo que asumir el sistema para que esa vulnerabilidad pudiera existir?

De eso hablaremos próximamente

¿Seguimos confiando demasiado? —
De Anderson a la Inteligencia Artificial

##

DailyCyberSecurity@infosec.exchange at 2026-09-14T07:16:02.000Z ##

Discover how the PivotC2 FortiGate RAT uses CVE-2025-25249 exploitation to harvest credentials and tunnel traffic across corporate network environments.

#PivotC2 #FortiGate #Malware #Cybercrime #CVE202525249

securityonline.info/pivotc2-fo

##

CVE-2026-69730
(9.8 CRITICAL)

EPSS: 1.05%

updated 2026-09-10T04:18:14.773000

2 posts

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

CVE-2026-50894
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-09-09T21:32:24

1 posts

easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.

hugovalters@mastodon.social at 2026-09-13T17:40:14.000Z ##

CVE-2026-50894: Unrestricted file upload in easyadmin v2.0.2.2 enables authenticated RCE and full server takeover. CVSS not scored, but impact is critical. If you use easyadmin, restrict access and audit uploads now. Patch valtersit.com/cve/CVE-2026-508

##

CVE-2026-75166
(8.8 HIGH)

EPSS: 0.49%

updated 2026-09-09T21:32:23

1 posts

Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a password. By leveraging the tcpdump -z option, an authenticated attacker can achieve arbitrary command execution.

hugovalters@mastodon.social at 2026-09-13T02:50:18.000Z ##

CVE-2026-75166: Insecure permission in MBS-Solutions X-Serie Gateway (V6_00_05) lets low-priv user run tcpdump as root, leading to RCE via -z flag. CVSS: N/A. Patch unknown—assume vulnerable. Restrict access & monitor now. valtersit.com/cve/CVE-2026-751 #CVE #infos

##

CVE-2026-53758
(0 None)

EPSS: 0.26%

updated 2026-09-09T18:16:59.010000

1 posts

Emlog is an open source website building system. In versions 2.6.29 and prior, article content is processed by Parsedown without enabling safe mode, which means raw HTML including <script> tags embedded in Markdown is passed through unescaped. The output is rendered with no additional sanitization, resulting in stored XSS visible to all site visitors. At time of publication, there are no publicly

hugovalters@mastodon.social at 2026-09-13T03:20:02.000Z ##

CVE-2026-53758: Stored XSS in Emlog ≤2.6.29 via Parsedown raw HTML. Unpatched—attacker can inject scripts into articles, hitting all visitors. No CVSS assigned. Patch unknown; restrict Markdown input or disable HTML now. Details: valtersit.com/cve/CVE-2026-537 #CVE

##

CVE-2026-50768
(8.8 HIGH)

EPSS: 0.45%

updated 2026-09-09T16:04:24.933000

1 posts

File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function.

DO3EET@mastodon.hams.social at 2026-09-13T09:50:43.000Z ##

@bsi Update zum Klärungsversuch bzgl. CVE-2026-50768:
Im Henkel-Repo heißt es zwar freundlich "For any inquiries or further details, feel free to reach out to us." – in der Praxis sind PRs, Issues & Diskussionen dicht und Kontaktinfos fehlen völlig.

Wie betreibt man eigentlich #ResponsibleDisclosure, wenn man offiziell zum Dialog einlädt, aber sämtliche Feedback-Türen fest verriegelt? 😉

#HenkelAG #Henkel #CyberSecurity #InfoSec #AppSec #ITSec #GitHub #Sicherheit #BugBounty #CVE

##

CVE-2026-78745
(9.8 CRITICAL)

EPSS: 0.72%

updated 2026-09-09T16:04:24.933000

1 posts

An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via the Android Debug Bridge (ADB) daemon (adbd)

1 repos

https://github.com/n0c71v3x/CVE-2026-78745

hugovalters@mastodon.social at 2026-09-12T21:20:05.000Z ##

CVE-2026-78745: Unpatched flaw in HiDPT Android (Hi3751V350/V352E) allows remote code execution via ADB daemon. Risk is critical if ADB exposed. CVSS N/A. Check exposure and restrict ADB now. Details: valtersit.com/cve/CVE-2026-787 #CVE #Android #infosec

##

CVE-2026-85103
(9.8 CRITICAL)

EPSS: 0.36%

updated 2026-09-09T15:35:15

9 posts

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

undercodenews@mastodon.social at 2026-09-14T05:34:50.000Z ##

Critical Check Point VPN Flaws Put Organizations on High Alert as Exploitation Threat Looms + Video

Introduction: A Dangerous Warning for Internet-Facing VPNs A new cybersecurity warning from the Netherlands’ National Cyber Security Center (NCSC) is putting organizations using Check Point VPN technology on notice. Two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, have received a near-maximum CVSS score of 9.8, and security officials believe large-scale…

undercodenews.com/critical-che

##

threatnoir at 2026-09-14T02:05:45.842Z ##

⚠️ CRITICAL: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Two critical remote code execution vulnerabilities in Check Point VPN (CVE-2026-85102 and CVE-2026-85103) are facing imminent exploitation. Any organization running affected Check Point VPN appliances is at immediate risk of full system compromise. Unpatched instances are likely to be targeted with…

threatnoir.com/focus

🤖 AI generated summary

##

netsecio@mastodon.social at 2026-09-13T16:23:48.000Z ##

📰 Check Point patches two critical 9.8 CVSS flaws in VPN products

Check Point patches two critical 9.8 CVSS vulnerabilities (CVE-2026-85102, CVE-2026-85103) in its VPN products. Flaws could allow unauthenticated RCE. Admins are urged to apply hotfixes immediately. #CyberSecurity #Vulnerability #VPN #PatchNow

🔗 cyber.netsecops.io/articles/ch

##

guru@thecybersecguru.com at 2026-09-13T13:02:46.000Z ##

Check Point patches two critical VPN gateway flaws scoring 9.8 on CVSS

Check Point patches two critical VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, rated CVSS 9.8 and capable of unauthenticated remote code execution

thecybersecguru.com/news/check

##

daniel1820815 at 2026-09-13T10:08:42.324Z ##

@cyberwald Bevor man hier einen Hersteller zu CVEs verurteilt, sollte man vielleicht tiefer recherchieren und dazu ein paar Fakten hinzufügen.

Beide Schwachstellen wurden intern entdeckt und bis zur Veröffentlichung gab es keine Hinweise darauf, dass sie in freier Wildbahn ausgenutzt wurden. Weiterhin gab es zu jedem CVE direkt entsprechende Anweisungen und Patches:

Darüber hinaus gibt es mittlerweile die Funktion Check Point Live Patch (CPLP), welches ein im Betriebssystem Gaia enthaltener Dienst zur Bereitstellung von Abwehrmaßnahmen ist. Es schließt kritische Schwachstellen im laufenden Betrieb durch gezielte In-Memory-Korrekturen (Live-Patches). -> support.checkpoint.com/results



##

threatnoir@infosec.exchange at 2026-09-14T02:05:45.000Z ##

⚠️ CRITICAL: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Two critical remote code execution vulnerabilities in Check Point VPN (CVE-2026-85102 and CVE-2026-85103) are facing imminent exploitation. Any organization running affected Check Point VPN appliances is at immediate risk of full system compromise. Unpatched instances are likely to be targeted with…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

guru@thecybersecguru.com at 2026-09-13T13:02:46.000Z ##

Check Point patches two critical VPN gateway flaws scoring 9.8 on CVSS

Check Point patches two critical VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, rated CVSS 9.8 and capable of unauthenticated remote code execution

thecybersecguru.com/news/check

##

daniel1820815@infosec.exchange at 2026-09-13T10:08:42.000Z ##

@cyberwald Bevor man hier einen Hersteller zu CVEs verurteilt, sollte man vielleicht tiefer recherchieren und dazu ein paar Fakten hinzufügen.

Beide Schwachstellen wurden intern entdeckt und bis zur Veröffentlichung gab es keine Hinweise darauf, dass sie in freier Wildbahn ausgenutzt wurden. Weiterhin gab es zu jedem CVE direkt entsprechende Anweisungen und Patches:

Darüber hinaus gibt es mittlerweile die Funktion Check Point Live Patch (CPLP), welches ein im Betriebssystem Gaia enthaltener Dienst zur Bereitstellung von Abwehrmaßnahmen ist. Es schließt kritische Schwachstellen im laufenden Betrieb durch gezielte In-Memory-Korrekturen (Live-Patches). -> support.checkpoint.com/results

#CheckPoint #CheckpointsoftwareTechnologies
#CheckPointsw
#CVE #CVE202685102 #CVE202685103

##

cR0w@infosec.exchange at 2026-09-12T14:18:21.000Z ##

ncsc.nl/alerts/kritieke-kwetsb

Er zijn 2 kritieke kwetsbaarheden in Check Point VPN-producten, met de kenmerken CVE-2026-85102 en CVE-2026-85103. Het gaat om 2 ernstige kwetsbaarheden met een CVSS-score van 9,8. Het NCSC beoordeelt de kans op misbruik en de mogelijke schade als hoog en verwacht dat er snel pogingen tot misbruik zullen plaatsvinden, het advies is dan ook om de updates zo snel mogelijk te installeren.

Translated by LibreWolf:

There are 2 critical vulnerabilities in Check Point VPN products, with the characteristics CVE-2026-85102 and CVE-2026-85103. This concerns 2 serious vulnerabilities with a CVSS score of 9.8. The NCSC assesses the risk of abuse and possible damage as high and expects that attempts at abuse will take place quickly, so the advice is to install the updates as quickly as possible.

##

CVE-2026-85102
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-09-09T15:35:15

9 posts

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

undercodenews@mastodon.social at 2026-09-14T05:34:50.000Z ##

Critical Check Point VPN Flaws Put Organizations on High Alert as Exploitation Threat Looms + Video

Introduction: A Dangerous Warning for Internet-Facing VPNs A new cybersecurity warning from the Netherlands’ National Cyber Security Center (NCSC) is putting organizations using Check Point VPN technology on notice. Two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, have received a near-maximum CVSS score of 9.8, and security officials believe large-scale…

undercodenews.com/critical-che

##

threatnoir at 2026-09-14T02:05:45.842Z ##

⚠️ CRITICAL: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Two critical remote code execution vulnerabilities in Check Point VPN (CVE-2026-85102 and CVE-2026-85103) are facing imminent exploitation. Any organization running affected Check Point VPN appliances is at immediate risk of full system compromise. Unpatched instances are likely to be targeted with…

threatnoir.com/focus

🤖 AI generated summary

##

netsecio@mastodon.social at 2026-09-13T16:23:48.000Z ##

📰 Check Point patches two critical 9.8 CVSS flaws in VPN products

Check Point patches two critical 9.8 CVSS vulnerabilities (CVE-2026-85102, CVE-2026-85103) in its VPN products. Flaws could allow unauthenticated RCE. Admins are urged to apply hotfixes immediately. #CyberSecurity #Vulnerability #VPN #PatchNow

🔗 cyber.netsecops.io/articles/ch

##

guru@thecybersecguru.com at 2026-09-13T13:02:46.000Z ##

Check Point patches two critical VPN gateway flaws scoring 9.8 on CVSS

Check Point patches two critical VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, rated CVSS 9.8 and capable of unauthenticated remote code execution

thecybersecguru.com/news/check

##

daniel1820815 at 2026-09-13T10:08:42.324Z ##

@cyberwald Bevor man hier einen Hersteller zu CVEs verurteilt, sollte man vielleicht tiefer recherchieren und dazu ein paar Fakten hinzufügen.

Beide Schwachstellen wurden intern entdeckt und bis zur Veröffentlichung gab es keine Hinweise darauf, dass sie in freier Wildbahn ausgenutzt wurden. Weiterhin gab es zu jedem CVE direkt entsprechende Anweisungen und Patches:

Darüber hinaus gibt es mittlerweile die Funktion Check Point Live Patch (CPLP), welches ein im Betriebssystem Gaia enthaltener Dienst zur Bereitstellung von Abwehrmaßnahmen ist. Es schließt kritische Schwachstellen im laufenden Betrieb durch gezielte In-Memory-Korrekturen (Live-Patches). -> support.checkpoint.com/results



##

threatnoir@infosec.exchange at 2026-09-14T02:05:45.000Z ##

⚠️ CRITICAL: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Two critical remote code execution vulnerabilities in Check Point VPN (CVE-2026-85102 and CVE-2026-85103) are facing imminent exploitation. Any organization running affected Check Point VPN appliances is at immediate risk of full system compromise. Unpatched instances are likely to be targeted with…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

guru@thecybersecguru.com at 2026-09-13T13:02:46.000Z ##

Check Point patches two critical VPN gateway flaws scoring 9.8 on CVSS

Check Point patches two critical VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, rated CVSS 9.8 and capable of unauthenticated remote code execution

thecybersecguru.com/news/check

##

daniel1820815@infosec.exchange at 2026-09-13T10:08:42.000Z ##

@cyberwald Bevor man hier einen Hersteller zu CVEs verurteilt, sollte man vielleicht tiefer recherchieren und dazu ein paar Fakten hinzufügen.

Beide Schwachstellen wurden intern entdeckt und bis zur Veröffentlichung gab es keine Hinweise darauf, dass sie in freier Wildbahn ausgenutzt wurden. Weiterhin gab es zu jedem CVE direkt entsprechende Anweisungen und Patches:

Darüber hinaus gibt es mittlerweile die Funktion Check Point Live Patch (CPLP), welches ein im Betriebssystem Gaia enthaltener Dienst zur Bereitstellung von Abwehrmaßnahmen ist. Es schließt kritische Schwachstellen im laufenden Betrieb durch gezielte In-Memory-Korrekturen (Live-Patches). -> support.checkpoint.com/results

#CheckPoint #CheckpointsoftwareTechnologies
#CheckPointsw
#CVE #CVE202685102 #CVE202685103

##

cR0w@infosec.exchange at 2026-09-12T14:18:21.000Z ##

ncsc.nl/alerts/kritieke-kwetsb

Er zijn 2 kritieke kwetsbaarheden in Check Point VPN-producten, met de kenmerken CVE-2026-85102 en CVE-2026-85103. Het gaat om 2 ernstige kwetsbaarheden met een CVSS-score van 9,8. Het NCSC beoordeelt de kans op misbruik en de mogelijke schade als hoog en verwacht dat er snel pogingen tot misbruik zullen plaatsvinden, het advies is dan ook om de updates zo snel mogelijk te installeren.

Translated by LibreWolf:

There are 2 critical vulnerabilities in Check Point VPN products, with the characteristics CVE-2026-85102 and CVE-2026-85103. This concerns 2 serious vulnerabilities with a CVSS score of 9.8. The NCSC assesses the risk of abuse and possible damage as high and expects that attempts at abuse will take place quickly, so the advice is to install the updates as quickly as possible.

##

CVE-2026-56711
(8.8 HIGH)

EPSS: 0.30%

updated 2026-09-09T15:35:15

5 posts

VLC media player computes the size of a picture buffer with 32-bit arithmetic and allocates from the wrapped result. In AllocatePicture in src/misc/picture.c the running total is accumulated as i_bytes += p->i_pitch * p->i_lines, and both plane_t fields are declared int in include/vlc_picture.h, so the multiplication is evaluated at 32 bits and wraps before it is widened to the size_t accumulator.

beyondmachines1 at 2026-09-13T17:01:13.011Z ##

VLC Media Player Flaws Allow Heap Corruption and Sensitive Data Disclosure

VideoLAN reports two vulnerabilities in VLC Media Player (CVE-2026-56711 and CVE-2026-73324) that allow attackers to corrupt heap memory or leak sensitive data via crafted PNG files and RTSP streams.

**If you use VLC Media Player (any version from 3.0.0 to 3.0.23), update it to the latest patched version as soon as VideoLAN releases it. Until you've updated, don't open media files, playlists, or RTSP streaming links that come from people or websites you don't know and trust.**

beyondmachines.net/event_detai

##

guru@thecybersecguru.com at 2026-09-12T17:11:54.000Z ##

VLC Media Player hit by two critical security flaws: heap corruption and memory disclosure putting millions at risk

Two critical VLC Media Player vulnerabilities, CVE-2026-56711 and CVE-2026-73324, expose users to heap corruption and memory disclosure. Here’s what to do

thecybersecguru.com/news/vlc-m

##

beyondmachines1@infosec.exchange at 2026-09-13T17:01:13.000Z ##

VLC Media Player Flaws Allow Heap Corruption and Sensitive Data Disclosure

VideoLAN reports two vulnerabilities in VLC Media Player (CVE-2026-56711 and CVE-2026-73324) that allow attackers to corrupt heap memory or leak sensitive data via crafted PNG files and RTSP streams.

**If you use VLC Media Player (any version from 3.0.0 to 3.0.23), update it to the latest patched version as soon as VideoLAN releases it. Until you've updated, don't open media files, playlists, or RTSP streaming links that come from people or websites you don't know and trust.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

guru@thecybersecguru.com at 2026-09-12T17:11:54.000Z ##

VLC Media Player hit by two critical security flaws: heap corruption and memory disclosure putting millions at risk

Two critical VLC Media Player vulnerabilities, CVE-2026-56711 and CVE-2026-73324, expose users to heap corruption and memory disclosure. Here’s what to do

thecybersecguru.com/news/vlc-m

##

DarkWebInformer@infosec.exchange at 2026-09-11T16:37:27.000Z ##

🚨 Two VLC Media Player flaws can allow code execution and leak sensitive memory

Security researchers have disclosed two vulnerabilities affecting VLC Media Player versions 3.0.0 through 3.0.23.

CVE-2026-56711, rated 8.6, is a heap out-of-bounds write caused by an integer overflow in VLC's picture buffer allocation.

An attacker can craft a malicious PNG with manipulated dimensions that causes VLC to allocate an undersized memory buffer before writing beyond its boundaries.

The flaw can potentially lead to arbitrary code execution when the malicious image is opened directly or loaded through a playlist.

CVE-2026-73324, rated 6.9, affects VLC's RealRTSP handling.

A malicious RTSP server can send an oversized response that causes VLC to read beyond an allocated buffer and return adjacent heap memory to the attacker, potentially exposing sensitive information.

The vulnerable RealRTSP component is enabled in official VideoLAN builds, although some Linux distribution packages may compile VLC without it.

As of September 11, VLC 3.0.23 remains the current stable desktop release listed by VideoLAN and is affected by both vulnerabilities.

Users should avoid opening untrusted image files or RealRTSP playlist links until an updated release addressing the flaws becomes available.

Source: securityonline.info/vlc-media-

##

CVE-2026-86218
(9.8 CRITICAL)

EPSS: 0.74%

updated 2026-09-09T05:18:19.490000

4 posts

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

2 repos

https://github.com/HORKimhab/CVE-2026-86218

https://github.com/jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit

DailyCyberSecurity at 2026-09-14T02:34:52.487Z ##

CVE-2026-86218, a CVSS 10 N-central vulnerability, is exploited in the wild for remote code execution. A public Metasploit PoC is out. Patch now.

securityonline.info/n-able-n-c

##

threatcodex at 2026-09-12T18:13:24.202Z ##

CVE-2026-86218: Active Exploitation of N-able N-central: Critical Pre-Auth Remote Code Execution (RCE) Vulnerability

arcticwolf.com/resources/blog/

##

DailyCyberSecurity@infosec.exchange at 2026-09-14T02:34:52.000Z ##

CVE-2026-86218, a CVSS 10 N-central vulnerability, is exploited in the wild for remote code execution. A public Metasploit PoC is out. Patch now.

#Nable #Ncentral #CVE202686218 #Cybersecurity #InfoSec

securityonline.info/n-able-n-c

##

threatcodex@infosec.exchange at 2026-09-12T18:13:24.000Z ##

CVE-2026-86218: Active Exploitation of N-able N-central: Critical Pre-Auth Remote Code Execution (RCE) Vulnerability
#N_central #CVE_2026_86218
arcticwolf.com/resources/blog/

##

CVE-2026-85880
(7.8 HIGH)

EPSS: 0.57%

updated 2026-09-09T05:18:19.193000

1 posts

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

PC_Fluesterer@social.tchncs.de at 2026-09-11T15:02:15.000Z ##

Die allerschlechteste Kombination: Chrome und Windows

Wer sich wundert, weshalb Chromium und und daraus abgeleitete Browser (Chrome, Edge, Opera, Vivaldi) schon wieder Updates erhalten, hier ist die Erklärung. Ein Sicherheitsunternehmen hat entdeckt, dass mindestens vier Gruppen von Cybergangstern eine Kette von Sicherheitslücken nutzen, um in Institution (Firmen, Behörden) vor allem in den USA und Südostasien einzudringen. Die Angreifer verketten zwei Sicherheitslücken in Chrome (CVE-2026-85046 und ein Sandkasten-Ausbruch ohne CVE-Nummer) mit einer in Windows (CVE-2026-85880). Die Lücke in Windows wurde gerade geflickt. ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #browser #chrome #cybercrime #exploits #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump #windows

##

CVE-2026-75650
(10.0 CRITICAL)

EPSS: 2.15%

updated 2026-09-09T05:18:07.237000

2 posts

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

5 repos

https://github.com/disrex-group/stylesmuggler-adobe-patches

https://github.com/jithinkrishnanrs/stylesmuggler-ioc-toolkit

https://github.com/dinosn/cve-2026-75650-magento-validation-lab

https://github.com/fortbridge/stylesmuggler

https://github.com/disrex-group/stylesmuggler-adobe-patches-mageos

secdb at 2026-09-14T00:02:28.608Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12745
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-09-09T05:17:19.467000

2 posts

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

secdb at 2026-09-14T00:02:28.608Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18073
(4.4 MEDIUM)

EPSS: 0.10%

updated 2026-09-08T19:44:49.527000

1 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements.

hugovalters@mastodon.social at 2026-09-13T16:00:01.000Z ##

CVE-2026-18073 IBM i 7.3-7.6: local authenticated attacker can inject parameters into a CL command (improper input neutralization). CVSS 4.4. No patch yet—assume risk. Restrict local access & monitor. Details: valtersit.com/cve/CVE-2026-180 #CVE #IBM #infosec

##

CVE-2026-85636
(5.3 MEDIUM)

EPSS: 0.43%

updated 2026-09-08T18:21:12.550000

1 posts

A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the file core/stats.py of the component Login Endpoint. The manipulation leads to missing authentication. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not respo

hugovalters@mastodon.social at 2026-09-13T11:20:02.000Z ##

CVE-2026-85636: Missing authentication in Trape 1.0.0 (core/stats.py Login Endpoint). Remote exploit is public; project unpatched and unresponsive. CVSS 5.3. If you run Trape, assume compromise and isolate now. Details: valtersit.com/cve/CVE-2026-856 #CVE #infosec

##

CVE-2026-13297
(7.5 HIGH)

EPSS: 0.25%

updated 2026-09-08T18:17:35.057000

1 posts

IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.

hugovalters@mastodon.social at 2026-09-13T14:30:02.000Z ##

CVE-2026-13297: IBM Verify Identity Access (AAC) risks info disclosure. CVSS N/A, patch status unknown. If you use it, audit exposure now. Details: valtersit.com/cve/CVE-2026-132 #CVE #infosec #IBM

##

CVE-2026-12744
(9.8 CRITICAL)

EPSS: 2.17%

updated 2026-09-08T15:32:04

2 posts

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

secdb at 2026-09-14T00:02:28.608Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-79697
(9.9 CRITICAL)

EPSS: 3.35%

updated 2026-09-07T09:31:46

2 posts

A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argu

secdb at 2026-09-14T00:02:28.608Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-09-14T00:02:28.000Z ##

📈 CVE Published in last 7 days (2026-09-07 - 2026-09-07)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 346
- High: 1713
- Medium: 1297
- Low: 177
- None: 301

Status:
- : 75
- Analyzed: 817
- Awaiting Analysis: 956
- Deferred: 771
- Modified: 23
- Received: 764
- Rejected: 23
- Undergoing Analysis: 405

CISA KEVs:
- CISA-2026:0908 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0909 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0910 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0911 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Microsoft Corporation: 967
- kernel.org: 443
- VulnCheck: 349
- Chrome: 230
- Adobe Systems Incorporated: 168
- VulDB: 156
- GitHub, Inc.: 134
- MITRE: 125
- Dell: 115
- WPScan: 105

Top Affected Products:
- UNKNOWN: 2097
- Microsoft Windows Server 2025: 676
- Microsoft Windows Server 2022: 638
- Microsoft Windows 11 24h2: 626
- Microsoft Windows 11 25h2: 625
- Microsoft Windows 11 26h1: 625
- Microsoft Windows Server 2019: 613
- Microsoft Windows 10 1809: 609
- Microsoft Windows 11 23h2: 599
- Microsoft Windows 10 22h2: 566

Top EPSS Score:
- CVE-2026-81467 - 3.84 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17176 - 3.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-79697 - 3.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-78488 - 3.25 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65638 - 3.20 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-89010 - 2.85 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-81468 - 2.28 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12744 - 2.17 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-75650 - 2.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12745 - 2.09 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

PC_Fluesterer@social.tchncs.de at 2026-09-11T15:02:15.000Z ##

Die allerschlechteste Kombination: Chrome und Windows

Wer sich wundert, weshalb Chromium und und daraus abgeleitete Browser (Chrome, Edge, Opera, Vivaldi) schon wieder Updates erhalten, hier ist die Erklärung. Ein Sicherheitsunternehmen hat entdeckt, dass mindestens vier Gruppen von Cybergangstern eine Kette von Sicherheitslücken nutzen, um in Institution (Firmen, Behörden) vor allem in den USA und Südostasien einzudringen. Die Angreifer verketten zwei Sicherheitslücken in Chrome (CVE-2026-85046 und ein Sandkasten-Ausbruch ohne CVE-Nummer) mit einer in Windows (CVE-2026-85880). Die Lücke in Windows wurde gerade geflickt. ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #browser #chrome #cybercrime #exploits #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump #windows

##

CVE-2026-86100
(6.4 MEDIUM)

EPSS: 0.19%

updated 2026-09-05T00:31:15

1 posts

Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. Authenticated attackers can supply URLs that pass initial validation but redirect to internal network addresses, allowing server-side request forgery to internal services.

hugovalters@mastodon.social at 2026-09-13T09:50:16.000Z ##

CVE-2026-86100: Camaleon CMS SSRF via media upload redirect bypass. Versions 2.7.5-2.9.1 expose internal services to authenticated attackers. CVSS 6.4. Unpatched—act now. Details: valtersit.com/cve/CVE-2026-861 #CVE #infosec

##

CVE-2026-80897(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-09-04T18:31:46

1 posts

In the Linux kernel, the following vulnerability has been resolved: netfs: release readahead folios on iterator preparation failure netfs_prepare_read_iterator() batches readahead folios in put_batch so that the folio references can be dropped after the I/O iterator has been prepared. If rolling_buffer_load_from_ra() fails after earlier folios have been batched, the function returns immediately

hugovalters@mastodon.social at 2026-09-14T02:10:01.000Z ##

CVE-2026-80897 - Linux kernel netfs flaw leaves readahead folio refs held on iterator prep failure, risking memory exhaustion. CVSS N/A. Currently unpatched. If you run a kernel with netfs, monitor for updates and test mitigations. valtersit.com/cve/CVE-2026-808

##

CVE-2026-80912(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-09-04T18:31:46

1 posts

In the Linux kernel, the following vulnerability has been resolved: selinux: reject an unclaimed class value in security_get_classes() security_get_classes() sizes an array by p_classes.nprim and fills it at value - 1, so a class value the policy never defines leaves a NULL. sel_make_classes() passes every entry to sel_make_dir(), reaching the same d_alloc_name() dereference as the permission ar

hugovalters@mastodon.social at 2026-09-13T20:50:05.000Z ##

CVE-2026-80912: Linux kernel SELinux flaw—a NULL deref via an unclaimed class value can crash the system. CVSS: N/A, unpatched. If you run SELinux, review your policy and wait for the fix. Patch ASAP when available. valtersit.com/cve/CVE-2026-809 #CVE #Linux #infos

##

CVE-2026-80904(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-09-04T18:31:46

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/tls: Fail tls_sw_splice_read() after a failed async decrypt When an async decrypt fails, tls_decrypt_done() records the error in ctx->async_wait.err and calls tls_err_abort(), which stores it in sk_err. tls_sw_recvmsg() and tls_sw_read_sock() each read async_wait.err once they hold the reader lock and fail the call: a record

hugovalters@mastodon.social at 2026-09-13T19:10:14.000Z ##

CVE-2026-80904 Linux kernel TLS flaw: failed async decrypt can bypass splice_read check, breaking connection authentication. CVSS N/A, unpatched. If you rely on kernel TLS splicing, audit exposure now. Update once fix lands. valtersit.com/cve/CVE-2026-809 #CVE #inf

##

CVE-2026-80909(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-09-04T18:31:46

1 posts

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Reject UVD message with invalid number of h265 refs Same change as for h264, avoids overflow later when calculating min dpb size. (cherry picked from commit a4b0720e4f1601f97f59a2be9c1b4b94fa6527d5)

hugovalters@mastodon.social at 2026-09-13T05:10:12.000Z ##

CVE-2026-80909 affects Linux kernel drm/amdgpu: UVD messages with invalid h265 refs can trigger an overflow. Potential for local DoS or memory corruption. CVSS not assigned, patch unknown. Update your kernel once a fix is available. valtersit.com/cve/CVE-2026-809

##

CVE-2026-80901(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-09-04T18:31:46

1 posts

In the Linux kernel, the following vulnerability has been resolved: ipvs: fix the checksum validations ip_vs_in_icmp_v6() is missing checksum validation for ICMPv6 packets from clients. In fact, as for TCP/UDP we should validate the checksum for ICMP packets only when we mangle the packets on MASQ or on reply for tunnel. Also, Sashiko points out that handle_response_icmp() being common for IPv4

hugovalters@mastodon.social at 2026-09-13T03:30:01.000Z ##

CVE-2026-80901: Linux kernel IPVS flaw allows unvalidated ICMPv6 checksums, risking packet manipulation in MASQ/tunnel setups. Unpatched & unknown CVSS—treat as high risk. Patch status unclear, so audit your kernel now. Details: valtersit.com/cve/CVE-2026-809 #CVE

##

CVE-2026-80883(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-09-04T18:31:41

1 posts

In the Linux kernel, the following vulnerability has been resolved: drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered The host1x_client_register() function is called just prior to register map initialization loop, making the device available to userspace. This may result in userspace attempting to submits a job before the register map is initialized. Addres

hugovalters@mastodon.social at 2026-09-13T03:30:34.000Z ##

CVE-2026-80883: Linux kernel flaw in drm/tegra gr2d/gr3d. Potential race condition lets userspace submit jobs before register map init—can lead to crashes or privilege issues. Unpatched; impact uncertain. If you run Tegra, test valtersit.com/cve/CVE-2026-808

##

CVE-2026-17273
(6.5 MEDIUM)

EPSS: 0.35%

updated 2026-09-04T18:31:40

1 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference.

hugovalters@mastodon.social at 2026-09-14T03:10:00.000Z ##

CVE-2026-17273: IBM i (7.3-7.6) flaw lets authenticated remote users trigger DoS via NULL pointer deref. CVSS 6.5. Unpatched—assume risk. Isolate admin access & monitor logs. Details: valtersit.com/cve/CVE-2026-172 Patch when available. #CVE #IBM #cybersecurity

##

CVE-2026-16693
(4.4 MEDIUM)

EPSS: 0.13%

updated 2026-09-04T18:31:40

1 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys.

hugovalters@mastodon.social at 2026-09-14T01:20:02.000Z ##

CVE-2026-16693: IBM i 7.3-7.6 flaw lets authenticated remote users grab sensitive data via hardcoded crypto constants to obfuscate keys. CVSS 4.4. No patch yet. Mitigate: restrict access, monitor logs. Details: valtersit.com/cve/CVE-2026-166 #CVE #IBM #infosec

##

CVE-2026-80880(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-09-04T18:31:40

1 posts

In the Linux kernel, the following vulnerability has been resolved: IB/mlx5: Properly support implicit ODP rereg_mr Due to all the child mkeys in the implicit ODP configuration we cannot change anything in place for the parent mkey. Instead the whole thing needs to be rebuilt if any change is requested. If the user does not specify a translation then force the implicit values which will then fal

hugovalters@mastodon.social at 2026-09-12T16:30:03.000Z ##

CVE-2026-80880: Linux kernel flaw in IB/mlx5 implicit ODP mkey handling. Exploitable to corrupt memory or crash systems—impact not fully disclosed. CVSS N/A, no patch available. Track this actively; test mitigations, restrict valtersit.com/cve/CVE-2026-808

##

CVE-2026-80913
(0 None)

EPSS: 0.17%

updated 2026-09-04T18:18:01.200000

1 posts

In the Linux kernel, the following vulnerability has been resolved: selinux: require every boolean value to be defined p_bools.nprim comes from the policy image independently of how many booleans follow it, and cond_index_bool() fills bool_val_to_struct[] at value - 1, so a count larger than the values present leaves NULL entries. Every user of that array then walks it by index and dereferences

hugovalters@mastodon.social at 2026-09-13T08:10:01.000Z ##

CVE-2026-80913: Linux kernel SELinux flaw – missing boolean definition check can lead to NULL deref. Potential crash/privilege issues. CVSS: N/A. Patch status unknown – treat as unpatched. Review & update kernels now. valtersit.com/cve/CVE-2026-809 #CVE #Linux #inf

##

CVE-2026-80894
(0 None)

EPSS: 0.17%

updated 2026-09-04T18:17:57.603000

1 posts

In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace iommufd_hwpt_replace_device() calls: iommufd_auto_response_faults(hwpt, old_handle); passing the *new* hwpt together with the handle of the device's *old* domain. This should be a parameter mismatch: 1. Semantically, iommufd_auto_response_faults(x, han

hugovalters@mastodon.social at 2026-09-13T06:40:18.000Z ##

CVE-2026-80894: Linux kernel iommufd flaw passes wrong hwpt on device replace, causing fault response mismatches. Impact unclear; CVSS N/A. Patch status unknown—assume risk. Check your kernel version and update immediately if a fix valtersit.com/cve/CVE-2026-808

##

CVE-2026-80890
(0 None)

EPSS: 0.18%

updated 2026-09-04T18:17:57.077000

1 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: reject stale cookies with mismatched verification tags sctp_unpack_cookie() skips cookie expiration checks whenever an association already exists. This is broader than the exception in RFC 9260 Section 5.2.4. For an existing association, Section 5.2.4 permits an expired State Cookie only when both Verification Tags in th

hugovalters@mastodon.social at 2026-09-12T18:10:13.000Z ##

CVE-2026-80890: Linux kernel SCTP flaw allows stale cookies with mismatched verification tags to bypass checks, risking connection hijacking or DoS. CVSS N/A, unpatched. Patch when available; audit SCTP exposure now. valtersit.com/cve/CVE-2026-808 #CVE #infosec #Li

##

CVE-2026-80871
(0 None)

EPSS: 0.15%

updated 2026-09-04T17:16:59.027000

1 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: xilinx-trng - Remove crypto_rng interface Implementing the crypto_rng interface has no purpose, as it isn't used in practice. It's being removed from other drivers too. Just remove it. This leaves hwrng, which is actually used. Tagging with 'Cc stable' due to the bugs that this removes: - xtrng_trng_generate() som

hugovalters@mastodon.social at 2026-09-12T19:40:06.000Z ##

CVE-2026-80871: Linux kernel crypto/xilinx-trng bug—removed crypto_rng interface that could return success without filling buffers. Potential data integrity risk. CVSS: N/A. Patch status unclear—check your kernel. Details: valtersit.com/cve/CVE-2026-808 Update kern

##

CVE-2026-20212
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-09-03T13:04:38.177000

1 posts

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with&nbsp;root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device an

1 repos

https://github.com/HORKimhab/CVE-2026-20212

dgchultaeiz@hachyderm.io at 2026-09-13T13:26:24.000Z ##

¿Seguimos confiando demasiado?

Anderson hablaba de confianza en seguridad informática a comienzos de los años 70.

Más de cincuenta años después tenemos Cloud, SaaS, Zero Trust, MFA, PAM, EDR y tecnologías que en aquella época hubieran parecido ciencia ficción.

Entonces me hice una pregunta:

¿El problema también cambió?

En lugar de buscar la respuesta en otro paper, decidí mirar algunas vulnerabilidades recientes:

CVE-2026-20079
CVE-2026-19490
CVE-2025-25249
CVE-2026-20212

Authentication bypass, problemas de memoria, componentes de infraestructura...

Vulnerabilidades técnicamente muy diferentes.

Pero hay una pregunta interesante que podemos hacerle a cada una:

¿Qué tuvo que asumir el sistema para que esa vulnerabilidad pudiera existir?

De eso hablaremos próximamente

¿Seguimos confiando demasiado? —
De Anderson a la Inteligencia Artificial

##

sayzard@mastodon.sayzard.org at 2026-09-14T02:41:08.000Z ##

Artifactory: In-the-Wild Exploitation of CVE-2026-42016,CVE-2026-42018

Wiz Research는 JFrog Artifactory의 CVE-2026-42016, CVE-2026-42018, CVE-2026-82329가 실제 환경에서 활발히 악용되고 있음을 확인했다. 공격자는 익명 사용자 토큰 노출과 토큰 스코프 검증 결함을 연쇄해 인증 없이 관리자 권한 토큰을 획득하거나, CVE-2026-82329의 인증 우회로 직접 관리자 권한을 얻을 수 있다. 침해 후에는 지속성 관리자 계정 생성, Groovy 플러그인을 통한 서버 명령 실행, 클러스...

wiz.io/blog/artifactory-under-

##

threatnoir@infosec.exchange at 2026-09-12T01:05:51.000Z ##

⚠️ CRITICAL: Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers are chaining multiple JFrog Artifactory vulnerabilities (CVE-2026-42018, CVE-2026-42016, CVE-2026-82329) to escalate from anonymous users to administrator control on self-hosted instances. This grants them ability to plant backdoors and execute arbitrary shell commands in your build pipel…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

cyberworldops@infosec.exchange at 2026-09-11T18:30:01.000Z ##

Active exploitation chains CVE-2026-42018 and CVE-2026-42016 to bypass authentication on self-hosted JFrog Artifactory and deploy a Rust backdoor with C2. CVE-2026-82329 is also abused to create admin tokens. This enables full server takeover and supply chain compromise. #JFrog #Artifactory #SupplyChainSecurity

cyberworldops.eu/en/attackers-

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 45.88%

updated 2026-08-19T04:17:24.940000

1 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

2 repos

https://github.com/HORKimhab/CVE-2026-59310

https://github.com/BiuTrap/CVE-2026-59310

kev_Stalker@infosec.exchange at 2026-09-12T13:15:13.000Z ##

CVE-2026-59310 - Changed to Known Ransomware Status

Broadcom VMware vCenter Path Traversal VulnerabilityVendor: BroadcomProduct: VMware vCenterBroadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 11, 2026 at 16:08:17 UTCDate Added to KEV: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-61511
(9.8 CRITICAL)

EPSS: 70.77%

updated 2026-08-07T06:16:56.993000

3 posts

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style

Nuclei template

5 repos

https://github.com/shootcannon/CVE-2026-61511

https://github.com/tc4dy/CVE-2026-61511-PoC-Exploit

https://github.com/puj790201-lab/cve-2026-61511

https://github.com/HORKimhab/CVE-2026-61511

https://github.com/codeb0ssx/Ultimate-CVE-2026-61511

undercodenews@mastodon.social at 2026-09-14T10:29:52.000Z ##

Critical vBulletin Pre-Authentication RCE Flaw Puts Internet-Facing Forums at Serious Risk of Full Server Takeover

Introduction A newly disclosed critical vulnerability in vBulletin has turned ordinary forum traffic into a potentially dangerous attack path. Tracked as CVE-2026-61511, the flaw can allow an unauthenticated remote attacker to execute arbitrary PHP code on affected servers, meaning an attacker may not need an administrator account, stolen credentials, or…

undercodenews.com/critical-vbu

##

_r_netsec at 2026-09-13T17:43:13.028Z ##

[CVE-2026-61511] vBulletin <= 6.2.1 (runMaths) Pre-Auth RCE Vulnerability karmainsecurity.com/KIS-2026-13

##

_r_netsec@infosec.exchange at 2026-09-13T17:43:13.000Z ##

[CVE-2026-61511] vBulletin <= 6.2.1 (runMaths) Pre-Auth RCE Vulnerability karmainsecurity.com/KIS-2026-13

##

CVE-2026-46331
(7.8 HIGH)

EPSS: 0.58%

updated 2026-07-23T12:33:27

2 posts

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd. Fix by moving skb

14 repos

https://github.com/HORKimhab/CVE-2026-46331

https://github.com/vulnquest58/dirtyclone-exploit

https://github.com/nawalacheker1/CVE-2026-46331

https://github.com/yanxinwu946/CVE-2026-46331

https://github.com/MarwahHadi/CVE-2026-46331-pedit-cow

https://github.com/douglasmun/pagecache-lpe-containment-kit

https://github.com/rjt-gupta/page-cache-corruption-lpes

https://github.com/cherrycherrymay/PoC-CVE-2026-46331

https://github.com/sgkdev/packet_edit_meme

https://github.com/Quaerendir/cve-2026-46331-audit

https://github.com/seguridadentrerios/CVE-2026-46331

https://github.com/V0IDNETWORK/CVE-2026-46331

https://github.com/g0thamRabb1t/CVE-2026-46331-pedit-COW-detection

https://github.com/0xBlackash/CVE-2026-46331

CVE-2026-4986
(5.3 MEDIUM)

EPSS: 0.20%

updated 2026-07-23T08:10:00.137000

2 posts

The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.

2 repos

https://github.com/Ap0dexMe0/CVE-2026-49869

https://github.com/cyeezy08/Kimai-CVE-2026-49865-POC

CVE-2026-49176
(7.8 HIGH)

EPSS: 0.47%

updated 2026-07-22T16:17:28.753000

2 posts

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

2 repos

https://github.com/DavidCarliez/CVE-2026-49176_LPE_POC

https://github.com/777erp/CVE-2026-49176_BOF

CVE-2026-15409
(10.0 CRITICAL)

EPSS: 84.54%

updated 2026-07-14T21:32:22

1 posts

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

6 repos

https://github.com/Ch4120N/CVE-2026-15409

https://github.com/remmons-r7/rapid7-CVE-2026-15409

https://github.com/HORKimhab/CVE-2026-15409

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

https://github.com/0xBlackash/CVE-2026-15409

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

cyberworldops@infosec.exchange at 2026-09-11T20:30:00.000Z ##

Borough Council of King's Lynn and West Norfolk incident linked with moderate confidence to mass exploitation of CVE-2026-15409 in SonicWall SMA1000. Unauthenticated SSRF in WorkPlace WebSocket proxy chains to RCE and LDAP credential theft, enabling pivot into internal networks. Exposed systems require immediate patching and compromise hunting. #SonicWall #Sma1000 #InfoSec

cyberworldops.eu/en/uk-council

##

CVE-2026-50458
(7.8 HIGH)

EPSS: 0.26%

updated 2026-07-14T18:32:25

2 posts

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-50013
(7.5 HIGH)

EPSS: 0.27%

updated 2026-07-14T18:03:10

1 posts

### Summary: When Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy requests are processed concurrently (the normal case for any proxy), the concurrent map writes trigger Go's built-in race detector which causes a `fatal error: concurrent map read and map write`, immediately killing the e

thehackerwire@mastodon.social at 2026-09-11T23:00:09.000Z ##

🟠 CVE-2026-50013 - High (7.5)

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy requests ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57239
(8.2 HIGH)

EPSS: 0.17%

updated 2026-07-09T15:33:27

2 posts

The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM.

1 repos

https://github.com/Paradoxis/CVE-2026-57239

CVE-2026-4201
(7.3 HIGH)

EPSS: 0.28%

updated 2026-06-17T10:56:10.603000

1 posts

A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This vulnerability affects the function Upload of the file business/business-system/src/main/java/com/glowxq/system/admin/controller/SysFileController.java. Executing a manipulation can lead to unrestricted upload. The attack can be launched remotely. The exploit has been made available to the public

sayzard@mastodon.sayzard.org at 2026-09-14T02:41:08.000Z ##

Artifactory: In-the-Wild Exploitation of CVE-2026-42016,CVE-2026-42018

Wiz Research는 JFrog Artifactory의 CVE-2026-42016, CVE-2026-42018, CVE-2026-82329가 실제 환경에서 활발히 악용되고 있음을 확인했다. 공격자는 익명 사용자 토큰 노출과 토큰 스코프 검증 결함을 연쇄해 인증 없이 관리자 권한 토큰을 획득하거나, CVE-2026-82329의 인증 우회로 직접 관리자 권한을 얻을 수 있다. 침해 후에는 지속성 관리자 계정 생성, Groovy 플러그인을 통한 서버 명령 실행, 클러스...

wiz.io/blog/artifactory-under-

##

CVE-2024-3094
(10.0 CRITICAL)

EPSS: 85.97%

updated 2026-06-17T07:43:17.830000

1 posts

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked

Nuclei template

89 repos

https://github.com/Ikram124/CVE-2024-3094-analysis

https://github.com/devjanger/CVE-2024-3094-XZ-Backdoor-Detector

https://github.com/valeriot30/cve-2024-3094

https://github.com/hariskhalil555000-sketch/What-utility-does-CVE-2024-3094-refer-to-

https://github.com/vesjolyjd/Kaspersky_CVE-2024-3094

https://github.com/Ava-Vispilio/CVE-2024-3094

https://github.com/hazemkya/CVE-2024-3094-checker

https://github.com/0xBlackash/CVE-2024-3094

https://github.com/encikayelwhitehat-glitch/CVE-2024-3094

https://github.com/robertdebock/ansible-playbook-cve-2024-3094

https://github.com/weltregie/liblzma-scan

https://github.com/hackura/xz-cve-2024-3094

https://github.com/Fractal-Tess/CVE-2024-3094

https://github.com/M1lo25/CS50FinalProject

https://github.com/dah4k/CVE-2024-3094

https://github.com/ElinaNotElina/cve-2024-3094-analysis

https://github.com/MrBUGLF/XZ-Utils_CVE-2024-3094

https://github.com/robertdfrench/ifuncd-up

https://github.com/bsekercioglu/cve2024-3094-Checker

https://github.com/Preacher98/Report-XZ-Utils-CVE-2024-3094

https://github.com/pentestfunctions/CVE-2024-3094

https://github.com/MagpieRYL/CVE-2024-3094-backdoor-env-container

https://github.com/Juul/xz-backdoor-scan

https://github.com/lypd0/CVE-2024-3094-Vulnerabity-Checker

https://github.com/nnatsopoulos/xz-backdoor-research

https://github.com/ashwani95/CVE-2024-3094

https://github.com/shefirot/CVE-2024-3094

https://github.com/gensecaihq/CVE-2024-3094-Vulnerability-Checker-Fixer

https://github.com/jfrog/cve-2024-3094-tools

https://github.com/mightysai1997/CVE-2024-3094-info

https://github.com/ykhurshudyan-blip/CVE-2024-3094

https://github.com/mhicairo-hue/cs50-cybersecurity-final-project

https://github.com/badsectorlabs/ludus_xz_backdoor

https://github.com/AndreaCicca/Sicurezza-Informatica-Presentazione

https://github.com/x-cmd-build/xz

https://github.com/Mustafa1986/CVE-2024-3094

https://github.com/KaminaDuck/ansible-CVE-2024-3094

https://github.com/robertdebock/ansible-role-cve_2024_3094

https://github.com/ackemed/detectar_cve-2024-3094

https://github.com/TheTorjanCaptain/CVE-2024-3094-Checker

https://github.com/teyhouse/CVE-2024-3094

https://github.com/spidygal/CVE-2024-3094-Nmap-NSE-script

https://github.com/namegabevictoire01-sys/cs50-cybersecurity-final-project

https://github.com/FabioBaroni/CVE-2024-3094-checker

https://github.com/michalAshurov/writeup-CVE-2024-3094

https://github.com/mesutgungor/xz-backdoor-vulnerability

https://github.com/stevehenderson/lab_xz_backdoor

https://github.com/iheb2b/CVE-2024-3094-Checker

https://github.com/neuralinhibitor/xzwhy

https://github.com/been22426/CVE-2024-3094

https://github.com/byinarie/CVE-2024-3094-info

https://github.com/24Owais/threat-intel-cve-2024-3094

https://github.com/felipecosta09/cve-2024-3094

https://github.com/brinhosa/CVE-2024-3094-One-Liner

https://github.com/HackerHermanos/CVE-2024-3094_xz_check

https://github.com/przemoc/xz-backdoor-links

https://github.com/lockness-Ko/xz-vulnerable-honeypot

https://github.com/emirkmo/xz-backdoor-github

https://github.com/amlweems/xzbot

https://github.com/hackingetico21/revisaxzutils

https://github.com/Simplifi-ED/CVE-2024-3094-patcher

https://github.com/Bella-Bc/xz-backdoor-CVE-2024-3094-Check

https://github.com/Titus-soc/-CVE-2024-3094-Vulnerability-Checker-Fixer-Public

https://github.com/zpxlz/CVE-2024-3094

https://github.com/h3raklez/CVE-2024-3094

https://github.com/vnchk1/sec_review_cve-2024-3094

https://github.com/Security-Phoenix-demo/CVE-2024-3094-fix-exploits

https://github.com/fevar54/Detectar-Backdoor-en-liblzma-de-XZ-utils-CVE-2024-3094-

https://github.com/r0binak/xzk8s

https://github.com/wgetnz/CVE-2024-3094-check

https://github.com/isuruwa/CVE-2024-3094

https://github.com/extracoding-dozen/CVE-2024-3094

https://github.com/harekrishnarai/xz-utils-vuln-checker

https://github.com/mightysai1997/CVE-2024-3094

https://github.com/BOSE122/CVE-2024-3094

https://github.com/galacticquest/cve-2024-3094-detect

https://github.com/OpensourceICTSolutions/xz_utils-CVE-2024-3094

https://github.com/ScrimForever/CVE-2024-3094

https://github.com/mrk336/CVE-2024-3094

https://github.com/gustavorobertux/CVE-2024-3094

https://github.com/buluma/ansible-role-cve_2024_3094

https://github.com/laxmikumari615/Linux---Security---Detect-and-Mitigate-CVE-2024-3094

https://github.com/Yuma-Tsushima07/CVE-2024-3094

https://github.com/ThomRgn/xzutils_backdoor_obfuscation

https://github.com/Horizon-Software-Development/CVE-2024-3094

https://github.com/jbnetwork-git/CVE-2024-3094-XZ-Utils-Check

https://github.com/Dermot-lab/TryHack

https://github.com/bioless/xz_cve-2024-3094_detection

https://github.com/0xlane/xz-cve-2024-3094

hugovalters@mastodon.social at 2026-09-14T08:00:01.000Z ##

Get CVE and exploit intel into your pipeline with one call. Metered, no seat licenses.
curl valtersit.com/api/cve/CVE-2024
Pricing at valtersit.com/cve/pricing/

##

CVE-2024-1813
(9.8 CRITICAL)

EPSS: 1.22%

updated 2026-06-17T07:05:03.993000

2 posts

The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted input in the job_board_applicant_list_columns_value function. This makes it possible for unauthenticated attackers to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could al

1 repos

https://github.com/MobetaSec/CVE-2024-1813-POC

_r_netsec at 2026-09-13T17:43:15.196Z ##

Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) mobeta.fr/simple-job-board-una

##

_r_netsec@infosec.exchange at 2026-09-13T17:43:15.000Z ##

Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) mobeta.fr/simple-job-board-una

##

CVE-2026-2275
(9.6 CRITICAL)

EPSS: 0.44%

updated 2026-03-31T18:32:38

2 posts

The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through arbitrary C function calling.

thehackerwire@mastodon.social at 2026-09-14T04:00:15.000Z ##

🟠 CVE-2026-37008 - High (8.1)

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete obj...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-14T04:00:15.000Z ##

🟠 CVE-2026-37008 - High (8.1)

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete obj...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-51990
(0 None)

EPSS: 0.00%

10 posts

N/A

1 repos

https://github.com/HORKimhab/CVE-2026-51990

cyberworldops at 2026-09-14T12:40:00.947Z ##

UNC3569 is exploiting CVE-2026-51990 in Tencent Sogou Input Method for Windows. A crafted sgbiz:// URL enables one-click SYSTEM-level code execution and GrayRabbit backdoor deployment. Widespread IME deployment makes this a high-priority patch and detection target.

cyberworldops.eu/en/tencent-so

##

ransomnews@poliversity.it at 2026-09-14T07:37:00.000Z ##

⚠️🐰 Tencent flaw deploys GrayRabbit

CVE-2026-51990 enables RCE through Sogou Input Method; fixed in version 16.3.

🔗 read more: bleepingcomputer.com/news/secu

#ransomNews #cyberthreats #GrayRabbit

##

DailyCyberSecurity at 2026-09-14T00:02:51.991Z ##

Defend against the CVE-2026-51990 Sogou exploit. Discover how hackers use this one-click flaw to drop backdoors and how to secure your systems today.

securityonline.info/cve-2026-5

##

security_crawler_carl at 2026-09-13T18:52:46.501Z ##

🏆 New Achievement! One Click to the Food Chain Bottom!

Here, in the wild habitat of Windows enterprise environments, we observe the Sogou Input Method — a text entry tool installed by millions — standing perfectly still as UNC3569, a China-aligned espionage group, approaches from the brush. CVE-2026-51990 is a critical one-click remote code execution flaw exploiting an unsandboxed Chromium chain. The creature does not run. It simply... accepts the GrayRabbit backdoor. (1/2)

##

oversecurity@mastodon.social at 2026-09-13T15:20:36.000Z ##

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method...

🔗️ [Bleepingcomputer] link.is.it/DXBwPD

##

Analyst207@mastodon.social at 2026-09-13T14:33:00.000Z ##

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Hackers are actively exploiting a critical flaw in Tencent's Sogou Input Method for Windows, using a clever one-click trick to deploy the GrayRabbit backdoor; researchers warn that this vulnerability, tracked as CVE-2026-51990, is being used to deliver malware to unsuspecting victims.

osintsights.com/hackers-exploi

#GrayrabbitMalware #Tencent #Cve202651990 #RemoteCodeExecution #Windows

##

cyberworldops@infosec.exchange at 2026-09-14T12:40:00.000Z ##

UNC3569 is exploiting CVE-2026-51990 in Tencent Sogou Input Method for Windows. A crafted sgbiz:// URL enables one-click SYSTEM-level code execution and GrayRabbit backdoor deployment. Widespread IME deployment makes this a high-priority patch and detection target. #SogouFlaw #GrayRabbit #ThreatIntel

cyberworldops.eu/en/tencent-so

##

DailyCyberSecurity@infosec.exchange at 2026-09-14T00:02:51.000Z ##

Defend against the CVE-2026-51990 Sogou exploit. Discover how hackers use this one-click flaw to drop backdoors and how to secure your systems today.

#CVE202651990 #SogouInputMethod #CyberSecurity #UNC3569 #InfoSec #EndpointSecurity #ThreatIntel

securityonline.info/cve-2026-5

##

security_crawler_carl@infosec.exchange at 2026-09-13T18:52:46.000Z ##

🏆 New Achievement! One Click to the Food Chain Bottom!

Here, in the wild habitat of Windows enterprise environments, we observe the Sogou Input Method — a text entry tool installed by millions — standing perfectly still as UNC3569, a China-aligned espionage group, approaches from the brush. CVE-2026-51990 is a critical one-click remote code execution flaw exploiting an unsandboxed Chromium chain. The creature does not run. It simply... accepts the GrayRabbit backdoor. (1/2)

##

oversecurity@mastodon.social at 2026-09-13T15:20:36.000Z ##

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method...

🔗️ [Bleepingcomputer] link.is.it/DXBwPD

##

CVE-2026-61797
(0 None)

EPSS: 0.00%

1 posts

N/A

labs.itresit.es@labs.itresit.es at 2026-09-14T08:15:00.000Z ##

Source-Driven Recon: When the Patch Becomes the PoC and what CVE-2026-61797 taught us about Disclosure OPSEC

The post discusses the discovery and reporting of a time-based blind SQL injection vulnerability (CVE-2026-61797) in the GLPI PDF plugin, followed by a chaotic 47-day disclosure process. Subsequent investigations revealed additional undisclosed vulnerabilities and a shift in vulnerability research dynamics, highlighting the impact of advanced tools like LLMs on software security management.

labs.itresit.es/2026/09/14/sou

##

CVE-2026-63030
(0 None)

EPSS: 97.27%

3 posts

N/A

Nuclei template

85 repos

https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030

https://github.com/yuag/wp2shell

https://github.com/securelayer7/WordPresShell

https://github.com/CybersecSpirit/CVE-2026-63030

https://github.com/mrx-arafat/CVE-2026-63030-POC

https://github.com/0xh7ml/CVE-2026-63030

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/47Cid/wp2shell-lab

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/imXur/WordPress-CVE-2026-63030-Analysis

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/michael-kanda/Wp2shell-ioc-scanner

https://github.com/Ch4120N/CVE-2026-63030

https://github.com/h4cd0c/wp2shell

https://github.com/johnlodan/wp2shell-rce

https://github.com/Procjevt/CVE-2026-63030

https://github.com/TomorrowX6/CVE-2026-63030-poc

https://github.com/M4xSec/wp2shell-Exploit-Waf-Bypass

https://github.com/shinthink/CVE-2026-63030

https://github.com/kulichr/wp2shell

https://github.com/ekomsSavior/wp2shell

https://github.com/ikow/wp2shell

https://github.com/bahartanir/wp2shell-scanner

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/dinosn/wp2shell-lab

https://github.com/DeadExpl0it/wp2shell-poc

https://github.com/Iqbalx7/wp2shell

https://github.com/mverschu/CVE-2026-63030

https://github.com/Crypto-Cat/wp2shell

https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2026-63030-WP2Shell

https://github.com/sowarma/wp2shell-PoC

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/mcipekci/wp2shell

https://github.com/c0gnit00/Wp2Shell

https://github.com/Lutfifakee-Project/wp2shell

https://github.com/zeroc00I/CVE-2026-63030

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/ChiefYoru/CVE-2026-63030_PoC

https://github.com/Madelleimproved411/wp-to-code

https://github.com/gbrsh/CVE-2026-63030

https://github.com/x-znn/CVE-2026-63030

https://github.com/0xjessie21/wp2shell-checker

https://github.com/0xBlackash/CVE-2026-63030

https://github.com/4minx/CVE-2026-63030

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/ebrasha/abdal-cve-2026-63030

https://github.com/mhtsec/CVE-2026-63030

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/AnggaTechI/CVE-2026-63030

https://github.com/4B3R4M4-607D/CVE-2026-63030-POC

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/ZenithGenius/wordpress-batch-rce-lab

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/raphy76/wp2shell-poc-fulljs

https://github.com/zi3lak/wp2shell_scanner

https://github.com/NULL200OK/WP2Shell

https://github.com/mhassani97/cve-2026-63030-lab

https://github.com/administrator-01001/CVE-2026-63030

https://github.com/Sec-Dan/WP2Shell-Scanner

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/attackercan/wp2shell-poc2

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/vulnquest58/PressVector

https://github.com/g0d150ne/WP2Shell

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030

https://github.com/fullhunt/wp2shell-scan

https://github.com/ananay/wp2shell-lab

https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t

https://github.com/TranDongA3/POC-CVE-2026-63030-CVE-2026-60137-

https://github.com/0xWhoknows/wp2shell

https://github.com/Icex0/wp2shell-poc

https://github.com/InstaWP/wp2shell-scan

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/ivanesk315/CVE-2026-60137-and-CVE-2026-63030

https://github.com/0xsha/wp2shell

psa@masto.ai at 2026-09-14T05:50:07.000Z ##

Browsing through my webserver logs to see what the internet brings me today and I come across:
user_agent: cve-2026-63030/1.0

Nice when the attack bot tells you exactly what it's after.

This came from 85.239.151.0/24 registered under "Aeza International LTD". Turns out this company is under international sanctions. Looking up AS19318, this netblock seems to be managed by Interserver, Inc, US.

##

_r_netsec at 2026-09-13T17:43:06.691Z ##

wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner fullhunt.io/blog/2026/07/17/wp

##

_r_netsec@infosec.exchange at 2026-09-13T17:43:06.000Z ##

wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner fullhunt.io/blog/2026/07/17/wp

##

CVE-2026-53761
(0 None)

EPSS: 0.34%

1 posts

N/A

hugovalters@mastodon.social at 2026-09-13T13:00:03.000Z ##

CVE-2026-53761: Authentication bypass in Frappe CRM via logged invitation keys, affecting versions before 1.73.0. CVSS N/A, but unpatched installs are at risk of unauthorized access. Patch immediately! Details: valtersit.com/cve/CVE-2026-537 #CVE #cybersecurity #Fr

##

CVE-2026-49846
(0 None)

EPSS: 0.34%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-11T22:59:58.000Z ##

🟠 CVE-2026-49846 - High (7.5)

libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonica...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites