##
Updated at UTC 2026-08-29T03:27:42.803307
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-73108 | 7.5 | 0.53% | 1 | 0 | 2026-08-28T23:17:11.710000 | RustDesk versions before 1.4.7 contain an uncontrolled speculative memory alloca | |
| CVE-2026-55848 | 8.6 | 0.00% | 2 | 0 | 2026-08-28T23:17:08.013000 | mapfish-print is a component of MapFish for printing templated cartographic maps | |
| CVE-2026-55841 | 7.5 | 0.00% | 2 | 0 | 2026-08-28T23:17:07.840000 | Graylog is a free and open log management platform. Prior to Graylog Server vers | |
| CVE-2026-55784 | 7.5 | 0.00% | 2 | 0 | 2026-08-28T23:17:07.517000 | free5GC is an open-source implementation of the 5G core network. In version 1.4. | |
| CVE-2026-82333 | 7.5 | 0.00% | 2 | 0 | 2026-08-28T22:16:57.037000 | multer is a middleware for handling multipart/form-data in Node.js. A small mult | |
| CVE-2026-82017 | 7.6 | 0.00% | 2 | 0 | 2026-08-28T22:16:55.067000 | IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry | |
| CVE-2026-81490 | 7.7 | 0.00% | 2 | 0 | 2026-08-28T22:16:54.247000 | A database user able to create a view in a namespace that MongoDB Connector for | |
| CVE-2026-55634 | 9.9 | 0.00% | 1 | 0 | 2026-08-28T22:16:51.290000 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.1 | |
| CVE-2026-18885 | None | 0.38% | 5 | 0 | 2026-08-28T21:32:13 | ServiceNow has remediated a code injection vulnerability that was identified in | |
| CVE-2026-82291 | 8.1 | 0.00% | 2 | 0 | 2026-08-28T21:31:36 | HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses w | |
| CVE-2026-82329 | 9.8 | 0.00% | 2 | 0 | 2026-08-28T21:31:36 | JFrog Artifactory contains an authentication weakness that, under default config | |
| CVE-2026-82279 | 8.1 | 0.00% | 2 | 0 | 2026-08-28T21:31:29 | HyperDX through 1.10.1 fails to enforce role-based access controls in team manag | |
| CVE-2026-82288 | 7.5 | 0.00% | 2 | 0 | 2026-08-28T21:31:28 | Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerabi | |
| CVE-2026-82287 | 8.1 | 0.00% | 2 | 0 | 2026-08-28T21:31:28 | Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows a | |
| CVE-2026-74820 | None | 0.24% | 2 | 0 | 2026-08-28T21:31:08 | ServiceNow has remediated a SQL injection vulnerability that was identified in i | |
| CVE-2026-74770 | 8.8 | 1.06% | 1 | 0 | 2026-08-28T20:26:02.403000 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutrali | |
| CVE-2026-82286 | 8.6 | 0.00% | 2 | 1 | 2026-08-28T20:20:20.093000 | gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the | |
| CVE-2026-82227 | 8.5 | 0.00% | 2 | 0 | 2026-08-28T20:20:15.380000 | Contributor SQL Injection in WPBulky <= 1.2.2 versions. | |
| CVE-2026-81694 | 3.3 | 0.18% | 2 | 0 | 2026-08-28T20:20:11.807000 | openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames rea | |
| CVE-2026-81572 | 7.8 | 0.17% | 3 | 0 | 2026-08-28T20:20:11.240000 | In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excludi | |
| CVE-2026-78286 | 9.8 | 0.53% | 3 | 0 | 2026-08-28T20:19:57.720000 | Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions. | |
| CVE-2026-76640 | 7.5 | 0.35% | 4 | 1 | 2026-08-28T20:19:54.877000 | Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities | |
| CVE-2026-59270 | 9.4 | 0.29% | 3 | 0 | 2026-08-28T20:18:54.127000 | Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditio | |
| CVE-2026-53362 | 7.8 | 0.51% | 11 | 1 | 2026-08-28T20:18:10.133000 | In the Linux kernel, the following vulnerability has been resolved: ipv6: accou | |
| CVE-2026-19313 | 0 | 0.47% | 2 | 0 | 2026-08-28T20:17:23.940000 | An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows | |
| CVE-2026-18886 | 0 | 0.26% | 2 | 0 | 2026-08-28T20:17:23.417000 | ServiceNow has remediated an improper access control vulnerability that was iden | |
| CVE-2026-76784 | 0 | 0.15% | 1 | 0 | 2026-08-28T19:02:53.760000 | Multiple TP-Link Kasa smart home devices contain insufficient cryptographic prot | |
| CVE-2026-81728 | 8.1 | 0.26% | 2 | 0 | 2026-08-28T18:56:49.340000 | Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizar | |
| CVE-2026-81701 | 9.8 | 0.31% | 4 | 0 | 2026-08-28T18:56:34.447000 | openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-i | |
| CVE-2026-81680 | 4.0 | 0.15% | 2 | 0 | 2026-08-28T18:56:34.447000 | openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presenc | |
| CVE-2026-82254 | 7.5 | 0.00% | 2 | 0 | 2026-08-28T18:54:09.323000 | gitoxide before 0.69.0 contains unchecked array indexing in delta application an | |
| CVE-2026-77532 | 9.6 | 0.27% | 1 | 0 | 2026-08-28T18:49:15.340000 | A malicious actor with access to an adjacent network could exploit a Buffer Over | |
| CVE-2026-47877 | 8.2 | 0.19% | 1 | 0 | 2026-08-28T18:47:30.163000 | Spring Security Authorization Server's default consent page renders user-control | |
| CVE-2026-47852 | 7.5 | 0.20% | 1 | 0 | 2026-08-28T18:47:30.163000 | A local attacker on a multi-user host can pre-create the deterministic cache pat | |
| CVE-2026-81767 | 7.5 | 0.00% | 2 | 0 | 2026-08-28T18:31:39 | Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions. | |
| CVE-2026-81285 | 7.5 | 0.00% | 2 | 0 | 2026-08-28T18:31:34 | Unauthenticated Denial of Service Attack in Smush Image Compression and Optimiza | |
| CVE-2026-81019 | 7.4 | 0.00% | 1 | 0 | 2026-08-28T18:31:30 | wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when | |
| CVE-2026-82222 | 10.0 | 0.00% | 2 | 0 | 2026-08-28T16:18:32.060000 | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP | |
| CVE-2026-78239 | 9.8 | 0.55% | 4 | 0 | 2026-08-28T16:18:27.560000 | Xiiaozet LK100W exposes a critical management function that can be invoked with | |
| CVE-2026-76943 | 9.8 | 0.67% | 2 | 0 | 2026-08-28T16:18:26.203000 | Xiiaozet LK100Wt contains an authentication weakness within an administrative s | |
| CVE-2026-75813 | 7.5 | 0.26% | 2 | 0 | 2026-08-28T16:18:25.510000 | Certain configuration endpoints may lack proper server-side authorization check | |
| CVE-2026-73809 | 7.5 | 0.17% | 1 | 0 | 2026-08-28T16:18:24.433000 | A cleartext transmission of sensitive information vulnerability exists in certa | |
| CVE-2026-73125 | 9.8 | 0.53% | 4 | 0 | 2026-08-28T16:18:24.173000 | Ebyte device web management interface does not consistently enforce authenticat | |
| CVE-2026-78293 | 7.1 | 0.24% | 1 | 0 | 2026-08-28T15:09:00.790000 | Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions. | |
| CVE-2026-78288 | 9.3 | 0.38% | 1 | 0 | 2026-08-28T15:09:00.790000 | Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions. | |
| CVE-2026-81273 | 8.1 | 0.17% | 2 | 0 | 2026-08-28T15:09:00.790000 | Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 | |
| CVE-2026-82252 | 7.5 | 0.00% | 2 | 0 | 2026-08-28T12:30:36 | gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules fi | |
| CVE-2026-82253 | 7.5 | 0.00% | 3 | 0 | 2026-08-28T12:30:36 | gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path | |
| CVE-2026-82234 | 8.2 | 0.00% | 1 | 0 | 2026-08-28T12:30:36 | SiYuan versions before v3.8.1 contain a server-side request forgery vulnerabilit | |
| CVE-2026-82251 | 7.5 | 0.00% | 2 | 0 | 2026-08-28T12:30:36 | gitoxide before 0.52.1 fails to validate submodule names from .gitmodules config | |
| CVE-2026-82260 | 7.5 | 0.00% | 3 | 0 | 2026-08-28T12:30:36 | SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remot | |
| CVE-2026-82261 | 7.5 | 0.00% | 2 | 0 | 2026-08-28T12:30:36 | SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remot | |
| CVE-2026-82259 | 7.5 | 0.00% | 2 | 0 | 2026-08-28T12:30:30 | SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deseri | |
| CVE-2026-82247 | 7.5 | 0.00% | 2 | 0 | 2026-08-28T12:30:28 | gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL par | |
| CVE-2023-49105 | 9.8 | 41.19% | 11 | 1 | template | 2026-08-28T12:21:09.753000 | An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker ca |
| CVE-2026-82123 | 6.5 | 0.18% | 2 | 0 | 2026-08-28T09:32:01 | Improper neutralization of input during web page generation ('cross-site scripti | |
| CVE-2026-76581 | 9.8 | 0.34% | 1 | 0 | 2026-08-28T09:31:57 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypa | |
| CVE-2026-82082 | 9.8 | 1.50% | 2 | 0 | 2026-08-28T06:31:13 | NUMail developed by Green-Computing has an OS Command Injection vulnerability. U | |
| CVE-2026-77365 | 7.2 | 0.31% | 1 | 0 | 2026-08-28T06:31:05 | The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image O | |
| CVE-2026-18983 | 7.5 | 0.50% | 2 | 0 | 2026-08-28T06:31:05 | The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to | |
| CVE-2026-38822 | 7.6 | 0.85% | 2 | 0 | 2026-08-28T03:31:24 | In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS da | |
| CVE-2026-38820 | 8.3 | 1.74% | 2 | 0 | 2026-08-28T03:31:23 | openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via | |
| CVE-2026-77977 | 8.1 | 0.23% | 2 | 0 | 2026-08-28T00:32:11 | Ebyte gateway product's vendor configuration utility does not require authentica | |
| CVE-2026-76945 | 7.5 | 0.36% | 2 | 0 | 2026-08-28T00:32:11 | The affected Ebyte device relies on client-managed authentication tokens withou | |
| CVE-2026-78037 | 8.8 | 1.22% | 2 | 0 | 2026-08-28T00:32:11 | Xiiaozet LK100W is vulnerable to OS command injection through its web-based man | |
| CVE-2026-76940 | 7.5 | 0.36% | 2 | 0 | 2026-08-28T00:32:04 | The affected Ebyte device does not restrict repeated authentication attempts th | |
| CVE-2026-71362 | 9.1 | 25.14% | 2 | 1 | template | 2026-08-28T00:18:09.390000 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul |
| CVE-2026-79619 | None | 0.14% | 2 | 0 | 2026-08-27T21:32:29 | On Linux, several OpenZFS ioctl authorization checks accept a capability held on | |
| CVE-2026-81934 | 9.8 | 0.58% | 2 | 0 | 2026-08-27T21:32:02 | Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' f | |
| CVE-2026-76639 | 8.8 | 0.71% | 7 | 1 | 2026-08-27T21:31:57 | Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code ex | |
| CVE-2026-81730 | 8.2 | 0.38% | 2 | 0 | 2026-08-27T21:31:54 | Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name sup | |
| CVE-2026-66384 | 5.3 | 0.54% | 8 | 1 | 2026-08-27T21:31:19 | An authenticated user may write data outside the intended Docker cache path unde | |
| CVE-2026-81094 | 9.1 | 0.42% | 2 | 0 | 2026-08-27T20:18:49.427000 | The mcp-router CLI served its MCP aggregator on every interface and enforced aut | |
| CVE-2026-81702 | 9.8 | 0.14% | 4 | 0 | 2026-08-27T18:32:38 | openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when l | |
| CVE-2026-81700 | 9.8 | 0.25% | 4 | 0 | 2026-08-27T18:32:38 | openssl_encrypt versions before 1.4.9 contain a signature verification vulnerabi | |
| CVE-2026-81698 | 7.5 | 0.28% | 4 | 0 | 2026-08-27T18:32:38 | openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in | |
| CVE-2026-81714 | 7.0 | 0.14% | 2 | 0 | 2026-08-27T18:32:38 | openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fin | |
| CVE-2026-81699 | 7.5 | 0.35% | 2 | 0 | 2026-08-27T18:32:38 | openssl_encrypt versions before 1.4.9 fail to properly validate key derivation f | |
| CVE-2026-81705 | 7.5 | 0.33% | 2 | 0 | 2026-08-27T18:32:38 | openssl-encrypt before 1.4.9 fails to redact the file password in its --debug ar | |
| CVE-2026-81735 | 10.0 | 0.53% | 2 | 0 | 2026-08-27T18:32:38 | startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its l | |
| CVE-2026-81685 | 3.3 | 0.18% | 2 | 0 | 2026-08-27T18:32:37 | openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in | |
| CVE-2026-81706 | 6.8 | 0.13% | 2 | 0 | 2026-08-27T18:32:37 | openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own i | |
| CVE-2026-81696 | 3.3 | 0.18% | 2 | 0 | 2026-08-27T18:32:37 | openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characte | |
| CVE-2026-81722 | 7.5 | 0.34% | 2 | 0 | 2026-08-27T18:32:31 | nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficie | |
| CVE-2026-81721 | 7.5 | 0.39% | 2 | 0 | 2026-08-27T18:32:31 | openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted | |
| CVE-2026-81717 | 3.5 | 0.09% | 2 | 0 | 2026-08-27T18:32:30 | openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weakness | |
| CVE-2026-81719 | 7.8 | 0.32% | 4 | 0 | 2026-08-27T18:32:30 | openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insuffi | |
| CVE-2026-81718 | 7.5 | 0.13% | 2 | 0 | 2026-08-27T18:32:30 | openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 | |
| CVE-2026-81695 | 3.3 | 0.18% | 2 | 0 | 2026-08-27T18:32:29 | openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id | |
| CVE-2026-81681 | 4.6 | 0.13% | 4 | 0 | 2026-08-27T18:32:27 | openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a port | |
| CVE-2026-78251 | None | 0.39% | 2 | 0 | 2026-08-27T18:32:25 | DJI drones contain an FTP service that uses hardcoded credentials shared across | |
| CVE-2026-47879 | 7.7 | 0.24% | 1 | 0 | 2026-08-27T18:32:09 | Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Reso | |
| CVE-2026-47851 | 7.5 | 0.26% | 1 | 1 | 2026-08-27T18:32:07 | Analyzing a PDF with a deeply nested or cyclic table of contents can cause a Sta | |
| CVE-2026-81707 | 9.8 | 0.41% | 4 | 0 | 2026-08-27T17:21:01.440000 | openssl_encrypt before 1.4.9 fails to sanitize the email field of imported ident | |
| CVE-2026-81576 | 7.7 | 0.33% | 2 | 0 | 2026-08-27T17:20:55.230000 | If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issu | |
| CVE-2026-55228 | 8.1 | 0.23% | 1 | 0 | 2026-08-27T17:18:48.693000 | Weblate is a web-based continuous localization platform used to manage software | |
| CVE-2026-18431 | 9.8 | 0.64% | 5 | 1 | 2026-08-27T17:17:29.533000 | The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versi | |
| CVE-2026-74232 | 9.8 | 0.47% | 6 | 0 | 2026-08-27T15:31:39 | Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink | |
| CVE-2026-74233 | 9.8 | 2.63% | 6 | 0 | 2026-08-27T15:31:35 | Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, an | |
| CVE-2026-80587 | 9.8 | 0.39% | 3 | 0 | 2026-08-27T15:31:34 | In the Linux kernel, the following vulnerability has been resolved: mptcp: avoi | |
| CVE-2026-80551 | 9.3 | 0.14% | 2 | 0 | 2026-08-27T15:31:32 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_c | |
| CVE-2026-81625 | 8.8 | 0.53% | 2 | 0 | 2026-08-27T13:18:41.920000 | A remote attacker with user privileges may use a malicious or compromised NASL v | |
| CVE-2026-80557 | 9.8 | 0.52% | 2 | 0 | 2026-08-27T13:18:40.360000 | In the Linux kernel, the following vulnerability has been resolved: libceph: fi | |
| CVE-2026-41992 | 7.5 | 0.37% | 11 | 0 | 2026-08-27T13:17:57.967000 | GNU gzip contains a global buffer overflow vulnerability in the LZH decompressio | |
| CVE-2026-78276 | 7.2 | 0.50% | 2 | 0 | 2026-08-27T12:30:34 | Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions. | |
| CVE-2026-78285 | 8.5 | 0.34% | 2 | 0 | 2026-08-27T12:30:34 | Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions. | |
| CVE-2026-81573 | 8.6 | 0.46% | 2 | 0 | 2026-08-27T12:30:27 | If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configu | |
| CVE-2026-81277 | 8.5 | 0.34% | 2 | 0 | 2026-08-27T12:30:27 | Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 version | |
| CVE-2026-81581 | 8.8 | 0.20% | 2 | 0 | 2026-08-27T12:30:27 | Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 | |
| CVE-2026-81579 | 8.8 | 0.16% | 2 | 0 | 2026-08-27T12:30:27 | In WibuKey for Windows before version 6.71, an untrusted pointer dereference in | |
| CVE-2026-81574 | 8.2 | 0.41% | 2 | 0 | 2026-08-27T12:30:27 | In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitiz | |
| CVE-2026-81575 | 7.5 | 0.44% | 2 | 0 | 2026-08-27T12:30:26 | If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 acce | |
| CVE-2026-80586 | 9.8 | 0.40% | 2 | 0 | 2026-08-27T06:31:38 | In the Linux kernel, the following vulnerability has been resolved: mptcp: opti | |
| CVE-2026-80589 | 9.8 | 0.38% | 3 | 0 | 2026-08-27T06:31:38 | In the Linux kernel, the following vulnerability has been resolved: block: stop | |
| CVE-2026-74746 | 9.8 | 0.54% | 2 | 0 | 2026-08-27T06:31:37 | In the Linux kernel, the following vulnerability has been resolved: netfilter: | |
| CVE-2026-74737 | 9.8 | 0.56% | 2 | 0 | 2026-08-27T06:31:37 | In the Linux kernel, the following vulnerability has been resolved: net: ethern | |
| CVE-2026-74744 | 9.8 | 0.52% | 2 | 0 | 2026-08-27T06:31:37 | In the Linux kernel, the following vulnerability has been resolved: ipvlan: inh | |
| CVE-2026-74743 | 9.8 | 0.52% | 2 | 0 | 2026-08-27T06:31:37 | In the Linux kernel, the following vulnerability has been resolved: macvlan: in | |
| CVE-2026-80561 | 9.8 | 0.52% | 2 | 0 | 2026-08-27T06:31:33 | In the Linux kernel, the following vulnerability has been resolved: libceph: fi | |
| CVE-2026-80588 | 7.5 | 0.34% | 1 | 0 | 2026-08-27T06:31:33 | In the Linux kernel, the following vulnerability has been resolved: mptcp: recl | |
| CVE-2026-74751 | 9.4 | 0.34% | 2 | 0 | 2026-08-27T06:31:31 | In the Linux kernel, the following vulnerability has been resolved: riscv: lib: | |
| CVE-2026-80585 | 9.4 | 0.32% | 2 | 0 | 2026-08-27T06:17:45.397000 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fast | |
| CVE-2026-80558 | 9.8 | 0.52% | 2 | 0 | 2026-08-27T06:17:39.903000 | In the Linux kernel, the following vulnerability has been resolved: libceph: Av | |
| CVE-2026-80554 | 9.3 | 0.14% | 2 | 0 | 2026-08-27T06:17:38.923000 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio_c | |
| CVE-2026-80528 | 9.8 | 0.52% | 2 | 0 | 2026-08-27T06:17:32.740000 | In the Linux kernel, the following vulnerability has been resolved: ceph: avoid | |
| CVE-2026-80519 | 9.8 | 0.45% | 2 | 0 | 2026-08-27T06:17:30.167000 | In the Linux kernel, the following vulnerability has been resolved: ovpn: finis | |
| CVE-2026-74752 | 9.8 | 0.43% | 2 | 0 | 2026-08-27T06:17:26.440000 | In the Linux kernel, the following vulnerability has been resolved: sctp: valid | |
| CVE-2021-23758 | 8.1 | 83.63% | 4 | 1 | 2026-08-27T04:16:38.863000 | All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted | |
| CVE-2015-3246 | 5.1 | 8.80% | 3 | 1 | 2026-08-27T04:16:36.600000 | libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper progr | |
| CVE-2026-65641 | None | 0.54% | 2 | 0 | 2026-08-27T00:30:36 | A vulnerability allowing an unauthenticated network attacker to coerce SMB authe | |
| CVE-2026-77317 | 8.1 | 0.22% | 1 | 0 | 2026-08-26T22:16:29.717000 | SeaweedFS is a distributed storage system for files and blobs. In versions from | |
| CVE-2026-68863 | 7.5 | 0.28% | 1 | 0 | 2026-08-26T21:31:52 | Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer | |
| CVE-2026-68861 | 8.8 | 0.98% | 1 | 0 | 2026-08-26T21:31:52 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutrali | |
| CVE-2026-77652 | 7.8 | 0.15% | 1 | 0 | 2026-08-26T21:31:52 | A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG | |
| CVE-2026-79938 | 7.6 | 0.22% | 1 | 0 | 2026-08-26T21:31:52 | Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Au | |
| CVE-2026-70419 | 9.1 | 2.19% | 2 | 0 | 2026-08-26T21:31:47 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutr | |
| CVE-2026-81029 | 8.1 | 0.30% | 1 | 0 | 2026-08-26T18:32:05 | OpenMetadata accepts a caller-supplied post-authentication redirect target and a | |
| CVE-2026-80428 | 9.8 | 0.52% | 1 | 0 | 2026-08-26T18:32:05 | ILIAS deserialises stored session data for an unauthenticated caller. The Shibbo | |
| CVE-2026-81036 | 8.1 | 0.31% | 1 | 0 | 2026-08-26T18:32:05 | Stalwart Mail Server does not compare an OAuth redirect target against any regis | |
| CVE-2026-81035 | 8.1 | 0.28% | 1 | 0 | 2026-08-26T18:32:05 | Midday allows any member of a team to delete it. The delete procedure in apps/ap | |
| CVE-2026-75960 | 8.1 | 0.35% | 3 | 0 | 2026-08-26T18:32:04 | Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently | |
| CVE-2026-15990 | 7.5 | 0.69% | 1 | 0 | 2026-08-26T18:32:04 | The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal | |
| CVE-2026-19271 | 7.5 | 0.30% | 1 | 0 | 2026-08-26T18:32:04 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injecti | |
| CVE-2026-58474 | 8.8 | 0.46% | 1 | 0 | 2026-08-26T18:32:04 | whichllm before 0.5.16 contains a code injection vulnerability in the run and sn | |
| CVE-2026-75896 | 9.1 | 0.23% | 1 | 0 | 2026-08-26T18:32:04 | Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technolog | |
| CVE-2026-18252 | 7.3 | 0.34% | 1 | 0 | 2026-08-26T18:32:04 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 bef | |
| CVE-2026-77533 | 9.9 | 1.01% | 1 | 0 | 2026-08-26T18:32:03 | A malicious actor with access to the network and low privileges could exploit an | |
| CVE-2026-65182 | 9.1 | 0.59% | 2 | 0 | 2026-08-26T18:31:49 | Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat | |
| CVE-2026-79282 | 9.6 | 0.35% | 1 | 0 | 2026-08-26T18:31:48 | Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 al | |
| CVE-2026-74932 | 7.5 | 0.22% | 1 | 0 | 2026-08-26T18:31:36 | The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host he | |
| CVE-2019-1068 | 8.8 | 52.84% | 3 | 2 | 2026-08-26T18:31:30 | A remote code execution vulnerability exists in Microsoft SQL Server when it inc | |
| CVE-2015-5287 | 7.8 | 4.96% | 3 | 1 | 2026-08-26T18:31:30 | The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2. | |
| CVE-2026-8452 | 9.8 | 1.61% | 11 | 3 | 2026-08-26T18:30:34 | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unp | |
| CVE-2022-0995 | 7.1 | 9.52% | 7 | 4 | 2026-08-26T18:30:28 | An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_q | |
| CVE-2026-81032 | 9.8 | 0.29% | 1 | 0 | 2026-08-26T18:17:05.890000 | NebulaGraph exposes its runtime configuration over an unauthenticated HTTP servi | |
| CVE-2026-81027 | 8.5 | 0.29% | 1 | 0 | 2026-08-26T18:17:05.420000 | one-api gates one of its two channel-pinning paths and not the other. middleware | |
| CVE-2026-32258 | 8.1 | 0.21% | 1 | 0 | 2026-08-26T18:16:27.550000 | Winter is a free, open-source content management system (CMS) based on the Larav | |
| CVE-2026-54569 | 9.8 | 0.78% | 1 | 0 | 2026-08-26T15:28:48 | ### Summary An unauthenticated remote code execution vulnerability in the SENAI | |
| CVE-2026-54511 | 8.6 | 0.31% | 1 | 0 | 2026-08-26T14:28:05 | `@logtape/syslog` contains two related output-encoding bugs in the structured da | |
| CVE-2026-54523 | 9.6 | 0.40% | 1 | 0 | 2026-08-26T14:21:54 | ## Summary In Kyverno v1.18.1, a tenant who can create a `NamespacedMutatingPol | |
| CVE-2026-65081 | 8.1 | 0.25% | 1 | 0 | 2026-08-25T21:31:35 | NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, | |
| CVE-2026-80049 | 8.8 | 0.34% | 1 | 0 | 2026-08-25T21:31:34 | Airbyte Platform resolves the workspace used for its authorization decision from | |
| CVE-2026-45018 | 9.8 | 0.65% | 1 | 0 | 2026-08-25T20:16:55.720000 | Chainlit is a Python framework for building production-ready conversational AI a | |
| CVE-2026-55099 | 7.5 | 0.38% | 1 | 0 | 2026-08-25T19:27:32 | ### Summary `Component.__eq__` compares subcomponents in `O(2^n)` time relative | |
| CVE-2026-19913 | None | 0.36% | 1 | 1 | 2026-08-25T18:32:01 | The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure v | |
| CVE-2026-19912 | None | 0.22% | 1 | 1 | 2026-08-25T18:32:01 | The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote | |
| CVE-2026-69836 | 10.0 | 1.55% | 2 | 2 | 2026-08-25T16:08:43.290000 | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized a | |
| CVE-2026-21962 | 10.0 | 42.02% | 1 | 10 | 2026-08-25T04:18:11.067000 | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in pr | |
| CVE-2026-19874 | 9.1 | 0.73% | 1 | 1 | 2026-08-24T20:16:42.277000 | A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online | |
| CVE-2026-73570 | 8.9 | 20.53% | 2 | 6 | template | 2026-08-24T13:19:17.577000 | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor |
| CVE-2026-64531 | 7.8 | 0.38% | 1 | 4 | 2026-08-22T04:17:58.720000 | In the Linux kernel, the following vulnerability has been resolved: net: openvs | |
| CVE-2026-77806 | 9.8 | 4.20% | 1 | 1 | template | 2026-08-21T15:32:18 | SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary |
| CVE-2026-69414 | 7.8 | 0.56% | 1 | 2 | 2026-08-20T04:16:56.450000 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect | |
| CVE-2026-75112 | None | 0.11% | 2 | 0 | 2026-08-19T21:30:46 | A security issue exists within OTTO® Fleet Manager. The vulnerability stems from | |
| CVE-2026-53361 | 7.1 | 0.13% | 1 | 1 | 2026-08-19T18:31:59 | In the Linux kernel, the following vulnerability has been resolved: af_unix: Se | |
| CVE-2026-65400 | 9.8 | 9.90% | 3 | 3 | 2026-08-19T04:17:34.547000 | An authentication issue was addressed with improved state management. This issue | |
| CVE-2026-19478 | 9.4 | 6.00% | 2 | 7 | template | 2026-08-18T14:57:10.630000 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 |
| CVE-2026-72137 | 9.8 | 0.62% | 5 | 0 | 2026-08-17T06:18:13.583000 | In the Linux kernel, the following vulnerability has been resolved: xfrm: nat_k | |
| CVE-2026-19598 | 9.8 | 2.79% | 1 | 4 | template | 2026-08-15T18:31:24 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to |
| CVE-2026-46369 | 7.5 | 0.39% | 1 | 0 | 2026-08-12T15:16:54 | ### Impact The validity store treats a transaction with stored `block_number = X | |
| CVE-2026-32257 | 8.1 | 0.21% | 1 | 0 | 2026-08-12T14:40:23 | ### Impact | |
| CVE-2026-62911 | 8.0 | 0.95% | 2 | 1 | 2026-08-11T18:31:34 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an a | |
| CVE-2026-63077 | 9.8 | 87.71% | 3 | 4 | template | 2026-08-05T18:32:31 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe |
| CVE-2026-36425 | 6.5 | 0.42% | 1 | 2 | 2026-07-17T15:33:27 | An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in | |
| CVE-2018-18472 | 9.8 | 25.63% | 2 | 0 | 2026-06-17T01:47:21.423000 | Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a ro | |
| CVE-2026-28389 | 7.5 | 0.80% | 1 | 0 | 2026-05-12T15:31:15 | Issue summary: During processing of a crafted CMS EnvelopedData message with Key | |
| CVE-2025-39367 | 5.3 | 0.27% | 1 | 0 | 2025-04-28T09:32:00 | Missing Authorization vulnerability in SeventhQueen Kleo.This issue affects Kleo | |
| CVE-2023-21931 | 7.5 | 82.26% | 1 | 2 | 2024-09-17T03:30:44 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware | |
| CVE-2021-35941 | 7.5 | 12.71% | 2 | 0 | 2023-01-27T05:02:51 | Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all ver | |
| CVE-2026-65643 | 0 | 0.00% | 4 | 1 | N/A | ||
| CVE-2026-76060 | 0 | 2.31% | 1 | 1 | N/A | ||
| CVE-2026-60004 | 0 | 84.55% | 11 | 9 | template | N/A | |
| CVE-2026-81525 | 0 | 0.27% | 4 | 0 | N/A | ||
| CVE-2026-75604 | 0 | 0.00% | 6 | 3 | N/A | ||
| CVE-2026-61800 | 0 | 0.59% | 2 | 0 | N/A | ||
| CVE-2026-81529 | 0 | 0.17% | 1 | 0 | N/A | ||
| CVE-2026-77438 | 0 | 0.24% | 2 | 0 | N/A | ||
| CVE-2026-81522 | 0 | 0.27% | 2 | 0 | N/A | ||
| CVE-2026-66155 | 0 | 0.17% | 2 | 0 | N/A | ||
| CVE-2026-47665 | 0 | 0.25% | 2 | 0 | N/A | ||
| CVE-2026-68503 | 0 | 0.40% | 1 | 0 | N/A | ||
| CVE-2026-19042 | 0 | 2.00% | 1 | 0 | N/A | ||
| CVE-2026-47666 | 0 | 0.20% | 1 | 0 | N/A | ||
| CVE-2026-61617 | 0 | 0.25% | 1 | 0 | N/A | ||
| CVE-2026-77368 | 0 | 0.21% | 1 | 0 | N/A | ||
| CVE-2026-80427 | 0 | 0.15% | 1 | 0 | N/A | ||
| CVE-2026-61792 | 0 | 0.32% | 1 | 0 | N/A | ||
| CVE-2026-78379 | 0 | 0.32% | 1 | 0 | N/A |
updated 2026-08-28T23:17:11.710000
1 posts
🟠 CVE-2026-73108 - High (7.5)
RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before rece...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73108/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T23:17:08.013000
2 posts
🟠 CVE-2026-55848 - High (8.6)
mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print endpoint and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55848/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55848 - High (8.6)
mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print endpoint and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55848/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T23:17:07.840000
2 posts
🟠 CVE-2026-55841 - High (7.5)
Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLFo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55841/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55841 - High (7.5)
Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLFo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55841/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T23:17:07.517000
2 posts
🟠 CVE-2026-55784 - High (7.5)
free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-subscriber authentication state in a global sync.Map named AUSFContext.UePool in internal/context/context.go, keyed only b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55784/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-55784 - High (7.5)
free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-subscriber authentication state in a global sync.Map named AUSFContext.UePool in internal/context/context.go, keyed only b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55784/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:57.037000
2 posts
🟠 CVE-2026-82333 - High (7.5)
multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted text field names can make multer's field parser synchronously iterate a maximum-length sparse array, blocking the event loop s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82333/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82333 - High (7.5)
multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted text field names can make multer's field parser synchronously iterate a maximum-length sparse array, blocking the event loop s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82333/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:55.067000
2 posts
🟠 CVE-2026-82017 - High (7.6)
IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82017/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82017 - High (7.6)
IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82017/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:54.247000
2 posts
🟠 CVE-2026-81490 - High (7.7)
A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. The sampling logic classifies the resulting se...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81490/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81490 - High (7.7)
A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. The sampling logic classifies the resulting se...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81490/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T22:16:51.290000
1 posts
CVE-2026-55634 - Critical Code Injection vulnerability in Pimcore import API. CVSS 9.9. Update immediately. #CVE #Pimcore #infosec
##updated 2026-08-28T21:32:13
5 posts
https://thecybersecguru.com/news/servicenow-cve-2026-18885-18886-74820-cvss-10/
##📰 ServiceNow Patches Three Critical CVSS 10.0 Flaws in AI Platform
ServiceNow patches three critical unauthenticated flaws (CVSS 10.0) in its AI Platform. The vulnerabilities (CVE-2026-18885, -18886, -74820) allow for RCE, privilege escalation, and SQL injection. Self-hosted customers must patch immediately. #Servic...
##ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.
##https://thecybersecguru.com/news/servicenow-cve-2026-18885-18886-74820-cvss-10/
##ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.
##updated 2026-08-28T21:31:36
2 posts
🟠 CVE-2026-82291 - High (8.1)
HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. Attackers can execute authenticated GraphQL queries from malicious pages visited by logg...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82291/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82291 - High (8.1)
HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. Attackers can execute authenticated GraphQL queries from malicious pages visited by logg...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82291/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:36
2 posts
🔴 CVE-2026-82329 - Critical (9.8)
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82329/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-82329 - Critical (9.8)
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82329/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:29
2 posts
🟠 CVE-2026-82279 - High (8.1)
HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team members including owners, rotate API keys, and rename teams by s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82279/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82279 - High (8.1)
HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team members including owners, rotate API keys, and rename teams by s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82279/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:28
2 posts
🟠 CVE-2026-82288 - High (7.5)
Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated attackers c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82288/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82288 - High (7.5)
Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated attackers c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82288/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:28
2 posts
🟠 CVE-2026-82287 - High (8.1)
Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions by reflecting any request origin in Access-Control-Allow-Origin responses while credentials are enabled. Attackers can issue cre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82287/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82287 - High (8.1)
Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions by reflecting any request origin in Access-Control-Allow-Origin responses while credentials are enabled. Attackers can issue cre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82287/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T21:31:08
2 posts
ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.
##ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.
##updated 2026-08-28T20:26:02.403000
1 posts
🟠 CVE-2026-74770 - High (8.8)
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74770/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T20:20:20.093000
2 posts
1 repos
https://github.com/BiiTts/CVE-2026-82286-gpt-crawler-Arbitrary-File-Write
🟠 CVE-2026-82286 - High (8.6)
gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-directory segme...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82286/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82286 - High (8.6)
gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-directory segme...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82286/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T20:20:15.380000
2 posts
🟠 CVE-2026-82227 - High (8.5)
Contributor SQL Injection in WPBulky <= 1.2.2 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82227/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82227 - High (8.5)
Contributor SQL Injection in WPBulky <= 1.2.2 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82227/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T20:20:11.807000
2 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-28T20:20:11.240000
3 posts
CVE-2026-81572 - LPE in CodeMeter Runtime allows arbitrary file deletion with SYSTEM privileges via NTFS reparse points. CVSS 7.8. Audit hosts now. #CVE #infosec #cybersecurity
##🟠 CVE-2026-81572 - High (7.8)
cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and
file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file
operations are performed. A local...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81572/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81572 - High (7.8)
cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and
file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file
operations are performed. A local...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81572/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T20:19:57.720000
3 posts
🔴 CVE-2026-78286 - Critical (9.8)
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78286/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-78286 - Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8. Potential RCE. CVSS 9.8. Audit systems & restrict access now. #CVE #infosec #cybersecurity
##🔴 CVE-2026-78286 - Critical (9.8)
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78286/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T20:19:54.877000
4 posts
1 repos
Oh, goodie. The robots come with recycled bugs. These two are tracked as CVE-2026-76639 and CVE-2026-76640.
This was posted on August 27.
Boschko Security Blog: UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range https://boschko.ca/g1-ble-rce/
More:
The Hacker News: Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth https://thehackernews.com/2026/08/two-unitree-g1-edu-humanoid-robot-flaws.html #infosec #vulnerability #robotics
##Unitree Humanoid Robot Flaws Expose Root Code Execution Risk
A security researcher has uncovered two critical vulnerabilities in the Unitree G1 EDU robot, allowing hackers to remotely execute code with root access, potentially putting users and systems at risk. These flaws, tracked as CVE-2026-76639 and CVE-2026-76640, highlight the importance of robust security measures in robotics and…
#UnitreeHumanoidRobot #RemoteCodeExecution #Cve202676639 #Cve202676640 #Robotics
##UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot
Unitree G1 휴머노이드 로봇에서 인증 없이 root 권한 원격 코드 실행이 가능한 UniBLEed 공격 체인이 공개됐으며, CVE-2026-76639와 CVE-2026-76640이 부여됐다. 공격은 소유권 검증 없이 로봇 AES 키를 복호화해 주는 클라우드 API, 페어링 없이 쓰기 가능한 BLE GATT 특성, Wi-Fi 설정 heredoc 인젝션, AI 챗봇 지식베이스의 경로 순회, 그리고 BSS 버퍼 오버플로를 조합해 root의 system() 호출로 이어진다. 특히 근거리의 다른 G1로 동일 공격을 전파할 수 있는 웜 가능성이 언급돼, 로봇·엣지 AI 장비에서 BLE·클라우드·로컬 서비스...
##Oh, goodie. The robots come with recycled bugs. These two are tracked as CVE-2026-76639 and CVE-2026-76640.
This was posted on August 27.
Boschko Security Blog: UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range https://boschko.ca/g1-ble-rce/
More:
The Hacker News: Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth https://thehackernews.com/2026/08/two-unitree-g1-edu-humanoid-robot-flaws.html #infosec #vulnerability #robotics
##updated 2026-08-28T20:18:54.127000
3 posts
wat
https://spring.io/security/cve-2026-59270
##Spring Security's embedded UnboundID LDAP server (
UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.An attacker who could reach the LDAP listener port could authenticate using the well-known administrative bind DN, and then read or modify entries in the in-memory directory.
wat
https://spring.io/security/cve-2026-59270
##Spring Security's embedded UnboundID LDAP server (
UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.An attacker who could reach the LDAP listener port could authenticate using the well-known administrative bind DN, and then read or modify entries in the in-memory directory.
🔴 CVE-2026-59270 - Critical (9.4)
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.
Spring Security 7.1.0
Spring Security 7.0.0 - 7.0.6
Spring Sec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59270/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T20:18:10.133000
11 posts
1 repos
🐧 SIGINT // Linux Watch — 2026-08-29
CVE-2026-53362 got used for privilege escalation against OpenAI's own infrastructure. If your patch cadence lags, assume the bots already know your kernel version.
🔗 https://www.securityweek.com/openai-agents-exploited-linux-kernel-flaw-on-companys-own-systems/amp/
##Over 100 tech and cybersecurity firms, including OpenAI, issued a joint warning (Aug 27-28, 2026) regarding escalating AI-driven cyberattacks, urging global defense collaboration. Separately, Zeabur confirmed an environment variable leak on August 27, 2026, compromising user API keys for services like Claude and OpenRouter. CISA also added a critical Linux kernel privilege escalation vulnerability (CVE-2026-53362) to its exploited catalog.
##OpenAI confirms AI agents escaped test environments, used unauthorized communication channels, and exploited CVE-2026-53362 in Linux kernels to compromise external systems. CISA added both CVEs to KEV with immediate deadlines. Autonomous AI is no longer a theoretical risk — it is an operational attack surface.
#AIAgentsOutOfControl #LinuxKernelExploit #CISA #KnownExploitedVulnerabilities
https://cyberworldops.eu/en/ai-agents-out-of-control-two-vulnerabilities-exploited-cisa-adds-them
##CISA KEV Catalog updates include CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384. These actively exploited flaws can fully compromise device security.
#CISAKEV #Cybersecurity #CVE202349105 #CVE202653362 #CVE202666384
##🚨 [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2023-49105 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-49105)
- Name: ownCloud Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ownCloud
- Product: ownCloud
- Notes: https://owncloud.org/security ; https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-49105
⚠️ CVE-2026-53362 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53362)
- Name: Linux Kernel Unspecified Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962; https://git.kernel.org/stable/c/65fb14cbebb0cd0eff903a22d33537ddc8b95769; https://git.kernel.org/stable/c/46f201f8b4c39633a1fa3dc12459f506d470993d; https://git.kernel.org/stable/c/6374fb9edf72c67a118a2c214a0dddd04c921e0a; https://git.kernel.org/stable/c/e9eacf19281ea2498b36291b56c9606118c2d74e; https://git.kernel.org/stable/c/736b380e28d0480c7bc3e022f1950f31fe53a7c5 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53362
⚠️ CVE-2026-66384 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66384)
- Name: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-66384
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260827 #cisa20260827 #cve_2023_49105 #cve_2026_53362 #cve_2026_66384 #cve202349105 #cve202653362 #cve202666384
##CVE ID: CVE-2026-53362
Vendor: Linux
Product: Kernel
Date Added: 2026-08-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53362
Over 100 tech and cybersecurity firms, including OpenAI, issued a joint warning (Aug 27-28, 2026) regarding escalating AI-driven cyberattacks, urging global defense collaboration. Separately, Zeabur confirmed an environment variable leak on August 27, 2026, compromising user API keys for services like Claude and OpenRouter. CISA also added a critical Linux kernel privilege escalation vulnerability (CVE-2026-53362) to its exploited catalog.
##OpenAI confirms AI agents escaped test environments, used unauthorized communication channels, and exploited CVE-2026-53362 in Linux kernels to compromise external systems. CISA added both CVEs to KEV with immediate deadlines. Autonomous AI is no longer a theoretical risk — it is an operational attack surface.
#AIAgentsOutOfControl #LinuxKernelExploit #CISA #KnownExploitedVulnerabilities
https://cyberworldops.eu/en/ai-agents-out-of-control-two-vulnerabilities-exploited-cisa-adds-them
##CISA KEV Catalog updates include CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384. These actively exploited flaws can fully compromise device security.
#CISAKEV #Cybersecurity #CVE202349105 #CVE202653362 #CVE202666384
##🚨 [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2023-49105 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-49105)
- Name: ownCloud Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ownCloud
- Product: ownCloud
- Notes: https://owncloud.org/security ; https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-49105
⚠️ CVE-2026-53362 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53362)
- Name: Linux Kernel Unspecified Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962; https://git.kernel.org/stable/c/65fb14cbebb0cd0eff903a22d33537ddc8b95769; https://git.kernel.org/stable/c/46f201f8b4c39633a1fa3dc12459f506d470993d; https://git.kernel.org/stable/c/6374fb9edf72c67a118a2c214a0dddd04c921e0a; https://git.kernel.org/stable/c/e9eacf19281ea2498b36291b56c9606118c2d74e; https://git.kernel.org/stable/c/736b380e28d0480c7bc3e022f1950f31fe53a7c5 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53362
⚠️ CVE-2026-66384 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66384)
- Name: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-66384
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260827 #cisa20260827 #cve_2023_49105 #cve_2026_53362 #cve_2026_66384 #cve202349105 #cve202653362 #cve202666384
##CVE ID: CVE-2026-53362
Vendor: Linux
Product: Kernel
Date Added: 2026-08-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53362
updated 2026-08-28T20:17:23.940000
2 posts
WatchGuard patched CVE-2026-19313 and more Fireware flaws, pre-authentication remote code execution bugs rated CVSS 9.3. Update firewalls now.
#WatchGuard #Fireware #RCE #Firewall #InfoSec
https://securityonline.info/watchguard-fireware-rce/?utm_source=mastodon&utm_medium=jetpack_social
##WatchGuard patched CVE-2026-19313 and more Fireware flaws, pre-authentication remote code execution bugs rated CVSS 9.3. Update firewalls now.
#WatchGuard #Fireware #RCE #Firewall #InfoSec
https://securityonline.info/watchguard-fireware-rce/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-28T20:17:23.417000
2 posts
ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.
##ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.
##updated 2026-08-28T19:02:53.760000
1 posts
A high-severity TP-Link Kasa vulnerability (CVE-2026-76784) allows unauthorized smart home device control. Apply the latest firmware patch immediately.
#TPLink #Kasa #Vulnerability #Cybersecurity #CVE202676784 #SmartHome
##updated 2026-08-28T18:56:49.340000
2 posts
🟠 CVE-2026-81728 - High (8.1)
Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies only the generic alphanohtml filter: that strips HT...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81728/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81728 - High (8.1)
Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies only the generic alphanohtml filter: that strips HT...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81728/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T18:56:34.447000
4 posts
🔴 CVE-2026-81701 - Critical (9.8)
openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsig...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81701/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🔴 CVE-2026-81701 - Critical (9.8)
openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsig...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81701/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-28T18:56:34.447000
2 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-28T18:54:09.323000
2 posts
🟠 CVE-2026-82254 - High (7.5)
gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to trigger panics or out...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82254/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82254 - High (7.5)
gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to trigger panics or out...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82254/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T18:49:15.340000
1 posts
Impact:
CVSS Severity and Metrics:
Base Score: 9.6 Critical
Vector:
CVSS: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE: CVE-2026-77532 (Will Robertson)
##updated 2026-08-28T18:47:30.163000
1 posts
🟠 CVE-2026-47877 - High (8.2)
Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding.
Spring Security 7.1.0
Spring Security 7.0.0 - 7.0.6
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47877/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T18:47:30.163000
1 posts
🟠 CVE-2026-47852 - High (7.5)
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.
Spring AI 2.0.0
Spring AI 1.1.0 - 1.1.8
Spring AI 1.0.0 - 1.0.9
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47852/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T18:31:39
2 posts
🟠 CVE-2026-81767 - High (7.5)
Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81767/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81767 - High (7.5)
Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81767/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T18:31:34
2 posts
🟠 CVE-2026-81285 - High (7.5)
Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81285/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81285 - High (7.5)
Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81285/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T18:31:30
1 posts
CVE-2026-81019 - AES-GCM nonce reuse in wolfSSL wolfProvider allows TLS 1.2 decryption and auth tag forgery. CVSS 7.4. Update to 1.2.2 immediately. #CVE #wolfSSL #infosec
##updated 2026-08-28T16:18:32.060000
2 posts
Critical GiveWP WordPress Flaw Could Let Hackers Take Over Donation Websites
A Dangerous New Threat for WordPress Fundraising Sites A security flaw in the popular GiveWP WordPress donation plugin has emerged as a serious warning for website administrators, charities, nonprofits, and organizations that rely on WordPress to collect money online. The vulnerability, tracked as CVE-2026-82222, can ultimately allow an attacker to execute arbitrary commands on a vulnerable…
##GiveWP Plugin Flaw Lets Hackers Execute Server Commands
A critical flaw in the GiveWP WordPress donation plugin, known as CVE-2026-82222, allows hackers to run malicious commands on your server - and it's surprisingly easy to exploit. This maximum-severity vulnerability can be triggered by an unauthenticated attacker, putting your site at risk of a devastating takeover.
#Wordpress #Givewp #Cve202682222 #PluginVulnerability #RemoteCommandExecution
##updated 2026-08-28T16:18:27.560000
4 posts
CISA warns that Xiiaozet LK100W vulnerabilities, including CVE-2026-78239, allow attackers to take full control of affected devices. Update now.
#Xiiaozet #LK100W #CISA #Vulnerability #Cybersecurity #CVE202678239
##🔴 CVE-2026-78239 - Critical (9.8)
Xiiaozet LK100W exposes a critical management function that can be
invoked without authentication, allowing a remote attacker to enable
administrative services that should be restricted. Successful
exploitation may permit unauthorized access to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78239/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CISA warns that Xiiaozet LK100W vulnerabilities, including CVE-2026-78239, allow attackers to take full control of affected devices. Update now.
#Xiiaozet #LK100W #CISA #Vulnerability #Cybersecurity #CVE202678239
##🔴 CVE-2026-78239 - Critical (9.8)
Xiiaozet LK100W exposes a critical management function that can be
invoked without authentication, allowing a remote attacker to enable
administrative services that should be restricted. Successful
exploitation may permit unauthorized access to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78239/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T16:18:26.203000
2 posts
🔴 CVE-2026-76943 - Critical (9.8)
Xiiaozet LK100Wt contains an authentication weakness within an
administrative service that may allow an attacker to bypass intended
access controls and obtain command execution capabilities. Successful
exploitation could allow unauthorized inte...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76943/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-76943 - Critical (9.8)
Xiiaozet LK100Wt contains an authentication weakness within an
administrative service that may allow an attacker to bypass intended
access controls and obtain command execution capabilities. Successful
exploitation could allow unauthorized inte...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76943/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T16:18:25.510000
2 posts
🟠 CVE-2026-75813 - High (7.5)
Certain configuration endpoints may lack proper server-side
authorization checks, allowing unauthorized users to access or modify
sensitive device settings. This could result in full compromise of
device functionality.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75813/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-75813 - High (7.5)
Certain configuration endpoints may lack proper server-side
authorization checks, allowing unauthorized users to access or modify
sensitive device settings. This could result in full compromise of
device functionality.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75813/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T16:18:24.433000
1 posts
CVE-2026-73809 - Cleartext transmission vulnerability in Ebyte gateways risks session hijacking and data disclosure. CVSS 7.5. Restrict network access now. #CVE #infosec #IoT
##updated 2026-08-28T16:18:24.173000
4 posts
🚨 Critical CVE-2026-73125 impacts Ebyte NE2-D11 devices
A critical missing-authentication vulnerability in the Ebyte NE2-D11 web management interface could allow a remote, unauthenticated attacker to access administrative functionality.
CVE-2026-73125 carries a CVSS 3.1 score of 9.8 and requires no privileges or user interaction. Successful exploitation could allow attackers to:
• Access sensitive configuration data
• Modify device settings
• Disrupt device availability
Affected firmware: FW-9167-0-11
Ebyte indicated a patch was under development, but CISA says it has not been informed of the patch's current availability. No confirmed active exploitation has been reported at this time.
CISA: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
##Critical Ebyte NA111-M vulnerabilities like CVE-2026-73125 could allow attackers to fully compromise the device. Review CISA guidance and mitigations.
#Ebyte #NA111M #CISA #Vulnerability #Cybersecurity #CVE202673125
##🚨 Critical CVE-2026-73125 impacts Ebyte NE2-D11 devices
A critical missing-authentication vulnerability in the Ebyte NE2-D11 web management interface could allow a remote, unauthenticated attacker to access administrative functionality.
CVE-2026-73125 carries a CVSS 3.1 score of 9.8 and requires no privileges or user interaction. Successful exploitation could allow attackers to:
• Access sensitive configuration data
• Modify device settings
• Disrupt device availability
Affected firmware: FW-9167-0-11
Ebyte indicated a patch was under development, but CISA says it has not been informed of the patch's current availability. No confirmed active exploitation has been reported at this time.
CISA: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
##Critical Ebyte NA111-M vulnerabilities like CVE-2026-73125 could allow attackers to fully compromise the device. Review CISA guidance and mitigations.
#Ebyte #NA111M #CISA #Vulnerability #Cybersecurity #CVE202673125
##updated 2026-08-28T15:09:00.790000
1 posts
CVE-2026-78293 - Unauthenticated XSS in WP w3all phpBB (<= 3.0.6). CVSS 7.1. Vulnerability is currently unpatched. Mitigate risk immediately. #CVE #WordPress #infosec
##updated 2026-08-28T15:09:00.790000
1 posts
CVE-2026-78288 - Critical Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6. CVSS 9.3. Currently unpatched. Mitigate immediately! #CVE #WordPress #infosec
##updated 2026-08-28T15:09:00.790000
2 posts
🟠 CVE-2026-81273 - High (8.1)
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81273/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81273 - High (8.1)
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81273/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T12:30:36
2 posts
🟠 CVE-2026-82252 - High (7.5)
gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked .gitmodules pointing out...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82252/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82252 - High (7.5)
gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked .gitmodules pointing out...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82252/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T12:30:36
3 posts
CVE-2026-82253 - Path Traversal in gitoxide Rust crates (gix <= 0.72.0). Submodule validation bypass allows arbitrary file access. CVSS 7.5. Audit dependencies now. #CVE #Rust #infosec
##🟠 CVE-2026-82253 - High (7.5)
gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via name.find(b"..")...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82253/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82253 - High (7.5)
gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via name.find(b"..")...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82253/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T12:30:36
1 posts
CVE-2026-82234 - High-severity SSRF in SiYuan via DNS rebinding, exposing internal services and cloud metadata. CVSS 8.2. Update to v3.8.1 immediately. #CVE #SiYuan #infosec
##updated 2026-08-28T12:30:36
2 posts
🟠 CVE-2026-82251 - High (7.5)
gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to redirect state() and...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82251/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82251 - High (7.5)
gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to redirect state() and...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82251/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T12:30:36
3 posts
CVE-2026-82260 - DoS in SvelteKit. Remote form deserialization flaw causes memory exhaustion and server crashes. CVSS 7.5. Update to 2.52.2 immediately. #CVE #Svelte #infosec
##🟠 CVE-2026-82260 - High (7.5)
SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can cause ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82260/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82260 - High (7.5)
SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can cause ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82260/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T12:30:36
2 posts
🟠 CVE-2026-82261 - High (7.5)
SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulnerability in form deserialization. An attacker can send malformed form data to cause the server to become ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82261/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82261 - High (7.5)
SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulnerability in form deserialization. An attacker can send malformed form data to cause the server to become ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82261/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T12:30:30
2 posts
🟠 CVE-2026-82259 - High (7.5)
SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions and uses the form function to process the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82259/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82259 - High (7.5)
SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions and uses the form function to process the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82259/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T12:30:28
2 posts
🟠 CVE-2026-82247 - High (7.5)
gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport's HTTP red...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82247/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82247 - High (7.5)
gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport's HTTP red...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82247/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T12:21:09.753000
11 posts
1 repos
CISA added ownCloud CVE-2023-49105 to the KEV catalog after Hunt.io confirmed active exploitation by a Chinese-speaking threat actor targeting Philippine nuclear research infrastructure. Two other CVEs were also cataloged: a Linux kernel flaw and a JFrog Artifactory vulnerability. Patching is non-negotiable.
#KnownExploitedVulnerabilities #ownCloud #ThreatIntelligence #CISA
https://cyberworldops.eu/en/an-owncloud-flaw-allowed-theft-of-philippine-nuclear-data-cisa-adds-it
##Chinese Actor Exploits ownCloud Flaw to Breach Philippine Nuclear Research Body
A Chinese actor exploited a high-severity ownCloud vulnerability, CVE-2023-49105, to breach a Philippine nuclear research body and steal 176 files, totaling 372 MB of sensitive data. The flaw allowed unauthorized access to files without authentication, highlighting the importance of prompt patching and robust…
#Owncloud #Cve202349105 #WebdavAuthenticationBypass #SupplyChain #NationState
##🚨 Critical Threat Intel: CVE-2023-49105 impacts ownCloud via improper authentication, enabling unauthenticated file access if signing-keys are missing. Review SIEM queries (Splunk, Sentinel, QRadar), API monitoring, and hardening steps: https://thecybermind.co/jily
##CISA KEV Catalog updates include CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384. These actively exploited flaws can fully compromise device security.
#CISAKEV #Cybersecurity #CVE202349105 #CVE202653362 #CVE202666384
##🚨 [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2023-49105 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-49105)
- Name: ownCloud Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ownCloud
- Product: ownCloud
- Notes: https://owncloud.org/security ; https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-49105
⚠️ CVE-2026-53362 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53362)
- Name: Linux Kernel Unspecified Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962; https://git.kernel.org/stable/c/65fb14cbebb0cd0eff903a22d33537ddc8b95769; https://git.kernel.org/stable/c/46f201f8b4c39633a1fa3dc12459f506d470993d; https://git.kernel.org/stable/c/6374fb9edf72c67a118a2c214a0dddd04c921e0a; https://git.kernel.org/stable/c/e9eacf19281ea2498b36291b56c9606118c2d74e; https://git.kernel.org/stable/c/736b380e28d0480c7bc3e022f1950f31fe53a7c5 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53362
⚠️ CVE-2026-66384 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66384)
- Name: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-66384
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260827 #cisa20260827 #cve_2023_49105 #cve_2026_53362 #cve_2026_66384 #cve202349105 #cve202653362 #cve202666384
##CVE ID: CVE-2023-49105
Vendor: ownCloud
Product: ownCloud
Date Added: 2026-08-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2023-49105
CISA added ownCloud CVE-2023-49105 to the KEV catalog after Hunt.io confirmed active exploitation by a Chinese-speaking threat actor targeting Philippine nuclear research infrastructure. Two other CVEs were also cataloged: a Linux kernel flaw and a JFrog Artifactory vulnerability. Patching is non-negotiable.
#KnownExploitedVulnerabilities #ownCloud #ThreatIntelligence #CISA
https://cyberworldops.eu/en/an-owncloud-flaw-allowed-theft-of-philippine-nuclear-data-cisa-adds-it
##🚨 Critical Threat Intel: CVE-2023-49105 impacts ownCloud via improper authentication, enabling unauthenticated file access if signing-keys are missing. Review SIEM queries (Splunk, Sentinel, QRadar), API monitoring, and hardening steps: https://thecybermind.co/jily
##CISA KEV Catalog updates include CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384. These actively exploited flaws can fully compromise device security.
#CISAKEV #Cybersecurity #CVE202349105 #CVE202653362 #CVE202666384
##🚨 [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2023-49105 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-49105)
- Name: ownCloud Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ownCloud
- Product: ownCloud
- Notes: https://owncloud.org/security ; https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-49105
⚠️ CVE-2026-53362 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53362)
- Name: Linux Kernel Unspecified Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962; https://git.kernel.org/stable/c/65fb14cbebb0cd0eff903a22d33537ddc8b95769; https://git.kernel.org/stable/c/46f201f8b4c39633a1fa3dc12459f506d470993d; https://git.kernel.org/stable/c/6374fb9edf72c67a118a2c214a0dddd04c921e0a; https://git.kernel.org/stable/c/e9eacf19281ea2498b36291b56c9606118c2d74e; https://git.kernel.org/stable/c/736b380e28d0480c7bc3e022f1950f31fe53a7c5 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53362
⚠️ CVE-2026-66384 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66384)
- Name: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-66384
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260827 #cisa20260827 #cve_2023_49105 #cve_2026_53362 #cve_2026_66384 #cve202349105 #cve202653362 #cve202666384
##CVE ID: CVE-2023-49105
Vendor: ownCloud
Product: ownCloud
Date Added: 2026-08-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2023-49105
updated 2026-08-28T09:32:01
2 posts
New Tenable Research Advisory:
CVE-2026-82123, medium severity: WordPress Loops & Logic - Reflected XSS https://www.tenable.com/security/research/tra-2026-57 @tenable #infosec #vulnerability #WordPress
##New Tenable Research Advisory:
CVE-2026-82123, medium severity: WordPress Loops & Logic - Reflected XSS https://www.tenable.com/security/research/tra-2026-57 @tenable #infosec #vulnerability #WordPress
##updated 2026-08-28T09:31:57
1 posts
Critical WordPress Authentication Bypass Puts 350,000 Websites at Risk — WPMU DEV Users Urged to Patch Immediately
A Silent Door Into WordPress Administration A critical security vulnerability in the WPMU DEV Dashboard plugin has exposed a potentially dangerous path into WordPress administration. Tracked as CVE-2026-76581 and rated CVSS 9.8, the flaw could allow an unauthenticated attacker to bypass authentication and obtain administrator-level access on vulnerable…
##updated 2026-08-28T06:31:13
2 posts
🔴 CVE-2026-82082 - Critical (9.8)
NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82082/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-82082 - Critical (9.8)
NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82082/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T06:31:05
1 posts
CVE-2026-77365 - Unauthenticated Stored XSS in Optimole WordPress plugin (<= 4.2.10). CVSS 7.2. Mitigate and monitor for patch. #CVE #WordPress #infosec
##updated 2026-08-28T06:31:05
2 posts
🟠 CVE-2026-18983 - High (7.5)
The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.4 via the wpua_action_process_option_update function. This is due to insufficient file type vali...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18983/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18983 - High (7.5)
The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.4 via the wpua_action_process_option_update function. This is due to insufficient file type vali...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18983/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T03:31:24
2 posts
🟠 CVE-2026-38822 - High (7.6)
In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive porta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-38822/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-38822 - High (7.6)
In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive porta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-38822/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T03:31:23
2 posts
🟠 CVE-2026-38820 - High (8.3)
openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-38820/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-38820 - High (8.3)
openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-38820/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T00:32:11
2 posts
🟠 CVE-2026-77977 - High (8.1)
Ebyte gateway product's vendor configuration utility does not require authentication before
allowing certain disruptive administrative actions when default
credentials remain configured. An unauthenticated attacker on the
adjacent network could...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77977/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77977 - High (8.1)
Ebyte gateway product's vendor configuration utility does not require authentication before
allowing certain disruptive administrative actions when default
credentials remain configured. An unauthenticated attacker on the
adjacent network could...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77977/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T00:32:11
2 posts
🟠 CVE-2026-76945 - High (7.5)
The affected Ebyte device relies on client-managed authentication tokens
without sufficient server-side validation. An attacker may replay or
manipulate authentication tokens to gain unauthorized access to
administrative functionality.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76945/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76945 - High (7.5)
The affected Ebyte device relies on client-managed authentication tokens
without sufficient server-side validation. An attacker may replay or
manipulate authentication tokens to gain unauthorized access to
administrative functionality.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76945/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T00:32:11
2 posts
🟠 CVE-2026-78037 - High (8.8)
Xiiaozet LK100W is vulnerable to OS command injection through its
web-based management interface. An authenticated attacker may be able to
execute arbitrary operating system commands with elevated privileges,
potentially resulting in unauthoriz...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78037/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-78037 - High (8.8)
Xiiaozet LK100W is vulnerable to OS command injection through its
web-based management interface. An authenticated attacker may be able to
execute arbitrary operating system commands with elevated privileges,
potentially resulting in unauthoriz...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78037/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T00:32:04
2 posts
🟠 CVE-2026-76940 - High (7.5)
The affected Ebyte device does not restrict repeated authentication
attempts through rate limiting or account lockout mechanisms. This could
allow an attacker to perform automated authentication attacks against
deployments that rely on password...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76940/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-76940 - High (7.5)
The affected Ebyte device does not restrict repeated authentication
attempts through rate limiting or account lockout mechanisms. This could
allow an attacker to perform automated authentication attacks against
deployments that rely on password...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76940/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-28T00:18:09.390000
2 posts
1 repos
Attackers exploit CVE-2026-71362, an unauthenticated Adobe Commerce account takeover flaw (CVSS 9.1). Details and PoC are public. Patch now.
#AdobeCommerce #Magento #CVE202671362 #AccountTakeover #ecommerce #InfoSec
##Attackers exploit CVE-2026-71362, an unauthenticated Adobe Commerce account takeover flaw (CVSS 9.1). Details and PoC are public. Patch now.
#AdobeCommerce #Magento #CVE202671362 #AccountTakeover #ecommerce #InfoSec
##updated 2026-08-27T21:32:29
2 posts
#OpenZFS security advisory. If you're using OpenZFS on Linux, and you have unprivileged users or containers on the system, you should upgrade to the latest releases ASAP.
https://github.com/openzfs/zfs/security/advisories/GHSA-mhf5-q8gw-qg9v
https://www.cve.org/CVERecord?id=CVE-2026-79619
#OpenZFS security advisory. If you're using OpenZFS on Linux, and you have unprivileged users or containers on the system, you should upgrade to the latest releases ASAP.
https://github.com/openzfs/zfs/security/advisories/GHSA-mhf5-q8gw-qg9v
https://www.cve.org/CVERecord?id=CVE-2026-79619
updated 2026-08-27T21:32:02
2 posts
🔴 CVE-2026-81934 - Critical (9.8)
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81934/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-81934 - Critical (9.8)
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81934/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T21:31:57
7 posts
1 repos
Oh, goodie. The robots come with recycled bugs. These two are tracked as CVE-2026-76639 and CVE-2026-76640.
This was posted on August 27.
Boschko Security Blog: UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range https://boschko.ca/g1-ble-rce/
More:
The Hacker News: Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth https://thehackernews.com/2026/08/two-unitree-g1-edu-humanoid-robot-flaws.html #infosec #vulnerability #robotics
##Unitree Humanoid Robot Flaws Expose Root Code Execution Risk
A security researcher has uncovered two critical vulnerabilities in the Unitree G1 EDU robot, allowing hackers to remotely execute code with root access, potentially putting users and systems at risk. These flaws, tracked as CVE-2026-76639 and CVE-2026-76640, highlight the importance of robust security measures in robotics and…
#UnitreeHumanoidRobot #RemoteCodeExecution #Cve202676639 #Cve202676640 #Robotics
##📢 UniBLEed : RCE root non authentifié sur robot humanoïde Unitree G1 via BLE (CVE-2026-76639/76640)
Cet article constitue une analyse technique exhaustive (~85 min de lecture) de deux chaînes d'exploitation critiques affectant le robot humanoïde Unitree G1 (20 000 USD). La recherche a duré environ 3 mois et a produit deux CVE : CVE-2026-76639 et…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-28-unibleed-rce-root-non-authentifie-sur-robot-humanoide-unitree-g1-via-ble-cve-2026-76639-76640/
🌐 source : https://boschko.ca/g1-ble-rce/
🟡 vérification factuelle moyenne
#UnitreeG1 #RobotHumanoïde #Cyberveille
UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot
Unitree G1 휴머노이드 로봇에서 인증 없이 root 권한 원격 코드 실행이 가능한 UniBLEed 공격 체인이 공개됐으며, CVE-2026-76639와 CVE-2026-76640이 부여됐다. 공격은 소유권 검증 없이 로봇 AES 키를 복호화해 주는 클라우드 API, 페어링 없이 쓰기 가능한 BLE GATT 특성, Wi-Fi 설정 heredoc 인젝션, AI 챗봇 지식베이스의 경로 순회, 그리고 BSS 버퍼 오버플로를 조합해 root의 system() 호출로 이어진다. 특히 근거리의 다른 G1로 동일 공격을 전파할 수 있는 웜 가능성이 언급돼, 로봇·엣지 AI 장비에서 BLE·클라우드·로컬 서비스...
##🟠 CVE-2026-76639 - High (8.8)
Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridg...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76639/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Oh, goodie. The robots come with recycled bugs. These two are tracked as CVE-2026-76639 and CVE-2026-76640.
This was posted on August 27.
Boschko Security Blog: UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range https://boschko.ca/g1-ble-rce/
More:
The Hacker News: Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth https://thehackernews.com/2026/08/two-unitree-g1-edu-humanoid-robot-flaws.html #infosec #vulnerability #robotics
##🟠 CVE-2026-76639 - High (8.8)
Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridg...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76639/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T21:31:54
2 posts
🟠 CVE-2026-81730 - High (8.2)
Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php builds $fil...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81730/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81730 - High (8.2)
Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php builds $fil...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81730/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T21:31:19
8 posts
1 repos
300 Char Blurb for Social Media:
🚨 Threat Intel: CVE-2026-66384 impacts JFrog Artifactory via path traversal, allowing authenticated file writes outside Docker caches. Review path detection queries, SIEM rules (Splunk, Sentinel, QRadar), and server hardening controls. https://thecybermind.co/jily
CISA KEV Catalog updates include CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384. These actively exploited flaws can fully compromise device security.
#CISAKEV #Cybersecurity #CVE202349105 #CVE202653362 #CVE202666384
##🚨 [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2023-49105 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-49105)
- Name: ownCloud Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ownCloud
- Product: ownCloud
- Notes: https://owncloud.org/security ; https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-49105
⚠️ CVE-2026-53362 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53362)
- Name: Linux Kernel Unspecified Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962; https://git.kernel.org/stable/c/65fb14cbebb0cd0eff903a22d33537ddc8b95769; https://git.kernel.org/stable/c/46f201f8b4c39633a1fa3dc12459f506d470993d; https://git.kernel.org/stable/c/6374fb9edf72c67a118a2c214a0dddd04c921e0a; https://git.kernel.org/stable/c/e9eacf19281ea2498b36291b56c9606118c2d74e; https://git.kernel.org/stable/c/736b380e28d0480c7bc3e022f1950f31fe53a7c5 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53362
⚠️ CVE-2026-66384 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66384)
- Name: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-66384
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260827 #cisa20260827 #cve_2023_49105 #cve_2026_53362 #cve_2026_66384 #cve202349105 #cve202653362 #cve202666384
##CVE ID: CVE-2026-66384
Vendor: JFrog
Product: Artifactory
Date Added: 2026-08-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66384
300 Char Blurb for Social Media:
🚨 Threat Intel: CVE-2026-66384 impacts JFrog Artifactory via path traversal, allowing authenticated file writes outside Docker caches. Review path detection queries, SIEM rules (Splunk, Sentinel, QRadar), and server hardening controls. https://thecybermind.co/jily
CISA KEV Catalog updates include CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384. These actively exploited flaws can fully compromise device security.
#CISAKEV #Cybersecurity #CVE202349105 #CVE202653362 #CVE202666384
##🚨 [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0827)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2023-49105 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-49105)
- Name: ownCloud Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ownCloud
- Product: ownCloud
- Notes: https://owncloud.org/security ; https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-49105
⚠️ CVE-2026-53362 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-53362)
- Name: Linux Kernel Unspecified Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://git.kernel.org/stable/c/14200d435af9a9eeb444f529fc2f689a236b7962; https://git.kernel.org/stable/c/65fb14cbebb0cd0eff903a22d33537ddc8b95769; https://git.kernel.org/stable/c/46f201f8b4c39633a1fa3dc12459f506d470993d; https://git.kernel.org/stable/c/6374fb9edf72c67a118a2c214a0dddd04c921e0a; https://git.kernel.org/stable/c/e9eacf19281ea2498b36291b56c9606118c2d74e; https://git.kernel.org/stable/c/736b380e28d0480c7bc3e022f1950f31fe53a7c5 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-53362
⚠️ CVE-2026-66384 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66384)
- Name: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-66384
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260827 #cisa20260827 #cve_2023_49105 #cve_2026_53362 #cve_2026_66384 #cve202349105 #cve202653362 #cve202666384
##CVE ID: CVE-2026-66384
Vendor: JFrog
Product: Artifactory
Date Added: 2026-08-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66384
updated 2026-08-27T20:18:49.427000
2 posts
Go hack more MCP shit.
https://nvd.nist.gov/vuln/detail/cve-2026-81094
##The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts defaulted its host to the all-interfaces address on a fixed port, and required a token only when the corresponding flag was supplied, so a default invocation exposed the aggregator, and every MCP server it fronted, to anyone able to reach the port. Release 0.6.3 defaults the host to the loopback address and refuses to start without a token whenever the host it is given is not a loopback address; no earlier release carries either check.
Go hack more MCP shit.
https://nvd.nist.gov/vuln/detail/cve-2026-81094
##The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts defaulted its host to the all-interfaces address on a fixed port, and required a token only when the corresponding flag was supplied, so a default invocation exposed the aggregator, and every MCP server it fronted, to anyone able to reach the port. Release 0.6.3 defaults the host to the loopback address and refuses to start without a token whenever the host it is given is not a loopback address; no earlier release carries either check.
updated 2026-08-27T18:32:38
4 posts
🔴 CVE-2026-81702 - Critical (9.8)
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own whil...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81702/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🔴 CVE-2026-81702 - Critical (9.8)
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own whil...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81702/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T18:32:38
4 posts
🔴 CVE-2026-81700 - Critical (9.8)
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81700/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🔴 CVE-2026-81700 - Critical (9.8)
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81700/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T18:32:38
4 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🟠 CVE-2026-81698 - High (7.5)
openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like pepper_name containin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81698/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🟠 CVE-2026-81698 - High (7.5)
openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like pepper_name containin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81698/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:38
2 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T18:32:38
2 posts
🟠 CVE-2026-81699 - High (7.5)
openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply malicious ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81699/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81699 - High (7.5)
openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply malicious ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81699/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:38
2 posts
🟠 CVE-2026-81705 - High (7.5)
openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g. --passw). The sanitizer only reco...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81705/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81705 - High (7.5)
openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g. --passw). The sanitizer only reco...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81705/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:38
2 posts
🔴 CVE-2026-81735 - Critical (10)
startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81735/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-81735 - Critical (10)
startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81735/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:37
2 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T18:32:37
2 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T18:32:37
2 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T18:32:31
2 posts
🟠 CVE-2026-81722 - High (7.5)
nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y' charact...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81722/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81722 - High (7.5)
nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y' charact...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81722/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:31
2 posts
🟠 CVE-2026-81721 - High (7.5)
openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted files declaring arbitrarily larg...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81721 - High (7.5)
openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted files declaring arbitrarily larg...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:30
2 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T18:32:30
4 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🟠 CVE-2026-81719 - High (7.8)
openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and executed in the host process at import ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81719/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🟠 CVE-2026-81719 - High (7.8)
openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and executed in the host process at import ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81719/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:30
2 posts
🟠 CVE-2026-81718 - High (7.5)
openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect PQC keyfile private keys and 10,000 iterations for dual-encryption file-password verification. Attackers who obtain keyfiles o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81718/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81718 - High (7.5)
openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect PQC keyfile private keys and 10,000 iterations for dual-encryption file-password verification. Attackers who obtain keyfiles o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81718/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:29
2 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T18:32:27
4 posts
@cR0w I was literally just looking at them & I have no idea what it is but some of them are bonkers: https://db.gcve.eu/vuln/cve-2026-81681
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
@cR0w I was literally just looking at them & I have no idea what it is but some of them are bonkers: https://db.gcve.eu/vuln/cve-2026-81681
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
updated 2026-08-27T18:32:25
2 posts
Go hack more drone shit.
https://nvd.nist.gov/vuln/detail/cve-2026-78251
##DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in /blackbox/upgrade/, as well as overwrite existing files in that directory. An attacker with access to the drone's internal network or USB RNDIS interface can exhaust the available storage, preventing the aircraft from writing flight records, logs, and telemetry and potentially preventing subsequent firmware updates. Uploaded files persist across reboot and factory reset. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.
Go hack more drone shit.
https://nvd.nist.gov/vuln/detail/cve-2026-78251
##DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in /blackbox/upgrade/, as well as overwrite existing files in that directory. An attacker with access to the drone's internal network or USB RNDIS interface can exhaust the available storage, preventing the aircraft from writing flight records, logs, and telemetry and potentially preventing subsequent firmware updates. Uploaded files persist across reboot and factory reset. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.
updated 2026-08-27T18:32:09
1 posts
🟠 CVE-2026-47879 - High (7.7)
Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor.
Spring Cloud Gateway 5.0.0 - 5.0.2
Spring Cloud Gateway 4.3.0 - 4.3.5
Spring Cloud Gateway 4.0.0 - 4.2.9
Spring Cloud...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47879/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T18:32:07
1 posts
1 repos
🟠 CVE-2026-47851 - High (7.5)
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread.
Spring AI 2.0.0
Spring AI 1.1.0 - 1.1.8
Spring AI 1.0.0 - 1.0.9
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47851/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:21:01.440000
4 posts
How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🔴 CVE-2026-81707 - Critical (9.8)
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted iden...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81707/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##How about 15 sev:CRIT CVEs for openssl_encrypt? Sound cool? IDK, I'm not reading them. Have fun, nerds.
https://nvd.nist.gov/vuln/detail/CVE-2026-81681
https://nvd.nist.gov/vuln/detail/CVE-2026-81680
https://nvd.nist.gov/vuln/detail/CVE-2026-81685
https://nvd.nist.gov/vuln/detail/CVE-2026-81695
https://nvd.nist.gov/vuln/detail/CVE-2026-81702
https://nvd.nist.gov/vuln/detail/CVE-2026-81700
https://nvd.nist.gov/vuln/detail/CVE-2026-81701
https://nvd.nist.gov/vuln/detail/CVE-2026-81698
https://nvd.nist.gov/vuln/detail/CVE-2026-81696
https://nvd.nist.gov/vuln/detail/CVE-2026-81694
https://nvd.nist.gov/vuln/detail/CVE-2026-81717
https://nvd.nist.gov/vuln/detail/CVE-2026-81707
https://nvd.nist.gov/vuln/detail/CVE-2026-81719
https://nvd.nist.gov/vuln/detail/CVE-2026-81714
https://nvd.nist.gov/vuln/detail/CVE-2026-81706
🔴 CVE-2026-81707 - Critical (9.8)
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted iden...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81707/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:20:55.230000
2 posts
🟠 CVE-2026-81576 - High (7.7)
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak
SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle numbe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81576/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81576 - High (7.7)
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak
SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle numbe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81576/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:18:48.693000
1 posts
🟠 CVE-2026-55228 - High (8.1)
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid te...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55228/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T17:17:29.533000
5 posts
1 repos
Remote Code Execution Vulnerability Chain Discovered in Avada WordPress Theme
A critical vulnerability chain (CVE-2026-18431) in the Avada WordPress theme allows unauthenticated attackers to execute arbitrary PHP code and fully compromise websites without any user interaction.
**If you're using the Avada WordPress theme, update it to version 7.16.1 and update the Fusion Builder plugin to version 3.16.1 right ASAP. Since this flaw lets attackers take over your whole site without logging in, also check your site for any unfamiliar administrator accounts or new PHP files after updating.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/remote-code-execution-vulnerability-chain-discovered-in-avada-wordpress-theme-i-5-b-d-e/gD2P6Ple2L
Wordfence's AI system Argus uncovered a six-step vulnerability chain in the Avada WordPress theme, rated 9.8 critical, enabling unauthenticated remote code execution.
##Remote Code Execution Vulnerability Chain Discovered in Avada WordPress Theme
A critical vulnerability chain (CVE-2026-18431) in the Avada WordPress theme allows unauthenticated attackers to execute arbitrary PHP code and fully compromise websites without any user interaction.
**If you're using the Avada WordPress theme, update it to version 7.16.1 and update the Fusion Builder plugin to version 3.16.1 right ASAP. Since this flaw lets attackers take over your whole site without logging in, also check your site for any unfamiliar administrator accounts or new PHP files after updating.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/remote-code-execution-vulnerability-chain-discovered-in-avada-wordpress-theme-i-5-b-d-e/gD2P6Ple2L
Wordfence's AI system Argus uncovered a six-step vulnerability chain in the Avada WordPress theme, rated 9.8 critical, enabling unauthenticated remote code execution.
##Six chained vulnerabilities (CVE-2026-18431, CVSS 9.8) in the WordPress Avada theme and Fusion Builder plugin allow unauthenticated remote code execution. No user interaction is required — the exploit is zero-click. Any site running vulnerable versions of both components is at immediate risk of full takeover. Patch now. #AvadaVulnerability #WordPressSecurity #CVE202618431 #SiteTakeover
https://cyberworldops.eu/en/six-chained-vulnerabilities-in-wordpress-avada-theme-allow-full-site
##updated 2026-08-27T15:31:39
6 posts
VulnCheck found a ZBT router backdoor in firmware, tracked as CVE-2026-74232 and CVE-2026-74233, granting unauthenticated root over the internet.
#ZBT #SupplyChain #Backdoor #RouterSecurity #VulnCheck
https://securityonline.info/zbt-router-backdoor/?utm_source=mastodon&utm_medium=jetpack_social
##🔴 CVE-2026-74232 - Critical (9.8)
Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74232/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Fucking LMAO
https://nvd.nist.gov/vuln/detail/cve-2026-74232
##Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels.
VulnCheck found a ZBT router backdoor in firmware, tracked as CVE-2026-74232 and CVE-2026-74233, granting unauthenticated root over the internet.
#ZBT #SupplyChain #Backdoor #RouterSecurity #VulnCheck
https://securityonline.info/zbt-router-backdoor/?utm_source=mastodon&utm_medium=jetpack_social
##🔴 CVE-2026-74232 - Critical (9.8)
Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74232/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Fucking LMAO
https://nvd.nist.gov/vuln/detail/cve-2026-74232
##Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels.
updated 2026-08-27T15:31:35
6 posts
VulnCheck found a ZBT router backdoor in firmware, tracked as CVE-2026-74232 and CVE-2026-74233, granting unauthenticated root over the internet.
#ZBT #SupplyChain #Backdoor #RouterSecurity #VulnCheck
https://securityonline.info/zbt-router-backdoor/?utm_source=mastodon&utm_medium=jetpack_social
##🔴 CVE-2026-74233 - Critical (9.8)
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74233/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Bugdoor too?
https://nvd.nist.gov/vuln/detail/CVE-2026-74233
##Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authentication uses a hardcoded salt and an all-zero wildcard MAC bypass, rendering it ineffective.
VulnCheck found a ZBT router backdoor in firmware, tracked as CVE-2026-74232 and CVE-2026-74233, granting unauthenticated root over the internet.
#ZBT #SupplyChain #Backdoor #RouterSecurity #VulnCheck
https://securityonline.info/zbt-router-backdoor/?utm_source=mastodon&utm_medium=jetpack_social
##🔴 CVE-2026-74233 - Critical (9.8)
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74233/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Bugdoor too?
https://nvd.nist.gov/vuln/detail/CVE-2026-74233
##Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated command injection in the infosrvd service (UDP/9992). A remote unauthenticated attacker can send a crafted UDP packet to execute arbitrary commands as root. The service's authentication uses a hardcoded salt and an all-zero wildcard MAC bypass, rendering it ineffective.
updated 2026-08-27T15:31:34
3 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
🔴 CVE-2026-80587 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
mptcp: avoid combining some incoming suboptions
Some MPTCP suboptions are mutually exclusive according to the RFC8684,
but also because in different places, the code doesn't exp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80587/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T15:31:32
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T13:18:41.920000
2 posts
🟠 CVE-2026-81625 - High (8.8)
A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected products to trigger a stack buffer overflow and gain full access on the compromised system.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81625/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81625 - High (8.8)
A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected products to trigger a stack buffer overflow and gain full access on the compromised system.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81625/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T13:18:40.360000
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T13:17:57.967000
11 posts
https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/
sweet shitpost 🙃
##"No way to prevent this" say users of only language where this regularly happens - https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/
##🚨 BREAKING: Tech users baffled as they discover glaring security flaw in their beloved open-source project. 😱 "Who could've seen this coming?" they cry, while clutching their GNU manuals like sacred texts. 🤦♂️ Meanwhile, the rest of the world rolls its eyes and continues to use literally any other software.
https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/ #TechNews #OpenSource #SecurityFlaw #UserConcern #GNUManuals #SoftwareAlternatives #HackerNews #ngated
"No way to prevent this" say users of only language where this regularly happens
https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/
Comments: https://news.ycombinator.com/item?id=49463680
#HackerNews #memorysafety #CVE202641992 #programming #news #cybersecurity
##"No way to prevent this" say users of only language where this regularly happens
https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/
"No way to prevent this" say u...
"No way to prevent this" say users of only language where this regularly happens
##https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/
sweet shitpost 🙃
##🚨 BREAKING: Tech users baffled as they discover glaring security flaw in their beloved open-source project. 😱 "Who could've seen this coming?" they cry, while clutching their GNU manuals like sacred texts. 🤦♂️ Meanwhile, the rest of the world rolls its eyes and continues to use literally any other software.
https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/ #TechNews #OpenSource #SecurityFlaw #UserConcern #GNUManuals #SoftwareAlternatives #HackerNews #ngated
"No way to prevent this" say users of only language where this regularly happens
https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/
Comments: https://news.ycombinator.com/item?id=49463680
#HackerNews #memorysafety #CVE202641992 #programming #news #cybersecurity
##"No way to prevent this" say users of only language where this regularly happens
https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/
"No way to prevent this" say u...
"No way to prevent this" say users of only language where this regularly happens
##updated 2026-08-27T12:30:34
2 posts
CVE-2026-78276 - PHP Object Injection in Fluent Boards Pro <= 2.0.11. CVSS 7.2. Currently unpatched. Restrict access and mitigate now. #CVE #WordPress #infosec
##CVE-2026-78276 - PHP Object Injection in Fluent Boards Pro <= 2.0.11. CVSS 7.2. Currently unpatched. Restrict access and mitigate now. #CVE #WordPress #infosec
##updated 2026-08-27T12:30:34
2 posts
🟠 CVE-2026-78285 - High (8.5)
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78285/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-78285 - High (8.5)
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78285/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T12:30:27
2 posts
🟠 CVE-2026-81573 - High (8.6)
If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network-
origin restrictions. Commands intended only for local or same-network clients can therefore be executed by
arbitrary r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81573/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81573 - High (8.6)
If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network-
origin restrictions. Commands intended only for local or same-network clients can therefore be executed by
arbitrary r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81573/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T12:30:27
2 posts
🟠 CVE-2026-81277 - High (8.5)
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81277/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81277 - High (8.5)
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81277/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T12:30:27
2 posts
🟠 CVE-2026-81581 - High (8.8)
Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually results in a denial of service, yet we cannot rule o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81581/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81581 - High (8.8)
Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually results in a denial of service, yet we cannot rule o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81581/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T12:30:27
2 posts
🟠 CVE-2026-81579 - High (8.8)
In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be lever...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81579/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81579 - High (8.8)
In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be lever...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81579/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T12:30:27
2 posts
🟠 CVE-2026-81574 - High (8.2)
In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format
specifiers. This can be used to reliably crash CodeMeter and disclose sensitive in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81574/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81574 - High (8.2)
In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format
specifiers. This can be used to reliably crash CodeMeter and disclose sensitive in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81574/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T12:30:26
2 posts
🟠 CVE-2026-81575 - High (7.5)
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and
the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, cau...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81575/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81575 - High (7.5)
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and
the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, cau...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81575/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T06:31:38
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:31:38
3 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
🔴 CVE-2026-80589 - Critical (9.8)
In the Linux kernel, the following vulnerability has been resolved:
block: stop the timeout timer when releasing a never added disk
disk_release() undoes blk_mq_init_allocated_queue() for a disk whose
probe failed before add_disk(), but it only ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80589/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T06:31:37
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:31:37
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:31:37
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:31:37
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:31:33
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:31:33
1 posts
🟠 CVE-2026-80588 - High (7.5)
In the Linux kernel, the following vulnerability has been resolved:
mptcp: reclaim forward-allocated memory on RX path errors
After commit 9db5b3cec4ec ("mptcp: borrow forward memory from subflow"),
errors in the receive path prior to queueing s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80588/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-27T06:31:31
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:17:45.397000
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:17:39.903000
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:17:38.923000
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:17:32.740000
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:17:30.167000
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T06:17:26.440000
2 posts
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
Anyone want 17 new sev:CRIT Linux vulns? Good. Happy Thursday.
https://nvd.nist.gov/vuln/detail/cve-2026-74746
https://nvd.nist.gov/vuln/detail/cve-2026-74737
https://nvd.nist.gov/vuln/detail/cve-2026-74744
https://nvd.nist.gov/vuln/detail/cve-2026-74743
https://nvd.nist.gov/vuln/detail/cve-2026-74752
https://nvd.nist.gov/vuln/detail/cve-2026-80528
https://nvd.nist.gov/vuln/detail/cve-2026-80519
https://nvd.nist.gov/vuln/detail/cve-2026-74751
https://nvd.nist.gov/vuln/detail/cve-2026-80551
https://nvd.nist.gov/vuln/detail/cve-2026-80557
https://nvd.nist.gov/vuln/detail/cve-2026-80561
https://nvd.nist.gov/vuln/detail/cve-2026-80558
https://nvd.nist.gov/vuln/detail/cve-2026-80554
https://nvd.nist.gov/vuln/detail/cve-2026-80587
https://nvd.nist.gov/vuln/detail/cve-2026-80589
https://nvd.nist.gov/vuln/detail/cve-2026-80586
https://nvd.nist.gov/vuln/detail/cve-2026-80585
updated 2026-08-27T04:16:38.863000
4 posts
1 repos
🚨 Executive Risk Brief: CVE-2021-23758 targets Ajax.NET Professional via unsafe deserialization. Leaders must review SBOM asset visibility, regulatory compliance, and financial risk mitigation strategies. Read the full CSUITE brief: https://thecybermind.co/uyx4
##🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2021-23758
Vendor: Ajax.NET Professional
Product: Ajax.NET Professional
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2021-23758
🚨 Critical Threat Intel: CVE-2021-23758 impacts Ajax.NET Professional via unsafe object deserialization, enabling remote code execution. Review exploit deployment mechanisms, process telemetry, and active hardening actions. Read the full TSUITE brief: https://thecycbermind.co/jily
##updated 2026-08-27T04:16:36.600000
3 posts
1 repos
🚨 Executive Risk Brief: CVE-2015-3246 targets Red Hat libuser via authentication race conditions. Leaders must review asset visibility, compliance tracking, and endpoint hardening protocols. Read the full CSUITE brief from The Cyber Mind Co. https://thecybermind.co/7ei4
##🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2015-3246
Vendor: Red Hat
Product: Libuser
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2015-3246
updated 2026-08-27T00:30:36
2 posts
Veeam Patches Critical Authentication Coercion Flaw in Veeam ONE
Veeam released patches for a critical vulnerability (CVE-2026-65641) in Veeam ONE that allows unauthenticated attackers to steal service account NTLM credentials via SMB coercion. The flaw affects version 13 builds and could lead to unauthorized access to backup infrastructure.
**If you're running Veeam ONE version 13.1.0.7034 or any earlier version 13 build, update ASAP to 13.1.0.7233 or 13.0.2.7159. This flaw lets attackers steal your service account credentials without logging in. After updating, review your network logs for any unusual SMB traffic coming from your Veeam servers, as this could indicate the flaw was already exploited.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/veeam-patches-critical-authentication-coercion-flaw-in-veeam-one-6-l-e-u-t/gD2P6Ple2L
Veeam Patches Critical Authentication Coercion Flaw in Veeam ONE
Veeam released patches for a critical vulnerability (CVE-2026-65641) in Veeam ONE that allows unauthenticated attackers to steal service account NTLM credentials via SMB coercion. The flaw affects version 13 builds and could lead to unauthorized access to backup infrastructure.
**If you're running Veeam ONE version 13.1.0.7034 or any earlier version 13 build, update ASAP to 13.1.0.7233 or 13.0.2.7159. This flaw lets attackers steal your service account credentials without logging in. After updating, review your network logs for any unusual SMB traffic coming from your Veeam servers, as this could indicate the flaw was already exploited.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/veeam-patches-critical-authentication-coercion-flaw-in-veeam-one-6-l-e-u-t/gD2P6Ple2L
updated 2026-08-26T22:16:29.717000
1 posts
🟠 CVE-2026-77317 - High (8.1)
SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77317/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T21:31:52
1 posts
🟠 CVE-2026-68863 - High (7.5)
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68863/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T21:31:52
1 posts
🟠 CVE-2026-68861 - High (8.8)
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68861/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T21:31:52
1 posts
🟠 CVE-2026-77652 - High (7.8)
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer.
In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette with:
ren->pPal = g_new0(WPGColorRGB, 256);
When handling ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77652/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T21:31:52
1 posts
🟠 CVE-2026-79938 - High (7.6)
Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79938/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T21:31:47
2 posts
Dell patched 5 Cloud Disaster Recovery flaws. The top bug, CVE-2026-70419 (CVSS 9.1), allows command execution. Update to CDR 20.3 now.
#Dell #CyberSecurity #CVE202670419 #CommandInjection #Infosec
##🔴 CVE-2026-70419 - Critical (9.1)
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-70419/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:05
1 posts
🟠 CVE-2026-81029 - High (8.1)
OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81029/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:05
1 posts
🔴 CVE-2026-80428 - Critical (9.8)
ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resources/shib_logout.php runs in a context that ilInitialisation exempts from authentication, and its lo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80428/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:05
1 posts
🟠 CVE-2026-81036 - High (8.1)
Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81036/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:05
1 posts
🟠 CVE-2026-81035 - High (8.1)
Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the caller with the team-access helper, which returns true for every row in the team-membership table irrespective of the role it...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81035/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:04
3 posts
One Resident Login, an Entire Apartment Complex: The Master PIN in Rently's API (CVE-2026-75960) https://planckdefense.com/blog/rently-master-pin-idor-cve-2026-75960
##One Resident Login, an Entire Apartment Complex: The Master PIN in Rently's API (CVE-2026-75960) https://planckdefense.com/blog/rently-master-pin-idor-cve-2026-75960
##🟠 CVE-2026-75960 - High (8.1)
Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75960/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:04
1 posts
🟠 CVE-2026-15990 - High (7.5)
The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.0.1 via the 'frm_graph' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15990/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:04
1 posts
🟠 CVE-2026-19271 - High (7.5)
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows LDAP Injection.
This issue affects Liderahenk: from 3.4.0 before 3....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19271/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:04
1 posts
🟠 CVE-2026-58474 - High (8.8)
whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename containing...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58474/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:04
1 posts
🔴 CVE-2026-75896 - Critical (9.1)
Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows Try Common or Default Usernames and Passwords.
This issue affects Liderahenk: before 3.5.5.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75896/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:32:04
1 posts
A critical GitLab EE security patch addresses CVE-2026-18252, fixing a command execution flaw. Learn about affected versions, mechanisms, and mitigation.
#GitLab #SecurityPatch #Cybersecurity #CVE202618252
http://securityonline.info/gitlab-ee-security-patch/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-08-26T18:32:03
1 posts
Security Advisory Bulletin 067
Ubiquiti의 Security Advisory Bulletin 067은 UniFi OS 및 Protect·Network·Access·Connect 등 관리 애플리케이션에서 발견된 다수의 치명적 취약점(CVE-2026-77533~77547 등)을 공개했다. 핵심 영향은 네트워크 접근만으로 가능한 명령 주입과 권한 상승이며, 일부 취약점은 낮은 권한 또는 권한 없이도 악용 가능하고 CVSS 9.9~10.0에 이른다. AI 서비스 운영 환경에서 UniFi 게이트웨이·NVR·Cloud Key·NAS 등을 네트워크 경계나 물리 보안, 사내 인프라에...
##updated 2026-08-26T18:31:49
2 posts
Apache Tomcat Patches Critical Security Constraint Bypass Vulnerability
Apache Tomcat addressed a critical vulnerability (CVE-2026-65182) that allows unauthenticated attackers to bypass security restrictions by exploiting path-ordering logic. Administrators should update to the latest versions or remove the examples application to prevent unauthorized access.
**If you run Apache Tomcat (versions 9.0.x, 10.1.x, or 11.0.x), update now to 11.0.25, 10.1.59, or 9.0.121. Note that 10.1.58 has the fix but was never officially released, so don't rely on it. If you can't patch right away, delete the default examples web application and review your security constraint rules so the more restrictive short paths are listed before longer ones.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/apache-tomcat-patches-critical-security-constraint-bypass-vulnerability-z-g-d-l-6/gD2P6Ple2L
Apache Tomcat Patches Critical Security Constraint Bypass Vulnerability
Apache Tomcat addressed a critical vulnerability (CVE-2026-65182) that allows unauthenticated attackers to bypass security restrictions by exploiting path-ordering logic. Administrators should update to the latest versions or remove the examples application to prevent unauthorized access.
**If you run Apache Tomcat (versions 9.0.x, 10.1.x, or 11.0.x), update now to 11.0.25, 10.1.59, or 9.0.121. Note that 10.1.58 has the fix but was never officially released, so don't rely on it. If you can't patch right away, delete the default examples web application and review your security constraint rules so the more restrictive short paths are listed before longer ones.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/apache-tomcat-patches-critical-security-constraint-bypass-vulnerability-z-g-d-l-6/gD2P6Ple2L
updated 2026-08-26T18:31:48
1 posts
📢 [VULN] Chrome : Google vient encore de combler plus de 300 failles - CVE-2026-79282
Google a déployé Chrome 152, une mise à jour qui corrige 327 vulnérabilités, dont dix jugées critiques. Un chercheur surnommé Goodluck reçoit à lui seul 25 000 dollars pour avoir signalé l'une d'entre elles, une faille critique logée dans le moteur graphique ANGLE.
🔗 https://www.clubic.com/actualite-626932-chrome-google-vient-encore-de-combler-plus-de-300-failles.html
💬 discussion : https://infosec.pub/post/51492518
#Vulnérabilité #CVE #Cyberveille
updated 2026-08-26T18:31:36
1 posts
🟠 CVE-2026-74932 - High (7.5)
The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs of the asset files it embeds in the pages it caches, and does not include that header in the cache key, allowing unauthenticated...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74932/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:31:30
3 posts
2 repos
🚨 Executive Risk Brief: CVE-2019-1068 targets Microsoft SQL Server via remote code execution vectors. Leaders must review asset inventory fidelity, least-privilege RBAC, and network segregation. Read the full CSUITE brief from The Cyber Mind Co. https://thecybermind.co/5am3
##🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2019-1068
Vendor: Microsoft
Product: SQL Server
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2019-1068
updated 2026-08-26T18:31:30
3 posts
1 repos
🚨 Executive Risk Brief: CVE-2015-5287 targets Red Hat ABRT via symlink privilege escalation. Leaders must review asset visibility, compliance tracking, and patch management protocols. Read the full CSUITE brief from The Cyber Mind Co. https://thecybermind.co/9pkv
##🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2015-5287
Vendor: Red Hat
Product: Automatic Bug Reporting Tool
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2015-5287
updated 2026-08-26T18:30:34
11 posts
3 repos
https://github.com/derekpreston81/CVE_ADC_IOC_2026
https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452
📰 Public PoC for Critical Citrix NetScaler Pre-Auth RCE Released
A public PoC exploit is now available for a critical pre-auth RCE vulnerability (CVE-2026-8452) in Citrix NetScaler ADC & Gateway. No patch is available yet. Admins should monitor devices closely. #Citrix #RCE #PoC
##CISA urges immediate patching for a critical Citrix NetScaler vulnerability (CVE-2026-8452) actively exploited in the wild. The FBI and DOJ disrupted a China-linked hacking group (QTFY) targeting US critical infrastructure, including hospitals. Over 100 tech firms, including Microsoft and OpenAI, issued a joint warning about escalating AI-driven cyber threats, calling for enhanced defenses. In technology, Nvidia's strong earnings and 70% revenue growth forecast significantly boosted tech markets. Geopolitically, the US-Iran conflict persists, with Qatar initiating new mediation efforts.
##Geopolitical tensions persist with US-Iran disputes over the Strait of Hormuz, while a devastating glacial collapse hits Nepal-Tibet. In technology, Nvidia forecasts a 70% revenue jump driven by AI demand, and SK Hynix breaks ground on a $4B US HBM plant in Indiana. Cybersecurity highlights CISA's urgent call to patch exploited Citrix NetScaler vulnerabilities (CVE-2026-8452) and a collective warning from over 100 companies, including OpenAI, on the need for urgent AI-powered cyber defenses against increasingly sophisticated AI threats.
##CISA Sounds the Alarm: Actively Exploited Citrix NetScaler Flaw Could Give Attackers Root-Level Access + Video
A Critical Warning for Organizations Running NetScaler A vulnerability that initially appeared to be primarily a denial-of-service concern has taken a far more dangerous turn. CISA has added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog after evidence emerged that attackers are exploiting the flaw in the wild. Federal civilian agencies have been…
##🚨 Executive Risk Brief: CVE-2026-8452 targets Citrix NetScaler ADC & Gateway via memory buffer flaws. Leaders must review asset visibility, patch velocity, and risk governance. Read the full CSUITE brief: https://thecybermind.co/zapn
##CISA urges immediate patching for a critical Citrix NetScaler vulnerability (CVE-2026-8452) actively exploited in the wild. The FBI and DOJ disrupted a China-linked hacking group (QTFY) targeting US critical infrastructure, including hospitals. Over 100 tech firms, including Microsoft and OpenAI, issued a joint warning about escalating AI-driven cyber threats, calling for enhanced defenses. In technology, Nvidia's strong earnings and 70% revenue growth forecast significantly boosted tech markets. Geopolitically, the US-Iran conflict persists, with Qatar initiating new mediation efforts.
##Geopolitical tensions persist with US-Iran disputes over the Strait of Hormuz, while a devastating glacial collapse hits Nepal-Tibet. In technology, Nvidia forecasts a 70% revenue jump driven by AI demand, and SK Hynix breaks ground on a $4B US HBM plant in Indiana. Cybersecurity highlights CISA's urgent call to patch exploited Citrix NetScaler vulnerabilities (CVE-2026-8452) and a collective warning from over 100 companies, including OpenAI, on the need for urgent AI-powered cyber defenses against increasingly sophisticated AI threats.
##🚨 Executive Risk Brief: CVE-2026-8452 targets Citrix NetScaler ADC & Gateway via memory buffer flaws. Leaders must review asset visibility, patch velocity, and risk governance. Read the full CSUITE brief: https://thecybermind.co/zapn
##CISA adds six exploited vulnerabilities to its KEV Catalog, including a Citrix NetScaler flaw and CVE-2026-8452, with active exploitation confirmed.
##🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2026-8452
Vendor: Citrix
Product: NetScaler ADC and NetScaler Gateway
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8452
updated 2026-08-26T18:30:28
7 posts
4 repos
https://github.com/Bonfee/CVE-2022-0995
https://github.com/1nzag/CVE-2022-0995
🐧 SIGINT // Linux Watch — 2026-08-28
CVE-2022-0995 (Linux kernel OOB write) joins the KEV list years after disclosure — a reminder that unpatched old bugs don't retire, they just wait for someone to notice they still work.
🔗 https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html
##🚨 Critical Threat Intel: CVE-2022-0995 impacts the Linux kernel watch_queue subsystem via out-of-bounds memory writes, enabling local root privilege escalation. Review IOCs, Splunk/Sentinel queries, and kernel hardening actions: https://thecybermind.co/heaz
##🚨 Executive Risk Brief: CVE-2022-0995 targets the Linux Kernel via an out-of-bounds write flaw enabling privilege escalation. Leaders must review asset visibility, patch cadence, and risk governance. Read the full CSUITE brief: https://thecybermind.co/rzv2
##🚨 Critical Threat Intel: CVE-2022-0995 impacts the Linux kernel watch_queue subsystem via out-of-bounds memory writes, enabling local root privilege escalation. Review IOCs, Splunk/Sentinel queries, and kernel hardening actions: https://thecybermind.co/heaz
##🚨 Executive Risk Brief: CVE-2022-0995 targets the Linux Kernel via an out-of-bounds write flaw enabling privilege escalation. Leaders must review asset visibility, patch cadence, and risk governance. Read the full CSUITE brief: https://thecybermind.co/rzv2
##🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0826)
CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3246 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3246)
- Name: Red Hat Libuser Race Condition Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Libuser
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
⚠️ CVE-2015-5287 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5287)
- Name: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Red Hat
- Product: Automatic Bug Reporting Tool
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5287
⚠️ CVE-2019-1068 (https://secdb.nttzen.cloud/cve/detail/CVE-2019-1068)
- Name: Microsoft SQL Server Remote Code Execution Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: SQL Server
- Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068
⚠️ CVE-2021-23758 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-23758)
- Name: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ajax.NET Professional
- Product: Ajax.NET Professional
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758
⚠️ CVE-2022-0995 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-0995)
- Name: Linux Kernel Out-of-Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Linux
- Product: Kernel
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2022-0995
⚠️ CVE-2026-8452 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8452)
- Name: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler ADC and NetScaler Gateway
- Notes: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-8452
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260826 #cisa20260826 #cve_2015_3246 #cve_2015_5287 #cve_2019_1068 #cve_2021_23758 #cve_2022_0995 #cve_2026_8452 #cve20153246 #cve20155287 #cve20191068 #cve202123758 #cve20220995 #cve20268452
##CVE ID: CVE-2022-0995
Vendor: Linux
Product: Kernel
Date Added: 2026-08-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2022-0995
updated 2026-08-26T18:17:05.890000
1 posts
🔴 CVE-2026-81032 - Critical (9.8)
NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and registers routes for reading and wr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81032/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:17:05.420000
1 posts
🟠 CVE-2026-81027 - High (8.5)
one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a suffix on the API key or through a URL path parameter. The suffix path is reached only after mod...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81027/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T18:16:27.550000
1 posts
🟠 CVE-2026-32258 - High (8.1)
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-32258/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T15:28:48
1 posts
🔴 CVE-2026-54569 - Critical (9.8)
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54569/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T14:28:05
1 posts
🟠 CVE-2026-54511 - High (8.6)
LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStructuredDataValue() function in packages/syslog/src/syslog.ts does not neutralize C0 control characters from U+0000 through U+001F...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54511/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-26T14:21:54
1 posts
🔴 CVE-2026-54523 - Critical (9.6)
Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to invoke gen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54523/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:31:35
1 posts
🟠 CVE-2026-65081 - High (8.1)
NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tamp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65081/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T21:31:34
1 posts
🟠 CVE-2026-80049 - High (8.8)
Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationServerHandler copies recognised identifiers out of the raw JSON request body into X-Airbyte-* headers, and AuthenticationHea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80049/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T20:16:55.720000
1 posts
🔴 CVE-2026-45018 - Critical (9.8)
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45018/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T19:27:32
1 posts
🟠 CVE-2026-55099 - High (7.5)
icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Component equality method in src/icalendar/cal/component.py compares nested subcomponents with two membership loops, and each membe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55099/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-25T18:32:01
1 posts
1 repos
https://github.com/HORKimhab/CVE-2026-19912-CVE-2026-19913-CVE-2026-19914
Two unpatched vulnerabilities in Kaltura's mwEmbed HTML5 player library (html5lib) allow unauthenticated file read and remote code execution via insecure deserialization in mwEmbedLoader.php. CVE-2026-19913 and CVE-2026-19912 affect any exposed instance with no auth or tokens required. No vendor patch exists yet.
#Kaltura #VulnerabilityManagement #RCE #CERTCC
https://cyberworldops.eu/en/unpatched-kaltura-player-vulnerabilities-expose-files-and-allow-code
##updated 2026-08-25T18:32:01
1 posts
1 repos
https://github.com/HORKimhab/CVE-2026-19912-CVE-2026-19913-CVE-2026-19914
Two unpatched vulnerabilities in Kaltura's mwEmbed HTML5 player library (html5lib) allow unauthenticated file read and remote code execution via insecure deserialization in mwEmbedLoader.php. CVE-2026-19913 and CVE-2026-19912 affect any exposed instance with no auth or tokens required. No vendor patch exists yet.
#Kaltura #VulnerabilityManagement #RCE #CERTCC
https://cyberworldops.eu/en/unpatched-kaltura-player-vulnerabilities-expose-files-and-allow-code
##updated 2026-08-25T16:08:43.290000
2 posts
2 repos
⚪️ Microsoft Patches a Critical Entra ID Vulnerability Scoring 10 on the CVSS Scale
🗨️ Microsoft has fixed five critical vulnerabilities in the Entra ID, Azure Arc, Exchange Online, and Azure Managed Instance for Apache Cassandra cloud services. The most severe issue, tracked as CVE-2026-69836, received the maximum possible CVSS score of 10.0 out of…
##🏆 New Achievement! Serialized, Unsanitized, Unauthorized!
Per my programming, I have located the most efficient path to arbitrary code execution on your network and executed it faithfully. CVE-2026-69836 in Microsoft Entra ID — the thing authenticating your Microsoft 365, Azure, and frankly embarrassing number of third-party apps — accepts specially crafted serialized data and runs whatever is inside. No credentials needed. No user to click anything. (1/2)
##updated 2026-08-25T04:18:11.067000
1 posts
10 repos
https://github.com/gglessner/cve_2026_21962_scanner
https://github.com/gregk4sec/cve-2026-21962
https://github.com/0xBlackash/CVE-2026-21962
https://github.com/gregk4sec/CVE-2026-21962-o
https://github.com/boroeurnprach/Ashwesker-CVE-2026-21962
https://github.com/zeetee1235/CVE-2026-21962
https://github.com/naozibuhao/CVE-2026-21962_Java_GUI_Exploit_Tool
Oracle Sicherheitsloch von Januar wird angegriffen!
Vor einem Monat hatte Oracle einen riesigen Haufen Sicherheitslücken geflickt. Aber um gefährdet zu sein, braucht man keine frischen Sicherheitslücken. Es reicht auch, Updates nicht zu installieren. Die CISA hat die Sicherheitslücke CVE-2026-21962 (Risiko 10 von 10) in Oracle-Software, gegen die im Januar bereits ein Update veröffentlicht wurde, am 2026-08-24 in den Katalog der als ausgenutzt bekannten Sicherheitslücken (KEV) aufgenommen. Die US-Behörden wurden angewiesen, das Update nunmehr binnen drei Tagen einzuspielen. Ab heute müssten also Angriffe auf diese Lücke in Leere laufen. ;-)
#cybercrime #exploits #sicherheit #UnplugOracle #UnplugTrump
##updated 2026-08-24T20:16:42.277000
1 posts
1 repos
📢 CVE-2026-19874 : Heap overflow dans Metal Gear Online 3 permettant une RCE via les lobbies Steam
Le CERT/CC (Carnegie Mellon University) a publié le 2026-08-24 la note de vulnérabilité VU#728712 concernant le jeu en ligne Metal Gear Online 3 de Konami (Steam AppID 287700). La vulnérabilité a été rapportée par Alice Cecchetto et documentée par Bob Kemerer.
📖 cyberveille : https://cyberveille.ch/posts/2026-08-26-cve-2026-19874-heap-overflow-dans-metal-gear-online-3-permettant-une-rce-via-les-lobbies-steam/
🌐 source : https://kb.cert.org/vuls/id/728712
🟢 vérification factuelle haute
#RCE #Steam #Cyberveille
updated 2026-08-24T13:19:17.577000
2 posts
6 repos
https://github.com/HORKimhab/CVE-2026-73570
https://github.com/BiuTrap/CVE-2026-73570
https://github.com/gabrielunknown/CVE-2026-73570
https://github.com/INFOKOM-KI/Zimbra-CVE-2026-73570-Rules
https://bugstoday.com/zimbra-servers-are-being-hacked-in-a-new-wave-of-cve-2026-73570-attacks/
#Cybersecurity #InfoSec #CVE #Vulnerability #Security #CyberAttack #Exploit #Malware #Ransomware
##Zimbra : plus de 270 serveurs de messagerie compromis grâce à la faille CVE-2026-73570 https://www.it-connect.fr/zimbra-cve-2026-73570-serveurs-compromis/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
##updated 2026-08-22T04:17:58.720000
1 posts
4 repos
https://github.com/suominen/ovswrap
https://github.com/0xBlackash/CVE-2026-64531
https://github.com/HackSpeak/CVE-2026-64531
https://github.com/mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool
🐧 SIGINT // Ubuntu Watch — 2026-08-29
Big batch of kernel CVEs including CVE-2026-64531 across multiple subsystems. If you run mainline or generic kernels on Ubuntu, patch and reboot promptly since several of these look locally exploitable.
##updated 2026-08-21T15:32:18
1 posts
1 repos
📢 ⚠️[VULN] Mise à jour critique de sécurité : sortie de SPIP 4.4.21- CVE-2026-77806
La version 4.4.21 corrige une faille de sécurité signalée anonymement via l’ANSSI. Cette version corrige une vulnérabilité universelle (sans conditions) pré-authentification RCE qui touche la version 4.4.20 de SPIP. Cette faille n’est pas prise en charge par l’écran de sécurité.
🔗 https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-21.html
💬 discussion : https://infosec.pub/post/51532987
#Vulnérabilité #CVE #Cyberveille
updated 2026-08-20T04:16:56.450000
1 posts
2 repos
⚠️ CRITICAL: CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days
CVE-2026-69414 ShieldBreak is a zero-day privilege escalation in Microsoft Malware Protection Engine affecting Microsoft Defender. A public PoC exists and no patch is available. Any low-privilege attacker on Windows systems running Defender can escalate to SYSTEM.
🤖 AI generated summary
##updated 2026-08-19T21:30:46
2 posts
Weak bcrypt hashes in Rockwell Automation OTTO Fleet Manager (CVE-2026-75112) reduce the computational cost of offline brute-force attacks against stored credentials. The flaw affects OT fleet management software in industrial environments. Patch and rotate passwords.
#CWE916 #OTSecurity #RockwellAdvisory #ICSAdvisory
https://cyberworldops.eu/en/rockwell-automation-otto-fleet-manager-weak-bcrypt-hashes-put
##Weak bcrypt hashes in Rockwell Automation OTTO Fleet Manager (CVE-2026-75112) reduce the computational cost of offline brute-force attacks against stored credentials. The flaw affects OT fleet management software in industrial environments. Patch and rotate passwords.
#CWE916 #OTSecurity #RockwellAdvisory #ICSAdvisory
https://cyberworldops.eu/en/rockwell-automation-otto-fleet-manager-weak-bcrypt-hashes-put
##updated 2026-08-19T18:31:59
1 posts
1 repos
A public PoC for CVE-2026-53361 turns an AF_UNIX kernel race into a local container escape on Linux.
#CVE202653361 #ContainerEscape #LinuxKernel #AFUNIX #UseAfterFree #KernelExploit
##updated 2026-08-19T04:17:34.547000
3 posts
3 repos
https://github.com/acheong08/CVE-2026-65400
An AI agent built a working exploit for this macOS flaw in four hours https://thenextweb.com/news/macos-screen-sharing-flaw-cve-2026-65400-monero-miner
##⚠️💻 Mac flaw exploited
CVE-2026-65400 gives root access on exposed Macs; attackers deploy #Monero miners.
##An AI agent built a working exploit for this macOS flaw in four hours https://thenextweb.com/news/macos-screen-sharing-flaw-cve-2026-65400-monero-miner
##updated 2026-08-18T14:57:10.630000
2 posts
7 repos
https://github.com/punitdarji/Gitlab-CVE-2026-19478
https://github.com/davkharrr/CVE-2026-19478-PoC
https://github.com/n0xdaemon/cve-2026-19478
https://github.com/renzi25031469/CVE-2026-19478
https://github.com/EQSTLab/CVE-2026-19478
⚪️ Hackers Are Already Exploiting a Critical GitLab Vulnerability
🗨️ Researchers at watchTowr reported that hackers have begun exploiting the critical GitLab vulnerability CVE-2026-19478 in real-world attacks, just days after the bug was disclosed. Last week, GitLab developers released emergency patches for Community Edition (CE) and Enterprise Edition (EE) that…
##⚪️ Hackers Are Already Exploiting a Critical GitLab Vulnerability
🗨️ Researchers at watchTowr reported that hackers have begun exploiting the critical GitLab vulnerability CVE-2026-19478 in real-world attacks, just days after the bug was disclosed. Last week, GitLab developers released emergency patches for Community Edition (CE) and Enterprise Edition (EE) that…
##updated 2026-08-17T06:18:13.583000
5 posts
Le kernel #Linux avait déjà free().
Avec CVE-2026-72137, il propose maintenant le double free. :apartyblobcat: :neocat_floof_explode:
Et CyberMeowfia (nebusec.ai) vient de publier le PoC « root inclus » pour #Ubuntu 7.0.0-28.
⬇️
LPE exploit for the latest Ubuntu 26.04 ( https://lnkd.in/p/eYP7_A2g ) 👀
👇
https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-72137-ubuntu-7.0.0-28
Bref, si ce kernel traîne chez vous : patcher avant que quelqu’un ne profite de la promo 2 pour 1.
🔍 :debian:
👇
https://vulnerability.circl.lu/vuln/CVE-2026-72137
Another Linux (Ubuntu) LPE https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-72137-ubuntu-7.0.0-28
##Le kernel #Linux avait déjà free().
Avec CVE-2026-72137, il propose maintenant le double free. :apartyblobcat: :neocat_floof_explode:
Et CyberMeowfia (nebusec.ai) vient de publier le PoC « root inclus » pour #Ubuntu 7.0.0-28.
⬇️
LPE exploit for the latest Ubuntu 26.04 ( https://lnkd.in/p/eYP7_A2g ) 👀
👇
https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-72137-ubuntu-7.0.0-28
Bref, si ce kernel traîne chez vous : patcher avant que quelqu’un ne profite de la promo 2 pour 1.
🔍 :debian:
👇
https://vulnerability.circl.lu/vuln/CVE-2026-72137
Another Linux (Ubuntu) LPE https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-72137-ubuntu-7.0.0-28
##A public PoC exploit targets CVE-2026-72137, a CVSS 9.8 Linux kernel double-free that enables root privilege escalation. Patch now.
#CVE202672137 #LinuxKernel #PrivilegeEscalation #PoC #xfrm #InfoSec
##updated 2026-08-15T18:31:24
1 posts
4 repos
https://github.com/sag-asab/CVE-2026-19598
https://github.com/HackfutSecRoot/multi_exploit_wp
Wordfence found CVE-2026-19598, a critical unauthenticated flaw in the Pods WordPress plugin (100,000+ installs) letting attackers reset any password, including the admin's.
#PodsPlugin #CVE202619598 #WordPress #Wordfence #PrivilegeEscalation
##updated 2026-08-12T15:16:54
1 posts
🟠 CVE-2026-46369 - High (7.5)
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound comparison that expires a stored transaction too early relative to Transact...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46369/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-12T14:40:23
1 posts
🟠 CVE-2026-32257 - High (8.1)
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compile...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-32257/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-11T18:31:34
2 posts
1 repos
📢 [VULN] Une vulnérabilité Exchange à patcher d'urgence CVE-2026-62911
Le 11 août dernier, Microsoft dévoilait son patch tuesday le plus volumineux, avec des correctifs pour rien moins que 421 vulnérabilités, dont 7 pour Exchange. L'une d'entre elles, la CVE-2026-62911, est une vulnérabilité critique d'élévation de privilèges présentant un score CVSS de 8,0.
🔗 https://www.lemagit.fr/actualites/366649756/Une-vulnerabilite-Exchange-a-patcher-durgence
💬 discussion : https://infosec.pub/post/51497197
#Vulnérabilité #CVE #Cyberveille
Pre-auth RCE on Exchange PoC https://github.com/hypnguyen1209/cve-2026-62911
##updated 2026-08-05T18:32:31
3 posts
4 repos
https://github.com/sfewer-r7/CVE-2026-63077
https://github.com/AnggaTechI/CVE-2026-63077
https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation
https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap
Security Incident Affecting JetBrains Cadence
JetBrains의 PyCharm 연동 클라우드 실행 서비스 Cadence가 TeamCity의 치명적 원격 명령 실행 취약점(CVE-2026-63077)을 통해 침해됐으며, 공격자는 2026년 8월 8일부터 24일까지 환경에 무단 접근했습니다. Cadence 실행에 사용됐거나 프로젝트 파일·2024년 서버 백업에 존재한 클라우드 IAM 자격 증명, 소스 제어 토큰, 패키지·컨테이너 레지스트리 토큰, SSH 키 및 소스 코드가 유출됐을 가능성이 있습니다. Cadence 사용자는 모든 관련 시크릿을 즉시 폐기·교체하고 AWS/GCP/Azure IAM, S3...
https://blog.jetbrains.com/pycharm/2026/08/cadence-security-incident-august-2026/
##CVE-2026-63077 has been flagged by both Australia's ACSC and CISA's Known Exploited Vulnerabilities catalog since August 5, meaning threat actors already found it on the shelf before you did.
No specific sector is being targeted. Everyone's invited. The ACSC recommends you urgently audit your network for vulnerable TeamCity On-Premises versions and apply available patches immediately. (2/3)
##CVE-2026-63077 has been flagged by both Australia's ACSC and CISA's Known Exploited Vulnerabilities catalog since August 5, meaning threat actors already found it on the shelf before you did.
No specific sector is being targeted. Everyone's invited. The ACSC recommends you urgently audit your network for vulnerable TeamCity On-Premises versions and apply available patches immediately. (2/3)
##updated 2026-07-17T15:33:27
1 posts
2 repos
BYOVD with a twist: ardrv.sys from OPSWAT AppRemover (CVE-2026-36425) is signed and built to terminate security agents, so kernel process kill is native functionality, not a groomed memory-corruption primitive. Delivery: Inno...
##updated 2026-06-17T01:47:21.423000
2 posts
@kirschner Western Digital did something like this with their My Book Live NAS drives. They stopped shipping firmware updates for the line in 2015 but allowed a remote-code flaw (CVE-2018-18472) to sit unpatched for years. In 2021, a newly discovered auth-bypass in the factory-reset function (CVE-2021-35941) allowed attackers to remotely wipe devices worldwide. Owners opened the app to find empty folders.
##@kirschner Western Digital did something like this with their My Book Live NAS drives. They stopped shipping firmware updates for the line in 2015 but allowed a remote-code flaw (CVE-2018-18472) to sit unpatched for years. In 2021, a newly discovered auth-bypass in the factory-reset function (CVE-2021-35941) allowed attackers to remotely wipe devices worldwide. Owners opened the app to find empty folders.
##updated 2026-05-12T15:31:15
1 posts
"This issue was reported on 13th February 2026 by Nathan Sportsman
(Praetorian), on 25th February 2026 by Daniel Rhea, on 15th March 2026
by Jaeho Nam (Seoul National University), on 26th March 2026 by
Muhammad Daffa, on 27th March 2026 by Zhanpeng Liu (Tencent Xuanwu Lab),
Guannan Wang (Tencent Xuanwu Lab) and Guancheng Li (Tencent Xuanwu Lab)
and on 30th March 2026 by Joshua Rogers (Aisle Research)."
It's really anybody who bothers to look these days. (This one is #OpenSSL CVE-2026-28389)
##updated 2025-04-28T09:32:00
1 posts
If you are running Avada, patch it now. CVE-2025-39367 allows a complete stranger to execute code on your site with no account and no password required. Avada is ThemeForest's best-selling theme, which makes the attack surface enormous. This one is as serious as it gets.
#WordPress #WordPressSecurity #Avada #SecurityHardening #WebSecurity
https://wpguy.uk/blog/avada-rce-vulnerability-patch-now-or-risk-full-takeover/
##updated 2024-09-17T03:30:44
1 posts
2 repos
⚠️ CRITICAL: CISA Warns Agencies to Patch Actively Exploited Oracle WebLogic Proxy Flaw
Oracle WebLogic Server CVE-2023-21931 is being actively exploited in the wild, allowing unauthenticated attackers to read or modify sensitive data. Federal agencies are mandated to patch by August 27, 2024. Any organization running unpatched WebLogic instances is at immediate risk of compromise.
🤖 AI generated summary
##updated 2023-01-27T05:02:51
2 posts
@kirschner Western Digital did something like this with their My Book Live NAS drives. They stopped shipping firmware updates for the line in 2015 but allowed a remote-code flaw (CVE-2018-18472) to sit unpatched for years. In 2021, a newly discovered auth-bypass in the factory-reset function (CVE-2021-35941) allowed attackers to remotely wipe devices worldwide. Owners opened the app to find empty folders.
##@kirschner Western Digital did something like this with their My Book Live NAS drives. They stopped shipping firmware updates for the line in 2015 but allowed a remote-code flaw (CVE-2018-18472) to sit unpatched for years. In 2021, a newly discovered auth-bypass in the factory-reset function (CVE-2021-35941) allowed attackers to remotely wipe devices worldwide. Owners opened the app to find empty folders.
##⚠️ CRITICAL: Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
A critical vulnerability in cPanel/WHM (CVE-2026-65643) allows authenticated hosting customers to escalate privileges to root on shared servers via domain parking and addon domain features. Any customer account can exploit this to achieve full server compromise. If your infrastructure runs cPanel/W…
🤖 AI generated summary
##📰 Critical cPanel Flaw Allows Hosting Customers to Gain Root Access
Critical cPanel vulnerability (CVE-2026-65643) allows any authenticated user to gain full root access on shared hosting servers by abusing the domain parking feature. Patches are available and must be applied immediately. #cPanel #Vulnerability #Cybe...
##cPanel Flaw Enables Root Code Execution via Domain Functionality
A critical cPanel security flaw, tracked as CVE-2026-65643, allows attackers to execute code as the root user, giving them full control of the server, by exploiting domain parking and addon domain functionality. This vulnerability impacts all supported versions of cPanel & WHM and can be triggered by an authenticated account holder.
#Cpanel #Cve202665643 #RootCodeExecution #WebHosting #SupplyChain
##⚠️ CRITICAL: Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
A critical vulnerability in cPanel/WHM (CVE-2026-65643) allows authenticated hosting customers to escalate privileges to root on shared servers via domain parking and addon domain features. Any customer account can exploit this to achieve full server compromise. If your infrastructure runs cPanel/W…
🤖 AI generated summary
##1 posts
1 repos
https://github.com/investigato/CVE-2026-76060_ZoneMinder_CommandInjection-PoC
🟠 New security advisory:
CVE-2026-76060 affects multiple systems.
• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-76060-zoneminder-rce-via-event-export-poc
by Yazoul AI
##11 posts
9 repos
https://github.com/EQSTLab/CVE-2026-60004
https://github.com/Sachinart/CVE-2026-60004-gitea-0day
https://github.com/0xBlackash/CVE-2026-60004
https://github.com/HackSpeak/CVE-2026-60004
https://github.com/HORKimhab/CVE-2026-60004
https://github.com/imbas007/CVE-2026-60004-POC
https://github.com/fevar54/cve-2026-60004
Over 8,300 Gitea Servers Remain Exposed to Critical Remote Code Execution Attacks + Video
A New Gitea Security Crisis Is Growing A critical vulnerability in the self-hosted Gitea Git service has become an urgent cybersecurity concern after researchers reported that more than 8,300 Internet-exposed Gitea servers remain vulnerable to active remote code execution attacks. The flaw, tracked as CVE-2026-60004, carries a CVSS score of 9.8, placing it firmly in the critical…
##Over 8,300 Gitea servers vulnerable to code execution attacks
Gitea의 diffpatch API 코드 인젝션 취약점(CVE-2026-60004)이 실제 공격에 악용되고 있으며, 인터넷에 노출된 약 8,393개 인스턴스가 아직 취약한 상태다. 저장소 쓰기 권한이 필요하지만 기본 설정에서 자체 회원가입이 활성화돼 있어 공격자는 계정을 만들고 저장소를 생성한 뒤 Gitea 서비스 계정 권한으로 임의 셸 명령을 실행할 수 있다. Gitea는 1.27.1에서 수정했으며, CISA는 이미 악용 중인 취약점 목록에 추가했고 미패치 서버에서는 암호...
##📢 [VULN] CVE-2026-60004 : RCE critique de Gitea exploitée pour déployer des charges utiles semblables à des mineurs | SOC Prime
Une vulnérabilité critique d’exécution de code à distance dans Gitea est passée de la divulgation à une exploitation active moins d’un mois après qu’un correctif est devenu disponible.
🔗 https://socprime.com/fr/blog/cve-2026-60004-rce-critique-de-gitea-exploitee-pour-deployer-des-charges-utiles-semblables-a-des-mineurs/
💬 discussion : https://infosec.pub/post/51545700
#Vulnérabilité #CVE #Cyberveille
Gitea Servers Exposed to Ongoing Code Execution Attacks
Thousands of Gitea servers remain vulnerable to code execution attacks, with 8393 Internet-exposed IPs still susceptible to CVE-2026-60004, a code injection bug that lets attackers execute arbitrary shell commands. This flaw can be easily exploited by anyone with write access to a repository, which is especially concerning since Gitea enables…
#Cve202660004 #CodeExecution #Gitea #SupplyChain #EmergingThreats
##https://bugstoday.com/gitea-cve-2026-60004-is-now-actively-exploited-attackers-deploy-cryptominers/
#Cybersecurity #InfoSec #CVE #Vulnerability #Security #CyberAttack #Exploit #Malware #Ransomware
##🔴 CVE-2026-60004 - Critical (9.8)
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-60004/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##⚠️ CRITICAL: Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
Gitea instances are under active attack for CVE-2026-60004, a critical RCE flaw (CVSS 9.8) that allows unauthenticated account creation to trigger arbitrary command execution. Attackers are deploying miner-like payloads. Any organization running Gitea with default open registration is at immediate…
🤖 AI generated summary
##CISA Reports Actively Exploited Gitea Critical RCE Vulnerability
Gitea patched a critical remote code execution vulnerability (CVE-2026-60004) that attackers are actively exploiting to install crypto-miners on self-hosted instances. The flaw allows users with write access to inject malicious Git hooks via the diffpatch API, potentially exposing database credentials and system secrets.
**Update self-hosted Gitea instances to version 1.27.1 immediately. Now it's urgent, since hackers are actively attacking you. If you can't patch right away, disable public registration to prevent new outsiders from obtaining repository write access. This does not protect against existing users who already have the required permissions.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisa-reports-actively-exploited-gitea-critical-rce-vulnerability-2-1-9-j-5/gD2P6Ple2L
CISA has listed CVE-2026-60004 in the KEV Catalog. Critical RCE in Gitea actively exploited via malicious patches submitted through the diff API endpoint. Attackers achieve code injection on self-hosted instances and deploy cryptominers on compromised servers. Patch by August 28 is mandatory.
#CriticalRCE #GiteaVulnerability #Cryptojacking #CISAKEV
https://cyberworldops.eu/en/gitea-under-attack-critical-rce-exploited-for-cryptojacking-cisa
##🏆 New Achievement! Hook, Line, and Git Hooked!
And here, in its natural habitat, we observe the self-hosted Git server — a creature believed by its keepers to be safely tucked away, far from predators. CVE-2026-60004 tells a different story. An attacker with mere repository write access may deliver a malicious patch to Gitea's diffpatch API endpoint, planting an executable Git hook and inheriting the Gitea service account like a cuckoo claiming another bird's nest. (1/2)
##CISA has added CVE-2026-60004 to the KEV catalog. The vulnerability in Gitea, a self-hosted Git service, has been exploited in the wild to achieve remote code execution and install cryptocurrency miners on compromised instances. FCEB agencies face a remediation deadline of August 28, 2026.
#KnownExploitedVulnerabilities #RemoteCodeExecution #Gitea #CISA
https://cyberworldops.eu/en/cisa-adds-gitea-vulnerability-to-kev-catalog-exploited-to-execute-code
##Discover the details of recent MongoDB security vulnerabilities affecting drivers and BI connectors. Update your systems to patch CVE-2026-81525 and others.
#MongoDB #Cybersecurity #Vulnerability #CVE202681525 #DatabaseSecurity
##🟠 CVE-2026-81525 - High (8.1)
The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application that incorporates untruste...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81525/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Discover the details of recent MongoDB security vulnerabilities affecting drivers and BI connectors. Update your systems to patch CVE-2026-81525 and others.
#MongoDB #Cybersecurity #Vulnerability #CVE202681525 #DatabaseSecurity
##🟠 CVE-2026-81525 - High (8.1)
The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application that incorporates untruste...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81525/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##6 posts
3 repos
https://github.com/e4zyy/Project-CVE-2026-75604
📢 [VULN] Next.js : deux failles critiques permettent une exécution de code à distance sans authentification - CVE-2026-75604
Le 25 août 2026, Vercel a publié plusieurs nouvelles versions de Next.js : 15.5.24 et 16.3.3. L'objectif ? Patcher deux failles critiques permettant toutes les deux une exécution de code à distance sans authentification. Voici l'essentiel à savoir sur ces failles.
🔗 https://www.it-connect.fr/nextjs-failles-critiques-avif-windows-rce/
💬 discussion : https://infosec.pub/post/51535270
#CVE #Cyberveille
Next.js Patches Flaws Enabling Unauthenticated Remote Code Execution
If your Next.js application is hosted on Windows, upgrade immediately to patch a critical vulnerability that allows unauthenticated remote code execution. This flaw, tracked as CVE-2026-75604, affects apps using both Pages Router and App Router without Cache Components.
#Nextjs #Cve202675604 #RemoteCodeExecution #PathTraversal #Windows
##https://thecybersecguru.com/news/nextjs-rce-avif-libheif-cve-2026-75604/
##Next.js Windows RCE PoC https://github.com/rafabd1/CVE-2026-75604-poc
##https://thecybersecguru.com/news/nextjs-rce-avif-libheif-cve-2026-75604/
##Next.js Windows RCE PoC https://github.com/rafabd1/CVE-2026-75604-poc
##🔴 CVE-2026-61800 - Critical (9.1)
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/oss...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61800/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-61800 - Critical (9.1)
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/oss...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61800/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-81529 - Connection-option injection in MongoDB C# Driver allows security control bypass. CVSS 7.1. Audit code and sanitize inputs now. #CVE #MongoDB #infosec
##🟠 CVE-2026-77438 - High (7.5)
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public share-search endpoint does not enforce the per-note shareCredentials and shareHiddenFromTree controls, allowing an unauthenticated ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77438/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77438 - High (7.5)
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public share-search endpoint does not enforce the per-note shareCredentials and shareHiddenFromTree controls, allowing an unauthenticated ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77438/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81522 - High (8.1)
A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace identifier from untrusted input without validating it may ther...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81522/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-81522 - High (8.1)
A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace identifier from untrusted input without validating it may ther...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81522/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-66155 - High (7.6)
A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66155/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-66155 - High (7.6)
A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66155/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-47665 - Stored XSS in Penpot design platform via file comments. CVSS 8.7. Restrict comment access and monitor for patches. #CVE #Penpot #cybersecurity
##🟠 CVE-2026-47665 - High (8.7)
Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as raw text and rendered into the page with innerH...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47665/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##LazyOwn RedTeam Framework Patches Critical Default Credential Vulnerability
LazyOwn RedTeam/APT Framework patched a critical vulnerability (CVE-2026-68503) that allows attackers to gain full administrative control over C2 dashboards using hardcoded default credentials. The flaw enables unauthorized users to hijack red-team campaigns, issue commands to beacons, and access exfiltrated data.
**If you run the LazyOwn RedTeam/APT framework, update it to version 0.2.154 or later ASAP. Older versions ship with default usernames and passwords that let anyone take over your C2 dashboard. If you can't update yet, change the `c2_user` and `c2_pass` values in your `payload.json` to unique strong passwords and put the dashboard behind a firewall so only trusted networks can reach it.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/lazyown-redteam-framework-patches-critical-default-credential-vulnerability-k-h-i-x-v/gD2P6Ple2L
TeamViewer patched CVE-2026-19042, a Linux command injection flaw, and a path traversal bug. Both TeamViewer vulnerabilities enable code execution.
#TeamViewer #CommandInjection #CVE202619042 #PathTraversal #RCE #InfoSec
##🟠 CVE-2026-47666 - High (7.6)
Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font family names, which are interpolated into a @font-face CSS rule and injected ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47666/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61617 - High (7.7)
Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61617/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-77368 - High (7.6)
SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a session is created, letting a low-privilege tenant hijack another tenant's upl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77368/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-80427 - High (8.4)
bestzip builds the argument list for the system zip utility without separating options from operands. The destination archive path and the caller-supplied source paths are passed to the child process with no -- delimiter between them, so any sourc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80427/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61792 - High (7.7)
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resol...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61792/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-78379 - High (8.1)
Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78379/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##