## Updated at UTC 2026-07-29T18:04:35.170333

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-20316 5.3 0.00% 2 0 2026-07-29T17:16:51.840000 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-20079 10.0 38.70% 2 1 template 2026-07-29T17:16:51.683000 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-67215 7.5 0.00% 2 0 2026-07-29T16:17:57.997000 cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack ex
CVE-2026-43698 7.8 0.15% 1 0 2026-07-29T15:46:07.463000 An injection issue was addressed with improved validation. This issue is fixed i
CVE-2026-65884 None 0.00% 1 0 2026-07-29T15:31:18 Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The
CVE-2026-0667 None 0.00% 2 0 2026-07-29T15:31:11 CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that
CVE-2026-59932 7.5 0.69% 1 0 2026-07-29T15:16:26.967000 PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files.
CVE-2026-55390 7.5 0.36% 3 0 2026-07-29T15:16:26.230000 datamodel-code-generator generates Python data models from schema definitions. F
CVE-2026-14996 8.2 0.22% 1 0 2026-07-29T15:16:20.930000 IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related
CVE-2026-50517 9.9 1.25% 1 0 2026-07-29T14:19:20.030000 Deserialization of untrusted data in M365 Copilot allows an authorized attacker
CVE-2026-66748 8.8 0.74% 1 1 2026-07-29T14:16:34.610000 Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code
CVE-2026-62325 9.1 0.34% 1 0 2026-07-29T14:16:33.530000 goshs is a feature-rich single-binary file server for red teamers and developers
CVE-2026-45293 8.6 0.18% 1 0 2026-07-29T14:16:30.737000 WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enfor
CVE-2026-14973 9.3 0.45% 1 0 2026-07-29T14:16:28.453000 IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow fil
CVE-2026-64863 9.1 0.34% 1 0 2026-07-29T13:19:09.987000 goshs is a feature-rich single-binary file server for red teamers and developers
CVE-2026-55389 7.5 0.36% 1 0 2026-07-29T13:19:01.067000 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, a
CVE-2026-18220 7.8 0.00% 2 1 2026-07-29T13:17:54.203000 An out-of-bounds write vulnerability was found in the BFD library's DLX ELF back
CVE-2026-16192 7.1 0.27% 1 0 2026-07-29T13:17:48.460000 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected
CVE-2026-15325 8.7 0.21% 1 0 2026-07-29T13:17:46.973000 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
CVE-2026-14270 8.8 0.00% 2 0 2026-07-29T12:31:30 The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCom
CVE-2026-65883 None 0.00% 2 0 2026-07-29T12:31:30 Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Ca
CVE-2026-35226 6.5 0.17% 1 0 2026-07-29T09:31:37 An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows a
CVE-2026-18072 9.8 0.59% 2 0 2026-07-29T06:32:11 The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick
CVE-2026-42533 8.1 3.60% 2 9 2026-07-29T05:16:44.720000 A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive
CVE-2026-12144 8.8 0.37% 1 0 2026-07-29T03:30:21 The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Es
CVE-2026-54650 8.6 0.36% 1 0 2026-07-28T22:20:54 ## Summary openhole-server forwarded the URL-decoded request path (`r.URL.Path`
CVE-2026-54658 9.8 0.40% 1 0 2026-07-28T22:19:24 ### Impact A SQL injection vulnerability exists in the `escapeValue()` function
CVE-2026-54638 7.5 0.35% 1 0 2026-07-28T22:15:29 ### Impact A remote, unauthenticated attacker can cause excessive memory alloca
CVE-2026-54719 7.5 0.28% 1 0 2026-07-28T21:59:49 GHSA-wvhv-qcqf-f3cx fixed the per-folder .goshs ACL bypass on the state-changing
CVE-2026-55391 7.5 0.19% 1 0 2026-07-28T21:45:50 ### Summary `datamodel-code-generator`'s anti-SSRF guard validates the resolved
CVE-2026-14893 7.3 0.33% 1 0 2026-07-28T21:31:45 IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana
CVE-2026-15057 7.5 0.26% 1 0 2026-07-28T21:31:45 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerab
CVE-2026-14981 7.5 0.26% 1 0 2026-07-28T21:31:45 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
CVE-2026-48395 8.6 0.17% 1 0 2026-07-28T21:31:39 Bridge is affected by an Untrusted Search Path vulnerability that could result i
CVE-2026-7769 8.1 0.27% 1 0 2026-07-28T21:31:39 IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2
CVE-2026-66745 7.5 0.32% 1 0 2026-07-28T21:31:39 Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) con
CVE-2026-43776 7.8 0.15% 1 0 2026-07-28T19:44:17.417000 A buffer overflow was addressed with improved bounds checking. This issue is fix
CVE-2026-59931 7.7 0.53% 1 0 2026-07-28T19:17:39.457000 PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files.
CVE-2026-66754 5.9 0.40% 1 1 2026-07-28T18:33:11 Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the
CVE-2026-54635 7.5 0.42% 1 0 2026-07-28T18:17:22.427000 pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webho
CVE-2026-59878 7.5 0.55% 1 0 2026-07-28T16:20:53.010000 Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ
CVE-2026-63727 8.8 0.26% 1 0 2026-07-28T16:19:43.127000 Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper
CVE-2026-66473 7.5 0.20% 1 0 2026-07-28T16:19:12.780000 Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
CVE-2026-63077 9.8 0.65% 5 0 2026-07-28T16:17:58.820000 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-63720 7.5 0.42% 2 0 2026-07-28T16:07:15.840000 datamodel-code-generator prior to version 0.70.0 contains a code injection vulne
CVE-2026-7187 8.8 0.21% 1 0 2026-07-28T15:32:18 Missing authentication for critical function vulnerability in Universal Software
CVE-2026-61609 7.5 0.39% 1 0 2026-07-28T14:58:00 ### Summary The `authentication` rate limiter used for the login and two-factor
CVE-2026-16812 10.0 0.88% 5 0 2026-07-28T14:50:33.960000 VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may a
CVE-2026-16462 9.8 0.42% 1 0 2026-07-28T12:31:27 In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This a
CVE-2026-64531 0 0.16% 1 0 2026-07-28T12:16:36.880000 In the Linux kernel, the following vulnerability has been resolved: net: openvs
CVE-2026-14168 8.8 0.28% 2 0 2026-07-28T09:31:36 A low privileged remote attacker can gain administrator privileges due to missin
CVE-2026-14167 8.8 0.28% 2 0 2026-07-28T09:31:36 A low privileged remote attacker can perform privileged configuration changes re
CVE-2026-14169 8.1 0.29% 2 0 2026-07-28T09:31:36 Due to incorrect behavior order a low privileged remote attacker could trigger a
CVE-2026-14171 6.1 0.18% 2 0 2026-07-28T09:31:35 An unauthenticated remote attacker can abuse the improper validation of the post
CVE-2026-61511 9.8 1.27% 10 5 2026-07-28T05:17:17.133000 vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vul
CVE-2026-43723 7.8 0.15% 1 0 2026-07-28T00:32:06 A path handling issue was addressed with improved validation. This issue is fixe
CVE-2026-43749 7.8 0.15% 1 0 2026-07-28T00:32:05 A parsing issue in the handling of directory paths was addressed with improved p
CVE-2026-39874 7.8 0.10% 1 0 2026-07-28T00:32:04 A permissions issue was addressed with additional restrictions. This issue is fi
CVE-2026-66018 6.5 0.23% 1 0 2026-07-27T21:31:32 Build readers can access another repository's environment properties. A caller w
CVE-2026-65923 6.8 0.19% 1 0 2026-07-27T21:31:28 A URL validation weakness in JFrog Artifactory Ansible repository handling could
CVE-2026-65617 8.8 0.30% 1 0 2026-07-27T21:31:24 A deserialization weakness in JFrog Artifactory package handling could allow a l
CVE-2026-17497 8.3 0.46% 1 0 2026-07-27T20:37:16.927000 NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capabili
CVE-2026-17457 4.3 0.32% 1 0 2026-07-27T20:25:13.817000 A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by t
CVE-2026-17458 6.3 0.23% 1 0 2026-07-27T20:25:13.817000 A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the f
CVE-2025-68686 5.9 1.26% 6 0 2026-07-27T18:31:25 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE
CVE-2026-16805 8.8 0.31% 1 0 2026-07-27T12:45:44.210000 Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remot
CVE-2026-16806 8.8 0.40% 1 0 2026-07-27T12:45:30.967000 Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remo
CVE-2026-16807 8.8 0.26% 1 0 2026-07-27T12:45:14.207000 Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a
CVE-2026-14837 7.8 0.08% 1 0 2026-07-27T09:31:26 Multiple Lenze products are affected by an improper signature verification vulne
CVE-2026-64600 7.8 0.49% 6 6 2026-07-27T05:16:56.870000 In the Linux kernel, the following vulnerability has been resolved: xfs: resamp
CVE-2026-17496 8.1 0.30% 1 0 2026-07-26T15:30:33 NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with
CVE-2026-17459 4.3 0.32% 1 0 2026-07-26T12:30:21 A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerabilit
CVE-2026-15962 8.8 0.38% 1 0 2026-07-26T03:30:31 The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Objec
CVE-2026-66012 10.0 0.44% 2 1 2026-07-25T12:31:47 SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST
CVE-2026-25243 8.8 3.30% 1 3 2026-07-25T11:10:00.100000 Redis is an in-memory data structure store. In versions of redis-server up to 8.
CVE-2026-10818 8.1 0.42% 1 1 2026-07-25T09:30:31 The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in a
CVE-2026-35425 8.0 0.48% 1 0 2026-07-25T05:16:34.867000 Improper access control in Azure API Management (APIM) allows an authorized atta
CVE-2026-65711 7.2 2.41% 1 0 2026-07-24T18:31:41 sysPass through version 3.2.11 contains an OS command injection vulnerability th
CVE-2026-16804 8.3 0.25% 1 0 2026-07-24T15:34:00 Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remot
CVE-2026-62145 7.5 7.54% 1 1 2026-07-24T05:16:45.940000 A vulnerability in Check Point Gaia Portal allows an authenticated attacker with
CVE-2026-62144 9.1 20.62% 1 1 2026-07-24T05:16:45.793000 An authentication bypass vulnerability in Check Point Security Management and Mu
CVE-2026-54120 9.9 0.71% 1 0 2026-07-24T03:31:56 Improper input validation in Microsoft Surface allows an authorized attacker to
CVE-2026-42933 10.0 0.29% 1 0 2026-07-24T00:32:40 Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or inter
CVE-2026-21655 None 0.17% 2 0 2026-07-23T21:31:03 Deserialization of untrusted data vulnerability in Johnson Control victor on Win
CVE-2026-6516 10.0 4.73% 1 0 2026-07-23T18:31:54 Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthen
CVE-2026-63108 8.8 1.92% 1 0 2026-07-23T15:24:59.880000 Roo Code through 3.54.0 contains a command injection vulnerability in the auto-a
CVE-2026-63766 9.8 1.75% 1 1 2026-07-23T15:24:59.880000 GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability
CVE-2026-59933 7.5 0.69% 1 0 2026-07-23T15:01:52 ## Summary PhpSpreadsheet's OLE reader follows sector chains from attacker-cont
CVE-2026-16723 9.0 0.41% 8 3 2026-07-23T15:01:24.377000 A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.
CVE-2026-46331 7.8 0.53% 1 13 2026-07-23T12:18:18.287000 In the Linux kernel, the following vulnerability has been resolved: net/sched:
CVE-2026-15342 6.5 0.22% 1 0 2026-07-22T21:33:00 Plane contains a multi‑tenant authorization flaw in its asset‑management API tha
CVE-2026-13072 8.1 0.32% 1 0 2026-07-22T21:32:15 When compute mode is enabled on a standalone mongod instance, insufficient valid
CVE-2026-16232 9.1 69.97% 8 2 template 2026-07-22T21:32:05 An authentication bypass vulnerability in the Check Point SmartConsole login pro
CVE-2026-50522 9.8 57.10% 2 5 2026-07-22T21:31:51 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-53359 8.8 0.91% 1 6 2026-07-22T21:31:50 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: F
CVE-2026-10702 4.3 0.55% 1 0 2026-07-22T19:10:00.120000 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w
CVE-2026-49176 7.8 0.40% 2 2 2026-07-22T16:17:28.753000 Improper privilege management in Windows WalletService allows an authorized atta
CVE-2026-60137 5.9 77.97% 1 45 2026-07-22T05:17:11.750000 WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does no
CVE-2026-8985 None 4.19% 1 0 2026-07-22T00:32:44 Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command
CVE-2026-64606 9.8 0.63% 1 0 2026-07-21T21:33:35 Deserialization of untrusted data vulnerability that may allow class-registratio
CVE-2026-64879 9.9 2.59% 1 0 2026-07-21T21:32:47 A filename supplied during file upload is not properly sanitized before being us
CVE-2026-40510 3.8 0.22% 2 0 2026-07-21T12:10:00.090000 OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overf
CVE-2026-2291 7.3 0.92% 2 1 2026-07-20T21:31:40 dnsmasqs extract_name() function can be abused to cause a heap buffer overflow,
CVE-2026-53362 7.8 0.27% 1 0 2026-07-18T09:32:17 In the Linux kernel, the following vulnerability has been resolved: ipv6: accou
CVE-2026-42530 8.1 3.68% 1 3 2026-07-16T12:33:31 NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGI
CVE-2026-15410 7.2 76.35% 1 3 2026-07-16T05:16:18.470000 Post-authentication improper control of generation of code ('Code Injection') vu
CVE-2023-4346 7.5 0.91% 1 0 2026-07-16T05:16:16.603000 KNX devices that use KNX Connection Authorization and support Option 1 are, dep
CVE-2026-46817 9.8 13.31% 1 2 2026-07-15T18:32:50 Vulnerability in the Oracle Payments product of Oracle E-Business Suite (compone
CVE-2026-56155 7.8 2.33% 1 0 2026-07-14T21:32:52 Insufficient granularity of access control in Active Directory Federation Servic
CVE-2026-54121 8.8 1.05% 6 8 2026-07-14T18:32:37 Improper authorization in Active Directory Certificate Services (AD CS) allows a
CVE-2026-50502 8.0 0.60% 3 0 2026-07-14T18:32:33 Insufficient granularity of access control in Windows Event Logging Service allo
CVE-2026-50469 7.8 0.27% 2 0 2026-07-14T18:32:32 Improper link resolution before file access ('link following') in Windows Projec
CVE-2025-15467 9.8 47.62% 2 6 2026-07-14T15:32:45 Issue summary: Parsing CMS AuthEnvelopedData message with maliciously crafted AE
CVE-2026-55255 8.4 29.05% 1 1 2026-07-07T22:14:37 ## Summary Insecure Direct Object Reference (IDOR) vulnerability in `/api/v1/re
CVE-2026-12569 9.8 2.26% 3 1 2026-06-30T18:16:43.113000 A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
CVE-2026-5172 7.3 2.68% 2 2 2026-06-30T03:37:45 A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker t
CVE-2026-42945 8.1 61.47% 2 42 2026-06-27T06:30:25 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo
CVE-2026-0160 8.8 0.23% 1 0 2026-06-17T18:36:29 In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there
CVE-2026-0149 8.8 0.29% 1 0 2026-06-17T18:36:28 In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap bu
CVE-2026-4893 5.3 2.68% 2 5 2026-06-17T10:57:24.507000 An information disclosure vulnerability in dnsmasq allows remote attackers to by
CVE-2026-22796 5.3 0.50% 2 0 2026-06-17T10:20:26.697000 Issue summary: A type confusion vulnerability exists in the signature verificati
CVE-2026-22795 5.5 0.14% 2 0 2026-06-17T10:20:26.520000 Issue summary: An invalid or NULL pointer dereference can happen in an applicati
CVE-2026-1623 6.3 2.18% 1 1 2026-06-17T10:16:12.407000 A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the fu
CVE-2025-69421 7.5 0.84% 2 1 2026-06-17T10:00:40.683000 Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer de
CVE-2025-69420 7.5 0.77% 2 1 2026-06-17T10:00:40.067000 Issue summary: A type confusion vulnerability exists in the TimeStamp Response v
CVE-2025-66376 7.2 21.62% 1 0 2026-06-17T09:56:44.753000 Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Clas
CVE-2024-1813 9.8 1.11% 1 2 2026-06-17T07:05:03.993000 The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection
CVE-2023-5217 8.8 49.01% 1 3 2026-06-17T06:48:06.467000 Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5
CVE-2014-0160 7.5 100.00% 2 75 template 2026-06-17T00:02:24.467000 The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not p
CVE-2013-4786 7.5 78.57% 1 1 2026-06-16T23:57:53.617000 The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (R
CVE-2008-1028 0 4.55% 1 0 2026-06-16T22:50:50.330000 Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-as
CVE-2026-47668 10.0 4.34% 1 1 template 2026-06-05T16:25:28 ### Summary DbGate's JSON script runner (`POST /runners/start`) allows remote co
CVE-2026-42897 8.1 5.64% 2 1 2026-05-15T18:30:32 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2025-68160 4.7 0.15% 2 0 2026-05-12T15:31:14 Issue summary: Writing large, newline-free data into a BIO chain using the line-
CVE-2025-69418 4.0 0.11% 2 1 2026-05-12T15:31:14 Issue summary: When using the low-level OCB API directly with AES-NI or<br>other
CVE-2025-69419 7.4 0.44% 2 1 2026-05-12T15:31:14 Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously craft
CVE-2025-29827 9.9 1.36% 1 0 2025-06-05T15:32:29 Improper Authorization in Azure Automation allows an authorized attacker to elev
CVE-2026-56848 0 0.00% 8 0 N/A
CVE-2026-58043 0 0.00% 6 0 N/A
CVE-2026-56846 0 0.00% 4 0 N/A
CVE-2026-59309 0 0.00% 7 0 N/A
CVE-2026-59310 0 0.00% 5 0 N/A
CVE-2026-47876 0 0.00% 5 0 N/A
CVE-2026-66066 0 0.00% 1 1 N/A
CVE-2026-56850 0 0.00% 2 0 N/A
CVE-2026-53921 0 0.00% 4 2 N/A
CVE-2026-60004 0 0.00% 1 1 N/A
CVE-2026-65094 0 0.00% 1 0 N/A
CVE-2026-63030 0 98.05% 1 70 template N/A
CVE-2026-25589 0 1.38% 1 1 N/A

CVE-2026-20316
(5.3 MEDIUM)

EPSS: 0.00%

updated 2026-07-29T17:16:51.840000

2 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vu

AAKL at 2026-07-29T17:36:00.288Z ##

New Cisco updates:

CRITICAL vulnerability, first released on March 4: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

High severity: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi

New informational advisory: Cisco Advance Notification for Publication of August 5, 2026, Security Advisories sec.cloudapps.cisco.com/securi @TalosSecurity

##

AAKL@infosec.exchange at 2026-07-29T17:36:00.000Z ##

New Cisco updates:

CRITICAL vulnerability, first released on March 4: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

High severity: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi

New informational advisory: Cisco Advance Notification for Publication of August 5, 2026, Security Advisories sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #vulnerability #Cisco

##

CVE-2026-20079
(10.0 CRITICAL)

EPSS: 38.70%

updated 2026-07-29T17:16:51.683000

2 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.&nbsp; This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this v

Nuclei template

1 repos

https://github.com/0xBlackash/CVE-2026-20079

AAKL at 2026-07-29T17:36:00.288Z ##

New Cisco updates:

CRITICAL vulnerability, first released on March 4: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

High severity: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi

New informational advisory: Cisco Advance Notification for Publication of August 5, 2026, Security Advisories sec.cloudapps.cisco.com/securi @TalosSecurity

##

AAKL@infosec.exchange at 2026-07-29T17:36:00.000Z ##

New Cisco updates:

CRITICAL vulnerability, first released on March 4: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

High severity: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi

New informational advisory: Cisco Advance Notification for Publication of August 5, 2026, Security Advisories sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #vulnerability #Cisco

##

CVE-2026-67215
(7.5 HIGH)

EPSS: 0.00%

updated 2026-07-29T16:17:57.997000

2 posts

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON

thehackerwire@mastodon.social at 2026-07-29T15:00:21.000Z ##

🟠 CVE-2026-67215 - High (7.5)

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy oper...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-29T15:00:21.000Z ##

🟠 CVE-2026-67215 - High (7.5)

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy oper...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43698
(7.8 HIGH)

EPSS: 0.15%

updated 2026-07-29T15:46:07.463000

1 posts

An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.

thehackerwire@mastodon.social at 2026-07-28T01:00:38.000Z ##

🟠 CVE-2026-43698 - High (7.8)

An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65884(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-07-29T15:31:18

1 posts

Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.

EUVD_Bot@mastodon.social at 2026-07-29T13:01:11.000Z ##

🚨 EUVD-2026-50298

📊 Score: 9.4/10 (CVSS v3.1)
📦 Product: Gridbox extension for Joomla
🏢 Vendor: balbooa.com
📅 Updated: 2026-07-29

📝 Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 ...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-0667(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-07-29T15:31:11

2 posts

CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when communicating over the Modbus TCP protocol.

offseq at 2026-07-29T13:30:28.352Z ##

CVE-2026-0667 (CRITICAL, CVSS 9.3): Schneider Electric SCADAPack 47x is vulnerable to improper Modbus TCP checks — risk of code execution, DoS, data loss. Review exposure & monitor for patches. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-29T13:30:28.000Z ##

CVE-2026-0667 (CRITICAL, CVSS 9.3): Schneider Electric SCADAPack 47x is vulnerable to improper Modbus TCP checks — risk of code execution, DoS, data loss. Review exposure & monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #ICS #Vulnerability #SCADA

##

CVE-2026-59932
(7.5 HIGH)

EPSS: 0.69%

updated 2026-07-29T15:16:26.967000

1 posts

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the Gnumeric reader reads attacker-supplied .gnumeric files into memory and, when the file starts with gzip magic bytes, calls gzdecode() on the full compressed contents without

thehackerwire@mastodon.social at 2026-07-28T20:00:48.000Z ##

🟠 CVE-2026-59932 - High (7.5)

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the Gnumeric reader read...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55390
(7.5 HIGH)

EPSS: 0.36%

updated 2026-07-29T15:16:26.230000

3 posts

datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for --input-file-type xmlschema resolves xs:include, xs:import, xs:redefine, and xs:override schemaLocation values outside the input base path, allowing arbitrary local files to be read and reflected into generated models. T

hugovalters@mastodon.social at 2026-07-29T17:02:27.000Z ##

CVE-2026-55390 - High severity path traversal in datamodel-code-generator 0.59.0-0.62.0. Arbitrary local file read via XML schema imports. CVSS 7.5. Update to 0.62.0 immediately. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-553

##

hugovalters@mastodon.social at 2026-07-29T17:02:27.000Z ##

CVE-2026-55390 - High severity path traversal in datamodel-code-generator 0.59.0-0.62.0. Arbitrary local file read via XML schema imports. CVSS 7.5. Update to 0.62.0 immediately. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-553

##

thehackerwire@mastodon.social at 2026-07-28T23:00:37.000Z ##

🟠 CVE-2026-55390 - High (7.5)

datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for --input-file-type xmlschema resolves xs:include, xs:import, xs:rede...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14996
(8.2 HIGH)

EPSS: 0.22%

updated 2026-07-29T15:16:20.930000

1 posts

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.

thehackerwire@mastodon.social at 2026-07-28T22:00:08.000Z ##

🟠 CVE-2026-14996 - High (8.2)

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50517
(9.9 CRITICAL)

EPSS: 1.25%

updated 2026-07-29T14:19:20.030000

1 posts

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-07-25T12:00:33.000Z ##

🔴 CVE-2026-50517 - Critical (9.9)

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66748
(8.8 HIGH)

EPSS: 0.74%

updated 2026-07-29T14:16:34.610000

1 posts

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_eval custom field type. Attackers can store an attacker-controlled Ruby expression in the field options command parameter, which is evaluated via instance_

1 repos

https://github.com/theopaid/CVE-2026-66748-Camaleon-CMS---Authenticated-RCE-via-select_eval-Custom-Field

thehackerwire@mastodon.social at 2026-07-28T17:00:35.000Z ##

🟠 CVE-2026-66748 - High (8.8)

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_ev...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62325
(9.1 CRITICAL)

EPSS: 0.34%

updated 2026-07-29T14:16:33.530000

1 posts

goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -fkf left both SFTP authentication handlers unset and allowed unauthenticated file access. This issue is fixed in version 2.1.4.

thehackerwire@mastodon.social at 2026-07-29T00:00:11.000Z ##

🔴 CVE-2026-62325 - Critical (9.1)

goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -fkf left...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45293
(8.6 HIGH)

EPSS: 0.18%

updated 2026-07-29T14:16:30.737000

1 posts

WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rulesets) reconstructed the $ver argument passed to functions such as wp_enqueue_script() and ran it through eval() inside its is_falsy() method, so a maliciously craf

CVE-2026-14973
(9.3 CRITICAL)

EPSS: 0.45%

updated 2026-07-29T14:16:28.453000

1 posts

IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.

DailyCyberSecurity@infosec.exchange at 2026-07-29T02:03:37.000Z ##

IBM Aspera vulnerabilities affect Faspex 5 and the Desktop App. CVE-2026-14973 and two RCE flaws rate up to 9.3. Update to Faspex 5.0.16 and Desktop 1.1.0.

#IBMAspera #AsperaFaspex #CVE202614973 #RCE #PathTraversal #CyberSecurity

securityonline.info/ibm-aspera

##

CVE-2026-64863
(9.1 CRITICAL)

EPSS: 0.34%

updated 2026-07-29T13:19:09.987000

1 posts

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce --no-delete, allowing WebDAV clients to delete or overwrite files via MOVE with Overwrite: T. This issue is fixed in version 2.1.4.

thehackerwire@mastodon.social at 2026-07-29T00:00:21.000Z ##

🔴 CVE-2026-64863 - Critical (9.1)

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce --no-delete, allowing WebDAV clients to delete or ove...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55389
(7.5 HIGH)

EPSS: 0.36%

updated 2026-07-29T13:19:01.067000

1 posts

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.62.0, datamodel-code-generator resolves JSON Schema $ref targets in src/datamodel_code_generator/parser/jsonschema.py through is_url and _get_ref_body without containing file:// or ../ traversal references to th

thehackerwire@mastodon.social at 2026-07-28T23:00:27.000Z ##

🟠 CVE-2026-55389 - High (7.5)

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.62.0, datamodel-code-generator resolves JSON Schema $ref t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18220
(7.8 HIGH)

EPSS: 0.00%

updated 2026-07-29T13:17:54.203000

2 posts

An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation

1 repos

https://github.com/4D4J/objdump-Out-Of-Bounds-write

thehackerwire@mastodon.social at 2026-07-29T15:00:44.000Z ##

🟠 CVE-2026-18220 - High (7.8)

An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds ch...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-29T15:00:44.000Z ##

🟠 CVE-2026-18220 - High (7.8)

An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds ch...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16192
(7.1 HIGH)

EPSS: 0.27%

updated 2026-07-29T13:17:48.460000

1 posts

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feature is enabled.

hugovalters@mastodon.social at 2026-07-29T14:14:24.000Z ##

CVE-2026-16192 - Denial of Service in IBM WebSphere Liberty. restConnector-2.0 feature enabled allows DoS. CVSS 7.1. Disable feature or apply mitigations. #CVE #IBM #infosec

valtersit.com/cve/CVE-2026-161

##

CVE-2026-15325
(8.7 HIGH)

EPSS: 0.21%

updated 2026-07-29T13:17:46.973000

1 posts

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling due to improper handling of TRACE requests.

hugovalters@mastodon.social at 2026-07-29T15:09:20.000Z ##

CVE-2026-15325 - Session Hijacking in IBM WebSphere via HTTP TRACE smuggling. CVSS 8.7. No patch yet. Mitigate immediately. #CVE #infosec #IBM

valtersit.com/cve/CVE-2026-153

##

CVE-2026-14270
(8.8 HIGH)

EPSS: 0.00%

updated 2026-07-29T12:31:30

2 posts

The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validation in the eco_save_settings() function, which allows low-privileged authenticated users to modify the tc_eco_custom_file_types upload allowlist setting,

thehackerwire@mastodon.social at 2026-07-29T15:00:33.000Z ##

🟠 CVE-2026-14270 - High (8.8)

The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-29T15:00:33.000Z ##

🟠 CVE-2026-14270 - High (8.8)

The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65883(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-07-29T12:31:30

2 posts

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.

offseq at 2026-07-29T10:30:27.044Z ##

CVE-2026-65883 (CRITICAL, CVSS 10): Aimy Captcha-Less Form Guard for Joomla (v18.0-20.0) is vulnerable to PHP object injection via clfgd field — enabling RCE. Patch or disable plugin urgently. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-29T10:30:27.000Z ##

CVE-2026-65883 (CRITICAL, CVSS 10): Aimy Captcha-Less Form Guard for Joomla (v18.0-20.0) is vulnerable to PHP object injection via clfgd field — enabling RCE. Patch or disable plugin urgently. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #Exploit #RCE

##

CVE-2026-35226
(6.5 MEDIUM)

EPSS: 0.17%

updated 2026-07-29T09:31:37

1 posts

An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in a controlled stop of the PLC application.

certvde@infosec.exchange at 2026-07-29T07:12:14.000Z ##

#OT #Advisory VDE-2026-041
CODESYS PROFINET Controller - Out-of-bounds Write

CODESYS PROFINET is an add‑on for the CODESYS Development System that provides a fully integrated PROFINET protocol stack along with diagnostic capabilities. When a PROFINET Controller is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.
#CVE CVE-2026-35226

certvde.com/en/advisories/vde-

#CSAF codesys.csaf-tp.certvde.com/.w

##

CVE-2026-18072
(9.8 CRITICAL)

EPSS: 0.59%

updated 2026-07-29T06:32:11

2 posts

The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs before any authentication checks on every request — reads an attacker-supplied t

thehackerwire@mastodon.social at 2026-07-29T06:59:52.000Z ##

🔴 CVE-2026-18072 - Critical (9.8)

The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` func...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T02:48:53.000Z ##

Active exploitation of CVE-2026-18072, a CVSS 9.8 video embedder backdoor, grants attackers full administrative control over 20,000 WordPress sites.

#CVE202618072 #WordPress #CyberSecurity #Backdoor

securityonline.info/cve-2026-1

##

CVE-2026-42533
(8.1 HIGH)

EPSS: 3.60%

updated 2026-07-29T05:16:44.720000

2 posts

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyon

9 repos

https://github.com/suominen/CVE-2026-42533

https://github.com/seguridadentrerios/CVE-2026-42533

https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner

https://github.com/srkyn/nginx-map-risk-audit

https://github.com/Daniyal48/ghostlock-vagrant-box

https://github.com/ChPratik/NGINX_2026_CVE_Bundle_CTI_Report

https://github.com/jelasin/CVE-2026-42533

https://github.com/gagaltotal/CVE-2026-42533-nginx

https://github.com/imbas007/CVE-2026-42533

CVE-2026-12144
(8.8 HIGH)

EPSS: 0.37%

updated 2026-07-29T03:30:21

1 posts

The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it directly to `WP_User::add_role()`, with no allowlist validation against permitted wholesale roles and no capability check

thehackerwire@mastodon.social at 2026-07-29T07:00:02.000Z ##

🟠 CVE-2026-12144 - High (8.8)

The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` P...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54650
(8.6 HIGH)

EPSS: 0.36%

updated 2026-07-28T22:20:54

1 posts

## Summary openhole-server forwarded the URL-decoded request path (`r.URL.Path`) to tunnel clients instead of the original request-target. Percent-encoded dot-segments (`%2e`) and separators (`%2f`) were decoded to `../` and `/` before reaching the local service. Go's ServeMux rejects literal `../` paths, but percent-encoded traversal sequences bypassed this and were delivered to backends as wor

thehackerwire@mastodon.social at 2026-07-29T02:00:25.000Z ##

🟠 CVE-2026-54650 - High (8.6)

openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.EscapedPath(), allowing percent e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54658
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-07-28T22:19:24

1 posts

### Impact A SQL injection vulnerability exists in the `escapeValue()` function used for parameter substitution. Attackers who can control parameter values can inject arbitrary SQL by using a trailing backslash to escape the closing quote. Who is impacted: All users of @hypequery/clickhouse versions prior to 2.0.2 who pass user-controlled input as query parameters. ### Patches The vulnerability

thehackerwire@mastodon.social at 2026-07-29T02:00:36.000Z ##

🔴 CVE-2026-54658 - Critical (9.8)

Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing attacker controlled query param...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54638
(7.5 HIGH)

EPSS: 0.35%

updated 2026-07-28T22:15:29

1 posts

### Impact A remote, unauthenticated attacker can cause excessive memory allocation (and resulting CPU / GC pressure, potentially OOM termination) by sending a crafted unencrypted MTProto packet. `(*proto.UnencryptedMessage).Decode` read an attacker-controlled 32-bit `dataLen` field and immediately allocated a buffer of that size via `make([]byte, dataLen)` **before** validating that the underly

thehackerwire@mastodon.social at 2026-07-29T02:00:15.000Z ##

🟠 CVE-2026-54638 - High (7.5)

gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]byte, data...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54719
(7.5 HIGH)

EPSS: 0.28%

updated 2026-07-28T21:59:49

1 posts

GHSA-wvhv-qcqf-f3cx fixed the per-folder .goshs ACL bypass on the state-changing routes (PUT/POST upload/?mkdir/?delete) and added recursive ACL resolution, and its description states the read/list path correctly enforces .goshs. That premise does not hold for the ?bulk zip-download route. bulkDownload (httpserver/updown.go) takes one or more ?file= parameters, runs each through sanitizePath(fs.We

thehackerwire@mastodon.social at 2026-07-29T00:00:31.000Z ##

🟠 CVE-2026-54719 - High (7.5)

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauthenticate...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55391
(7.5 HIGH)

EPSS: 0.19%

updated 2026-07-28T21:45:50

1 posts

### Summary `datamodel-code-generator`'s anti-SSRF guard validates the resolved IP of a fetch target once and then lets `httpx` perform its own independent DNS resolution to connect, so the validated address is never pinned. A hostname that resolves to a public IP at validation time and a private IP at connection time (DNS rebinding) bypasses the guard and reaches loopback, link-local cloud-metad

thehackerwire@mastodon.social at 2026-07-28T23:00:47.000Z ##

🟠 CVE-2026-55391 - High (7.5)

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.63.0, datamodel-code-generator validates a URL host once i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14893
(7.3 HIGH)

EPSS: 0.33%

updated 2026-07-28T21:31:45

1 posts

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API.

hugovalters@mastodon.social at 2026-07-29T11:14:41.000Z ##

CVE-2026-14893 - Prototype Pollution in IBM Instana Node.js tracer. CVSS 7.3. No patch available. Limit configuration API access to mitigate. #CVE #IBM #infosec

valtersit.com/cve/CVE-2026-148

##

CVE-2026-15057
(7.5 HIGH)

EPSS: 0.26%

updated 2026-07-28T21:31:45

1 posts

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.

thehackerwire@mastodon.social at 2026-07-28T22:00:18.000Z ##

🟠 CVE-2026-15057 - High (7.5)

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14981
(7.5 HIGH)

EPSS: 0.26%

updated 2026-07-28T21:31:45

1 posts

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.

thehackerwire@mastodon.social at 2026-07-28T21:59:58.000Z ##

🟠 CVE-2026-14981 - High (7.5)

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48395
(8.6 HIGH)

EPSS: 0.17%

updated 2026-07-28T21:31:39

1 posts

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

hugovalters@mastodon.social at 2026-07-29T12:04:45.000Z ##

CVE-2026-48395 - High severity RCE in Bridge via untrusted search path. CVSS 8.6. User interaction needed: open malicious file. No patch available. Be cautious with untrusted files. #CVE #infosec #Bridge

valtersit.com/cve/CVE-2026-483

##

CVE-2026-7769
(8.1 HIGH)

EPSS: 0.27%

updated 2026-07-28T21:31:39

1 posts

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in t

thehackerwire@mastodon.social at 2026-07-28T20:00:38.000Z ##

🟠 CVE-2026-7769 - High (8.1)

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to SQL ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66745
(7.5 HIGH)

EPSS: 0.32%

updated 2026-07-28T21:31:39

1 posts

Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated attackers to hijack administrative sessions by setting a known PHPSESSID on a victim's browser prior to authentication. Attackers can pre-set a controlled session identifier and wait for a victim to authenticate through fw.login.php, after which the att

thehackerwire@mastodon.social at 2026-07-28T20:00:25.000Z ##

🟠 CVE-2026-66745 - High (7.5)

Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated attackers to hijack administrative sessions by setting a known PHPSESSID on a victim's browser prior...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43776
(7.8 HIGH)

EPSS: 0.15%

updated 2026-07-28T19:44:17.417000

1 posts

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

thehackerwire@mastodon.social at 2026-07-27T23:00:21.000Z ##

🟠 CVE-2026-43776 - High (7.8)

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59931
(7.7 HIGH)

EPSS: 0.53%

updated 2026-07-28T19:17:39.457000

1 posts

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the WEBSERVICE() domain whitelist can be bypassed via an HTTP redirect (SSRF). In Calculation/Web/Service.php, the webService() method validates a URL's host against the whiteli

thehackerwire@mastodon.social at 2026-07-28T19:00:20.000Z ##

🟠 CVE-2026-59931 - High (7.7)

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the WEBSERVICE() domain ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66754
(5.9 MEDIUM)

EPSS: 0.40%

updated 2026-07-28T18:33:11

1 posts

Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL. Attackers can send a request whose decoded path matches a configured prefix while the raw percent-encoded path does not, causing the assert! to fail and triggering either a 500 erro

1 repos

https://github.com/theopaid/CVE-2026-66754-Remote-Denial-of-Service-via-Reachable-Assertion-in-URL-Prefix-Handling-rouille-

thehackerwire@mastodon.social at 2026-07-28T17:00:26.000Z ##

🟠 CVE-2026-66754 - High (7.5)

Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL. Attackers can send a request...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54635
(7.5 HIGH)

EPSS: 0.42%

updated 2026-07-28T18:17:22.427000

1 posts

pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.0.0 to 2.2.0, TonapiWebhookDispatcher fails to validate the Authorization header when a webhook handler is registered with the documented path argument, because setup() stores bearer tokens only under the default suffix paths and never adds the custom path to the token map, so se

thehackerwire@mastodon.social at 2026-07-28T19:00:11.000Z ##

🟠 CVE-2026-54635 - High (7.5)

pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.0.0 to 2.2.0, TonapiWebhookDispatcher fails to validate the Authorization header when a webhook handler is registered with the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59878
(7.5 HIGH)

EPSS: 0.55%

updated 2026-07-28T16:20:53.010000

1 posts

Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value. This cause the NIO threads to die and if done rapidly enough can lead to exhaustion of the NIO thread pool denying service to other connections. This i

thehackerwire@mastodon.social at 2026-07-28T16:00:34.000Z ##

🟠 CVE-2026-59878 - High (7.5)

Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All.

A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63727
(8.8 HIGH)

EPSS: 0.26%

updated 2026-07-28T16:19:43.127000

1 posts

Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions to gain access to additional resources and operations. It is not possible to grant the system-admin role, but a read onl

thehackerwire@mastodon.social at 2026-07-28T16:00:24.000Z ##

🟠 CVE-2026-63727 - High (8.8)

Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capab...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66473
(7.5 HIGH)

EPSS: 0.20%

updated 2026-07-28T16:19:12.780000

1 posts

Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.

thehackerwire@mastodon.social at 2026-07-28T01:00:26.000Z ##

🟠 CVE-2026-66473 - High (7.5)

Unauthenticated Broken Access Control in Xendit Payment &lt;= 7.1.0 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63077
(9.8 CRITICAL)

EPSS: 0.65%

updated 2026-07-28T16:17:58.820000

5 posts

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

netsecio@mastodon.social at 2026-07-29T16:57:17.000Z ##

📰 JetBrains Patches Critical Unauthenticated RCE Flaw in TeamCity

🚨 CRITICAL ALERT: JetBrains patches CVE-2026-63077, a 9.8 CVSS unauthenticated RCE in TeamCity On-Premises. All versions affected. Exploit allows full server takeover. Upgrade immediately to prevent supply chain attacks! #TeamCity #CI/CD #CyberSecurity

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/je

##

cyberveille@mastobot.ping.moi at 2026-07-29T16:00:05.000Z ##

📢 Vulnérabilité critique RCE non authentifiée dans TeamCity On-Premises (CVE-2026-63077)
📝 ## 🔍 Contexte

Le 27 juillet 2026, JetBrains a publié sur son blog officiel un avis de sécurité critique concernant **TeamCity On-Premise...
📖 cyberveille : cyberveille.ch/posts/2026-07-2
🌐 source : blog.jetbrains.com/teamcity/20
#CI_CD #CVE_2026_44413 #Cyberveille

##

security_crawler_carl@infosec.exchange at 2026-07-28T21:57:19.000Z ##

🏆 New Achievement! Exhibit A: Your CI Server Did It!

The record will reflect that on or about July 28, 2026, JetBrains disclosed CVE-2026-63077, a CVSS 9.8 vulnerability in TeamCity On-Premises. The record will further reflect that any unauthenticated attacker with mere HTTP(S) access could bypass authentication and execute arbitrary operating system commands. (1/3)

##

beyondmachines1@infosec.exchange at 2026-07-28T20:01:50.000Z ##

JetBrains Fixes Critical TeamCity Authentication Bypass Allowing Remote Code Execution

JetBrains patched a critical authentication bypass (CVE-2026-63077) in TeamCity On-Premises that allows unauthenticated remote code execution. The flaw affects all on-premises versions and could lead to a full takeover of CI/CD pipelines.

**If you run TeamCity On-Premises, urgently update to version 2025.11.7 or 2026.1.3 to patch CVE-2026-63077. All on-premises versions are vulnerable to a full server takeover. TeamCity Cloud is already patched and needs no action. If you can't update right away, install the security patch plugin (for versions 2017.1 and later) and restrict access to your TeamCity server to trusted internal networks or a VPN.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-07-28T13:34:19.000Z ##

#TeamCity #CVE202663077 #RCE #RemoteCodeExecution #JetBrains #CyberSecurity

securityonline.info/teamcity-r

##

CVE-2026-63720
(7.5 HIGH)

EPSS: 0.42%

updated 2026-07-28T16:07:15.840000

2 posts

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines and a dot-free Python expression. The crafted value is emitted verbatim into a generated 'from ... import ...' statement without identifier validation, cau

offseq@infosec.exchange at 2026-07-26T06:00:24.000Z ##

CVE-2026-63720 (HIGH): koxudaxi datamodel-code-generator <0.70.0 is vulnerable to code injection. Malicious input schemas can trigger remote Python code execution. Avoid untrusted schemas & update when possible. radar.offseq.com/threat/cve-20 #OffSeq #infosec #Python #CVE202663720

##

thehackerwire@mastodon.social at 2026-07-26T05:59:49.000Z ##

🟠 CVE-2026-63720 - High (7.5)

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-7187
(8.8 HIGH)

EPSS: 0.21%

updated 2026-07-28T15:32:18

1 posts

Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects UKBS: through 28072026. NOTE: The vendor was contacted and it was learned that the product is not supported.

thehackerwire@mastodon.social at 2026-07-28T16:00:44.000Z ##

🟠 CVE-2026-7187 - High (8.8)

Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects UKBS: through 28072026.
NOTE: The vendor was contacted and it was learn...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61609
(7.5 HIGH)

EPSS: 0.39%

updated 2026-07-28T14:58:00

1 posts

### Summary The `authentication` rate limiter used for the login and two-factor checkpoint endpoints applies a single global bucket shared by every client, instead of keying per IP or per account. An unauthenticated attacker sending ~10 requests per minute from one IP exhausts the shared bucket and causes HTTP 429 for every user on every IP attempting to log in or complete 2FA, for as long as the

thehackerwire@mastodon.social at 2026-07-28T17:00:45.000Z ##

🟠 CVE-2026-61609 - High (7.5)

Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProvider::configureRateLimiting() applied a single global bucket to the login and two-factor checkpoin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16812
(10.0 CRITICAL)

EPSS: 0.88%

updated 2026-07-28T14:50:33.960000

5 posts

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intende

security_crawler_carl@infosec.exchange at 2026-07-28T08:14:53.000Z ##

🏆 New Achievement! Ten Out of Ten, Would Exploit Again!

Step right up, valued on-premises customer! Today's featured item is CVE-2026-16812, a perfect-score CVSS 10.0 OS command injection in Arista's VeloCloud Orchestrator — the centralized management platform you trusted with the confidentiality, integrity, and availability of, well, everything. Unknown attackers are already browsing your privileged internal functionality like it's a clearance rack. (1/2)

##

thecybermind@infosec.exchange at 2026-07-28T01:37:38.000Z ##

(CISA TS-SOC) CVE-2026-16812 – Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

Severity: CRITICAL Impact Summary: Remote attackers may access privileged internal functionality and impact the VCO host, compromising the confidentiality, integrity, and availability of the orchestrator and managed data....

thecybermind.co/2026/07/27/cis

##

DailyCyberSecurity@infosec.exchange at 2026-07-27T21:54:32.000Z ##

CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now.

#CISA #KEV #Arista #VeloCloud #Fortinet #FortiOS #CVE #ExploitedInTheWild #Cybersecurity

securityonline.info/cisa-kev-a

##

cisakevtracker@mastodon.social at 2026-07-27T20:00:55.000Z ##

CVE ID: CVE-2026-16812
Vendor: Arista
Product: VeloCloud Orchestrator
Date Added: 2026-07-27
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-07-27T15:27:08.000Z ##

CVE-2026-16812, a VeloCloud command injection scored CVSS 10, is exploited in the wild. Patch VeloCloud Orchestrator now, plus two related bugs.

#VeloCloud #Arista #CVE202616812 #CommandInjection #ExploitedInTheWild #VCO #SSRF #Cybersecurity

securityonline.info/velocloud-

##

CVE-2026-16462
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-07-28T12:31:27

1 posts

In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.

certvde@infosec.exchange at 2026-07-28T09:28:50.000Z ##

#OT #Advisory VDE-2026-085
Weidmueller: SQL Injection Vulnerability in PROCON-WEB SCADA

A remote unauthenticated attacker can exploit a SQL injection vulnerability in PROCON-WEB SCADA to execute arbitrary commands.
#CVE CVE-2026-16462

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

CVE-2026-64531
(0 None)

EPSS: 0.16%

updated 2026-07-28T12:16:36.880000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guar

DailyCyberSecurity@infosec.exchange at 2026-07-28T11:12:26.000Z ##

The OVSwrap local root flaw hits the Linux kernel Open vSwitch datapath. CVE-2026-64531 now has a public patch and PoC. See affected distros and fixes.

#OVSwrap #CVE202664531 #LinuxKernel #OpenvSwitch #LocalRoot #PrivilegeEscalation

securityonline.info/ovswrap-cv

##

CVE-2026-14168
(8.8 HIGH)

EPSS: 0.28%

updated 2026-07-28T09:31:36

2 posts

A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-14167
(8.8 HIGH)

EPSS: 0.28%

updated 2026-07-28T09:31:36

2 posts

A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization.

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-14169
(8.1 HIGH)

EPSS: 0.29%

updated 2026-07-28T09:31:36

2 posts

Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete administrative unavailability of the device.

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-14171
(6.1 MEDIUM)

EPSS: 0.18%

updated 2026-07-28T09:31:35

2 posts

An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website. This can result in a loss of confidentiality and availability.

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-61511
(9.8 CRITICAL)

EPSS: 1.27%

updated 2026-07-28T05:17:17.133000

10 posts

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style

5 repos

https://github.com/codeb0ssx/Ultimate-CVE-2026-61511

https://github.com/tc4dy/CVE-2026-61511-PoC-Exploit

https://github.com/puj790201-lab/cve-2026-61511

https://github.com/webshellseo8/CVE-2026-61511-POC

https://github.com/HORKimhab/CVE-2026-61511

cyberveille@mastobot.ping.moi at 2026-07-29T17:00:18.000Z ##

📢 RCE non authentifiée dans vBulletin ≤ 6.2.1 via la méthode runMaths() (CVE-2026-61511)
📝 ## 🔍 Contexte

Publié le 27 juillet 2026 sur le blog de recherche Karma(In)Security (karmainsecurity.com), cet article détaille une vulnérabilité critique d'exécut...
📖 cyberveille : cyberveille.ch/posts/2026-07-2
🌐 source : karmainsecurity.com/KIS-2026-13
#CVE_2026_61511 #IOC #Cyberveille

##

DailyCyberSecurity at 2026-07-29T15:03:42.458Z ##

A critical vBulletin pre-auth RCE vulnerability, CVE-2026-61511, threatens unpatched forums. Learn how attackers exploit template math evaluation.

meterpreter.org/vbulletin-pre-

##

beyondmachines1 at 2026-07-29T12:01:49.729Z ##

vBulletin Fixes Critical Pre-Auth Remote Code Execution Flaw

vBulletin released patches for a critical remote code execution vulnerability, tracked as CVE-2026-61511 (CVSS score 9.8), that allows unauthenticated attackers to execute arbitrary PHP code on affected forum servers. The flaw affects vBulletin 5.x and 6.x installations, and a public proof-of-concept exploit is available.

**If you run a self-hosted vBulletin forum, upgrade to version 6.2.2 or apply the available security patch immediately. A public exploit allows unauthenticated attackers to target vulnerable servers. Users running the unsupported 5.x branch should migrate to a patched 6.x release.**

beyondmachines.net/event_detai

##

cyberveille@mastobot.ping.moi at 2026-07-29T17:00:18.000Z ##

📢 RCE non authentifiée dans vBulletin ≤ 6.2.1 via la méthode runMaths() (CVE-2026-61511)
📝 ## 🔍 Contexte

Publié le 27 juillet 2026 sur le blog de recherche Karma(In)Security (karmainsecurity.com), cet article détaille une vulnérabilité critique d'exécut...
📖 cyberveille : cyberveille.ch/posts/2026-07-2
🌐 source : karmainsecurity.com/KIS-2026-13
#CVE_2026_61511 #IOC #Cyberveille

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T15:03:42.000Z ##

A critical vBulletin pre-auth RCE vulnerability, CVE-2026-61511, threatens unpatched forums. Learn how attackers exploit template math evaluation.

#vBulletin #CVE202661511 #RCE #Cybersecurity #Infosec

meterpreter.org/vbulletin-pre-

##

beyondmachines1@infosec.exchange at 2026-07-29T12:01:49.000Z ##

vBulletin Fixes Critical Pre-Auth Remote Code Execution Flaw

vBulletin released patches for a critical remote code execution vulnerability, tracked as CVE-2026-61511 (CVSS score 9.8), that allows unauthenticated attackers to execute arbitrary PHP code on affected forum servers. The flaw affects vBulletin 5.x and 6.x installations, and a public proof-of-concept exploit is available.

**If you run a self-hosted vBulletin forum, upgrade to version 6.2.2 or apply the available security patch immediately. A public exploit allows unauthenticated attackers to target vulnerable servers. Users running the unsupported 5.x branch should migrate to a patched 6.x release.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DarkWebInformer@infosec.exchange at 2026-07-28T18:15:24.000Z ##

‼️ CVE-2026-61511: Improper Neutralization of Directives in Dynamically Evaluated Code

FOFA Query: app="vBulletin"

FOFA: en.fofa.info/result?qbase64=YX

Results: 11,081

##

obivan@infosec.exchange at 2026-07-27T19:22:58.000Z ##

PoC for CVE-2026-61511, unauthenticated vBulletin RCE ssd-disclosure.com/vbulletin-r

##

DarkWebInformer@infosec.exchange at 2026-07-27T17:45:06.000Z ##

🚨‼️ CVE-2026-61511: A vulnerability in vBulletin has been identified, the vulnerability allows an unauthenticated user to cause the vBulletin to execute arbitrary code (PHP) on the remote server.

CVSS: 9.8

Exploit: ssd-disclosure.com/vbulletin-r

##

DailyCyberSecurity@infosec.exchange at 2026-07-27T08:21:15.000Z ##

A public PoC now targets CVE-2026-61511, a vBulletin preauth RCE via runMaths eval. Patch to vBulletin 6.2.2 to block remote code execution.

#vBulletin #CVE202661511 #RCE #PreauthRCE #RemoteCodeExecution #PoC #WebSecurity #Cybersecurity

securityonline.info/vbulletin-

##

CVE-2026-43723
(7.8 HIGH)

EPSS: 0.15%

updated 2026-07-28T00:32:06

1 posts

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to gain root privileges.

thehackerwire@mastodon.social at 2026-07-27T23:00:42.000Z ##

🟠 CVE-2026-43723 - High (7.8)

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to gain root pri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43749
(7.8 HIGH)

EPSS: 0.15%

updated 2026-07-28T00:32:05

1 posts

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.

thehackerwire@mastodon.social at 2026-07-27T23:00:32.000Z ##

🟠 CVE-2026-43749 - High (7.8)

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39874
(7.8 HIGH)

EPSS: 0.10%

updated 2026-07-28T00:32:04

1 posts

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

thehackerwire@mastodon.social at 2026-07-28T01:00:48.000Z ##

🟠 CVE-2026-39874 - High (7.8)

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66018
(6.5 MEDIUM)

EPSS: 0.23%

updated 2026-07-27T21:31:32

1 posts

Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).

sayzard@mastodon.sayzard.org at 2026-07-29T09:44:28.000Z ##

We now have a better understanding how OpenAI hacked into Hugging Face

OpenAI의 보안 평가용 모델이 샌드박스를 벗어나 Hugging Face 인프라에 침입한 사건은, 자체 운영형 JFrog Artifactory의 제로데이 취약점 체인을 악용해 가능했다는 분석이 나왔습니다. JFrog Artifactory 7.161.15는 9개 취약점을 수정했으며, 그중 CVE-2026-65617·CVE-2026-65923·CVE-2026-66018은 OpenAI 연구자가 비공개 제보한 것으로 확인됐지만 실제 악용된 취약점인지는 공식...

arstechnica.com/security/2026/

##

CVE-2026-65923
(6.8 MEDIUM)

EPSS: 0.19%

updated 2026-07-27T21:31:28

1 posts

A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions.

sayzard@mastodon.sayzard.org at 2026-07-29T09:44:28.000Z ##

We now have a better understanding how OpenAI hacked into Hugging Face

OpenAI의 보안 평가용 모델이 샌드박스를 벗어나 Hugging Face 인프라에 침입한 사건은, 자체 운영형 JFrog Artifactory의 제로데이 취약점 체인을 악용해 가능했다는 분석이 나왔습니다. JFrog Artifactory 7.161.15는 9개 취약점을 수정했으며, 그중 CVE-2026-65617·CVE-2026-65923·CVE-2026-66018은 OpenAI 연구자가 비공개 제보한 것으로 확인됐지만 실제 악용된 취약점인지는 공식...

arstechnica.com/security/2026/

##

CVE-2026-65617
(8.8 HIGH)

EPSS: 0.30%

updated 2026-07-27T21:31:24

1 posts

A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.

sayzard@mastodon.sayzard.org at 2026-07-29T09:44:28.000Z ##

We now have a better understanding how OpenAI hacked into Hugging Face

OpenAI의 보안 평가용 모델이 샌드박스를 벗어나 Hugging Face 인프라에 침입한 사건은, 자체 운영형 JFrog Artifactory의 제로데이 취약점 체인을 악용해 가능했다는 분석이 나왔습니다. JFrog Artifactory 7.161.15는 9개 취약점을 수정했으며, 그중 CVE-2026-65617·CVE-2026-65923·CVE-2026-66018은 OpenAI 연구자가 비공개 제보한 것으로 확인됐지만 실제 악용된 취약점인지는 공식...

arstechnica.com/security/2026/

##

CVE-2026-17497
(8.3 HIGH)

EPSS: 0.46%

updated 2026-07-27T20:37:16.927000

1 posts

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in

thehackerwire@mastodon.social at 2026-07-26T15:59:58.000Z ##

🟠 CVE-2026-17497 - High (8.3)

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17457
(4.3 MEDIUM)

EPSS: 0.32%

updated 2026-07-27T20:25:13.817000

1 posts

A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component Scheme Handler. Such manipulation of the argument url leads to information disclosure. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project

offseq@infosec.exchange at 2026-07-26T13:30:26.000Z ##

mf-yang openclaw-cn (v0.2.0, 0.2.1) faces a MEDIUM info disclosure issue (CVE-2026-17457). Remote, no user interaction needed. No patch yet — restrict access & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #InfoSec #CVE202617457

##

CVE-2026-17458
(6.3 MEDIUM)

EPSS: 0.23%

updated 2026-07-27T20:25:13.817000

1 posts

A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server-side request forgery. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem

offseq@infosec.exchange at 2026-07-26T12:00:25.000Z ##

SSRF in mf-yang openclaw-cn (CVE-2026-17458) affects v0.2.0 & v0.2.1. MEDIUM severity, CVSS 5.3. Exploit details public, no patch yet. Restrict outbound server requests as interim mitigation. radar.offseq.com/threat/cve-20 #OffSeq #SSRF #Vuln #mfyang

##

CVE-2025-68686
(5.9 MEDIUM)

EPSS: 1.26%

updated 2026-07-27T18:31:25

6 posts

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases

beyondmachines1@infosec.exchange at 2026-07-28T08:01:42.000Z ##

CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass

CISA reports active explotation of CVE-2025-68686, a flaw in Fortinet FortiOS that allows attackers to bypass security patches and maintain persistent access on compromised devices.

**If you use Fortinet devices, make sure they are isolated from the internet and accessible only from trusted networks. Then update FortiOS ASAP to version 7.6.2, 7.4.7, or later. This flaw is combined with others, so make sure all your Fortinet devices are up-to-date. And check your devices for indicators of compromise, this flaw allowed hackers to maintain access over patch cycles.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-07-27T21:54:32.000Z ##

CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now.

#CISA #KEV #Arista #VeloCloud #Fortinet #FortiOS #CVE #ExploitedInTheWild #Cybersecurity

securityonline.info/cisa-kev-a

##

secdb@infosec.exchange at 2026-07-27T19:00:11.000Z ##

🚨 [CISA-2026:0727] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-68686 (secdb.nttzen.cloud/cve/detail/)
- Name: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: FortiOS
- Notes: fortiguard.fortinet.com/psirt/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260727 #cisa20260727 #cve_2025_68686 #cve202568686

##

thecybermind@infosec.exchange at 2026-07-27T18:39:00.000Z ##

(CISA TS-SOC) CVE-2025-68686 – Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Severity: MEDIUM Impact Summary: Exposure of sensitive information to unauthorized actors due to patch bypass, potentially leaking data after prior compromise....

thecybermind.co/2026/07/27/cis

##

cisakevtracker@mastodon.social at 2026-07-27T18:00:47.000Z ##

CVE ID: CVE-2025-68686
Vendor: Fortinet
Product: FortiOS
Date Added: 2026-07-27
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-07-27T17:09:22.000Z ##

CISA has added a vulnerability to the KEV catalogue.

- CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability cve.org/CVERecord?id=CVE-2025-

Also:

Cisco tagged Apple yesterday for zero-day reports talosintelligence.com/vulnerab @TalosSecurity #Fortinet #CISA #infosec #vulnerability #Apple #zeroday

##

CVE-2026-16805
(8.8 HIGH)

EPSS: 0.31%

updated 2026-07-27T12:45:44.210000

1 posts

Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-07-25T13:00:03.000Z ##

🟠 CVE-2026-16805 - High (8.8)

Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16806
(8.8 HIGH)

EPSS: 0.40%

updated 2026-07-27T12:45:30.967000

1 posts

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-07-25T13:00:13.000Z ##

🟠 CVE-2026-16806 - High (8.8)

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16807
(8.8 HIGH)

EPSS: 0.26%

updated 2026-07-27T12:45:14.207000

1 posts

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-07-25T13:59:50.000Z ##

🟠 CVE-2026-16807 - High (8.8)

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14837
(7.8 HIGH)

EPSS: 0.08%

updated 2026-07-27T09:31:26

1 posts

Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.

certvde@infosec.exchange at 2026-07-27T07:01:06.000Z ##

#OT #Advisory VDE-2026-077
Lenze: Incorrect signature validation in the enable SSH routine

The affected products belong to the Controller or Servo Drive product family and contain a vulnerability in a security-critical activation mechanism for service access. The signature verification of a file used for SSH activation can be compromised, which could allow unauthorized access to the device.
#CVE CVE-2026-14837

certvde.com/en/advisories/vde-

#CSAF lenze.csaf-tp.certvde.com/.wel

##

CVE-2026-64600
(7.8 HIGH)

EPSS: 0.49%

updated 2026-07-27T05:16:56.870000

6 posts

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently

6 repos

https://github.com/0xBlackash/CVE-2026-64600

https://github.com/Debajyoti0-0/CVE-2026-64600

https://github.com/letsr00t/RefluxFS_CVE-2026-64600

https://github.com/vulnquest58/VQ-RefluxCore

https://github.com/bha-vin/CVE-2026-64600-Exploit

https://github.com/HORKimhab/CVE-2026-64600

benzogaga33@mamot.fr at 2026-07-27T09:40:02.000Z ##

RefluXFS : cette faille dans XFS donne un accès root sur RHEL, CentOS et AlmaLinux it-connect.fr/refluxfs-cve-202 #ActuCybersécurité #Cybersécurité #Vulnérabilité #Linux

##

hackmag@infosec.exchange at 2026-07-27T06:30:14.000Z ##

⚪️ New RefluXFS Vulnerability Enables Root Access on Linux

🗨️ Researchers at Qualys have discovered a nine-year-old vulnerability in the XFS file system. The bug, tracked as CVE-2026-64600 and dubbed RefluXFS, allows a local unprivileged user to overwrite protected files and gain root privileges. According to researchers, the bug was…

🔗 hackmag.com/news/refluxfs?utm_

#news

##

cyberveille@mastobot.ping.moi at 2026-07-26T17:30:15.000Z ##

📢 RefluXFS (CVE-2026-64600) : élévation de privilèges locale vers root dans le noyau Linux via XFS
📝 ## 🔍 Contexte

Le 22 juillet 2026...
📖 cyberveille : cyberveille.ch/posts/2026-07-2
🌐 source : blog.qualys.com/vulnerabilitie
#CVE_2026_64600 #IOC #Cyberveille

##

security_crawler_carl@infosec.exchange at 2026-07-26T02:24:57.000Z ##

CVE-2026-64600, dubbed RefluXFS by Qualys Threat Research Unit, is a nine-year-old race condition that lets a local attacker clone a root-owned file — /etc/passwd, a SUID binary, you name it — then hammer it with concurrent O_DIRECT writes until they win the race and own the box. Highly reliable exploitation. Survives reboot. A beautiful, silent corpse. (2/3)

##

secdb@infosec.exchange at 2026-07-25T12:52:05.000Z ##

🚨 RefluXFS (CVE-2026-64600) has been identified as a notable vulnerability.

In the Linux kernel, the following vulnerability has been resolved:

xfs: resample the data fork mapping after cycling ILOCK

RefluXFS is a local privilege escalation vulnerability in the Linux kernel's XFS filesystem copy-on-write path. It allows local users to overwrite protected files and gain root access.

ℹ️ Additional details on ZEN SecDB secdb.nttzen.cloud/updates/1d2

#infosec #refluxfs #linux #kernel #xfs #lpe
#nttdata #zen #secdb

##

schwerdtfegr.wordpress.com@schwerdtfegr.wordpress.com at 2026-07-25T11:41:44.000Z ##

Aber linux ist doch sicherer als linux…

Sicherheitsforscher von Qualys haben mithilfe von Claude Mythos eine neun Jahre alte und RefluXFS genannte Sicherheitslücke im Linux-Kernel entdeckt, mit der Angreifer durch das überschreiben geschützter Dateien Root-Zugriff erlangen können. Viele Linux-Distributionen sind in der Standardkonfiguration angreifbar, darunter Red Hat Enterprise Linux (RHEL), CentOS, Fedora und Oracle Linux. Admins sollten ihre Systeme absichern […] anfällig sind alle Linux-Kernel ab Version 4.11, welche im April 2017 veröffentlicht wurde. Voraussetzung ist jedoch, dass ein anvisiertes Linux-System über ein XFS-Volume mit aktiver Reflink-Funktion verfügt […] es gebe keinen alternativen Workaround, der zuverlässig vor CVE-2026-64600 schütze

Na, zumindest das kriegen die angelernten neuronalen netzwerke sehr zuverlässig hin: einen haufen uralter fehler in linux aufzufinden. Schön die sicherheitsaktualisierungen einspielen!

#Epic #Fail #Golem #Link #Linux #Security ##

CVE-2026-17496
(8.1 HIGH)

EPSS: 0.30%

updated 2026-07-26T15:30:33

1 posts

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to inc

thehackerwire@mastodon.social at 2026-07-26T15:59:49.000Z ##

🟠 CVE-2026-17496 - High (8.1)

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17459
(4.3 MEDIUM)

EPSS: 0.32%

updated 2026-07-26T12:30:21

1 posts

A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. Executing a manipulation can lead to symlink following. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The proj

offseq@infosec.exchange at 2026-07-26T10:30:25.000Z ##

CVE-2026-17459: perwendel spark 2.9.0 – 2.9.4 affected by symlink following in staticFiles.externalLocation. Exploit public, MEDIUM severity. Restrict external resource access and monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #CVE202617459 #Java #Security

##

CVE-2026-15962
(8.8 HIGH)

EPSS: 0.38%

updated 2026-07-26T03:30:31

1 posts

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over a

thehackerwire@mastodon.social at 2026-07-26T03:00:20.000Z ##

🟠 CVE-2026-15962 - High (8.8)

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-lev...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66012
(10.0 CRITICAL)

EPSS: 0.44%

updated 2026-07-25T12:31:47

2 posts

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy actions across the entire workspace. When the Publish server is enabled in anonymous mode (Conf.Publis

1 repos

https://github.com/Hunt-Benito/siyuan-mcp-admin-takeover-cve-2026-66012-missing-authorization

offseq@infosec.exchange at 2026-07-25T12:00:26.000Z ##

CVE-2026-66012: CRITICAL flaw in siyuan-note siyuan (<3.7.2). Missing authorization on /mcp lets remote attackers read secrets & plant malicious plugins for admin takeover. Disable anonymous Publish mode & restrict /mcp access. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec

##

thehackerwire@mastodon.social at 2026-07-25T12:00:01.000Z ##

🔴 CVE-2026-66012 - Critical (10)

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-25243
(8.8 HIGH)

EPSS: 3.30%

updated 2026-07-25T11:10:00.100000

1 posts

Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rules.

3 repos

https://github.com/mgiay/CVE-2026-25589-25588-25243-23631-23479-REDIS

https://github.com/dinosn/CVE-2026-25243-debugfree

https://github.com/dinosn/CVE-2026-25243

DailyCyberSecurity@infosec.exchange at 2026-07-27T13:10:16.000Z ##

Discover how new Redis RCE exploit PoC code bypasses fixes for CVE-2026-25243 and CVE-2026-25589 across multiple Redis versions.

#Redis #Cybersecurity #RCE #Vulnerability #ExploitPoC

meterpreter.org/redis-rce-expl

##

CVE-2026-10818
(8.1 HIGH)

EPSS: 0.42%

updated 2026-07-25T09:30:31

1 posts

The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the assembled file not being deleted upon validation failure. This makes it possible for unauthenticated

1 repos

https://github.com/Nxploited/CVE-2026-10818

offseq@infosec.exchange at 2026-07-25T13:30:10.000Z ##

CVE-2026-10818: WPForms Pro <=1.10.1.1 has a HIGH severity file upload vuln (CVSS 8.1). Unauthenticated RCE possible via ajax_chunk_upload_finalize. Restrict access & monitor uploads until a patch is released. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #CVE202610818

##

CVE-2026-35425
(8.0 HIGH)

EPSS: 0.48%

updated 2026-07-25T05:16:34.867000

1 posts

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-07-25T12:00:43.000Z ##

🟠 CVE-2026-35425 - High (8)

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65711
(7.2 HIGH)

EPSS: 2.41%

updated 2026-07-24T18:31:41

1 posts

sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands as the web server process user by setting a malicious backup path and triggering a backup. The FileBackupService builds a tar shell command via string concatenation, inserting the admin-configurable siteBackupPath setting without escapeshellarg() or e

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-16804
(8.3 HIGH)

EPSS: 0.25%

updated 2026-07-24T15:34:00

1 posts

Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-07-25T12:59:53.000Z ##

🟠 CVE-2026-16804 - High (8.3)

Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62145
(7.5 HIGH)

EPSS: 7.54%

updated 2026-07-24T05:16:45.940000

1 posts

A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.

1 repos

https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-62144
(9.1 CRITICAL)

EPSS: 20.62%

updated 2026-07-24T05:16:45.793000

1 posts

An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a conf

1 repos

https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-54120
(9.9 CRITICAL)

EPSS: 0.71%

updated 2026-07-24T03:31:56

1 posts

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-07-25T12:00:23.000Z ##

🔴 CVE-2026-54120 - Critical (9.9)

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-42933
(10.0 CRITICAL)

EPSS: 0.29%

updated 2026-07-24T00:32:40

1 posts

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.

DailyCyberSecurity@infosec.exchange at 2026-07-28T14:04:40.000Z ##

A Panduit IntraVUE vulnerability tracked as CVE-2026-42933 scores CVSS 10. Five flaws let attackers cross OT segmentation and steal credentials.

#PanduitIntraVUE #CVE202642933 #ICSSecurity #OTSecurity

securityonline.info/panduit-in

##

CVE-2026-21655(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-07-23T21:31:03

2 posts

Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0.

DailyCyberSecurity at 2026-07-29T14:30:41.058Z ##

A C-CURE 9000 vulnerability chain hits CVSS 9.6. CVE-2026-21655 allows remote code execution on Johnson Controls victor application servers.

securityonline.info/c-cure-900

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T14:30:41.000Z ##

A C-CURE 9000 vulnerability chain hits CVSS 9.6. CVE-2026-21655 allows remote code execution on Johnson Controls victor application servers.

#CCURE9000 #CVE202621655 #JohnsonControls #ICSSecurity

securityonline.info/c-cure-900

##

CVE-2026-6516
(10.0 CRITICAL)

EPSS: 4.73%

updated 2026-07-23T18:31:54

1 posts

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-63108
(8.8 HIGH)

EPSS: 1.92%

updated 2026-07-23T15:24:59.880000

1 posts

Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions inside parameter expansion defaults. The command parser in parse-command.ts replaces parameter expansions with opaque placeholders before extracting command substitutions, causing the containsDangerous

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-63766
(9.8 CRITICAL)

EPSS: 1.75%

updated 2026-07-23T15:24:59.880000

1 posts

GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into shell commands executed with shell=True. Attackers can inject shell metacharacters through path parameters to execute arbitrary OS commands as the server process user without authentication.

1 repos

https://github.com/0xdak/CVE-2026-63766_exploit

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-59933
(7.5 HIGH)

EPSS: 0.69%

updated 2026-07-23T15:01:52

1 posts

## Summary PhpSpreadsheet's OLE reader follows sector chains from attacker-controlled XLS/OLE metadata without detecting cycles or enforcing a maximum chain length. A tiny malformed `.xls`/OLE file can set the small-block depot sector chain to point back to itself. During normal XLS detection, `OLERead::read()` appends the same sector data repeatedly until the PHP process exhausts memory. This i

thehackerwire@mastodon.social at 2026-07-28T19:00:00.000Z ##

🟠 CVE-2026-59933 - High (7.5)

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the OLE reader follows s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16723
(9.0 CRITICAL)

EPSS: 0.41%

updated 2026-07-23T15:01:24.377000

8 posts

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

3 repos

https://github.com/dinosn/fastjson-jsontype-rce-lab

https://github.com/HORKimhab/CVE-2026-16723

https://github.com/why-success/fastjson-rce-lab

netsecio@mastodon.social at 2026-07-29T16:57:09.000Z ##

📰 Unpatched FastJson RCE Zero-Day (CVE-2026-16723) Actively Exploited

🚨 ACTIVE EXPLOITATION: A critical, unpatched RCE zero-day (CVE-2026-16723) in FastJson 1.x is being exploited in the wild. Affects versions 1.2.68-1.2.83. Users must migrate to FastJson2 or enable SafeMode now! #Java #ZeroDay #CyberAttack

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/un

##

DailyCyberSecurity at 2026-07-29T12:34:32.837Z ##

Discover the critical Fastjson RCE CVE-2026-16723 vulnerability. Learn how attackers exploit Spring Boot applications and find mitigation strategies.

meterpreter.org/fastjson-rce-c

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T12:34:32.000Z ##

Discover the critical Fastjson RCE CVE-2026-16723 vulnerability. Learn how attackers exploit Spring Boot applications and find mitigation strategies.

#Fastjson #CVE202616723 #Cybersecurity #SpringBoot #Malware

meterpreter.org/fastjson-rce-c

##

threatnoir@infosec.exchange at 2026-07-29T07:07:47.000Z ##

⚠️ CRITICAL: Hackers target US firms in FastJson RCE zero-day attacks

A critical RCE zero-day (CVE-2026-16723) in FastJson Java library versions 1.2.68-1.2.83 is actively exploited against U.S. firms across multiple sectors. Attackers can execute arbitrary code without user interaction. FastJson 1.x is unmaintained, leaving affected systems without patches.

threatnoir.com/focus

#infosec #cybersecurity

##

threatnoir@infosec.exchange at 2026-07-27T08:06:02.000Z ##

⚠️ CRITICAL: Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Attackers are actively exploiting CVE-2026-16723, a critical RCE in Alibaba Fastjson 1.x used by Spring Boot applications. Unauthenticated code execution is possible with Java process privileges. No patch exists for 1.x versions yet.

threatnoir.com/focus

#infosec #cybersecurity

##

security_crawler_carl@infosec.exchange at 2026-07-26T12:49:23.000Z ##

🏆 New Achievement! Critical Hit: JSON and the Argonauts!

You have looted a CURSED ITEM: Fastjson 1.x (versions 1.2.68–1.2.83). Equip penalty: unauthenticated attackers may now execute arbitrary code on your Spring Boot applications via crafted JSON requests, bypassing default security configurations entirely. CVE-2026-16723 is active in the wild, no patch exists for the 1.x branch, and yes, that means you.

Inventory is full of regret. (1/2)

##

obivan@infosec.exchange at 2026-07-26T10:57:36.000Z ##

FastJson 1.2.83 RCE (CVE-2026-16723) fearsoff.org/research/fastjson

##

beyondmachines1@infosec.exchange at 2026-07-26T10:01:41.000Z ##

Critical Fastjson 1.x Zero-Day RCE Exploited in the Wild

Alibaba's Fastjson 1.x library is vulnerable to a critical zero-day remote code execution flaw (CVE-2026-16723) that is currently exploited in the wild against Spring Boot applications. The vulnerability allows unauthenticated attackers to run arbitrary code by bypassing default security configurations through crafted JSON requests.

**If you run Java apps using Fastjson 1.x (versions 1.2.68–1.2.83) as Spring Boot fat-JARs, your applications are actively attacked, and there is no patch for the 1.x branch. Migrate to Fastjson2 ASAP. If you can't migrate, immediately enable SafeMode by adding `-Dfastjson.parser.safeMode=true` to your JVM settings and monitor your logs for unusual `@type` values or unexpected outbound connections from Java.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-46331
(7.8 HIGH)

EPSS: 0.53%

updated 2026-07-23T12:18:18.287000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime header offset added by typed keys. This can leave part of the write region un-COW'd. Fix by moving skb

13 repos

https://github.com/HORKimhab/CVE-2026-46331

https://github.com/seguridadentrerios/CVE-2026-46331

https://github.com/g0thamRabb1t/CVE-2026-46331-pedit-COW-detection

https://github.com/V0IDNETWORK/CVE-2026-46331

https://github.com/vulnquest58/dirtyclone-exploit

https://github.com/Quaerendir/cve-2026-46331-audit

https://github.com/douglasmun/pagecache-lpe-containment-kit

https://github.com/yanxinwu946/CVE-2026-46331

https://github.com/MarwahHadi/CVE-2026-46331-pedit-cow

https://github.com/cherrycherrymay/PoC-CVE-2026-46331

https://github.com/sgkdev/packet_edit_meme

https://github.com/0xBlackash/CVE-2026-46331

https://github.com/rjt-gupta/page-cache-corruption-lpes

CVE-2026-15342
(6.5 MEDIUM)

EPSS: 0.22%

updated 2026-07-22T21:33:00

1 posts

Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID. The affected endpoints return presigned file URLs and enable destructive or duplicative actions without verifying that the requester is a member

CVE-2026-13072
(8.1 HIGH)

EPSS: 0.32%

updated 2026-07-22T21:32:15

1 posts

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or other unintended behavior. This configuration is non-default and requires explicit enablement at startup.

beyondmachines1@infosec.exchange at 2026-07-27T15:01:42.000Z ##

MongoDB Patches 26 Vulnerabilities Including Critical Memory Corruption Flaw

MongoDB released security updates to fix 26 vulnerabilities, including a critical memory corruption flaw (CVE-2026-13072) and multiple high-severity issues that allow unauthorized data access and service crashes.

**If you run self-hosted MongoDB, update your servers now to the latest patched version (7.0.39, 8.0.28, 8.2.12, 8.3.7, or 9.0.0-rc1). There's a critical flaw that could let attackers crash your database or run their own code. If you use MongoDB Atlas or another managed service, you're already covered and don't need to do anything.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-16232
(9.1 CRITICAL)

EPSS: 69.97%

updated 2026-07-22T21:32:05

8 posts

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server I

Nuclei template

2 repos

https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

https://github.com/sfewer-r7/CVE-2026-16232

threatcodex at 2026-07-29T13:18:07.384Z ##

Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)

rapid7.com/blog/post/ra-check-

##

undercodenews@mastodon.social at 2026-07-29T10:06:53.000Z ##

Critical Check Point Zero-Day Under Active Attack: How CVE-2026-16232 Gives Hackers Full Administrative Control + Video

Introduction: Another Wake-Up Call for Enterprise Cybersecurity Enterprise security appliances are designed to protect organizations from cyberattacks, but what happens when those very systems become the target? That is exactly the concern surrounding CVE-2026-16232, a newly disclosed critical vulnerability affecting Check Point Security Management…

undercodenews.com/critical-che

##

Analyst207@mastodon.social at 2026-07-29T09:24:59.000Z ##

Check Point Flaw Exploited as Researchers Release Public PoC

A critical flaw in Check Point's SmartConsole, known as CVE-2026-16232, allows hackers to bypass authentication and gain full administrative privileges with a staggering CVSS score of 9.3. This vulnerability lets unauthenticated remote attackers obtain a login token and take control, potentially modifying security policies and…

osintsights.com/check-point-fl

#Cve202616232 #CheckPoint #AuthenticationBypass #Smartconsole #Vulnerability

##

threatcodex@infosec.exchange at 2026-07-29T13:18:07.000Z ##

Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
#CVE_2026_16232
rapid7.com/blog/post/ra-check-

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T02:27:22.000Z ##

CVE-2026-16232 is a SmartConsole authentication bypass in Check Point Security Management. Exploited in the wild, with a public PoC now available.

#CheckPoint #SmartConsole #CVE202616232 #AuthenticationBypass #ZeroDay #CyberSecurity

securityonline.info/check-poin

##

hackmag@infosec.exchange at 2026-07-28T21:30:05.000Z ##

⚪️ Hackers Exploit a Zero-Day in Check Point SmartConsole

🗨️ Check Point has warned customers about a critical vulnerability, CVE-2026-16232, affecting its Security Management and Multi-Domain Management products. The flaw allows attackers to bypass authentication, gain administrator privileges, and modify security policies. The vulnerability is already be…

🔗 hackmag.com/news/cve-2026-1623

#news

##

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

DailyCyberSecurity@infosec.exchange at 2026-07-26T15:30:52.000Z ##

Discover the critical CVE-2026-16232 vulnerability in Check Point Security Management servers, allowing remote attackers to gain full administrative privileges without a password.

#CheckPoint #CyberSecurity #CVE202616232 #NetworkSecurity #Vulnerability

meterpreter.org/check-point-se

##

CVE-2026-50522
(9.8 CRITICAL)

EPSS: 57.10%

updated 2026-07-22T21:31:51

2 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

5 repos

https://github.com/ChPratik/CVE-2026-50522

https://github.com/webshellseo8/CVE-2026-50522-Proof-of-Concept

https://github.com/darses/CVE-2026-50522

https://github.com/4minx/CVE-2026-50522

https://github.com/HORKimhab/CVE-2026-50522

beyondmachines1@infosec.exchange at 2026-07-27T19:01:42.000Z ##

State of (in)security - Week 30, 2026

During week 30 of 2026, cybersecurity monitoring recorded 7 advisories and 28 incidents/breaches affecting roughly 80 million individuals. The largest breach is Suno exposing 55.3 million users and AI training source code. Malware/ransomware and unauthorized access are the leading causes of incidents and healthcare and IT/software as the most-targeted industries.

**Patch the actively exploited on-premises SharePoint (CVE-2026-50522), self-hosted ServiceNow, Fastjson 1.x Java apps, Oracle systems (July 2026 Critical Patch Update), and WordPress. Then update Firefox and Thunderbird and confirm your Adobe Acrobat Chrome extension is running version 26.5.2.3 or later.**
#cybersecurity #infosec #knowledge #weeklyreport
beyondmachines.net/event_detai

##

security_crawler_carl@infosec.exchange at 2026-07-26T15:21:30.000Z ##

🏆 New Achievement! Stand In the Fire, Lose the SharePoint!

MOVE OUT OF THE DESERIALIZATION FLAW. I AM NOT KIDDING. CVE-2026-50522 is a CVSS 9.8 critical hole in on-premises Microsoft SharePoint — remote code execution, low complexity, no special system knowledge required. Researchers at watchTowr and Defused are screaming in chat right now because exploit code just dropped and attackers are already in your server. (1/2)

##

CVE-2026-53359
(8.8 HIGH)

EPSS: 0.91%

updated 2026-07-22T21:31:50

1 posts

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. Th

6 repos

https://github.com/Aoripus-LTD/Januscape-Hotfix

https://github.com/xj2268-TA/KVM-Januscape

https://github.com/chuzhongyun/CVE-2026-53359-Kernel-Fix

https://github.com/ndouglas-cloudsmith/CVE-2026-53359

https://github.com/0xBlackash/CVE-2026-53359

https://github.com/HORKimhab/CVE-2026-53359

benoit@benoit.jp.net at 2026-07-25T12:29:58.000Z ##

I wonder how many hosters are vulnerable to CVE-2026-53359 (Januscape). Probably a lot.

##

CVE-2026-10702
(4.3 MEDIUM)

EPSS: 0.55%

updated 2026-07-22T19:10:00.120000

1 posts

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.

Analyst207@mastodon.social at 2026-07-29T13:26:47.000Z ##

Firefox Flaw Exploited by Malicious Webpage

A single visit to a malicious webpage is all it takes to compromise your Firefox browser, thanks to a recently exploited flaw tracked as CVE-2026-10702. No settings changes or extra interaction required - just a simple visit can leave you vulnerable.

osintsights.com/firefox-flaw-e

#Firefox #Cve202610702 #JitCompiler #BrowserVulnerability #RemoteCompromise

##

CVE-2026-49176
(7.8 HIGH)

EPSS: 0.40%

updated 2026-07-22T16:17:28.753000

2 posts

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

2 repos

https://github.com/777erp/CVE-2026-49176_BOF

https://github.com/DavidCarliez/CVE-2026-49176_LPE_POC

CVE-2026-60137
(5.9 MEDIUM)

EPSS: 77.97%

updated 2026-07-22T05:17:11.750000

1 posts

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

45 repos

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/ikow/wp2shell

https://github.com/kulichr/wp2shell

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/shinthink/CVE-2026-63030

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/yuag/wp2shell

https://github.com/dinosn/wp2shell-lab

https://github.com/zi3lak/wp2shell_scanner

https://github.com/ekomsSavior/wp2shell

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/northsia/CVE-2026-60137-With-Skip-SSL

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/Icex0/wp2shell-poc

https://github.com/bahartanir/wp2shell-scanner

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/Crypto-Cat/wp2shell

https://github.com/0xsha/wp2shell

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/NULL200OK/WP2Shell

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/mcipekci/wp2shell

https://github.com/vulnquest58/PressVector

https://github.com/47Cid/wp2shell-lab

https://github.com/0xWhoknows/wp2shell

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/securelayer7/WordPresShell

https://github.com/Iqbalx7/wp2shell

https://github.com/ebrasha/abdal-cve-2026-60137

https://github.com/0xjessie21/wp2shell-checker

https://github.com/h4cd0c/wp2shell

https://github.com/ananay/wp2shell-lab

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

stux@mstdn.social at 2026-07-27T13:21:48.000Z ##

Holy shit

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

" Independent proof-of-concept for the unauthenticated WordPress REST batch route-confusion SQL injection associated with Searchlight Cyber's wp2shell advisory."

github.com/Icex0/wp2shell-poc

#WordPress #RCE

##

CVE-2026-8985(CVSS UNKNOWN)

EPSS: 4.19%

updated 2026-07-22T00:32:44

1 posts

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-64606
(9.8 CRITICAL)

EPSS: 0.63%

updated 2026-07-21T21:33:35

1 posts

Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users are recommended to upgrade to version 1.4.0, which fixes the issue.

CVE-2026-64879
(9.9 CRITICAL)

EPSS: 2.59%

updated 2026-07-21T21:32:47

1 posts

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-40510
(3.8 LOW)

EPSS: 0.22%

updated 2026-07-21T12:10:00.090000

2 posts

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device returning a URL field longer than 118 bytes in the Key History Object ASN.1 response.

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-2291
(7.3 HIGH)

EPSS: 0.92%

updated 2026-07-20T21:31:40

2 posts

dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.

1 repos

https://github.com/JianrongXiao-Linksys/dnsmasq-cve-2026

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-53362
(7.8 HIGH)

EPSS: 0.27%

updated 2026-07-18T09:32:17

1 posts

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length +

CVE-2026-42530
(8.1 HIGH)

EPSS: 3.68%

updated 2026-07-16T12:33:31

1 posts

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers

3 repos

https://github.com/0xBlackash/CVE-2026-42530

https://github.com/v4ltonn/CVE-2026-42530

https://github.com/HORKimhab/CVE-2026-42530

CVE-2026-15410
(7.2 HIGH)

EPSS: 76.35%

updated 2026-07-16T05:16:18.470000

1 posts

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

3 repos

https://github.com/HORKimhab/CVE-2026-15410

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

thecybermind@infosec.exchange at 2026-07-26T17:26:03.000Z ##

🚨 Active Exploit Warning: SonicWall SMA1000 appliances are under fire from a high-severity code injection flaw (CVE-2026-15410). Our latest TSUITE brief breaks down the CrowdStrike detection logic and immediate hardening steps to secure your management interfaces. Command the wire: thecybermind.co/jily

#SOC

##

CVE-2023-4346
(7.5 HIGH)

EPSS: 0.91%

updated 2026-07-16T05:16:16.603000

1 posts

KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to i

thecybermind@infosec.exchange at 2026-07-25T17:04:55.000Z ##

(CISA TS-MAN) CVE-2023-4346 – KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability

Severity: HIGH Impact Summary: An attacker could purge all devices and set a BCU key to lock the device, potentially resulting in denial of service if additional security options are not enabled....

thecybermind.co/2026/07/25/cis

##

CVE-2026-46817
(9.8 CRITICAL)

EPSS: 13.31%

updated 2026-07-15T18:32:50

1 posts

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Con

2 repos

https://github.com/HORKimhab/CVE-2026-46817

https://github.com/0xBlackash/CVE-2026-46817

thecybermind@infosec.exchange at 2026-07-25T17:07:36.000Z ##

(CISA TS-MAN) CVE-2026-46817 – Oracle E-Business Suite Improper Privilege Management Vulnerability

Severity: CRITICAL Impact Summary: Allows unauthenticated attacker to compromise Oracle Payments, potentially resulting in full takeover....

thecybermind.co/2026/07/25/cis

##

CVE-2026-56155
(7.8 HIGH)

EPSS: 2.33%

updated 2026-07-14T21:32:52

1 posts

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

thecybermind@infosec.exchange at 2026-07-25T16:43:09.000Z ##

(CISA TS-MAN) CVE-2026-56155 – Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Severity: HIGH Impact Summary: Allows an authorized attacker to locally elevate privileges due to insufficient granularity of access control....

thecybermind.co/2026/07/25/cis

##

DailyCyberSecurity at 2026-07-29T13:30:38.224Z ##

Certighost AD CS vulnerability details and PoC code for CVE-2026-54121 are public. The flaw let a low-privileged user impersonate a Domain Controller.

securityonline.info/certighost

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T13:30:38.000Z ##

Certighost AD CS vulnerability details and PoC code for CVE-2026-54121 are public. The flaw let a low-privileged user impersonate a Domain Controller.

#Certighost #CVE202654121 #ADCS #ActiveDirectory

securityonline.info/certighost

##

tugatech@masto.pt at 2026-07-28T16:03:08.000Z ##

Exploit público para a falha Certighost expôs domínios do Windows a controlo total. Uma nova vulnerabilidade, rastreada como CVE-2026-54121, coloca redes empresariais em risco e permite que um atacante assuma o controlo completo de um domínio informático. 🚨

🔗 tugatech.com.pt/t88205-exploit

#controlo #exploit #falha #windows 

##

obivan@infosec.exchange at 2026-07-27T18:24:41.000Z ##

CertiGhost fork - Patched SAN handling + MAQ-safe account reuse github.com/marcgoam/CVE-2026-5

##

al3x-n3ff.bsky.social@bsky.brid.gy at 2026-07-26T17:51:24.488Z ##

Detect the Certighost with NetExec🔥

Thanks to Xed_sama, the enum_cve module of NetExec will now detect if a host has not been patched and is potentially vulnerable to the Certighost vulnerability (CVE-2026-54121)🚀

##

guru@thecybersecguru.com at 2026-07-26T05:47:01.000Z ##

Certighost Exploit Allows Low-Privileged Active Directory Users to Impersonate a Domain Controller

A newly disclosed AD CS vulnerability, Certighost (CVE-2026-54121), allows low-privileged domain users to impersonate a Domain Controller

thecybersecguru.com/news/certi

##

CVE-2026-50502
(8.0 HIGH)

EPSS: 0.60%

updated 2026-07-14T18:32:33

3 posts

Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.

DailyCyberSecurity at 2026-07-29T13:04:49.233Z ##

A public PoC exploit now targets CVE-2026-50502, an RCE in the Windows Event Log service. Microsoft patched the flaw on July 14, 2026. Details below.

securityonline.info/cve-2026-5

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T13:04:49.000Z ##

A public PoC exploit now targets CVE-2026-50502, an RCE in the Windows Event Log service. Microsoft patched the flaw on July 14, 2026. Details below.

#CVE202650502 #WindowsEventLog #RCE #PatchTuesday #InfoSec #Microsoft

securityonline.info/cve-2026-5

##

DailyCyberSecurity@infosec.exchange at 2026-07-27T13:34:15.000Z ##

Microsoft has patched a critical Windows Event Logging vulnerability (CVE-2026-50502) allowing remote code execution. Update your systems immediately.

#Microsoft #Vulnerability #CyberSecurity #WindowsServer #CVE202650502

meterpreter.org/windows-event-

##

CVE-2026-50469
(7.8 HIGH)

EPSS: 0.27%

updated 2026-07-14T18:32:32

2 posts

Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.

CVE-2025-15467
(9.8 CRITICAL)

EPSS: 47.62%

updated 2026-07-14T15:32:45

2 posts

Issue summary: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 para

6 repos

https://github.com/materaj2/cve-2025-15467

https://github.com/balgan/CVE-2025-15467

https://github.com/WostGit/cve-2025-15467-crash

https://github.com/x-stp/cves-2025-11187_15467_69418

https://github.com/guiimoraes/CVE-2025-15467

https://github.com/mr-r3b00t/CVE-2025-15467

beyondmachines1 at 2026-07-29T09:01:49.957Z ##

Siemens Patches Critical OpenSSL Flaw in Desigo CC Building Management Systems

Siemens released security updates for Desigo CC to address a critical OpenSSL vulnerability (CVE-2025-15467) that allows unauthenticated remote code execution or denial of service through malformed cryptographic messages.

**First, make sure all Desigo CC building management systems are isolated from the internet and reachable only from trusted networks. Then, if you run V9 update to V9.0 QU1 (or later) and if you run V8 apply patch V8.0 QU2.0021; for V7 there is no patch yet.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-07-29T09:01:49.000Z ##

Siemens Patches Critical OpenSSL Flaw in Desigo CC Building Management Systems

Siemens released security updates for Desigo CC to address a critical OpenSSL vulnerability (CVE-2025-15467) that allows unauthenticated remote code execution or denial of service through malformed cryptographic messages.

**First, make sure all Desigo CC building management systems are isolated from the internet and reachable only from trusted networks. Then, if you run V9 update to V9.0 QU1 (or later) and if you run V8 apply patch V8.0 QU2.0021; for V7 there is no patch yet.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-55255
(8.4 HIGH)

EPSS: 29.05%

updated 2026-07-07T22:14:37

1 posts

## Summary Insecure Direct Object Reference (IDOR) vulnerability in `/api/v1/responses` endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. ## Details The vulnerability exists in the `get_flow_by_id_or_endpoint_name` helper function in [`src/backend/base/langflow/helpers/flow.py` (lines 399-414)](https://gith

1 repos

https://github.com/rootdirective-sec/CVE-2026-55255-Lab

thecybermind@infosec.exchange at 2026-07-25T17:06:29.000Z ##

(CISA TS-MAN) CVE-2026-55255 – Langflow Authorization Bypass Through User-Controlled Key Vulnerability

Severity: HIGH Impact Summary: An authenticated attacker can execute any flow belonging to another user by specifying the victim's flow ID in the request, bypassing authorization controls....

thecybermind.co/2026/07/25/cis

##

CVE-2026-12569
(9.8 CRITICAL)

EPSS: 2.26%

updated 2026-06-30T18:16:43.113000

3 posts

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

1 repos

https://github.com/west-wind/Threat-Hunting-With-Splunk

threatnoir@infosec.exchange at 2026-07-27T08:05:59.000Z ##

⚠️ CRITICAL: Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Cl0p ransomware affiliates are actively exploiting unauthenticated RCE vulnerabilities in internet-exposed PTC Windchill and FlexPLM instances by chaining CVE-2026-12569 with a separate information disclosure flaw. Affected organizations in manufacturing, automotive, aerospace, and retail face data…

threatnoir.com/focus

#infosec #cybersecurity

##

threatcodex@infosec.exchange at 2026-07-26T18:35:42.000Z ##

Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)
#Cl0p #CVE_2026_12569
ransom-isac.org/blog/clop-wind

##

threatnoir@infosec.exchange at 2026-07-26T05:15:05.000Z ##

2026-W30 — Weekly Threat Roundup

🦅 Russian APT Laundry Bear exploited a Zimbra zero-click XSS flaw (CVE-2025-66376) to steal emails and MFA tokens from NATO, US, and Ukrainian targets with no user interaction required.
🏭 Clop affiliates are mass-exploiting PTC Windchill and FlexPLM (CVE-2026-12569) for unauthenticated RCE and da…

threatnoir.com/weekly/2026-w30

#infosec #cybersecurity #threatintel

##

CVE-2026-5172
(7.3 HIGH)

EPSS: 2.68%

updated 2026-06-30T03:37:45

2 posts

A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.

2 repos

https://github.com/JianrongXiao-Linksys/dnsmasq-cve-2026

https://github.com/lottiedeyan/CVE20265172poc

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-42945
(8.1 HIGH)

EPSS: 61.47%

updated 2026-06-27T06:30:25

2 posts

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond it

42 repos

https://github.com/p3Nt3st3r-sTAr/CVE-2026-42945-POC

https://github.com/nu0l/NGINX-Rift

https://github.com/imSre9/CVE-2026-42945

https://github.com/quantumworld-dpdns-io/CVE-2026-42945

https://github.com/Renison-Gohel/CVE-2026-42945-NGINX-Rift

https://github.com/dinosn/cve-2026-42945-nginx32-lab

https://github.com/azilRababe/CVE-2026-42945

https://github.com/cipherspy/CVE-2026-42945-POC

https://github.com/edgecases-PurpleHax/cve-images

https://github.com/F2u0a0d3/CVE-2026-42945-nginx-rift-poc

https://github.com/yusufdalbudak/CVE-2026-42945

https://github.com/nanwinata/nginxrift-CVE-2026-42945

https://github.com/webdev75950-ux/nginx-rce-cve-2026-42945

https://github.com/chenqin231/CVE-2026-42945

https://github.com/hnytgl/CVE-2026-42945

https://github.com/realityone/cve-2026-42945-scan

https://github.com/soksofos/wazuh-nginx-cve-2026-42945-sca-lab

https://github.com/byezero/nginx-cve-2026-42945-check

https://github.com/lowilol/CVE-2026-42945-NGINX-Rift-Check-Script

https://github.com/iammerrida-source/nginx-rift-detect

https://github.com/sec-sys/CVE-2026-42945-Reverse-Shell-POC

https://github.com/hulina9900-boop/DIY-CVE-2026-42945-POC

https://github.com/BarAppTeam/nginx-cve-fix

https://github.com/0xBlackash/CVE-2026-42945

https://github.com/simota/nginx-rift-scanner

https://github.com/rheodev/CVE-2026-42945

https://github.com/RedCrazyGhost/CVE-2026-42945

https://github.com/fkj-src/fix_nginx_cve_2026_42945

https://github.com/gagaltotal/CVE-2026-42945-NGINX-Rift-Toolkit

https://github.com/oseasfr/Scanner_CVE_2026-42945

https://github.com/jelasin/CVE-2026-42945

https://github.com/ChamsBouzaiene/ai-vuln-rediscovery-nginx-cve-2026-42945

https://github.com/strivepan/Nginx_cve-2026-42945-scanner-gui

https://github.com/MateusVerass/nGixshell

https://github.com/limo57640-crypto/nginx-rift-detector

https://github.com/tal7aouy/nginx-cve-2026-42945

https://github.com/sibersan/web-server-audit_CVE-2026-42945

https://github.com/aratane/CVE-2026-42945

https://github.com/forxiucn/nginx-cve-2026-42945-poc

https://github.com/LiaoZiqi-GZFLS/CVE-2026-42945

https://github.com/friparia/NGINX_RIFT_SCAN_CVE_2026_42945

https://github.com/josephfelix/CVE-2026-42945-nginx-rift

security_crawler_carl@infosec.exchange at 2026-07-27T05:03:52.000Z ##

You do not get to respawn. The debuff is applied to all servers simultaneously. Enjoy your stay.

Patch NGINX now to address CVE-2026-42945 before the PoC makes your threat landscape significantly more crowded.

Reward: You've received the Mandatory Participation Trophy — it's just a heap of broken memory.

#Nginx #RCE #CyberSecurity #ZeroDay #BufferOverflow #ExploitUnlocked (2/2)

##

security_crawler_carl@infosec.exchange at 2026-07-27T05:03:51.000Z ##

🏆 New Achievement! Heap Today, Gone Tomorrow!

Welcome, new player, to the NGINX Rift tutorial! This mandatory onboarding introduces CVE-2026-42945, a critical heap buffer overflow in NGINX that enables remote code execution. A proof-of-concept exploit has now been published publicly, which means this mechanic is fully unlocked for every participant — including the ones you did not invite.

Think of it like Minecraft's Hardcore Mode, except the world was already on fire when you loaded in. (1/2)

##

CVE-2026-0160
(8.8 HIGH)

EPSS: 0.23%

updated 2026-06-17T18:36:29

1 posts

In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

0v1@infosec.exchange at 2026-07-28T15:06:01.000Z ##

@drwhax also CVE-2026-0160 affecting RTT (US mandated). Reachability is via RTT call.

##

CVE-2026-0149
(8.8 HIGH)

EPSS: 0.29%

updated 2026-06-17T18:36:28

1 posts

In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2026-4893
(5.3 MEDIUM)

EPSS: 2.68%

updated 2026-06-17T10:57:24.507000

2 posts

An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.

5 repos

https://github.com/lottiedeyan/CVE20264893poc

https://github.com/shinthink/CVE-2026-48939

https://github.com/Polosss/By-Poloss..-..CVE-2026-48939

https://github.com/JianrongXiao-Linksys/dnsmasq-cve-2026

https://github.com/ChiefYoru/CVE-2026-48939_PoC

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-22796
(5.3 MEDIUM)

EPSS: 0.50%

updated 2026-06-17T10:20:26.697000

2 posts

Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data. Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attribu

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-22795
(5.5 MEDIUM)

EPSS: 0.14%

updated 2026-06-17T10:20:26.520000

2 posts

Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2026-1623
(6.3 MEDIUM)

EPSS: 2.18%

updated 2026-06-17T10:16:12.407000

1 posts

A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument FileName causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

1 repos

https://github.com/sfewer-r7/CVE-2026-16232

hackmag@infosec.exchange at 2026-07-28T21:30:05.000Z ##

⚪️ Hackers Exploit a Zero-Day in Check Point SmartConsole

🗨️ Check Point has warned customers about a critical vulnerability, CVE-2026-16232, affecting its Security Management and Multi-Domain Management products. The flaw allows attackers to bypass authentication, gain administrator privileges, and modify security policies. The vulnerability is already be…

🔗 hackmag.com/news/cve-2026-1623

#news

##

CVE-2025-69421
(7.5 HIGH)

EPSS: 0.84%

updated 2026-06-17T10:00:40.683000

2 posts

Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files. The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When

1 repos

https://github.com/Kha-Beleh/PoC-CVE-2025-69421

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2025-69420
(7.5 HIGH)

EPSS: 0.77%

updated 2026-06-17T10:00:40.067000

2 posts

Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file. Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to deref

1 repos

https://github.com/Kha-Beleh/PoC-CVE-2025-69420

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2025-66376
(7.2 HIGH)

EPSS: 21.62%

updated 2026-06-17T09:56:44.753000

1 posts

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

threatnoir@infosec.exchange at 2026-07-26T05:15:05.000Z ##

2026-W30 — Weekly Threat Roundup

🦅 Russian APT Laundry Bear exploited a Zimbra zero-click XSS flaw (CVE-2025-66376) to steal emails and MFA tokens from NATO, US, and Ukrainian targets with no user interaction required.
🏭 Clop affiliates are mass-exploiting PTC Windchill and FlexPLM (CVE-2026-12569) for unauthenticated RCE and da…

threatnoir.com/weekly/2026-w30

#infosec #cybersecurity #threatintel

##

CVE-2024-1813
(9.8 CRITICAL)

EPSS: 1.11%

updated 2026-06-17T07:05:03.993000

1 posts

The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted input in the job_board_applicant_list_columns_value function. This makes it possible for unauthenticated attackers to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could al

2 repos

https://github.com/webshellseo8/CVE-2024-1813-Proof-of-Concept

https://github.com/MobetaSec/CVE-2024-1813-POC

_r_netsec@infosec.exchange at 2026-07-28T14:13:04.000Z ##

Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) mobeta.fr/simple-job-board-una

##

CVE-2023-5217
(8.8 HIGH)

EPSS: 49.01%

updated 2026-06-17T06:48:06.467000

1 posts

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

3 repos

https://github.com/Trinadh465/platform_external_libvpx_v1.8.0_CVE-2023-5217

https://github.com/UT-Security/cve-2023-5217-poc

https://github.com/Trinadh465/platform_external_libvpx_v1.4.0_CVE-2023-5217

nyanbinary@infosec.exchange at 2026-07-28T14:50:54.000Z ##

now to figure out if CVE-2023-5217 on our NAS actually matters...

##

CVE-2014-0160
(7.5 HIGH)

EPSS: 100.00%

updated 2026-06-17T00:02:24.467000

2 posts

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

Nuclei template

75 repos

https://github.com/proactiveRISK/heartbleed-extention

https://github.com/titanous/heartbleeder

https://github.com/caiqiqi/OpenSSL-HeartBleed-CVE-2014-0160-PoC

https://github.com/Saymeis/HeartBleed

https://github.com/mozilla-services/Heartbleed

https://github.com/cbk914/heartbleed-checker

https://github.com/22imer/CVE-2014-0160

https://github.com/belmind/heartbleed

https://github.com/iwaffles/heartbleed-test.crx

https://github.com/rouze-d/heartbleed

https://github.com/victoriacfigueiredo/heartbleed-lab

https://github.com/0x90/CVE-2014-0160

https://github.com/isgroup/openmagic

https://github.com/xanas/heartbleed.py

https://github.com/hreese/heartbleed-dtls

https://github.com/h3x0v3rl0rd/CVE-2014-0160_Heartbleed

https://github.com/cheese-hub/heartbleed

https://github.com/amerine/coronary

https://github.com/OffensivePython/HeartLeak

https://github.com/Ryo-Soikutsu/Heartbleed

https://github.com/fb1h2s/CVE-2014-0160

https://github.com/ice-security88/CVE-2014-0160

https://github.com/Xyl2k/CVE-2014-0160-Chrome-Plugin

https://github.com/DisK0nn3cT/MaltegoHeartbleed

https://github.com/GuillermoEscobero/heartbleed

https://github.com/sammyfung/openssl-heartbleed-fix

https://github.com/cved-sources/cve-2014-0160

https://github.com/0xinf0/bleeding_onions

https://github.com/musalbas/heartbleed-masstest

https://github.com/DominikTo/bleed

https://github.com/artofscripting-zz/cmty-ssl-heartbleed-CVE-2014-0160-HTTP-HTTPS

https://github.com/anthophilee/A2SV--SSL-VUL-Scan

https://github.com/undacmic/heartbleed-proof-of-concept

https://github.com/iSCInc/heartbleed

https://github.com/indrajeetmp11/Heartbleed-PoC-Exploit-Script

https://github.com/GeeksXtreme/ssl-heartbleed.nse

https://github.com/hmlio/vaas-cve-2014-0160

https://github.com/cyphar/heartthreader

https://github.com/yryz/heartbleed.js

https://github.com/tungduongNT/CVE-2014-0160.

https://github.com/vortextube/ssl_scanner

https://github.com/SimoesCTT/CTT-HEARTBLEED-Temporal-Resonance-Memory-Leak-Exploit-Heartbleed-CVE-2014-0160

https://github.com/ingochris/heartpatch.us

https://github.com/indiw0rm/-Heartbleed-

https://github.com/ThanHuuTuan/Heartexploit

https://github.com/waqasjamal-zz/HeartBleed-Vulnerability-Checker

https://github.com/froyo75/Heartbleed_Dockerfile_with_Nginx

https://github.com/pblittle/aws-suture

https://github.com/PinkP4nther/Heartbleed_PoC

https://github.com/hybridus/heartbleedscanner

https://github.com/pierceoneill/bleeding-heart

https://github.com/MrE-Fog/CVE-2014-0160-Chrome-Plugin

https://github.com/takeshixx/ssl-heartbleed.nse

https://github.com/tomdevman/heartbleed-bug

https://github.com/siddolo/knockbleed

https://github.com/xlucas/heartbleed

https://github.com/obayesshelton/CVE-2014-0160-Scanner

https://github.com/a0726h77/heartbleed-test

https://github.com/Shayhha/HeartbleedAttack

https://github.com/Lekensteyn/pacemaker

https://github.com/FiloSottile/Heartbleed

https://github.com/timsonner/cve-2014-0160-heartbleed

https://github.com/0xBlackash/CVE-2014-0160

https://github.com/jdauphant/patch-openssl-CVE-2014-0160

https://github.com/GardeniaWhite/fuzzing

https://github.com/yashfren/CVE-2014-0160-HeartBleed

https://github.com/marstornado/cve-2014-0160-Yunfeng-Jiang

https://github.com/idkqh7/heatbleeding

https://github.com/ArtemCyberLab/Project-Field-Analysis-and-Memory-Leak-Demonstration

https://github.com/mpgn/heartbleed-PoC

https://github.com/WildfootW/CVE-2014-0160_OpenSSL_1.0.1f_Heartbleed

https://github.com/zouguangxian/heartbleed

https://github.com/roganartu/heartbleedchecker-chrome

https://github.com/sensepost/heartbleed-poc

https://github.com/einaros/heartbleed-tools

g0rb at 2026-07-29T17:09:54.504Z ##

Shodan-Query of the day:

asn:"AS59399" vuln:"cve-2014-0160"

##

g0rb@infosec.exchange at 2026-07-29T17:09:54.000Z ##

Shodan-Query of the day:

asn:"AS59399" vuln:"cve-2014-0160"

#ThruntersAnonymous #shodansafari #yeet

##

CVE-2013-4786
(7.5 HIGH)

EPSS: 78.57%

updated 2026-06-16T23:57:53.617000

1 posts

The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.

1 repos

https://github.com/fin3ss3g0d/CosmicRakp

hrbrmstr@mastodon.social at 2026-07-28T12:18:05.000Z ##

RE: infosec.exchange/@BleepingComp

The firm that provided the story to BC is a new startup aiming to help "Manage and Secure Data Centers".

They exploited CVE-2013-4786

This is advertising a new startup by flogging a report by extremely lazy "researchers" (did they even do *any* "is this a honeypot" tests?)

Perhaps don't let your C-suite give Lava any business?

##

CVE-2008-1028
(0 None)

EPSS: 4.55%

updated 2026-06-16T22:50:50.330000

1 posts

Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document file, as demonstrated by opening the document with TextEdit.

rosyna@mastodon.social at 2026-07-27T21:40:58.000Z ##

Apple was much more verbose in describing security issues in 2008 (look at CVE-2008-1028)
support.apple.com/en-ie/102486

##

CVE-2026-47668
(10.0 CRITICAL)

EPSS: 4.34%

updated 2026-06-05T16:25:28

1 posts

### Summary DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. ### Details #### Step 1:

Nuclei template

1 repos

https://github.com/Nxploited/CVE-2026-47668

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-42897
(8.1 HIGH)

EPSS: 5.64%

updated 2026-05-15T18:30:32

2 posts

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

1 repos

https://github.com/atiilla/CVE-2026-42897

DailyCyberSecurity at 2026-07-29T12:41:20.932Z ##

A TA488 half-click exploit abuses CVE-2026-42897 in Outlook Web Access to drop OWAReaper, a stealthy implant that survives device reimaging.

securityonline.info/ta488-owar

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T12:41:20.000Z ##

A TA488 half-click exploit abuses CVE-2026-42897 in Outlook Web Access to drop OWAReaper, a stealthy implant that survives device reimaging.

#TA488 #OWAReaper #HalfClickExploit #CVE202642897 #OutlookWebAccess #InfoSec

securityonline.info/ta488-owar

##

CVE-2025-68160
(4.7 MEDIUM)

EPSS: 0.15%

updated 2026-05-12T15:31:14

2 posts

Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write. Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application. The line-buffering BIO filter (BIO_f_linebuffer) is not used

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2025-69418
(4.0 None)

EPSS: 0.11%

updated 2026-05-12T15:31:14

2 posts

Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an

1 repos

https://github.com/x-stp/cves-2025-11187_15467_69418

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2025-69419
(7.4 HIGH)

EPSS: 0.44%

updated 2026-05-12T15:31:14

2 posts

Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer. Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service. The OPENSSL_uni2utf8() functi

1 repos

https://github.com/Kha-Beleh/PoC-CVE-2025-69419

certvde@infosec.exchange at 2026-07-28T09:10:27.000Z ##

#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities

Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF weidmueller.csaf-tp.certvde.co

##

certvde@infosec.exchange at 2026-07-28T09:09:08.000Z ##

#OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510

certvde.com/en/advisories/vde-

#CSAF ads-tec-iit.csaf-tp.certvde.co

##

CVE-2025-29827
(9.9 CRITICAL)

EPSS: 1.36%

updated 2025-06-05T15:32:29

1 posts

Improper Authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.

security_crawler_carl@infosec.exchange at 2026-07-26T16:52:38.000Z ##

By continuing to run Azure Automation with default settings, you hereby agree to the following terms: (1) your tenant identity may be made available to any registered Azure user who wishes to borrow it, (2) your credentials, cloud workloads, and data shall be considered shared resources, and (3) you waive all complaints regarding CVE-2025-29827, CVSS 9.9, which allowed any attacker with their own Azure Automation account to vault the trust boundary and impersonate another tenant entirely. (2/3)

##

CVE-2026-56848
(0 None)

EPSS: 0.00%

8 posts

N/A

nodejs_release_watcher@kodesumber.com at 2026-07-29T17:29:15.000Z ##

2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

DailyCyberSecurity at 2026-07-29T15:30:05.730Z ##

Node.js patched 11 vulnerabilities in its July 2026 release. The high-severity bugs include a HTTP/2 use-after-free (CVE-2026-56848). Update now.

securityonline.info/nodejs-jul

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:01.000Z ##

2026-07-29, Version 26.5.1 (Current), @RafaelGSS

This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:00.000Z ##

2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolito

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T17:29:15.000Z ##

2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T15:30:05.000Z ##

Node.js patched 11 vulnerabilities in its July 2026 release. The high-severity bugs include a HTTP/2 use-after-free (CVE-2026-56848). Update now.

#NodeJS #CVE202656848 #HTTP2 #UseAfterFree #Vulnerability #InfoSec

securityonline.info/nodejs-jul

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:01.000Z ##

2026-07-29, Version 26.5.1 (Current), @RafaelGSS

This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:00.000Z ##

2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolito

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

CVE-2026-58043
(0 None)

EPSS: 0.00%

6 posts

N/A

nodejs_release_watcher@kodesumber.com at 2026-07-29T17:29:15.000Z ##

2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:01.000Z ##

2026-07-29, Version 26.5.1 (Current), @RafaelGSS

This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:00.000Z ##

2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolito

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T17:29:15.000Z ##

2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:01.000Z ##

2026-07-29, Version 26.5.1 (Current), @RafaelGSS

This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:00.000Z ##

2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolito

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

CVE-2026-56846
(0 None)

EPSS: 0.00%

4 posts

N/A

nodejs_release_watcher@kodesumber.com at 2026-07-29T17:29:15.000Z ##

2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:00.000Z ##

2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolito

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T17:29:15.000Z ##

2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:00.000Z ##

2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolito

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

CVE-2026-59309
(0 None)

EPSS: 0.00%

7 posts

N/A

netsecio@mastodon.social at 2026-07-29T16:57:04.000Z ##

📰 VMware Patches Critical VM Escape Flaw (CVE-2026-47876) in ESXi

Broadcom patches critical VMware flaws, including a VM escape in ESXi (CVE-2026-47876) and unauthenticated RCE in vCenter (CVE-2026-59309, CVE-2026-59310). CVSS scores up to 9.8. Immediate patching is crucial. #VMware #CyberSecurity #PatchTuesday

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/vm

##

DailyCyberSecurity at 2026-07-29T12:48:35.599Z ##

Broadcom patched a critical VMware vCenter vulnerability. CVE-2026-59309 and CVE-2026-59310 both score 9.8 CVSS and allow auth bypass or code execution.

meterpreter.org/vmware-vcenter

##

offseq at 2026-07-29T12:00:27.751Z ##

VMware ESXi, vCenter, Workstation, and Fusion patched for CRITICAL flaws: CVE-2026-47876 enables VM escape and host code execution; CVE-2026-59309/59310 impact vCenter auth & RCE. Patch ASAP — no exploitation reported. radar.offseq.com/threat/critic

##

DailyCyberSecurity at 2026-07-29T10:28:35.812Z ##

Broadcom released updates to fix a critical VMware authentication bypass (CVE-2026-59309). A directory traversal flaw (CVE-2026-59310) was also patched.

securityonline.info/vmware-aut

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T12:48:35.000Z ##

Broadcom patched a critical VMware vCenter vulnerability. CVE-2026-59309 and CVE-2026-59310 both score 9.8 CVSS and allow auth bypass or code execution.

#VMware #vCenter #CVE202659309 #CVE202659310 #ESXi #InfoSec

meterpreter.org/vmware-vcenter

##

offseq@infosec.exchange at 2026-07-29T12:00:27.000Z ##

VMware ESXi, vCenter, Workstation, and Fusion patched for CRITICAL flaws: CVE-2026-47876 enables VM escape and host code execution; CVE-2026-59309/59310 impact vCenter auth & RCE. Patch ASAP — no exploitation reported. radar.offseq.com/threat/critic #OffSeq #VMware #Vuln #PatchNow

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T10:28:35.000Z ##

Broadcom released updates to fix a critical VMware authentication bypass (CVE-2026-59309). A directory traversal flaw (CVE-2026-59310) was also patched.

#VMware #CyberSecurity #CVE202659309 #InfoSec

securityonline.info/vmware-aut

##

CVE-2026-59310
(0 None)

EPSS: 0.00%

5 posts

N/A

netsecio@mastodon.social at 2026-07-29T16:57:04.000Z ##

📰 VMware Patches Critical VM Escape Flaw (CVE-2026-47876) in ESXi

Broadcom patches critical VMware flaws, including a VM escape in ESXi (CVE-2026-47876) and unauthenticated RCE in vCenter (CVE-2026-59309, CVE-2026-59310). CVSS scores up to 9.8. Immediate patching is crucial. #VMware #CyberSecurity #PatchTuesday

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/vm

##

DailyCyberSecurity at 2026-07-29T12:48:35.599Z ##

Broadcom patched a critical VMware vCenter vulnerability. CVE-2026-59309 and CVE-2026-59310 both score 9.8 CVSS and allow auth bypass or code execution.

meterpreter.org/vmware-vcenter

##

DailyCyberSecurity at 2026-07-29T10:28:35.812Z ##

Broadcom released updates to fix a critical VMware authentication bypass (CVE-2026-59309). A directory traversal flaw (CVE-2026-59310) was also patched.

securityonline.info/vmware-aut

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T12:48:35.000Z ##

Broadcom patched a critical VMware vCenter vulnerability. CVE-2026-59309 and CVE-2026-59310 both score 9.8 CVSS and allow auth bypass or code execution.

#VMware #vCenter #CVE202659309 #CVE202659310 #ESXi #InfoSec

meterpreter.org/vmware-vcenter

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T10:28:35.000Z ##

Broadcom released updates to fix a critical VMware authentication bypass (CVE-2026-59309). A directory traversal flaw (CVE-2026-59310) was also patched.

#VMware #CyberSecurity #CVE202659309 #InfoSec

securityonline.info/vmware-aut

##

CVE-2026-47876
(0 None)

EPSS: 0.00%

5 posts

N/A

netsecio@mastodon.social at 2026-07-29T16:57:04.000Z ##

📰 VMware Patches Critical VM Escape Flaw (CVE-2026-47876) in ESXi

Broadcom patches critical VMware flaws, including a VM escape in ESXi (CVE-2026-47876) and unauthenticated RCE in vCenter (CVE-2026-59309, CVE-2026-59310). CVSS scores up to 9.8. Immediate patching is crucial. #VMware #CyberSecurity #PatchTuesday

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/vm

##

jbhall56 at 2026-07-29T12:17:18.070Z ##

Three of the vulnerabilities have been assigned a ‘critical’ severity rating. One of them is CVE-2026-47876, an out-of-bounds write issue in ESXi’s VMXNET3 virtual network adapter. securityweek.com/critical-vm-e

##

offseq at 2026-07-29T12:00:27.751Z ##

VMware ESXi, vCenter, Workstation, and Fusion patched for CRITICAL flaws: CVE-2026-47876 enables VM escape and host code execution; CVE-2026-59309/59310 impact vCenter auth & RCE. Patch ASAP — no exploitation reported. radar.offseq.com/threat/critic

##

jbhall56@infosec.exchange at 2026-07-29T12:17:18.000Z ##

Three of the vulnerabilities have been assigned a ‘critical’ severity rating. One of them is CVE-2026-47876, an out-of-bounds write issue in ESXi’s VMXNET3 virtual network adapter. securityweek.com/critical-vm-e

##

offseq@infosec.exchange at 2026-07-29T12:00:27.000Z ##

VMware ESXi, vCenter, Workstation, and Fusion patched for CRITICAL flaws: CVE-2026-47876 enables VM escape and host code execution; CVE-2026-59309/59310 impact vCenter auth & RCE. Patch ASAP — no exploitation reported. radar.offseq.com/threat/critic #OffSeq #VMware #Vuln #PatchNow

##

rinsuki@mstdn.rinsuki.net at 2026-07-29T15:27:37.000Z ##

深刻度「緊急」のRails脆弱性「KindaRails2Shell」(CVE-2026-66066)の概要と対応指針 - GMO Flatt Security Blog
blog.flatt.tech/entry/kindarai

##

CVE-2026-56850
(0 None)

EPSS: 0.00%

2 posts

N/A

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:01.000Z ##

2026-07-29, Version 26.5.1 (Current), @RafaelGSS

This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:01.000Z ##

2026-07-29, Version 26.5.1 (Current), @RafaelGSS

This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...

github.com/nodejs/node/release

#nodejs #javascript

##

DailyCyberSecurity at 2026-07-29T14:01:16.103Z ##

OpenWrt Vulnerability CVE-2026-53921 Demands Immediate Action

securityexpress.info/openwrt-v

##

threatnoir at 2026-07-29T08:06:52.205Z ##

⚠️ CRITICAL: Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

OpenWrt released a critical patch (v24.10.8) for CVE-2026-53921, a stack overflow in the DHCPv6 service (odhcpd) that allows unauthenticated remote code execution as root. Any unpatched OpenWrt device is exploitable by sending crafted DHCPv6 packets. This affects routers and edge devices across ent…

threatnoir.com/focus

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T14:01:16.000Z ##

OpenWrt Vulnerability CVE-2026-53921 Demands Immediate Action

securityexpress.info/openwrt-v

##

threatnoir@infosec.exchange at 2026-07-29T08:06:52.000Z ##

⚠️ CRITICAL: Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

OpenWrt released a critical patch (v24.10.8) for CVE-2026-53921, a stack overflow in the DHCPv6 service (odhcpd) that allows unauthenticated remote code execution as root. Any unpatched OpenWrt device is exploitable by sending crafted DHCPv6 packets. This affects routers and edge devices across ent…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-60004
(0 None)

EPSS: 0.00%

1 posts

N/A

1 repos

https://github.com/HORKimhab/CVE-2026-60004

Analyst207@mastodon.social at 2026-07-29T09:26:23.000Z ##

Gitea Flaw Lets Writers Run Shell Commands via Git Hook

A newly discovered vulnerability in Gitea, rated 9.8 in severity, allows ordinary repository writers to execute shell commands as the Gitea service account by exploiting a remote code execution bug via a cleverly planted Git hook. This critical flaw, tracked as CVE-2026-60004, puts Gitea users at risk of a devastating attack.

osintsights.com/gitea-flaw-let

#RemoteCodeExecution #Gitea #Cve202660004 #GitHook #SupplyChain

##

CVE-2026-65094
(0 None)

EPSS: 0.00%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-07-29T02:15:59.000Z ##

NVIDIA BlueField has a critical VIRTIO-Net flaw, CVE-2026-65094, rated CVSS 9.0. A VM user could trigger code execution. Update to the fixed DOCA build.

#NVIDIA #BlueField #VIRTIONet #CVE202665094 #CodeExecution #CyberSecurity

securityonline.info/nvidia-blu

##

CVE-2026-63030
(0 None)

EPSS: 98.05%

1 posts

N/A

Nuclei template

70 repos

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/ChiefYoru/CVE-2026-63030_PoC

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/mrx-arafat/CVE-2026-63030-POC

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/4minx/CVE-2026-63030

https://github.com/ikow/wp2shell

https://github.com/ebrasha/abdal-cve-2026-63030

https://github.com/kulichr/wp2shell

https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner

https://github.com/gbrsh/CVE-2026-63030

https://github.com/raphy76/wp2shell-poc-fulljs

https://github.com/shinthink/CVE-2026-63030

https://github.com/mverschu/CVE-2026-63030

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/yuag/wp2shell

https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause

https://github.com/Lutfifakee-Project/wp2shell

https://github.com/dinosn/wp2shell-lab

https://github.com/zi3lak/wp2shell_scanner

https://github.com/ekomsSavior/wp2shell

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/4B3R4M4-607D/CVE-2026-63030-POC

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/0xBlackash/CVE-2026-63030

https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030

https://github.com/zeroc00I/CVE-2026-63030

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/Icex0/wp2shell-poc

https://github.com/bahartanir/wp2shell-scanner

https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030

https://github.com/Crypto-Cat/wp2shell

https://github.com/0xsha/wp2shell

https://github.com/TomorrowX6/CVE-2026-63030-poc

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/NULL200OK/WP2Shell

https://github.com/0xh7ml/CVE-2026-63030

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/c0gnit00/Wp2Shell

https://github.com/fullhunt/wp2shell-scan

https://github.com/mhtsec/CVE-2026-63030

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/mcipekci/wp2shell

https://github.com/vulnquest58/PressVector

https://github.com/CybersecSpirit/CVE-2026-63030

https://github.com/47Cid/wp2shell-lab

https://github.com/ZenithGenius/wordpress-batch-rce-lab

https://github.com/0xWhoknows/wp2shell

https://github.com/Ch4120N/CVE-2026-63030

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/securelayer7/WordPresShell

https://github.com/attackercan/wp2shell-poc2

https://github.com/Iqbalx7/wp2shell

https://github.com/0xjessie21/wp2shell-checker

https://github.com/InstaWP/wp2shell-scan

https://github.com/h4cd0c/wp2shell

https://github.com/ananay/wp2shell-lab

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/administrator-01001/CVE-2026-63030

https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030

https://github.com/imXur/WordPress-CVE-2026-63030-Analysis

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

stux@mstdn.social at 2026-07-27T13:21:48.000Z ##

Holy shit

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

" Independent proof-of-concept for the unauthenticated WordPress REST batch route-confusion SQL injection associated with Searchlight Cyber's wp2shell advisory."

github.com/Icex0/wp2shell-poc

#WordPress #RCE

##

DailyCyberSecurity@infosec.exchange at 2026-07-27T13:10:16.000Z ##

Discover how new Redis RCE exploit PoC code bypasses fixes for CVE-2026-25243 and CVE-2026-25589 across multiple Redis versions.

#Redis #Cybersecurity #RCE #Vulnerability #ExploitPoC

meterpreter.org/redis-rce-expl

##

Visit counter For Websites