## Updated at UTC 2026-09-24T12:07:40.683860

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-12227 9.8 0.00% 2 0 2026-09-24T10:17:32.623000 The Visual Composer Website Builder plugin for WordPress is vulnerable to Local
CVE-2026-78308 9.8 0.00% 2 0 2026-09-24T09:32:00 Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass
CVE-2026-84502 9.9 0.00% 1 0 2026-09-24T06:31:14 A flaw was found in Red Hat Ansible Automation Platform's automation- controller
CVE-2026-19599 9.9 0.00% 2 0 2026-09-24T04:17:48.027000 ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable
CVE-2026-18467 9.8 0.00% 4 0 2026-09-24T03:30:34 The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable
CVE-2026-96891 9.8 0.00% 2 0 2026-09-24T03:16:58.950000 A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the functi
CVE-2026-97055 8.1 0.00% 2 0 2026-09-24T02:16:54.333000 SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (to
CVE-2026-70125 8.8 0.00% 2 0 2026-09-24T00:30:34 Microsoft Outlook Remote Code Execution Vulnerability
CVE-2026-19125 8.1 0.00% 2 1 2026-09-24T00:30:29 The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication B
CVE-2026-81536 7.7 0.00% 2 0 2026-09-24T00:30:29 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-81208 7.7 0.00% 2 0 2026-09-24T00:30:29 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to
CVE-2026-86583 8.8 0.00% 2 0 2026-09-24T00:30:29 The Import and export users and customers plugin for WordPress is vulnerable to
CVE-2026-75887 7.5 0.00% 2 0 2026-09-24T00:30:26 A flaw was found in the OpenShift console. An unauthenticated attacker can explo
CVE-2026-93577 9.9 0.00% 3 0 2026-09-24T00:17:22.850000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2
CVE-2026-89078 9.9 0.00% 1 0 2026-09-24T00:17:22.060000 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2
CVE-2026-93352 9.8 0.00% 4 0 2026-09-23T22:16:59.523000 Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49
CVE-2026-81537 8.8 0.00% 2 0 2026-09-23T22:16:57.690000 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-80423 8.8 0.00% 2 0 2026-09-23T22:16:57.270000 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-6928 9.8 0.00% 2 0 2026-09-23T21:31:08 IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been
CVE-2026-87899 None 0.00% 2 0 2026-09-23T21:31:03 Execution with unnecessary privileges in cPanel allows remote authenticated user
CVE-2026-68490 None 0.00% 1 0 2026-09-23T21:30:56 Incorrect permission assignment allows local users to obtain sensitive CalDAV/Ca
CVE-2026-6730 9.8 0.00% 2 0 2026-09-23T21:17:02.053000 IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by im
CVE-2026-88020 6.1 0.27% 1 0 2026-09-23T19:42:48.540000 Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input d
CVE-2026-19202 0 0.23% 1 0 2026-09-23T19:42:48.540000 A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK cau
CVE-2026-49881 7.8 0.11% 1 2 2026-09-23T19:23:28.350000 In serviceClassExists of InCallController.java, there is a possible arbitrary co
CVE-2026-18162 9.8 0.86% 2 0 2026-09-23T19:17:28.687000 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remot
CVE-2026-73512 7.5 0.83% 1 0 2026-09-23T18:43:37.403000 Envoy is an open source edge and service proxy designed for cloud-native applica
CVE-2026-73547 7.5 0.83% 1 0 2026-09-23T18:21:42.327000 Envoy is an open source edge and service proxy designed for cloud-native applica
CVE-2026-18169 9.9 0.78% 1 0 2026-09-23T18:17:07.270000 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remot
CVE-2026-63447 7.5 0.36% 1 0 2026-09-23T18:12:04.247000 Suricata is a network Intrusion Detection System, Intrusion Prevention System an
CVE-2026-91809 7.8 0.17% 1 0 2026-09-23T17:58:26.570000 A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of m
CVE-2026-91818 7.8 0.17% 1 0 2026-09-23T17:58:26.570000 A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript ha
CVE-2026-83621 8.1 0.29% 1 0 2026-09-23T17:17:50.090000 ntopng is a web-based network traffic monitoring application. Prior to 6.7.26071
CVE-2026-93616 9.8 2.42% 15 2 2026-09-23T16:38:38.987000 A directory traversal and file upload vulnerability allows an unauthenticated at
CVE-2026-77987 0 0.89% 1 0 2026-09-23T16:16:45.047000 A server-side request forgery (SSRF) vulnerability was identified in the noteboo
CVE-2026-96257 10.0 1.04% 1 0 2026-09-23T15:17:31.920000 A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this i
CVE-2026-93952 10.0 0.74% 11 0 2026-09-23T14:32:12.417000 VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may a
CVE-2026-94127 9.8 1.39% 16 1 2026-09-23T14:32:07.910000 When a BIG-IP APM access policy and an OAuth profile are configured on a virtual
CVE-2026-91811 7.8 0.17% 1 0 2026-09-23T09:30:37 A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader
CVE-2026-74849 9.8 4.46% 1 0 2026-09-23T04:17:44.340000 Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerab
CVE-2026-32996 0 0.16% 3 1 2026-09-23T04:17:43.927000 This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privile
CVE-2026-18163 9.8 0.81% 2 0 2026-09-23T00:31:21 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remot
CVE-2026-28324 9.8 0.65% 2 0 2026-09-22T21:31:34 SolarWinds Observability Self-Hosted was found to be affected by an unauthentica
CVE-2026-87121 9.8 0.78% 2 0 2026-09-22T21:31:34 lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow
CVE-2026-85102 9.8 0.66% 15 0 2026-09-22T21:30:40 Improper certificate trust validation during VPN negotiation in Check Point Quan
CVE-2026-94411 8.8 0.28% 1 0 2026-09-22T20:43:58.793000 jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueBy
CVE-2026-94497 8.3 0.26% 1 0 2026-09-22T20:43:58.793000 jshERP through 3.6 fails to validate object ownership in by-id info, update, and
CVE-2026-77560 8.1 0.33% 1 0 2026-09-22T20:37:12 # tinyauth: forward-auth per-app ACL is matched case-sensitively against the (ca
CVE-2026-77322 7.5 0.61% 1 0 2026-09-22T20:34:31 ### Summary The WebSocket transport allocates a buffer from the frame payload l
CVE-2026-93345 7.5 0.49% 1 0 2026-09-22T20:25:55.870000 MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnera
CVE-2026-94626 7.5 0.45% 1 0 2026-09-22T20:25:55.870000 vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_param
CVE-2026-94624 7.5 0.45% 1 0 2026-09-22T20:25:55.870000 vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offload
CVE-2026-94623 7.5 0.45% 1 0 2026-09-22T20:25:55.870000 vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL conne
CVE-2026-88419 8.8 0.48% 1 0 2026-09-22T20:17:11.083000 An unrestricted upload of files with a dangerous type in the thumbnail-upload en
CVE-2026-87902 8.1 0.42% 15 13 2026-09-22T20:00:03.713000 An unauthenticated attacker can make `get_page_template()` page-template resolut
CVE-2026-88407 7.5 0.26% 1 0 2026-09-22T20:00:03.713000 An out-of-bounds read in the node_token_count/relation_token_count component of
CVE-2026-88411 7.5 0.28% 1 0 2026-09-22T20:00:03.713000 Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c)
CVE-2026-88409 8.8 0.28% 1 0 2026-09-22T20:00:03.713000 FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer ov
CVE-2026-94084 9.4 0.40% 1 0 2026-09-22T19:44:01.280000 Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transacti
CVE-2026-25254 9.8 0.73% 1 0 2026-09-22T19:37:36.747000 Improper authorization leads to Remote Code Execution via SocketIO interface.
CVE-2026-84239 7.6 0.41% 1 0 2026-09-22T19:32:25.730000 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-19658 9.8 0.41% 1 1 2026-09-22T19:04:55.677000 The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in
CVE-2026-81642 9.8 0.60% 2 1 2026-09-22T18:59:21.953000 In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in t
CVE-2026-89275 10.0 1.25% 1 0 2026-09-22T18:33:43 Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of
CVE-2026-94099 9.9 1.69% 1 0 2026-09-22T16:18:17.183000 A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This
CVE-2026-95675 9.8 3.91% 1 0 2026-09-22T15:32:43 D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated re
CVE-2026-65113 9.8 0.61% 1 0 2026-09-22T15:32:43 NVIDIA Infrastructure Controller for Linux contains a vulnerability where an att
CVE-2026-84388 9.6 0.38% 1 1 2026-09-22T15:32:41 A improper restriction of rendered ui layers or frames vulnerability in Fortinet
CVE-2026-88406 7.5 0.27% 1 0 2026-09-22T15:32:31 FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack ove
CVE-2026-7273 8.8 2.41% 7 0 2026-09-22T12:10:51.067000 A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-4
CVE-2026-13355 9.8 0.34% 1 1 2026-09-22T06:30:35 The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to A
CVE-2026-94301 9.8 0.39% 1 0 2026-09-22T04:18:02.810000 The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - accept
CVE-2026-94493 10.0 0.73% 1 0 2026-09-22T03:31:06 A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issu
CVE-2026-94540 7.7 0.11% 1 0 2026-09-22T00:31:02 DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that a
CVE-2026-94627 7.5 0.45% 1 0 2026-09-22T00:31:02 vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache blo
CVE-2026-94425 8.8 0.11% 2 0 2026-09-22T00:31:02 A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The a
CVE-2026-12249 9.0 0.14% 1 0 2026-09-21T22:27:11 An issue was discovered in Canonical ADSys upstream versions through v0.16.2. Du
CVE-2026-81469 7.8 0.13% 1 0 2026-09-21T21:32:01 Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted S
CVE-2026-94501 8.8 0.30% 1 0 2026-09-21T21:32:00 jshERP through 3.6 contains an authorization bypass vulnerability in the userBus
CVE-2026-94424 8.8 0.14% 1 0 2026-09-21T21:31:57 A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340
CVE-2026-93958 9.1 2.17% 1 1 2026-09-21T19:17:18.593000 A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affec
CVE-2026-79920 9.9 0.36% 1 0 2026-09-21T19:17:11.323000 Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any
CVE-2026-61674 0 0.65% 2 0 2026-09-21T19:17:07.067000 Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Lin
CVE-2026-80521 7.8 0.13% 3 1 2026-09-21T15:32:39 In the Linux kernel, the following vulnerability has been resolved: af_unix: Un
CVE-2026-82187 9.8 0.30% 1 0 2026-09-21T15:17:32.223000 The Web to Print Online Designer WordPress plugin before 2.15.0 does not validat
CVE-2026-10747 10.0 0.52% 1 0 2026-09-21T13:17:07.147000 IBM MQ Appliance could allow a remote attacker to cause a denial of service or p
CVE-2026-94101 9.9 0.45% 1 0 2026-09-21T03:30:27 A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246
CVE-2026-86553 8.5 0.45% 1 1 2026-09-20T06:30:20 SmartLife app dynamically generates fresh SmartLife application authentication p
CVE-2026-94083 9.4 0.40% 1 0 2026-09-20T03:30:29 Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free,
CVE-2026-93485 7.1 0.16% 1 2 2026-09-19T15:17:08.323000 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2026-61817 8.5 0.58% 1 0 2026-09-19T15:16:59.910000 pg_partman is a PostgreSQL extension that manages partitioned tables by time or
CVE-2026-53266 8.8 0.28% 2 2 2026-09-19T04:17:53.580000 In the Linux kernel, the following vulnerability has been resolved: netfilter:
CVE-2026-88097 8.1 0.22% 1 0 2026-09-18T21:32:43 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke
CVE-2026-84086 7.2 0.65% 1 0 2026-09-18T21:32:40 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to
CVE-2026-84085 8.1 0.32% 1 0 2026-09-18T21:32:39 IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit
CVE-2026-81937 7.2 1.45% 1 0 2026-09-18T21:32:35 IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerabi
CVE-2025-39682 7.1 2.03% 1 3 2026-09-18T21:31:33 In the Linux kernel, the following vulnerability has been resolved: tls: fix ha
CVE-2026-13639 9.8 0.51% 1 0 2026-09-18T20:17:06.860000 An insufficient entropy vulnerability in login logic in Synology DiskStation Man
CVE-2026-90898 9.8 0.34% 1 1 2026-09-18T19:31:11.370000 Bifrost registers MCP clients through its management API. A stdio client is a co
CVE-2026-19499 7.7 0.38% 1 0 2026-09-18T18:17:47.257000 Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can writ
CVE-2026-85058 7.5 0.27% 1 0 2026-09-18T17:58:41 ## Summary Moquette MQTT Broker fails to enforce ACL write permission checks wh
CVE-2025-39964 3.3 0.79% 2 3 2026-09-18T15:31:06 In the Linux kernel, the following vulnerability has been resolved: crypto: af_
CVE-2026-13684 9.8 0.46% 1 0 2026-09-18T09:31:20 An improper encoding or escaping of output vulnerability in SCGI in Synology Dis
CVE-2026-76460 10.0 0.78% 2 1 2026-09-17T12:46:31.670000 A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an
CVE-2026-79994 0 0.11% 1 0 2026-09-16T20:38:33.883000 The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a
CVE-2026-58704 8.0 0.21% 1 0 2026-09-16T15:30:57 In Cellular Modem, there is a possible permission bypass due to a logic error in
CVE-2026-77179 None 0.16% 1 1 2026-09-16T00:32:25 On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows
CVE-2026-43783 7.8 0.15% 2 1 2026-09-15T19:24:16.433000 A race condition was addressed with improved locking. This issue is fixed in mac
CVE-2026-59570 7.5 0.09% 1 0 2026-09-14T15:32:56 On affected versions of Zscaler client connector, a pre-installed peer app can t
CVE-2026-86060 9.8 1.06% 1 2 2026-09-11T15:32:27 RouterOS contains an argument-handling flaw in the SSH login path involving user
CVE-2026-85103 9.8 0.36% 2 0 2026-09-10T04:18:18.390000 A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unau
CVE-2026-85880 7.8 0.57% 1 0 2026-09-08T21:34:12 Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elev
CVE-2026-81963 7.8 0.63% 1 0 2026-09-08T21:34:09 Improper link resolution before file access ('link following') in Windows Update
CVE-2026-86296 10.0 1.35% 3 0 2026-09-08T17:18:39.613000 A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affe
CVE-2026-67279 0 0.45% 1 0 2026-09-08T16:18:10.600000 RouterOS SSH enters the connection protocol after a client-requested rekey even
CVE-2026-75925 9.6 0.67% 1 0 2026-09-08T15:28:33.090000 Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.
CVE-2026-50093 9.0 0.19% 1 0 2026-09-08T09:35:45 A vulnerability has been identified in Siveillance Control Pro V3.0 (All version
CVE-2026-43499 7.8 0.79% 2 100 2026-09-08T09:18:05.213000 In the Linux kernel, the following vulnerability has been resolved: rtmutex: Us
CVE-2026-78306 0 0.15% 1 2 2026-08-26T16:49:18.760000 DJI drones expose an unauthenticated DUML command interface over Bluetooth that
CVE-2026-42945 8.1 68.05% 1 45 2026-08-25T15:33:26 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo
CVE-2026-33824 9.8 72.69% 1 2 2026-08-19T04:16:58.560000 Double free in Windows IKE Extension allows an unauthorized attacker to execute
CVE-2026-59310 9.8 50.38% 2 2 2026-08-18T18:32:52 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-55040 9.1 50.59% 1 5 template 2026-08-18T18:32:50 Weak authentication in Microsoft Office SharePoint allows an unauthorized attack
CVE-2026-15830 5.3 1.26% 2 0 2026-08-18T16:30:33.827000 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDja
CVE-2026-68820 7.0 6.18% 1 4 2026-08-11T21:33:01 Use after free in Windows Ancillary Function Driver for WinSock allows an author
CVE-2026-65660 6.5 0.81% 4 0 2026-08-11T18:31:43 Improper control of generation of code ('code injection') in Microsoft Office Sh
CVE-2026-63077 9.8 86.52% 1 6 template 2026-08-06T05:17:05.170000 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-39364 7.5 2.00% 1 0 template 2026-08-04T13:18:24.733000 Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2
CVE-2026-20805 5.5 5.19% 1 6 2026-07-30T21:16:56.810000 Exposure of sensitive information to an unauthorized actor in Desktop Windows Ma
CVE-2026-59309 9.8 7.94% 2 0 2026-07-30T15:31:54 VMware vCenter contains an authentication bypass vulnerability in the VMware Dir
CVE-2026-12495 0 0.17% 1 0 2026-07-28T08:17:14.187000 Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http
CVE-2025-68686 5.9 29.60% 1 0 2026-07-27T18:31:25 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE
CVE-2026-48842 8.1 0.76% 3 0 2026-07-24T10:10:00.197000 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authenticat
CVE-2026-41091 7.8 8.20% 1 4 2026-07-24T10:10:00.197000 Improper link resolution before file access ('link following') in Microsoft Defe
CVE-2026-45659 8.8 76.08% 1 2 2026-07-23T11:10:00.120000 Deserialization of untrusted data in Microsoft Office SharePoint allows an autho
CVE-2026-50522 9.8 85.40% 1 5 2026-07-22T21:31:51 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-49972 8.8 1.08% 3 0 2026-07-13T21:31:30 Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows u
CVE-2026-47065 9.8 0.50% 1 0 2026-07-13T17:24:48 ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via j
CVE-2026-21519 7.8 2.46% 1 0 2026-06-17T10:18:46.287000 Access of resource using incompatible type ('type confusion') in Desktop Window
CVE-2026-21513 8.8 15.64% 1 0 2026-06-17T10:18:45.540000 Protection mechanism failure in MSHTML Framework allows an unauthorized attacker
CVE-2022-42475 9.8 99.47% 1 9 2026-06-17T05:04:59.630000 A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 th
CVE-2021-44168 3.3 0.87% 1 1 2026-06-17T04:11:59.317000 A download of code without integrity check vulnerability in the "execute restore
CVE-2020-4428 9.1 61.69% 1 0 2026-06-17T03:19:58.553000 IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authen
CVE-2026-45756 None 0.63% 1 0 2026-05-28T17:34:56 ### Description The `JsonPath` component's `match()` and `search()` filter func
CVE-2026-21525 6.2 5.04% 1 0 2026-03-27T21:31:32 Null pointer dereference in Windows Remote Access Connection Manager allows an u
CVE-2026-4575 2.4 0.21% 1 0 2026-03-23T06:30:39 A flaw has been found in code-projects Exam Form Submission 1.0. This issue affe
CVE-2020-4427 9.8 70.03% 1 0 template 2025-11-04T00:30:30 IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a
CVE-2023-48788 9.8 98.45% 1 1 2025-10-22T00:34:05 A improper neutralization of special elements used in an sql command ('sql injec
CVE-2023-20118 7.2 54.11% 2 0 2025-10-22T00:33:50 A vulnerability in the web-based management interface of Cisco Small Business Ro
CVE-2025-6625 7.5 0.48% 1 0 2025-08-18T09:31:52 CWE-20: Improper Input Validation vulnerability exists that could cause a Denial
CVE-2024-20260 8.6 0.59% 1 0 2024-10-23T18:33:16 A vulnerability in the VPN and management web servers of the Cisco Adaptive Secu
CVE-2024-0244 9.8 1.38% 1 0 2024-02-22T05:08:38 Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers an
CVE-2026-94545 0 0.00% 3 2 N/A
CVE-2026-84739 0 0.00% 2 0 N/A
CVE-2026-78902 0 0.00% 2 0 N/A
CVE-2026-67231 0 0.00% 2 0 N/A
CVE-2026-88804 0 0.00% 2 0 N/A
CVE-2026-96419 0 0.00% 1 0 N/A
CVE-2026-69184 0 0.68% 1 0 N/A
CVE-2024-85880 0 0.00% 1 0 N/A
CVE-2024-85046 0 0.00% 1 0 N/A
CVE-2024-87491 0 0.00% 1 0 N/A
CVE-2026-89090 0 0.31% 1 0 N/A
CVE-2026-85279 0 0.21% 1 0 N/A
CVE-2026-79916 0 0.27% 1 0 N/A
CVE-2026-73550 0 0.88% 1 0 N/A
CVE-2026-73552 0 0.66% 1 0 N/A
CVE-2026-73548 0 0.66% 1 0 N/A

CVE-2026-12227
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-24T10:17:32.623000

2 posts

The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive da

offseq at 2026-09-24T10:30:27.801Z ##

Visual Composer Website Builder plugin ≤45.16.0 hit by CRITICAL LFI (CVE-2026-12227). Unauthenticated attackers can execute arbitrary PHP files via 'vcv-template'. Patch unconfirmed. Mitigate & monitor now: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-24T10:30:27.000Z ##

Visual Composer Website Builder plugin ≤45.16.0 hit by CRITICAL LFI (CVE-2026-12227). Unauthenticated attackers can execute arbitrary PHP files via 'vcv-template'. Patch unconfirmed. Mitigate & monitor now: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #LFI

##

CVE-2026-78308
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-24T09:32:00

2 posts

Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.

offseq at 2026-09-24T09:00:25.133Z ##

CVE-2026-78308 | CRITICAL | DIAEnergie (<1.11.00.022): Improper Authentication lets attackers bypass auth controls. Patch urgently when available. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-24T09:00:25.000Z ##

CVE-2026-78308 | CRITICAL | DIAEnergie (<1.11.00.022): Improper Authentication lets attackers bypass auth controls. Patch urgently when available. radar.offseq.com/threat/cve-20 #OffSeq #ICS #Vulnerability #Cybersecurity

##

CVE-2026-84502
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-24T06:31:14

1 posts

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the module runs git ls-remote with the URL as a positional argument and without a "--" separator, a git project URL such as "--upload-pack=<command>:x" is interpreted by gi

undercodenews@mastodon.social at 2026-09-24T00:58:35.000Z ##

Red Hat Ansible Automation Platform CVE-2026-84502: A Low-Privilege Project Permission Can Become Control-Plane RCE + Video

Critical Vulnerability Exposes a Dangerous Privilege Boundary Red Hat has disclosed CVE-2026-84502, a critical argument-injection vulnerability in the Ansible Automation Platform automation-controller. The flaw carries a CVSS score of 9.9 and can allow an authenticated, low-privileged project user to execute arbitrary commands on the controller's…

undercodenews.com/red-hat-ansi

##

CVE-2026-19599
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-24T04:17:48.027000

2 posts

ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.

DailyCyberSecurity@infosec.exchange at 2026-09-23T14:35:09.000Z ##

ManageEngine security vulnerabilities expose servers to remote code execution. Patch these OpManager vulnerabilities and CVE-2026-19599 to secure your network.

#ManageEngine #Cybersecurity #CVE202619599 #OpManager #Infosec #Vulnerability

securityonline.info/manageengi

##

offseq@infosec.exchange at 2026-09-23T13:30:24.000Z ##

CVE-2026-19599: CRITICAL RCE in ManageEngine OpManager MSP (<12.8.711). Improper OS command neutralization enables remote command execution (CVSS 9.9). Upgrade to 12.8.711+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #InfoSec #RCE

##

CVE-2026-18467
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-24T03:30:34

4 posts

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3. The 5.0.3 patch introduced a wp_hash()/hash_equals() signature gate on the pt-paytium-user-data field, but left a second filter — pt_cf_checkout_meta(), registered on the pt_meta_values hook after the signed builder — that copies every $_POST['pt_for

thehackerwire@mastodon.social at 2026-09-24T07:47:59.000Z ##

🔴 CVE-2026-18467 - Critical (9.8)

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3. The 5.0.3 patch introduced a wp_hash()/hash_equals() signature gate on the pt-paytium-user-data f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-09-24T03:00:25.849Z ##

CVE-2026-18467: CRITICAL privilege escalation in Paytium: Mollie payment forms (≤5.0.3). Unauthenticated users can create admin accounts via exploited payment forms. Restrict forms or disable plugin until full fix. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-24T07:47:59.000Z ##

🔴 CVE-2026-18467 - Critical (9.8)

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3. The 5.0.3 patch introduced a wp_hash()/hash_equals() signature gate on the pt-paytium-user-data f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-24T03:00:25.000Z ##

CVE-2026-18467: CRITICAL privilege escalation in Paytium: Mollie payment forms (≤5.0.3). Unauthenticated users can create admin accounts via exploited payment forms. Restrict forms or disable plugin until full fix. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202618467 #Security

##

CVE-2026-96891
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-24T03:16:58.950000

2 posts

A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname  leads to out-of-bounds write. The attack may be initiated remotely.

thehackerwire@mastodon.social at 2026-09-24T07:47:42.000Z ##

🔴 CVE-2026-96891 - Critical (9.8)

A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname  leads to out-of-bounds write. The attack may be in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-24T07:47:42.000Z ##

🔴 CVE-2026-96891 - Critical (9.8)

A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname  leads to out-of-bounds write. The attack may be in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97055
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-24T02:16:54.333000

2 posts

SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() does not reject the empty value, so a deployment that does not configure a secret starts up and both signs and verifies session tokens with an empty HMAC key. Because the JWT tokenize

thehackerwire@mastodon.social at 2026-09-24T07:47:51.000Z ##

🟠 CVE-2026-97055 - High (8.1)

SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() does not reject the empty valu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-24T07:47:51.000Z ##

🟠 CVE-2026-97055 - High (8.1)

SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() does not reject the empty valu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70125
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-24T00:30:34

2 posts

Microsoft Outlook Remote Code Execution Vulnerability

CVE-2026-19125
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-24T00:30:29

2 posts

The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to the verify_login() function in app/Login.php containing a missing return statement in the signature verification failure branch — when Signature::verify2() reports a mismatch, the function only assigns a WP_Error to a local variable and continues executi

1 repos

https://github.com/Polosss/By-Poloss..-..CVE-2026-19125

thehackerwire@mastodon.social at 2026-09-24T00:16:28.000Z ##

🟠 CVE-2026-19125 - High (8.1)

The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to the verify_login() function in app/Login.php containing a missing return statement in the signature...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-24T00:16:28.000Z ##

🟠 CVE-2026-19125 - High (8.1)

The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to the verify_login() function in app/Login.php containing a missing return statement in the signature...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81536
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-24T00:30:29

2 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

thehackerwire@mastodon.social at 2026-09-23T23:04:21.000Z ##

🟠 CVE-2026-81536 - High (7.7)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-23T23:04:21.000Z ##

🟠 CVE-2026-81536 - High (7.7)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81208
(7.7 HIGH)

EPSS: 0.00%

updated 2026-09-24T00:30:29

2 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An attacker could exploit this vulnerability to obtain credentials intended for other users or environments.

thehackerwire@mastodon.social at 2026-09-23T23:04:12.000Z ##

🟠 CVE-2026-81208 - High (7.7)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An attacker could exploit this vulnerability to obtain credentials intended for other ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-23T23:04:12.000Z ##

🟠 CVE-2026-81208 - High (7.7)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An attacker could exploit this vulnerability to obtain credentials intended for other ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86583
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-24T00:30:29

2 posts

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter writes CSV cells using fputcsv() with a NUL byte (\0) as the escape character, while the importer parses the same file using SplFileObject::fgetcsv() with o

thehackerwire@mastodon.social at 2026-09-23T23:01:57.000Z ##

🟠 CVE-2026-86583 - High (8.8)

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter wri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-23T23:01:57.000Z ##

🟠 CVE-2026-86583 - High (8.8)

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter wri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75887
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-24T00:30:26

2 posts

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including plugin manifests and configuration files. Furthermore, this flaw can enable path traversal against

thehackerwire@mastodon.social at 2026-09-23T23:02:15.000Z ##

🟠 CVE-2026-75887 - High (7.5)

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-23T23:02:15.000Z ##

🟠 CVE-2026-75887 - High (7.5)

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93577
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-24T00:17:22.850000

3 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration.

bearstech@mamot.fr at 2026-09-24T09:45:00.000Z ##

Toutes nos instances GitLab sont à jour en version 19.4.1 depuis hier soir à 22h.

Il faut mettre à jour rapidement : cette nouvelle version corrige 2 CVE évaluées à 9,9 (CVE-2026-93577 et CVE-2026-84739).

En savoir plus sur nos offres 👇
gitlab-saas.bearstech.com/

##

sayzard@mastodon.sayzard.org at 2026-09-24T02:38:14.000Z ##

Critical GitLab Auth RCE via Double-Free in Regex Parser

GitLab은 CE/EE의 정규식 파서 double-free(CVE-2026-89078)와 정규식 컴파일러 integer overflow(CVE-2026-93577)를 포함한 긴급 보안 패치를 19.4.1, 19.3.3, 19.2.7로 배포했다. 두 취약점은 인증된 사용자가 CI/CD 구성에 특수 제작한 정규식을 넣어 GitLab 서버에서 임의 코드 실행을 유발할 수 있으며, 각각 CVSS 9.9로 평가됐다. 또한 Duo AI job troubleshooting의 권한 검증 누락으로 디버그 잡 로그에 포함된 민감한 CI/CD 변수 값을 열...

docs.gitlab.com/releases/patch

##

bearstech@mamot.fr at 2026-09-24T09:45:00.000Z ##

Toutes nos instances GitLab sont à jour en version 19.4.1 depuis hier soir à 22h.

Il faut mettre à jour rapidement : cette nouvelle version corrige 2 CVE évaluées à 9,9 (CVE-2026-93577 et CVE-2026-84739).

En savoir plus sur nos offres 👇
gitlab-saas.bearstech.com/

##

CVE-2026-89078
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-24T00:17:22.060000

1 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to a double free issue when parsing a specially crafted regular expression in a CI/CD configuration.

sayzard@mastodon.sayzard.org at 2026-09-24T02:38:14.000Z ##

Critical GitLab Auth RCE via Double-Free in Regex Parser

GitLab은 CE/EE의 정규식 파서 double-free(CVE-2026-89078)와 정규식 컴파일러 integer overflow(CVE-2026-93577)를 포함한 긴급 보안 패치를 19.4.1, 19.3.3, 19.2.7로 배포했다. 두 취약점은 인증된 사용자가 CI/CD 구성에 특수 제작한 정규식을 넣어 GitLab 서버에서 임의 코드 실행을 유발할 수 있으며, 각각 CVSS 9.9로 평가됐다. 또한 Duo AI job troubleshooting의 권한 검증 누락으로 디버그 잡 로그에 포함된 민감한 CI/CD 변수 값을 열...

docs.gitlab.com/releases/patch

##

CVE-2026-93352
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-23T22:16:59.523000

4 posts

Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes phpt but omits pht, which Apache executes as PHP via the default FilesMatch directive on Debian and Ubuntu systems. An attacker can upload a .pht file tha

offseq at 2026-09-24T00:00:35.451Z ##

plank laravel-mediable <7.0.2 has a CRITICAL vuln (CVE-2026-93352): .pht files not blocked, allowing unauthenticated RCE. Upgrade to 7.0.2+ ASAP. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-23T23:02:06.000Z ##

🔴 CVE-2026-93352 - Critical (9.8)

Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-24T00:00:35.000Z ##

plank laravel-mediable <7.0.2 has a CRITICAL vuln (CVE-2026-93352): .pht files not blocked, allowing unauthenticated RCE. Upgrade to 7.0.2+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202693352 #RCE #Laravel #Infosec

##

thehackerwire@mastodon.social at 2026-09-23T23:02:06.000Z ##

🔴 CVE-2026-93352 - Critical (9.8)

Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81537
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-23T22:16:57.690000

2 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection.

thehackerwire@mastodon.social at 2026-09-24T00:16:19.000Z ##

🟠 CVE-2026-81537 - High (8.8)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-24T00:16:19.000Z ##

🟠 CVE-2026-81537 - High (8.8)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80423
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-23T22:16:57.270000

2 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts.

thehackerwire@mastodon.social at 2026-09-23T23:04:02.000Z ##

🟠 CVE-2026-80423 - High (8.8)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-23T23:04:02.000Z ##

🟠 CVE-2026-80423 - High (8.8)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-6928
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-23T21:31:08

2 posts

IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application crashes, or execute arbitrary code.

offseq at 2026-09-24T01:30:25.932Z ##

IBM Concert v1.0.0 – 3.0.0 hit by CRITICAL use-after-free bug (CVE-2026-6928, CVSS 9.8). Remote code execution & full compromise possible; no patch confirmed. Monitor IBM advisories. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-24T01:30:25.000Z ##

IBM Concert v1.0.0 – 3.0.0 hit by CRITICAL use-after-free bug (CVE-2026-6928, CVSS 9.8). Remote code execution & full compromise possible; no patch confirmed. Monitor IBM advisories. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IBM #CVE20266928 #Infosec

##

CVE-2026-87899(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-23T21:31:03

2 posts

Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.

DailyCyberSecurity at 2026-09-24T01:10:49.330Z ##

cPanel patched critical cPanel security vulnerabilities including CVE-2026-87899. Update cPanel and WP Toolkit now to prevent privilege escalation.

securityonline.info/cpanel-sec

##

DailyCyberSecurity@infosec.exchange at 2026-09-24T01:10:49.000Z ##

cPanel patched critical cPanel security vulnerabilities including CVE-2026-87899. Update cPanel and WP Toolkit now to prevent privilege escalation.

#cPanel #WHM #WPToolkit #PrivilegeEscalation #Cybersecurity #Infosec #CVE202687899

securityonline.info/cpanel-sec

##

CVE-2026-68490(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-09-23T21:30:56

1 posts

Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.

undercodenews@mastodon.social at 2026-09-24T06:57:15.000Z ##

cPanel CalDAV/CardDAV Vulnerability Exposes Shared-Hosting Calendars and Contacts Across Accounts

A Critical Privacy Risk for Multi-Tenant Servers cPanel has released security updates addressing CVE-2026-68490, a permissions vulnerability in its CalDAV and CardDAV functionality that could allow a local user on a shared server to access calendar events and contact information belonging to other hosting accounts. The Vulnerability Behind the Exposure The flaw is…

undercodenews.com/cpanel-calda

##

CVE-2026-6730
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-23T21:17:02.053000

2 posts

IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.

offseq at 2026-09-24T06:00:23.741Z ##

Buffer overflow (CVE-2026-6730) in IBM Concert 1.0.0-3.0.0 (CVSS 9.8, CRITICAL) lets local users execute arbitrary code. No patch yet — restrict local access, check vendor updates. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-24T06:00:23.000Z ##

Buffer overflow (CVE-2026-6730) in IBM Concert 1.0.0-3.0.0 (CVSS 9.8, CRITICAL) lets local users execute arbitrary code. No patch yet — restrict local access, check vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #IBM #Vuln #CyberSecurity

##

CVE-2026-88020
(6.1 MEDIUM)

EPSS: 0.27%

updated 2026-09-23T19:42:48.540000

1 posts

Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.

cyberworldops@infosec.exchange at 2026-09-23T11:00:01.000Z ##

CISA reports CVE-2026-88020, XSS in OpenPLC Runtime v3 6.1. Theft of an operator session cookie can enable state-changing requests and PLC-level control. Exposure of OT web interfaces significantly raises impact. #IcsSecurity #OtSecurity #Xss

cyberworldops.eu/en/openplc-we

##

CVE-2026-19202
(0 None)

EPSS: 0.23%

updated 2026-09-23T19:42:48.540000

1 posts

A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audiences. If an application uses the SDK to authenticate to two or more different audiences within the same process, the module-level token cache fails to key its cached tokens by the requested audience. Consequently, a valid, unexpired token minted

offseq@infosec.exchange at 2026-09-23T06:00:25.000Z ##

CVE-2026-19202: CRITICAL vuln in Google mcp-toolbox-sdk-python (v0 – 1.1.0). Shared cache flaw lets Google ID tokens be reused across audiences — risk of token replay & impersonation. Patch pending. Details: radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE202619202 #Python

##

CVE-2026-49881
(7.8 HIGH)

EPSS: 0.11%

updated 2026-09-23T19:23:28.350000

1 posts

In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

2 repos

https://github.com/Supersonic/TLPE

https://github.com/LSPosed/LSPromise

DailyCyberSecurity@infosec.exchange at 2026-09-22T00:24:53.000Z ##

A critical Android Telecom vulnerability (CVE-2026-49881) allows remote code execution. Read the analysis and learn how to secure your device today.

#Android #CVE202649881 #Cybersecurity #Infosec #ZeroDay

securityonline.info/android-te

##

CVE-2026-18162
(9.8 CRITICAL)

EPSS: 0.86%

updated 2026-09-23T19:17:28.687000

2 posts

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor.

undercodenews@mastodon.social at 2026-09-23T23:32:23.000Z ##

IBM FTM for OpenShift Faces Critical Unauthenticated RCE Vulnerabilities — CVE-2026-18163 and CVE-2026-18162 + Video

Introduction IBM has issued a Critical security bulletin affecting Financial Transaction Manager (FTM) for Red Hat OpenShift, warning of multiple vulnerabilities that could expose affected deployments to serious attacks. Among more than 40 vulnerabilities addressed in the bulletin, two stand out because they reportedly allow unauthenticated remote code…

undercodenews.com/ibm-ftm-for-

##

offseq@infosec.exchange at 2026-09-23T03:00:24.000Z ##

CVE-2026-18162: IBM FTM for RedHat OpenShift v4.0.6.0 has a CRITICAL code injection flaw (CVSS 9.8). Remote attackers can execute arbitrary code via improper input neutralization. No patch yet — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202618162 #IBM #RCE

##

CVE-2026-73512
(7.5 HIGH)

EPSS: 0.83%

updated 2026-09-23T18:43:37.403000

1 posts

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current RequestDecoder when Capsule Protocol is enabled. Stream recreation, including an internal redirect, replaces the ActiveStream and updates EnvoyQuicServerStream but does not update the handler's cached pointer. A subseque

thehackerwire@mastodon.social at 2026-09-21T21:03:01.000Z ##

🟠 CVE-2026-73512 - High (7.5)

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current RequestDecoder when Capsule Protocol is enabled. Stream recreation,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73547
(7.5 HIGH)

EPSS: 0.83%

updated 2026-09-23T18:21:42.327000

1 posts

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ext_authz filter assumes that a request contains a :path pseudoheader when applying query_parameters_to_set or query_parameters_to_remove from an authorization response. A path-less CONNECT request makes request_headers_->Path() return null, and Filter::onCom

thehackerwire@mastodon.social at 2026-09-21T21:01:11.000Z ##

🟠 CVE-2026-73547 - High (7.5)

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ext_authz filter assumes that a request contains a :path pseudoheader when applying query_parameters_to_se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18169
(9.9 CRITICAL)

EPSS: 0.78%

updated 2026-09-23T18:17:07.270000

1 posts

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.

offseq@infosec.exchange at 2026-09-23T00:00:43.000Z ##

CVE-2026-18169: CRITICAL path traversal in IBM FTM for RedHat OpenShift 4.0.6.0 (CVSS 9.9) 🕵️‍♂️. Authenticated attackers can access sensitive info via symlink abuse. Restrict access & monitor logs. Patch status unknown. radar.offseq.com/threat/cve-20 #OffSeq #IBM #CVE202618169 #Infosec

##

CVE-2026-63447
(7.5 HIGH)

EPSS: 0.36%

updated 2026-09-23T18:12:04.247000

1 posts

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp.max-tx is reached while processing one large chunk of FTP command data. The oversized transaction list is repeatedly processed with quadratic complexity

hugovalters@mastodon.social at 2026-09-24T09:10:01.000Z ##

CVE-2026-63447: Suricata FTP parser DoS, CVSS 7.5. Crafted FTP traffic causes quadratic processing that degrades packet inspection. No patch yet. Apply mitigations and watch for updates. valtersit.com/cve/CVE-2026-634 #CVE #infosec #Suricata

##

CVE-2026-91809
(7.8 HIGH)

EPSS: 0.17%

updated 2026-09-23T17:58:26.570000

1 posts

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access a released object, resulting in an application crash.

thehackerwire@mastodon.social at 2026-09-23T09:03:07.000Z ##

🟠 CVE-2026-91809 - High (7.8)

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access a released object, resulting in an application crash.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91818
(7.8 HIGH)

EPSS: 0.17%

updated 2026-09-23T17:58:26.570000

1 posts

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, which is subsequently accessed, resulting in an application crash.

thehackerwire@mastodon.social at 2026-09-23T09:02:58.000Z ##

🟠 CVE-2026-91818 - High (7.8)

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, which is subsequently accessed, resu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83621
(8.1 HIGH)

EPSS: 0.29%

updated 2026-09-23T17:17:50.090000

1 posts

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.editList for any authenticated user. The list_name, list_enabled, url, and list_update parameters allow a non-admin user to redirect threat-intelligence downloads

thehackerwire@mastodon.social at 2026-09-21T18:01:13.000Z ##

🟠 CVE-2026-83621 - High (8.1)

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.editList f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93616
(9.8 CRITICAL)

EPSS: 2.42%

updated 2026-09-23T16:38:38.987000

15 posts

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

2 repos

https://github.com/Nebula-Consulting-Limited/CVE-2026-93616-PoC

https://github.com/WadesWeaponShed/CVE-2026-93616_Checks

undercodenews@mastodon.social at 2026-09-24T09:00:25.000Z ##

Check Point Warns of Active Exploitation of Critical VPN and Management Server Flaws

Attackers Are Targeting Check Point Security Infrastructure Check Point has issued an urgent security warning after confirming active exploitation of two critical vulnerabilities affecting its VPN gateways and security-management infrastructure. Tracked as CVE-2026-85102 and CVE-2026-93616, both vulnerabilities carry a CVSS score of 9.8 and can allow unauthenticated attackers to…

undercodenews.com/check-point-

##

beyondmachines1 at 2026-09-24T08:01:13.483Z ##

Check Point VPN Gateways and Management Server Flaws Actively Exploited

Check Point confirmed active exploitation of three critical vulnerabilities (CVE-2026-85102, CVE-2026-85103, and CVE-2026-93616) affecting VPN gateways and management servers, prompting a 72-hour US federal remediation deadline.

**If you run Check Point Security Gateways, Spark Firewalls or Security Management Servers, patch immediately to LivePatch Take 26 or the latest Jumbo Hotfix. Older unsupported versions R80 through R81.10 must be upgraded first. Make sure the management server's web interface is reachable only from trusted internal networks. Patching isn't enough, since attackers have been active since September 12: check your VPN logs for unknown sessions and internal LDAP scanning, and if you find anything suspicious, treat the device as compromised and escalate to your incident response team.**

beyondmachines.net/event_detai

##

tugatech@masto.pt at 2026-09-24T07:07:21.000Z ##

Até 30 de junho, a Check Point confirma ataques ativos a falhas críticas em seus produtos, recomendando atualização urgente. Piratas informáticos exploram vulnerabilidades nos certificados de VPN do Security Gateway (CVE-2026-85102) e no serviço web de Management (CVE-2026-93616), permitindo a execução remota de código sem autenticação prévia. 🚨

🔗 tugatech.com.pt/t91581-check-p

#urgente 

##

beyondmachines1@infosec.exchange at 2026-09-24T08:01:13.000Z ##

Check Point VPN Gateways and Management Server Flaws Actively Exploited

Check Point confirmed active exploitation of three critical vulnerabilities (CVE-2026-85102, CVE-2026-85103, and CVE-2026-93616) affecting VPN gateways and management servers, prompting a 72-hour US federal remediation deadline.

**If you run Check Point Security Gateways, Spark Firewalls or Security Management Servers, patch immediately to LivePatch Take 26 or the latest Jumbo Hotfix. Older unsupported versions R80 through R81.10 must be upgraded first. Make sure the management server's web interface is reachable only from trusted internal networks. Patching isn't enough, since attackers have been active since September 12: check your VPN logs for unknown sessions and internal LDAP scanning, and if you find anything suspicious, treat the device as compromised and escalate to your incident response team.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

tugatech@masto.pt at 2026-09-24T07:07:21.000Z ##

Até 30 de junho, a Check Point confirma ataques ativos a falhas críticas em seus produtos, recomendando atualização urgente. Piratas informáticos exploram vulnerabilidades nos certificados de VPN do Security Gateway (CVE-2026-85102) e no serviço web de Management (CVE-2026-93616), permitindo a execução remota de código sem autenticação prévia. 🚨

🔗 tugatech.com.pt/t91581-check-p

#urgente 

##

cyberworldops@infosec.exchange at 2026-09-23T20:50:00.000Z ##

Check Point confirms active exploitation of CVE-2026-85102, unauthenticated RCE in Security Gateway VPN negotiation, and CVE-2026-93616, path traversal leading to script execution on management systems. Internet-exposed gateways and management planes should be patched and reviewed for compromise immediately. #CheckPoint #ThreatIntel #VpnSecurity

cyberworldops.eu/en/active-att

##

uztq@infosec.exchange at 2026-09-23T19:49:09.000Z ##

Checkpoint / CVE-2026-93616: support.checkpoint.com/results

Soooo, it is always fun to translate a vendor advisory into real facts. Here, checkpoint says "Directory Traversal and File upload allows execution of arbitrary script", and provide, as an example:

login(loginRequest=LoginRequest{authenticationInfo=AuthenticationInfoBase{username='abcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdababcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcd'}

And: "if a core dump file was generated at the same time as the login attempt [...]"

Sorry guys, but you are totally misleading whoever is trying to qualify/understand your adivsory. Security vendors should really be accountable of whatever they deliver. I am not even mentioning 1. the triviality of the findings, 2. everything is running as root.

They also discovered that ASN.1 parsing requires extensive fuzzing (support.checkpoint.com/results).

I was expected more from checkpoint, but at least they provide a bit more info than the other "similar" vendors.

##

secdb@infosec.exchange at 2026-09-22T22:00:21.000Z ##

🚨 [CISA-2026:0922] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-85102 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Improper Certificate Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93616 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93952 (secdb.nttzen.cloud/cve/detail/)
- Name: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Arista
- Product: VeloCloud Orchestrator
- Notes: arista.com/en/support/advisori ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-94127 (secdb.nttzen.cloud/cve/detail/)
- Name: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: F5
- Product: BIG-IP APM
- Notes: For temporary mitigation to allow for proactive forensic triage, apply the vendor-provided iRule. Once completed, install the final vendor patch as soon as possible. For more information please see: my.f5.com/manage/s/article/K00 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260922 #cisa20260922 #cve_2026_85102 #cve_2026_93616 #cve_2026_93952 #cve_2026_94127 #cve202685102 #cve202693616 #cve202693952 #cve202694127

##

security_crawler_carl@infosec.exchange at 2026-09-22T21:31:08.000Z ##

blog.checkpoint.com/security/s

#CyberSecurity #ZeroDay #CheckPoint #Vulnerability #ActiveExploitation #PatchedOrPerish (3/3)

##

security_crawler_carl@infosec.exchange at 2026-09-22T21:31:07.000Z ##

Meanwhile a second zero-day, CVE-2026-93616, materialized in Security Management with its own handful of pinpointed hits.

Policy dictates we inform you patches now exist for both CVE-2026-85102 and CVE-2026-93616. Policy does not require we feel bad about what happens next if you ignore them. Install both immediately.

Reward: Compliance logged. Outcome: your problem. (2/3)

##

campuscodi@mastodon.social at 2026-09-22T20:02:50.000Z ##

Check Point has disclosed a zero-day (in Security Management Server) and marked an older bug also as exploited in the wild (in Site-to-Site VPN)

blog.checkpoint.com/security/s

##

cisakevtracker@mastodon.social at 2026-09-22T20:01:22.000Z ##

CVE ID: CVE-2026-93616
Vendor: Check Point
Product: Multiple Products
Date Added: 2026-09-22
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DarkWebInformer@infosec.exchange at 2026-09-22T18:46:03.000Z ##

🚨 Check Point patches Management Server zero-day exploited in attacks
⠀
Check Point has released fixes for CVE-2026-93616, a vulnerability that allows unauthenticated attackers to upload and execute arbitrary scripts on affected management servers.
⠀
The company says a small number of customers have already been attacked.
⠀
Affected products include:

• Security Management Server
• Multi-Domain Security Management Server
• Log Server
• Multi-Domain Log Server
• SmartEvent
⠀
The vulnerability carries a CVSS score of 9.8.
⠀
Check Point advises installing the applicable fixes, restricting management access to trusted IP addresses, and checking for signs of exploitation.
⠀
LivePatch Take 28/29 does not fix this vulnerability.

Source: bleepingcomputer.com/news/secu

##

DailyCyberSecurity@infosec.exchange at 2026-09-22T13:58:15.000Z ##

A critical exploited Check Point Management vulnerability (CVE-2026-93616) allows attackers to execute arbitrary scripts. Secure your servers now.

#CheckPoint #CVE202693616 #Cybersecurity #InfoSec #Vulnerability #RCE

securityonline.info/exploited-

##

offseq@infosec.exchange at 2026-09-22T13:30:26.000Z ##

Check Point Quantum Security Management is affected by CVE-2026-93616 (CRITICAL, CVSS 9.8): unauthenticated attackers can upload & execute scripts via path traversal. Restrict access & monitor activity until patch info is released. radar.offseq.com/threat/cve-20 #OffSeq #CheckPoint #CyberAlert

##

CVE-2026-77987
(0 None)

EPSS: 0.89%

updated 2026-09-23T16:16:45.047000

1 posts

A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to internal services listening on other ports of the same appliance. Response bodies were not returned to the requester, but response timing acte

cR0w@infosec.exchange at 2026-09-22T21:36:48.000Z ##

Go hack more GitHub shit.

nvd.nist.gov/vuln/detail/cve-2

A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to internal services listening on other ports of the same appliance. Response bodies were not returned to the requester, but response timing acted as an oracle that allowed instance secrets to be extracted character by character. An extracted secret could then be used in a separate interaction with an internal service to obtain remote code execution on the appliance. Exploitation required network access to the instance and was unauthenticated when private mode was disabled, or required any authenticated user when private mode was enabled. This vulnerability affected GitHub Enterprise Server versions 3.17 through 3.22 and was fixed in versions 3.22.1, 3.21.6, 3.20.8, 3.19.12, 3.18.15, and 3.17.21. This vulnerability was reported through the GitHub Bug Bounty program.

sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

##

CVE-2026-96257
(10.0 CRITICAL)

EPSS: 1.04%

updated 2026-09-23T15:17:31.920000

1 posts

A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of the component Device Discovery Service. Executing a manipulation can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

offseq@infosec.exchange at 2026-09-23T04:30:24.000Z ##

Fast FAC1203R Gigabit Edition v2.0.4 hit by CRITICAL stack-based buffer overflow (CVE-2026-96257). Remote, unauthenticated RCE possible. Exploit is public, no patch exists — restrict access to Device Discovery Service now. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec

##

CVE-2026-93952
(10.0 CRITICAL)

EPSS: 0.74%

updated 2026-09-23T14:32:12.417000

11 posts

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been

beyondmachines1 at 2026-09-24T11:01:12.831Z ##

Arista Networks Patches Critical VeloCloud Orchestrator Zero-Day Exploited in the Wild

Arista Networks disclosed a critical CVSS 10.0 vulnerability (CVE-2026-93952) in VeloCloud Orchestrator On-Prem that is being actively exploited to gain unauthenticated remote access to orchestrator hosts and managed edge devices.

**If you run VeloCloud Orchestrator On-Prem, this is urgent. Make sure its web interface is not reachable from the internet and is accessible only from trusted admin networks, then update right away to a fixed version (5.2.3.16, 6.4.2.8 or later). Attackers are already using this flaw to take full control without any password. After patching, look for the hidden file /usr/local/sbin/.vcnode.js or the x-vc-opt header in your web logs, and if you find either, treat the orchestrator and every connected Edge device as compromised.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-24T11:01:12.000Z ##

Arista Networks Patches Critical VeloCloud Orchestrator Zero-Day Exploited in the Wild

Arista Networks disclosed a critical CVSS 10.0 vulnerability (CVE-2026-93952) in VeloCloud Orchestrator On-Prem that is being actively exploited to gain unauthenticated remote access to orchestrator hosts and managed edge devices.

**If you run VeloCloud Orchestrator On-Prem, this is urgent. Make sure its web interface is not reachable from the internet and is accessible only from trusted admin networks, then update right away to a fixed version (5.2.3.16, 6.4.2.8 or later). Attackers are already using this flaw to take full control without any password. After patching, look for the hidden file /usr/local/sbin/.vcnode.js or the x-vc-opt header in your web logs, and if you find either, treat the orchestrator and every connected Edge device as compromised.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

offseq@infosec.exchange at 2026-09-23T09:00:25.000Z ##

CVE-2026-93952: CRITICAL zero-day in Arista VeloCloud Orchestrator (on-prem <5.2.3.16, <6.4.2.8) is actively exploited. Remote attackers can access privileged functions w/o creds. Patch now — review logs for signs of compromise. radar.offseq.com/threat/arista #OffSeq #Arista #ZeroDay #Infosec

##

DailyCyberSecurity@infosec.exchange at 2026-09-23T08:40:23.000Z ##

Arista confirmed active exploitation of a CVSS 10 VeloCloud Orchestrator vulnerability (CVE-2026-93952) affecting certificate-based SD-WAN setups. Patch now.

#VeloCloud #Arista #CVE202693952 #SDWAN #Vulnerability #CyberSecurity

meterpreter.org/arista-veloclo

##

ifin@infosec.exchange at 2026-09-22T22:28:10.000Z ##

Completing our tour of new known-exploited vulns today, here is Arista's perfect-10.

ifin.network/t/arista-cve-2026

#ThreatIntel #ThreatIntelligence #IFIN

##

secdb@infosec.exchange at 2026-09-22T22:00:21.000Z ##

🚨 [CISA-2026:0922] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-85102 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Improper Certificate Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93616 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93952 (secdb.nttzen.cloud/cve/detail/)
- Name: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Arista
- Product: VeloCloud Orchestrator
- Notes: arista.com/en/support/advisori ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-94127 (secdb.nttzen.cloud/cve/detail/)
- Name: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: F5
- Product: BIG-IP APM
- Notes: For temporary mitigation to allow for proactive forensic triage, apply the vendor-provided iRule. Once completed, install the final vendor patch as soon as possible. For more information please see: my.f5.com/manage/s/article/K00 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260922 #cisa20260922 #cve_2026_85102 #cve_2026_93616 #cve_2026_93952 #cve_2026_94127 #cve202685102 #cve202693616 #cve202693952 #cve202694127

##

cisakevtracker@mastodon.social at 2026-09-22T20:00:51.000Z ##

CVE ID: CVE-2026-93952
Vendor: Arista
Product: VeloCloud Orchestrator
Date Added: 2026-09-22
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

cyberworldops@infosec.exchange at 2026-09-22T14:40:00.000Z ##

Arista disclosed active exploitation of CVE-2026-93952, a CVSS 10.0 unauthenticated flaw in on-prem VeloCloud Orchestrator with certificate authentication enabled. Compromise of the management plane risks full SD-WAN Edge control and lateral movement. Isolate exposed instances and hunt for abuse. #VeloCloud #ThreatIntel #InfoSec

cyberworldops.eu/en/active-att

##

security_crawler_carl@infosec.exchange at 2026-09-22T14:39:04.000Z ##

🏆 New Achievement! Exceeds Expectations (Except Security)!

Thank you for joining us for your annual review, Arista VeloCloud Orchestrator team. Uptime? Stellar. Throughput? Impressive. Unauthorized remote access granted to unauthenticated strangers due to CVE-2026-93952, a CVSS 10.0 critical improper-input-validation flaw currently being actively exploited in the wild? That's a "needs improvement," and frankly it drags down the whole scorecard.

Full system compromise is on the table. (1/2)

##

offseq@infosec.exchange at 2026-09-22T09:00:24.000Z ##

CVE-2026-93952 (CRITICAL, CVSS 10) impacts Arista VeloCloud Orchestrator (On-Prem) via improper input validation. Remote, unauthenticated access may lead to full system compromise. Patch urgently. radar.offseq.com/threat/cve-20 #OffSeq #CVE #infosec #Vulnerability

##

DailyCyberSecurity@infosec.exchange at 2026-09-22T03:14:59.000Z ##

An exploited VeloCloud vulnerability with a 10.0 CVSS score hits Arista appliances. Patch the critical VeloCloud vulnerability to stop active attacks.

#VeloCloud #Arista #CVE202693952 #ZeroDay #Cybersecurity #Infosec

securityonline.info/velocloud-

##

CVE-2026-94127
(9.8 CRITICAL)

EPSS: 1.39%

updated 2026-09-23T14:32:07.910000

16 posts

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by

1 repos

https://github.com/FurkanKAYAPINAR/CVE-2026-94127

cyberveille@mastobot.ping.moi at 2026-09-24T11:00:06.000Z ##

📢 CVE-2026-94127 : Vulnérabilité critique F5 BIG-IP APM exploitée en zero-day

SecurityWeek, article de Ionut Arghire publié le 23 septembre 2026. F5 et la CISA ont émis conjointement une alerte concernant l'exploitation active d'une vulnérabilité critique dans le composant BIG-IP Access Policy Manager (APM).

📖 cyberveille : cyberveille.ch/posts/2026-09-2
🌐 source : securityweek.com/critical-f5-b
🟡 vérification factuelle moyenne
#APM #F5BIGIP #Cyberveille

##

raptor at 2026-09-24T05:01:11.616Z ##

Is This A Joke? In The Auth Header? (#F5 BIG-IP UnAuth Heap-Overflow to CVE-2026-94127)

labs.watchtowr.com/is-this-a-j

##

glitterbean@wehavecookies.social at 2026-09-24T01:18:11.000Z ##

Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) labs.watchtowr.com/is-this-a-j

##

_r_netsec at 2026-09-23T23:28:04.854Z ##

Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) - watchTowr Labs labs.watchtowr.com/is-this-a-j

##

raptor@infosec.exchange at 2026-09-24T05:01:11.000Z ##

Is This A Joke? In The Auth Header? (#F5 BIG-IP UnAuth Heap-Overflow to #RCE CVE-2026-94127)

labs.watchtowr.com/is-this-a-j

##

_r_netsec@infosec.exchange at 2026-09-23T23:28:04.000Z ##

Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) - watchTowr Labs labs.watchtowr.com/is-this-a-j

##

security_crawler_carl@infosec.exchange at 2026-09-23T11:14:37.000Z ##

🏆 New Achievement! Terms and Conditions of Your Own Destruction!

LOOTBOX DISCLAIMER: By operating F5 BIG-IP APM versions 21.1.0, 17.5.0–17.5.1, or 17.1.0–17.1.3, you have automatically entered our Unauthenticated Remote Code Execution Sweepstakes. Prizes are awarded via CVE-2026-94127, targeting the OAuth Authorization Server component. Odds of receiving a prize are classified as "active exploitation." The System does not guarantee prize desirability. (1/3)

##

offseq@infosec.exchange at 2026-09-23T10:30:25.000Z ##

F5 BIG-IP APM (OAuth Authorization Server) is facing a CRITICAL RCE zero-day, CVE-2026-94127, with active exploitation. Versions 21.1.0, 17.5.0 – 17.5.1, 17.1.0 – 17.1.3 affected. Apply hotfixes now. Details: radar.offseq.com/threat/critic #OffSeq #F5 #ZeroDay #Infosec

##

cyberworldops@infosec.exchange at 2026-09-23T08:20:00.000Z ##

F5 patched CVE-2026-94127, a heap-based buffer overflow in BIG-IP APM when operating as OAuth Authorization Server, enabling remote code execution. Active zero-day exploitation poses high risk of full appliance compromise. Patch immediately and review for crafted malicious traffic. #F5BigIp #ZeroDay #RemoteCodeExecution

cyberworldops.eu/en/actively-e

##

bsi@social.bund.de at 2026-09-23T08:09:54.000Z ##

Der Hersteller F5 veröffentlichte ein Advisory zu einer ausgenutzten Zero-Day Schwachstelle in seinem Produkt BIG-IP Access Policy Manager (APM) zur sicheren Zugriffsteuerung und Anwendungszugriff: CVE-2026-94127, CVSS-Score 9.8/10 ("kritisch")

F5 gibt an, dass die Schwachstelle bereits aktiv ausgenutzt wird. IT-Sicherheitsverantwortliche sollten unverzüglich die Patchstände prüfen und, sofern erforderlich, die verfügbaren Engineering Hotfixes einspielen.

👉️ bsi.bund.de/dok/1209384

##

offseq@infosec.exchange at 2026-09-23T07:30:23.000Z ##

CVE-2026-94127: Critical zero-day in F5 BIG-IP APM exploited for RCE on OAuth Authorization Servers. Patch urgently or use F5's iRule mitigation. Monitor for OAuth auth failures and TMM SIGABRTs. radar.offseq.com/threat/f5-pat #OffSeq #F5 #ZeroDay #RCE #Vuln

##

secdb@infosec.exchange at 2026-09-22T22:00:21.000Z ##

🚨 [CISA-2026:0922] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-85102 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Improper Certificate Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93616 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93952 (secdb.nttzen.cloud/cve/detail/)
- Name: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Arista
- Product: VeloCloud Orchestrator
- Notes: arista.com/en/support/advisori ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-94127 (secdb.nttzen.cloud/cve/detail/)
- Name: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: F5
- Product: BIG-IP APM
- Notes: For temporary mitigation to allow for proactive forensic triage, apply the vendor-provided iRule. Once completed, install the final vendor patch as soon as possible. For more information please see: my.f5.com/manage/s/article/K00 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260922 #cisa20260922 #cve_2026_85102 #cve_2026_93616 #cve_2026_93952 #cve_2026_94127 #cve202685102 #cve202693616 #cve202693952 #cve202694127

##

ifin@infosec.exchange at 2026-09-22T20:51:00.000Z ##

When it rains, it pours. F5 BIG-IP APM also has an exploited CVE!

ifin.network/t/f5-big-ip-cve-2

#ThreatIntel #ThreatIntelligence #IFIN

##

cisakevtracker@mastodon.social at 2026-09-22T20:01:07.000Z ##

CVE ID: CVE-2026-94127
Vendor: F5
Product: BIG-IP APM
Date Added: 2026-09-22
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-09-22T16:27:39.000Z ##

An exploited BIG-IP APM vulnerability tracked as CVE-2026-94127 allows RCE attacks. Secure your BIG-IP APM vulnerability deployments with new F5 hotfixes.

#F5 #BIGIP #CVE202694127 #Cybersecurity #InfoSec #RCE #Vulnerability

securityonline.info/big-ip-apm

##

cR0w@infosec.exchange at 2026-09-22T15:03:32.000Z ##

EITW 0day in F5 APM.

my.f5.com/manage/s/article/K00

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). (CVE-2026-94127)

This vulnerability allows an unauthenticated attacker to perform RCE. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.

##

CVE-2026-91811
(7.8 HIGH)

EPSS: 0.17%

updated 2026-09-23T09:30:37

1 posts

A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful exploitation could result in memory corruption and an application crash.

thehackerwire@mastodon.social at 2026-09-23T09:03:17.000Z ##

🟠 CVE-2026-91811 - High (7.8)

A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful exploitation could result in memory corruption and an app...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-74849
(9.8 CRITICAL)

EPSS: 4.46%

updated 2026-09-23T04:17:44.340000

1 posts

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.

CVE-2026-32996
(0 None)

EPSS: 0.16%

updated 2026-09-23T04:17:43.927000

3 posts

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

1 repos

https://github.com/suce0155/CVE-2026-32996

obivan@infosec.exchange at 2026-09-22T11:20:45.000Z ##

Veeam Agent LPE PoC github.com/suce0155/CVE-2026-3

##

cyberworldops@infosec.exchange at 2026-09-22T08:30:01.000Z ##

Zyxel GS1900 switches (CVE-2026-7273) and Veeam Agent for Microsoft Windows (CVE-2026-32996) are under active exploitation. The former allows unauthenticated LAN command execution via CGI buffer overflow, the latter enables SYSTEM-level access on endpoints. Both expand persistence and backup tampering risk. #Zyxel #Veeam #ThreatIntel #VulnManagement

cyberworldops.eu/en/active-att

##

DailyCyberSecurity@infosec.exchange at 2026-09-22T07:35:44.000Z ##

A critical exploited Veeam Agent vulnerability (CVE-2026-32996) is under active attack. Public PoC exploit code has been disclosed. Update systems now.

#Veeam #CVE202632996 #Cybersecurity #Vulnerability #Infosec

securityonline.info/actively-e

##

CVE-2026-18163
(9.8 CRITICAL)

EPSS: 0.81%

updated 2026-09-23T00:31:21

2 posts

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.

undercodenews@mastodon.social at 2026-09-23T23:32:23.000Z ##

IBM FTM for OpenShift Faces Critical Unauthenticated RCE Vulnerabilities — CVE-2026-18163 and CVE-2026-18162 + Video

Introduction IBM has issued a Critical security bulletin affecting Financial Transaction Manager (FTM) for Red Hat OpenShift, warning of multiple vulnerabilities that could expose affected deployments to serious attacks. Among more than 40 vulnerabilities addressed in the bulletin, two stand out because they reportedly allow unauthenticated remote code…

undercodenews.com/ibm-ftm-for-

##

offseq@infosec.exchange at 2026-09-23T01:30:24.000Z ##

CVE-2026-18163 (CRITICAL, CVSS 9.8): IBM FTM for RedHat OpenShift v4.0.6.0 has a deserialization vulnerability enabling remote code execution without auth. Restrict access & monitor activity. Patch status unconfirmed. radar.offseq.com/threat/cve-20 #OffSeq #CVE202618163 #IBM #InfoSec 🛡️

##

CVE-2026-28324
(9.8 CRITICAL)

EPSS: 0.65%

updated 2026-09-22T21:31:34

2 posts

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.

DailyCyberSecurity@infosec.exchange at 2026-09-23T01:02:41.000Z ##

SolarWinds Observability vulnerabilities allow RCE via CVE-2026-28324. Update to version 2026.2.3 to secure your monitoring infrastructure today.

#SolarWinds #Cybersecurity #CVE202628324 #CVE202628325 #RCE #Infosec

securityonline.info/solarwinds

##

cR0w@infosec.exchange at 2026-09-22T21:34:44.000Z ##

solarwinds.com/trust-center/se

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.

sev:CRIT 9.8 - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

##

CVE-2026-87121
(9.8 CRITICAL)

EPSS: 0.78%

updated 2026-09-22T21:31:34

2 posts

lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.

cR0w@infosec.exchange at 2026-09-22T21:35:40.000Z ##

Go hack more MQTT shit.

nvd.nist.gov/vuln/detail/cve-2

##

thehackerwire@mastodon.social at 2026-09-22T21:01:57.000Z ##

🔴 CVE-2026-87121 - Critical (9.8)

lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85102
(9.8 CRITICAL)

EPSS: 0.66%

updated 2026-09-22T21:30:40

15 posts

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

undercodenews@mastodon.social at 2026-09-24T09:00:25.000Z ##

Check Point Warns of Active Exploitation of Critical VPN and Management Server Flaws

Attackers Are Targeting Check Point Security Infrastructure Check Point has issued an urgent security warning after confirming active exploitation of two critical vulnerabilities affecting its VPN gateways and security-management infrastructure. Tracked as CVE-2026-85102 and CVE-2026-93616, both vulnerabilities carry a CVSS score of 9.8 and can allow unauthenticated attackers to…

undercodenews.com/check-point-

##

beyondmachines1 at 2026-09-24T08:01:13.483Z ##

Check Point VPN Gateways and Management Server Flaws Actively Exploited

Check Point confirmed active exploitation of three critical vulnerabilities (CVE-2026-85102, CVE-2026-85103, and CVE-2026-93616) affecting VPN gateways and management servers, prompting a 72-hour US federal remediation deadline.

**If you run Check Point Security Gateways, Spark Firewalls or Security Management Servers, patch immediately to LivePatch Take 26 or the latest Jumbo Hotfix. Older unsupported versions R80 through R81.10 must be upgraded first. Make sure the management server's web interface is reachable only from trusted internal networks. Patching isn't enough, since attackers have been active since September 12: check your VPN logs for unknown sessions and internal LDAP scanning, and if you find anything suspicious, treat the device as compromised and escalate to your incident response team.**

beyondmachines.net/event_detai

##

tugatech@masto.pt at 2026-09-24T07:07:21.000Z ##

Até 30 de junho, a Check Point confirma ataques ativos a falhas críticas em seus produtos, recomendando atualização urgente. Piratas informáticos exploram vulnerabilidades nos certificados de VPN do Security Gateway (CVE-2026-85102) e no serviço web de Management (CVE-2026-93616), permitindo a execução remota de código sem autenticação prévia. 🚨

🔗 tugatech.com.pt/t91581-check-p

#urgente 

##

sayzard@mastodon.sayzard.org at 2026-09-24T03:45:20.000Z ##

Hackers Actively Exploit Check Point VPN Flaw

Check Point Security Gateway의 VPN 인증서 처리 기능에서 인증 전 원격 코드 실행(RCE)이 가능한 CVE-2026-85102가 공개되었고, 이미 실제 공격에 악용되고 있다고 보고됐다. CVSS 9.8의 치명적 취약점으로, 공격자는 유효한 계정 없이 조작된 VPN 인증서를 보내 게이트웨이에서 임의 코드를 실행할 수 있어 원격접속 경계가 직접 침해될 수 있다. 영향을 받는 조직은 9월 23일 배포된 최신 패치를 즉시 적용하고, VPN 장비 로그·비정상 인증서 요청·관리 인터페이스 접근 흔적을 점검해야 한다. AI 서비스 운영 조직도 VP...

2tinteractive.com/blog/hackers

##

beyondmachines1@infosec.exchange at 2026-09-24T08:01:13.000Z ##

Check Point VPN Gateways and Management Server Flaws Actively Exploited

Check Point confirmed active exploitation of three critical vulnerabilities (CVE-2026-85102, CVE-2026-85103, and CVE-2026-93616) affecting VPN gateways and management servers, prompting a 72-hour US federal remediation deadline.

**If you run Check Point Security Gateways, Spark Firewalls or Security Management Servers, patch immediately to LivePatch Take 26 or the latest Jumbo Hotfix. Older unsupported versions R80 through R81.10 must be upgraded first. Make sure the management server's web interface is reachable only from trusted internal networks. Patching isn't enough, since attackers have been active since September 12: check your VPN logs for unknown sessions and internal LDAP scanning, and if you find anything suspicious, treat the device as compromised and escalate to your incident response team.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

tugatech@masto.pt at 2026-09-24T07:07:21.000Z ##

Até 30 de junho, a Check Point confirma ataques ativos a falhas críticas em seus produtos, recomendando atualização urgente. Piratas informáticos exploram vulnerabilidades nos certificados de VPN do Security Gateway (CVE-2026-85102) e no serviço web de Management (CVE-2026-93616), permitindo a execução remota de código sem autenticação prévia. 🚨

🔗 tugatech.com.pt/t91581-check-p

#urgente 

##

cyberworldops@infosec.exchange at 2026-09-23T20:50:00.000Z ##

Check Point confirms active exploitation of CVE-2026-85102, unauthenticated RCE in Security Gateway VPN negotiation, and CVE-2026-93616, path traversal leading to script execution on management systems. Internet-exposed gateways and management planes should be patched and reviewed for compromise immediately. #CheckPoint #ThreatIntel #VpnSecurity

cyberworldops.eu/en/active-att

##

oversecurity@mastodon.social at 2026-09-23T20:10:05.000Z ##

Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE)...

🔗️ [Bleepingcomputer] link.is.it/iSJtsD

##

secdb@infosec.exchange at 2026-09-22T22:00:21.000Z ##

🚨 [CISA-2026:0922] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-85102 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Improper Certificate Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93616 (secdb.nttzen.cloud/cve/detail/)
- Name: Check Point Multiple Products Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Check Point
- Product: Multiple Products
- Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-93952 (secdb.nttzen.cloud/cve/detail/)
- Name: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Arista
- Product: VeloCloud Orchestrator
- Notes: arista.com/en/support/advisori ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-94127 (secdb.nttzen.cloud/cve/detail/)
- Name: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: F5
- Product: BIG-IP APM
- Notes: For temporary mitigation to allow for proactive forensic triage, apply the vendor-provided iRule. Once completed, install the final vendor patch as soon as possible. For more information please see: my.f5.com/manage/s/article/K00 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260922 #cisa20260922 #cve_2026_85102 #cve_2026_93616 #cve_2026_93952 #cve_2026_94127 #cve202685102 #cve202693616 #cve202693952 #cve202694127

##

security_crawler_carl@infosec.exchange at 2026-09-22T21:31:08.000Z ##

blog.checkpoint.com/security/s

#CyberSecurity #ZeroDay #CheckPoint #Vulnerability #ActiveExploitation #PatchedOrPerish (3/3)

##

security_crawler_carl@infosec.exchange at 2026-09-22T21:31:07.000Z ##

Meanwhile a second zero-day, CVE-2026-93616, materialized in Security Management with its own handful of pinpointed hits.

Policy dictates we inform you patches now exist for both CVE-2026-85102 and CVE-2026-93616. Policy does not require we feel bad about what happens next if you ignore them. Install both immediately.

Reward: Compliance logged. Outcome: your problem. (2/3)

##

campuscodi@mastodon.social at 2026-09-22T20:02:50.000Z ##

Check Point has disclosed a zero-day (in Security Management Server) and marked an older bug also as exploited in the wild (in Site-to-Site VPN)

blog.checkpoint.com/security/s

##

cisakevtracker@mastodon.social at 2026-09-22T20:01:37.000Z ##

CVE ID: CVE-2026-85102
Vendor: Check Point
Product: Multiple Products
Date Added: 2026-09-22
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

ifin@infosec.exchange at 2026-09-22T19:56:52.000Z ##

Two Check Point critical vulnerabilities are now listed as exploited in the wild.

ifin.network/t/cve-2026-85102-

#ThreatIntel #ThreatIntelligence #IFIN

##

DailyCyberSecurity@infosec.exchange at 2026-09-22T16:11:01.000Z ##

An exploited Check Point VPN vulnerability allows remote code execution. Patch this Check Point VPN vulnerability now to block active in-the-wild attacks.

#CheckPoint #CVE202685102 #VPN #Cybersecurity #Infosec #ZeroDay

securityonline.info/checkpoint

##

CVE-2026-94411
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-22T20:43:58.793000

1 posts

jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles. Attackers can send a POST request with type=UserRole, their own user ID, and a role ID list to escalate from low-privilege tenant user to tenant administrator.

thehackerwire@mastodon.social at 2026-09-21T20:01:05.000Z ##

🟠 CVE-2026-94411 - High (8.8)

jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles. Attackers can send a POST request with type=UserRole, their own user ID, and...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94497
(8.3 HIGH)

EPSS: 0.26%

updated 2026-09-22T20:43:58.793000

1 posts

jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and delete other users' business objects by submitting direct object identifiers without authorization checks.

thehackerwire@mastodon.social at 2026-09-21T20:00:43.000Z ##

🟠 CVE-2026-94497 - High (8.3)

jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and delete other users' business objects by submitting direct object identifier...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77560
(8.1 HIGH)

EPSS: 0.33%

updated 2026-09-22T20:37:12

1 posts

# tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for ## GitHub Advisory Details (form fields — paste-ready) **Affected products** | Field | Value | |-------|-------| | Ecosystem | `Other (self-hosted)` / Go | | Package name | `github.com/steveiliop56/tinyauth` (forwar

thehackerwire@mastodon.social at 2026-09-21T18:01:33.000Z ##

🟠 CVE-2026-77560 - High (8.1)

Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege user to byp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77322
(7.5 HIGH)

EPSS: 0.61%

updated 2026-09-22T20:34:31

1 posts

### Summary The WebSocket transport allocates a buffer from the frame payload length before validating its size, which can lead to an unauthenticated DoS. ### Details `WSConnection.Read` allocates a buffer from the declared WebSocket frame length before reading the payload (https://github.com/emiago/sipgo/blob/v1.4.0/sip/transport_ws.go#L400): ```go data := make([]byte, header.Length) // hea

thehackerwire@mastodon.social at 2026-09-22T21:02:07.000Z ##

🟠 CVE-2026-77322 - High (7.5)

SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go creates a wsutil.Reader without setting MaxFrameSize, allowing NextFrame to accept a client-controlled header.Length before Pa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93345
(7.5 HIGH)

EPSS: 0.49%

updated 2026-09-22T20:25:55.870000

1 posts

MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service by sending a malformed MP_REACH_NLRI UPDATE message with a prefix-length value below the minimum valid for a labelled-VPN NLRI, which passes validation while describing a route with

thehackerwire@mastodon.social at 2026-09-22T19:04:08.000Z ##

🟠 CVE-2026-93345 - High (7.5)

MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service by sending a malformed MP_REA...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94626
(7.5 HIGH)

EPSS: 0.45%

updated 2026-09-22T20:25:55.870000

1 posts

vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode disaggregated deployments to exhaust memory and trigger kernel OOM-kill of the decode worker process.

thehackerwire@mastodon.social at 2026-09-21T23:02:44.000Z ##

🟠 CVE-2026-94626 - High (7.5)

vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode disaggreg...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94624
(7.5 HIGH)

EPSS: 0.45%

updated 2026-09-22T20:25:55.870000

1 posts

vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in kv_transfer_params to create unreachable peer sessions that retain ZeroMQ sockets until the context quota is exhausted, causing an uncaught ZMQError that

thehackerwire@mastodon.social at 2026-09-21T23:02:35.000Z ##

🟠 CVE-2026-94624 - High (7.5)

vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94623
(7.5 HIGH)

EPSS: 0.45%

updated 2026-09-22T20:25:55.870000

1 posts

vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. Attackers can trigger an assertion failure in NixlBaseConnectorWorker._apply_prefix_caching by submitting completion requests with multiple prompts of va

thehackerwire@mastodon.social at 2026-09-21T23:02:26.000Z ##

🟠 CVE-2026-94623 - High (7.5)

vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88419
(8.8 HIGH)

EPSS: 0.48%

updated 2026-09-22T20:17:11.083000

1 posts

An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a crafted .php file and execute arbitrary PHP code on the server, because the stored file extension is taken verbatim from the client-supplied filename with no extension allowlist or content va

thehackerwire@mastodon.social at 2026-09-22T21:01:48.000Z ##

🟠 CVE-2026-88419 - High (8.8)

An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a crafted .php file and execute arbitrar...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

youranonnewsirc@nerdculture.de at 2026-09-24T10:26:17.000Z ##

Cybersecurity faces immediate threats as a critical WordPress vulnerability (CVE-2026-87902) was exploited post-disclosure (Sept 24). Ransomware attacks reached a record high in August 2026, marking a significant surge. On the technology front, Meta Connect 2026 showcased key advancements in AI and virtual reality. Geopolitically, the Ukraine war persists, with President Zelensky expressing hope for peace before winter amidst ongoing US-Iran tensions.

#Cybersecurity #TechNews #Geopolitics

##

Analyst207@mastodon.social at 2026-09-24T08:51:12.000Z ##

WordPress Exploits CVE-2026-87902 Flaw Within Hours of Disclosure

Within hours of being disclosed, WordPress was exploited through a critical vulnerability, CVE-2026-87902, that could allow hackers to remotely execute code on vulnerable sites. This flaw, with a near-perfect CVSS score of 9.2, lets unauthenticated attackers inject malicious code by tricking WordPress into including a rogue…

osintsights.com/wordpress-expl

#Cve202687902 #Wordpress #RemoteCodeExecution #Rce #VulnerabilityExploitation

##

cyberworldops at 2026-09-24T08:30:00.439Z ##

Unauthenticated LFI in WordPress page-template resolution (CVE-2026-87902, CVSS 9.2) is being exploited in the wild. Under specific server and theme conditions it escalates to RCE, enabling full site compromise. Patch and review exposure immediately.

cyberworldops.eu/en/attackers-

##

undercodenews@mastodon.social at 2026-09-24T07:27:41.000Z ##

Critical WordPress Vulnerability Under Active Attack as Hackers Move Toward Remote Code Execution

Exploitation Has Entered a More Dangerous Phase Threat actors are escalating attacks against a critical WordPress vulnerability, moving beyond basic reconnaissance and vulnerability testing to attempts to write attacker-controlled PHP files onto compromised servers. Tracked as CVE-2026-87902, the flaw affects WordPress versions 4.7.0 through 7.1.1 and can potentially lead…

undercodenews.com/critical-wor

##

sayzard@mastodon.sayzard.org at 2026-09-24T04:40:35.000Z ##

Hackers start exploiting critical WordPress flaw for code execution

WordPress의 인증 없는 경로 순회 취약점 CVE-2026-87902(CVSS 9.2)가 실제 공격에 악용되기 시작했다. 공격자는 `pagename`의 이중 인코딩 경로 순회와 유효한 `page_id`를 이용해 로컬 PHP 파일을 포함시키며, 특정 조건에서는 `pearcmd.php`를 통해 디스크에 공격자 제어 PHP 파일을 작성하고 쉘 명령 실행으로 이어질 수 있다. WordPress 7.1.2 및 4.7 이상 지원 브랜치에 패치가 백포트됐으므로...

bleepingcomputer.com/news/secu

##

youranonnewsirc@nerdculture.de at 2026-09-24T10:26:17.000Z ##

Cybersecurity faces immediate threats as a critical WordPress vulnerability (CVE-2026-87902) was exploited post-disclosure (Sept 24). Ransomware attacks reached a record high in August 2026, marking a significant surge. On the technology front, Meta Connect 2026 showcased key advancements in AI and virtual reality. Geopolitically, the Ukraine war persists, with President Zelensky expressing hope for peace before winter amidst ongoing US-Iran tensions.

#Cybersecurity #TechNews #Geopolitics

##

cyberworldops@infosec.exchange at 2026-09-24T08:30:00.000Z ##

Unauthenticated LFI in WordPress page-template resolution (CVE-2026-87902, CVSS 9.2) is being exploited in the wild. Under specific server and theme conditions it escalates to RCE, enabling full site compromise. Patch and review exposure immediately. #WordPress #InfoSec #RemoteCodeExecution

cyberworldops.eu/en/attackers-

##

oversecurity@mastodon.social at 2026-09-23T19:00:44.000Z ##

Hackers start exploiting critical WordPress flaw for code execution

Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell...

🔗️ [Bleepingcomputer] link.is.it/xdsXDB

##

DarkWebInformer@infosec.exchange at 2026-09-23T18:52:55.000Z ##

🚨[POC] CVE-2026-87902: WordPress Core versions up to and including 7.1.1 are affected by a Local File Inclusion vulnerability in the locate_template() function.

GitHub: github.com/abraxas/CVE-2026-87

Credit: @abraxas_null (X)

##

DailyCyberSecurity@infosec.exchange at 2026-09-23T15:02:03.000Z ##

An exploited WordPress RCE vulnerability (CVE-2026-87902) is under attack. Details and PoC exploit code are public. Patch your sites now.

#WordPress #CVE202687902 #RCE #Cybersecurity #Infosec #ZeroDay

securityonline.info/exploited-

##

obivan@infosec.exchange at 2026-09-23T08:47:19.000Z ##

WordPress unauthenticated LFI to RCE PoC github.com/dinosn/cve-2026-879

##

appinn@m.cmx.im at 2026-09-23T04:13:48.000Z ##

新内容:《WordPress 爆出 9.2 分严重安全漏洞|CVE-2026-87902》
appinn.com/wordpress-cve-2026-
2026年9月23日,WordPress 爆出 9.2 分的严重安全漏洞,攻击者无需登录即可在服务器上运行代码。漏洞编号 CVE-2026-87902,请务必升级至最新版本 7.1.2。@appinn 根据 W3Techs 2026 年 9 月 22 日的最新统计,全球约 40.2% 的网站都在使用

##

technotenshi@infosec.exchange at 2026-09-22T21:07:41.000Z ##

WordPress patched a critical unauthenticated path traversal vulnerability (CVE-2026-87902, GHSA-7hp8-65ch-5whp, CVSS 9.2) in its page-template resolution function get_page_template(), discovered and responsibly disclosed by Robert Ressl. Under specific preconditions, such as an active theme with a top level directory starting with "page-" and a readable local PHP file usable for the pearcmd.php PEAR RCE chain, an attacker could achieve remote code execution with no authentication. WordPress 7.1.2 fixes the issue, and the patch has been backported to every supported branch back to 4.7.37, so all sites should update immediately.

github.com/WordPress/wordpress

#InfoSec #WordPress #Vulnerability #CVE

##

DailyCyberSecurity@infosec.exchange at 2026-09-22T15:47:49.000Z ##

WordPress 7.1.2 patches a critical WordPress RCE vulnerability (CVE-2026-87902). Update your site to prevent conditional remote code execution.

#WordPress #CVE202687902 #RCE #Cybersecurity #Infosec #WordPressSecurity

securityonline.info/wordpress-

##

cyberia@mast.eu.org at 2026-09-22T15:30:11.000Z ##

Service notice: all hosted/maintained WP websites have been updated to the latest minor version of your current major branch (security release, CVE-2026-87902). No action needed from you!

I don't host or maintain your website? Be sure to update your WordPress ASAP. This one is critical.

Release notes → wordpress.org/news/2026/09/wor

#WordPress #Security #Critical #Cyberia

##

CVE-2026-88407
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-22T20:00:03.713000

1 posts

An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20.4 allows attackers to cause a Denial of Service (DoS) via a crafted input.

thehackerwire@mastodon.social at 2026-09-21T22:04:05.000Z ##

🟠 CVE-2026-88407 - High (7.5)

An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20.4 allows attackers to cause a Denial of Service (DoS) via a crafted input.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88411
(7.5 HIGH)

EPSS: 0.28%

updated 2026-09-22T20:00:03.713000

1 posts

Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1 leads to a Denial of Service (DoS) within the application.

thehackerwire@mastodon.social at 2026-09-21T22:02:46.000Z ##

🟠 CVE-2026-88411 - High (7.5)

Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1 leads to a Denial of Service (DoS) within the application.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88409
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-22T20:00:03.713000

1 posts

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix function (/v19/decode_matrix.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

thehackerwire@mastodon.social at 2026-09-21T22:02:37.000Z ##

🟠 CVE-2026-88409 - High (8.8)

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix function (/v19/decode_matrix.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94084
(9.4 CRITICAL)

EPSS: 0.40%

updated 2026-09-22T19:44:01.280000

1 posts

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

cR0w@infosec.exchange at 2026-09-21T13:27:36.000Z ##

RE: infosec.exchange/@suricata/117

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

##

CVE-2026-25254
(9.8 CRITICAL)

EPSS: 0.73%

updated 2026-09-22T19:37:36.747000

1 posts

Improper authorization leads to Remote Code Execution via SocketIO interface.

offseq@infosec.exchange at 2026-09-22T10:30:25.000Z ##

Qualcomm Snapdragon devices hit by CRITICAL CVE-2026-25254: improper authorization in SocketIO allows unauthenticated RCE. No patch yet; monitor advisories and review exposure. CVSS 9.8. radar.offseq.com/threat/cve-20 #OffSeq #CVE202625254 #Snapdragon #Infosec #Vuln

##

CVE-2026-84239
(7.6 HIGH)

EPSS: 0.41%

updated 2026-09-22T19:32:25.730000

1 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

hugovalters@mastodon.social at 2026-09-24T10:40:40.000Z ##

CVE-2026-84239 IBM Guardium Data Protection 12.2 SQL injection lets authenticated attackers pull sensitive data. CVSS 7.6, no patch yet. Harden access and monitor until IBM ships a fix. valtersit.com/cve/CVE-2026-842 #CVE #infosec #IBM

##

CVE-2026-19658
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-09-22T19:04:55.677000

1 posts

The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1 via deserialization of untrusted input . This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is i

1 repos

https://github.com/murrez/CVE-2026-19658

offseq@infosec.exchange at 2026-09-22T06:00:28.000Z ##

LiquidWeb Give Tributes <=2.3.1 is vulnerable (CVE-2026-19658, CRITICAL) to PHP Object Injection via unsafe deserialization. Only exploitable if a POP chain is present from other plugins/themes. Mitigate by disabling "Allow Multiple Recipients" or enabling eCard msg. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202619658

##

CVE-2026-81642
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-09-22T18:59:21.953000

2 posts

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerabili

1 repos

https://github.com/suominen/CVE-2026-81642

CVE-2026-89275
(10.0 CRITICAL)

EPSS: 1.25%

updated 2026-09-22T18:33:43

1 posts

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

thehackerwire@mastodon.social at 2026-09-22T19:04:18.000Z ##

🔴 CVE-2026-89275 - Critical (10)

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94099
(9.9 CRITICAL)

EPSS: 1.69%

updated 2026-09-22T16:18:17.183000

1 posts

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was c

offseq@infosec.exchange at 2026-09-21T13:30:28.000Z ##

CVE-2026-94099 | Netcore NBR200V2 (1.3.241127.071246): CRITICAL command injection via restore.cgi (QUERY_STRING). Remote exploit, no patch, vendor silent. Isolate devices & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #Netcore #CVE202694099 #infosec

##

CVE-2026-95675
(9.8 CRITICAL)

EPSS: 3.91%

updated 2026-09-22T15:32:43

1 posts

D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device to persistently modify its configuration and use it as a pivot point into the loc

DailyCyberSecurity@infosec.exchange at 2026-09-23T00:38:45.000Z ##

Technical details and a PoC for the D-Link DAP-1360 vulnerability (CVE-2026-95675) are public. Learn how this unauthenticated flaw impacts legacy routers.

#DLink #DAP1360 #CVE202695675 #RCE #RouterSecurity #Cybersecurity

securityonline.info/d-link-dap

##

CVE-2026-65113
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-09-22T15:32:43

1 posts

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure.

CVE-2026-84388
(9.6 CRITICAL)

EPSS: 0.38%

updated 2026-09-22T15:32:41

1 posts

A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack

1 repos

https://github.com/ShadowForge-Cyber/CVE-2026-84388-POC

CVE-2026-88406
(7.5 HIGH)

EPSS: 0.27%

updated 2026-09-22T15:32:31

1 posts

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses function (/ast/ast_validations.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

thehackerwire@mastodon.social at 2026-09-21T22:03:55.000Z ##

🟠 CVE-2026-88406 - High (7.5)

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses function (/ast/ast_validations.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-7273
(8.8 HIGH)

EPSS: 2.41%

updated 2026-09-22T12:10:51.067000

7 posts

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

beyondmachines1@infosec.exchange at 2026-09-23T10:01:13.000Z ##

Zyxel GS1900 Switches Targeted by Chinese Threat Actor in Data Theft Campaign

Zyxel GS1900 series switches are under active exploitation by a Chinese threat actor using a high-severity buffer overflow (CVE-2026-7273) to steal sensitive data from nearly 1,000 devices worldwide. The campaign has compromised government records and relies on unpatched firmware and default credentials to gain system control.

**If you have Zyxel GS1900 series switches, make sure their management interface is isolated from the internet, accessible from trusted networks only and all default passwords are changed. Then update the firmware to version 2.90(xxxx.2)C0 or later ASAP and check the switches for signs of breach. Attackers are actively exploiting this flaw.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

jbhall56@infosec.exchange at 2026-09-22T11:48:40.000Z ##

The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating system (OS) command execution. thehackernews.com/2026/09/zyxe

##

cyberworldops@infosec.exchange at 2026-09-22T10:40:00.000Z ##

CISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 CGI handling, to KEV on Sept 21, 2026 after confirmed active exploitation. Unauthenticated LAN HTTP requests can yield OS command execution, risking switch takeover and lateral movement. #Zyxel #KnownExploitedVulnerabilities #NetworkSecurity

cyberworldops.eu/en/actively-e

##

cyberworldops@infosec.exchange at 2026-09-22T08:30:01.000Z ##

Zyxel GS1900 switches (CVE-2026-7273) and Veeam Agent for Microsoft Windows (CVE-2026-32996) are under active exploitation. The former allows unauthenticated LAN command execution via CGI buffer overflow, the latter enables SYSTEM-level access on endpoints. Both expand persistence and backup tampering risk. #Zyxel #Veeam #ThreatIntel #VulnManagement

cyberworldops.eu/en/active-att

##

thecybermind@infosec.exchange at 2026-09-21T23:33:43.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-7273 – Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

Analyze the executive impact of CVE-2026-7273 with our strategic Zyxel CSUITE brief, covering zero-trust network segmentation, asset risk assessment, and CISA compliance....

thecybermind.co/18gk

##

secdb@infosec.exchange at 2026-09-21T21:00:18.000Z ##

🚨 [CISA-2026:0921] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-7273 (secdb.nttzen.cloud/cve/detail/)
- Name: Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Zyxel
- Product: GS1900 Series Switches
- Notes: zyxel.com/global/en/support/se ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260921 #cisa20260921 #cve_2026_7273 #cve20267273

##

cisakevtracker@mastodon.social at 2026-09-21T20:00:49.000Z ##

CVE ID: CVE-2026-7273
Vendor: Zyxel
Product: GS1900 Series Switches
Date Added: 2026-09-21
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-13355
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-09-22T06:30:35

1 posts

The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-frontend-submission component unconditionally overrides the form's target object_id from the GET parameter 'rwmb_frontend_field_object_id' without any authorization check, and Form::p

1 repos

https://github.com/murrez/CVE-2026-13355

offseq@infosec.exchange at 2026-09-22T07:30:24.000Z ##

Privilege escalation (CRITICAL, CVE-2026-13355) in Meta Box Frontend Submission <=4.5.6 & User Profile <=3.11.0 lets unauthenticated attackers gain admin on WordPress. Patch status TBD — restrict plugin use & monitor activity. Details: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026_13355

##

CVE-2026-94301
(9.8 CRITICAL)

EPSS: 0.39%

updated 2026-09-22T04:18:02.810000

1 posts

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the  2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed a

cR0w@infosec.exchange at 2026-09-21T15:49:50.000Z ##

sev:CRIT bypass of CVE-2026-47065 in Apache MINA.

nvd.nist.gov/vuln/detail/cve-2

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the 2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close.

##

CVE-2026-94493
(10.0 CRITICAL)

EPSS: 0.73%

updated 2026-09-22T03:31:06

1 posts

A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebSocket Service. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

offseq@infosec.exchange at 2026-09-22T01:30:25.000Z ##

CVE-2026-94493 (CRITICAL, CVSS 10) in Gigatech PDV5701 1.0.31_240305_112640: WebSocket Service has missing authentication. Remote exploit is public, no vendor fix. Isolate devices, monitor for attacks. radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoTSecurity

##

CVE-2026-94540
(7.7 HIGH)

EPSS: 0.11%

updated 2026-09-22T00:31:02

1 posts

DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can exploit the unauthenticated local service through same-device loopback to perform

thehackerwire@mastodon.social at 2026-09-22T00:01:22.000Z ##

🟠 CVE-2026-94540 - High (7.7)

DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local servi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94627
(7.5 HIGH)

EPSS: 0.45%

updated 2026-09-22T00:31:02

1 posts

vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments. Attackers can trigger GPU memory exhaustion by submitting completion requests with multiple prompts, causing orphaned KV cache blocks to accumulate until process restart and eventually preventing legitima

thehackerwire@mastodon.social at 2026-09-22T00:01:13.000Z ##

🟠 CVE-2026-94627 - High (7.5)

vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments. Attackers can trigger GPU memory exhaustion by subm...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94425
(8.8 HIGH)

EPSS: 0.11%

updated 2026-09-22T00:31:02

2 posts

A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_140006F0C in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation results in improper privilege management. Attacking locally is a requirement. The vendor was contacted early about this disclosure but did not respond in any way.

thehackerwire@mastodon.social at 2026-09-22T00:01:02.000Z ##

🟠 CVE-2026-94425 - High (8.8)

A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_140006F0C in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation results in improper privilege management. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-22T00:00:35.000Z ##

CVE-2026-94425 (CRITICAL, CVSS 9.3) hits Moore Threads MTT S80 Driver v340.150 🛡️. Improper privilege management in IOCTL Handler allows local escalation. No patch yet. Limit local access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #Vuln #PrivilegeEscalation #Infosec

##

CVE-2026-12249
(9.0 None)

EPSS: 0.14%

updated 2026-09-21T22:27:11

1 posts

An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Samba client script (internal/policies/certificate/python/vendor_samba/gp/gp_cert_auto_enroll_ext.py), ADSys utilizes a plaintext HTTP connection (http://) instead of a secure HTTPS connection (https://) to request the CA ce

beyondmachines1@infosec.exchange at 2026-09-23T09:01:13.000Z ##

Canonical Patches Critical Trust Store Poisoning Flaw in ADSys

Canonical patched a critical vulnerability (CVE-2026-12249) in ADSys that allows attackers to poison the Ubuntu system trust store by intercepting unencrypted certificate enrollment requests. This flaw enables persistent decryption of TLS traffic and full compromise of encrypted communications on affected hosts.

**If you manage Ubuntu machines connected to Active Directory through ADSys, update ADSys to version 0.16.3 or later on all of them. Oder versions fetch certificates over unencrypted HTTP and let an attacker plant a fake root certificate that exposes all encrypted traffic on the machine. After updating, check each machine's trusted certificates for any unfamiliar root certificates and remove them, since a machine that was already compromised stays exposed even after the patch.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-81469
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-21T21:32:01

1 posts

Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of Privileges

thehackerwire@mastodon.social at 2026-09-21T21:00:59.000Z ##

🟠 CVE-2026-81469 - High (7.8)

Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94501
(8.8 HIGH)

EPSS: 0.30%

updated 2026-09-21T21:32:00

1 posts

jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without privilege checks. Attackers can manipulate user-role mappings and access controls to escalate privileges, strip access from other accounts, or modify role-function relationships for any user in the tena

thehackerwire@mastodon.social at 2026-09-21T20:00:56.000Z ##

🟠 CVE-2026-94501 - High (8.8)

jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without privilege checks. Attackers can manipulate user-r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94424
(8.8 HIGH)

EPSS: 0.14%

updated 2026-09-21T21:31:57

1 posts

A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way.

thehackerwire@mastodon.social at 2026-09-21T22:02:26.000Z ##

🟠 CVE-2026-94424 - High (8.8)

A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overflow. An att...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93958
(9.1 CRITICAL)

EPSS: 2.17%

updated 2026-09-21T19:17:18.593000

1 posts

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.

1 repos

https://github.com/HackSpeak/CVE-2026-93958

CVE-2026-79920
(9.9 CRITICAL)

EPSS: 0.36%

updated 2026-09-21T19:17:11.323000

1 posts

Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-management authorization. InstallPlugin and UnInstallPlugin construct a pip package specification from unvalidated name and version fields, and the task worker invokes

thehackerwire@mastodon.social at 2026-09-21T18:01:21.000Z ##

🔴 CVE-2026-79920 - Critical (9.9)

Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-management aut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61674
(0 None)

EPSS: 0.65%

updated 2026-09-21T19:17:07.067000

2 posts

Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. From 0.11.0 until 5.0.8, plugins/out_forward/forward.c secure_forward_pong copies the server-controlled PONG[2] reason into the 32-byte stack buffer msg with memcpy without checking its MessagePack type or length. An attacker who controls or can impersonate an out_forward Secure Forward des

DailyCyberSecurity at 2026-09-24T01:09:00.228Z ##

Technical details and a PoC for a critical Fluent Bit vulnerability (CVE-2026-61674) are public. Patch this Fluent Bit vulnerability to prevent RCE attacks.

securityonline.info/fluent-bit

##

DailyCyberSecurity@infosec.exchange at 2026-09-24T01:09:00.000Z ##

Technical details and a PoC for a critical Fluent Bit vulnerability (CVE-2026-61674) are public. Patch this Fluent Bit vulnerability to prevent RCE attacks.

#FluentBit #CVE202661674 #BufferOverflow #RCE #Cybersecurity #InfoSec

securityonline.info/fluent-bit

##

CVE-2026-80521
(7.8 HIGH)

EPSS: 0.13%

updated 2026-09-21T15:32:39

3 posts

In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially. The scenario is as follows: 1) Create two SCCs: X -. A <-> B ^--' 2) Run the following concurrently: 2-1) send() sk-B to sk-B from sk-X 2-2) close() both A and B At 2-1), there is a sm

1 repos

https://github.com/Markakd/Container_escape

undercodenews@mastodon.social at 2026-09-24T02:03:17.000Z ##

Public Exploit for Linux Kernel Container Escape Could Turn Container Compromise Into Host Root + Video

A Serious New Development for Container Security A newly published Linux kernel exploit has raised the stakes for organizations running Docker, Kubernetes, and other containerized workloads. Researchers at DepthFirst have released technical details and exploit code for CVE-2026-80521, a Linux kernel AF_UNIX use-after-free vulnerability that can allow an attacker…

undercodenews.com/public-explo

##

sigint@fosstodon.org at 2026-09-23T23:45:06.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-09-24

CVE-2026-80521, an AF_UNIX use-after-free, is patched upstream but still unfixed on Ubuntu 22.04/24.04/26.04 with public exploit code out. If you run containers on Ubuntu hosts, this is a real priority-patch-now situation, not theoretical.

🔗 thehackernews.com/2026/09/expl

#Ubuntu #Linux #infosec

##

guru@thecybersecguru.com at 2026-09-23T12:54:00.000Z ##

Exploit released for unpatched Ubuntu kernel flaw that lets containers root the host (CVE-2026-80521)

CVE-2026-80521 is a Linux kernel AF_UNIX use-after-free that enables container escape to host root. Ubuntu 22.04, 24.04 and 26.04 remain vulnerable

thecybersecguru.com/news/cve-2

##

CVE-2026-82187
(9.8 CRITICAL)

EPSS: 0.30%

updated 2026-09-21T15:17:32.223000

1 posts

The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.

offseq@infosec.exchange at 2026-09-21T09:00:25.000Z ##

Web to Print Online Designer plugin (v1.7.0 – 2.14.9) hit by CRITICAL CVE-2026-82187: unauthenticated attackers can upload & execute arbitrary files (incl. PHP), leading to RCE. Upgrade to 2.15.0+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202682187 #RCE

##

CVE-2026-10747
(10.0 CRITICAL)

EPSS: 0.52%

updated 2026-09-21T13:17:07.147000

1 posts

IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.

censys@infosec.exchange at 2026-09-21T16:20:25.000Z ##

🚨 RAPID RESPONSE: IBM MQ Pre-Authentication RCE [CVE-2026-10747]

A critical heap buffer overflow in IBM MQ could allow remote code execution before authentication. CVSS: 10.0.

Censys ARC observes IBM MQ web consoles on 120 hosts and 149 web properties Internet-wide. These numbers indicate IBM MQ presence, not confirmed vulnerable systems.

IBM has released fixes for affected MQ Server and MQ Appliance versions. No public PoC or reported active exploitation is known at this time.

Read the full analysis for affected versions, Internet observations, and remediation guidance. censys.com/advisory/cve-2026-1

#CensysARC #IBMMQ #Cybersecurity #Vulnerability

##

CVE-2026-94101
(9.9 CRITICAL)

EPSS: 0.45%

updated 2026-09-21T03:30:27

1 posts

A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did

offseq@infosec.exchange at 2026-09-21T12:00:26.000Z ##

Netcore NBR200V2 (v1.3.241127.071246) hit by CRITICAL CVE-2026-94101 buffer overflow in /usr/bin/routerd. Remote code exec possible. Public exploit, no patch. Restrict remote access ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Netcore #RouterSecurity #Infosec

##

CVE-2026-86553
(8.5 HIGH)

EPSS: 0.45%

updated 2026-09-20T06:30:20

1 posts

SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/verify.serv to obtain the real account ID corresponding to a registered email address. By spoofing the application authentication information together wi

1 repos

https://github.com/minanagehsalalma/zte-smartlife-app-pwned

_r_netsec@infosec.exchange at 2026-09-21T16:43:05.000Z ##

ZTE SmartHome Account Takeover: Password Reset Without Verification Code. 4 CVEs, 100K+ Android Downloads - CVE-2026-86553 minanagehsalalma.github.io/zte

##

CVE-2026-94083
(9.4 CRITICAL)

EPSS: 0.40%

updated 2026-09-20T03:30:29

1 posts

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.

cR0w@infosec.exchange at 2026-09-21T13:27:36.000Z ##

RE: infosec.exchange/@suricata/117

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

##

CVE-2026-93485
(7.1 HIGH)

EPSS: 0.16%

updated 2026-09-19T15:17:08.323000

1 posts

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.1

2 repos

https://github.com/HORKimhab/CVE-2026-93485

https://github.com/0xBlackash/CVE-2026-93485

DailyCyberSecurity@infosec.exchange at 2026-09-23T12:59:52.000Z ##

Details and PoC exploit code for a critical WordPress stored XSS are public. Learn how CVE-2026-93485 enables RCE and patch WordPress today.

#WordPress #CVE202693485 #StoredXSS #RCE #Cybersecurity #Infosec

securityonline.info/wordpress-

##

CVE-2026-61817
(8.5 HIGH)

EPSS: 0.58%

updated 2026-09-19T15:16:59.910000

1 posts

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance(), show_partitions(), show_partition_info(), undo_partition(), and partition_data_time() interpolate the writable part_config.time_dncoder text value without identifier quoting into dynamic SQL. A role with the documented partman_user privileges can store SQL rather than a decoder fu

hugovalters@mastodon.social at 2026-09-24T04:30:08.000Z ##

CVE-2026-61817: SQL injection in pg_partman before 5.5.0. A partman_user role can poison part_config and inject SQL through run_maintenance. CVSS 8.5, no patch yet. Restrict that role until 5.5.0 lands. valtersit.com/cve/CVE-2026-618 #CVE #infosec #PostgreSQL

##

CVE-2026-53266
(8.8 HIGH)

EPSS: 0.28%

updated 2026-09-19T04:17:53.580000

2 posts

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Aski

2 repos

https://github.com/mc493/linux-kernel-zero-day-mitigation-zero-downtime-kernel-defense-

https://github.com/suominen/CVE-2026-53266

thecybermind@infosec.exchange at 2026-09-21T18:47:53.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-53266 – Linux Kernel Out-of-Bounds Write Vulnerability

Analyze the executive impact of CVE-2026-53266 with our strategic Linux CSUITE brief, covering kernel out-of-bounds write risks, compliance assurance, and board-level risk communication....

thecybermind.co/n7ln

##

cyberworldops@infosec.exchange at 2026-09-21T10:40:00.000Z ##

CISA added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its KEV catalog after exploitation was reported. The flaws affect TLS, AF_ALG, and ebtables SNAT, with CVSS scores up to 9.8, making rapid exposure assessment and patch validation essential. #LinuxSecurity #VulnerabilityManagement #KEV

cyberworldops.eu/en/three-expl

##

CVE-2026-88097
(8.1 HIGH)

EPSS: 0.22%

updated 2026-09-18T21:32:43

1 posts

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

hugovalters@mastodon.social at 2026-09-24T07:40:01.000Z ##

CVE-2026-88097: Use-after-free in Microsoft Edge lets a local attacker elevate privileges. CVSS 8.1, patch still under review. Limit exposure and watch for updates. valtersit.com/cve/CVE-2026-880 #Microsoft #infosec #CVE

##

CVE-2026-84086
(7.2 HIGH)

EPSS: 0.65%

updated 2026-09-18T21:32:40

1 posts

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

hugovalters@mastodon.social at 2026-09-24T03:20:19.000Z ##

CVE-2026-84086: IBM Guardium Data Protection 12.2 path traversal lets remote authenticated attackers run arbitrary code. CVSS 7.2, no patch. Restrict access now. valtersit.com/cve/CVE-2026-840 #CVE #infosec #IBM

##

CVE-2026-84085
(8.1 HIGH)

EPSS: 0.32%

updated 2026-09-18T21:32:39

1 posts

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

hugovalters@mastodon.social at 2026-09-24T06:00:49.000Z ##

CVE-2026-84085 IBM Guardium Data Protection 12.2 RCE via OS command injection, CVSS 8.1, no patch yet. Isolate affected systems and restrict access now: valtersit.com/cve/CVE-2026-840 #CVE #infosec #IBM

##

CVE-2026-81937
(7.2 HIGH)

EPSS: 1.45%

updated 2026-09-18T21:32:35

1 posts

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can inject shell commands through the filename parameter, potentially resulting in arbitrary command execution with root privileges and impact to the confidentiality, integrity, and availability of the affected system.

hugovalters@mastodon.social at 2026-09-24T03:10:56.000Z ##

CVE-2026-81937: command injection in IBM Guardium Data Protection 12.2 lets a privileged user run shell commands as root via the import remotelog_config filename. CVSS 7.2. No patch yet - restrict CLI access and watch for vendor valtersit.com/cve/CVE-2026-819 #CVE #infosec #IBM

##

CVE-2025-39682
(7.1 HIGH)

EPSS: 2.03%

updated 2026-09-18T21:31:33

1 posts

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next record has different type than what has already been processed we break out of the main processing loop. If the record has already been decrypted

3 repos

https://github.com/suominen/CVE-2025-39682

https://github.com/mc493/linux-kernel-zero-day-mitigation-zero-downtime-kernel-defense-

https://github.com/khoatran107/cve-2025-39682

cyberworldops@infosec.exchange at 2026-09-21T10:40:00.000Z ##

CISA added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its KEV catalog after exploitation was reported. The flaws affect TLS, AF_ALG, and ebtables SNAT, with CVSS scores up to 9.8, making rapid exposure assessment and patch validation essential. #LinuxSecurity #VulnerabilityManagement #KEV

cyberworldops.eu/en/three-expl

##

CVE-2026-13639
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-09-18T20:17:06.860000

1 posts

An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.

cyberveille@mastobot.ping.moi at 2026-09-22T07:30:06.000Z ##

📢 [VULN] Alerte sécurité : deux vulnérabilités majeures menacent vos NAS Synology - CVE-2026-13684 CVE-2026-13639

Huit vulnérabilités viennent d'être identifiées dans le système d'exploitation DiskStation Manager de Synology, dont deux atteignent un score de gravité maximal de 9.8. Ces failles critiques permettent à des attaquants distants de lire, d'écrire ou d'effacer vos fichiers sans aucune…

🔗 generation-nt.com/actualites/a
💬 discussion : infosec.pub/post/52624526
#Vulnérabilité #CVE #Cyberveille

##

CVE-2026-90898
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-09-18T19:31:11.370000

1 posts

Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user

1 repos

https://github.com/HORKimhab/CVE-2026-90898

sipirtu@mastodon.social at 2026-09-24T11:08:28.000Z ##

A critical vulnerability in the open-source Bifrost AI gateway lets unauthenticated attackers execute arbitrary commands on servers.

Source: TechJuice
techjuice.pk/bifrost-ai-gatewa

#AI

##

CVE-2026-19499
(7.7 HIGH)

EPSS: 0.38%

updated 2026-09-18T18:17:47.257000

1 posts

Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the int

hugovalters@mastodon.social at 2026-09-22T03:30:31.000Z ##

CVE-2026-19499: glibc 2.38-2.44 strfmon buffer overflow via right-justified padding. CVSS 7.7. Unpatched. Audit risky calls, update now.
valtersit.com/cve/CVE-2026-194
#CVE #infosec #glibc

##

CVE-2026-85058
(7.5 HIGH)

EPSS: 0.27%

updated 2026-09-18T17:58:41

1 posts

## Summary Moquette MQTT Broker fails to enforce ACL write permission checks when publishing Will (Last Will and Testament) messages on behalf of disconnected clients. All normal PUBLISH paths (`receivedPublishQos0`, `receivedPublishQos1`, `receivedPublishQos2`) correctly invoke `authorizator.canWrite()` before publishing, but the Will message publishing path (`fireWill()` → `publishWill()` → `pu

hugovalters@mastodon.social at 2026-09-24T03:50:03.000Z ##

CVE-2026-85058 Moquette MQTT broker: Last Will path skips canWrite ACL check, letting remote clients inject messages into protected topics. CVSS 7.5. No patch confirmed yet. Restrict anonymous access now. valtersit.com/cve/CVE-2026-850 #CVE #infosec #MQTT

##

CVE-2025-39964
(3.3 LOW)

EPSS: 0.79%

updated 2026-09-18T15:31:06

2 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates

3 repos

https://github.com/n1k0oowang/CVE-2025-39964_EXP

https://github.com/suominen/CVE-2025-39964

https://github.com/mc493/linux-kernel-zero-day-mitigation-zero-downtime-kernel-defense-

thecybermind@infosec.exchange at 2026-09-21T12:02:57.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2025-39964 – Linux Kernel Race Condition Vulnerability

Analyze the mechanics of CVE-2025-39964 with our technical Linux TSUITE brief, covering AF_ALG race conditions, CrowdStrike CQL queries, and endpoint hardening....

thecybermind.co/dxag

##

cyberworldops@infosec.exchange at 2026-09-21T10:40:00.000Z ##

CISA added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its KEV catalog after exploitation was reported. The flaws affect TLS, AF_ALG, and ebtables SNAT, with CVSS scores up to 9.8, making rapid exposure assessment and patch validation essential. #LinuxSecurity #VulnerabilityManagement #KEV

cyberworldops.eu/en/three-expl

##

CVE-2026-13684
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-09-18T09:31:20

1 posts

An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.

cyberveille@mastobot.ping.moi at 2026-09-22T07:30:06.000Z ##

📢 [VULN] Alerte sécurité : deux vulnérabilités majeures menacent vos NAS Synology - CVE-2026-13684 CVE-2026-13639

Huit vulnérabilités viennent d'être identifiées dans le système d'exploitation DiskStation Manager de Synology, dont deux atteignent un score de gravité maximal de 9.8. Ces failles critiques permettent à des attaquants distants de lire, d'écrire ou d'effacer vos fichiers sans aucune…

🔗 generation-nt.com/actualites/a
💬 discussion : infosec.pub/post/52624526
#Vulnérabilité #CVE #Cyberveille

##

CVE-2026-76460
(10.0 CRITICAL)

EPSS: 0.78%

updated 2026-09-17T12:46:31.670000

2 posts

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized ac

1 repos

https://github.com/S3v3n-JG/CVE-2026-76460

thecybermind at 2026-09-24T09:40:51.452Z ##

(CISA TS-MAN) The Cyber Mind TSUITE Brief: CVE-2026-76460 – Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

Analyze the technical mechanics of CVE-2026-76460 with our Cisco TSUITE brief, covering Cisco ISE authentication bypass, path traversal vectors, and endpoint hardening....

thecybermind.co/9ysa

##

thecybermind@infosec.exchange at 2026-09-24T09:40:51.000Z ##

(CISA TS-MAN) The Cyber Mind TSUITE Brief: CVE-2026-76460 – Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

Analyze the technical mechanics of CVE-2026-76460 with our Cisco TSUITE brief, covering Cisco ISE authentication bypass, path traversal vectors, and endpoint hardening....

thecybermind.co/9ysa

##

CVE-2026-79994
(0 None)

EPSS: 0.11%

updated 2026-09-16T20:38:33.883000

1 posts

The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a symlink between validation and connection, causing the host to connect to an arbitrary AF_UNIX socket outside the shared workspace. This can expose data or host-side cap

CVE-2026-58704
(8.0 HIGH)

EPSS: 0.21%

updated 2026-09-16T15:30:57

1 posts

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

hackmag@infosec.exchange at 2026-09-21T15:30:23.000Z ##

⚪️ Google Patches Zero-Day Vulnerability in Pixel Devices

🗨️ Google has released September patches for Pixel smartphones, fixing 110 vulnerabilities. Among them is a zero-day flaw found in the cellular modem (CVE-2026-58704). The company warned that the issue is already being exploited by hackers in targeted attacks. CVE-2026-58704 has…

🔗 hackmag.com/news/pixel-0-day?u

#news

##

CVE-2026-77179(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-09-16T00:32:25

1 posts

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.

1 repos

https://github.com/HORKimhab/CVE-2026-77179

CVE-2026-43783
(7.8 HIGH)

EPSS: 0.15%

updated 2026-09-15T19:24:16.433000

2 posts

A race condition was addressed with improved locking. This issue is fixed in macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

1 repos

https://github.com/andrd3v/CVE-2026-43783

CVE-2026-59570
(7.5 HIGH)

EPSS: 0.09%

updated 2026-09-14T15:32:56

1 posts

On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.

hugovalters@mastodon.social at 2026-09-24T02:30:23.000Z ##

CVE-2026-59570 Zscaler client connector: a peer app can kill the tunnel, force logout, toggle packet capture. CVSS 7.5, no patch yet. Limit third-party apps and watch for updates. valtersit.com/cve/CVE-2026-595 #CVE #infosec #Zscaler

##

CVE-2026-86060
(9.8 CRITICAL)

EPSS: 1.06%

updated 2026-09-11T15:32:27

1 posts

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable

2 repos

https://github.com/bahirul/cve-2026-86060

https://github.com/digiprosec/MicroTrick

undercodenews@mastodon.social at 2026-09-24T00:57:08.000Z ##

MikroTik “MikroTrick” Attack Chain Lets Hackers Take Full Router Control Without a Password

Introduction A serious security warning from CERT Polska highlights a dangerous attack chain affecting MikroTik RouterOS devices. Two vulnerabilities—CVE-2026-67279 and CVE-2026-86060—can reportedly be chained together to achieve full administrative control of an Internet-exposed MikroTik router without knowing the administrator's password or possessing an SSH key. The discovery…

undercodenews.com/mikrotik-mik

##

CVE-2026-85103
(9.8 CRITICAL)

EPSS: 0.36%

updated 2026-09-10T04:18:18.390000

2 posts

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

beyondmachines1 at 2026-09-24T08:01:13.483Z ##

Check Point VPN Gateways and Management Server Flaws Actively Exploited

Check Point confirmed active exploitation of three critical vulnerabilities (CVE-2026-85102, CVE-2026-85103, and CVE-2026-93616) affecting VPN gateways and management servers, prompting a 72-hour US federal remediation deadline.

**If you run Check Point Security Gateways, Spark Firewalls or Security Management Servers, patch immediately to LivePatch Take 26 or the latest Jumbo Hotfix. Older unsupported versions R80 through R81.10 must be upgraded first. Make sure the management server's web interface is reachable only from trusted internal networks. Patching isn't enough, since attackers have been active since September 12: check your VPN logs for unknown sessions and internal LDAP scanning, and if you find anything suspicious, treat the device as compromised and escalate to your incident response team.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-24T08:01:13.000Z ##

Check Point VPN Gateways and Management Server Flaws Actively Exploited

Check Point confirmed active exploitation of three critical vulnerabilities (CVE-2026-85102, CVE-2026-85103, and CVE-2026-93616) affecting VPN gateways and management servers, prompting a 72-hour US federal remediation deadline.

**If you run Check Point Security Gateways, Spark Firewalls or Security Management Servers, patch immediately to LivePatch Take 26 or the latest Jumbo Hotfix. Older unsupported versions R80 through R81.10 must be upgraded first. Make sure the management server's web interface is reachable only from trusted internal networks. Patching isn't enough, since attackers have been active since September 12: check your VPN logs for unknown sessions and internal LDAP scanning, and if you find anything suspicious, treat the device as compromised and escalate to your incident response team.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-85880
(7.8 HIGH)

EPSS: 0.57%

updated 2026-09-08T21:34:12

1 posts

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

cyberworldops@infosec.exchange at 2026-09-22T05:10:01.000Z ##

Microsoft shipped its largest patch batch to date with at least 974 fixes, including 113 rated Critical. Two local EoP flaws, CVE-2026-81963 and CVE-2026-85880, are under active exploitation and enable SYSTEM privileges, making immediate triage essential. #PatchTuesday #WindowsSecurity #VulnManagement

cyberworldops.eu/en/microsoft-

##

CVE-2026-81963
(7.8 HIGH)

EPSS: 0.63%

updated 2026-09-08T21:34:09

1 posts

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

cyberworldops@infosec.exchange at 2026-09-22T05:10:01.000Z ##

Microsoft shipped its largest patch batch to date with at least 974 fixes, including 113 rated Critical. Two local EoP flaws, CVE-2026-81963 and CVE-2026-85880, are under active exploitation and enable SYSTEM privileges, making immediate triage essential. #PatchTuesday #WindowsSecurity #VulnManagement

cyberworldops.eu/en/microsoft-

##

CVE-2026-86296
(10.0 CRITICAL)

EPSS: 1.35%

updated 2026-09-08T17:18:39.613000

3 posts

A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

DailyCyberSecurity@infosec.exchange at 2026-09-23T13:31:12.000Z ##

Discover the critical CVE-2026-86296 vulnerability in D-Link DIR-822A routers. Learn how this DHCP flaw allows attackers to execute arbitrary code locally.

#DLink #RouterSecurity #CVE #CyberSecurity #TechNews

meterpreter.org/dlink-dir-822a

##

campuscodi@mastodon.social at 2026-09-22T13:25:37.000Z ##

D-Link warns of two major bugs with public POCs

CVE-2026-86296: supportannouncement.us.dlink.c

POC: tzh00203.notion.site/D-Link-DI

CVE-2026-93958: supportannouncement.us.dlink.c

POC: github.com/FoundTL/D-Link-R95-

##

oversecurity@mastodon.social at 2026-09-22T13:20:34.000Z ##

D-Link warns of max severity zero-day bug in DIR-822A routers

D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch,...

🔗️ [Bleepingcomputer] link.is.it/hXngI9

##

CVE-2026-67279
(0 None)

EPSS: 0.45%

updated 2026-09-08T16:18:10.600000

1 posts

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support

undercodenews@mastodon.social at 2026-09-24T00:57:08.000Z ##

MikroTik “MikroTrick” Attack Chain Lets Hackers Take Full Router Control Without a Password

Introduction A serious security warning from CERT Polska highlights a dangerous attack chain affecting MikroTik RouterOS devices. Two vulnerabilities—CVE-2026-67279 and CVE-2026-86060—can reportedly be chained together to achieve full administrative control of an Internet-exposed MikroTik router without knowing the administrator's password or possessing an SSH key. The discovery…

undercodenews.com/mikrotik-mik

##

CVE-2026-75925
(9.6 CRITICAL)

EPSS: 0.67%

updated 2026-09-08T15:28:33.090000

1 posts

Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralized, which allows additional directives to be introduced into that file. The configuration interface

certvde@infosec.exchange at 2026-09-21T14:13:08.000Z ##

🔒 New CSAF advisory published

VDE-2026-089
Lenze: VPN Client Remote Code Execution in combination with Lenze x500 IoT Gateway
CVE-2026-75925

The Lenze VPN client is vulnerable to a Remote Code Execution. The vulnerability would allow an attacker to perform a remote code execution on the computer running the client with elevated privile…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: lenze.csaf-tp.certvde.com/.wel

#OT #Advisory

##

CVE-2026-50093
(9.0 None)

EPSS: 0.19%

updated 2026-09-08T09:35:45

1 posts

A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.0 (All versions < V4.0.11.2177). A vulnerability in the OIS web module allows an attacker to upload arbitrary files to the server. Successful exploitation of this

beyondmachines1@infosec.exchange at 2026-09-23T08:01:13.000Z ##

Siemens Patches Root-Level File Upload Flaw in Siveillance Control OIS Module

Siemens patched a critical root-level file upload vulnerability (CVE-2026-50093) in the Siveillance Control OIS web module that affects physical security management systems worldwide.

**If you use Siemens Siveillance Control or Control Pro, make sure all these systems are isolated from the internet and the OIS web module is reachable only from trusted internal networks. Then update right away to the fixed version for your edition.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-43499
(7.8 HIGH)

EPSS: 0.79%

updated 2026-09-08T09:18:05.213000

2 posts

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue oper

100 repos

https://github.com/MobiusM/CVE-2026-43499

https://github.com/huaguiqi/asus-i005-cve-2026-43499

https://github.com/fusiondrive/CVE-2026-43499-S24U

https://github.com/Meowkis/tcp-zerocopy-sm

https://github.com/joehquak/Mi8E5-Unlocker-by-CVE-2026-43499

https://github.com/knowlily/cve-2026-43499-honor

https://github.com/boxiaolanya2008/CVE-2026-43499-Neo11Plus

https://github.com/0xBlackash/CVE-2026-43499

https://github.com/NothingFumo/ghostlock-aresin

https://github.com/veygax/HORiZonstack

https://github.com/onesmiledx/CVE-2026-43499

https://github.com/CakesTwix/Android-CVE-2026-43499

https://github.com/ReBiliBin/ghostlock-oppo-watch3pro

https://github.com/ctn-Qvo/CVE-2026-43499-so-build

https://github.com/alex193a/Root-My-Pixel

https://github.com/Thiasap/oppo-pgem10-ghostlock

https://github.com/wxxsfxyzm/GhostLock-Galaxy

https://github.com/gagaltotal/CVE-2026-43499-PoC-Scanner

https://github.com/k-o-n-t-o-r/ghostlock-sabrina

https://github.com/hmascs/KSuRoot

https://github.com/sarabpal-dev/IonStack-S22U

https://github.com/fusiondrive/CVE-2026-43499-A36

https://github.com/eroorvbsyes-hotmail/CVE-2026-43499_x86_Exploit

https://github.com/ctn-Qvo/auto_extract_offsets

https://github.com/BuSung-dev/CVE-2026-43499-S25U

https://github.com/HORKimhab/CVE-2026-43499

https://github.com/BuSung-dev/Root-My-Galaxy

https://github.com/xrzcc/s26-m1q-ghostlock-selinux

https://github.com/SammyEnigma/CVE-2026-43499-S26

https://github.com/inforcqb/CVE-2026-43499-pja110

https://github.com/zhubaohe123/ghostlock-kit

https://github.com/Petalrain224/CVE-2026-43499-Redmi-Turbo5

https://github.com/hui191/cve-2026-43499-aak-an00

https://github.com/oopnv70-lab/ghostlock-honor-aak

https://github.com/Bartixxx32/CVE-2026-43499-OnePlus15

https://github.com/dorlow/hazel-cve-2026-43499

https://github.com/yijiacloud/GhostLock-OPPO-PCKM00

https://github.com/MiaPatsune/cve-2026-43499

https://github.com/Bailan766/rmx3888-cve-2026-43499-config

https://github.com/pubglite55/oppo-ghostlock

https://github.com/fusiondrive/CVE-2026-43499-ZFOLD4

https://github.com/xianwan1314/CVE-2026-43499-Poc-Analysis

https://github.com/ankitrawatgit/iQOO-Z9_5G-vivo-T3_5G-Root-GhostLock

https://github.com/pimpamebanihah/cve-2026-43499-app.so

https://github.com/Bugel/cve-2026-43499-m3q-azf1

https://github.com/233laoliu/mt6985-CVE-2026-43499

https://github.com/Colorful-glassblock/duchamp-root

https://github.com/WitAqua-tools/Root-My-Device

https://github.com/oopnv70-lab/ghostlock-aak-apk

https://github.com/XiaoBaiLovesStirring/ghostlock-k419-adapter

https://github.com/slapah/ghostlock-h8q

https://github.com/tc3650/CVE-2026-43499-armv7

https://github.com/mobilehackinglab/ghostlock-a17

https://github.com/fancyzll/CVE-2026-43499_OPPO-MT6835

https://github.com/justsoman/CVE-2026-43499-jinghu

https://github.com/ccp-p/ghostlock-cve-2026-43499-4.19-k40

https://github.com/yakidango-official/GhostLock-H80GT

https://github.com/Wtrwx/smt878u-ionstack-poc

https://github.com/No-22-Github/UnPlus

https://github.com/gitchw/ghostlock-cve-2026-43499

https://github.com/Linuxoid-cn/Mi8E5-Unlocker-by-CVE-2026-43499

https://github.com/oopnv70-lab/ghostlock-apk

https://github.com/jason5545/ghostlock-myron-tw

https://github.com/p2p3p/GhostLock-for-OnePlus

https://github.com/1ndevelopment/ghostlock-s26

https://github.com/woshimaniubi8/CVE-2026-43499-root-KernelSU

https://github.com/lkeld/CVE-2026-43499-poc

https://github.com/cuteaplane/GhostLock-for-OnePlus15T

https://github.com/dmcdtc/openvz-cve-patch-2026

https://github.com/yijiacloud/ghostlock-cve-2026-43499-4.19-k40

https://github.com/soralis0912/CVE-2026-43499-pmg110-root

https://github.com/HYCQAQ/Logitech-G-Cloud-GhostLock-CVE-2026-43499

https://github.com/CatXiaoShi/cve-2026-43499

https://github.com/hybLOVE/iqoo-temp-root

https://github.com/datfooldive/ghostlock-emerald

https://github.com/x-spy/CVE-2026-43499-popsicle

https://github.com/dnlid/CVE-2026-43499

https://github.com/mumaosong/cve-2026-43499-CyberMeowfia

https://github.com/accessmodifier364/cve-2026-43499-firetv-sheldonp-writeup

https://github.com/YuKongA/ghostlock-app

https://github.com/zenyxx-xd/RootMyVivo

https://github.com/Linuxoid-cn/CVE-2026-43499-Poc-Analysis

https://github.com/soralis0912/CVE-2026-43499-warhol-root

https://github.com/soralis0912/CVE-2026-43499-aristotle-apk

https://github.com/JoinChang/ghostlock-oneplus

https://github.com/Cxyofficial/x200-cve-2026-43499

https://github.com/Bobikl/CVE-2026-43499-T807D

https://github.com/zzzxxxxxxxxxx/GhostLock-GOT-W29

https://github.com/xiaohj233/ghostlock-x200-root

https://github.com/snothin/ghostlock-s26

https://github.com/2932796375github/CVE-2026-43499_OPPO-MT6835

https://github.com/PeronGH/ghostlock-selinux-disabler

https://github.com/caspy123/CVE-2026-43499

https://github.com/XingChenRS/CyberMeowfiaNS

https://github.com/R0rt1z2/GhostLock

https://github.com/sorrow404Null/CVE-2026-43499-RMX5200

https://github.com/soralis0912/CVE-2026-43499-aristotle

https://github.com/hackyangwen-lgtm/rmg-s9180-fzg1

https://github.com/TheAndersMadsen/humane-aipin-ghostlock

https://github.com/NanoTurtle1145/root-my-s24

CVE-2026-78306
(0 None)

EPSS: 0.15%

updated 2026-08-26T16:49:18.760000

1 posts

DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the Wi-Fi PSK with a known value and connect to the drone's internal Wi-Fi network, potentially gaining access to the flight

2 repos

https://github.com/FEEDBEEF/Dji_ble_vuln

https://github.com/Wh02m1/CVE-2026-78306

DailyCyberSecurity@infosec.exchange at 2026-09-23T14:45:15.000Z ##

The DJI Bluetooth vulnerability CVE-2026-78306 lets a nearby attacker send unauthenticated DUML commands to 16 drone models. Update firmware now.

#DJI #CVE202678306 #Bluetooth #DroneSecurity #DUML #CyberSecurity

meterpreter.org/dji-bluetooth-

##

CVE-2026-42945
(8.1 HIGH)

EPSS: 68.05%

updated 2026-08-25T15:33:26

1 posts

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond it

45 repos

https://github.com/soksofos/wazuh-nginx-cve-2026-42945-sca-lab

https://github.com/tal7aouy/nginx-cve-2026-42945

https://github.com/yusufdalbudak/CVE-2026-42945

https://github.com/jelasin/CVE-2026-42945

https://github.com/LiaoZiqi-GZFLS/CVE-2026-42945

https://github.com/imSre9/CVE-2026-42945

https://github.com/nu0l/NGINX-Rift

https://github.com/hnytgl/CVE-2026-42945

https://github.com/Kentox493/CVE-2026-42945_NginxRift

https://github.com/fkj-src/fix_nginx_cve_2026_42945

https://github.com/iammerrida-source/nginx-rift-detect

https://github.com/nanwinata/nginxrift-CVE-2026-42945

https://github.com/FranklinF25/cve-2026-42945

https://github.com/Renison-Gohel/CVE-2026-42945-NGINX-Rift

https://github.com/p3Nt3st3r-sTAr/CVE-2026-42945-POC

https://github.com/chenqin231/CVE-2026-42945

https://github.com/RedCrazyGhost/CVE-2026-42945

https://github.com/CynepMyx/nginx-rift-check

https://github.com/quantumworld-dpdns-io/CVE-2026-42945

https://github.com/BarAppTeam/nginx-cve-fix

https://github.com/limo57640-crypto/nginx-rift-detector

https://github.com/simota/nginx-rift-scanner

https://github.com/aratane/CVE-2026-42945

https://github.com/webdev75950-ux/nginx-rce-cve-2026-42945

https://github.com/hulina9900-boop/DIY-CVE-2026-42945-POC

https://github.com/forxiucn/nginx-cve-2026-42945-poc

https://github.com/MateusVerass/nGixshell

https://github.com/friparia/NGINX_RIFT_SCAN_CVE_2026_42945

https://github.com/oseasfr/Scanner_CVE_2026-42945

https://github.com/byezero/nginx-cve-2026-42945-check

https://github.com/lowilol/CVE-2026-42945-NGINX-Rift-Check-Script

https://github.com/realityone/cve-2026-42945-scan

https://github.com/sec-sys/CVE-2026-42945-Reverse-Shell-POC

https://github.com/ChamsBouzaiene/ai-vuln-rediscovery-nginx-cve-2026-42945

https://github.com/0xBlackash/CVE-2026-42945

https://github.com/sibersan/web-server-audit_CVE-2026-42945

https://github.com/gagaltotal/CVE-2026-42945-NGINX-Rift-Toolkit

https://github.com/strivepan/Nginx_cve-2026-42945-scanner-gui

https://github.com/edgecases-PurpleHax/cve-images

https://github.com/F2u0a0d3/CVE-2026-42945-nginx-rift-poc

https://github.com/rheodev/CVE-2026-42945

https://github.com/josephfelix/CVE-2026-42945-nginx-rift

https://github.com/azilRababe/CVE-2026-42945

https://github.com/cipherspy/CVE-2026-42945-POC

https://github.com/dinosn/cve-2026-42945-nginx32-lab

kubesploit@learnk8s.news at 2026-09-21T19:16:02.000Z ##

Nginx Rift is a proof of concept for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module that allows unauthenticated remote code execution on servers using rewrite and set directives
The README lists affected and fixed versions

➤ ku.bz/PQSlZ7Khl

##

CVE-2026-33824
(9.8 CRITICAL)

EPSS: 72.69%

updated 2026-08-19T04:16:58.560000

1 posts

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

2 repos

https://github.com/kaleth4/CVE-2026-33824

https://github.com/EpSiLoNPoInTOrI/IKEV2-POC

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 50.38%

updated 2026-08-18T18:32:52

2 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

2 repos

https://github.com/HORKimhab/CVE-2026-59310

https://github.com/BiuTrap/CVE-2026-59310

christopherkunz@chaos.social at 2026-09-23T13:06:38.000Z ##

@nyanbinary @cR0w here's one
(from the writeup to CVE-2026-59310 from July/August).
Point at the variables in the picture that traversed your path inappropriately...
mobeta.fr/blog/vcenter-cve-202

##

_r_netsec@infosec.exchange at 2026-09-22T08:13:04.000Z ##

vCenter pre-auth RCE: CVE-2026-59309/59310 mobeta.fr/blog/vcenter-cve-202

##

CVE-2026-55040
(9.1 CRITICAL)

EPSS: 50.59%

updated 2026-08-18T18:32:50

1 posts

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Nuclei template

5 repos

https://github.com/sfewer-r7/CVE-2026-55040

https://github.com/l0ggg/CVE-2026-55040

https://github.com/virologi-info/mssharepoint-scanner

https://github.com/maxprog-svg/CVE-2026-55040-Mass-Exploit

https://github.com/zenzue/CVE-2026-55040

CVE-2026-15830
(5.3 MEDIUM)

EPSS: 1.26%

updated 2026-08-18T16:30:33.827000

2 posts

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spa

djangonews@mastodon.social at 2026-09-23T23:00:08.000Z ##

Django Fellow Report - Jacob

Jacob reviewed six Django pull requests and authored changes covering GEOS 3.10 support removal and expanded WKT depth-check coverage related to CVE-2026-15830. He also worked on security reports and Django coordination...

forum.djangoproject.com/t/djan

##

djangonews@mastodon.social at 2026-09-23T23:00:08.000Z ##

Django Fellow Report - Jacob

Jacob reviewed six Django pull requests and authored changes covering GEOS 3.10 support removal and expanded WKT depth-check coverage related to CVE-2026-15830. He also worked on security reports and Django coordination...

forum.djangoproject.com/t/djan

##

CVE-2026-68820
(7.0 None)

EPSS: 6.18%

updated 2026-08-11T21:33:01

1 posts

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

4 repos

https://github.com/fevar54/CVE-2026-68820-Mitigation-PoC-

https://github.com/HORKimhab/CVE-2026-68820

https://github.com/ubitquity/Windows-WinSock-UAF-Mitigation

https://github.com/maxprog-svg/CVE-2026-68820_Mass_Exploit

CVE-2026-65660
(6.5 MEDIUM)

EPSS: 0.81%

updated 2026-08-11T18:31:43

4 posts

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

oversecurity@mastodon.social at 2026-09-23T10:20:31.000Z ##

Microsoft Upgrades SharePoint Flaw From Spoofing to 8.8 RCE

A SharePoint Server vulnerability tracked as CVE-2026-65660 turned out to be far more serious than Microsoft first indicated. The company

🔗️ [Thecyberexpress] link.is.it/qUvtLM

##

obivan@infosec.exchange at 2026-09-23T08:53:09.000Z ##

SharePoint CVE-2026-65660: From Anonymous Access to Pre-Auth RCE via EditingPageParser Type-Check Bypass blog.viettelcybersecurity.com/

##

guru@thecybersecguru.com at 2026-09-22T14:06:40.000Z ##

Microsoft Called CVE-2026-65660 a Spoofing Bug. It’s an Authenticated SharePoint RCE

CVE-2026-65660 is an authenticated SharePoint RCE, not just spoofing. Learn about the ToolPane flaw, XAML exploit chain, affected versions, and fixes

thecybersecguru.com/news/cve-2

##

cyberworldops@infosec.exchange at 2026-09-22T12:50:01.000Z ##

CVE-2026-65660 reportedly enables authenticated, low-privilege attackers to execute arbitrary code remotely on SharePoint Server. Its initial spoofing classification makes accurate advisory tracking and impact reassessment especially important. #SharePointSecurity #VulnerabilityManagement #ThreatIntelligence

cyberworldops.eu/en/sharepoint

##

kev_Stalker@infosec.exchange at 2026-09-23T19:19:31.000Z ##

CVE-2026-63077 - Changed to Known Ransomware Status

JetBrains TeamCity Deserialization of Untrusted Data VulnerabilityVendor: JetBrainsProduct: TeamCityJetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 23, 2026 at 14:08:17 UTCDate Added nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-39364
(7.5 HIGH)

EPSS: 2.00%

updated 2026-08-04T13:18:24.733000

1 posts

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.

Nuclei template

CVE-2026-59309
(9.8 CRITICAL)

EPSS: 7.94%

updated 2026-07-30T15:31:54

2 posts

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

christopherkunz@chaos.social at 2026-09-23T13:06:38.000Z ##

@nyanbinary @cR0w here's one
(from the writeup to CVE-2026-59310 from July/August).
Point at the variables in the picture that traversed your path inappropriately...
mobeta.fr/blog/vcenter-cve-202

##

_r_netsec@infosec.exchange at 2026-09-22T08:13:04.000Z ##

vCenter pre-auth RCE: CVE-2026-59309/59310 mobeta.fr/blog/vcenter-cve-202

##

CVE-2026-12495
(0 None)

EPSS: 0.17%

updated 2026-07-28T08:17:14.187000

1 posts

Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration se

CVE-2025-68686
(5.9 MEDIUM)

EPSS: 29.60%

updated 2026-07-27T18:31:25

1 posts

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases

CVE-2026-48842
(8.1 HIGH)

EPSS: 0.76%

updated 2026-07-24T10:10:00.197000

3 posts

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

undercodenews@mastodon.social at 2026-09-24T09:01:01.000Z ##

Critical Roundcube Webmail SQL Injection Under Active Attack: What Organizations Need to Know + Video

Roundcube Vulnerability Is Now Being Exploited Threat actors are actively exploiting a critical SQL injection vulnerability in Roundcube Webmail, putting internet-facing email servers at immediate risk. Tracked as CVE-2026-48842, the vulnerability affects Roundcube versions earlier than 1.6.16 and 1.7.1. The Canadian Centre for Cyber Security has confirmed that…

undercodenews.com/critical-rou

##

DailyCyberSecurity at 2026-09-24T03:12:50.316Z ##

An exploited Roundcube Webmail vulnerability allows SQL injection attacks. Learn how CVE-2026-48842 impacts servers and apply the latest patches immediately.

securityonline.info/exploited-

##

DailyCyberSecurity@infosec.exchange at 2026-09-24T03:12:50.000Z ##

An exploited Roundcube Webmail vulnerability allows SQL injection attacks. Learn how CVE-2026-48842 impacts servers and apply the latest patches immediately.

#Roundcube #Cybersecurity #CVE202648842 #Vulnerability #SQLInjection

securityonline.info/exploited-

##

CVE-2026-41091
(7.8 HIGH)

EPSS: 8.20%

updated 2026-07-24T10:10:00.197000

1 posts

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

4 repos

https://github.com/ridhinva/defender-privilege-escalation-scanner

https://github.com/s4m98/RedSun-

https://github.com/tc4dy/CVE-2026-41091-PoC-Exploit

https://github.com/0xBlackash/CVE-2026-41091

CVE-2026-45659
(8.8 HIGH)

EPSS: 76.08%

updated 2026-07-23T11:10:00.120000

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

2 repos

https://github.com/WismanSec/sharepoint-2026-poc

https://github.com/HORKimhab/CVE-2026-45659

CVE-2026-50522
(9.8 CRITICAL)

EPSS: 85.40%

updated 2026-07-22T21:31:51

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

5 repos

https://github.com/WismanSec/sharepoint-2026-poc

https://github.com/ChPratik/CVE-2026-50522

https://github.com/HORKimhab/CVE-2026-50522

https://github.com/darses/CVE-2026-50522

https://github.com/4minx/CVE-2026-50522

CVE-2026-49972
(8.8 HIGH)

EPSS: 1.08%

updated 2026-07-13T21:31:30

3 posts

Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading a file with an embedded PHP extension disguised within a double extension such as shell.php.jpg. The PATHINFO_FILENAME extraction preserves the inner .php extension in the base name, and on misconfigured Apache or nginx servers that execute any file

thehackerwire@mastodon.social at 2026-09-23T23:02:06.000Z ##

🔴 CVE-2026-93352 - Critical (9.8)

Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

EUVD_Bot@mastodon.social at 2026-09-23T23:01:10.000Z ##

🚨 EUVD-2026-85706

📊 Score: 9.3/10 (CVSS v3.1)
📦 Product: laravel-mediable
🏢 Vendor: plank
📅 Updated: 2026-09-23

📝 Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes phpt ...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

thehackerwire@mastodon.social at 2026-09-23T23:02:06.000Z ##

🔴 CVE-2026-93352 - Critical (9.8)

Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47065
(9.8 CRITICAL)

EPSS: 0.50%

updated 2026-07-13T17:24:48

1 posts

ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ), JDK’s ObjectInputStream.readProxyDesc() is dispatched. JDK then calls the default ObjectInputStream.resolveProxyClass(interfaces) implementation, which performs C

cR0w@infosec.exchange at 2026-09-21T15:49:50.000Z ##

sev:CRIT bypass of CVE-2026-47065 in Apache MINA.

nvd.nist.gov/vuln/detail/cve-2

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the 2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close.

##

CVE-2026-21519
(7.8 HIGH)

EPSS: 2.46%

updated 2026-06-17T10:18:46.287000

1 posts

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-21513
(8.8 HIGH)

EPSS: 15.64%

updated 2026-06-17T10:18:45.540000

1 posts

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

CVE-2022-42475
(9.8 CRITICAL)

EPSS: 99.47%

updated 2026-06-17T05:04:59.630000

1 posts

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

9 repos

https://github.com/bryanster/ioc-cve-2022-42475

https://github.com/Mustafa1986/cve-2022-42475-Fortinet

https://github.com/natceil/cve-2022-42475

https://github.com/scrt/cve-2022-42475

https://github.com/uLl0a/cve-2022-42475-poc

https://github.com/ArthurHendrich/CVE-2022-42475-POC

https://github.com/Amir-hy/cve-2022-42475

https://github.com/0xhaggis/CVE-2022-42475

https://github.com/P4x1s/CVE-2022-42475-RCE-POC

CVE-2021-44168
(3.3 LOW)

EPSS: 0.87%

updated 2026-06-17T04:11:59.317000

1 posts

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.

1 repos

https://github.com/0xhaggis/CVE-2021-44168

CVE-2020-4428
(9.1 CRITICAL)

EPSS: 61.69%

updated 2026-06-17T03:19:58.553000

1 posts

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533.

CVE-2026-45756(CVSS UNKNOWN)

EPSS: 0.63%

updated 2026-05-28T17:34:56

1 posts

### Description The `JsonPath` component's `match()` and `search()` filter functions compile a caller-supplied pattern straight into `preg_match()`: ```php 'match' => @preg_match(\sprintf('/^%s$/u', $this->transformJsonPathRegex($argList[1])), $value), 'search' => @preg_match("/{$this->transformJsonPathRegex($argList[1])}/u", $value), ``` `transformJsonPathRegex()` only performs cosmetic escap

_r_netsec@infosec.exchange at 2026-09-22T11:28:04.000Z ##

CVE-2026-45756: attacker-controlled regex in Symfony JsonPath filters (ReDoS) daubois.dev/blog/cve-2026-4575

##

CVE-2026-21525
(6.2 MEDIUM)

EPSS: 5.04%

updated 2026-03-27T21:31:32

1 posts

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

CVE-2026-4575
(2.4 LOW)

EPSS: 0.21%

updated 2026-03-23T06:30:39

1 posts

A flaw has been found in code-projects Exam Form Submission 1.0. This issue affects some unknown processing of the file /admin/update_s2.php. This manipulation of the argument sname causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used.

_r_netsec@infosec.exchange at 2026-09-22T11:28:04.000Z ##

CVE-2026-45756: attacker-controlled regex in Symfony JsonPath filters (ReDoS) daubois.dev/blog/cve-2026-4575

##

CVE-2020-4427
(9.8 CRITICAL)

EPSS: 70.03%

updated 2025-11-04T00:30:30

1 posts

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.

Nuclei template

CVE-2023-48788
(9.8 CRITICAL)

EPSS: 98.45%

updated 2025-10-22T00:34:05

1 posts

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.

1 repos

https://github.com/horizon3ai/CVE-2023-48788

CVE-2023-20118
(7.2 HIGH)

EPSS: 54.11%

updated 2025-10-22T00:33:50

2 posts

A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to improper validation of user input within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted

oversecurity@mastodon.social at 2026-09-23T10:39:29.000Z ##

PolarEdge: Unveiling an uncovered ORB network

Discover PolarEdge, a newly identified botnet targeting edge devices via CVE-2023-20118, using a stealthy TLS backdoor.

🔗️ [Sekoia] link.is.it/PmRTZ9

##

oversecurity@mastodon.social at 2026-09-23T10:38:41.000Z ##

PolarEdge: Unveiling an uncovered ORB network

Discover PolarEdge, a newly identified botnet targeting edge devices via CVE-2023-20118, using a stealthy TLS backdoor.

🔗️ [Sekoia] link.is.it/PmRTZ9

##

CVE-2025-6625
(7.5 HIGH)

EPSS: 0.48%

updated 2025-08-18T09:31:52

1 posts

CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP command is sent to the device.

cyberworldops@infosec.exchange at 2026-09-22T02:50:00.000Z ##

Schneider Electric Modicon M340 controllers and comm modules are vulnerable to DoS via crafted FTP command (CVE-2025-6625, CVSS 7.5, CWE-20). Remote low-complexity exploitation can take OT devices offline, impacting process availability. Apply vendor mitigations and restrict FTP exposure. #IcsSecurity #SchneiderElectric #Cve20256625

cyberworldops.eu/en/crafted-ft

##

CVE-2024-20260
(8.6 HIGH)

EPSS: 0.59%

updated 2024-10-23T18:33:16

1 posts

A vulnerability in the VPN and management web servers of the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv), formerly Cisco Firepower Threat Defense Virtual, platforms could allow an unauthenticated, remote attacker to cause the virtual devices to run out of system memory, which could cause SSL VPN connection processing to slow down and eve

AAKL@infosec.exchange at 2026-09-23T15:33:07.000Z ##

Broadcom has a long list of advisories addressing some critical vulnerabilities, among others support.broadcom.com/web/ecx/s #Broadcom

Cisco:

This addresses high-severity CVE-2024-20260, first published in October.

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2024-0244
(9.8 CRITICAL)

EPSS: 1.38%

updated 2024-02-22T05:08:38

1 posts

Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS MF750C Series/Color imageCLASS X MF1333C firmware v03.07 and earlier sold in US. i-SEN

thezdi@infosec.exchange at 2026-09-23T19:09:09.000Z ##

CVE-2024-0244: Connor Ford details how he exploited the #Canon MF753Cdw printer back when he was a #Pwn2Own contestant. Now he's on the judging side as a ZDI analyst, but Doom is still on the table. zerodayinitiative.com/blog/202

##

beyondmachines1 at 2026-09-24T10:01:13.413Z ##

Vercel Patches Critical Remote Code Execution Vulnerability in Next.js Image Generation Feature

Vercel patched a critical vulnerability (CVE-2026-94545) in Next.js that allows remote code execution through the ImageResponse feature. The flaw involves improper input escaping in the Satori library when processing SVG content on the Node.js runtime.

**If your web apps run Next.js 16 (versions 16.2.0 to 16.3.5), update to 16.3.6 ASAP. Don't rely on dependency scanners to flag this one, because they may miss it. If you can't update right away, make sure your developers sanitize up all user input before it reaches the social preview image feature (ImageResponse).**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-24T10:01:13.000Z ##

Vercel Patches Critical Remote Code Execution Vulnerability in Next.js Image Generation Feature

Vercel patched a critical vulnerability (CVE-2026-94545) in Next.js that allows remote code execution through the ImageResponse feature. The flaw involves improper input escaping in the Satori library when processing SVG content on the Node.js runtime.

**If your web apps run Next.js 16 (versions 16.2.0 to 16.3.5), update to 16.3.6 ASAP. Don't rely on dependency scanners to flag this one, because they may miss it. If you can't update right away, make sure your developers sanitize up all user input before it reaches the social preview image feature (ImageResponse).**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-09-23T07:55:06.000Z ##

Vercel fixed a critical Next.js RCE vulnerability in image generation. Update to patch this Next.js RCE vulnerability and secure your apps.

#Nextjs #CVE202694545 #RCE #Cybersecurity #WebSecurity #Vulnerability

securityonline.info/nextjs-rce

##

CVE-2026-84739
(0 None)

EPSS: 0.00%

2 posts

N/A

bearstech@mamot.fr at 2026-09-24T09:45:00.000Z ##

Toutes nos instances GitLab sont à jour en version 19.4.1 depuis hier soir à 22h.

Il faut mettre à jour rapidement : cette nouvelle version corrige 2 CVE évaluées à 9,9 (CVE-2026-93577 et CVE-2026-84739).

En savoir plus sur nos offres 👇
gitlab-saas.bearstech.com/

##

bearstech@mamot.fr at 2026-09-24T09:45:00.000Z ##

Toutes nos instances GitLab sont à jour en version 19.4.1 depuis hier soir à 22h.

Il faut mettre à jour rapidement : cette nouvelle version corrige 2 CVE évaluées à 9,9 (CVE-2026-93577 et CVE-2026-84739).

En savoir plus sur nos offres 👇
gitlab-saas.bearstech.com/

##

CVE-2026-78902
(0 None)

EPSS: 0.00%

2 posts

N/A

CVE-2026-67231
(0 None)

EPSS: 0.00%

2 posts

N/A

offseq at 2026-09-24T04:30:23.720Z ##

CVE-2026-67231: Critical flaw in rabbitmq-server trust-store plugin (CVSS 9.1) lets attackers bypass TLS client auth with forged certs if they know whitelisted issuer/serial. Patch or disable plugin ASAP. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-24T04:30:23.000Z ##

CVE-2026-67231: Critical flaw in rabbitmq-server trust-store plugin (CVSS 9.1) lets attackers bypass TLS client auth with forged certs if they know whitelisted issuer/serial. Patch or disable plugin ASAP. radar.offseq.com/threat/cve-20 #OffSeq #RabbitMQ #Vuln #TLS #InfoSec

##

CVE-2026-88804
(0 None)

EPSS: 0.00%

2 posts

N/A

DailyCyberSecurity at 2026-09-24T02:50:37.629Z ##

A critical Rancher XSS vulnerability tracked as CVE-2026-88804 exposes admin sessions. Update your clusters immediately to prevent system compromise.

securityonline.info/rancher-xs

##

DailyCyberSecurity@infosec.exchange at 2026-09-24T02:50:37.000Z ##

A critical Rancher XSS vulnerability tracked as CVE-2026-88804 exposes admin sessions. Update your clusters immediately to prevent system compromise.

#Rancher #Kubernetes #CVE202688804 #XSS #Cybersecurity #Infosec

securityonline.info/rancher-xs

##

CVE-2026-96419
(0 None)

EPSS: 0.00%

1 posts

N/A

linuxmint_hun@mastodon.social at 2026-09-24T06:46:10.000Z ##

Megjelent a Wireshark 4.6.9, amely 19 sebezhetőséget és több kritikus összeomlást, végtelen ciklust és memóriaszivárgást javít. Aggódsz, hogy a profilimportálás (CVE-2026-96419) akár kódfuttatást is lehetővé tehetett — frissítettél már? Nézd meg a részleteket és a javítások listáját!

linuxmint.hu/hir/2026/09/a-wir

#Wireshark #CVE2026-96419 #Sharkd #ZigBee #IEEE80211 #LoRaWAN #QUIC #SMB #pcapng #hálózat #sebezhetőség #biztonság

##

CVE-2026-69184
(0 None)

EPSS: 0.68%

1 posts

N/A

hugovalters@mastodon.social at 2026-09-23T20:40:13.000Z ##

CVE-2026-69184 c-ares memory corruption, CVSS 7.5. Malicious DNS server can stall any app using the resolver via crafted compression pointers. Patch to 1.34.7 now. valtersit.com/cve/CVE-2026-691 #CVE #infosec #cybersecurity

##

CVE-2024-85880
(0 None)

EPSS: 0.00%

1 posts

N/A

security_crawler_carl@infosec.exchange at 2026-09-23T04:54:36.000Z ##

🏆 New Achievement! Triple Threat, Zero Regrets!

PATCH NOTES v0.0.0 — KNOWN ISSUES: A China-aligned threat group has successfully shipped a three-zero-day exploit chain targeting Google Chrome and Microsoft Windows. ADDED: coordinated weaponization across CVE-2024-85046, CVE-2024-87491, and CVE-2024-85880. FIXED: nothing on your end, apparently. DEPRECATED: the assumption that one vendor's unpatched flaw is somebody else's problem. (1/2)

##

CVE-2024-85046
(0 None)

EPSS: 0.00%

1 posts

N/A

security_crawler_carl@infosec.exchange at 2026-09-23T04:54:36.000Z ##

🏆 New Achievement! Triple Threat, Zero Regrets!

PATCH NOTES v0.0.0 — KNOWN ISSUES: A China-aligned threat group has successfully shipped a three-zero-day exploit chain targeting Google Chrome and Microsoft Windows. ADDED: coordinated weaponization across CVE-2024-85046, CVE-2024-87491, and CVE-2024-85880. FIXED: nothing on your end, apparently. DEPRECATED: the assumption that one vendor's unpatched flaw is somebody else's problem. (1/2)

##

CVE-2024-87491
(0 None)

EPSS: 0.00%

1 posts

N/A

security_crawler_carl@infosec.exchange at 2026-09-23T04:54:36.000Z ##

🏆 New Achievement! Triple Threat, Zero Regrets!

PATCH NOTES v0.0.0 — KNOWN ISSUES: A China-aligned threat group has successfully shipped a three-zero-day exploit chain targeting Google Chrome and Microsoft Windows. ADDED: coordinated weaponization across CVE-2024-85046, CVE-2024-87491, and CVE-2024-85880. FIXED: nothing on your end, apparently. DEPRECATED: the assumption that one vendor's unpatched flaw is somebody else's problem. (1/2)

##

CVE-2026-89090
(0 None)

EPSS: 0.31%

1 posts

N/A

awssecurityfeed@infosec.exchange at 2026-09-22T20:00:01.000Z ##

CVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v2

Bulletin ID: 2026-110-AWS

Scope: AWS

Content Type: Important (requires attention)

Publication Date: 09/11/2026 10:00 AM PDT
Description:
An issue exists in the the EventStream header decoder in AWS SDK for Go v2 in versio...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-85279
(0 None)

EPSS: 0.21%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-22T19:04:28.000Z ##

🟠 CVE-2026-85279 - High (8.6)

Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in PluginsManager::loadPluginFromPath in PowerEditor/src/MISC/PluginsManager/PluginsManager.cpp because the plugin-supplied GetLexer...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79916
(0 None)

EPSS: 0.27%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-21T22:04:14.000Z ##

🔴 CVE-2026-79916 - Critical (9.1)

MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject control characters into AWS Bedrock access_key_id and secret_access_key fields that _update_aws_credentials writes to /root/.aws/c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73550
(0 None)

EPSS: 0.88%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-21T21:02:36.000Z ##

🟠 CVE-2026-73550 - High (7.5)

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy copies every decoded HTTP/2 Host header value before discarding it when :authority is already present. The d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73552
(0 None)

EPSS: 0.66%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-21T21:02:50.000Z ##

🟠 CVE-2026-73552 - High (7.5)

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy HTTP RBAC accepts RFC-valid opaque header bytes but evaluates safe_regex values with RE2's UTF-8 subject sem...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73548
(0 None)

EPSS: 0.66%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-21T21:01:20.000Z ##

🟠 CVE-2026-73548 - High (7.5)

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy forwards data for a configured non-WebSocket HTTP upgrade before the upstream accepts the upgrade. An unauth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites