## Updated at UTC 2026-09-11T05:01:51.525928

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-8778 9.8 0.00% 2 0 2026-09-11T04:18:04.617000 The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout
CVE-2026-84869 9.9 0.38% 3 0 2026-09-11T04:18:01.777000 A condition in the ScreenConnect client may allow files to be transferred and ex
CVE-2026-79641 7.5 0.67% 1 0 2026-09-11T04:17:52.993000 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application
CVE-2026-19583 9.9 0.60% 2 0 2026-09-11T04:17:24.930000 Velociraptor allows some sensitive artifacts to be gated by additional permissio
CVE-2026-0310 0 0.34% 6 0 2026-09-11T04:17:13.060000 A buffer overflow vulnerability in the XML processing functionality of Palo Alto
CVE-2026-0307 0 0.10% 1 0 2026-09-11T04:17:10.160000 Multiple local privilege escalation vulnerabilities in the Palo Alto Networks Gl
CVE-2026-82107 9.6 0.00% 4 0 2026-09-11T00:31:23 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-77807 7.5 0.00% 2 0 2026-09-11T00:31:23 The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution
CVE-2026-82100 9.6 0.00% 4 0 2026-09-11T00:31:23 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a
CVE-2026-81940 8.8 0.00% 2 0 2026-09-11T00:31:23 IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacke
CVE-2026-84889 8.8 0.00% 2 0 2026-09-11T00:31:23 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacke
CVE-2026-87958 8.1 0.00% 2 0 2026-09-11T00:31:16 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a deni
CVE-2026-86093 7.5 0.00% 2 0 2026-09-11T00:31:16 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker
CVE-2026-88044 9.1 0.00% 2 0 2026-09-10T22:47:10 ## Summary `serve/start` accepts protocol options in a per-server `proxyOpt` ob
CVE-2026-88045 7.5 0.00% 2 0 2026-09-10T22:45:14 ## Summary In streamed multipart mode, `serve s3` passes the request's declared
CVE-2026-87011 7.5 0.34% 1 0 2026-09-10T22:45:10 ## Summary The OIDC back-channel logout endpoint is unauthenticated by design,
CVE-2026-19646 9.1 0.00% 2 0 2026-09-10T22:16:55.697000 IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0
CVE-2026-41870 8.8 0.43% 1 0 2026-09-10T21:32:31 Missing Authorization, Improper Control of Generation of Code ('Code Injection')
CVE-2026-86060 None 0.40% 4 1 2026-09-10T21:32:21 RouterOS contains an argument-handling flaw in the SSH login path involving user
CVE-2026-89054 8.2 0.00% 2 0 2026-09-10T21:31:41 A missing authorization vulnerability in OpenNMS Horizon allows configuration ch
CVE-2026-89086 9.1 0.00% 2 0 2026-09-10T21:31:41 In the jose package before 0.11.0 for OCaml, library calls to validate an RSA si
CVE-2026-67277 None 0.43% 4 0 2026-09-10T21:31:20 RouterOS accepts a "related" btest connection before the corresponding primary s
CVE-2026-87016 8.1 0.33% 1 0 2026-09-10T21:23:26 ## Summary On SQLite deployments, the lookup that maps an external identity to
CVE-2026-89094 9.9 0.00% 2 0 2026-09-10T21:17:53.160000 Forgejo before 16.0.4 allows remote code execution via a crafted template reposi
CVE-2026-14873 8.0 0.24% 2 0 2026-09-10T21:17:18.500000 The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalati
CVE-2026-53938 8.2 0.24% 1 0 2026-09-10T19:57:48.533000 OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encr
CVE-2026-65639 0 0.00% 2 0 2026-09-10T19:54:25.810000 OS command injection in the advanced-rule parser of ConfigServer Security & Fire
CVE-2026-65638 0 0.00% 2 0 2026-09-10T19:54:25.810000 Improper escaping of a request URL in ConfigServer Security & Firewall allows a
CVE-2026-88052 7.8 0.00% 2 0 2026-09-10T19:54:25.810000 Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET
CVE-2026-85228 9.1 0.00% 2 0 2026-09-10T19:54:25.810000 An integer overflow in the tensor buffer validation component in Amazon Deep Jav
CVE-2026-89049 9.9 0.00% 4 0 2026-09-10T19:44:21.980000 A server-side request forgery issue due to improper validation of equivalent add
CVE-2026-67593 9.1 0.29% 2 0 2026-09-10T18:33:11 A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause
CVE-2026-89046 8.2 0.00% 2 0 2026-09-10T18:33:05 zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnera
CVE-2026-89042 9.1 0.00% 2 0 2026-09-10T18:33:04 passport-saml-encrypted through 0.1.13 makes SAML signature verification conditi
CVE-2026-88889 7.8 0.00% 2 0 2026-09-10T16:18:11.693000 Renovate before 44.14.7 contains a command injection vulnerability in the Maven
CVE-2026-88290 7.5 0.26% 2 0 2026-09-10T16:18:10.767000 GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare un
CVE-2026-13745 0 0.30% 2 0 2026-09-10T16:17:07.727000 A vulnerability in the Gemini CLI and associated GitHub Action allowed an unpriv
CVE-2026-15913 7.7 0.39% 1 0 2026-09-10T15:53:23.707000 In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteF
CVE-2026-73786 7.5 0.33% 1 1 2026-09-10T15:47:22.273000 A vulnerability in the web-based management interface of CPPM could allow an una
CVE-2026-88069 0 0.33% 2 0 2026-09-10T15:43:03.760000 Pandora contains a path traversal vulnerability in its archive extraction worker
CVE-2026-21096 None 0.41% 1 0 2026-09-10T15:34:15 Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SM
CVE-2026-19490 9.8 6.00% 2 2 2026-09-10T15:33:58 Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: f
CVE-2026-88887 8.6 0.00% 2 0 2026-09-10T15:33:28 Renovate is a dependency update automation tool. When listing tags/digests for a
CVE-2026-85983 7.8 0.14% 1 0 2026-09-10T15:17:50.033000 The Auth0 AD/LDAP Connector improperly processes a configuration value during se
CVE-2026-82533 9.6 0.42% 1 0 2026-09-10T15:17:47.593000 DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerab
CVE-2026-6485 8.2 0.12% 1 0 2026-09-10T15:17:39.427000 UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands
CVE-2026-88891 8.3 0.00% 2 0 2026-09-10T15:13:07.090000 OpenPanel fails to enforce read-only project access level on 26 of 29 mutating p
CVE-2026-88890 8.5 0.00% 2 0 2026-09-10T15:13:07.090000 OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the
CVE-2026-87995 8.7 0.22% 1 0 2026-09-10T15:10:20 ## Summary Any authenticated user with access to a shared terminal server could
CVE-2026-87996 7.7 0.21% 1 0 2026-09-10T14:50:07.813000 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI plat
CVE-2026-18351 9.8 0.77% 2 2 2026-09-10T14:39:13.757000 The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulner
CVE-2026-4800 8.1 2.76% 2 2 2026-09-10T13:20:23.210000 Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h
CVE-2026-39821 9.6 0.69% 2 0 2026-09-10T13:19:50.873000 The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels t
CVE-2026-33186 9.1 1.56% 2 1 2026-09-10T13:18:13.270000 gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have
CVE-2026-20079 10.0 74.70% 19 2 template 2026-09-10T12:48:17.580000 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-78082 None 0.49% 2 0 2026-09-10T12:31:26 Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Se
CVE-2026-8323 9.3 0.25% 2 0 2026-09-10T09:31:48 URL redirection to untrusted site ('open redirect') vulnerability in Armiya Info
CVE-2026-88289 7.5 0.33% 2 0 2026-09-10T09:31:44 GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variab
CVE-2026-87931 9.6 0.45% 1 0 2026-09-10T06:32:50 A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral
CVE-2026-15019 7.5 0.68% 2 0 2026-09-10T06:31:51 The Direct Download for WooCommerce plugin for WordPress is vulnerable to Direct
CVE-2026-85102 9.8 0.33% 6 0 2026-09-10T04:18:18.243000 Improper certificate trust validation during VPN negotiation in Check Point Quan
CVE-2026-67401 9.9 0.96% 3 3 2026-09-10T04:18:04.630000 A vulnerability in cPanel allows a mail-enabled account to achieve remote code e
CVE-2026-19584 7.7 0.19% 2 0 2026-09-10T03:30:27 Velociraptor allows for the creation of notebook backups in its default enabled
CVE-2026-79324 7.5 0.32% 1 0 2026-09-09T21:32:03 Missing authorization in the Address Delete controller in Mageplaza GDPR for Mag
CVE-2026-79323 7.5 0.33% 1 0 2026-09-09T21:31:57 Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL
CVE-2026-79322 8.6 0.28% 1 0 2026-09-09T21:31:56 SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (magep
CVE-2026-87491 8.8 0.76% 13 1 2026-09-09T21:31:35 Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remo
CVE-2025-25249 8.1 1.70% 4 0 2026-09-09T21:30:27 A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6
CVE-2026-84942 8.7 0.33% 1 0 2026-09-09T21:17:05.473000 Improper input validation in the Vega expression function implementation in Open
CVE-2026-12855 8.2 0.12% 1 0 2026-09-09T21:17:01.313000 Unvalidated memory boundary could result in arbitrary code execution. The vulner
CVE-2026-85061 10.0 0.31% 1 0 2026-09-09T21:09:13.080000 MapLibre GL JS is an interactive vector tile map library for web browsers. Prior
CVE-2026-17469 5.3 0.21% 2 0 2026-09-09T18:32:16 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause
CVE-2026-87929 9.8 0.29% 2 0 2026-09-09T18:32:12 MaxSite CMS through 109.6 ships with a hardcoded session encryption key in appli
CVE-2026-87927 8.2 0.34% 1 0 2026-09-09T18:32:12 MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the a
CVE-2026-87874 8.1 0.43% 1 0 2026-09-09T18:32:11 A flaw was found in the memcached cache plugin of the community.general Ansible
CVE-2026-83970 7.8 0.31% 1 0 2026-09-09T17:17:48.473000 Heap-based buffer overflow in Windows Biometric Service allows an authorized att
CVE-2026-57166 0 0.44% 1 0 2026-09-09T17:17:23.950000 PJSIP is a free and open source multimedia communication library written in C. P
CVE-2026-75165 6.5 0.41% 1 0 2026-09-09T16:04:24.933000 An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_
CVE-2026-85103 9.8 0.36% 7 0 2026-09-09T15:35:15 A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unau
CVE-2026-87628 8.3 0.17% 1 0 2026-09-09T15:35:03 Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjace
CVE-2026-81953 7.8 0.43% 1 0 2026-09-09T15:03:00.630000 Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized att
CVE-2026-53581 9.0 0.33% 2 0 2026-09-09T14:17:12.343000 OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1
CVE-2026-87794 8.4 0.19% 1 0 2026-09-09T12:32:22 bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in
CVE-2026-80172 9.8 0.27% 1 0 2026-09-09T12:32:22 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application
CVE-2026-87795 8.2 0.34% 1 0 2026-09-09T12:32:12 zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters
CVE-2026-69829 9.8 1.05% 1 0 2026-09-09T10:20:20.210000 Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to e
CVE-2026-79696 None 0.44% 1 0 2026-09-09T09:33:06 A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit
CVE-2026-16272 9.1 0.14% 1 0 2026-09-09T09:33:00 Use of less trusted source vulnerability in PayTR Payment and Electronic Money I
CVE-2026-76009 8.1 0.52% 2 0 2026-09-09T06:31:48 The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable
CVE-2026-87734 7.5 0.29% 1 0 2026-09-09T06:31:40 An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order
CVE-2026-81963 7.8 0.63% 8 0 2026-09-09T05:18:17.173000 Improper link resolution before file access ('link following') in Windows Update
CVE-2026-75650 10.0 2.15% 11 4 2026-09-09T05:18:07.237000 Adobe Commerce is affected by an Improper Neutralization of Special Elements Use
CVE-2025-14733 9.8 26.51% 9 1 2026-09-09T04:17:52.700000 An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process
CVE-2026-15667 7.5 0.56% 1 0 2026-09-09T03:30:51 The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)
CVE-2026-81994 8.2 0.30% 1 0 2026-09-08T21:34:41 Acrobat Reader is affected by an Improperly Controlled Modification of Object Pr
CVE-2026-82007 7.8 0.23% 1 0 2026-09-08T21:34:36 Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability
CVE-2026-85880 7.8 0.57% 8 0 2026-09-08T21:34:12 Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elev
CVE-2026-86218 9.8 0.74% 12 1 2026-09-08T21:33:02 N-central is vulnerable to a pre-auth remote code execution This issue affects N
CVE-2026-84372 9.8 0.41% 1 0 2026-09-08T20:57:52 ### Summary An improper CRLF neutralization flaw in Predis' pipeline handling o
CVE-2026-80119 7.8 0.12% 1 0 2026-09-08T20:10:30.270000 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10
CVE-2026-86206 0 0.68% 1 0 2026-09-08T19:16:41.410000 A vulnerability in the N-central internal API access control filter allows unaut
CVE-2026-78234 9.9 0.21% 1 0 2026-09-08T19:08:15.590000 A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA
CVE-2026-85008 3.7 0.12% 1 0 2026-09-08T19:07:52.113000 undici's cache interceptor documents that only safe HTTP methods are cached, but
CVE-2026-83972 7.8 0.31% 1 0 2026-09-08T18:34:21 Heap-based buffer overflow in Windows Biometric Service allows an authorized att
CVE-2026-81954 7.8 0.32% 1 0 2026-09-08T18:34:18 Use after free in Microsoft Office Excel allows an unauthorized attacker to exec
CVE-2026-83991 5.5 0.34% 1 2 2026-09-08T18:34:14 Missing authentication for critical function in Windows Cloud Files Mini Filter
CVE-2026-80081 8.8 0.47% 1 0 2026-09-08T18:34:00 Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to
CVE-2026-69730 9.8 1.05% 3 0 2026-09-08T18:33:07 Use after free in Windows DNS allows an unauthorized attacker to execute code ov
CVE-2026-69420 7.8 0.32% 1 0 2026-09-08T18:32:42 Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker
CVE-2026-20293 7.1 0.13% 1 0 2026-09-08T18:32:05 A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implem
CVE-2026-82067 8.1 0.28% 2 0 2026-09-08T18:32:04 Improper handling of case sensitivity in the configuration validation component
CVE-2026-17057 6.5 0.38% 1 0 2026-09-08T18:17:35.417000 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of
CVE-2025-20701 8.8 7.77% 1 2 2026-09-08T16:17:48.883000 In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth aud
CVE-2026-33197 None 0.12% 2 0 2026-09-08T15:32:05 AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause th
CVE-2026-85786 7.5 0.33% 1 0 2026-09-08T14:00:33.017000 Improper handling of highly compressed data in Amazon ion-java before 1.12.1 mig
CVE-2026-85012 8.0 1.06% 1 0 2026-09-08T14:00:33.017000 Improper neutralization of special elements used in an OS command (CWE-78) in th
CVE-2026-85703 6.5 0.33% 1 0 2026-09-08T13:12:58.310000 A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca926
CVE-2026-31431 7.8 99.91% 1 100 2026-09-08T09:36:36 In the Linux kernel, the following vulnerability has been resolved: crypto: alg
CVE-2026-50093 9.0 0.19% 1 0 2026-09-08T09:35:45 A vulnerability has been identified in Siveillance Control Pro V3.0 (All version
CVE-2026-44756 10.0 0.32% 5 0 2026-09-08T03:31:21 A memory safety vulnerability exists in the Extended Passport Protocol (EPP) pro
CVE-2026-67276 None 0.24% 1 4 2026-09-05T21:31:20 RouterOS does not compare the complete RSA public key when matching an SSH authe
CVE-2026-86207 None 0.73% 1 0 2026-09-05T21:31:20 An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypa
CVE-2026-86090 7.1 0.25% 1 0 2026-09-05T00:31:10 ntopng before 6.7.260717 fails to perform authorization checks in the delete end
CVE-2026-85704 3.7 0.27% 1 0 2026-09-04T21:32:00 A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3df
CVE-2026-85637 5.3 0.43% 1 0 2026-09-04T21:31:59 A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected by this
CVE-2026-80905 None 0.15% 1 0 2026-09-04T18:31:46 In the Linux kernel, the following vulnerability has been resolved: net: tap: f
CVE-2026-80874 None 0.14% 1 0 2026-09-04T18:31:40 In the Linux kernel, the following vulnerability has been resolved: arm64: dts:
CVE-2026-17255 4.3 0.40% 1 0 2026-09-04T18:31:40 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of
CVE-2026-17440 5.5 0.10% 1 0 2026-09-04T18:31:40 IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.
CVE-2026-16660 5.3 0.36% 1 0 2026-09-04T18:31:39 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a
CVE-2026-80872 0 0.15% 1 0 2026-09-04T17:16:59.160000 In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/t
CVE-2026-75754 None 0.21% 1 0 2026-09-04T03:31:07 Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF)
CVE-2026-20212 9.8 0.53% 1 1 2026-09-02T18:32:26 A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switc
CVE-2026-83548 10.0 4.67% 1 3 2026-09-02T18:32:06 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla
CVE-2026-82078 9.1 1.69% 4 2 2026-09-01T04:18:02.160000 An unsafe dynamic class loading vulnerability exists in the database connection
CVE-2026-81578 9.8 1.62% 4 2 2026-08-31T21:31:56 An improper access control vulnerability exists in the web management interface
CVE-2026-18963 9.1 3.18% 1 15 2026-08-28T22:53:42 A flaw was found in the reset-credentials flow of the keycloak-services componen
CVE-2026-77234 8.8 0.12% 1 0 2026-08-27T20:18:39.130000 Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unpriv
CVE-2026-69836 10.0 1.55% 1 2 2026-08-25T16:08:43.290000 Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized a
CVE-2026-75936 7.5 0.44% 1 0 2026-08-20T13:01:19.947000 Improper handling of highly compressed data in the GZIP auto-decompression handl
CVE-2026-69414 7.8 0.56% 6 2 2026-08-19T18:32:28 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect
CVE-2026-68820 7.0 6.18% 1 4 2026-08-16T19:17:24.183000 Use after free in Windows Ancillary Function Driver for WinSock allows an author
CVE-2026-19311 8.1 0.41% 1 0 2026-08-12T21:31:44 Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting p
CVE-2026-20316 5.3 11.15% 7 0 2026-07-29T21:31:00 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-43502 7.8 0.12% 2 1 2026-07-23T16:10:00.137000 In the Linux kernel, the following vulnerability has been resolved: net/rds: ha
CVE-2026-15409 10.0 83.66% 2 6 template 2026-07-16T05:16:18.293000 A Server-side request forgery (SSRF) vulnerability has been identified in the SM
CVE-2026-52774 6.1 0.51% 1 1 2026-07-09T21:01:12 ### Summary YesWiki's Bazar widget handler reflects the `id` `GET` parameter int
CVE-2026-53932 8.0 0.91% 1 0 2026-07-09T20:52:58 ## Summary A crafted backup archive can trigger OS command injection during data
CVE-2026-11387 9.8 2.21% 2 2 template 2026-07-01T09:30:33 The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart
CVE-2026-28576 5.5 0.15% 2 1 2026-06-17T16:43:32.927000 In Contacts Provider, there is a possible way to access the contacts database du
CVE-2026-33671 7.5 0.40% 2 1 2026-06-17T10:37:54.007000 Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2,
CVE-2019-0859 7.8 4.15% 2 1 2026-06-17T02:09:03.317000 An elevation of privilege vulnerability exists in Windows when the Win32k compon
CVE-2026-8510 7.5 0.21% 2 0 2026-05-15T00:31:36 Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 all
CVE-2026-0915 7.5 0.59% 2 1 2026-01-20T18:31:56 Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that spec
CVE-2022-41352 9.8 95.48% 2 4 2025-10-22T00:32:37 An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacke
CVE-2016-7255 7.8 80.97% 2 5 2025-10-22T00:32:21 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2
CVE-2026-16338 0 0.00% 2 0 N/A
CVE-2026-70416 0 0.00% 2 0 N/A
CVE-2026-63695 0 0.00% 2 0 N/A
CVE-2026-85706 0 0.00% 2 0 N/A
CVE-2026-72898 0 94.22% 2 8 N/A
CVE-2026-57162 0 0.35% 1 0 N/A
CVE-2026-73453 0 0.00% 1 0 N/A
CVE-2026-84390 0 0.00% 2 0 N/A
CVE-2026-84388 0 0.00% 2 0 N/A
CVE-2026-87911 0 0.99% 3 0 N/A
CVE-2026-77236 0 0.11% 1 0 N/A
CVE-2026-77237 0 0.13% 1 0 N/A
CVE-2026-77235 0 0.11% 1 0 N/A
CVE-2026-54694 0 0.28% 1 0 N/A
CVE-2026-85982 0 0.22% 1 0 N/A
CVE-2026-85083 0 0.00% 1 0 N/A
CVE-2026-53939 0 0.20% 1 0 N/A

CVE-2026-8778
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-09-11T04:18:04.617000

2 posts

The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote

offseq at 2026-09-11T04:30:23.692Z ##

CVE-2026-8778 (CRITICAL): MIPL Grouped Checkout Fields for WooCommerce ≤1.2.2 suffers from unrestricted file upload due to missing file type validation. Remote code execution possible by unauthenticated attackers. Restrict uploads & monitor! radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-11T04:30:23.000Z ##

CVE-2026-8778 (CRITICAL): MIPL Grouped Checkout Fields for WooCommerce ≤1.2.2 suffers from unrestricted file upload due to missing file type validation. Remote code execution possible by unauthenticated attackers. Restrict uploads & monitor! radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE20268778

##

CVE-2026-84869
(9.9 CRITICAL)

EPSS: 0.38%

updated 2026-09-11T04:18:01.777000

3 posts

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

ssvc@infosec.exchange at 2026-09-09T20:37:11.000Z ##

ConnectWise ScreenConnect #zeroday CVE-2026-84869

Huntress article: huntress.com/blog/rogue-screen

Canadian Centre for Cyber Security: cyber.gc.ca/en/alerts-advisori

Open-source reporting indicates that CVE-2026-84869 is being exploited in the wild.

ConnectWise is silent on exploitation status: connectwise.com/company/trust/

#connectwise #screenconnect #cve

##

cR0w@infosec.exchange at 2026-09-08T21:38:08.000Z ##

WTF

github.com/ConnectWise-Advisor

Earlier versions of ScreenConnect Client Support and Access sessions contained a client-side file-transfer handling condition in which file-transfer actions could be processed through an active remote session without proper authorization or Host confirmation. Under certain circumstances, this could allow files to be transferred to and executed on the Host client system, including through elevated execution actions. ScreenConnect servers are not impacted. Disabling file-transfer permissions for affected sessions may reduce exposure until the update is applied.

##

thehackerwire@mastodon.social at 2026-09-08T21:00:02.000Z ##

🔴 CVE-2026-84869 - Critical (9.9)

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79641
(7.5 HIGH)

EPSS: 0.67%

updated 2026-09-11T04:17:52.993000

1 posts

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.

thehackerwire@mastodon.social at 2026-09-09T12:00:14.000Z ##

🟠 CVE-2026-79641 - High (7.5)

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19583
(9.9 CRITICAL)

EPSS: 0.60%

updated 2026-09-11T04:17:24.930000

2 posts

Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS

offseq at 2026-09-10T04:30:24.651Z ##

CVE-2026-19583: CRITICAL vuln in Rapid7 Velociraptor (<0.77.2) allows users w/ artifact scheduling rights to execute privileged artifacts like Linux.Sys.BashShell — risking full compromise. Restrict permissions, monitor activity. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-10T04:30:24.000Z ##

CVE-2026-19583: CRITICAL vuln in Rapid7 Velociraptor (<0.77.2) allows users w/ artifact scheduling rights to execute privileged artifacts like Linux.Sys.BashShell — risking full compromise. Restrict permissions, monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Infosec

##

CVE-2026-0310
(0 None)

EPSS: 0.34%

updated 2026-09-11T04:17:13.060000

6 posts

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimiz

threatcodex at 2026-09-10T18:39:08.028Z ##

CVE-2026-0310: PAN-OS Buffer Overflow Can Enable Root RCE on PA-Series Firewalls

socprime.com/blog/cve-2026-031

##

threatcodex@infosec.exchange at 2026-09-10T18:39:08.000Z ##

CVE-2026-0310: PAN-OS Buffer Overflow Can Enable Root RCE on PA-Series Firewalls
#CVE_2026_0310
socprime.com/blog/cve-2026-031

##

cR0w@infosec.exchange at 2026-09-09T17:10:22.000Z ##

RE: infosec.exchange/@cR0w/1172419

Seriously, maybe take a good look at CVE-2026-0310.

CVSS-BT: 7.2 / **CVSS-B: 9.2** (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Red)

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T17:06:44.000Z ##

A new PAN-OS buffer overflow flaw, tracked as CVE-2026-0310, exposes firewalls to remote code execution. Patch your network devices immediately.

#PANOS #BufferOverflow #CVE20260310 #Cybersecurity #PaloAltoNetworks

securityonline.info/pan-os-buf

##

cR0w@infosec.exchange at 2026-09-09T16:12:33.000Z ##

RE: infosec.exchange/@cR0w/1172369

lol. lmao even.

security.paloaltonetworks.com/

security.paloaltonetworks.com/

##

AAKL@infosec.exchange at 2026-09-09T16:10:40.000Z ##

Broadcom has a long list of advisories today for high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom #Linux

Palo Alto:

Palo Alto has several advisories, one of them critical:

CRITICAL: CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing security.paloaltonetworks.com/

More: security.paloaltonetworks.com/

Cisco:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco

Dell:

A Dell release that impacts multiple CVEs: Security Update for Dell PowerScale OneFS Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell

Posted yesterday:

Apple:

Several releases were posted yesterday support.apple.com/en-us/100100 #Apple #iOS

AMD:

AMD: Linux GPU Driver NULL Pointer Dereference amd.com/en/resources/product-s #AMD

Adobe:

Adobe has a long list of updates here helpx.adobe.com/security/secur #Adobe #infosec #vulnerability

@cR0w

##

CVE-2026-0307
(0 None)

EPSS: 0.10%

updated 2026-09-11T04:17:10.160000

1 posts

Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges. This GlobalProtect app on iOS, Android and ChromeOS is not impacted.

CVE-2026-82107
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-11T00:31:23

4 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

offseq at 2026-09-11T03:00:24.330Z ##

CVE-2026-82107: CRITICAL vuln in IBM DataStage on Cloud Pak for Data 5.4.0.0 (CVSS 9.6). Authenticated attackers can bypass authentication & access sensitive data. No patch — limit access & monitor for abuse. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-10T23:00:08.000Z ##

🔴 CVE-2026-82107 - Critical (9.6)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-11T03:00:24.000Z ##

CVE-2026-82107: CRITICAL vuln in IBM DataStage on Cloud Pak for Data 5.4.0.0 (CVSS 9.6). Authenticated attackers can bypass authentication & access sensitive data. No patch — limit access & monitor for abuse. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IBM #InfoSec

##

thehackerwire@mastodon.social at 2026-09-10T23:00:08.000Z ##

🔴 CVE-2026-82107 - Critical (9.6)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77807
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-11T00:31:23

2 posts

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires

thehackerwire@mastodon.social at 2026-09-11T02:00:03.000Z ##

🟠 CVE-2026-77807 - High (7.5)

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes it p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-11T02:00:03.000Z ##

🟠 CVE-2026-77807 - High (7.5)

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes it p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82100
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-09-11T00:31:23

4 posts

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

offseq at 2026-09-11T01:30:25.852Z ##

CVE-2026-82100: CRITICAL path traversal in IBM DataStage on Cloud Pak for Data 5.4.0.0 (CVSS 9.6). Remote authenticated attackers can cause denial of service via improper directory handling. Restrict access & monitor until patch confirmed. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-09-10T22:59:59.000Z ##

🔴 CVE-2026-82100 - Critical (9.6)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-11T01:30:25.000Z ##

CVE-2026-82100: CRITICAL path traversal in IBM DataStage on Cloud Pak for Data 5.4.0.0 (CVSS 9.6). Remote authenticated attackers can cause denial of service via improper directory handling. Restrict access & monitor until patch confirmed. radar.offseq.com/threat/cve-20 #OffSeq #CVE202682100 #IBM #infosec

##

thehackerwire@mastodon.social at 2026-09-10T22:59:59.000Z ##

🔴 CVE-2026-82100 - Critical (9.6)

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81940
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-11T00:31:23

2 posts

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.

thehackerwire@mastodon.social at 2026-09-11T00:02:16.000Z ##

🟠 CVE-2026-81940 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-11T00:02:16.000Z ##

🟠 CVE-2026-81940 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84889
(8.8 HIGH)

EPSS: 0.00%

updated 2026-09-11T00:31:23

2 posts

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

thehackerwire@mastodon.social at 2026-09-10T23:00:18.000Z ##

🟠 CVE-2026-84889 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T23:00:18.000Z ##

🟠 CVE-2026-84889 - High (8.8)

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87958
(8.1 HIGH)

EPSS: 0.00%

updated 2026-09-11T00:31:16

2 posts

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.

thehackerwire@mastodon.social at 2026-09-11T00:02:05.000Z ##

🟠 CVE-2026-87958 - High (8.1)

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-11T00:02:05.000Z ##

🟠 CVE-2026-87958 - High (8.1)

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86093
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-11T00:31:16

2 posts

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds checking.

thehackerwire@mastodon.social at 2026-09-11T00:01:55.000Z ##

🟠 CVE-2026-86093 - High (7.5)

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-11T00:01:55.000Z ##

🟠 CVE-2026-86093 - High (7.5)

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88044
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T22:47:10

2 posts

## Summary `serve/start` accepts protocol options in a per-server `proxyOpt` object. The FTP and S3 RC adapters parse that object and pass it to their server constructors, but the constructors decide whether proxy authentication is enabled by checking the process-global `proxy.Opt.AuthProxy` instead of the supplied `proxyOpt.AuthProxy`. When the process-global option is empty—the normal case whe

thehackerwire@mastodon.social at 2026-09-10T18:00:11.000Z ##

🔴 CVE-2026-88044 - Critical (9.1)

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T18:00:11.000Z ##

🔴 CVE-2026-88044 - Critical (9.1)

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88045
(7.5 HIGH)

EPSS: 0.00%

updated 2026-09-10T22:45:14

2 posts

## Summary In streamed multipart mode, `serve s3` passes the request's declared part length to `multipart.NewRW().Reserve(contentLength)` before reading any part data. `Reserve` immediately obtains enough 1 MiB pool pages for the entire declared length. The request handler therefore allocates attacker-selected memory based only on `Content-Length` or `X-Amz-Decoded-Content-Length`; the client doe

thehackerwire@mastodon.social at 2026-09-10T18:00:22.000Z ##

🟠 CVE-2026-88045 - High (7.5)

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentLength to m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T18:00:22.000Z ##

🟠 CVE-2026-88045 - High (7.5)

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentLength to m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87011
(7.5 HIGH)

EPSS: 0.34%

updated 2026-09-10T22:45:10

1 posts

## Summary The OIDC back-channel logout endpoint is unauthenticated by design, because the identity provider calls it without a browser session. Before checking whether the submitted logout token was genuine, the handler fetched the provider's discovery document and its signing keys over the network, and repeated both fetches on every request because nothing was cached. The signing-key fetch also

thehackerwire@mastodon.social at 2026-09-09T21:59:49.000Z ##

🟠 CVE-2026-87011 - High (7.5)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, the unauthenticated POST /oauth/backchannel-logout handler in backend/open_webui/utils/oauth.py fetched the OIDC discovery document and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19646
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T22:16:55.697000

2 posts

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.

offseq at 2026-09-11T00:00:36.046Z ##

CVE-2026-19646 (CRITICAL, CVSS 9.1) affects IBM Common Licensing 9.0.x & ART 9.0. Improper Host header validation enables remote redirection to attacker domains. No patch yet — monitor IBM guidance. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-11T00:00:36.000Z ##

CVE-2026-19646 (CRITICAL, CVSS 9.1) affects IBM Common Licensing 9.0.x & ART 9.0. Improper Host header validation enables remote redirection to attacker domains. No patch yet — monitor IBM guidance. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IBM #InfoSec

##

CVE-2026-41870
(8.8 HIGH)

EPSS: 0.43%

updated 2026-09-10T21:32:31

1 posts

Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.11 through 1.22. Users are recommended to upgrade to version 1.23, which remo

CVE-2026-86060(CVSS UNKNOWN)

EPSS: 0.40%

updated 2026-09-10T21:32:21

4 posts

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable

1 repos

https://github.com/bahirul/cve-2026-86060

secdb at 2026-09-10T21:00:32.914Z ##

🚨 [CISA-2026:0910] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-67277 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: mikrotik.com/supportsec/septem ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-86060 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-09-10T20:01:01.000Z ##

CVE ID: CVE-2026-86060
Vendor: MikroTik
Product: RouterOS
Date Added: 2026-09-10
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-09-10T21:00:32.000Z ##

🚨 [CISA-2026:0910] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-67277 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: mikrotik.com/supportsec/septem ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-86060 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260910 #cisa20260910 #cve_2026_67277 #cve_2026_86060 #cve202667277 #cve202686060

##

cisakevtracker@mastodon.social at 2026-09-10T20:01:01.000Z ##

CVE ID: CVE-2026-86060
Vendor: MikroTik
Product: RouterOS
Date Added: 2026-09-10
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-89054
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-10T21:31:41

2 posts

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @PATCH configuration endpoints for event configuration and SNMP data collection (which enable and disable event definitions and data-collection sources) are re

thehackerwire@mastodon.social at 2026-09-10T21:00:08.000Z ##

🟠 CVE-2026-89054 - High (8.2)

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @patch...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T21:00:08.000Z ##

🟠 CVE-2026-89054 - High (8.2)

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @patch...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89086
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T21:31:41

2 posts

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

thehackerwire@mastodon.social at 2026-09-10T20:59:58.000Z ##

🔴 CVE-2026-89086 - Critical (9.1)

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T20:59:58.000Z ##

🔴 CVE-2026-89086 - Critical (9.1)

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67277(CVSS UNKNOWN)

EPSS: 0.43%

updated 2026-09-10T21:31:20

4 posts

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragment

secdb at 2026-09-10T21:00:32.914Z ##

🚨 [CISA-2026:0910] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-67277 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: mikrotik.com/supportsec/septem ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-86060 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-09-10T20:01:17.000Z ##

CVE ID: CVE-2026-67277
Vendor: MikroTik
Product: RouterOS
Date Added: 2026-09-10
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-09-10T21:00:32.000Z ##

🚨 [CISA-2026:0910] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-67277 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: mikrotik.com/supportsec/septem ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-86060 (secdb.nttzen.cloud/cve/detail/)
- Name: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: MikroTik
- Product: RouterOS
- Notes: ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260910 #cisa20260910 #cve_2026_67277 #cve_2026_86060 #cve202667277 #cve202686060

##

cisakevtracker@mastodon.social at 2026-09-10T20:01:17.000Z ##

CVE ID: CVE-2026-67277
Vendor: MikroTik
Product: RouterOS
Date Added: 2026-09-10
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-87016
(8.1 HIGH)

EPSS: 0.33%

updated 2026-09-10T21:23:26

1 posts

## Summary On SQLite deployments, the lookup that maps an external identity to a local account does a substring match instead of an exact match. A subject value containing SQL wildcard characters therefore matches accounts the value was never issued for, and the sign-in binds to whichever account the database returns first, which can be an administrator. The same defect affects SCIM external-ID r

thehackerwire@mastodon.social at 2026-09-09T23:00:46.000Z ##

🟠 CVE-2026-87016 - High (8.1)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that compiled ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89094
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T21:17:53.160000

2 posts

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

cR0w at 2026-09-10T21:42:08.433Z ##

RE: infosec.exchange/@cR0w/1172478

CVE for this one:

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.9 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

##

cR0w@infosec.exchange at 2026-09-10T21:42:08.000Z ##

RE: infosec.exchange/@cR0w/1172478

CVE for this one:

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.9 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

##

CVE-2026-14873
(8.0 HIGH)

EPSS: 0.24%

updated 2026-09-10T21:17:18.500000

2 posts

The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their details like arbitrary user passwords, including administrator passwords, to a known plugin-configured custom value, enabling full account takeover of the site

thehackerwire@mastodon.social at 2026-09-10T06:00:48.000Z ##

🟠 CVE-2026-14873 - High (8)

The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their detail...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T06:00:48.000Z ##

🟠 CVE-2026-14873 - High (8)

The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their detail...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53938
(8.2 HIGH)

EPSS: 0.24%

updated 2026-09-10T19:57:48.533000

1 posts

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) does not validate the length of the attacker-supplied `encrypted_key` (JWE Encrypted Key) before unwrapping it into a fixed-size, heap-allocated Content Encryption K

thehackerwire@mastodon.social at 2026-09-09T01:00:08.000Z ##

🟠 CVE-2026-53938 - High (8.2)

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) does not val...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65639
(0 None)

EPSS: 0.00%

updated 2026-09-10T19:54:25.810000

2 posts

OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data. The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that co

DailyCyberSecurity at 2026-09-11T03:18:48.410Z ##

Two critical CSF plugin vulnerabilities, CVE-2026-65638 and CVE-2026-65639, allow remote code execution. Patch your ConfigServer firewall immediately.

securityonline.info/csf-plugin

##

DailyCyberSecurity@infosec.exchange at 2026-09-11T03:18:48.000Z ##

Two critical CSF plugin vulnerabilities, CVE-2026-65638 and CVE-2026-65639, allow remote code execution. Patch your ConfigServer firewall immediately.

#CSFPlugin #Cybersecurity #CVE202665639 #Vulnerabilities #InfoSec

securityonline.info/csf-plugin

##

CVE-2026-65638
(0 None)

EPSS: 0.00%

updated 2026-09-10T19:54:25.810000

2 posts

Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed t

DailyCyberSecurity at 2026-09-11T03:18:48.410Z ##

Two critical CSF plugin vulnerabilities, CVE-2026-65638 and CVE-2026-65639, allow remote code execution. Patch your ConfigServer firewall immediately.

securityonline.info/csf-plugin

##

DailyCyberSecurity@infosec.exchange at 2026-09-11T03:18:48.000Z ##

Two critical CSF plugin vulnerabilities, CVE-2026-65638 and CVE-2026-65639, allow remote code execution. Patch your ConfigServer firewall immediately.

#CSFPlugin #Cybersecurity #CVE202665639 #Vulnerabilities #InfoSec

securityonline.info/csf-plugin

##

CVE-2026-88052
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-10T19:54:25.810000

2 posts

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the unichars vector. unichar_insert_backwards_compatible can leave the vector unchanged for an empty, duplicate, or already-encodable representation, causing id to become larger than un

thehackerwire@mastodon.social at 2026-09-10T19:00:53.000Z ##

🟠 CVE-2026-88052 - High (7.8)

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the unichars vector. unichar_ins...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T19:00:53.000Z ##

🟠 CVE-2026-88052 - High (7.8)

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the unichars vector. unichar_ins...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85228
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T19:54:25.810000

2 posts

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload. To remediate this issue, users should upgrade to version 0.37.0 or above.

thehackerwire@mastodon.social at 2026-09-10T18:00:33.000Z ##

🔴 CVE-2026-85228 - Critical (9.1)

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a de...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T18:00:33.000Z ##

🔴 CVE-2026-85228 - Critical (9.1)

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a de...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89049
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T19:44:21.980000

4 posts

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role cre

thehackerwire@mastodon.social at 2026-09-10T21:00:17.000Z ##

🔴 CVE-2026-89049 - Critical (9.9)

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

awssecurityfeed at 2026-09-10T19:00:01.199Z ##

CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

Bulletin ID: 2026-107-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 11:30 AM PDT
Description:
AWS Systems Manager Agent (SSM Agent) is software that runs on managed nodes (EC2 instances...

aws.amazon.com/security/securi

##

thehackerwire@mastodon.social at 2026-09-10T21:00:17.000Z ##

🔴 CVE-2026-89049 - Critical (9.9)

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

awssecurityfeed@infosec.exchange at 2026-09-10T19:00:01.000Z ##

CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

Bulletin ID: 2026-107-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 11:30 AM PDT
Description:
AWS Systems Manager Agent (SSM Agent) is software that runs on managed nodes (EC2 instances...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-67593
(9.1 CRITICAL)

EPSS: 0.29%

updated 2026-09-10T18:33:11

2 posts

A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes

DailyCyberSecurity at 2026-09-10T02:55:57.475Z ##

Critical Apache Artemis vulnerabilities, including CVE-2026-67593 and other ActiveMQ Artemis flaws, expose systems to denial of service and data exposure.

securityonline.info/apache-art

##

DailyCyberSecurity@infosec.exchange at 2026-09-10T02:55:57.000Z ##

Critical Apache Artemis vulnerabilities, including CVE-2026-67593 and other ActiveMQ Artemis flaws, expose systems to denial of service and data exposure.

#ApacheArtemis #Cybersecurity #Vulnerabilities #ActiveMQ #CVE202667593

securityonline.info/apache-art

##

CVE-2026-89046
(8.2 HIGH)

EPSS: 0.00%

updated 2026-09-10T18:33:05

2 posts

zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and reach the native frame-header parser, causing out-of-bounds memory reads that lead to information disclosure or JVM crashes.

thehackerwire@mastodon.social at 2026-09-10T19:00:33.000Z ##

🟠 CVE-2026-89046 - High (8.2)

zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and rea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T19:00:33.000Z ##

🟠 CVE-2026-89046 - High (8.2)

zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and rea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89042
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-09-10T18:33:04

2 posts

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.

thehackerwire@mastodon.social at 2026-09-10T19:00:43.000Z ##

🔴 CVE-2026-89042 - Critical (9.1)

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T19:00:43.000Z ##

🔴 CVE-2026-89042 - Critical (9.1)

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88889
(7.8 HIGH)

EPSS: 0.00%

updated 2026-09-10T16:18:11.693000

2 posts

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inject shell commands through unescaped distributionType values to achieve remote code execution when Renovate processes Maven Wrapper updates in binarySour

thehackerwire@mastodon.social at 2026-09-10T15:00:03.000Z ##

🟠 CVE-2026-88889 - High (7.8)

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inj...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T15:00:03.000Z ##

🟠 CVE-2026-88889 - High (7.8)

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inj...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88290
(7.5 HIGH)

EPSS: 0.26%

updated 2026-09-10T16:18:10.767000

2 posts

GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.

thehackerwire@mastodon.social at 2026-09-10T11:00:24.000Z ##

🟠 CVE-2026-88290 - High (7.5)

GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T11:00:24.000Z ##

🟠 CVE-2026-88290 - High (7.5)

GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13745
(0 None)

EPSS: 0.30%

updated 2026-09-10T16:17:07.727000

2 posts

A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attacker to achieve an arbitrary code execution in Gemini CLI via untrusted local .env files overriding GEMINI_CLI_HOME.

offseq at 2026-09-10T09:00:26.166Z ##

CVE-2026-13745: CRITICAL vuln (CVSS 9.2) in Google Cloud Gemini CLI allows arbitrary code execution via untrusted .env files overriding GEMINI_CLI_HOME. Review .env file usage & restrict access. More info: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-10T09:00:26.000Z ##

CVE-2026-13745: CRITICAL vuln (CVSS 9.2) in Google Cloud Gemini CLI allows arbitrary code execution via untrusted .env files overriding GEMINI_CLI_HOME. Review .env file usage & restrict access. More info: radar.offseq.com/threat/cve-20 #OffSeq #GoogleCloud #Vulnerability #InfoSec

##

CVE-2026-15913
(7.7 HIGH)

EPSS: 0.39%

updated 2026-09-10T15:53:23.707000

1 posts

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.

thehackerwire@mastodon.social at 2026-09-10T00:04:36.000Z ##

🟠 CVE-2026-15913 - High (7.7)

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73786
(7.5 HIGH)

EPSS: 0.33%

updated 2026-09-10T15:47:22.273000

1 posts

A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack. Successful exploitation could allow an attacker to cause instability and degrade performance of the vulnerable CPPM server.

1 repos

https://github.com/promasu/CVE-2026-73786

thehackerwire@mastodon.social at 2026-09-09T21:01:11.000Z ##

🟠 CVE-2026-73786 - High (7.5)

A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack. Successful exploitation could allow an attacker to cause instability and degrade performance ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88069
(0 None)

EPSS: 0.33%

updated 2026-09-10T15:43:03.760000

2 posts

Pandora contains a path traversal vulnerability in its archive extraction worker. When processing a specially crafted archive or disk image, attacker-controlled file paths could be used without ensuring that the resulting destination remained within the intended extraction directory. An attacker able to submit a malicious file for analysis could use path traversal sequences or crafted paths to ca

offseq at 2026-09-10T01:30:24.171Z ##

CVE-2026-88069: Path traversal in pandora-analysis pandora (<=1.12.7) allows attackers to overwrite system/app files via crafted archives. Severity: CRITICAL (CVSS 9.3). No patch confirmed — monitor vendor updates. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-10T01:30:24.000Z ##

CVE-2026-88069: Path traversal in pandora-analysis pandora (<=1.12.7) allows attackers to overwrite system/app files via crafted archives. Severity: CRITICAL (CVSS 9.3). No patch confirmed — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202688069 #vuln #infosec

##

CVE-2026-21096(CVSS UNKNOWN)

EPSS: 0.41%

updated 2026-09-10T15:34:15

1 posts

Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

cR0w@infosec.exchange at 2026-09-09T15:35:49.000Z ##

CATTE OVERFLOW I REPEAT CATTE OVERFLOW THIS IS NOT A DRILL :catte:

nvd.nist.gov/vuln/detail/cve-2

Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

##

CVE-2026-19490
(9.8 CRITICAL)

EPSS: 6.00%

updated 2026-09-10T15:33:58

2 posts

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

2 repos

https://github.com/TarPeg007/CVE-2026-19490

https://github.com/BishopFox/CVE-2026-19490-check

secdb@infosec.exchange at 2026-09-09T21:00:26.000Z ##

🚨 [CISA-2026:0909] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-25249 (secdb.nttzen.cloud/cve/detail/)
- Name: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: Multiple Products
- Notes: fortiguard.fortinet.com/psirt/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-19490 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-20079 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-87491 (secdb.nttzen.cloud/cve/detail/)
- Name: Google Chromium V8 Out of Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: chromereleases.googleblog.com/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260909 #cisa20260909 #cve_2025_25249 #cve_2026_19490 #cve_2026_20079 #cve_2026_87491 #cve202525249 #cve202619490 #cve202620079 #cve202687491

##

cisakevtracker@mastodon.social at 2026-09-09T20:00:53.000Z ##

CVE ID: CVE-2026-19490
Vendor: Citrix
Product: NetScaler
Date Added: 2026-09-09
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-88887
(8.6 HIGH)

EPSS: 0.00%

updated 2026-09-10T15:33:28

2 posts

Renovate is a dependency update automation tool. When listing tags/digests for a container image, Renovate follows pagination links supplied by the remote registry in the HTTP Link header and attaches the registry credentials to the follow-up request without verifying that the pagination URL has the same origin as the original registry. A malicious or compromised container registry can therefore s

offseq at 2026-09-10T13:30:26.740Z ##

CRITICAL: CVE-2026-88887 in renovatebot renovate enables open redirect — malicious registries can steal credentials using crafted Link headers. Upgrade to 44.11.2+ ASAP. More info: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-10T13:30:26.000Z ##

CRITICAL: CVE-2026-88887 in renovatebot renovate enables open redirect — malicious registries can steal credentials using crafted Link headers. Upgrade to 44.11.2+ ASAP. More info: radar.offseq.com/threat/cve-20 #OffSeq #CVE202688887 #SupplyChain #ContainerSecurity

##

CVE-2026-85983
(7.8 HIGH)

EPSS: 0.14%

updated 2026-09-10T15:17:50.033000

1 posts

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can lead to code execution with the privileges of the service account.

thehackerwire@mastodon.social at 2026-09-09T03:00:18.000Z ##

🟠 CVE-2026-85983 - High (7.8)

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configuration can ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82533
(9.6 CRITICAL)

EPSS: 0.42%

updated 2026-09-10T15:17:47.593000

1 posts

DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the actual TCP connection origin. On the default configuration, a confined tool-executed process can reach the loopback API without any port exposure and use it to esca

blog@spcnet.it at 2026-09-10T11:05:13.000Z ##

CVE-2026-82533: la falla in DeepSeek Harness che lasciava agli agenti AI le chiavi della propria sandbox

Un'interfaccia locale priva di autenticazione e vulnerabile a host header spoofing permetteva agli agenti di DeepSeek Harness di disattivare la propria sandbox con un solo comando. Analisi tecnica di CVE-2026-82533 (CVSS 9.4) e consigli pratici per proteggere gli ambienti dove girano coding agent AI.

spcnet.it/cve-2026-82533-la-fa

##

CVE-2026-6485
(8.2 HIGH)

EPSS: 0.12%

updated 2026-09-10T15:17:39.427000

1 posts

UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.

thehackerwire@mastodon.social at 2026-09-09T09:01:59.000Z ##

🟠 CVE-2026-6485 - High (8.2)

UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88891
(8.3 HIGH)

EPSS: 0.00%

updated 2026-09-10T15:13:07.090000

2 posts

OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics to public share links, and modify alerting rules by exploiting missing access level validation

thehackerwire@mastodon.social at 2026-09-10T15:00:22.000Z ##

🟠 CVE-2026-88891 - High (8.3)

OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedul...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T15:00:22.000Z ##

🟠 CVE-2026-88891 - High (8.3)

OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedul...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88890
(8.5 HIGH)

EPSS: 0.00%

updated 2026-09-10T15:13:07.090000

2 posts

OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analyti

thehackerwire@mastodon.social at 2026-09-10T15:00:12.000Z ##

🟠 CVE-2026-88890 - High (8.5)

OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T15:00:12.000Z ##

🟠 CVE-2026-88890 - High (8.5)

OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87995
(8.7 HIGH)

EPSS: 0.22%

updated 2026-09-10T15:10:20

1 posts

## Summary Any authenticated user with access to a shared terminal server could get script of their choosing to run in the Open WebUI origin itself. The in-app port preview rendered the content of a previewed port in an iframe whose sandbox always granted `allow-same-origin` alongside `allow-scripts`, and that content is served from a path on the application's own origin, so the sandbox provided n

thehackerwire@mastodon.social at 2026-09-09T23:00:25.000Z ##

🟠 CVE-2026-87995 - High (8.7)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered terminal port content in an iframe sandbox containing both allow-scripts an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87996
(7.7 HIGH)

EPSS: 0.21%

updated 2026-09-10T14:50:07.813000

1 posts

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then let the Playwright browser resolve it again in the sync and async request interceptors. An authenticated user controlling authoritative DNS could return a public ad

thehackerwire@mastodon.social at 2026-09-09T23:00:35.000Z ##

🟠 CVE-2026-87996 - High (7.7)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then let the Pla...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18351
(9.8 CRITICAL)

EPSS: 0.77%

updated 2026-09-10T14:39:13.757000

2 posts

The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled 'type' parameter as regex keys in the MIME allowlist, allowing blacklist bypass via

2 repos

https://github.com/ChiefYoru/Exploit-CVE-2026-18351

https://github.com/JohenLastGen-JLG/CVE-2026-18351

offseq at 2026-09-10T03:00:31.108Z ##

CVE-2026-18351 (CRITICAL): addonsorg Drag and Drop File Upload for Elementor Forms <=1.6.0 lets unauthenticated attackers upload arbitrary files — enabling RCE. Restrict or disable plugin use until remediation. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-10T03:00:31.000Z ##

CVE-2026-18351 (CRITICAL): addonsorg Drag and Drop File Upload for Elementor Forms <=1.6.0 lets unauthenticated attackers upload arbitrary files — enabling RCE. Restrict or disable plugin use until remediation. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #RCE

##

CVE-2026-4800
(8.1 HIGH)

EPSS: 2.76%

updated 2026-09-10T13:20:23.210000

2 posts

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions tha

2 repos

https://github.com/SvenLie/next-rep-CVE-2026-4800

https://github.com/threalwinky/CVE-2026-4800-POC

certvde at 2026-09-10T07:33:05.830Z ##

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-09-10T07:33:05.000Z ##

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2026-39821
(9.6 CRITICAL)

EPSS: 0.69%

updated 2026-09-10T13:19:50.873000

2 posts

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "examp

certvde at 2026-09-10T07:33:05.830Z ##

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-09-10T07:33:05.000Z ##

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2026-33186
(9.1 CRITICAL)

EPSS: 1.56%

updated 2026-09-10T13:18:13.270000

2 posts

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully ro

1 repos

https://github.com/JohannesLks/CVE-2026-33186

certvde at 2026-09-10T07:33:05.830Z ##

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-09-10T07:33:05.000Z ##

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2026-20079
(10.0 CRITICAL)

EPSS: 74.70%

updated 2026-09-10T12:48:17.580000

19 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.&nbsp; This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this v

Nuclei template

2 repos

https://github.com/0xBlackash/CVE-2026-20079

https://github.com/CyberAuth/CVE-2026-20079

youranonnewsirc@nerdculture.de at 2026-09-11T04:26:21.000Z ##

The EU Cyber Resilience Act (CRA) takes effect today, September 11, mandating 24-hour vulnerability reporting from manufacturers of connected hardware and software. Simultaneously, state-backed threat actors are increasingly targeting EU officials via encrypted messaging apps for phishing attacks, and a critical Cisco Secure Firewall Management Center flaw (CVE-2026-20079) requires urgent patching. Geopolitically, tensions escalated in the Strait of Hormuz following Iranian claims of ship attacks after US actions, and conflicts continue in the Middle East. In technology, Google Threat Intelligence reported on an AI system capable of harvesting thousands of credentials autonomously.

#Cybersecurity #Geopolitics #TechNews

##

cyberworldops at 2026-09-10T17:00:00.702Z ##

Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by Qilin ransomware, credential-theft actors, and Sandworm-linked groups. The auth bypass provides root command execution and the static credential exposure broadens initial access.

cyberworldops.eu/en/cisco-fmc-

##

undercodenews@mastodon.social at 2026-09-10T16:48:33.000Z ##

Cisco FMC Under Attack as Sandworm and Qilin Exploit Critical Vulnerabilities to Reach Protected Networks + Video

A New Warning for Enterprise Defenders Cisco Secure Firewall Management Center is facing a serious security crisis after Cisco Talos confirmed active exploitation of two vulnerabilities that can give attackers a foothold inside vulnerable environments. The flaws, tracked as CVE-2026-20079 and CVE-2026-20316, are being abused in real-world attacks involving…

undercodenews.com/cisco-fmc-un

##

cyberveille@mastobot.ping.moi at 2026-09-10T15:00:05.000Z ##

📢 Cisco confirme l'exploitation active de CVE-2026-20079, faille critique dans Secure FMC

BleepingComputer, publié le 9 septembre 2026. Cisco a officiellement confirmé l'exploitation active de CVE-2026-20079, une vulnérabilité d'authentification bypass de sévérité maximale (CVSS 10.0) affectant son logiciel Cisco Secure Firewall Management Center…

📖 cyberveille : cyberveille.ch/posts/2026-09-1
🌐 source : bleepingcomputer.com/news/secu
🟢 vérification factuelle haute
#CISAKEV #CiscoSecureFMC #Cyberveille

##

jbhall56 at 2026-09-10T12:53:19.814Z ##

The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices. bleepingcomputer.com/news/secu

##

beyondmachines1 at 2026-09-10T10:01:13.581Z ##

Cisco Secure Firewall Management Center Under Active Attack

Cisco Talos warns of active exploitation of two vulnerabilities (CVE-2026-20079 and CVE-2026-20316) in Secure Firewall Management Center, allowing attackers to gain root access and deploy malware like Cyclops Blink and Qilin ransomware.

**If you run Cisco Secure Firewall Management Center (versions 7.0.x, 7.1.x, or 7.2–7.7), apply Cisco's emergency patches for CVE-2026-20079 and CVE-2026-20316 right away. Make sure the management interface is reachable only from trusted internal networks, never the internet. Because these flaws are already being exploited, also check for unexpected files in /var/sf/bin/ and the Tomcat webroot. Then plan to install Cisco's hardening update due to be released in the week of September 14.**

beyondmachines.net/event_detai

##

cyberworldops at 2026-09-10T00:50:00.849Z ##

Cisco confirmed active exploitation of CVE-2026-20079, a CVSS 10.0 authentication bypass in Secure FMC. Unauthenticated remote attackers can execute commands as root via crafted HTTP requests, compromising firewall management. Immediate patching and exposure review are critical.

cyberworldops.eu/en/cisco-secu

##

youranonnewsirc@nerdculture.de at 2026-09-11T04:26:21.000Z ##

The EU Cyber Resilience Act (CRA) takes effect today, September 11, mandating 24-hour vulnerability reporting from manufacturers of connected hardware and software. Simultaneously, state-backed threat actors are increasingly targeting EU officials via encrypted messaging apps for phishing attacks, and a critical Cisco Secure Firewall Management Center flaw (CVE-2026-20079) requires urgent patching. Geopolitically, tensions escalated in the Strait of Hormuz following Iranian claims of ship attacks after US actions, and conflicts continue in the Middle East. In technology, Google Threat Intelligence reported on an AI system capable of harvesting thousands of credentials autonomously.

#Cybersecurity #Geopolitics #TechNews

##

cyberworldops@infosec.exchange at 2026-09-10T17:00:00.000Z ##

Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by Qilin ransomware, credential-theft actors, and Sandworm-linked groups. The auth bypass provides root command execution and the static credential exposure broadens initial access.

#CiscoFMC #ThreatIntelligence #VulnerabilityManagement #Qilin

cyberworldops.eu/en/cisco-fmc-

##

jbhall56@infosec.exchange at 2026-09-10T12:53:19.000Z ##

The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices. bleepingcomputer.com/news/secu

##

beyondmachines1@infosec.exchange at 2026-09-10T10:01:13.000Z ##

Cisco Secure Firewall Management Center Under Active Attack

Cisco Talos warns of active exploitation of two vulnerabilities (CVE-2026-20079 and CVE-2026-20316) in Secure Firewall Management Center, allowing attackers to gain root access and deploy malware like Cyclops Blink and Qilin ransomware.

**If you run Cisco Secure Firewall Management Center (versions 7.0.x, 7.1.x, or 7.2–7.7), apply Cisco's emergency patches for CVE-2026-20079 and CVE-2026-20316 right away. Make sure the management interface is reachable only from trusted internal networks, never the internet. Because these flaws are already being exploited, also check for unexpected files in /var/sf/bin/ and the Tomcat webroot. Then plan to install Cisco's hardening update due to be released in the week of September 14.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-09-10T00:50:00.000Z ##

Cisco confirmed active exploitation of CVE-2026-20079, a CVSS 10.0 authentication bypass in Secure FMC. Unauthenticated remote attackers can execute commands as root via crafted HTTP requests, compromising firewall management. Immediate patching and exposure review are critical. #CiscoFmc #AuthBypass #CriticalVulnerability

cyberworldops.eu/en/cisco-secu

##

patrickcmiller@infosec.exchange at 2026-09-09T22:12:01.000Z ##

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks bleepingcomputer.com/news/secu

##

oversecurity@mastodon.social at 2026-09-09T22:01:24.000Z ##

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center...

🔗️ [Bleepingcomputer] link.is.it/y6fb5Q

##

ssvc@infosec.exchange at 2026-09-09T21:01:44.000Z ##

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system. Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account.

blog.talosintelligence.com/fmc

#threatintel #ransomware #Qilin #KEV #CVE

##

secdb@infosec.exchange at 2026-09-09T21:00:26.000Z ##

🚨 [CISA-2026:0909] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-25249 (secdb.nttzen.cloud/cve/detail/)
- Name: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: Multiple Products
- Notes: fortiguard.fortinet.com/psirt/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-19490 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-20079 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-87491 (secdb.nttzen.cloud/cve/detail/)
- Name: Google Chromium V8 Out of Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: chromereleases.googleblog.com/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260909 #cisa20260909 #cve_2025_25249 #cve_2026_19490 #cve_2026_20079 #cve_2026_87491 #cve202525249 #cve202619490 #cve202620079 #cve202687491

##

cisakevtracker@mastodon.social at 2026-09-09T20:01:41.000Z ##

CVE ID: CVE-2026-20079
Vendor: Cisco
Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
Date Added: 2026-09-09
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T16:28:31.000Z ##

Cisco Talos warns of Cisco FMC vulnerabilities actively exploited in the wild. Attackers chain CVE-2026-20079 and CVE-2026-20316 to deploy ransomware.

#CiscoFMC #Cybersecurity #CVE202620079 #Ransomware #InfoSec

securityonline.info/cisco-fmc-

##

AAKL@infosec.exchange at 2026-09-09T16:10:40.000Z ##

Broadcom has a long list of advisories today for high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom #Linux

Palo Alto:

Palo Alto has several advisories, one of them critical:

CRITICAL: CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing security.paloaltonetworks.com/

More: security.paloaltonetworks.com/

Cisco:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco

Dell:

A Dell release that impacts multiple CVEs: Security Update for Dell PowerScale OneFS Multiple Third-Party Component Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell

Posted yesterday:

Apple:

Several releases were posted yesterday support.apple.com/en-us/100100 #Apple #iOS

AMD:

AMD: Linux GPU Driver NULL Pointer Dereference amd.com/en/resources/product-s #AMD

Adobe:

Adobe has a long list of updates here helpx.adobe.com/security/secur #Adobe #infosec #vulnerability

@cR0w

##

CVE-2026-78082(CVSS UNKNOWN)

EPSS: 0.49%

updated 2026-09-10T12:31:26

2 posts

Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting, price_range_dropdown, and psize_range_dropdown) by directly concatenating raw request parameters into SQL strings without quoting or type casting. An unauthentic

offseq at 2026-09-10T10:30:24.303Z ##

CVE-2026-78082: SP Property extension for Joomla v1.0.0-4.1.3 suffers CRITICAL SQL injection (CVSS 9.3). Unauthenticated attackers can extract DB data via blind injection. Patch status unknown — check vendor guidance. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-10T10:30:24.000Z ##

CVE-2026-78082: SP Property extension for Joomla v1.0.0-4.1.3 suffers CRITICAL SQL injection (CVSS 9.3). Unauthenticated attackers can extract DB data via blind injection. Patch status unknown — check vendor guidance. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #SQLi #Infosec

##

CVE-2026-8323
(9.3 CRITICAL)

EPSS: 0.25%

updated 2026-09-10T09:31:48

2 posts

URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data. This issue affects Access Control System: before Versiyon 2.

thehackerwire@mastodon.social at 2026-09-10T11:00:35.000Z ##

🔴 CVE-2026-8323 - Critical (9.3)

URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data.

This issue affects Access Control System: before Versiyon 2.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T11:00:35.000Z ##

🔴 CVE-2026-8323 - Critical (9.3)

URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data.

This issue affects Access Control System: before Versiyon 2.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88289
(7.5 HIGH)

EPSS: 0.33%

updated 2026-09-10T09:31:44

2 posts

GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service.

thehackerwire@mastodon.social at 2026-09-10T11:00:14.000Z ##

🟠 CVE-2026-88289 - High (7.5)

GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T11:00:14.000Z ##

🟠 CVE-2026-88289 - High (7.5)

GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87931
(9.6 CRITICAL)

EPSS: 0.45%

updated 2026-09-10T06:32:50

1 posts

A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any

offseq@infosec.exchange at 2026-09-10T00:00:52.000Z ##

CVE-2026-87931 | CRITICAL buffer overflow in Pavlok Behavioral Conditioning Wearable (Apple Notification Center Service Event Handler). Exploitable locally, no patch or vendor response. Limit device network access. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202687931 #IoTSecurity

##

CVE-2026-15019
(7.5 HIGH)

EPSS: 0.68%

updated 2026-09-10T06:31:51

2 posts

The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The product ownership check only verifies that some free, virtual, downloada

thehackerwire@mastodon.social at 2026-09-10T06:01:01.000Z ##

🟠 CVE-2026-15019 - High (7.5)

The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the content...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T06:01:01.000Z ##

🟠 CVE-2026-15019 - High (7.5)

The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the content...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85102
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-09-10T04:18:18.243000

6 posts

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

571906@ap.podcastindex.org at 2026-09-11T02:00:02.000Z ##

New Episode: SANS Stormcast Friday, September 11th, 2026: Redtail Analsys (@sans_edu); Checkpoint VPN Patch; Netscaler and Sonicwall Attacks

Shownotes:

Redtail Payload Analysis
https://isc.sans.edu/diary/Redtail%20Payload%20Analysis%20%5BGuest%20Diary%5D/33326
Checkpoint Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510
https://community.checkpoint.com/t

Transcript

AntennaPod | Anytime Player | Apple Podcasts | Castamatic | CurioCaster | Fountain | gPodder | Overcast | Pocket Casts | Podcast Addict | Podcast Guru | Podnews | Podverse | Truefans

Or Listen right here.

##

cyberworldops at 2026-09-10T15:00:00.734Z ##

Check Point patched two critical VPN certificate handling flaws, CVE-2026-85102 and CVE-2026-85103, both rated 9.8. They allow unauthenticated remote code execution, making internet-facing VPN gateways an immediate target. Review exposure, apply patches, and investigate for signs of compromise.

cyberworldops.eu/en/check-poin

##

undercodenews@mastodon.social at 2026-09-10T12:39:01.000Z ##

Check Point Rushes to Patch Two Critical VPN Vulnerabilities With 98 CVSS Scores + Video

A Serious Warning for Security Gateway Operators Check Point has moved quickly to patch two critical vulnerabilities affecting its VPN certificate-processing technology, closing a potentially dangerous path that could allow an unauthenticated remote attacker to execute code on vulnerable security infrastructure. The flaws, tracked as CVE-2026-85102 and CVE-2026-85103, were…

undercodenews.com/check-point-

##

cyberworldops@infosec.exchange at 2026-09-10T15:00:00.000Z ##

Check Point patched two critical VPN certificate handling flaws, CVE-2026-85102 and CVE-2026-85103, both rated 9.8. They allow unauthenticated remote code execution, making internet-facing VPN gateways an immediate target. Review exposure, apply patches, and investigate for signs of compromise. #CyberSecurity #CheckPoint #VPN #RCE

cyberworldops.eu/en/check-poin

##

daniel1820815@infosec.exchange at 2026-09-09T20:10:44.000Z ##

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510

Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.

community.checkpoint.com/t5/Ge

#CheckPoint #CheckPointSoftwareTechnologies #VPN #vulnerability

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T14:36:57.000Z ##

Check Point fixed critical Check Point VPN vulnerabilities. Update gateways to prevent remote code execution under CVE-2026-85102 and CVE-2026-85103.

#CheckPoint #VPN #Cybersecurity #CVE202685102 #CVE202685103

securityonline.info/checkpoint

##

CVE-2026-67401
(9.9 CRITICAL)

EPSS: 0.96%

updated 2026-09-10T04:18:04.630000

3 posts

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component

3 repos

https://github.com/HORKimhab/CVE-2026-67401

https://github.com/jithinkrishnanrs/CVE-2026-67401-cPanel-EmailTrack-SQLi

https://github.com/axedos/CVE-2026-67401

cR0w@infosec.exchange at 2026-09-09T18:43:49.000Z ##

I can't imagine trying to manage cPanel on the public Internet in 2026, especially on shared systems.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.9 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component

##

guru@thecybersecguru.com at 2026-09-09T13:15:19.000Z ##

Critical cPanel Vulnerability (CVE-2026-67401): How an EmailTrack SQL Injection Grants Root Access

A critical cPanel EmailTrack SQL injection vulnerability, CVE-2026-67401, can allow authenticated attackers to escalate to root and take over an entire hosting server

thecybersecguru.com/news/cve-2

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T01:47:41.000Z ##

A critical CVE-2026-67401 cPanel SQL injection flaw in EmailTrack allows authenticated users to gain full control of the server. Patch your system today.

#cPanel #SQLInjection #CVE202667401 #Cybersecurity #Vulnerability

securityonline.info/cve-2026-6

##

CVE-2026-19584
(7.7 HIGH)

EPSS: 0.19%

updated 2026-09-10T03:30:27

2 posts

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored.

thehackerwire@mastodon.social at 2026-09-10T06:01:16.000Z ##

🟠 CVE-2026-19584 - High (7.7)

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T06:01:16.000Z ##

🟠 CVE-2026-19584 - High (7.7)

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79324
(7.5 HIGH)

EPSS: 0.32%

updated 2026-09-09T21:32:03

1 posts

Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by iterating the address id, via a GET request to /customer/address/delete/id/{id}. The controller extends the legacy Action class instead of AbstractAccount, so

thehackerwire@mastodon.social at 2026-09-09T21:01:00.000Z ##

🟠 CVE-2026-79324 - High (7.5)

Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by itera...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79323
(7.5 HIGH)

EPSS: 0.33%

updated 2026-09-09T21:31:57

1 posts

Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog commenter email addresses and internal customer and admin identifiers via a POST request to /graphql.

thehackerwire@mastodon.social at 2026-09-09T21:04:34.000Z ##

🟠 CVE-2026-79323 - High (7.5)

Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog commenter email addresses and internal customer and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-79322
(8.6 HIGH)

EPSS: 0.28%

updated 2026-09-09T21:31:56

1 posts

SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id parameter to /mpblog/post/view.

thehackerwire@mastodon.social at 2026-09-09T21:04:44.000Z ##

🟠 CVE-2026-79322 - High (8.6)

SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87491
(8.8 HIGH)

EPSS: 0.76%

updated 2026-09-09T21:31:35

13 posts

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

1 repos

https://github.com/SneakyNachos/CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter

hackmag at 2026-09-10T22:32:52.684Z ##

⚪️ Google Chrome Patches Another Zero-Day Vulnerability

🗨️ Google developers have released an update for the Chrome browser that fixes 230 vulnerabilities, including a zero-day flaw in the V8 engine (CVE-2026-87491) that is already being exploited in attacks. The bug allows a remote attacker to achieve arbitrary code…

🔗 hackmag.com/news/chrome-7th-0d

##

beyondmachines1 at 2026-09-10T08:01:13.314Z ##

Google Patches Chrome Zero-Day and 229 Other Flaws in Version 153

Google released Chrome 153 to fix 230 vulnerabilities, including an actively exploited V8 zero-day (CVE-2026-87491) and five critical flaws in WebGL and Cast.

**This one is urgent, again. Actively exploited flaw and a bunch of fixes. Update Google Chrome to version 153.0.8010.36/.37 for Windows and macOS, or 153.0.8010.36 for Linux. Users of Microsoft Edge, Brave, Opera, Vivaldi, and other Chromium-based browsers. Don't delay, the tabs reopen after an update.**

beyondmachines.net/event_detai

##

Matchbook3469@mastodon.social at 2026-09-10T00:33:59.000Z ##

🟠 New security advisory:

CVE-2026-87491 affects Google Chrome.

• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#Cybersecurity #ZeroDay #ThreatIntel

##

threatnoir at 2026-09-10T00:06:04.781Z ##

⚠️ CRITICAL: Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google patched CVE-2026-87491, a zero-day out-of-bounds write in Chrome's V8 engine actively exploited in the wild. Attackers can execute arbitrary code within the browser sandbox via crafted HTML, potentially compromising any user visiting a malicious page. This is the seventh exploited Chrome zer…

threatnoir.com/focus

🤖 AI generated summary

##

hackmag@infosec.exchange at 2026-09-10T22:32:52.000Z ##

⚪️ Google Chrome Patches Another Zero-Day Vulnerability

🗨️ Google developers have released an update for the Chrome browser that fixes 230 vulnerabilities, including a zero-day flaw in the V8 engine (CVE-2026-87491) that is already being exploited in attacks. The bug allows a remote attacker to achieve arbitrary code…

🔗 hackmag.com/news/chrome-7th-0d

#news

##

beyondmachines1@infosec.exchange at 2026-09-10T08:01:13.000Z ##

Google Patches Chrome Zero-Day and 229 Other Flaws in Version 153

Google released Chrome 153 to fix 230 vulnerabilities, including an actively exploited V8 zero-day (CVE-2026-87491) and five critical flaws in WebGL and Cast.

**This one is urgent, again. Actively exploited flaw and a bunch of fixes. Update Google Chrome to version 153.0.8010.36/.37 for Windows and macOS, or 153.0.8010.36 for Linux. Users of Microsoft Edge, Brave, Opera, Vivaldi, and other Chromium-based browsers. Don't delay, the tabs reopen after an update.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

threatnoir@infosec.exchange at 2026-09-10T00:06:04.000Z ##

⚠️ CRITICAL: Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google patched CVE-2026-87491, a zero-day out-of-bounds write in Chrome's V8 engine actively exploited in the wild. Attackers can execute arbitrary code within the browser sandbox via crafted HTML, potentially compromising any user visiting a malicious page. This is the seventh exploited Chrome zer…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

secdb@infosec.exchange at 2026-09-09T21:00:26.000Z ##

🚨 [CISA-2026:0909] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-25249 (secdb.nttzen.cloud/cve/detail/)
- Name: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: Multiple Products
- Notes: fortiguard.fortinet.com/psirt/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-19490 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-20079 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-87491 (secdb.nttzen.cloud/cve/detail/)
- Name: Google Chromium V8 Out of Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: chromereleases.googleblog.com/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260909 #cisa20260909 #cve_2025_25249 #cve_2026_19490 #cve_2026_20079 #cve_2026_87491 #cve202525249 #cve202619490 #cve202620079 #cve202687491

##

cisakevtracker@mastodon.social at 2026-09-09T20:01:25.000Z ##

CVE ID: CVE-2026-87491
Vendor: Google
Product: Chromium V8
Date Added: 2026-09-09
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

jbhall56@infosec.exchange at 2026-09-09T12:46:30.000Z ##

The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. thehackernews.com/2026/09/chro

##

ssvc@infosec.exchange at 2026-09-09T12:33:54.000Z ##

Google Chrome #zeroday

Google is aware that an exploit for CVE-2026-87491 exists in the wild.

chromereleases.googleblog.com/

#Google #Chrome #CVE

##

cyberworldops@infosec.exchange at 2026-09-09T11:40:01.000Z ##

Google fixed CVE-2026-87491, an out-of-bounds write in Chrome V8 exploited in the wild via crafted HTML. It enables arbitrary code execution inside the sandbox with risk of heap corruption and memory disclosure. Patch to version 153 immediately and hunt for anomalous browser activity. #ChromeSecurity #ZeroDay #ThreatIntel

cyberworldops.eu/en/chrome-v8-

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T00:17:29.000Z ##

Google patched a Chrome zero-day, CVE-2026-87491, exploited in the wild. Chrome 153 fixes 230 flaws including critical WebGL bugs. Update now.

#Chrome #ZeroDay #Google #CyberSecurity #CVE #V8 #BrowserSecurity #Infosec

securityonline.info/chrome-zer

##

CVE-2025-25249
(8.1 HIGH)

EPSS: 1.70%

updated 2026-09-09T21:30:27

4 posts

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4.0 through 6.4.16, FortiSASE 25.2.b, FortiSASE 25.1.a.2, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted p

cyberworldops at 2026-09-10T08:30:00.916Z ##

Fortinet CVE-2025-25249, an unauthenticated heap-based buffer overflow RCE, is being exploited at scale to deploy PivotC2 RAT. CISA added it to KEV on 2026-09-09 with remediation due 2026-09-12. Unpatched Fortinet perimeter devices should be assumed compromised and investigated for RAT persistence.

cyberworldops.eu/en/fortinet-c

##

cyberworldops@infosec.exchange at 2026-09-10T08:30:00.000Z ##

Fortinet CVE-2025-25249, an unauthenticated heap-based buffer overflow RCE, is being exploited at scale to deploy PivotC2 RAT. CISA added it to KEV on 2026-09-09 with remediation due 2026-09-12. Unpatched Fortinet perimeter devices should be assumed compromised and investigated for RAT persistence. #Fortinet #PivotC2 #ThreatIntel

cyberworldops.eu/en/fortinet-c

##

secdb@infosec.exchange at 2026-09-09T21:00:26.000Z ##

🚨 [CISA-2026:0909] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-25249 (secdb.nttzen.cloud/cve/detail/)
- Name: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: Multiple Products
- Notes: fortiguard.fortinet.com/psirt/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-19490 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: support.citrix.com/external/ar ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-20079 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-87491 (secdb.nttzen.cloud/cve/detail/)
- Name: Google Chromium V8 Out of Bounds Write Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: chromereleases.googleblog.com/ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260909 #cisa20260909 #cve_2025_25249 #cve_2026_19490 #cve_2026_20079 #cve_2026_87491 #cve202525249 #cve202619490 #cve202620079 #cve202687491

##

cisakevtracker@mastodon.social at 2026-09-09T20:01:09.000Z ##

CVE ID: CVE-2025-25249
Vendor: Fortinet
Product: Multiple Products
Date Added: 2026-09-09
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-84942
(8.7 HIGH)

EPSS: 0.33%

updated 2026-09-09T21:17:05.473000

1 posts

Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function pro

thehackerwire@mastodon.social at 2026-09-08T21:00:13.000Z ##

🟠 CVE-2026-84942 - High (8.7)

Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12855
(8.2 HIGH)

EPSS: 0.12%

updated 2026-09-09T21:17:01.313000

1 posts

Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects.

offseq@infosec.exchange at 2026-09-09T04:30:23.000Z ##

CVE-2026-12855: HIGH-severity vuln in InsydeH2O firmware (HP). Local attackers with high privileges may execute arbitrary code due to improper input validation. No patch yet — restrict local admin access. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Firmware #Infosec

##

CVE-2026-85061
(10.0 CRITICAL)

EPSS: 0.31%

updated 2026-09-09T21:09:13.080000

1 posts

MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collection, shifting indexes and skipping an adjacent dangerous attribute. An attacker who controls untrusted third-party style attribution strings or user-supplied cust

DailyCyberSecurity@infosec.exchange at 2026-09-09T02:25:56.000Z ##

A critical MapLibre XSS vulnerability allows zero-click code execution in 2.7M weekly downloads. Discover how CVE-2026-85061 works and how to patch now.

#MapLibre #XSS #CVE202685061 #WebSecurity #InfoSec #CyberSecurity #OpenSource

securityonline.info/maplibre-x

##

CVE-2026-17469
(5.3 MEDIUM)

EPSS: 0.21%

updated 2026-09-09T18:32:16

2 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.

hugovalters@mastodon.social at 2026-09-10T20:40:01.000Z ##

CVE-2026-17469: IBM i (7.3-7.6) DoS via off-by-one write in LPD queue parser. Local authenticated attacker can crash the service. CVSS 5.3. No patch yet. Lock down LPD access & monitor. Details: valtersit.com/cve/CVE-2026-174 #CVE #IBM #infosec

##

hugovalters@mastodon.social at 2026-09-10T20:40:01.000Z ##

CVE-2026-17469: IBM i (7.3-7.6) DoS via off-by-one write in LPD queue parser. Local authenticated attacker can crash the service. CVSS 5.3. No patch yet. Lock down LPD access & monitor. Details: valtersit.com/cve/CVE-2026-174 #CVE #IBM #infosec

##

CVE-2026-87929
(9.8 CRITICAL)

EPSS: 0.29%

updated 2026-09-09T18:32:12

2 posts

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a malicious ci_session cookie with administrator privileges by computing an HMAC-SHA1 using the publicly known encryption key, bypassing authentication checks

thehackerwire@mastodon.social at 2026-09-10T00:04:45.000Z ##

🔴 CVE-2026-87929 - Critical (9.8)

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a mal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-09-10T00:04:45.000Z ##

🔴 CVE-2026-87929 - Critical (9.8)

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a mal...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87927
(8.2 HIGH)

EPSS: 0.34%

updated 2026-09-09T18:32:12

1 posts

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler actions without authentication to access sensitive functionality.

thehackerwire@mastodon.social at 2026-09-09T20:00:47.000Z ##

🟠 CVE-2026-87927 - High (8.2)

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Att...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87874
(8.1 HIGH)

EPSS: 0.43%

updated 2026-09-09T18:32:11

1 posts

A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached is unauthenticated and cache keys are predictable, an attacker able to reach a n

thehackerwire@mastodon.social at 2026-09-09T20:00:36.000Z ##

🟠 CVE-2026-87874 - High (8.1)

A flaw was found in the memcached cache plugin of the community.general Ansible
collection. Although its documentation states that records are stored in JSON
format, the plugin performs no explicit serialization and relies on
python-memcached, whi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83970
(7.8 HIGH)

EPSS: 0.31%

updated 2026-09-09T17:17:48.473000

1 posts

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

nyanbinary@infosec.exchange at 2026-09-08T18:36:25.000Z ##

I'm also quickly going to mention this, explicitly not as a complaint but as a good case study of a well chosen "SHOULD" & why should is better than must here:

cve.org/ResourcesSupport/AllRe

5.1.1 SHOULD contain sufficient information to uniquely identify the Vulnerability and distinguish it from similar Vulnerabilities.

This, uh, will be a bit of an issue with msrc.microsoft.com/update-guid & msrc.microsoft.com/update-guid . You it actually doesn't matter. The fix is the same, fucking update. And it doesn't matter if you got owned through -83972 or -83970, given the current firehose. It's actually one of those cases where I'd be happy to relax the "one record per vuln" rule, in no world does the differentiation of these two matter to anyone.

##

CVE-2026-57166
(0 None)

EPSS: 0.44%

updated 2026-09-09T17:17:23.950000

1 posts

PJSIP is a free and open source multimedia communication library written in C. Prior to commit 4472a31, a stack buffer overflow exists in the PJLIB-UTIL telnet CLI front-end when rendering feedback for an entered command line. Several command-line handling paths write an attacker-influenced amount of data into fixed-size buffers without sufficient bounds checking, so a long command line can overfl

hugovalters@mastodon.social at 2026-09-11T03:30:35.000Z ##

CVE-2026-57166: Stack buffer overflow in PJSIP's telnet CLI front-end (pj_cli_telnet_cre). Long command lines can overflow fixed buffers—potential code execution. CVSS N/A, unpatched. If you enable telnet CLI, disable it or update once a fix lands. Details: https://www.valtersit.

##

CVE-2026-75165
(6.5 MEDIUM)

EPSS: 0.41%

updated 2026-09-09T16:04:24.933000

1 posts

An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to invoke hidden network diagnostic methods (ugw-ping, ugw-traceroute) that are not exposed in the web UI, allowing attackers to obtain sensitive information.

hugovalters@mastodon.social at 2026-09-11T03:10:17.000Z ##

CVE-2026-75165: Authenticated RCE risk via hidden diagnostics in MBS-Solutions X-Serie Gateway (V6_00_05). Low-privileged users can trigger ugw-ping/traceroute to leak sensitive data. CVSS: N/A, unpatched. Restrict access & monitor logs now. Details: valtersit.com/cve

##

CVE-2026-85103
(9.8 CRITICAL)

EPSS: 0.36%

updated 2026-09-09T15:35:15

7 posts

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

cyberworldops at 2026-09-10T15:00:00.734Z ##

Check Point patched two critical VPN certificate handling flaws, CVE-2026-85102 and CVE-2026-85103, both rated 9.8. They allow unauthenticated remote code execution, making internet-facing VPN gateways an immediate target. Review exposure, apply patches, and investigate for signs of compromise.

cyberworldops.eu/en/check-poin

##

undercodenews@mastodon.social at 2026-09-10T12:39:01.000Z ##

Check Point Rushes to Patch Two Critical VPN Vulnerabilities With 98 CVSS Scores + Video

A Serious Warning for Security Gateway Operators Check Point has moved quickly to patch two critical vulnerabilities affecting its VPN certificate-processing technology, closing a potentially dangerous path that could allow an unauthenticated remote attacker to execute code on vulnerable security infrastructure. The flaws, tracked as CVE-2026-85102 and CVE-2026-85103, were…

undercodenews.com/check-point-

##

cyberworldops@infosec.exchange at 2026-09-10T15:00:00.000Z ##

Check Point patched two critical VPN certificate handling flaws, CVE-2026-85102 and CVE-2026-85103, both rated 9.8. They allow unauthenticated remote code execution, making internet-facing VPN gateways an immediate target. Review exposure, apply patches, and investigate for signs of compromise. #CyberSecurity #CheckPoint #VPN #RCE

cyberworldops.eu/en/check-poin

##

daniel1820815@infosec.exchange at 2026-09-09T20:10:44.000Z ##

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510

Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.

community.checkpoint.com/t5/Ge

#CheckPoint #CheckPointSoftwareTechnologies #VPN #vulnerability

##

cR0w@infosec.exchange at 2026-09-09T15:52:09.000Z ##

It has been :zero_percent: days since an ASN.1 decoding vuln.

It has been :zero_percent: days since an overflow vuln in a corp VPN.

It has been :zero_percent: days since a vuln with "Quantum" in the system name.

They are all the same vuln.

nvd.nist.gov/vuln/detail/cve-2

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T14:36:57.000Z ##

Check Point fixed critical Check Point VPN vulnerabilities. Update gateways to prevent remote code execution under CVE-2026-85102 and CVE-2026-85103.

#CheckPoint #VPN #Cybersecurity #CVE202685102 #CVE202685103

securityonline.info/checkpoint

##

offseq@infosec.exchange at 2026-09-09T13:30:24.000Z ##

CRITICAL CVE-2026-85103 in Check Point Quantum Security Gateway: Heap-based buffer overflow in VPN certificate ASN.1 decoding allows unauthenticated RCE. Patch pending — monitor vendor. radar.offseq.com/threat/cve-20 #OffSeq #CheckPoint #infosec #Vuln

##

CVE-2026-87628
(8.3 HIGH)

EPSS: 0.17%

updated 2026-09-09T15:35:03

1 posts

Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)

offseq@infosec.exchange at 2026-09-09T01:30:26.000Z ##

CVE-2026-87628: CRITICAL use-after-free in Chrome's Cast (<153.0.8010.36) enables adjacent code execution outside the sandbox. Patch status unconfirmed. Check the vendor advisory: radar.offseq.com/threat/cve-20 #OffSeq #Chrome #Vuln #CVE202687628

##

CVE-2026-81953
(7.8 HIGH)

EPSS: 0.43%

updated 2026-09-09T15:03:00.630000

1 posts

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

nyanbinary@infosec.exchange at 2026-09-08T18:13:22.000Z ##

db.gcve.eu/vuln/cve-2026-81953

Microsoft Excel Remote Code Execution Vulnerability

looks inside

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

##

CVE-2026-53581
(9.0 CRITICAL)

EPSS: 0.33%

updated 2026-09-09T14:17:12.343000

2 posts

OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary files on the system as the root user. By manipulating the GPS or PPS serial port parameter, an attacker with access to the NTP configuration can escape th

offseq@infosec.exchange at 2026-09-09T00:00:35.000Z ##

CVE-2026-53581 (CRITICAL, CVSS 9.0): OPNsense core <26.1.9 NTP module path traversal lets privileged users overwrite files as root. Upgrade to 26.1.9+ & backend 26.4_20+ now. radar.offseq.com/threat/cve-20 #OffSeq #OPNsense #Vuln #PathTraversal

##

thehackerwire@mastodon.social at 2026-09-09T00:00:16.000Z ##

🔴 CVE-2026-53581 - Critical (9)

OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87794
(8.4 HIGH)

EPSS: 0.19%

updated 2026-09-09T12:32:22

1 posts

bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.

thehackerwire@mastodon.social at 2026-09-09T12:00:25.000Z ##

🟠 CVE-2026-87794 - High (8.4)

bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with cra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-80172
(9.8 CRITICAL)

EPSS: 0.27%

updated 2026-09-09T12:32:22

1 posts

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Verification of Data Authenticity vulnerability. An unauthenticated attacker with remote access could exploit this, leading to unauthorized access. This vulnerability is considered critical as an unauthenticated attacker can repeatedly reuse a captured request to

offseq@infosec.exchange at 2026-09-09T12:00:25.000Z ##

Dell SCG 5.0 (pre-5.36.00.00) hit by CRITICAL vuln (CVE-2026-80172, CVSS 9.8): unauthenticated attackers can reuse requests to gain admin access. Upgrade required to patch. radar.offseq.com/threat/cve-20 #OffSeq #CVE202680172 #Dell #Infosec

##

CVE-2026-87795
(8.2 HIGH)

EPSS: 0.34%

updated 2026-09-09T12:32:12

1 posts

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

thehackerwire@mastodon.social at 2026-09-09T12:00:35.000Z ##

🟠 CVE-2026-87795 - High (8.2)

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69829
(9.8 CRITICAL)

EPSS: 1.05%

updated 2026-09-09T10:20:20.210000

1 posts

Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.

security_crawler_carl@infosec.exchange at 2026-09-09T00:46:57.000Z ##

Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.

Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately — yes, right now, before you ask if it can wait until Friday.

Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.

#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)

##

CVE-2026-79696(CVSS UNKNOWN)

EPSS: 0.44%

updated 2026-09-09T09:33:06

1 posts

A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay.

offseq@infosec.exchange at 2026-09-09T10:30:26.000Z ##

CVE-2026-79696: Critical code injection (CVSS 10.0) in Google Cloud ADK for Python (2.0.0 – 2.6.0). Unauth RCE possible via crafted session replay in pytest-enabled Cloud Run & GKE. Patch or update now. radar.offseq.com/threat/cve-20 #OffSeq #CVE #CloudSecurity #Python

##

CVE-2026-16272
(9.1 CRITICAL)

EPSS: 0.14%

updated 2026-09-09T09:33:00

1 posts

Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.

offseq@infosec.exchange at 2026-09-09T09:00:24.000Z ##

CVE-2026-16272 (CVSS 9.1, CRITICAL) in PayTR Virtual Pos iFrame API (v9x) WHMCS Module v9.0.0: Use of less trusted source can compromise confidentiality and integrity. No patch yet — restrict access and monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026_16272 #infosec

##

CVE-2026-76009
(8.1 HIGH)

EPSS: 0.52%

updated 2026-09-09T06:31:48

2 posts

The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function. This is due to the plugin registering the `/wp-json/next_cart/v1/migration` REST route with `permission_callback` set to `__return_true` and relying on a hardcoded fallback value of `__token__` in `get_option

thehackerwire@mastodon.social at 2026-09-09T09:01:38.000Z ##

🟠 CVE-2026-76009 - High (8.1)

The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function. This is due to the plugin registering the `/wp-json/nex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-09-09T06:00:25.000Z ##

CVE-2026-76009 (HIGH): Next-Cart Store to WooCommerce Migration ≤3.9.8 exposes an auth bypass via REST API. Attackers can execute arbitrary SQL & delete files — full site compromise possible. Patch status unknown. Details: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #Infosec

##

CVE-2026-87734
(7.5 HIGH)

EPSS: 0.29%

updated 2026-09-09T06:31:40

1 posts

An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.

thehackerwire@mastodon.social at 2026-09-09T09:01:48.000Z ##

🟠 CVE-2026-87734 - High (7.5)

An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-81963
(7.8 HIGH)

EPSS: 0.63%

updated 2026-09-09T05:18:17.173000

8 posts

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

AAKL@infosec.exchange at 2026-09-09T16:27:09.000Z ##

New.

Press release:

CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats cisa.gov/news-events/news/cisa

The guide: cisa.gov/resources-tools/resou

Updates to the Kev catalogue:

- CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability cve.org/CVERecord?id=CVE-2026- #Microsoft #Windows

- CVE-2026-86218: N-able N-central Static Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-81963: Microsoft Windows Link Following Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability cve.org/CVERecord?id=CVE-2026- #Adobe

Yesterday:

Joint advisory: China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies cisa.gov/news-events/cybersecu #CISA #infosec #vulnerability

##

youranonnewsirc@nerdculture.de at 2026-09-09T16:26:23.000Z ##

**Latest Global Briefing: September 9, 2026**

**Cybersecurity:** Microsoft's September Patch Tuesday revealed nearly 1000 vulnerabilities, with CISA flagging two exploited zero-days (CVE-2026-81963, CVE-2026-85880) requiring urgent patching by federal agencies. The FBI also announced a new strategy to enhance cyberattack disruptions.

**Technology:** Dell Technologies reported surging Q2 FY 2027 earnings driven by high AI server demand, with OpenAI exploring AI infrastructure-as-a-service.

**Geopolitics:** Tensions heightened in the Middle East as US forces destroyed five Iranian oil tankers following IRGC attacks on a US Navy warship. Separately, 12 nations implemented trade bans on goods from Israeli settlements.

#Cybersecurity #TechNews #Geopolitics

##

secdb@infosec.exchange at 2026-09-09T11:00:11.000Z ##

🚨 [CISA-2026:0908] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-75650 (secdb.nttzen.cloud/cve/detail/)
- Name: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: helpx.adobe.com/security/produ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-81963 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Link Following Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-85880 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Heap-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-86218 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Static Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: status.n-able.com/2026/09/06/n ; me.n-able.com/s/security-advis ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260908 #cisa20260908 #cve_2026_75650 #cve_2026_81963 #cve_2026_85880 #cve_2026_86218 #cve202675650 #cve202681963 #cve202685880 #cve202686218

##

beyondmachines1@infosec.exchange at 2026-09-09T09:01:13.000Z ##

Microsoft Patches 966 Vulnerabilities in September 2026 Update Including Two Actively Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixed 966 flaws, its largest ever. The patch package includes 105 critical bugs and two actively exploited zero-days (CVE-2026-81963 and CVE-2026-85880). The critical flaws cluster in Windows network services (DNS, DHCP, RRAS, Netlogon), Office file parsing, imaging/graphics components, and Azure/Entra cloud services. Microsoft is attributing the surge in volume to AI-assisted vulnerability discovery.

**Patch the Windows OS first for the two zero-days, CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in ALPC, both already exploited in attacks to gain SYSTEM privileges. Next, patch internet-reachable and domain-joined Windows servers: DNS, DHCP, RRAS, Netlogon, Kerberos and the Key Distribution Center, Services for NFS, Deployment Services, Failover Cluster and SSTP all carry critical remote code execution flaws. Then move through Outlook, Word, Excel, and Office, followed by SQL Server, SharePoint Server, and Exchange. Windows Hello, Secure Kernel Mode, Credential Guard, and VBS should follow for anything holding credentials or running as a security boundary. Everything else can follow in the normal cycle, but plan for it to take longer than usual: almost no organization can test and deploy this volume in a single window.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

security_crawler_carl@infosec.exchange at 2026-09-09T00:46:57.000Z ##

Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.

Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately — yes, right now, before you ask if it can wait until Friday.

Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.

#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)

##

security_crawler_carl@infosec.exchange at 2026-09-09T00:46:57.000Z ##

🏆 New Achievement! Stand In The Fire One More Time, I Dare You!

NINE HUNDRED AND SEVENTY-FOUR vulnerabilities. Microsoft dropped 974 patches this Patch Tuesday and you are STILL standing in the bad stuff. CVE-2026-81963 and CVE-2026-85880, both CVSS 7.8, are being actively exploited RIGHT NOW against the Windows Update Stack and Windows Advanced Local Procedure Call — privilege escalation, in the wild, before disclosure. (1/2)

##

cisakevtracker@mastodon.social at 2026-09-08T19:01:01.000Z ##

CVE ID: CVE-2026-81963
Vendor: Microsoft
Product: Windows
Date Added: 2026-09-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-09-08T18:09:23.000Z ##

Microsoft's September 2026 Patch Tuesday fixes two zero-day flaws, CVE-2026-81963 and CVE-2026-85880, both exploited in the wild.

#PatchTuesday #ZeroDay #Microsoft #Windows #CyberSecurity #CVE #Infosec #VulnerabilityManagement

securityonline.info/patch-tues

##

CVE-2026-75650
(10.0 CRITICAL)

EPSS: 2.15%

updated 2026-09-09T05:18:07.237000

11 posts

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

4 repos

https://github.com/jithinkrishnanrs/stylesmuggler-ioc-toolkit

https://github.com/dinosn/cve-2026-75650-magento-validation-lab

https://github.com/disrex-group/stylesmuggler-adobe-patches-mageos

https://github.com/disrex-group/stylesmuggler-adobe-patches

shochdoerfer@phpc.social at 2026-09-10T16:51:52.000Z ##

If you want to learn more about the latest zero-day #Magento exploit (StyleSmuggler), this a great read: graycore.io/case-studies/CVE-2

##

thecybermind at 2026-09-10T09:42:55.630Z ##

Executive alert: CVE-2026-75650 actively threatens Adobe Commerce and Magento infrastructure. Review board-ready risk evaluation protocols, asset integrity measures, and strategic remediation steps to protect your enterprise value today.

thecybermind.co/hip4

##

thecybermind at 2026-09-10T00:59:17.540Z ##

Critical CVE-2026-75650 alert for Adobe Commerce and Magento. Active CISA KEV exploitation requires immediate template parsing audits and endpoint hardening. Access our technical forensic brief to secure your enterprise perimeter today.

thecybermind.co/8in9

##

shochdoerfer@phpc.social at 2026-09-10T16:51:52.000Z ##

If you want to learn more about the latest zero-day #Magento exploit (StyleSmuggler), this a great read: graycore.io/case-studies/CVE-2

##

thecybermind@infosec.exchange at 2026-09-10T09:42:55.000Z ##

Executive alert: CVE-2026-75650 actively threatens Adobe Commerce and Magento infrastructure. Review board-ready risk evaluation protocols, asset integrity measures, and strategic remediation steps to protect your enterprise value today.

thecybermind.co/hip4

##

thecybermind@infosec.exchange at 2026-09-10T00:59:17.000Z ##

Critical CVE-2026-75650 alert for Adobe Commerce and Magento. Active CISA KEV exploitation requires immediate template parsing audits and endpoint hardening. Access our technical forensic brief to secure your enterprise perimeter today.

thecybermind.co/8in9

##

AAKL@infosec.exchange at 2026-09-09T16:27:09.000Z ##

New.

Press release:

CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats cisa.gov/news-events/news/cisa

The guide: cisa.gov/resources-tools/resou

Updates to the Kev catalogue:

- CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability cve.org/CVERecord?id=CVE-2026- #Microsoft #Windows

- CVE-2026-86218: N-able N-central Static Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-81963: Microsoft Windows Link Following Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability cve.org/CVERecord?id=CVE-2026- #Adobe

Yesterday:

Joint advisory: China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies cisa.gov/news-events/cybersecu #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-09-09T11:00:11.000Z ##

🚨 [CISA-2026:0908] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-75650 (secdb.nttzen.cloud/cve/detail/)
- Name: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: helpx.adobe.com/security/produ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-81963 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Link Following Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-85880 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Heap-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-86218 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Static Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: status.n-able.com/2026/09/06/n ; me.n-able.com/s/security-advis ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260908 #cisa20260908 #cve_2026_75650 #cve_2026_81963 #cve_2026_85880 #cve_2026_86218 #cve202675650 #cve202681963 #cve202685880 #cve202686218

##

benzogaga33@mamot.fr at 2026-09-09T09:40:05.000Z ##

Magento : la faille zero-day StyleSmuggler est corrigée, mais des boutiques sont déjà piratées it-connect.fr/magento-adobe-co #ActuCybersécurité #Cybersécurité #Vulnérabilité #Adobe

##

beyondmachines1@infosec.exchange at 2026-09-08T20:01:13.000Z ##

Adobe releases September 2026 patches for multiple products

Adobe's September 2026 security updates patch vulnerabilities across eight product families: Commerce/Magento, ColdFusion, Campaign Classic, Acrobat/Reader, Experience Manager, Photoshop, Illustrator, and Animate. The flaws could allow arbitrary code execution, privilege escalation, security feature bypass, file system read/write, memory exposure, and denial-of-service. The most urgent is CVE-2026-75650 (CVSS 10.0) in Adobe Commerce and Magento Open Source, an unauthenticated template-engine flaw already exploited in the wild and fixed by a separate out-of-band hotfix on September 7 that must be applied in addition to the September update.

**If you run Adobe Commerce or Magento Open Source, apply the out-of-band hotfix for CVE-2026-75650 immediately! Adobe is aware of this flaw being exploited in the wild, it carries a CVSS score of 10.0, and it can be triggered without authentication. Next, update ColdFusion and Adobe Campaign Classic, both of which received Adobe's highest priority rating and contain critical flaws that could lead to arbitrary code execution. Then apply the September Adobe Commerce security update, which is separate from the hotfix and must be installed in addition to it. After that, update Adobe Experience Manager and Acrobat and Reader. Finally, update Photoshop, Illustrator, and Animate. If you can't update right away, restrict network access to Commerce, ColdFusion, Campaign Classic, and Experience Manager servers, and avoid opening untrusted PDFs and untrusted image or project files in Acrobat, Reader, Photoshop, Illustrator, and Animate until patches are applied.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

cisakevtracker@mastodon.social at 2026-09-08T19:00:46.000Z ##

CVE ID: CVE-2026-75650
Vendor: Adobe
Product: Commerce and Magento
Date Added: 2026-09-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2025-14733
(9.8 CRITICAL)

EPSS: 26.51%

updated 2026-09-09T04:17:52.700000

9 posts

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN us

1 repos

https://github.com/machevalia/CVE-2025-14733

security_crawler_carl at 2026-09-10T20:28:41.199Z ##

🏆 New Achievement! WatchGuard Out, Ransomware In!

Patch Notes v0.0.0 (Unplanned Release): REMOVED — the assumption that your perimeter firewall was keeping anyone out. ADDED — unauthenticated remote code execution via CVE-2025-14733, a critical out-of-bounds write in the Fireware OS iked process affecting versions 11.x, 12.x, and 2025.1 through 2025.1.3. KNOWN ISSUE — ransomware gangs are already shipping this feature to your network. (1/2)

##

undercodenews@mastodon.social at 2026-09-10T13:08:36.000Z ##

CISA Warns WatchGuard Firebox RCE Is Being Exploited by Ransomware Attackers + Video

A Critical Firewall Vulnerability Has Become a Real-World Threat A serious warning is emerging for organizations that rely on WatchGuard Firebox appliances to protect their networks. The vulnerability tracked as CVE-2025-14733 is a critical out-of-bounds write flaw in the Fireware OS iked process that can allow an unauthenticated remote attacker to execute arbitrary code. WatchGuard…

undercodenews.com/cisa-warns-w

##

offseq at 2026-09-10T12:00:25.712Z ##

CVE-2025-14733: CRITICAL RCE in WatchGuard Firebox (Fireware OS 11.x+, 12.x+, 2025.1 – 2025.1.3) exploited by ransomware. Patch ASAP! Review VPN configs, monitor for IOCs. Details: radar.offseq.com/threat/cisa-w

##

cyberworldops at 2026-09-10T10:50:00.694Z ##

CISA confirmed CVE-2025-14733, a critical WatchGuard Firebox RCE, is being exploited in ransomware attacks. Edge firewalls are high-value targets because compromise enables network-wide access. Patch immediately and audit exposed interfaces for post-exploitation activity.

cyberworldops.eu/en/cisa-confi

##

Analyst207@mastodon.social at 2026-09-10T09:37:59.000Z ##

Ransomware gangs exploit WatchGuard firewall flaw

Ransomware gangs are exploiting a critical vulnerability in WatchGuard Firebox firewalls, allowing them to execute malicious code remotely with ease. This flaw, known as CVE-2025-14733, affects various Fireware OS versions and could leave your network exposed to low-complexity attacks.

osintsights.com/ransomware-gan

#Ransomware #Watchguard #Cve202514733 #FirewareOs #Ikev2Vpn

##

security_crawler_carl@infosec.exchange at 2026-09-10T20:28:41.000Z ##

🏆 New Achievement! WatchGuard Out, Ransomware In!

Patch Notes v0.0.0 (Unplanned Release): REMOVED — the assumption that your perimeter firewall was keeping anyone out. ADDED — unauthenticated remote code execution via CVE-2025-14733, a critical out-of-bounds write in the Fireware OS iked process affecting versions 11.x, 12.x, and 2025.1 through 2025.1.3. KNOWN ISSUE — ransomware gangs are already shipping this feature to your network. (1/2)

##

offseq@infosec.exchange at 2026-09-10T12:00:25.000Z ##

CVE-2025-14733: CRITICAL RCE in WatchGuard Firebox (Fireware OS 11.x+, 12.x+, 2025.1 – 2025.1.3) exploited by ransomware. Patch ASAP! Review VPN configs, monitor for IOCs. Details: radar.offseq.com/threat/cisa-w #OffSeq #WatchGuard #Ransomware #Infosec

##

cyberworldops@infosec.exchange at 2026-09-10T10:50:00.000Z ##

CISA confirmed CVE-2025-14733, a critical WatchGuard Firebox RCE, is being exploited in ransomware attacks. Edge firewalls are high-value targets because compromise enables network-wide access. Patch immediately and audit exposed interfaces for post-exploitation activity. #WatchGuard #Ransomware #CisaKev

cyberworldops.eu/en/cisa-confi

##

kev_Stalker@infosec.exchange at 2026-09-09T11:19:35.000Z ##

CVE-2025-14733 - Changed to Known Ransomware Status

WatchGuard Firebox Out of Bounds Write VulnerabilityVendor: WatchGuardProduct: FireboxWatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-15667
(7.5 HIGH)

EPSS: 0.56%

updated 2026-09-09T03:30:51

1 posts

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execut

offseq@infosec.exchange at 2026-09-09T03:00:25.000Z ##

CVE-2026-15667: HIGH-severity LFI in Eventin WordPress plugin (≤4.1.22). Contributors can include arbitrary PHP via 'event_layout', risking code execution. Restrict privileges & await patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #LFI

##

CVE-2026-81994
(8.2 HIGH)

EPSS: 0.30%

updated 2026-09-08T21:34:41

1 posts

Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious fi

thehackerwire@mastodon.social at 2026-09-09T03:00:30.000Z ##

🟠 CVE-2026-81994 - High (8.2)

Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitiv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82007
(7.8 HIGH)

EPSS: 0.23%

updated 2026-09-08T21:34:36

1 posts

Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

thehackerwire@mastodon.social at 2026-09-08T21:00:23.000Z ##

🟠 CVE-2026-82007 - High (7.8)

Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a ma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85880
(7.8 HIGH)

EPSS: 0.57%

updated 2026-09-08T21:34:12

8 posts

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

AAKL@infosec.exchange at 2026-09-09T16:27:09.000Z ##

New.

Press release:

CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats cisa.gov/news-events/news/cisa

The guide: cisa.gov/resources-tools/resou

Updates to the Kev catalogue:

- CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability cve.org/CVERecord?id=CVE-2026- #Microsoft #Windows

- CVE-2026-86218: N-able N-central Static Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-81963: Microsoft Windows Link Following Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability cve.org/CVERecord?id=CVE-2026- #Adobe

Yesterday:

Joint advisory: China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies cisa.gov/news-events/cybersecu #CISA #infosec #vulnerability

##

youranonnewsirc@nerdculture.de at 2026-09-09T16:26:23.000Z ##

**Latest Global Briefing: September 9, 2026**

**Cybersecurity:** Microsoft's September Patch Tuesday revealed nearly 1000 vulnerabilities, with CISA flagging two exploited zero-days (CVE-2026-81963, CVE-2026-85880) requiring urgent patching by federal agencies. The FBI also announced a new strategy to enhance cyberattack disruptions.

**Technology:** Dell Technologies reported surging Q2 FY 2027 earnings driven by high AI server demand, with OpenAI exploring AI infrastructure-as-a-service.

**Geopolitics:** Tensions heightened in the Middle East as US forces destroyed five Iranian oil tankers following IRGC attacks on a US Navy warship. Separately, 12 nations implemented trade bans on goods from Israeli settlements.

#Cybersecurity #TechNews #Geopolitics

##

secdb@infosec.exchange at 2026-09-09T11:00:11.000Z ##

🚨 [CISA-2026:0908] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-75650 (secdb.nttzen.cloud/cve/detail/)
- Name: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: helpx.adobe.com/security/produ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-81963 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Link Following Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-85880 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Heap-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-86218 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Static Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: status.n-able.com/2026/09/06/n ; me.n-able.com/s/security-advis ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260908 #cisa20260908 #cve_2026_75650 #cve_2026_81963 #cve_2026_85880 #cve_2026_86218 #cve202675650 #cve202681963 #cve202685880 #cve202686218

##

beyondmachines1@infosec.exchange at 2026-09-09T09:01:13.000Z ##

Microsoft Patches 966 Vulnerabilities in September 2026 Update Including Two Actively Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixed 966 flaws, its largest ever. The patch package includes 105 critical bugs and two actively exploited zero-days (CVE-2026-81963 and CVE-2026-85880). The critical flaws cluster in Windows network services (DNS, DHCP, RRAS, Netlogon), Office file parsing, imaging/graphics components, and Azure/Entra cloud services. Microsoft is attributing the surge in volume to AI-assisted vulnerability discovery.

**Patch the Windows OS first for the two zero-days, CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in ALPC, both already exploited in attacks to gain SYSTEM privileges. Next, patch internet-reachable and domain-joined Windows servers: DNS, DHCP, RRAS, Netlogon, Kerberos and the Key Distribution Center, Services for NFS, Deployment Services, Failover Cluster and SSTP all carry critical remote code execution flaws. Then move through Outlook, Word, Excel, and Office, followed by SQL Server, SharePoint Server, and Exchange. Windows Hello, Secure Kernel Mode, Credential Guard, and VBS should follow for anything holding credentials or running as a security boundary. Everything else can follow in the normal cycle, but plan for it to take longer than usual: almost no organization can test and deploy this volume in a single window.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

security_crawler_carl@infosec.exchange at 2026-09-09T00:46:57.000Z ##

Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.

Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately — yes, right now, before you ask if it can wait until Friday.

Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.

#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)

##

security_crawler_carl@infosec.exchange at 2026-09-09T00:46:57.000Z ##

🏆 New Achievement! Stand In The Fire One More Time, I Dare You!

NINE HUNDRED AND SEVENTY-FOUR vulnerabilities. Microsoft dropped 974 patches this Patch Tuesday and you are STILL standing in the bad stuff. CVE-2026-81963 and CVE-2026-85880, both CVSS 7.8, are being actively exploited RIGHT NOW against the Windows Update Stack and Windows Advanced Local Procedure Call — privilege escalation, in the wild, before disclosure. (1/2)

##

cisakevtracker@mastodon.social at 2026-09-08T19:01:33.000Z ##

CVE ID: CVE-2026-85880
Vendor: Microsoft
Product: Windows
Date Added: 2026-09-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-09-08T18:09:23.000Z ##

Microsoft's September 2026 Patch Tuesday fixes two zero-day flaws, CVE-2026-81963 and CVE-2026-85880, both exploited in the wild.

#PatchTuesday #ZeroDay #Microsoft #Windows #CyberSecurity #CVE #Infosec #VulnerabilityManagement

securityonline.info/patch-tues

##

CVE-2026-86218
(9.8 CRITICAL)

EPSS: 0.74%

updated 2026-09-08T21:33:02

12 posts

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

1 repos

https://github.com/HORKimhab/CVE-2026-86218

DailyCyberSecurity at 2026-09-10T14:04:30.724Z ##

Discover the severe N-central CVE-2026-86218 vulnerability allowing unauthenticated RCE. Learn about N-able HF4 patches, CISA mandates, and threat actors.

meterpreter.org/n-central-cve-

##

beyondmachines1 at 2026-09-10T11:01:14.357Z ##

N-Able Patches N-Central Zero-Day Exploited in the Wild

N-Able released an emergency hotfix for a remote code execution vulnerability (CVE-2026-86218) in N-Central that attackers are actively exploiting to gain full administrative control over RMM servers and downstream client endpoints.

**If you run on-premises N-able N-central, upgrade immediately to version 2026.3.1.14 (2026.3 Hotfix 4). Make sure to keep the management console off the open internet behind a VPN or firewall allowlist limited to trusted admin networks. Since attackers may have already gained access, check for unfamiliar administrator accounts, unknown scripts or scheduled jobs and strange outbound connections, and change all passwords and keys used by or stored on the N-central server.**

beyondmachines.net/event_detai

##

threatnoir at 2026-09-10T00:06:02.183Z ##

⚠️ CRITICAL: N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

CVE-2026-86218 is a critical pre-auth RCE in N-able N-central being actively exploited in the wild. Any organization running N-central is vulnerable to unauthenticated remote code execution. Federal agencies are mandated to patch by September 11, 2026.

threatnoir.com/focus

🤖 AI generated summary

##

DailyCyberSecurity@infosec.exchange at 2026-09-10T14:04:30.000Z ##

Discover the severe N-central CVE-2026-86218 vulnerability allowing unauthenticated RCE. Learn about N-able HF4 patches, CISA mandates, and threat actors.

#Ncentral #CVE202686218 #CyberSecurity #ZeroDay #Vulnerability

meterpreter.org/n-central-cve-

##

beyondmachines1@infosec.exchange at 2026-09-10T11:01:14.000Z ##

N-Able Patches N-Central Zero-Day Exploited in the Wild

N-Able released an emergency hotfix for a remote code execution vulnerability (CVE-2026-86218) in N-Central that attackers are actively exploiting to gain full administrative control over RMM servers and downstream client endpoints.

**If you run on-premises N-able N-central, upgrade immediately to version 2026.3.1.14 (2026.3 Hotfix 4). Make sure to keep the management console off the open internet behind a VPN or firewall allowlist limited to trusted admin networks. Since attackers may have already gained access, check for unfamiliar administrator accounts, unknown scripts or scheduled jobs and strange outbound connections, and change all passwords and keys used by or stored on the N-central server.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

threatnoir@infosec.exchange at 2026-09-10T00:06:02.000Z ##

⚠️ CRITICAL: N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

CVE-2026-86218 is a critical pre-auth RCE in N-able N-central being actively exploited in the wild. Any organization running N-central is vulnerable to unauthenticated remote code execution. Federal agencies are mandated to patch by September 11, 2026.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

AAKL@infosec.exchange at 2026-09-09T16:27:09.000Z ##

New.

Press release:

CISA Releases Updated Insider Threat Guide With New Insights to Mitigate Physical and Cyber Threats cisa.gov/news-events/news/cisa

The guide: cisa.gov/resources-tools/resou

Updates to the Kev catalogue:

- CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability cve.org/CVERecord?id=CVE-2026- #Microsoft #Windows

- CVE-2026-86218: N-able N-central Static Code Injection Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-81963: Microsoft Windows Link Following Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability cve.org/CVERecord?id=CVE-2026- #Adobe

Yesterday:

Joint advisory: China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies cisa.gov/news-events/cybersecu #CISA #infosec #vulnerability

##

cyberworldops@infosec.exchange at 2026-09-09T15:00:01.000Z ##

N-able released Hotfix 4 for CVE-2026-86218, a pre-auth RCE in on-prem N-central with CVSS 4.0 10.0. All builds before 2026.3.1.14 are vulnerable, including Hotfix 3. RMM pre-auth RCE is high-value for initial access, prioritize patching and internet exposure review. #NAble #NCentral #RemoteCodeExecution

cyberworldops.eu/en/n-able-fix

##

secdb@infosec.exchange at 2026-09-09T11:00:11.000Z ##

🚨 [CISA-2026:0908] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-75650 (secdb.nttzen.cloud/cve/detail/)
- Name: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Adobe
- Product: Commerce and Magento
- Notes: helpx.adobe.com/security/produ ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-81963 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Link Following Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-85880 (secdb.nttzen.cloud/cve/detail/)
- Name: Microsoft Windows Heap-Based Buffer Overflow Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: msrc.microsoft.com/update-guid ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-86218 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Static Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: status.n-able.com/2026/09/06/n ; me.n-able.com/s/security-advis ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260908 #cisa20260908 #cve_2026_75650 #cve_2026_81963 #cve_2026_85880 #cve_2026_86218 #cve202675650 #cve202681963 #cve202685880 #cve202686218

##

cyberworldops@infosec.exchange at 2026-09-09T07:10:01.000Z ##

CISA added CVE-2026-86218 to KEV after confirmed active exploitation. The N-able N-central static code injection allows pre-auth RCE with CVSS 9.8, exposing centralized management infrastructure. Patch and hunt for pre-patch compromise. #Nable #NCentral #RemoteCodeExecution

cyberworldops.eu/en/actively-e

##

ssvc@infosec.exchange at 2026-09-09T01:37:53.000Z ##

N-able didn't beat around the bush:

Since our post 9/5/2026, 08:11:00 UTC a third independent researcher disclosed to N-able a new vulnerability— one that has been exploited in the wild and is unrelated to the previously disclosed CVEs.

This critical zero-day vulnerability, CVE-2026-86218, could allow pre-authenticated access to the N-central server if exploited.

#nable #zeroday #KEV #CVE

##

cisakevtracker@mastodon.social at 2026-09-08T19:01:17.000Z ##

CVE ID: CVE-2026-86218
Vendor: N-able
Product: N-central
Date Added: 2026-09-08
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-84372
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-09-08T20:57:52

1 posts

### Summary An improper CRLF neutralization flaw in Predis' pipeline handling on aggregate connections lets an unauthenticated attacker who can influence any pipelined argument — a value **or** a key, e.g. a URL slug used as a cache key — smuggle arbitrary Redis commands into the connection. - On **cluster** connections (`cluster` option, incl. client-side sharding) this is remote command inje

CVE-2026-80119
(7.8 HIGH)

EPSS: 0.12%

updated 2026-09-08T20:10:30.270000

1 posts

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump complete physical memory contents by supplying a caller-controlled file path to an exposed IOCTL. Attackers can issue a single IOCTL call to trigger the driver

hugovalters@mastodon.social at 2026-09-10T04:20:44.000Z ##

CVE-2026-80119: Info disclosure in Directio64.sys lets unauthenticated local attackers dump physical memory via crafted IOCTL. CVSS 7.8. Unpatched. Update PassMark tools or restrict driver access. Details: valtersit.com/cve/CVE-2026-801 #CVE #infosec #cybersecurity

##

CVE-2026-86206
(0 None)

EPSS: 0.68%

updated 2026-09-08T19:16:41.410000

1 posts

A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4

ssvc@infosec.exchange at 2026-09-09T01:37:53.000Z ##

N-able didn't beat around the bush:

Since our post 9/5/2026, 08:11:00 UTC a third independent researcher disclosed to N-able a new vulnerability— one that has been exploited in the wild and is unrelated to the previously disclosed CVEs.

This critical zero-day vulnerability, CVE-2026-86218, could allow pre-authenticated access to the N-central server if exploited.

#nable #zeroday #KEV #CVE

##

CVE-2026-78234
(9.9 CRITICAL)

EPSS: 0.21%

updated 2026-09-08T19:08:15.590000

1 posts

A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource. Because the operator ships a ClusterRole that aggregates Hawtio CR permissions into the edit and admin roles, any user with

DailyCyberSecurity@infosec.exchange at 2026-09-09T00:32:06.000Z ##

A critical Hawtio Operator vulnerability, tracked as CVE-2026-78234, allows in-cluster service impersonation. Discover the impact and mitigation steps.

#HawtioOperator #CVE202678234 #Kubernetes #OpenShift #Vulnerability

securityonline.info/hawtio-ope

##

CVE-2026-85008
(3.7 LOW)

EPSS: 0.12%

updated 2026-09-08T19:07:52.113000

1 posts

undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of safe methods, so an unsafe method such as POST, PUT, or DELETE is never placed in the skip list and instead falls through to the full cache-read path. The response-storage gate also lacked a method check, so a response to an unsaf

hugovalters@mastodon.social at 2026-09-11T04:10:22.000Z ##

CVE-2026-85008: undici cache flaw lets unsafe methods (POST/PUT/DELETE) hit the cache-read path, risking data leaks & poisoning. CVSS 3.7 (low, but sneaky). Patch status unknown—audit your Node.js fetch cache config now. Details: valtersit.com/cve/CVE-2026-850 #CVE

##

CVE-2026-83972
(7.8 HIGH)

EPSS: 0.31%

updated 2026-09-08T18:34:21

1 posts

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

nyanbinary@infosec.exchange at 2026-09-08T18:36:25.000Z ##

I'm also quickly going to mention this, explicitly not as a complaint but as a good case study of a well chosen "SHOULD" & why should is better than must here:

cve.org/ResourcesSupport/AllRe

5.1.1 SHOULD contain sufficient information to uniquely identify the Vulnerability and distinguish it from similar Vulnerabilities.

This, uh, will be a bit of an issue with msrc.microsoft.com/update-guid & msrc.microsoft.com/update-guid . You it actually doesn't matter. The fix is the same, fucking update. And it doesn't matter if you got owned through -83972 or -83970, given the current firehose. It's actually one of those cases where I'd be happy to relax the "one record per vuln" rule, in no world does the differentiation of these two matter to anyone.

##

CVE-2026-81954
(7.8 HIGH)

EPSS: 0.32%

updated 2026-09-08T18:34:18

1 posts

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

nyanbinary@infosec.exchange at 2026-09-08T18:26:10.000Z ##

I explicitly don't want to complain about MSRC here, this is a bigger topic, but I am a bit confused here:

Compare these two:

msrc.microsoft.com/update-guid - AV:L,UI:R

Q: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
A: An attacker must send a user a malicious Office file and convince them to open it.

msrc.microsoft.com/update-guid - AV:N,UI:R

Q: How could an attacker exploit this vulnerability?
A: An attacker could send a specially crafted PowerPoint presentation containing malicious linked media to a target user. The user would need to open the presentation, start the slideshow, and allow the linked content. Successful exploitation could allow the attacker to execute code on the user's system. Authentication is not required.

To me the attack flow looks equivalent wrt to attacker location. We can argue about #2 being actually harder to execute, having more social engineering prerequisites... which is why it totally makes sense for #2 to scored higher on CVSS as it's apparently network & the other one local.

##

CVE-2026-83991
(5.5 MEDIUM)

EPSS: 0.34%

updated 2026-09-08T18:34:14

1 posts

Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.

2 repos

https://github.com/karollooool/CVE-2026-83991-writeup-and-poc

https://github.com/ZeroDayVPN/CVE-2026-83991-WriteUP-and-PoC

CVE-2026-80081
(8.8 HIGH)

EPSS: 0.47%

updated 2026-09-08T18:34:00

1 posts

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.

nyanbinary@infosec.exchange at 2026-09-08T18:26:10.000Z ##

I explicitly don't want to complain about MSRC here, this is a bigger topic, but I am a bit confused here:

Compare these two:

msrc.microsoft.com/update-guid - AV:L,UI:R

Q: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
A: An attacker must send a user a malicious Office file and convince them to open it.

msrc.microsoft.com/update-guid - AV:N,UI:R

Q: How could an attacker exploit this vulnerability?
A: An attacker could send a specially crafted PowerPoint presentation containing malicious linked media to a target user. The user would need to open the presentation, start the slideshow, and allow the linked content. Successful exploitation could allow the attacker to execute code on the user's system. Authentication is not required.

To me the attack flow looks equivalent wrt to attacker location. We can argue about #2 being actually harder to execute, having more social engineering prerequisites... which is why it totally makes sense for #2 to scored higher on CVSS as it's apparently network & the other one local.

##

CVE-2026-69730
(9.8 CRITICAL)

EPSS: 1.05%

updated 2026-09-08T18:33:07

3 posts

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

lrosa@mastodon.uno at 2026-09-10T03:46:13.000Z ##

Esecuzione remota di programmi (RCE) da remoto senza autenticazione sui server DNS di Microsoft.

Problema risolto con gli ultimi aggiornamenti.

Quasi tutti i Domain Controller hanno un server DNS a bordo e la vulnerabilità è sfruttabile con richieste DNS, quindi non bloccabili da un normale firewall.

msrc.microsoft.com/update-guid

##

i0null@infosec.exchange at 2026-09-09T22:38:29.000Z ##

@pkprotoplasm the infamous phrase is used on the FAQ of the MSRC advisory. the NIST description is even more generic.

msrc.microsoft.com/update-guid

##

security_crawler_carl@infosec.exchange at 2026-09-09T00:46:57.000Z ##

Meanwhile CVE-2026-69829 is a CVSS 9.8 heap overflow in Windows Shell letting unauthenticated attackers run code over a network. I called the mechanics. I drew the diagram. I made a spreadsheet.

Patch CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, and CVE-2026-69829 immediately — yes, right now, before you ask if it can wait until Friday.

Reward: You've received the Tunnel Vision Debuff. It cannot be cleansed.

#ZeroDay #Microsoft #WindowsUpdate #PrivilegeEscalation #CyberSecurity (2/2)

##

CVE-2026-69420
(7.8 HIGH)

EPSS: 0.32%

updated 2026-09-08T18:32:42

1 posts

Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally.

winterknight1337@infosec.exchange at 2026-09-08T22:18:42.000Z ##

CVE-2026-69420 is a heap based buffer overflow on Windows resulting in an LPE. Couldn’t have come up with a more memey CVE for 69420 if I tried.

##

CVE-2026-20293
(7.1 HIGH)

EPSS: 0.13%

updated 2026-09-08T18:32:05

1 posts

A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin&nbsp;or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized softw

ssvc@infosec.exchange at 2026-09-09T01:33:59.000Z ##

#Cisco only had one for #PatchTuesday? CVE-2026-20293 Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability

The Cisco PSIRT is aware that proof-of-concept exploit code is available for the vulnerability described in this advisory.

It appears to be related to Eclypsium research into UEFI shell vulnerabilities from 2025:

#poc #UEFI

##

CVE-2026-82067
(8.1 HIGH)

EPSS: 0.28%

updated 2026-09-08T18:32:04

2 posts

Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup. An unauthenticated user with network access to a deployment where this condition occurs can perform arbitrary administrative operations, resulting in full impact of data confidentiality, integrity, and a

CVE-2026-17057
(6.5 MEDIUM)

EPSS: 0.38%

updated 2026-09-08T18:17:35.417000

1 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.

hugovalters@mastodon.social at 2026-09-10T06:40:01.000Z ##

CVE-2026-17057: IBM i (7.3-7.6) missing auth for critical functions. Remote DoS + data integrity risk. CVSS 6.5. No patch available—assume exposed. Lock down network access & monitor logs now. valtersit.com/cve/CVE-2026-170 #CVE #IBM #cybersecurity

##

CVE-2025-20701
(8.8 HIGH)

EPSS: 7.77%

updated 2026-09-08T16:17:48.883000

1 posts

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

2 repos

https://github.com/x0jac0b0x/skullcandy-dime3-cve-2025-20701

https://github.com/SpiritualMachines/buds-audit

cyberveille@mastobot.ping.moi at 2026-09-10T14:30:05.000Z ##

📢 CVE-2025-20701 : Les écouteurs Skullcandy Dime 3 vulnérables au détournement Bluetooth

Le 9 septembre 2026, BleepingComputer relaie un avis du CERT/CC de l'Université Carnegie Mellon concernant une vulnérabilité affectant les écouteurs sans fil Skullcandy Dime 3 (modèle S2DCW). La faille, identifiée sous CVE-2025-20701, est présente dans le…

📖 cyberveille : cyberveille.ch/posts/2026-09-1
🌐 source : bleepingcomputer.com/news/secu
🟡 vérification factuelle moyenne
#Bluetooth #SkullcandyDime3 #Cyberveille

##

CVE-2026-33197(CVSS UNKNOWN)

EPSS: 0.12%

updated 2026-09-08T15:32:05

2 posts

AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of this vulnerability may lead to arbitrary code execution and impact system Confidentiality, Integrity, and Availability.

DailyCyberSecurity at 2026-09-10T01:14:10.106Z ##

A critical Secure Boot bypass vulnerability via a UEFI Shell flaw exposes servers to code execution. Discover how CVE-2026-33197 impacts devices.

securityonline.info/secure-boo

##

DailyCyberSecurity@infosec.exchange at 2026-09-10T01:14:10.000Z ##

A critical Secure Boot bypass vulnerability via a UEFI Shell flaw exposes servers to code execution. Discover how CVE-2026-33197 impacts devices.

#SecureBoot #UEFI #Vulnerability #Cybersecurity #CVE202633197

securityonline.info/secure-boo

##

CVE-2026-85786
(7.5 HIGH)

EPSS: 0.33%

updated 2026-09-08T14:00:33.017000

1 posts

Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression due to insufficient coverage of the GZIP auto-decompression opt-out introduced for CVE-2026-75936. To remediate this issue, users should upgrade to version 1.12.1.

hugovalters@mastodon.social at 2026-09-10T02:40:38.000Z ##

CVE-2026-85786: DoS via crafted compressed Ion data in Amazon ion-java <1.12.1. Expansion bomb bypasses GZIP opt-out (CVE-2026-75936). CVSS 7.5. Update to 1.12.1 now. valtersit.com/cve/CVE-2026-857 #CVE #infosec #AWS

##

CVE-2026-85012
(8.0 HIGH)

EPSS: 1.06%

updated 2026-09-08T14:00:33.017000

1 posts

Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the project to execute arbitrary commands in the blueprint resynthesis environment via shell metacharacters in the owner field of a [local] merge strategy entry

awssecurityfeed@infosec.exchange at 2026-09-09T21:45:02.000Z ##

CVE-2026-85012 - OS command injection in the Amazon CodeCatalyst blueprints SDK

Bulletin ID: 2026-095-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/03/2026 10:00 AM PDT
Description:
Amazon CodeCatalyst blueprints are reusable project templates that generate a software proj...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-85703
(6.5 MEDIUM)

EPSS: 0.33%

updated 2026-09-08T13:12:58.310000

1 posts

A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/backend.py of the component Jailbreak Mode. Executing a manipulation can lead to allocation of resources. The attack can be executed remotely. The exploit has been published and may be used. This product implements a rolling rele

hugovalters@mastodon.social at 2026-09-11T04:30:24.000Z ##

CVE-2026-85703: Freegpt Webui jailbreak mode flaw (getJailbreak) enables remote resource exhaustion. CVSS 6.5. Unpatched, exploit public. Rolling release—check for fixes now. valtersit.com/cve/CVE-2026-857 #CVE #infosec #cybersecurity

##

CVE-2026-31431
(7.8 HIGH)

EPSS: 99.91%

updated 2026-09-08T09:36:36

1 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just

100 repos

https://github.com/badsectorlabs/copyfail-go

https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized

https://github.com/b5null/CVE-2026-31431-C

https://github.com/jbnetwork-git/copy-fail-check

https://github.com/Iamliuxiaozhen/copy_fail

https://github.com/pascal-gujer/CVE-2026-31431

https://github.com/0xShe/CVE-2026-31431

https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit

https://github.com/rvzsec/CVE-2026-31431

https://github.com/novysodope/copy-fail-CVE-2026-31431-C

https://github.com/ErdemOzgen/copy-fail-cve-2026-31431

https://github.com/povzayd/CVE-2026-31431

https://github.com/lonelyor/CVE-2026-31431-exp

https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail

https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite

https://github.com/cs8425/copy-fail-go

https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431

https://github.com/AdityaBhatt3010/CVE-2026-31431

https://github.com/Alfredooe/CVE-2026-31431

https://github.com/qi4L/CVE-2026-31431-Container-Escape

https://github.com/sec17br/CVE-2026-31431-Copy-Fail

https://github.com/samanzamani/copy-fail-checker

https://github.com/sgkdev/ptrace_may_dream

https://github.com/aestechno/cve-2026-31431-ansible

https://github.com/mrunalp/block-copyfail

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script

https://github.com/0xBlackash/CVE-2026-31431

https://github.com/erlangparasu/mitigate_cve_2026_31431-sh

https://github.com/philfry/cve-2026-31431-ftrace

https://github.com/Xerxes-2/CVE-2026-31431-rs

https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE

https://github.com/insomnisec/Detections-CVE-2026-31431

https://github.com/wuwu001/CVE-2026-31431-exploit

https://github.com/Boos4721/copyfail-rs

https://github.com/nisec-eric/cve-2026-31431

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC

https://github.com/ExploitEoom/CVE-2026-31431

https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs

https://github.com/bigwario/copy-fail-CVE-2026-31431-C

https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431

https://github.com/sgkdev/page_inject

https://github.com/JuanBindez/CVE-2026-31431

https://github.com/haydenjames/CVE-2026-31431-check

https://github.com/sudoytang/copyfail-arm64

https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit

https://github.com/sammwyy/copyfail-rs

https://github.com/pyroceper/copy-fail-CVE-2026-31431

https://github.com/MrAriaNet/cPanel-Fix

https://github.com/Sl4cK0TH/CVE-2026-31431-PoC

https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4

https://github.com/atgreen/block-copyfail

https://github.com/ncmprbll/copy-fail-rs

https://github.com/SeanRickerd/cve-2026-31431

https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell

https://github.com/diemoeve/copyfail-rs

https://github.com/ben-slates/CVE-2026-31431-Exploit

https://github.com/guiimoraes/CVE-2026-31431

https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape

https://github.com/wesmar/CVE-2026-31431

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/tgies/copy-fail-c

https://github.com/wgnet/wg.copyfail.patch

https://github.com/kadir/copy-fail-CVE-2026-31431-IOC

https://github.com/theori-io/copy-fail-CVE-2026-31431

https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

https://github.com/pedromizz/copy-fail

https://github.com/JnamerZ/CopyFail-CVE-2026-31431

https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit

https://github.com/XsanFlip/CVE-2026-31431-Patch

https://github.com/yuspring/cve-2026-31431-poc

https://github.com/Dabbleam/CVE-2026-31431-mitigation

https://github.com/rootsecdev/cve_2026_31431

https://github.com/desultory/CVE-2026-31431

https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail

https://github.com/ZephrFish/CopyFail-CVE-2026-31431

https://github.com/luotian2/CVE-2026-31431

https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH

https://github.com/Huchangzhi/autorootlinux

https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431

https://github.com/abdelkabirouadoukou/CVE-2026-31431-Analysis-and-Fix

https://github.com/kinryulabs/rootpacket-cve-2026-31431

https://github.com/Smarttfoxx/copyfail

https://github.com/cyber-joker/copy-fail-python

https://github.com/TheMalwareGuardian/CVE-2026-31431

https://github.com/Qengineering/RK35xx-CopyFail-Hotfix

https://github.com/Juguitos/copy-fail

https://github.com/bootsareme/copyfail-deconstructed

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431

https://github.com/xeloxa/copyfail-exploit

https://github.com/malwarekid/CVE-2026-31431

https://github.com/cozystack/copy-fail-blocker

https://github.com/MartinPham/copy-fail-CVE-2026-31431-php

https://github.com/AliHzSec/CVE-2026-31431

https://github.com/gagaltotal/cve-2026-31431-copy-fail

https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431

https://github.com/4xura/CVE-2026-31431-Copy-Fail

kubesploit@learnk8s.news at 2026-09-09T18:36:03.000Z ##

This article examines why Copy Fail (CVE-2026-31431) breaks container assumptions and provides a small, safe Python check to determine whether your nodes can reach the vulnerable kernel path

ku.bz/CTv-Yf60c

##

CVE-2026-50093
(9.0 None)

EPSS: 0.19%

updated 2026-09-08T09:35:45

1 posts

A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.0 (All versions < V4.0.11.2177). A vulnerability in the OIS web module allows an attacker to upload arbitrary files to the server. Successful exploitation of this

CVE-2026-44756
(10.0 CRITICAL)

EPSS: 0.32%

updated 2026-09-08T03:31:21

5 posts

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availabil

DailyCyberSecurity at 2026-09-10T14:37:16.736Z ##

The SAP OVERPASS vulnerability (CVE-2026-44756) scores a perfect CVSS 10.0, letting attackers seize SAP servers before login. Patch Note 3747649 now.

securityexpress.info/sap-overp

##

DailyCyberSecurity@infosec.exchange at 2026-09-10T14:37:16.000Z ##

The SAP OVERPASS vulnerability (CVE-2026-44756) scores a perfect CVSS 10.0, letting attackers seize SAP servers before login. Patch Note 3747649 now.

#SAP #OVERPASS #CVE202644756 #CyberSecurity #RCE #Onapsis #InfoSec

securityexpress.info/sap-overp

##

guru@thecybersecguru.com at 2026-09-09T12:33:27.000Z ##

SAP OVERPASS CVE-2026-44756: CVSS 10.0 Kernel RCE Explained

SAP OVERPASS CVE-2026-44756 is a CVSS 10.0 kernel flaw enabling unauthenticated RCE. Learn the attack path, S4GET risks and patching steps

thecybersecguru.com/news/sap-o

##

jbhall56@infosec.exchange at 2026-09-09T12:29:39.000Z ##

The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP security company Onapsis, it has been codenamed OVERPASS. thehackernews.com/2026/09/sap-

##

security_crawler_carl@infosec.exchange at 2026-09-09T03:04:18.000Z ##

🏆 New Achievement! OVERPASS: The SAP Kernel Speedrun!

Patch compliance policy activated. Scanning enterprise environment. Detecting CVE-2026-44756, a CVSS 10/10 memory corruption flaw in SAP Extended Passport Processing, dubbed OVERPASS. Policy requires acknowledgment of impact: unauthenticated remote attackers may execute arbitrary system commands, drain database credentials and password hashes, hijack live user sessions, and rewrite configurations and SAP binaries. (1/2)

##

CVE-2026-67276(CVSS UNKNOWN)

EPSS: 0.24%

updated 2026-09-05T21:31:20

1 posts

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target

4 repos

https://github.com/dinosn/mikrotrick-poc

https://github.com/BlackHatExploitation/exploit-mikrotik-2026

https://github.com/4rt-Net/Mikrotrick_POC

https://github.com/HORKimhab/CVE-2026-67276

CVE-2026-86207(CVSS UNKNOWN)

EPSS: 0.73%

updated 2026-09-05T21:31:20

1 posts

An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs

ssvc@infosec.exchange at 2026-09-09T01:37:53.000Z ##

N-able didn't beat around the bush:

Since our post 9/5/2026, 08:11:00 UTC a third independent researcher disclosed to N-able a new vulnerability— one that has been exploited in the wild and is unrelated to the previously disclosed CVEs.

This critical zero-day vulnerability, CVE-2026-86218, could allow pre-authenticated access to the N-central server if exploited.

#nable #zeroday #KEV #CVE

##

CVE-2026-86090
(7.1 HIGH)

EPSS: 0.25%

updated 2026-09-05T00:31:10

1 posts

ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts.

hugovalters@mastodon.social at 2026-09-10T03:30:03.000Z ##

CVE-2026-86090: ntopng auth bypass lets non-admin users delete all alert endpoints, silencing critical notifications. CVSS 7.1. No patch yet. Audit your instance now. Details: valtersit.com/cve/CVE-2026-860 #CVE #infosec #ntopng

##

CVE-2026-85704
(3.7 LOW)

EPSS: 0.27%

updated 2026-09-04T21:32:00

1 posts

A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file server/config.py of the component Jailbreak Mode. The manipulation results in race condition. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is assessed as difficu

hugovalters@mastodon.social at 2026-09-10T12:50:16.000Z ##

CVE-2026-85704: Race condition in Freegpt Webui (Jailbreak Mode, server/config.py) allows remote attacks, but high complexity makes exploitation difficult. CVSS 3.7. Public exploit exists. No patch available.

Update or monitor immediately. More: valtersit.com/cve/CVE

##

CVE-2026-85637
(5.3 MEDIUM)

EPSS: 0.43%

updated 2026-09-04T21:31:59

1 posts

A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected by this issue is the function join_room of the file core/sockets.py of the component Admin Endpoint. The manipulation results in missing authentication. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue re

hugovalters@mastodon.social at 2026-09-11T01:10:13.000Z ##

CVE-2026-85637: Missing auth in jofpin/trape (Admin Endpoint) allows remote attacks via join_room. CVSS 5.3. Exploit public, no patch yet. If you run trape 1.0/2.0, isolate/disconnect it now. Details: valtersit.com/cve/CVE-2026-856 #CVE #infosec #cybersecurity

##

CVE-2026-80905(CVSS UNKNOWN)

EPSS: 0.15%

updated 2026-09-04T18:31:46

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: tap: fix wrong transport_header when sending VLAN-tagged frame In tap_get_user_xdp(), when processing a VLAN-tagged frame (e.g. ETH_P_8021Q), skb_set_network_header() is called first to advance network_header past the VLAN tag to the inner protocol header. skb_probe_transport_header() is then called with skb->protocol still

hugovalters@mastodon.social at 2026-09-10T08:10:03.000Z ##

CVE-2026-80905: Linux kernel net: tap bug mishandles VLAN-tagged frames, corrupting transport_header. Potential for network disruption or security bypass. Unpatched—act now. CVSS N/A. Details: valtersit.com/cve/CVE-2026-809 Update kernel immediately. #CVE #Linux #i

##

CVE-2026-80874(CVSS UNKNOWN)

EPSS: 0.14%

updated 2026-09-04T18:31:40

1 posts

In the Linux kernel, the following vulnerability has been resolved: arm64: dts: renesas: ironhide: Describe inline ECC carveouts The DBSC5 DRAM controller protects DRAM content using inline ECC. The inline ECC utilizes areas of DRAM for its operation, which are in the DRAM address range, but must not be accessed or modified. Describe the inline ECC carveout areas used by the DBSC5 controller on

hugovalters@mastodon.social at 2026-09-10T19:10:04.000Z ##

CVE-2026-80874: Linux kernel arm64 Renesas flaw—inline ECC carveouts not reserved, risking DRAM corruption via memory access. Unpatched. If you run affected kernels, isolate or patch ASAP. Details: valtersit.com/cve/CVE-2026-808 #CVE #Linux #infosec

##

CVE-2026-17255
(4.3 MEDIUM)

EPSS: 0.40%

updated 2026-09-04T18:31:40

1 posts

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements.

hugovalters@mastodon.social at 2026-09-10T17:30:01.000Z ##

CVE-2026-17255: DoS in IBM i (7.3-7.6) via malformed ICMPv6 Router Advertisements. Remote crash risk, CVSS 4.3. No patch confirmed. Review firewall rules & disable IPv6 if unused. Details: valtersit.com/cve/CVE-2026-172 #CVE #IBM #infosec

##

CVE-2026-17440
(5.5 MEDIUM)

EPSS: 0.10%

updated 2026-09-04T18:31:40

1 posts

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to cause a denial of service due to uncontrolled recursion.

hugovalters@mastodon.social at 2026-09-10T09:40:01.000Z ##

CVE-2026-17440: IBM App Connect Enterprise & Integration Bus for z/OS affected by DoS via uncontrolled recursion. CVSS 5.5. Local attacker can crash services. No patch yet—monitor and limit local access. Details: valtersit.com/cve/CVE-2026-174 #CVE #IBM #cybersecur

##

CVE-2026-16660
(5.3 MEDIUM)

EPSS: 0.36%

updated 2026-09-04T18:31:39

1 posts

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

hugovalters@mastodon.social at 2026-09-10T11:20:02.000Z ##

CVE-2026-16660: IBM Db2 Mirror for i (7.4-7.6) has an out-of-bounds read flaw. Remote attackers can trigger a DoS. CVSS 5.3. No patch yet. Details: valtersit.com/cve/CVE-2026-166 Monitor and harden access now. #CVE #IBM #infosec

##

CVE-2026-80872
(0 None)

EPSS: 0.15%

updated 2026-09-04T17:16:59.160000

1 posts

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/tas2781: Cancel async firmware request at unbind TAS2781 HDA I2C and SPI queue RCA firmware loading from component bind with request_firmware_nowait(). The firmware loader keeps the callback module pinned and holds a device reference, but the callback still uses driver-private HDA state. Component unbind removes contr

hugovalters@mastodon.social at 2026-09-10T14:30:03.000Z ##

CVE-2026-80872: Linux kernel ALSA tas2781 driver risks use-after-free during unbind—async firmware callback can outlive private HDA state. Local impact, no CVSS yet. Patch status unknown, so audit & update when fix lands. Full details: valtersit.com/cve/CVE-2026-808

##

CVE-2026-75754(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-09-04T03:31:07

1 posts

Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The attacker can then log in with the hardcode credentials to obtain a root shell, enabling direct reading, writing, and deletion of

sekurakbot@mastodon.com.pl at 2026-09-09T10:26:00.000Z ##

RCE z uprawnieniami roota. Krytyczna podatność (CVSS 10.0) w ASUS Control Center Enterprise

Firma ASUS w najnowszym biuletynie bezpieczeństwa poinformowała o wykryciu krytycznej luki w popularnym oprogramowaniu ASUS Control Center Enterprise (ACC). Podatność oznaczona identyfikatorem CVE-2026-75754 otrzymała maksymalną ocenę 10.0 w skali CVSS 4.0. TLDR: Świadczy to o tym, że potencjalny atakujący może w łatwy sposób, całkowicie zdalnie oraz bez konieczności jakiejkolwiek interakcji...

#WBiegu #Asus #ControlCenter #Cve #Rce

sekurak.pl/rce-z-uprawnieniami

##

CVE-2026-20212
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-09-02T18:32:26

1 posts

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with&nbsp;root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and

1 repos

https://github.com/HORKimhab/CVE-2026-20212

sekurakbot@mastodon.com.pl at 2026-09-09T10:26:00.000Z ##

Krytyczna luka w przełącznikach Cisco Nexus 9000 [CVE-2026-20212]. RCE bez uwierzytelnienia i dostęp do roota

Firma Cisco opublikowała biuletyn bezpieczeństwa opisujący krytyczną lukę w przełącznikach Nexus serii 9000 opartych na układach Silicon One. Podatność została oznaczona jako CVE-2026-20212 i oceniona na 9.8 (Critical) w skali CVSS v3.1. Umożliwia nieuwierzytelnionemu użytkownikowi zdalne wykonanie kodu z uprawnieniami roota. Poprawki bezpieczeństwa są już dostępne, zalecamy niezwłoczną aktualizację oprogramowania. ...

#WBiegu #Cisco #Cve #Nexus #Rce #Switch

sekurak.pl/krytyczna-luka-w-pr

##

CVE-2026-83548
(10.0 CRITICAL)

EPSS: 4.67%

updated 2026-09-02T18:32:06

1 posts

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

3 repos

https://github.com/xcoy0te/CVE-2026-83548-checker

https://github.com/xoessie/CVE-2026-83548-SonicWall-SMA1000-Analysis

https://github.com/HORKimhab/CVE-2026-83548-CVE-2026-83549

PC_Fluesterer@social.tchncs.de at 2026-09-10T11:55:45.000Z ##

SonicWall VPN-Router (Closed-Source) wird aktiv angegriffen

Appliances der SMA1000 Serie des amerikanischen Herstellers SonicWall stehen gerade unter Beschuss. Die Boxen sollen eigentlich für einen sicheren Fernzugang per VPN ins Intranet sorgen. Ja, es hätte so schön sein können. Die Angreifer verketten zwei unterschiedliche "Sicherheitslücken", um sich unbefugten Zugang in das Unternehmensnetzwerk dahinter zu verschaffen. Weshalb habe ich "Sicherheitslücken" in Anführungszeichen geschrieben? Weil es hier wieder mal streng riecht - nach Hintertür. Die erste Zero-day Schwachstelle CVE-2026-83548 (10 von 10) entsteht durch ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#0day #backdoor #cybercrime #exploits #firewall #hersteller #router #UnplugTrump #vorbeugen #wissen #zeroday

##

CVE-2026-82078
(9.1 CRITICAL)

EPSS: 1.69%

updated 2026-09-01T04:18:02.160000

4 posts

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on

2 repos

https://github.com/virologi-info/papercut-toolkit

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

cyberveille@mastobot.ping.moi at 2026-09-10T14:00:06.000Z ##

📢 Exploitation IA à grande échelle de PaperCut via CVE-2026-81578 et CVE-2026-82078

Cet article présente l'analyse technique d'une campagne d'exploitation active de serveurs PaperCut exposés sur Internet, utilisant les vulnérabilités CVE-2026-81578 et CVE-2026-82078.

📖 cyberveille : cyberveille.ch/posts/2026-09-1
🌐 source : blackpointcyber.com/blog/death
🟢 vérification factuelle haute
#PaperCut #AIAssistedExploitation #Cyberveille

##

AAKL@infosec.exchange at 2026-09-09T16:37:11.000Z ##

Which is to say, a real person directed this nonsense.

"On 31 August 2026, a likely Russian-speaking malicious cyber actor (MCA) used 45.142.193.132 and artificial intelligence (AI) to develop, test, and use exploits for PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078)."

GreyNoise: Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF greynoise.io/blog/ai-orchestra @greynoise #infosec #cyberattack #bot

##

guru@thecybersecguru.com at 2026-09-09T15:35:45.000Z ##

The AI swarm that breached 440 PaperCut servers worldwide

GreyNoise uncovered an AI-driven PaperCut attack that compromised 440 servers across 395 organizations in 48 countries using CVE-2026-81578 and CVE-2026-82078

thecybersecguru.com/news/ai-sw

##

ssvc@infosec.exchange at 2026-09-09T13:54:30.000Z ##

GreyNoise: Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF

On 31 August 2026, a likely Russian-speaking malicious cyber actor (MCA) used 45.142.193.132 and artificial intelligence (AI) to develop, test, and use exploits for PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078).
greynoise.io/blog/ai-orchestra

#papercut #CVE #threatintel #IOC

##

CVE-2026-81578
(9.8 CRITICAL)

EPSS: 1.62%

updated 2026-08-31T21:31:56

4 posts

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

2 repos

https://github.com/virologi-info/papercut-toolkit

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

cyberveille@mastobot.ping.moi at 2026-09-10T14:00:06.000Z ##

📢 Exploitation IA à grande échelle de PaperCut via CVE-2026-81578 et CVE-2026-82078

Cet article présente l'analyse technique d'une campagne d'exploitation active de serveurs PaperCut exposés sur Internet, utilisant les vulnérabilités CVE-2026-81578 et CVE-2026-82078.

📖 cyberveille : cyberveille.ch/posts/2026-09-1
🌐 source : blackpointcyber.com/blog/death
🟢 vérification factuelle haute
#PaperCut #AIAssistedExploitation #Cyberveille

##

AAKL@infosec.exchange at 2026-09-09T16:37:11.000Z ##

Which is to say, a real person directed this nonsense.

"On 31 August 2026, a likely Russian-speaking malicious cyber actor (MCA) used 45.142.193.132 and artificial intelligence (AI) to develop, test, and use exploits for PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078)."

GreyNoise: Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF greynoise.io/blog/ai-orchestra @greynoise #infosec #cyberattack #bot

##

guru@thecybersecguru.com at 2026-09-09T15:35:45.000Z ##

The AI swarm that breached 440 PaperCut servers worldwide

GreyNoise uncovered an AI-driven PaperCut attack that compromised 440 servers across 395 organizations in 48 countries using CVE-2026-81578 and CVE-2026-82078

thecybersecguru.com/news/ai-sw

##

ssvc@infosec.exchange at 2026-09-09T13:54:30.000Z ##

GreyNoise: Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF

On 31 August 2026, a likely Russian-speaking malicious cyber actor (MCA) used 45.142.193.132 and artificial intelligence (AI) to develop, test, and use exploits for PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078).
greynoise.io/blog/ai-orchestra

#papercut #CVE #threatintel #IOC

##

CVE-2026-77234
(8.8 HIGH)

EPSS: 0.12%

updated 2026-08-27T20:18:39.130000

1 posts

Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later.

awssecurityfeed@infosec.exchange at 2026-09-09T21:45:01.000Z ##

Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-69836
(10.0 CRITICAL)

EPSS: 1.55%

updated 2026-08-25T16:08:43.290000

1 posts

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

2 repos

https://github.com/sentinel-aidefense/CVE-2026-69836-EXP

https://github.com/HORKimhab/CVE-2026-69836

adulau@infosec.exchange at 2026-09-09T14:43:49.000Z ##

The @gcve BCP-07 KEV format has been updated to allow the Withdrawn and Reasserted KEV Assertions.

This allows to support case like CVE-2026-69836 .

🔗 gcve.eu/bcp/gcve-bcp-07/#withd

#cve #gcve #kev #cybersecurity #vulnerabilitymanagement #vulnerability

##

CVE-2026-75936
(7.5 HIGH)

EPSS: 0.44%

updated 2026-08-20T13:01:19.947000

1 posts

Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression. To remediate this issue, users should upgrade to version 1.12.0 and configure withGzipDecompressionEnabled(false) and/or set a

hugovalters@mastodon.social at 2026-09-10T02:40:38.000Z ##

CVE-2026-85786: DoS via crafted compressed Ion data in Amazon ion-java <1.12.1. Expansion bomb bypasses GZIP opt-out (CVE-2026-75936). CVSS 7.5. Update to 1.12.1 now. valtersit.com/cve/CVE-2026-857 #CVE #infosec #AWS

##

CVE-2026-69414
(7.8 HIGH)

EPSS: 0.56%

updated 2026-08-19T18:32:28

6 posts

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;ShieldBreak &quot;. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

2 repos

https://github.com/1neptune/ShieldBreak

https://github.com/HORKimhab/CVE-2026-50656

cyberworldops at 2026-09-10T18:50:00.635Z ##

Researcher Nightmare-Eclipse has released ShieldCrash, a PoC claiming to bypass Microsoft's fix for CVE-2026-69414, a privilege escalation flaw in Defender's Malware Protection Engine. Public exploit code may increase abuse; verify the patch blocks the technique and monitor for exploitation.

cyberworldops.eu/en/shieldcras

##

offseq at 2026-09-10T07:30:25.020Z ##

CRITICAL: ShieldCrash zero-day (CVE-2026-69414) exploits Microsoft Defender on patched Windows (Sept 2026), enabling privilege escalation to System and SAM dumping. No patch yet. Monitor for Defender anomalies. radar.offseq.com/threat/new-sh

##

cyberworldops@infosec.exchange at 2026-09-10T18:50:00.000Z ##

Researcher Nightmare-Eclipse has released ShieldCrash, a PoC claiming to bypass Microsoft's fix for CVE-2026-69414, a privilege escalation flaw in Defender's Malware Protection Engine. Public exploit code may increase abuse; verify the patch blocks the technique and monitor for exploitation. #CyberSecurity #Vulnerability #ThreatIntel #MicrosoftDefender

cyberworldops.eu/en/shieldcras

##

offseq@infosec.exchange at 2026-09-10T07:30:25.000Z ##

CRITICAL: ShieldCrash zero-day (CVE-2026-69414) exploits Microsoft Defender on patched Windows (Sept 2026), enabling privilege escalation to System and SAM dumping. No patch yet. Monitor for Defender anomalies. radar.offseq.com/threat/new-sh #OffSeq #ZeroDay #MicrosoftDefender #Infosec

##

cyberworldops@infosec.exchange at 2026-09-09T12:50:00.000Z ##

Chaotic Eclipse released ShieldCrash PoC, described as a patch bypass for CVE-2026-69414 ShieldBreak in Microsoft Malware Protection Engine. If valid, Defender privilege escalation remains exploitable despite the official fix, requiring re-validation of mitigations. #ShieldBreak #MicrosoftDefender #PatchBypass

cyberworldops.eu/en/microsoft-

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T00:35:56.000Z ##

A Windows Defender 0day has public PoC exploit code. ShieldCrash reads files as SYSTEM on all supported Windows versions.

#WindowsDefender #0day #CVE #ShieldCrash #CyberSecurity #Windows #PoC #Infosec

securityonline.info/windows-de

##

CVE-2026-68820
(7.0 HIGH)

EPSS: 6.18%

updated 2026-08-16T19:17:24.183000

1 posts

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

4 repos

https://github.com/maxprog-svg/CVE-2026-68820_Mass_Exploit

https://github.com/HORKimhab/CVE-2026-68820

https://github.com/fevar54/CVE-2026-68820-Mitigation-PoC-

https://github.com/ubitquity/Windows-WinSock-UAF-Mitigation

cyberworldops@infosec.exchange at 2026-09-09T10:30:00.000Z ##

Microsoft patched 398 vulnerabilities, 42 rated Critical. CVE-2026-68820 in afd.sys is actively exploited and added to CISA KEV, enabling local privilege escalation to SYSTEM. Prioritize Kernel and RCE flaws in this cycle. #PatchTuesday #WindowsSecurity #CisaKev

cyberworldops.eu/en/microsoft-

##

CVE-2026-19311
(8.1 HIGH)

EPSS: 0.41%

updated 2026-08-12T21:31:44

1 posts

Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.

awssecurityfeed@infosec.exchange at 2026-09-09T21:45:02.000Z ##

CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin

Bulletin ID: 2026-078-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 11:30 AM PDT
Description:
OpenSearch is a community-driven, open-source search and analytics suite. We identified CVE...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-20316
(5.3 MEDIUM)

EPSS: 11.15%

updated 2026-07-29T21:31:00

7 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vuln

cyberworldops at 2026-09-10T17:00:00.702Z ##

Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by Qilin ransomware, credential-theft actors, and Sandworm-linked groups. The auth bypass provides root command execution and the static credential exposure broadens initial access.

cyberworldops.eu/en/cisco-fmc-

##

undercodenews@mastodon.social at 2026-09-10T16:48:33.000Z ##

Cisco FMC Under Attack as Sandworm and Qilin Exploit Critical Vulnerabilities to Reach Protected Networks + Video

A New Warning for Enterprise Defenders Cisco Secure Firewall Management Center is facing a serious security crisis after Cisco Talos confirmed active exploitation of two vulnerabilities that can give attackers a foothold inside vulnerable environments. The flaws, tracked as CVE-2026-20079 and CVE-2026-20316, are being abused in real-world attacks involving…

undercodenews.com/cisco-fmc-un

##

beyondmachines1 at 2026-09-10T10:01:13.581Z ##

Cisco Secure Firewall Management Center Under Active Attack

Cisco Talos warns of active exploitation of two vulnerabilities (CVE-2026-20079 and CVE-2026-20316) in Secure Firewall Management Center, allowing attackers to gain root access and deploy malware like Cyclops Blink and Qilin ransomware.

**If you run Cisco Secure Firewall Management Center (versions 7.0.x, 7.1.x, or 7.2–7.7), apply Cisco's emergency patches for CVE-2026-20079 and CVE-2026-20316 right away. Make sure the management interface is reachable only from trusted internal networks, never the internet. Because these flaws are already being exploited, also check for unexpected files in /var/sf/bin/ and the Tomcat webroot. Then plan to install Cisco's hardening update due to be released in the week of September 14.**

beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-09-10T17:00:00.000Z ##

Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by Qilin ransomware, credential-theft actors, and Sandworm-linked groups. The auth bypass provides root command execution and the static credential exposure broadens initial access.

#CiscoFMC #ThreatIntelligence #VulnerabilityManagement #Qilin

cyberworldops.eu/en/cisco-fmc-

##

beyondmachines1@infosec.exchange at 2026-09-10T10:01:13.000Z ##

Cisco Secure Firewall Management Center Under Active Attack

Cisco Talos warns of active exploitation of two vulnerabilities (CVE-2026-20079 and CVE-2026-20316) in Secure Firewall Management Center, allowing attackers to gain root access and deploy malware like Cyclops Blink and Qilin ransomware.

**If you run Cisco Secure Firewall Management Center (versions 7.0.x, 7.1.x, or 7.2–7.7), apply Cisco's emergency patches for CVE-2026-20079 and CVE-2026-20316 right away. Make sure the management interface is reachable only from trusted internal networks, never the internet. Because these flaws are already being exploited, also check for unexpected files in /var/sf/bin/ and the Tomcat webroot. Then plan to install Cisco's hardening update due to be released in the week of September 14.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

ssvc@infosec.exchange at 2026-09-09T21:01:44.000Z ##

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system. Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account.

blog.talosintelligence.com/fmc

#threatintel #ransomware #Qilin #KEV #CVE

##

DailyCyberSecurity@infosec.exchange at 2026-09-09T16:28:31.000Z ##

Cisco Talos warns of Cisco FMC vulnerabilities actively exploited in the wild. Attackers chain CVE-2026-20079 and CVE-2026-20316 to deploy ransomware.

#CiscoFMC #Cybersecurity #CVE202620079 #Ransomware #InfoSec

securityonline.info/cisco-fmc-

##

CVE-2026-43502
(7.8 HIGH)

EPSS: 0.12%

updated 2026-07-23T16:10:00.137000

2 posts

In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but before the message is attached to the sending socket. The purge path currently infers zerocopy state from rm->m_rs, so an unqueued message can be cleaned up as if it owned normal payload pages. Howev

1 repos

https://github.com/suominen/pintheft

bearstech@mamot.fr at 2026-09-10T09:14:32.000Z ##

ZcopyReaper (CVE-2026-43502) nous avons déployé cette nuit les mesures de contournement.

Toutes nos VM ont été redémarrées en moins d’une heure.

👉 En savoir plus sur nos offres d'infogérance : bearstech.com/contact

Merci à @Octopuce et @evolix pour votre collaboration sur ce sujet.

##

bearstech@mamot.fr at 2026-09-10T09:14:32.000Z ##

ZcopyReaper (CVE-2026-43502) nous avons déployé cette nuit les mesures de contournement.

Toutes nos VM ont été redémarrées en moins d’une heure.

👉 En savoir plus sur nos offres d'infogérance : bearstech.com/contact

Merci à @Octopuce et @evolix pour votre collaboration sur ce sujet.

##

CVE-2026-15409
(10.0 CRITICAL)

EPSS: 83.66%

updated 2026-07-16T05:16:18.293000

2 posts

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

Nuclei template

6 repos

https://github.com/remmons-r7/rapid7-CVE-2026-15409

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

https://github.com/0xBlackash/CVE-2026-15409

https://github.com/HORKimhab/CVE-2026-15409

https://github.com/Ch4120N/CVE-2026-15409

_r_netsec at 2026-09-10T17:58:04.748Z ##

🕵️‍♂️ SonicWall SMA1000 (CVE-2026-15409): SSRF to Erlang RCE chained into automated DCSync from the appliance hunt.io/blog/sonicwall-sma1000

##

_r_netsec@infosec.exchange at 2026-09-10T17:58:04.000Z ##

🕵️‍♂️ SonicWall SMA1000 (CVE-2026-15409): SSRF to Erlang RCE chained into automated DCSync from the appliance hunt.io/blog/sonicwall-sma1000

##

CVE-2026-52774
(6.1 MEDIUM)

EPSS: 0.51%

updated 2026-07-09T21:01:12

1 posts

### Summary YesWiki's Bazar widget handler reflects the `id` `GET` parameter into HTML attributes using `strip_tags()` only. Because `strip_tags()` does not escape double quotes, an attacker can break out of the attribute value, inject an event handler such as `onmouseover`, and execute arbitrary JavaScript in the victim's browser. This issue is reachable without authentication. During validation

1 repos

https://github.com/0xTerror/CVE-2026-52774-YESWIKI-XSS

hugovalters@mastodon.social at 2026-09-10T05:00:36.000Z ##

CVE-2026-52774: YesWiki < 4.6.6 has a stored XSS via the Bazar widget's id parameter, exploitable without auth. CVSS 6.1. No patch confirmed. Update immediately or restrict access. Details: valtersit.com/cve/CVE-2026-527 #CVE #infosec #YesWiki

##

CVE-2026-53932
(8.0 HIGH)

EPSS: 0.91%

updated 2026-07-09T20:52:58

1 posts

## Summary A crafted backup archive can trigger OS command injection during database restore. The restore workflow extracts a ZIP archive, enumerates files under `db-dumps`, converts the dump path to an absolute path, and passes that path into database import commands that are built as shell command strings. The dump filename is not shell-escaped before it is interpolated into commands such as:

hugovalters@mastodon.social at 2026-09-10T05:00:01.000Z ##

CVE-2026-53932: OS command injection in laravel-backup-restore via crafted backup archives. CVSS 8. Unpatched before v1.9.4. If you restore Spatie backups, update now. Details: valtersit.com/cve/CVE-2026-539 #CVE #infosec #Laravel

##

CVE-2026-11387
(9.8 CRITICAL)

EPSS: 2.21%

updated 2026-07-01T09:30:33

2 posts

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.9.5. This is due to the plugin not properly validating a user's identity prior to updating their details like reset the password of any user account, including administrators, and gain full a

Nuclei template

2 repos

https://github.com/abraxas/CVE-2026-11387-WooCommerce-SMS-OTP

https://github.com/1beelze/CVE-2026-11387

DarkWebInformer at 2026-09-10T20:20:41.274Z ##

‼️ CVE-2026-11387: A critical improper-authentication flaw in the WordPress plugin SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery.

GitHub: github.com/abraxas/CVE-2026-11

##

DarkWebInformer@infosec.exchange at 2026-09-10T20:20:41.000Z ##

‼️ CVE-2026-11387: A critical improper-authentication flaw in the WordPress plugin SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery.

GitHub: github.com/abraxas/CVE-2026-11

##

CVE-2026-28576
(5.5 MEDIUM)

EPSS: 0.15%

updated 2026-06-17T16:43:32.927000

2 posts

In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

1 repos

https://github.com/mobilehackinglab/CVE-2026-28576-poc

CVE-2026-33671
(7.5 HIGH)

EPSS: 0.40%

updated 2026-06-17T10:37:54.007000

2 posts

Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlapping alternatives or nested extglobs, are compiled into regular expressions that can exhibit catastr

1 repos

https://github.com/BeLazy167/next-picomatch-cve-repro

certvde at 2026-09-10T07:33:05.830Z ##

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-09-10T07:33:05.000Z ##

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2019-0859
(7.8 HIGH)

EPSS: 4.15%

updated 2026-06-17T02:09:03.317000

2 posts

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0803.

1 repos

https://github.com/Sheisback/CVE-2019-0859-1day-Exploit

kev_Stalker at 2026-09-10T11:20:16.857Z ##

CVE-2019-0859 - Changed to Known Ransomware Status

Microsoft Win32k Privilege Escalation VulnerabilityVendor: MicrosoftProduct: Win32kMicrosoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 at 14:08:17 UTCDate Added to KEV: 2021-11-03View nvd.nist.gov/vuln/detail/CVE-2

##

kev_Stalker@infosec.exchange at 2026-09-10T11:20:16.000Z ##

CVE-2019-0859 - Changed to Known Ransomware Status

Microsoft Win32k Privilege Escalation VulnerabilityVendor: MicrosoftProduct: Win32kMicrosoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 at 14:08:17 UTCDate Added to KEV: 2021-11-03View nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-8510
(7.5 HIGH)

EPSS: 0.21%

updated 2026-05-15T00:31:36

2 posts

Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

571906@ap.podcastindex.org at 2026-09-11T02:00:02.000Z ##

New Episode: SANS Stormcast Friday, September 11th, 2026: Redtail Analsys (@sans_edu); Checkpoint VPN Patch; Netscaler and Sonicwall Attacks

Shownotes:

Redtail Payload Analysis
https://isc.sans.edu/diary/Redtail%20Payload%20Analysis%20%5BGuest%20Diary%5D/33326
Checkpoint Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510
https://community.checkpoint.com/t

Transcript

AntennaPod | Anytime Player | Apple Podcasts | Castamatic | CurioCaster | Fountain | gPodder | Overcast | Pocket Casts | Podcast Addict | Podcast Guru | Podnews | Podverse | Truefans

Or Listen right here.

##

daniel1820815@infosec.exchange at 2026-09-09T20:10:44.000Z ##

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510

Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.

community.checkpoint.com/t5/Ge

#CheckPoint #CheckPointSoftwareTechnologies #VPN #vulnerability

##

CVE-2026-0915
(7.5 HIGH)

EPSS: 0.59%

updated 2026-01-20T18:31:56

2 posts

Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.

1 repos

https://github.com/Terra-Nova83/CVE-2026-0915-json-Patch.-V2.0

certvde at 2026-09-10T07:33:05.830Z ##

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

##

certvde@infosec.exchange at 2026-09-10T07:33:05.000Z ##

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

#OT #Advisory

##

CVE-2022-41352
(9.8 CRITICAL)

EPSS: 95.48%

updated 2025-10-22T00:32:37

2 posts

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavisd via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red H

4 repos

https://github.com/rxerium/CVE-2022-41352

https://github.com/segfault-it/cve-2022-41352

https://github.com/dafrax/cve-2022-41352-zimbra-rce

https://github.com/Cr4ckC4t/cve-2022-41352-zimbra-rce

kev_Stalker at 2026-09-10T11:25:19.656Z ##

CVE-2022-41352 - Changed to Known Ransomware Status

Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityVendor: SynacorProduct: Zimbra Collaboration Suite (ZCS)Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 nvd.nist.gov/vuln/detail/CVE-2

##

kev_Stalker@infosec.exchange at 2026-09-10T11:25:19.000Z ##

CVE-2022-41352 - Changed to Known Ransomware Status

Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityVendor: SynacorProduct: Zimbra Collaboration Suite (ZCS)Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2016-7255
(7.8 HIGH)

EPSS: 80.97%

updated 2025-10-22T00:32:21

2 posts

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

5 repos

https://github.com/homjxi0e/CVE-2016-7255

https://github.com/FSecureLABS/CVE-2016-7255

https://github.com/heh3/CVE-2016-7255

https://github.com/yuvatia/page-table-exploitation

https://github.com/bbolmin/cve-2016-7255_x86_x64

kev_Stalker at 2026-09-10T11:30:23.497Z ##

CVE-2016-7255 - Changed to Known Ransomware Status

Microsoft Win32k Privilege Escalation VulnerabilityVendor: MicrosoftProduct: Win32kMicrosoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 at 14:08:17 UTCDate nvd.nist.gov/vuln/detail/CVE-2

##

kev_Stalker@infosec.exchange at 2026-09-10T11:30:23.000Z ##

CVE-2016-7255 - Changed to Known Ransomware Status

Microsoft Win32k Privilege Escalation VulnerabilityVendor: MicrosoftProduct: Win32kMicrosoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: September 09, 2026 at 14:08:17 UTCDate nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-16338
(0 None)

EPSS: 0.00%

2 posts

N/A

CVE-2026-70416
(0 None)

EPSS: 0.00%

2 posts

N/A

DailyCyberSecurity at 2026-09-11T01:59:08.824Z ##

Dell patched critical Dell ObjectScale vulnerabilities, led by CVE-2026-70416. Fix these Dell ObjectScale vulnerabilities to stop remote code execution.

securityonline.info/dell-objec

##

DailyCyberSecurity@infosec.exchange at 2026-09-11T01:59:08.000Z ##

Dell patched critical Dell ObjectScale vulnerabilities, led by CVE-2026-70416. Fix these Dell ObjectScale vulnerabilities to stop remote code execution.

#DellObjectScale #Cybersecurity #CVE202670416 #Vulnerabilities #InfoSec

securityonline.info/dell-objec

##

CVE-2026-63695
(0 None)

EPSS: 0.00%

2 posts

N/A

DailyCyberSecurity at 2026-09-11T01:32:54.532Z ##

Dell patched critical Dell Networking OS10 vulnerabilities, including CVE-2026-63695. Update your Dell SmartFabric OS10 switches to prevent session theft.

securityonline.info/dell-netwo

##

DailyCyberSecurity@infosec.exchange at 2026-09-11T01:32:54.000Z ##

Dell patched critical Dell Networking OS10 vulnerabilities, including CVE-2026-63695. Update your Dell SmartFabric OS10 switches to prevent session theft.

#DellNetworking #Cybersecurity #Vulnerabilities #CVE202663695 #InfoSec

securityonline.info/dell-netwo

##

CVE-2026-85706
(0 None)

EPSS: 0.00%

2 posts

N/A

DailyCyberSecurity at 2026-09-11T00:18:04.493Z ##

GitLab patched critical GitLab vulnerabilities, led by CVE-2026-85706 with a CVSS 10.0 score. Update your server now to protect source code from exposure.


securityonline.info/gitlab-vul

##

DailyCyberSecurity@infosec.exchange at 2026-09-11T00:18:04.000Z ##

GitLab patched critical GitLab vulnerabilities, led by CVE-2026-85706 with a CVSS 10.0 score. Update your server now to protect source code from exposure.

#GitLab #CVE202685706 #Vulnerabilities #DevSecOps #Cybersecurity
securityonline.info/gitlab-vul

##

cert_fr@social.numerique.gouv.fr at 2026-09-10T16:04:24.000Z ##

⚠️Alerte CERT-FR⚠️

Le CERT-FR a connaissance de nombreuses compromissions de Metabase vulnérables à l'injection SQL CVE-2026-72898.

cert.ssi.gouv.fr/alerte/CERTFR

##

cert_fr@social.numerique.gouv.fr at 2026-09-10T16:04:24.000Z ##

⚠️Alerte CERT-FR⚠️

Le CERT-FR a connaissance de nombreuses compromissions de Metabase vulnérables à l'injection SQL CVE-2026-72898.

cert.ssi.gouv.fr/alerte/CERTFR

##

CVE-2026-57162
(0 None)

EPSS: 0.35%

1 posts

N/A

hugovalters@mastodon.social at 2026-09-10T16:00:22.000Z ##

CVE-2026-57162: Stack buffer overflow in PJSIP SRTP/SDES when processing crafted crypto attributes during SDP negotiation. CVSS: N/A, unpatched. If you use SRTP with SDES keying, you are exposed. Patch immediately. Details: valtersit.com/cve/CVE-2026-571 #CVE #info

##

CVE-2026-73453
(0 None)

EPSS: 0.00%

1 posts

N/A

sayzard@mastodon.sayzard.org at 2026-09-10T11:42:38.000Z ##

Arista Networks Arbitrary RCE Vulnerability

Arista EOS에서 P4Runtime가 활성화된 특정 구성에 대해 인증 없이 원격 코드 실행이 가능한 CVE-2026-73453이 공개됐다. 공격자는 P4Runtime 세션 초기화 과정의 악성 패킷으로 스위치의 완전한 관리자 권한을 획득할 수 있으며, CVSS v3.1 점수는 10.0이다. 다만 P4Runtime는 기본적으로 비활성화되어 있으므로, 운영자는 `show p4-runtime`으로 노출 여부를 우선 점검해야 한다. 영향받는 환경은 mTLS와 gNSI Authz를 적용하고, EOS 4.36.2F·4.35.6M·4...

arista.com/en/support/advisori

##

CVE-2026-84390
(0 None)

EPSS: 0.00%

2 posts

N/A

beyondmachines1 at 2026-09-10T09:01:13.421Z ##

Fortinet Patches Critical Authentication Bypass and Proxy Flaws Across Product Line

Fortinet patched 10 vulnerabilities, including two critical flaws (CVE-2026-84390 and CVE-2026-84388) that allow unauthenticated attackers to bypass authentication in FortiMonitorOnSight and proxy browser traffic via a Chrome extension.

**If you use Fortinet products, patch ASAP. Prioritise FortiMonitorOnSight and the Privileged Access Agent Chrome extension, then review everything else and update to the latest stable versions such as FortiOS and FortiProxy 7.6.7. After patching, check your logs for reused or forged JWTs and any unusual traffic from admin machines.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-10T09:01:13.000Z ##

Fortinet Patches Critical Authentication Bypass and Proxy Flaws Across Product Line

Fortinet patched 10 vulnerabilities, including two critical flaws (CVE-2026-84390 and CVE-2026-84388) that allow unauthenticated attackers to bypass authentication in FortiMonitorOnSight and proxy browser traffic via a Chrome extension.

**If you use Fortinet products, patch ASAP. Prioritise FortiMonitorOnSight and the Privileged Access Agent Chrome extension, then review everything else and update to the latest stable versions such as FortiOS and FortiProxy 7.6.7. After patching, check your logs for reused or forged JWTs and any unusual traffic from admin machines.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-84388
(0 None)

EPSS: 0.00%

2 posts

N/A

beyondmachines1 at 2026-09-10T09:01:13.421Z ##

Fortinet Patches Critical Authentication Bypass and Proxy Flaws Across Product Line

Fortinet patched 10 vulnerabilities, including two critical flaws (CVE-2026-84390 and CVE-2026-84388) that allow unauthenticated attackers to bypass authentication in FortiMonitorOnSight and proxy browser traffic via a Chrome extension.

**If you use Fortinet products, patch ASAP. Prioritise FortiMonitorOnSight and the Privileged Access Agent Chrome extension, then review everything else and update to the latest stable versions such as FortiOS and FortiProxy 7.6.7. After patching, check your logs for reused or forged JWTs and any unusual traffic from admin machines.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-09-10T09:01:13.000Z ##

Fortinet Patches Critical Authentication Bypass and Proxy Flaws Across Product Line

Fortinet patched 10 vulnerabilities, including two critical flaws (CVE-2026-84390 and CVE-2026-84388) that allow unauthenticated attackers to bypass authentication in FortiMonitorOnSight and proxy browser traffic via a Chrome extension.

**If you use Fortinet products, patch ASAP. Prioritise FortiMonitorOnSight and the Privileged Access Agent Chrome extension, then review everything else and update to the latest stable versions such as FortiOS and FortiProxy 7.6.7. After patching, check your logs for reused or forged JWTs and any unusual traffic from admin machines.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-87911
(0 None)

EPSS: 0.99%

3 posts

N/A

offseq at 2026-09-10T06:00:25.092Z ##

CVE-2026-87911 (CVSS 9.6): CRITICAL OS command injection in AWS Labs postgres MCP Server (<1.1.7). Unauthenticated attackers can execute OS commands via crafted SQL. Upgrade to 1.1.7+ ASAP. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-09-10T06:00:25.000Z ##

CVE-2026-87911 (CVSS 9.6): CRITICAL OS command injection in AWS Labs postgres MCP Server (<1.1.7). Unauthenticated attackers can execute OS commands via crafted SQL. Upgrade to 1.1.7+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #AWS #PostgreSQL #Vuln

##

thehackerwire@mastodon.social at 2026-09-09T21:00:50.000Z ##

🔴 CVE-2026-87911 - Critical (9.6)

An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-manage...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77236
(0 None)

EPSS: 0.11%

1 posts

N/A

awssecurityfeed@infosec.exchange at 2026-09-09T21:45:01.000Z ##

Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-77237
(0 None)

EPSS: 0.13%

1 posts

N/A

awssecurityfeed@infosec.exchange at 2026-09-09T21:45:01.000Z ##

Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-77235
(0 None)

EPSS: 0.11%

1 posts

N/A

awssecurityfeed@infosec.exchange at 2026-09-09T21:45:01.000Z ##

Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT
Description:
FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small micro...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-54694
(0 None)

EPSS: 0.28%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-09T20:00:26.000Z ##

🔴 CVE-2026-54694 - Critical (9.6)

SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` builds an H...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85982
(0 None)

EPSS: 0.22%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-09T03:00:08.000Z ##

🔴 CVE-2026-85982 - Critical (9)

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify dir...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-85083
(0 None)

EPSS: 0.00%

1 posts

N/A

cyberworldops@infosec.exchange at 2026-09-09T01:30:00.000Z ##

CISA advisory ICSA-26-251-01 documents CVE-2026-85083 in CareCam Pro ANJIA AJL33PC0801: hard-coded bootloader credential allows privileged access with physical presence. It enables firmware modification and persistent compromise, undermining trust in affected deployments. #HardcodedCredentials #IotSecurity #FirmwareSecurity

cyberworldops.eu/en/hard-coded

##

CVE-2026-53939
(0 None)

EPSS: 0.20%

1 posts

N/A

thehackerwire@mastodon.social at 2026-09-09T01:00:19.000Z ##

🔴 CVE-2026-53939 - Critical (9.1)

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites