## Updated at UTC 2026-06-24T22:19:00.938518

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2025-60471 5.5 0.00% 2 0 2026-06-24T21:30:43 A use-after-free in the gf_filter_pid_reconfigure_task_discard function (/filter
CVE-2026-48939 0 0.40% 1 0 2026-06-24T19:17:11.143000 A vulnerability in the iCagenda extension for Joomla allows the upload of arbitr
CVE-2026-48908 0 0.61% 1 4 2026-06-24T19:17:11.037000 A vulnerability in SP Page Builder for Joomla allows unauthenticated users to up
CVE-2026-20230 8.6 25.85% 4 2 2026-06-24T18:33:41 A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco U
CVE-2026-55200 8.1 0.91% 5 1 2026-06-24T17:17:29.693000 libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write
CVE-2026-10735 7.5 0.20% 1 2 2026-06-24T15:31:43 Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimoni
CVE-2026-32174 7.7 0.37% 1 0 2026-06-24T15:19:03.857000 Improper authentication in Azure Bot Service allows an authorized attacker to el
CVE-2026-34908 10.0 2.10% 5 1 2026-06-24T14:50:41.720000 A malicious actor with access to the network could exploit an Improper Access Co
CVE-2026-34909 10.0 1.82% 4 0 2026-06-24T14:49:53.287000 A malicious actor with access to the network could exploit a Path Traversal vuln
CVE-2026-34910 10.0 81.84% 4 0 template 2026-06-24T14:49:47.237000 A malicious actor with access to the network could exploit an Improper Input Val
CVE-2026-12850 9.1 1.72% 1 0 2026-06-24T14:17:30.287000 Multiple OS command injection vulnerabilities exist in the libNetSetObj.so funct
CVE-2026-12417 9.8 0.45% 1 1 2026-06-24T09:30:46 The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass
CVE-2026-12416 9.8 0.36% 1 1 2026-06-24T09:30:46 The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via
CVE-2026-12851 9.1 1.68% 1 0 2026-06-24T06:31:51 Multiple OS command injection vulnerabilities exist in the libNetSetObj.so funct
CVE-2026-47647 9.9 0.44% 1 0 2026-06-24T05:17:28.903000 Improper access control in Microsoft Dynamics 365 allows an authorized attacker
CVE-2026-44914 7.2 0.39% 1 0 2026-06-24T05:17:28.290000 Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Proces
CVE-2025-67038 9.8 1.13% 8 0 2026-06-24T05:17:25.670000 An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module exec
CVE-2026-11807 9.6 0.36% 1 0 2026-06-24T03:31:40 A missing authorization vulnerability was found in the Event-Driven Ansible (EDA
CVE-2026-54317 7.6 0.19% 1 0 2026-06-23T19:34:58.770000 Home Assistant is open source home automation software that puts local control a
CVE-2026-7664 9.8 0.28% 1 0 2026-06-23T19:17:12.450000 IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to ac
CVE-2026-48979 7.5 0.27% 1 0 2026-06-23T16:04:55.583000 PHP Standard Library (PSL) is set of APIs covering async, collections, networkin
CVE-2026-12866 9.8 0.45% 1 0 2026-06-23T15:42:30.483000 All versions of the package expr-eval are vulnerable to Code Execution via the t
CVE-2026-44727 0 0.24% 1 0 2026-06-23T15:37:54.137000 Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the n
CVE-2026-10521 7.2 0.31% 3 0 2026-06-23T09:32:28 An high privileged remote attacker can access a hidden configuration method, tha
CVE-2026-11374 9.0 1.24% 1 0 2026-06-23T09:32:28 In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and
CVE-2026-6645 0 0.14% 1 0 2026-06-23T05:17:05.117000 An insecure process execution vulnerability exists in the pc-printer-updater.exe
CVE-2026-11833 None 0.22% 1 0 2026-06-23T03:31:48 Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web s
CVE-2026-11551 9.8 0.62% 2 3 2026-06-23T03:16:40.677000 The Branda plugin for WordPress is vulnerable to privilege escalation via accoun
CVE-2026-8461 8.8 0.39% 4 3 2026-06-22T20:31:03.510000 An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specificall
CVE-2026-12044 8.8 0.51% 1 0 2026-06-22T20:23:26.770000 SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT O
CVE-2026-11717 0 0.19% 1 0 2026-06-22T20:18:53.300000 An authentication bypass vulnerability exists in the generic opaque token valida
CVE-2026-12581 7.5 0.30% 1 0 2026-06-22T20:17:59.447000 EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unau
CVE-2026-54414 9.8 0.72% 1 0 2026-06-22T20:17:59.447000 FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder uplo
CVE-2026-55199 5.9 0.37% 1 0 2026-06-22T18:43:49.900000 libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication d
CVE-2026-56382 7.2 0.49% 1 0 2026-06-22T18:40:05.833000 Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contai
CVE-2026-8157 8.8 0.24% 1 0 2026-06-22T18:38:02.507000 The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles
CVE-2026-10789 9.6 0.29% 1 0 2026-06-22T18:34:24 A maliciously crafted webpage, when visited by a user with Autodesk Fusion Deskt
CVE-2026-56448 0 0.29% 1 0 2026-06-22T18:16:50.207000 A path traversal vulnerability exists in AIL Framework before the release contai
CVE-2026-41950 6.5 0.33% 2 0 2026-06-22T18:16:37.293000 Dify before version 1.14.0 contains an authorization bypass vulnerability that a
CVE-2026-41948 9.4 0.51% 2 0 2026-06-22T18:16:37.033000 Dify version 1.14.1 and prior contain a path traversal vulnerability that allows
CVE-2026-41947 9.1 0.45% 2 0 2026-06-22T18:16:36.883000 Dify before version 1.14.2 contains an authorization bypass vulnerability that a
CVE-2026-9843 8.1 0.66% 1 0 2026-06-22T16:43:14.450000 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress i
CVE-2026-10561 10.0 0.53% 1 0 2026-06-22T15:30:52 IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper iso
CVE-2026-7166 None 0.38% 1 0 2026-06-22T15:30:46 Vulnerability involving the exposure of sensitive data provided without adequate
CVE-2026-20181 9.1 0.75% 2 0 2026-06-22T14:31:46.277000 A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote at
CVE-2026-54104 8.8 0.40% 2 0 2026-06-22T14:17:41.693000 The U.S. Government Accountability Office (GAO) Electronic Protest Docketing Sys
CVE-2026-12806 8.8 0.46% 1 0 2026-06-21T21:31:04 A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element
CVE-2026-56394 6.5 0.34% 1 0 2026-06-21T15:31:31 Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability
CVE-2026-56265 9.8 0.43% 1 0 2026-06-21T15:31:31 Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a h
CVE-2026-12786 7.8 0.11% 1 0 2026-06-21T09:30:57 A vulnerability has been found in Ezbsystems UltraISO Premium Edition up to 9.76
CVE-2026-12784 7.8 0.11% 1 0 2026-06-21T09:30:51 A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This a
CVE-2026-12781 7.8 0.11% 1 0 2026-06-21T09:30:50 A vulnerability was identified in EaseUS Partition Master up to 14.5. The affect
CVE-2026-12782 7.8 0.11% 1 0 2026-06-21T09:30:50 A security flaw has been discovered in EaseUS Partition Master up to 14.5. The i
CVE-2026-56099 5.3 0.36% 1 0 2026-06-21T09:30:50 OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulner
CVE-2025-20701 8.8 4.19% 1 0 2026-06-21T09:30:49 In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth aud
CVE-2026-12779 7.8 0.11% 1 0 2026-06-21T06:32:15 A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issu
CVE-2026-12780 7.8 0.11% 1 0 2026-06-21T06:32:14 A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an un
CVE-2026-12774 6.3 0.21% 1 0 2026-06-21T06:32:14 A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affe
CVE-2026-5366 9.9 0.57% 1 0 2026-06-20T18:31:35 Prefect version 3.6.23 is vulnerable to remote code execution due to improper ha
CVE-2022-50972 9.8 0.63% 1 0 2026-06-20T15:32:32 WooCommerce 7.1.0 contains a remote code execution vulnerability that allows att
CVE-2026-48909 None 0.80% 1 1 2026-06-20T15:32:23 SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie dat
CVE-2026-11912 7.5 0.43% 1 1 2026-06-20T09:33:32 The Simple File List plugin for WordPress is vulnerable to arbitrary file modifi
CVE-2026-11911 7.5 0.78% 1 0 2026-06-20T09:33:32 The Simple File List plugin for WordPress is vulnerable to arbitrary file deleti
CVE-2026-56082 7.5 0.24% 1 0 2026-06-20T00:34:15 Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnera
CVE-2026-56081 9.1 0.35% 2 0 2026-06-20T00:34:14 Cap-go before 12.128.2 contains an authentication logic flaw that lets an attack
CVE-2026-56073 9.4 0.19% 1 0 2026-06-20T00:34:08 Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP ve
CVE-2026-42824 6.5 7.64% 1 0 2026-06-19T21:16:42.893000 Missing authentication for critical function in M365 Copilot allows an unauthori
CVE-2026-50195 None 0.00% 1 0 2026-06-19T19:35:24 ## Impact containerd's CRI checkpoint import process contains a vulnerability wh
CVE-2026-8713 9.1 1.19% 1 0 2026-06-19T06:32:02 The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file
CVE-2026-7515 9.8 0.89% 1 2 2026-06-19T06:32:02 The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in
CVE-2026-40624 9.8 0.62% 1 0 2026-06-19T00:31:46 Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras
CVE-2026-12048 9.3 0.31% 1 0 2026-06-19T00:31:46 Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-renderi
CVE-2026-47633 7.5 0.58% 1 0 2026-06-19T00:31:41 Exposure of sensitive information to an unauthorized actor in Cost Management In
CVE-2026-54130 9.8 0.50% 1 0 2026-06-19T00:31:41 Missing authentication for critical function in M365 Copilot allows an unauthori
CVE-2026-11409 7.2 2.79% 1 0 2026-06-18T21:33:34 An authenticated OS command injection vulnerability exists in the IPv6 PPPoE con
CVE-2026-11410 7.2 2.79% 1 0 2026-06-18T21:33:34 An authenticated OS command injection vulnerability exists in the BigPond Cable
CVE-2026-55203 7.5 0.29% 1 0 2026-06-18T18:35:31 HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vul
CVE-2026-54103 9.8 0.43% 3 0 2026-06-18T18:35:31 The U.S. Government Accountability Office (GAO) Electronic Protest Docketing Sys
CVE-2026-54390 9.8 0.33% 1 0 2026-06-18T18:35:31 JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection
CVE-2026-20253 9.8 92.10% 11 3 template 2026-06-18T18:35:18 In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform
CVE-2026-42530 8.1 2.39% 5 3 2026-06-18T04:16:48.520000 NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGI
CVE-2026-42055 8.1 1.82% 4 1 2026-06-18T04:16:48.367000 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_m
CVE-2026-54388 9.1 0.39% 1 0 2026-06-17T21:34:45 Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests cont
CVE-2026-23243 7.8 0.12% 1 0 2026-06-17T19:17:16.593000 In the Linux kernel, the following vulnerability has been resolved: RDMA/umad:
CVE-2026-50656 7.8 3.39% 1 1 2026-06-17T19:10:40.163000 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect
CVE-2026-48907 9.8 80.42% 2 9 template 2026-06-17T18:36:17 A vulnerability in the JCE editor extension for Joomla allows the creation of ne
CVE-2026-20190 7.5 0.41% 2 0 2026-06-17T18:36:07 A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote
CVE-2026-53876 7.2 1.79% 1 0 2026-06-17T18:35:59 RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vuln
CVE-2026-5667 0 0.15% 1 0 2026-06-17T16:21:32.403000 Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Cond
CVE-2026-20262 6.5 1.37% 2 2 2026-06-17T13:20:04.900000 A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN
CVE-2026-9271 5.9 0.14% 1 0 2026-06-17T11:04:59.717000 Vulnerability Title
CVE-2026-7473 5.8 0.84% 1 1 2026-06-17T11:02:29.070000 On affected platforms running Arista EOS where a tunnel decapsulation configurat
CVE-2026-54420 8.5 1.26% 1 4 2026-06-17T10:58:13.830000 LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn bef
CVE-2026-50751 9.3 71.05% 1 8 template 2026-06-17T10:57:46.373000 A logic flow weakness in Remote Access and Mobile Access certificate validation
CVE-2026-48970 8.1 0.32% 1 0 2026-06-17T10:55:25.967000 Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.
CVE-2026-48558 10.0 0.72% 1 0 2026-06-17T10:55:05.230000 SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an aut
CVE-2026-45504 8.8 0.43% 2 1 2026-06-17T10:52:10.200000 Server-side request forgery (ssrf) in Microsoft Exchange Server allows an author
CVE-2026-20245 7.8 9.92% 5 3 2026-06-17T10:17:19.370000 A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN
CVE-2025-8088 8.8 85.78% 1 31 2026-06-17T10:06:17.243000 A path traversal vulnerability affecting the Windows version of WinRAR allows th
CVE-2026-50874 8.1 1.12% 1 0 2026-06-16T21:33:04 An OS command injection vulnerability in the /manage/features/media component of
CVE-2026-38065 9.8 1.34% 1 0 2026-06-16T21:32:59 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the
CVE-2026-53753 9.8 0.45% 1 0 2026-06-16T20:13:08 ### Summary The `_safe_eval_expression()` function in the computed fields featu
CVE-2026-50871 9.8 1.57% 1 0 2026-06-16T15:33:48 An OS command injection vulnerability in the media archiving and export pipeline
CVE-2026-12219 6.3 1.52% 1 0 2026-06-15T06:31:46 A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is
CVE-2026-12223 5.5 1.53% 1 0 2026-06-15T06:31:41 A vulnerability was identified in Yealink SIP-T46U 108.86.0.118. Affected by thi
CVE-2026-12197 7.2 2.38% 1 0 2026-06-15T00:31:55 A security flaw has been discovered in Ruijie EG105G-P 2.340. The impacted eleme
CVE-2026-10520 10.0 98.94% 1 6 template 2026-06-11T21:31:50 An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6
CVE-2026-34182 9.1 0.24% 1 0 2026-06-10T18:32:45 Issue Summary: Cryptographic Message Services (CMS) processing fails to perform
CVE-2026-25860 6.1 0.29% 1 1 2026-06-10T00:31:50 OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability i
CVE-2026-26980 9.4 70.00% 1 4 template 2026-06-08T23:22:35 ### Impact A SQL injection vulnerability existed in Ghost's Content API that al
CVE-2026-45034 None 0.35% 1 1 2026-06-08T23:00:17 ## Summary CVE-2026-34084 was patched by the helper `File::prohibitWrappers`. T
CVE-2026-8206 9.8 1.26% 1 3 2026-06-02T06:30:33 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordP
CVE-2026-47717 7.5 0.00% 1 0 template 2026-05-27T22:51:19 ### Summary The GET /api/project endpoint exposes sensitive project configurati
CVE-2026-39987 9.8 95.64% 1 12 template 2026-04-27T16:30:09 ## Summary Marimo (19.6k stars) has a Pre-Auth RCE vulnerability. The terminal
CVE-2026-41175 8.1 0.30% 1 0 2026-04-24T20:52:07 ### Impact Manipulating query parameters on Control Panel and REST API endpoint
CVE-2026-4020 7.5 39.70% 3 1 template 2026-03-31T03:31:35 The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exp
CVE-2026-20971 7.8 0.13% 2 0 2026-01-15T21:31:44 Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local atta
CVE-2024-40766 9.3 15.69% 1 0 2025-10-22T00:33:06 An improper access control vulnerability has been identified in the SonicWall So
CVE-2014-9223 None 6.03% 1 0 2025-04-12T12:44:27 Multiple buffer overflows in AllegroSoft RomPager, as used in Huawei Home Gatewa
CVE-2014-9222 None 63.50% 1 2 2025-04-12T12:44:27 AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products a
CVE-2019-1003037 6.5 1.30% 1 0 2023-12-14T18:25:14 An information exposure vulnerability exists in Jenkins Azure VM Agents Plugin 0
CVE-2013-6786 None 2.17% 1 0 2023-01-28T05:02:55 Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as use
CVE-2026-47729 0 0.00% 4 1 N/A
CVE-2026-50000 0 0.00% 1 0 N/A
CVE-2026-8932 0 0.00% 1 0 N/A
CVE-2026-53662 0 0.24% 1 0 N/A
CVE-2026-28496 0 1.89% 1 0 template N/A
CVE-2026-50160 0 0.00% 1 0 N/A
CVE-2026-12958 0 0.14% 1 0 N/A
CVE-2026-12957 0 0.12% 1 0 N/A
CVE-2026-10658 0 0.17% 1 0 N/A
CVE-2026-49287 0 0.27% 1 0 N/A
CVE-2026-9142 0 0.31% 1 0 N/A
CVE-2026-48773 0 0.36% 1 0 N/A
CVE-2025-60467 0 0.00% 2 0 N/A
CVE-2025-60474 0 0.00% 1 0 N/A
CVE-2026-48772 0 0.18% 1 0 N/A
CVE-2025-60473 0 0.00% 1 0 N/A
CVE-2025-60466 0 0.00% 1 0 N/A
CVE-2025-60465 0 0.00% 1 0 N/A
CVE-2025-60464 0 0.00% 1 0 N/A
CVE-2026-49252 0 0.27% 1 0 N/A
CVE-2026-49454 0 0.14% 1 0 N/A
CVE-2026-49257 0 0.50% 1 0 N/A
CVE-2026-55074 0 0.00% 1 0 N/A
CVE-2026-47846 0 0.34% 1 0 N/A

CVE-2025-60471
(5.5 MEDIUM)

EPSS: 0.00%

updated 2026-06-24T21:30:43

2 posts

A use-after-free in the gf_filter_pid_reconfigure_task_discard function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.

sigdevel@infosec.exchange at 2026-06-19T19:39:05.000Z ##

Security Advisory: CVE-2025-60471 - Use-After-Free in GPAC MP4Box PID Reconfiguration

Processing a crafted media file with MP4Box `-info` can trigger a heap use-after-free in `gf_filter_pid_reconfigure_task_discard()`, causing a crash and potential code execution.

Summary:
The `gf_filter_pid_reconfigure_task_discard()` function in `filter_core/filter_pid.c` can access a freed Packet ID (PID) object during filter reconfiguration cleanup. When MP4Box processes a specially crafted file with malformed MPEG-2 TS packet data, broken PMT descriptors, unsupported stream types, and invalid packet structure, the vulnerable path may free a PID instance through `gf_filter_pid_inst_swap()` and later dereference it during reconfiguration task discard.
AddressSanitizer reports a `heap-use-after-free` at `filter_core/filter_pid.c:1346`, with a `READ of size 8` from a freed 336-byte heap region.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filter_core/filter_pid.c:1346
Function: gf_filter_pid_reconfigure_task_discard()
```
Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:

```
GPAC version: 2.5-DEV-rev1570-g6208015df-master
Commit: 6208015dff3a6735a26e413c484c714666eb3ea2
```

Builds before the fix commit `48b0f505679ee41004cb521ac3b76b610650c0cb` should be considered affected if they contain the vulnerable PID reconfiguration cleanup path.

Attack Conditions:
An attacker supplies a crafted media file that is processed by MP4Box through the info/import path. The issue can be reproduced locally with:
```
./MP4Box -info 33_gf_filter_pid_reconfigure_task_discard_filter_core_filter_pid_c_1346
```
No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

The prepared CVSS vector in the local BDU data is:
```
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
```

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is a heap use-after-free, memory corruption and potential arbitrary code execution are possible.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
48b0f505679ee41004cb521ac3b76b610650c0cb
```

Users should update to a GPAC build containing this commit or later. The affected PID reconfiguration path should ensure that PID object lifetime remains valid before discard logic accesses the object.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/48
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

sigdevel@infosec.exchange at 2026-06-19T18:57:48.000Z ##

Security Advisory: CVE-2025-60471 - Use-After-Free in GPAC MP4Box PID Reconfiguration

Processing a crafted MPEG-2 TS file with MP4Box `-info` can trigger a heap use-after-free in `gf_filter_pid_reconfigure_task_discard()`, causing a crash and potential code execution.

Summary:
The `gf_filter_pid_reconfigure_task_discard()` function in `filter_core/filter_pid.c` can access a freed `pid_inst` structure during PID reconfiguration task disposal. When MP4Box processes a specially crafted MPEG-2 Transport Stream file containing broken PMT descriptors, missing packet sync markers, unsupported stream types, and invalid packet data, a PID instance can be freed by `gf_filter_pid_inst_swap_delete()` and later accessed in `gf_filter_pid_reconfigure_task_discard()`.

AddressSanitizer reports a `heap-use-after-free` at `filter_core/filter_pid.c:1341`, with a `READ of size 8` from a freed 336-byte heap region.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filter_core/filter_pid.c:1341
Function: gf_filter_pid_reconfigure_task_discard()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:
```
GPAC version: 2.5-DEV-rev1557-g62714f27c-master
Commit: 62714f27c64a3d1eb7e880f9eed2d38673cb43ce
```

The MITRE response states that GPAC Project/MP4Box before `26.02.0` is affected. Local MITRE data also describes affected GPAC MP4Box 2.4 and earlier, including development branches that contain the vulnerable PID reconfiguration lifecycle handling.
Builds before the fix commit `868c6801c226e9964cace54cfd5a759f152780b4` should be considered affected if they contain the vulnerable path.

Attack Conditions:
An attacker supplies a crafted MPEG-2 TS file with corrupted PMT descriptors and invalid packet data. The issue can be reproduced locally with:
```
./MP4Box -info 31_gf_filter_pid_reconfigure_task_discard_filter_core_filter_pid_c_1341
```

No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is a heap use-after-free, memory corruption and potential arbitrary code execution are possible.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
868c6801c226e9964cace54cfd5a759f152780b4
```
Users should update to a GPAC build containing this commit or later. The affected filter PID reconfiguration path should ensure that PID instance lifetime is valid before task discard logic accesses the object.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/86
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

CVE-2026-48939
(0 None)

EPSS: 0.40%

updated 2026-06-24T19:17:11.143000

1 posts

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

offseq@infosec.exchange at 2026-06-21T01:30:25.000Z ##

CVE-2026-48939 (CRITICAL): iCagenda for Joomla (v1.0.0-3.9.14, 4.0.0-4.0.7) allows unauthenticated PHP file upload & execution. No patch yet — disable or restrict access, use WAF to block. Full site/server compromise risk. Details: radar.offseq.com/threat/cve-20 #OffSeq #Joomla #infosec

##

CVE-2026-48908
(0 None)

EPSS: 0.61%

updated 2026-06-24T19:17:11.037000

1 posts

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

4 repos

https://github.com/ogenich/CVE-2026-48908

https://github.com/gagaltotal/CVE-2026-48908-SP-Page-Builder-Joomla

https://github.com/papageo75/CVE-2026-48908-PoC

https://github.com/webshellseo8/CVE-2026-48908-POC

offseq@infosec.exchange at 2026-06-20T13:30:24.000Z ##

CRITICAL vuln (CVSS 10) in Joomla SP Page Builder (1.0.0 – 6.6.1): CVE-2026-48908 enables unauthenticated PHP uploads, risking full compromise. No patch yet — restrict/disable extension, monitor activity. Details: radar.offseq.com/threat/cve-20 #OffSeq #Joomla #CVE #AppSec

##

CVE-2026-20230
(8.6 HIGH)

EPSS: 25.85%

updated 2026-06-24T18:33:41

4 posts

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this

2 repos

https://github.com/HORKimhab/CVE-2026-20230

https://github.com/HalilDeniz/CVE-2026-20230-Scanner

thenewoil@mastodon.thenewoil.org at 2026-06-24T20:00:03.000Z ##

#Cisco #UnifiedCM flaw CVE-2026-20230 now exploited in attacks

bleepingcomputer.com/news/secu

#cybersecurity

##

thenewoil@mastodon.thenewoil.org at 2026-06-24T20:00:03.000Z ##

#Cisco #UnifiedCM flaw CVE-2026-20230 now exploited in attacks

bleepingcomputer.com/news/secu

#cybersecurity

##

tugatech@masto.pt at 2026-06-24T06:45:50.000Z ##

Falha crítica em servidores da Cisco está a ser ativamente explorada. A vulnerabilidade CVE-2026-20230 afeta o Unified Communications Manager e a Session Management Edition, exigindo ação imediata dos administradores de sistemas em Portugal. ⚠️

🔗 tugatech.com.pt/t86118-falha-c

#falha 

##

oversecurity@mastodon.social at 2026-06-23T22:30:19.000Z ##

Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks

A high-severity SSRF vulnerability, tracked as CVE-2026-20230, in Cisco Unified Communications Manager Server is now being exploited in attacks.

🔗️ [Bleepingcomputer] link.is.it/Y4BXYl

##

CVE-2026-55200
(8.1 HIGH)

EPSS: 0.91%

updated 2026-06-24T17:17:29.693000

5 posts

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.

1 repos

https://github.com/0xBlackash/CVE-2026-55200

xeiaso.net@bsky.brid.gy at 2026-06-24T17:31:32.235Z ##

"No way to prevent this" say users of only language where this regularly happens https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-55200/

"No way to prevent this" say u...

##

cadey@pony.social at 2026-06-24T17:31:32.000Z ##

"No way to prevent this" say users of only language where this regularly happens

xeiaso.net/shitposts/no-way-to

##

bortzmeyer@mastodon.gougere.fr at 2026-06-23T09:21:40.000Z ##

Ah sinon, si vous utilisez du logiciel, vous allez être piraté. Cette fois, c'est SSH (CVE-2026-55200).
cve.org/CVERecord?id=CVE-2026-

##

harrysintonen@infosec.exchange at 2026-06-22T09:58:42.000Z ##

For example it seems Debian stable is currently affected: security-tracker.debian.org/tr

##

beyondmachines1@infosec.exchange at 2026-06-22T09:01:09.000Z ##

libssh2 Vulnerabilities Enable Remote Code Execution and Denial of Service

libssh2 disclosed two vulnerabilities, including a critical out-of-bounds write (CVE-2026-55200) and a high-severity denial of service (CVE-2026-55199), affecting versions up to 1.11.1. These flaws allow malicious servers to execute code on connecting clients or cause resource exhaustion.

**Plan to update libssh2 to a patched build as soon as a fixed release is available. In the meantime audit your tools (curl/libcurl, PHP ssh2 extension, monitoring utilities, IoT firmware) for the vulnerable library versions up to 1.11.1. Only connect to SSH servers you trust and isolate sensitive management interfaces so they're reachable from trusted networks only, since a malicious server can now attack your client.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-10735
(7.5 HIGH)

EPSS: 0.20%

updated 2026-06-24T15:31:43

1 posts

Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 were distributed with malicious code throug

2 repos

https://github.com/HORKimhab/CVE-Wordpress

https://github.com/xxconi/CVE-2026-49777-CVE-2026-10735

offseq@infosec.exchange at 2026-06-24T07:30:26.000Z ##

CVE-2026-10735 (CRITICAL): smart-post-show-pro 4.0.1 for WordPress shipped with malicious code via compromised update server. Unauth attackers can exfiltrate creds & control sites. Remove/disable affected plugin & monitor for IOCs. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #SupplyChain

##

CVE-2026-32174
(7.7 HIGH)

EPSS: 0.37%

updated 2026-06-24T15:19:03.857000

1 posts

Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.

offseq@infosec.exchange at 2026-06-19T04:30:25.000Z ##

CVE-2026-32174: HIGH severity improper authentication in Microsoft Azure AI Bot Service (CVSS 7.7). Privilege escalation possible for authorized users. Microsoft has issued a server-side fix. No active exploits. Details: radar.offseq.com/threat/cve-20 #OffSeq #Azure #Vuln #CloudSec

##

CVE-2026-34908
(10.0 CRITICAL)

EPSS: 2.10%

updated 2026-06-24T14:50:41.720000

5 posts

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

1 repos

https://github.com/BishopFox/CVE-2026-34908-check

offseq@infosec.exchange at 2026-06-24T13:30:30.000Z ##

CRITICAL UniFi OS vulnerabilities (CVE-2026-34908/09/10) allow remote, unauthenticated attackers to bypass auth and execute commands (pre-5.0.8). Exploited in the wild. Patch ASAP: radar.offseq.com/threat/critic #OffSeq #infosec #Ubiquiti #vulnerability

##

beyondmachines1@infosec.exchange at 2026-06-24T13:01:42.000Z ##

CISA Repoers Active Exploitation of Three Critical Ubiquiti UniFi OS Vulnerabilities

CISA added three critical Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910) to its Known Exploited Vulnerabilities Catalog due to active exploitation. These flaws allow unauthenticated attackers to gain full control over network gateways and consoles through command injection and improper access controls.

**Now this advisory is urgent, since the flaws are actively exploited. Make sure all your UniFi devices (UDM, UNVR, UCG gateways, Cloud Keys, etc.) are isolated from the internet and accessible only from trusted networks. Immediately update UniFi OS to the latest patched version for your model (5.1.12+ for most hardware, 5.0.8 for UniFi OS Server, 4.0.14 for Express).**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

AAKL@infosec.exchange at 2026-06-23T19:03:54.000Z ##

CISA has updated the KEV catalogue:

- CVE-2026-34908: Ubiquiti UniFi OS Improper Access Control Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34909: Ubiquiti UniFi OS Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34910: Ubiquiti UniFi OS Improper Input Validation Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2025-67038:
Lantronix EDS5000 Code Injection Vulnerability cve.org/CVERecord?id=CVE-2025- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-06-23T19:00:51.000Z ##

🚨 [CISA-2026:0623] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-67038 (secdb.nttzen.cloud/cve/detail/)
- Name: Lantronix EDS5000 Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Lantronix
- Product: EDS5000
- Notes: ltrxdev.atlassian.net/wiki/spa ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34908 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34909 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34910 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260623 #cisa20260623 #cve_2025_67038 #cve_2026_34908 #cve_2026_34909 #cve_2026_34910 #cve202567038 #cve202634908 #cve202634909 #cve202634910

##

cisakevtracker@mastodon.social at 2026-06-23T18:01:34.000Z ##

CVE ID: CVE-2026-34908
Vendor: Ubiquiti
Product: UniFi OS
Date Added: 2026-06-23
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-34909
(10.0 CRITICAL)

EPSS: 1.82%

updated 2026-06-24T14:49:53.287000

4 posts

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

beyondmachines1@infosec.exchange at 2026-06-24T13:01:42.000Z ##

CISA Repoers Active Exploitation of Three Critical Ubiquiti UniFi OS Vulnerabilities

CISA added three critical Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910) to its Known Exploited Vulnerabilities Catalog due to active exploitation. These flaws allow unauthenticated attackers to gain full control over network gateways and consoles through command injection and improper access controls.

**Now this advisory is urgent, since the flaws are actively exploited. Make sure all your UniFi devices (UDM, UNVR, UCG gateways, Cloud Keys, etc.) are isolated from the internet and accessible only from trusted networks. Immediately update UniFi OS to the latest patched version for your model (5.1.12+ for most hardware, 5.0.8 for UniFi OS Server, 4.0.14 for Express).**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

AAKL@infosec.exchange at 2026-06-23T19:03:54.000Z ##

CISA has updated the KEV catalogue:

- CVE-2026-34908: Ubiquiti UniFi OS Improper Access Control Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34909: Ubiquiti UniFi OS Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34910: Ubiquiti UniFi OS Improper Input Validation Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2025-67038:
Lantronix EDS5000 Code Injection Vulnerability cve.org/CVERecord?id=CVE-2025- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-06-23T19:00:51.000Z ##

🚨 [CISA-2026:0623] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-67038 (secdb.nttzen.cloud/cve/detail/)
- Name: Lantronix EDS5000 Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Lantronix
- Product: EDS5000
- Notes: ltrxdev.atlassian.net/wiki/spa ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34908 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34909 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34910 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260623 #cisa20260623 #cve_2025_67038 #cve_2026_34908 #cve_2026_34909 #cve_2026_34910 #cve202567038 #cve202634908 #cve202634909 #cve202634910

##

cisakevtracker@mastodon.social at 2026-06-23T18:01:17.000Z ##

CVE ID: CVE-2026-34909
Vendor: Ubiquiti
Product: UniFi OS
Date Added: 2026-06-23
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-34910
(10.0 CRITICAL)

EPSS: 81.84%

updated 2026-06-24T14:49:47.237000

4 posts

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

Nuclei template

beyondmachines1@infosec.exchange at 2026-06-24T13:01:42.000Z ##

CISA Repoers Active Exploitation of Three Critical Ubiquiti UniFi OS Vulnerabilities

CISA added three critical Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910) to its Known Exploited Vulnerabilities Catalog due to active exploitation. These flaws allow unauthenticated attackers to gain full control over network gateways and consoles through command injection and improper access controls.

**Now this advisory is urgent, since the flaws are actively exploited. Make sure all your UniFi devices (UDM, UNVR, UCG gateways, Cloud Keys, etc.) are isolated from the internet and accessible only from trusted networks. Immediately update UniFi OS to the latest patched version for your model (5.1.12+ for most hardware, 5.0.8 for UniFi OS Server, 4.0.14 for Express).**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

AAKL@infosec.exchange at 2026-06-23T19:03:54.000Z ##

CISA has updated the KEV catalogue:

- CVE-2026-34908: Ubiquiti UniFi OS Improper Access Control Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34909: Ubiquiti UniFi OS Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34910: Ubiquiti UniFi OS Improper Input Validation Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2025-67038:
Lantronix EDS5000 Code Injection Vulnerability cve.org/CVERecord?id=CVE-2025- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-06-23T19:00:51.000Z ##

🚨 [CISA-2026:0623] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-67038 (secdb.nttzen.cloud/cve/detail/)
- Name: Lantronix EDS5000 Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Lantronix
- Product: EDS5000
- Notes: ltrxdev.atlassian.net/wiki/spa ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34908 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34909 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34910 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260623 #cisa20260623 #cve_2025_67038 #cve_2026_34908 #cve_2026_34909 #cve_2026_34910 #cve202567038 #cve202634908 #cve202634909 #cve202634910

##

cisakevtracker@mastodon.social at 2026-06-23T18:01:01.000Z ##

CVE ID: CVE-2026-34910
Vendor: Ubiquiti
Product: UniFi OS
Date Added: 2026-06-23
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-12850
(9.1 CRITICAL)

EPSS: 1.72%

updated 2026-06-24T14:17:30.287000

1 posts

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various servi

offseq@infosec.exchange at 2026-06-24T12:00:28.000Z ##

CVE-2026-12850: CRITICAL OS command injection in GeoVision GV-I/O Box 4E v2.09 via libNetSetObj.so allows remote code execution. No patch — restrict access to DVRSearch & Network.cgi. Details: radar.offseq.com/threat/cve-20 #OffSeq #ICS #infosec #vulnerability

##

CVE-2026-12417
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-06-24T09:30:46

1 posts

The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_password()` AJAX handler — registered via `wp_ajax_nopriv_pravel_change_password` and therefore accessible to unauthenticated users — performing no nonce verification, no capability

1 repos

https://github.com/Nxploited/CVE-2026-12416-CVE-2026-12417

offseq@infosec.exchange at 2026-06-24T10:30:27.000Z ##

pravel SignUp & SignIn (<=1.0.0) has a CRITICAL flaw (CVE-2026-12417): unauthenticated attackers can reset any WordPress user password, including admins. Remove or disable plugin until patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #CVE202612417

##

CVE-2026-12416
(9.8 CRITICAL)

EPSS: 0.36%

updated 2026-06-24T09:30:46

1 posts

The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invoice_change_password()` function being registered as a nopriv AJAX handler with no nonce verification and no authorization check, and performing a loose equality comparison between the supplied `reset_activation_code` POST parame

1 repos

https://github.com/Nxploited/CVE-2026-12416-CVE-2026-12417

offseq@infosec.exchange at 2026-06-24T09:00:32.000Z ##

CRITICAL (CVSS 9.8): CVE-2026-12416 impacts pravel Invoice Generator ≤1.0.0. Weak password reset lets unauthenticated attackers reset any user’s password, including admins. Restrict access or disable plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE #infosec

##

CVE-2026-12851
(9.1 CRITICAL)

EPSS: 1.68%

updated 2026-06-24T06:31:51

1 posts

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various servi

offseq@infosec.exchange at 2026-06-24T06:00:25.000Z ##

CVE-2026-12851: CRITICAL OS command injection in GeoVision GV-I/O Box 4E v2.09 via DVRSearch/Network.cgi allows remote code execution. Patch status pending — restrict access & monitor endpoints. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity #CVE #Security

##

CVE-2026-47647
(9.9 CRITICAL)

EPSS: 0.44%

updated 2026-06-24T05:17:28.903000

1 posts

Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.

offseq@infosec.exchange at 2026-06-18T23:00:22.000Z ##

CVE-2026-47647 (CRITICAL, CVSS 9.9) affects Microsoft Dynamics 365: improper access control lets authorized users escalate privileges over the network. Fix applied by Microsoft server-side — admins should confirm updates. Details: radar.offseq.com/threat/cve-20 #OffSeq #Microsoft #Infosec #CVE

##

CVE-2026-44914
(7.2 HIGH)

EPSS: 0.39%

updated 2026-06-24T05:17:28.290000

1 posts

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework authorization did not check restricted status when handling requests to replace Process Groups. The missing authorization pe

offseq@infosec.exchange at 2026-06-22T09:00:27.000Z ##

CVE-2026-44914: HIGH severity in Apache NiFi (1.12.0 – 2.9.0). Missing authorization lets users with write access add restricted components. Upgrade to 2.9.0 or enforce specific controls. radar.offseq.com/threat/cve-20 #OffSeq #NiFi #Vuln #Infosec

##

CVE-2025-67038
(9.8 CRITICAL)

EPSS: 1.13%

updated 2026-06-24T05:17:25.670000

8 posts

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

beyondmachines1 at 2026-06-24T20:01:42.398Z ##

CISA Reports Active Exploitation of Lantronix Flaws

CISA flagged an actively exploited critical flaw (CVE-2025-67038) in Lantronix EDS5000 v2.1.0.0R3 devices: an unauthenticated OS command injection in the HTTP RPC module that lets attackers gain root access and fully compromise the equipment.

**Make sure all Lantronix EDS5000 devices are isolated from the internet and accessible only from trusted networks, since this flaw lets attackers gain full root control without any login. Check your inventory for version 2.1.0.0R3, apply the latest firmware update from Lantronix, and because attackers can survive patches by creating rogue admin accounts, audit for unknown accounts and rotate any stored secrets after patching.**

beyondmachines.net/event_detai

##

thecybermind at 2026-06-24T18:30:10.576Z ##

For the Boardroom: A critical unauthenticated code injection flaw (CVE-2025-67038) in Lantronix EDS5000 servers is under active exploitation. Read the full C-SUITE threat advisory on mitigating this operational risk. Ping the word 'ok' mike@thecybermind.co to upgrade your intel. thecybermind.co/jpul

##

Analyst207@mastodon.social at 2026-06-24T18:14:10.000Z ##

CISA Warns of Active Exploitation of Lantronix EDS5000 Flaw

A critical code-injection flaw, CVE-2025-67038, has been discovered in Lantronix EDS5000 Series devices, allowing attackers to inject arbitrary OS commands with root privileges due to a lack of input sanitization in the HTTP RPC module. This vulnerability has a CVSS score of 9.8, indicating a high severity level.

osintsights.com/cisa-warns-of-

#LantronixEds5000 #Cve202567038 #CodeInjection #IotVulnerabilities #EmergingThreats

##

beyondmachines1@infosec.exchange at 2026-06-24T20:01:42.000Z ##

CISA Reports Active Exploitation of Lantronix Flaws

CISA flagged an actively exploited critical flaw (CVE-2025-67038) in Lantronix EDS5000 v2.1.0.0R3 devices: an unauthenticated OS command injection in the HTTP RPC module that lets attackers gain root access and fully compromise the equipment.

**Make sure all Lantronix EDS5000 devices are isolated from the internet and accessible only from trusted networks, since this flaw lets attackers gain full root control without any login. Check your inventory for version 2.1.0.0R3, apply the latest firmware update from Lantronix, and because attackers can survive patches by creating rogue admin accounts, audit for unknown accounts and rotate any stored secrets after patching.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

thecybermind@infosec.exchange at 2026-06-24T18:30:10.000Z ##

For the Boardroom: A critical unauthenticated code injection flaw (CVE-2025-67038) in Lantronix EDS5000 servers is under active exploitation. Read the full C-SUITE threat advisory on mitigating this operational risk. Ping the word 'ok' mike@thecybermind.co to upgrade your intel. thecybermind.co/jpul
#CyberSec #RiskManagement

##

AAKL@infosec.exchange at 2026-06-23T19:03:54.000Z ##

CISA has updated the KEV catalogue:

- CVE-2026-34908: Ubiquiti UniFi OS Improper Access Control Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34909: Ubiquiti UniFi OS Path Traversal Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-34910: Ubiquiti UniFi OS Improper Input Validation Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2025-67038:
Lantronix EDS5000 Code Injection Vulnerability cve.org/CVERecord?id=CVE-2025- #CISA #infosec #vulnerability

##

secdb@infosec.exchange at 2026-06-23T19:00:51.000Z ##

🚨 [CISA-2026:0623] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2025-67038 (secdb.nttzen.cloud/cve/detail/)
- Name: Lantronix EDS5000 Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Lantronix
- Product: EDS5000
- Notes: ltrxdev.atlassian.net/wiki/spa ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34908 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34909 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34910 (secdb.nttzen.cloud/cve/detail/)
- Name: Ubiquiti UniFi OS Improper Input Validation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Ubiquiti
- Product: UniFi OS
- Notes: community.ui.com/releases/Secu ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260623 #cisa20260623 #cve_2025_67038 #cve_2026_34908 #cve_2026_34909 #cve_2026_34910 #cve202567038 #cve202634908 #cve202634909 #cve202634910

##

cisakevtracker@mastodon.social at 2026-06-23T18:00:45.000Z ##

CVE ID: CVE-2025-67038
Vendor: Lantronix
Product: EDS5000
Date Added: 2026-06-23
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-11807
(9.6 CRITICAL)

EPSS: 0.36%

updated 2026-06-24T03:31:40

1 posts

A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send a forged message with an arbitrary activation_id to receive plaintext credentials associated with that activation, including OAuth tokens, vault passwords, and SSH

offseq@infosec.exchange at 2026-06-24T00:00:36.000Z ##

CVE-2026-11807 (CRITICAL, CVSS 9.6) affects Red Hat Ansible Automation Platform 2.5: missing authorization in EDA websocket API lets any authenticated user access plaintext credentials. Patch immediately. radar.offseq.com/threat/cve-20 #OffSeq #RedHat #Ansible #Vuln

##

CVE-2026-54317
(7.6 HIGH)

EPSS: 0.19%

updated 2026-06-23T19:34:58.770000

1 posts

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration registers an HTTP endpoint, KonnectedView (homeassistant/components/konnected/__init__.py), that is marked as not requiring authentication (requires_auth = False). A comment next to that line says auth is instead handled "via the access token from configura

hugovalters@mastodon.social at 2026-06-24T12:14:14.000Z ##

CVE-2026-54317 - Authentication Bypass in Home Assistant. Konnected integration exposes an unauthenticated HTTP endpoint allowing unauthorized write requests. CVSS 7.6. Update to 2026.6.0 immediately. #CVE #HomeAssistant #infosec

valtersit.com/cve/CVE-2026-543

##

CVE-2026-7664
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-06-23T19:17:12.450000

1 posts

IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

offseq@infosec.exchange at 2026-06-22T16:30:14.000Z ##

CVE-2026-7664 (CRITICAL, CVSS 9.8): IBM Langflow OSS 1.0.0 – 1.8.4 has an improper auth flaw in MCP endpoint, allowing unauthenticated access to protected resources. Patch status unknown — monitor IBM advisories. radar.offseq.com/threat/cve-20 #OffSeq #CVE #IBM #infosec

##

CVE-2026-48979
(7.5 HIGH)

EPSS: 0.27%

updated 2026-06-23T16:04:55.583000

1 posts

PHP Standard Library (PSL) is set of APIs covering async, collections, networking, I/O, cryptography, terminal UI, etc. In versions 6.1.0, 6.1.1 and 6.2.0, the Psl\H2\ServerConnection does not validate that the total bytes received in DATA frames match the content-length header declared in the HEADERS frame, allowing request smuggling. This is in violation of RFC 9113 §8.1.1. A malicious client is

hugovalters@mastodon.social at 2026-06-19T12:01:41.000Z ##

CVE-2026-48979 - HTTP/2 request smuggling in PHP standard library (PSL). Unvalidated DATA frame bytes allow content overflow. CVSS 7.5. No patch yet; disable PSL H2 servers or upgrade if fix released. #CVE #PHP #infosec

valtersit.com/cve/CVE-2026-489

##

CVE-2026-12866
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-06-23T15:42:30.483000

1 posts

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code w

offseq@infosec.exchange at 2026-06-23T06:00:27.000Z ##

CVE-2026-12866 | CRITICAL severity in expr-eval (all versions): Arbitrary code execution via toJSFunction() API. No patch yet — avoid untrusted input. Risk: full app compromise. Details: radar.offseq.com/threat/cve-20 #OffSeq #infosec #security #CVE202612866

##

CVE-2026-44727
(0 None)

EPSS: 0.24%

updated 2026-06-23T15:37:54.137000

1 posts

Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their Content-Security-Policy. Combined with nbconvert.HTMLExporter's default non-sanitizing behavior, a notebook carrying an HTML payload in a display_data output triggers stored XSS with

offseq@infosec.exchange at 2026-06-23T00:00:39.000Z ##

CVE-2026-44727: CRITICAL XSS in jupyter_server <2.20. Malicious notebooks can lead to cookie theft & remote code execution due to missing CSP sandboxing. Upgrade to 2.20+ to secure your server. Details: radar.offseq.com/threat/cve-20 #OffSeq #XSS #Jupyter #Security

##

CVE-2026-10521
(7.2 HIGH)

EPSS: 0.31%

updated 2026-06-23T09:32:28

3 posts

An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters. This can result in a total loss of confidentiality, integrity and availability.

offseq@infosec.exchange at 2026-06-23T12:00:37.000Z ##

CVE-2026-10521 (HIGH, CVSS 8.6) in mbCONNECT24: Remote attackers with high privileges can access hidden configs, risking full system compromise. No patch yet — restrict access & monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #ICS #Security

##

certvde@infosec.exchange at 2026-06-23T07:45:42.000Z ##

#OT #Advisory VDE-2026-070
Helmholz: Authenticated unintended access to critical program parameters in myREX24V2/myREX24V2.virtual

There is a vulnerability in myREX24V2/myREX24V2.virtual that allows an authenticated remote attacker to access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters.
#CVE CVE-2026-10521

certvde.com/en/advisories/vde-

#CSAF helmholz.csaf-tp.certvde.com/.

##

certvde@infosec.exchange at 2026-06-23T07:36:27.000Z ##

#OT #Advisory VDE-2026-068
MB connect line: Authenticated unintended access to critical program parameters in mbCONNECT24/mymbCONNECT24

There is a vulnerability in mbCONNECT24/mymbCONNECT24 that allows an authenticated remote attacker to access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters.
#CVE CVE-2026-10521

certvde.com/en/advisories/vde-

#CSAF mbconnectline.csaf-tp.certvde.

##

CVE-2026-11374
(9.0 None)

EPSS: 1.24%

updated 2026-06-23T09:32:28

1 posts

In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.

offseq@infosec.exchange at 2026-06-23T10:30:32.000Z ##

Zoho ManageEngine ADSelfService Plus hit by CRITICAL CVE-2026-11374: predictable SSO tickets enable unauthenticated account takeover. No patch yet — monitor advisories and review exposure. radar.offseq.com/threat/cve-20 #OffSeq #Zoho #Vuln #SSO #Infosec

##

CVE-2026-6645
(0 None)

EPSS: 0.14%

updated 2026-06-23T05:17:05.117000

1 posts

An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system utility using an unqualified file reference. Because the application does not specify an absolute pa

offseq@infosec.exchange at 2026-06-22T04:30:24.000Z ##

CVE-2026-6645 (HIGH, CVSS 7.3) affects PaperCut Print Deploy for Windows. Insecure search path in pc-printer-updater.exe lets local attackers execute malicious code as SYSTEM. Audit directories & monitor for suspicious files. radar.offseq.com/threat/cve-20 #OffSeq #CVE20266645 #infosec

##

CVE-2026-11833(CVSS UNKNOWN)

EPSS: 0.22%

updated 2026-06-23T03:31:48

1 posts

Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing the CI Server setting information. This information could be exploited by an attacker for other attacks. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04 CI Server (All packages) R1.01 to R1.04

offseq@infosec.exchange at 2026-06-23T03:00:29.000Z ##

Yokogawa FAST/TOOLS & CI Server (R9.01 – R10.04, R1.01 – R1.04) affected by HIGH severity CVE-2026-11833 (CVSS 8.2): config data sent in cleartext 🛡️. Limit access, monitor advisories. radar.offseq.com/threat/cve-20 #OffSeq #ICS #Vuln #Cybersecurity

##

CVE-2026-11551
(9.8 CRITICAL)

EPSS: 0.62%

updated 2026-06-23T03:16:40.677000

2 posts

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their ac

3 repos

https://github.com/Polosss/By-Poloss..-..CVE-2026-11551-PoC

https://github.com/ubaydev/CVE-2026-11551-PoC

https://github.com/xxconi/2026-11551

thehackerwire@mastodon.social at 2026-06-20T01:00:21.000Z ##

🔴 CVE-2026-11551 - Critical (9.8)

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This mak...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-06-20T00:00:36.000Z ##

CVE-2026-11551: CRITICAL (CVSS 9.8) privilege escalation in wpmudev Branda ≤3.4.29. Weak password recovery lets unauthenticated attackers reset admin passwords. No patch. Restrict or disable plugin, monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #BlueTeam

##

CVE-2026-8461
(8.8 HIGH)

EPSS: 0.39%

updated 2026-06-22T20:31:03.510000

4 posts

An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in some cases, can be exploited for remote code execution. This vulnerability is associated with the file libavcodec/magicyuv.C. This issue affects FFmpeg before version 8.1.2.

3 repos

https://github.com/HORKimhab/CVE-2026-8461

https://github.com/anyanything/CVE-2026-8461-PoC

https://github.com/Y5neKO/CVE-2026-8461-EXP

undercodenews@mastodon.social at 2026-06-24T18:16:38.000Z ##

PixelSmash CVE-2026-8461: The Tiny Video File Flaw That Could Give Attackers Control Over FFmpeg Systems + Video

Introduction: When a Simple Video Preview Becomes a Security Threat Modern technology depends heavily on invisible software layers that most users never notice. Every time a computer creates a video thumbnail, a media server organizes a library, or an artificial intelligence system analyzes a clip, powerful multimedia engines are working silently in the…

undercodenews.com/pixelsmash-c

##

beyondmachines1@infosec.exchange at 2026-06-23T10:01:04.000Z ##

PixelSmash Vulnerability in FFmpeg Enables Remote Code Execution

FFmpeg version 8.1.2 patches a high-severity heap overflow (CVE-2026-8461) in the MagicYUV decoder that allows attackers to execute arbitrary code via malicious video files. The flaw impacts a wide range of media applications, including Jellyfin and Nextcloud.

**Update FFmpeg to version 8.1.2 or later immediately to close the PixelSmash flaw (CVE-2026-8461), and update any apps that bundle it like Jellyfin, Nextcloud, Kodi, or OBS. If you can't update right away, restrict file uploads to trusted users only and isolate any servers that automatically scan or process media files.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

tugatech@masto.pt at 2026-06-23T07:23:13.000Z ##

Foi descoberta uma vulnerabilidade crítica na biblioteca FFmpeg, denominada PixelSmash, que pode permitir a execução remota de código em servidores Jellyfin e causar a negação de serviço em plataformas como Kodi. A falha, identificada como CVE-2026-8461, recebeu uma pontuação de gravidade significativa. 💻

🔗 tugatech.com.pt/t86024-ffmpeg-

#kodi #vulnerabilidade 

##

offseq@infosec.exchange at 2026-06-22T22:30:13.000Z ##

FFmpeg MagicYUV decoder CRITICAL heap out-of-bounds bug (CVE-2026-8461): AVI/MKV/MOV files can trigger DoS or RCE in apps like Jellyfin, Nextcloud. Patch to 8.1.2 ASAP. radar.offseq.com/threat/ffmpeg #OffSeq #FFmpeg #CVE20268461 #infosec

##

CVE-2026-12044
(8.8 HIGH)

EPSS: 0.51%

updated 2026-06-22T20:23:26.770000

1 posts

SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-supplied description field. The Jinja templates for Domains (and their constraints), Foreign Tables, Languages, and Event Triggers, plus the Views OID-lookup query, interpolated the description directly inside a single-quoted SQL literal -- ``'{{ data.description }}'`` -- instead o

thehackerwire@mastodon.social at 2026-06-19T05:00:44.000Z ##

🟠 CVE-2026-12044 - High (8.8)

SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS ''`` for a user-supplied description field. The Jinja templates for Domains (and their constraints), Foreign Tables, Languages, and Event Triggers, plus the V...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11717
(0 None)

EPSS: 0.19%

updated 2026-06-22T20:18:53.300000

1 posts

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When verifying an unparsed opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), the toolbox decodes the response into an introspectResp struct where the Active field is declared as a pointer to a boolean (*bool). The code only explicitly rejects a

offseq@infosec.exchange at 2026-06-18T15:30:20.000Z ##

CVE-2026-11717: CRITICAL vuln in googleapis/mcp-toolbox v1.0.0. Improper auth check lets tokens without 'active' field bypass controls — unauthorized access risk. Patch unconfirmed, monitor advisories: radar.offseq.com/threat/cve-20 #OffSeq #CVE202611717 #OAuth2 #CloudSecurity

##

CVE-2026-12581
(7.5 HIGH)

EPSS: 0.30%

updated 2026-06-22T20:17:59.447000

1 posts

EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in.

offseq@infosec.exchange at 2026-06-22T12:00:27.000Z ##

CVE-2026-12581 (HIGH): Digiwin EasyFlow .NET is exposed to session fixation — attackers can hijack user sessions after login. No patch yet; apply session controls & monitor activity. Details: radar.offseq.com/threat/cve-20 #OffSeq #vulnerability #infosec #security

##

CVE-2026-54414
(9.8 CRITICAL)

EPSS: 0.72%

updated 2026-06-22T20:17:59.447000

1 posts

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by FolderController with basename() and REGEX_FILE_NAME, which permit URL-encoded sequences (the regex blocks / and \ but not %). The raw filename is then passed to Up

offseq@infosec.exchange at 2026-06-19T07:30:27.000Z ##

CVE-2026-54414: Critical path traversal in FileRise <3.16.0 allows attackers with a valid shared-folder upload link to write files outside the intended dir — can lead to admin takeover & RCE. Patch to 3.16.0+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #vuln #FileRise

##

CVE-2026-55199
(5.9 MEDIUM)

EPSS: 0.37%

updated 2026-06-22T18:43:49.900000

1 posts

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop f

beyondmachines1@infosec.exchange at 2026-06-22T09:01:09.000Z ##

libssh2 Vulnerabilities Enable Remote Code Execution and Denial of Service

libssh2 disclosed two vulnerabilities, including a critical out-of-bounds write (CVE-2026-55200) and a high-severity denial of service (CVE-2026-55199), affecting versions up to 1.11.1. These flaws allow malicious servers to execute code on connecting clients or cause resource exhaustion.

**Plan to update libssh2 to a patched build as soon as a fixed release is available. In the meantime audit your tools (curl/libcurl, PHP ssh2 extension, monitoring utilities, IoT firmware) for the vulnerable library versions up to 1.11.1. Only connect to SSH servers you trust and isolate sensitive management interfaces so they're reachable from trusted networks only, since a malicious server can now attack your client.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-56382
(7.2 HIGH)

EPSS: 0.49%

updated 2026-06-22T18:40:05.833000

1 posts

Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability in the FieldsController::actionRenderCardPreview() method, which passes the fieldLayoutConfig POST parameter directly to Fields::createLayout() without calling Component::cleanseConfig(). An authenticated admin user can inject Yii2 event handlers (e.g., 'on init' keys) via the fi

offseq@infosec.exchange at 2026-06-22T03:00:24.000Z ##

CVE-2026-56382: HIGH severity RCE in Craft CMS (5.5.0 – 5.9.13). Authenticated admins can inject code via FieldsController, leaking sensitive env vars. Patch now by upgrading to 5.9.14+. radar.offseq.com/threat/cve-20 #OffSeq #CraftCMS #RCE #Vuln

##

CVE-2026-8157
(8.8 HIGH)

EPSS: 0.24%

updated 2026-06-22T18:38:02.507000

1 posts

The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a custom Vitepos WordPress plugin before 3.4.2 role to escalate privileges to administrator.

offseq@infosec.exchange at 2026-06-22T07:30:32.000Z ##

Vitepos WordPress plugin <3.4.2 has a HIGH severity privilege escalation vuln (CVE-2026-8157). Auth users with custom Vitepos roles can become admins via REST API. Restrict API access & monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE20268157 #Infosec

##

CVE-2026-10789
(9.6 CRITICAL)

EPSS: 0.29%

updated 2026-06-22T18:34:24

1 posts

A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user.

offseq@infosec.exchange at 2026-06-22T18:00:12.000Z ##

CVE-2026-10789: CRITICAL code injection in Autodesk Fusion MCP ext (v2703.1.11). Visiting a crafted page can lead to arbitrary code execution with user rights. Update guidance pending. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Autodesk #CVE2026_10789

##

CVE-2026-56448
(0 None)

EPSS: 0.29%

updated 2026-06-22T18:16:50.207000

1 posts

A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticated AIL user can supply crafted object identifiers through the investigation workflow to cause file paths to resolve outside the intended image, favicon, or screenshot storage directories. This may allow the attacker to download and read arbitrary files

offseq@infosec.exchange at 2026-06-22T13:30:29.000Z ##

CVE-2026-56448 (HIGH, CVSS 8.3) in ail framework v0: Authenticated users can exploit path traversal to access files beyond intended dirs. Restrict permissions & monitor file access until patch is released. radar.offseq.com/threat/cve-20 #OffSeq #CyberSecurity #Vuln #PathTraversal

##

CVE-2026-41950
(6.5 MEDIUM)

EPSS: 0.33%

updated 2026-06-22T18:16:37.293000

2 posts

Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same tenant by supplying an arbitrary file UUID in the files array of a chat-messages request. Attackers can exploit insufficient permission verification in the chat-messages endpoints to access files without ownership valid

threatnoir at 2026-06-24T21:05:19.890Z ##

⚠️ CRITICAL: Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

Four critical vulnerabilities in Dify AI platform (CVE-2026-41947, CVE-2026-41948, CVE-2026-41950) enable unauthorized access to private chats, cross-tenant document theft, and lateral API calls across multi-tenant environments. The platform powers 1 million applications, making this a widespread s…

threatnoir.com/focus

##

threatnoir@infosec.exchange at 2026-06-24T21:05:19.000Z ##

⚠️ CRITICAL: Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

Four critical vulnerabilities in Dify AI platform (CVE-2026-41947, CVE-2026-41948, CVE-2026-41950) enable unauthorized access to private chats, cross-tenant document theft, and lateral API calls across multi-tenant environments. The platform powers 1 million applications, making this a widespread s…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-41948
(9.4 CRITICAL)

EPSS: 0.51%

updated 2026-06-22T18:16:37.033000

2 posts

Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant path using unencoded dot sequences in task identifiers or manipulated filename parameters to access internal endpoints su

threatnoir at 2026-06-24T21:05:19.890Z ##

⚠️ CRITICAL: Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

Four critical vulnerabilities in Dify AI platform (CVE-2026-41947, CVE-2026-41948, CVE-2026-41950) enable unauthorized access to private chats, cross-tenant document theft, and lateral API calls across multi-tenant environments. The platform powers 1 million applications, making this a widespread s…

threatnoir.com/focus

##

threatnoir@infosec.exchange at 2026-06-24T21:05:19.000Z ##

⚠️ CRITICAL: Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

Four critical vulnerabilities in Dify AI platform (CVE-2026-41947, CVE-2026-41948, CVE-2026-41950) enable unauthorized access to private chats, cross-tenant document theft, and lateral API calls across multi-tenant environments. The platform powers 1 million applications, making this a widespread s…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-41947
(9.1 CRITICAL)

EPSS: 0.45%

updated 2026-06-22T18:16:36.883000

2 posts

Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant ownership. Attackers can exploit missing tenant ownership checks in the trace configuration endpoints to redirect all messages and responses from victim applications to attacker-controlled LLM trace provider

threatnoir at 2026-06-24T21:05:19.890Z ##

⚠️ CRITICAL: Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

Four critical vulnerabilities in Dify AI platform (CVE-2026-41947, CVE-2026-41948, CVE-2026-41950) enable unauthorized access to private chats, cross-tenant document theft, and lateral API calls across multi-tenant environments. The platform powers 1 million applications, making this a widespread s…

threatnoir.com/focus

##

threatnoir@infosec.exchange at 2026-06-24T21:05:19.000Z ##

⚠️ CRITICAL: Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

Four critical vulnerabilities in Dify AI platform (CVE-2026-41947, CVE-2026-41948, CVE-2026-41950) enable unauthorized access to private chats, cross-tenant document theft, and lateral API calls across multi-tenant environments. The platform powers 1 million applications, making this a widespread s…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-9843
(8.1 HIGH)

EPSS: 0.66%

updated 2026-06-22T16:43:14.450000

1 posts

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is dele

offseq@infosec.exchange at 2026-06-20T09:00:28.000Z ##

CVE-2026-9843: HIGH severity (CVSS 8.1) path traversal in crmperks Database for Contact Form 7, WPforms, Elementor forms (≤1.5.1). Unauthenticated file deletion possible if admin interacts with malicious entries. Restrict access, monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE20269843 #BlueTeam

##

CVE-2026-10561
(10.0 CRITICAL)

EPSS: 0.53%

updated 2026-06-22T15:30:52

1 posts

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise

offseq@infosec.exchange at 2026-06-22T15:00:13.000Z ##

IBM Langflow OSS v1.0.0 – 1.9.3 hit by CRITICAL code injection (CVE-2026-10561, CVSS 10). Auth bypass enables unauth'd RCE & total compromise. No patch yet — track IBM advisories for updates. radar.offseq.com/threat/cve-20 #OffSeq #Infosec #CVE202610561

##

CVE-2026-7166(CVSS UNKNOWN)

EPSS: 0.38%

updated 2026-06-22T15:30:46

1 posts

Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and phone number data from the ‘email’ and ‘telefon’ fields. This vulnerability is also present in the local database, as it contains accessible sensitive information such as data on minors and municipal users. Successful exploitation of this vulnerability could allow an unauthenticat

offseq@infosec.exchange at 2026-06-22T19:30:11.000Z ##

Gaudire Assassin game hit by CRITICAL vuln (CVE-2026-7166, CVSS 9.2): API & DB leak emails, phone numbers, and sensitive user info (including minors). No auth needed. Restrict access & monitor for fixes. radar.offseq.com/threat/cve-20 #OffSeq #CVE20267166 #infosec #dataleak

##

CVE-2026-20181
(9.1 CRITICAL)

EPSS: 0.75%

updated 2026-06-22T14:31:46.277000

2 posts

A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a

AAKL@infosec.exchange at 2026-06-19T17:19:43.000Z ##

New advisory.

This relates to critical CVE-2026-20181 and CVE-2026-20190 vulnerabilities, published on the 17th.

Cisco: CRITICAL: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

@cR0w

##

beyondmachines1@infosec.exchange at 2026-06-19T09:01:22.000Z ##

Cisco Patches Critical Root RCE and Credential Theft Flaws in ISE

Cisco patched a critical root RCE vulnerability (CVE-2026-20181) and a high-severity information disclosure flaw (CVE-2026-20190) in its Identity Services Engine. These vulnerabilities allow authenticated root access or theft of hashed credentials.

**Make sure your Cisco ISE and ISE-PIC systems are isolated from the internet and reachable only from trusted management networks. Apply the latest patches immediately (ISE 3.3 Patch 11, 3.4 Patch 6, or 3.5 Patch 3) and for the 3.5 command-execution fix, request the hotfix from Cisco TAC now. Don't wait for Patch 4 in August 2026.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-54104
(8.8 HIGH)

EPSS: 0.40%

updated 2026-06-22T14:17:41.693000

2 posts

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own privileges.

CVE-2026-12806
(8.8 HIGH)

EPSS: 0.46%

updated 2026-06-21T21:31:04

1 posts

A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component POST Request Handler. The manipulation of the argument selSSID leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early ab

offseq@infosec.exchange at 2026-06-22T00:00:37.000Z ##

CVE-2026-12806: HIGH severity buffer overflow in Edimax BR-6478AC V2 (fw 1.23). Remote exploitation possible, no patch available. Limit access & watch for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #RouterSecurity #Infosec

##

CVE-2026-56394
(6.5 MEDIUM)

EPSS: 0.34%

updated 2026-06-21T15:31:31

1 posts

Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can bypass extension validation by passing traversal sequences that resolve to existing SVG files, allowing local file read access.

offseq@infosec.exchange at 2026-06-22T01:30:27.000Z ##

CVE-2026-56394: HIGH severity path traversal in Craft CMS 4.0.0-RC1 & 5.0.0-RC1. Authenticated attackers can read local files via assets/icon endpoint. Restrict access & monitor activity. No patch yet. radar.offseq.com/threat/cve-20 #OffSeq #CraftCMS #Vuln #PathTraversal

##

CVE-2026-56265
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-06-21T15:31:31

1 posts

Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentication tokens for any user, bypassing authentication and gaining full access to protected functionality.

CVE-2026-12786
(7.8 HIGH)

EPSS: 0.11%

updated 2026-06-21T09:30:57

1 posts

A vulnerability has been found in Ezbsystems UltraISO Premium Edition up to 9.76. Affected by this issue is some unknown functionality in the library bootpt64.sys of the component Kernel Driver. The manipulation leads to improper access controls. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this

offseq@infosec.exchange at 2026-06-21T09:00:26.000Z ##

UltraISO Premium Edition ≤9.76 hit by HIGH severity vuln (CVE-2026-12786) in bootpt64.sys — local attackers can bypass kernel access controls. No patch yet. Restrict local access & monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #InfoSec #UltraISO

##

CVE-2026-12784
(7.8 HIGH)

EPSS: 0.11%

updated 2026-06-21T09:30:51

1 posts

A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the library MDA_NTDRV.sys of the component Kernel Driver. This manipulation causes improper access controls. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not r

offseq@infosec.exchange at 2026-06-21T07:30:25.000Z ##

CVE-2026-12784 | HIGH severity in IM-Magic Partition Resizer ≤7.9.0: improper access controls in MDA_NTDRV.sys kernel driver. Local exploit is public. Restrict access or remove vulnerable versions. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #SysSec #CVE2026

##

CVE-2026-12781
(7.8 HIGH)

EPSS: 0.11%

updated 2026-06-21T09:30:50

1 posts

A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unknown function in the library epmntdrv.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit is publicly available and might be used. You should upgrade the affected component. The vendor explains: "We have confir

offseq@infosec.exchange at 2026-06-21T12:00:24.000Z ##

CVE-2026-12781 (HIGH, CVSS 8.5) found in EaseUS Partition Master 14.0 – 14.5: improper access controls in kernel driver epmntdrv.sys enable local privilege escalation. Upgrade to latest version ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #PrivilegeEscalation #CyberSecurity

##

CVE-2026-12782
(7.8 HIGH)

EPSS: 0.11%

updated 2026-06-21T09:30:50

1 posts

A security flaw has been discovered in EaseUS Partition Master up to 14.5. The impacted element is an unknown function in the library EUEDKEPM.sys of the component Kernel Driver. The manipulation results in improper access controls. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The affected component should be upgraded. The vendor ex

offseq@infosec.exchange at 2026-06-21T10:30:25.000Z ##

CVE-2026-12782: HIGH severity vuln in EaseUS Partition Master (14.0 – 14.5). Improper access in kernel driver (EUEDKEPM.sys), local attack, public exploit out. Upgrade ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #InfoSec #CVE202612782

##

CVE-2026-56099
(5.3 MEDIUM)

EPSS: 0.36%

updated 2026-06-21T09:30:50

1 posts

OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function within sys/netmpls/mpls_input.c that allows remote attackers to disclose kernel stack memory by sending crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set.

CVE-2025-20701
(8.8 HIGH)

EPSS: 4.19%

updated 2026-06-21T09:30:49

1 posts

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

beyondmachines1@infosec.exchange at 2026-06-20T11:01:35.000Z ##

Apple Patches Beats Studio Buds Eavesdropping Flaw

Apple patched a high-severity flaw (CVE-2025-20701) in Beats Studio Buds that allowed nearby attackers to eavesdrop via the microphone.

**Update your Beats Studio Buds firmware immediately to version 1B211 to prevent unauthorized microphone access.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-12779
(7.8 HIGH)

EPSS: 0.11%

updated 2026-06-21T06:32:15

1 posts

A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unknown processing in the library ddmdrv.sys of the component Kernel Driver. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did

offseq@infosec.exchange at 2026-06-21T13:30:27.000Z ##

AOMEI Dynamic Disk Manager ≤10.10.1: CVE-2026-12779 (HIGH, CVSS 8.5) allows local privilege abuse via improper access controls in ddmdrv.sys. Exploit is public, no patch available. Restrict access & monitor systems. radar.offseq.com/threat/cve-20 #OffSeq #CVE202612779 #vuln #cybersecurity

##

CVE-2026-12780
(7.8 HIGH)

EPSS: 0.11%

updated 2026-06-21T06:32:14

1 posts

A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.sys of the component Kernel Driver. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any

offseq@infosec.exchange at 2026-06-21T06:00:24.000Z ##

CVE-2026-12780: HIGH severity vuln in AOMEI Backupper ≤8.3.0. Local attackers can abuse improper access controls in amwrtdrv.sys for potential privilege escalation. No patch available — limit local access & watch for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #AOMEI

##

CVE-2026-12774
(6.3 MEDIUM)

EPSS: 0.21%

updated 2026-06-21T06:32:14

1 posts

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client of the file litellm/proxy/_experimental/mcp_server/rest_endpoints.py of the component MCP Server Connection Testing. The manipulation leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed pu

offseq@infosec.exchange at 2026-06-21T04:30:23.000Z ##

CVE-2026-12774: SSRF in BerriAI litellm v1.82.0 – 1.82.2 (MEDIUM, CVSS 5.3). Remote attackers can manipulate server requests via _execute_with_mcp_client. No patch yet — monitor vendor advisories. radar.offseq.com/threat/cve-20 #OffSeq #Infosec #SSRF #Vuln

##

CVE-2026-5366
(9.9 CRITICAL)

EPSS: 0.57%

updated 2026-06-20T18:31:35

1 posts

Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage class. The `commit_sha` parameter, which is passed to git commands, lacks validation and does not include a `--` separator to distinguish user input from git flags. This allows attackers to inject arbitrary git flags, such as `--upload-pack`, enabling execu

offseq@infosec.exchange at 2026-06-21T00:00:35.000Z ##

CVE-2026-5366 (CRITICAL, CVSS 9.9): prefecthq/prefect 3.6.23 lets users with deployment creation rights inject git flags via commit_sha/directories in GitRepository, enabling remote code exec. Restrict permissions & monitor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE20265366 #infosec

##

CVE-2022-50972
(9.8 CRITICAL)

EPSS: 0.63%

updated 2026-06-20T15:32:32

1 posts

WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send requests to the class-wc-meta-box-product-images.php endpoint with unsanitized product-type values to write malicious PHP files to the web root.

wpguyuk@infosec.exchange at 2026-06-23T07:04:29.000Z ##

If your WooCommerce store is running below version 7.1.0, I'd update it today. CVE-2022-50972 carries a CVSS score of 9.8 out of 10 — meaning an attacker can gain full admin control, access every customer record, and wipe your database entirely. No patch exists for older versions. Updating is the only viable option right now.

#WordPress #WooCommerce #SecurityHardening #CVE #WordPressSecurity

wpguy.uk/blog/critical-vulnera

##

CVE-2026-48909(CVSS UNKNOWN)

EPSS: 0.80%

updated 2026-06-20T15:32:23

1 posts

SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server.

1 repos

https://github.com/Is4yev/CVE-2026-48909

offseq@infosec.exchange at 2026-06-21T03:00:23.000Z ##

JoomShaper SP LMS for Joomla (v1.0.0 – 4.1.3) hit by CRITICAL vuln (CVE-2026-48909): unsafe cookie deserialization enables unauth RCE. No patch yet — restrict access & monitor traffic. Details: radar.offseq.com/threat/cve-20 #OffSeq #Joomla #CVE #infosec

##

CVE-2026-11912
(7.5 HIGH)

EPSS: 0.43%

updated 2026-06-20T09:33:32

1 posts

The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete and modify files on the serve. This vulnerability is exploitable even when the administrator has not enabled the AllowFrontManage setting, because the is_admin() ch

1 repos

https://github.com/Polosss/By-Poloss..-..CVE-2026-11912

offseq@infosec.exchange at 2026-06-20T12:00:26.000Z ##

CVE-2026-11912: HIGH severity vulnerability in eemitch Simple File List ≤6.3.7 lets unauthenticated attackers modify/delete server files due to missing auth checks. No patch yet — restrict or disable plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #vuln

##

CVE-2026-11911
(7.5 HIGH)

EPSS: 0.78%

updated 2026-06-20T09:33:32

1 posts

The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the eeSFL_DeleteFile function in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). T

offseq@infosec.exchange at 2026-06-20T10:30:26.000Z ##

CVE-2026-11911: HIGH severity path traversal in eemitch Simple File List (≤6.3.7). Unauth attackers can delete files via exposed AJAX action, risking RCE. Restrict admin-ajax.php or disable plugin. Details: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Security

##

CVE-2026-56082
(7.5 HIGH)

EPSS: 0.24%

updated 2026-06-20T00:34:15

1 posts

Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record_build_time, which is granted to the anon role and callable with only the public Supabase publishable (sb_publishable_*) anon key. An unauthenticated attacker can insert rows into public.build_logs for arbitrary organizations and, because the function u

thehackerwire@mastodon.social at 2026-06-20T01:00:41.000Z ##

🟠 CVE-2026-56082 - High (7.5)

Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record_build_time, which is granted to the anon role and callable with only the public Supabase publishabl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56081
(9.1 CRITICAL)

EPSS: 0.35%

updated 2026-06-20T00:34:14

2 posts

Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that email is verified. By enabling two-factor authentication on the pre-registered account, the attacker gains control over the account claimed under the victim's identity, allowing them to read and modify its state and enforce organization-le

offseq@infosec.exchange at 2026-06-20T01:30:26.000Z ##

CRITICAL: Cap-go capgo (<12.128.2) hit by CVE-2026-56081. Attackers can register with victim emails pre-verification, enable 2FA, and fully take over accounts — including org policy control. No patch confirmed. Monitor new signups. radar.offseq.com/threat/cve-20 #OffSeq #CVE202656081 #Infosec

##

thehackerwire@mastodon.social at 2026-06-20T01:00:31.000Z ##

🔴 CVE-2026-56081 - Critical (9.1)

Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that email is verified. By enabling two-factor authentication on the pre-registered account...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56073
(9.4 CRITICAL)

EPSS: 0.19%

updated 2026-06-20T00:34:08

1 posts

Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modifying server responses. Attackers can intercept OTP verification requests and manipulate HTTP responses to falsely mark verification successful, enabling unauthorized 2FA enablement and account takeover.

offseq@infosec.exchange at 2026-06-20T03:00:25.000Z ##

CVE-2026-56073 (CRITICAL) affects Cap-go capgo <12.128.2: Insufficient data authenticity checks allow OTP bypass, enabling attackers to activate 2FA & take over accounts. No patch yet — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec #AppSec

##

CVE-2026-42824
(6.5 MEDIUM)

EPSS: 7.64%

updated 2026-06-19T21:16:42.893000

1 posts

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

hackmag@infosec.exchange at 2026-06-18T18:00:03.000Z ##

⚪️ Critical Copilot bug allowed theft of two-factor authentication codes

🗨️ In early June, Microsoft engineers announced that they had fixed a critical vulnerability, CVE-2026-42824. Now specialists from Varonis have revealed the details of this issue and described an attack that has been dubbed SearchLeak. As it turned out, the vulnerability…

🔗 hackmag.com/news/searchleak?ut

#news

##

CVE-2026-50195(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-06-19T19:35:24

1 posts

## Impact containerd's CRI checkpoint import process contains a vulnerability where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions to create pods can use a crafted checkpoint image to force containerd to pull a malicious image and assign it an arbitrary local tag, thereby poisoning the node's local image cache. Subsequent

canartuc@mastodon.social at 2026-06-19T09:11:45.000Z ##

containerd released 2.3.2, 2.2.5, 2.1.9, 2.0.10 and 1.7.33 on June 18, fixing five CVEs in the CRI plugin that AWS reported. CVE-2026-50195 lets a poisoned checkpoint import swap an image reference; companion flaws cover CDI annotation smuggling and host-root command execution during restore and image pulls. If you run Kubernetes on containerd, which of these branches do you still ship?

#containers #kubernetes

##

CVE-2026-8713
(9.1 CRITICAL)

EPSS: 1.19%

updated 2026-06-19T06:32:02

1 posts

The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all versions up to, and including, 3.15.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-confi

offseq@infosec.exchange at 2026-06-19T10:30:27.000Z ##

CVE-2026-8713: CRITICAL path traversal (CVSS 9.1) in Avada (Fusion) Builder ≤3.15.3. Unauthenticated file deletion possible; RCE risk if wp-config.php is removed. Restrict access, monitor usage, check vendor for fixes. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec

##

CVE-2026-7515
(9.8 CRITICAL)

EPSS: 0.89%

updated 2026-06-19T06:32:02

1 posts

The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code e

2 repos

https://github.com/Polosss/By-Poloss..-..CVE-2026-7515-PoC

https://github.com/izxci/CVE_2026_7515

offseq@infosec.exchange at 2026-06-19T09:00:28.000Z ##

CVE-2026-7515 | CRITICAL LFI in BetterDocs Pro ≤3.8.0: Unauthenticated attackers can execute arbitrary PHP via doc_style, risking full server compromise. Patch status unknown — check vendor. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vulnerability #CVE20267515

##

CVE-2026-40624
(9.8 CRITICAL)

EPSS: 0.62%

updated 2026-06-19T00:31:46

1 posts

Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated attacker to achieve arbitrary code execution via a specially crafted web request.

thehackerwire@mastodon.social at 2026-06-19T05:00:30.000Z ##

🔴 CVE-2026-40624 - Critical (9.8)

Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+
cameras may allow a remote, unauthenticated attacker to achieve
arbitrary code execution via a specially crafted web request.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12048
(9.3 CRITICAL)

EPSS: 0.31%

updated 2026-06-19T00:31:46

1 posts

Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relation-does-not-exist errors and inside EXPLAIN Recheck Cond / Exact Heap Blocks fields) was passed verbatim through html-react-parser at every user-facing sink — the notifier toasts, FormFooterMessage /

thehackerwire@mastodon.social at 2026-06-19T05:00:19.000Z ##

🔴 CVE-2026-12048 - Critical (9.3)

Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relation-does-not-exist errors and inside EXPLAIN Rec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47633
(7.5 HIGH)

EPSS: 0.58%

updated 2026-06-19T00:31:41

1 posts

Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network.

offseq@infosec.exchange at 2026-06-19T06:00:39.000Z ##

Microsoft Cost Management is affected by CVE-2026-47633 (HIGH, CVSS 7.5) — remote attackers can access sensitive info with no auth or user interaction. Patch available: radar.offseq.com/threat/cve-20 #OffSeq #Microsoft #CVE #BlueTeam

##

CVE-2026-54130
(9.8 CRITICAL)

EPSS: 0.50%

updated 2026-06-19T00:31:41

1 posts

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

offseq@infosec.exchange at 2026-06-19T00:00:37.000Z ##

Microsoft 365 Copilot hit by CVE-2026-54130 (CRITICAL, CVSS 9.8): Missing authentication lets attackers disclose info over the network. Official fix deployed — verify your cloud service is updated. 📢 radar.offseq.com/threat/cve-20 #OffSeq #Microsoft365 #CVE #CloudSecurity

##

CVE-2026-11409
(7.2 HIGH)

EPSS: 2.79%

updated 2026-06-18T21:33:34

1 posts

An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-11410
(7.2 HIGH)

EPSS: 2.79%

updated 2026-06-18T21:33:34

1 posts

An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-55203
(7.5 HIGH)

EPSS: 0.29%

updated 2026-06-18T18:35:31

1 posts

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potential

cR0w@infosec.exchange at 2026-06-18T19:42:03.000Z ##

:blobcat_thisisfine:

nvd.nist.gov/vuln/detail/CVE-2

sev:CRIT 9.0 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.

##

CVE-2026-54103
(9.8 CRITICAL)

EPSS: 0.43%

updated 2026-06-18T18:35:31

3 posts

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the '/update-profile/N' API endpoint. A remote, unauthenticated attacker could change an arbitrary user's password.

cR0w@infosec.exchange at 2026-06-18T19:39:54.000Z ##

lol. lmao.

nvd.nist.gov/vuln/detail/CVE-2

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the '/update-profile/N' API endpoint. A remote, unauthenticated attacker could change an arbitrary user's password.

##

nyanbinary@infosec.exchange at 2026-06-18T17:43:30.000Z ##

db.gcve.eu/vuln/cve-2026-54103
db.gcve.eu/vuln/cve-2026-54104

:blobcatthinkingglare:

##

offseq@infosec.exchange at 2026-06-18T17:00:11.000Z ##

CVE-2026-54103 (CRITICAL, CVSS 9.8): GAO EPDS & CBCA EDS lack authentication on password change API, enabling remote takeover. No patch yet. Restrict access, monitor logs. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CVE202654103 #GovSec

##

CVE-2026-54390
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-06-18T18:35:31

1 posts

JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicious template syntax due to unsanitized user-supplied input passed to the Smarty template engine. Attackers can exploit this flaw to read sensitive server-side values such as database credentials and encryption keys, and on versions 5.4.0 through 5.7.1,

offseq@infosec.exchange at 2026-06-18T18:30:13.000Z ##

CRITICAL: CVE-2026-54390 in JTL Shop (5.2.0 – 5.7.1) enables unauthenticated template injection. Attackers can extract secrets; RCE possible in 5.4.0+. No patch yet — restrict access & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #CVE202654390 #infosec #websecurity

##

CVE-2026-20253
(9.8 CRITICAL)

EPSS: 92.10%

updated 2026-06-18T18:35:18

11 posts

In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.<br><br>The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file

Nuclei template

3 repos

https://github.com/0xBlackash/CVE-2026-20253

https://github.com/watchtowrlabs/watchTowr-vs-Splunk-CVE-2026-20253

https://github.com/HORKimhab/CVE-2026-20253

threatnoir@infosec.exchange at 2026-06-20T19:05:21.000Z ##

⚠️ CRITICAL: CISA: Splunk Enterprise flaw actively exploited, patch by Sunday

CVE-2026-20253 in Splunk Enterprise is actively exploited in the wild, allowing attackers to create or truncate arbitrary files on vulnerable systems. Federal agencies are mandated to patch by Sunday. Any organization running unpatched Splunk Enterprise is at immediate risk of file manipulation and…

threatnoir.com/focus

#infosec #cybersecurity

##

threatnoir@infosec.exchange at 2026-06-20T19:05:18.000Z ##

⚠️ CRITICAL: Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure

CVE-2026-20253 is a critical unauthenticated RCE in Splunk Enterprise being actively exploited in the wild. Attackers can create or truncate arbitrary files via the PostgreSQL sidecar service. All Splunk Enterprise instances are at risk and federal agencies have been mandated to patch by June 21st.

threatnoir.com/focus

#infosec #cybersecurity

##

beyondmachines1@infosec.exchange at 2026-06-20T08:01:21.000Z ##

Splunk Enterprise PostgreSQL Sidecar Vulnerability Exploited in the Wild

A critical, actively exploited vulnerability (CVE-2026-20253) in Splunk Enterprise allows anyone on the network to bypass authentication and manipulate files, leading to potential system takeover. Patches are available in versions 10.4.0, 10.2.4, and 10.0.7.

**Check your versions and patch Splunk Enterprise to 10.4.0, 10.2.4, or 10.0.7 immediately. If you cannot patch today, mitigate the risk right now by disabling the PostgreSQL sidecar service. Finally, verify your network architecture: ensure Splunk Web (port 8000) and management ports are restricted by a firewall, placed on an isolated network segment, and only accessible remotely via a VPN.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

youranonnewsirc@nerdculture.de at 2026-06-19T22:23:33.000Z ##

Here's a summary of recent geopolitical, technology, and cybersecurity news:

Geopolitical: Western allies pledged $4B military aid to Ukraine (June 18). US-Iran talks stalled, and a Lebanon ceasefire was agreed. France emphasized tech sovereignty, ditching US vendors.

Technology: Anthropic's Fable 5 AI model returned with restricted access after a government-forced shutdown.

Cybersecurity: An unpatchable 'usbliter8' exploit impacts Apple A12/A13 chips. A critical Splunk Enterprise vulnerability (CVE-2026-20253) is actively exploited; CISA urged urgent patching (June 19).

#Cybersecurity #Geopolitics #TechNews

##

thecybermind@infosec.exchange at 2026-06-19T20:12:50.000Z ##

CVE-2026-20253 Splunk Vulnerability. Active exploitation is confirmed. CROs and Boards must prioritize this directive to secure enterprise assets and prevent privilege escalation. Review our latest C-SUITE intelligence brief now. thecybermind.co/xo4x

#CyberSecurity #Splunk #CISO #RiskManagement

##

youranonnewsirc@nerdculture.de at 2026-06-19T14:23:38.000Z ##

Latest Geopolitical: An interim US-Iran agreement aims to de-escalate tensions and reopen the Strait of Hormuz, while Moscow endured its largest Ukrainian drone attack, hitting an oil refinery.

Technology: Anthropic's Claude Fable 5 AI is back online after a six-day shutdown, as Google makes Gemini 2.5 Flash its default model.

Cybersecurity: CISA issued alerts for an actively exploited Splunk vulnerability (CVE-2026-20253) and widespread Fortinet "FortiBleed" attacks. Accenture also acquired key OT security firms.

#AnonNews_irc #Cybersecurity #News

##

thecybermind@infosec.exchange at 2026-06-19T08:32:18.000Z ##

ACTIVE THREAT: CVE-2026-20253 Splunk Enterprise vulnerability is being exploited in the wild. Our latest TSUITE Brief provides a full SQL injection defense playbook, including n8n automation triggers for your SOC. Secure your infrastructure now. thecybermind.co/2yn5

#Cybersecurity #Splunk #CVE202620253

##

cyberveille@mastobot.ping.moi at 2026-06-18T22:00:21.000Z ##

📢 CVE-2026-20253 : RCE pré-authentifiée dans Splunk Enterprise via le service PostgreSQL Sidecar
📝 ## 🔍 Contexte

Le 12 juin 2026, watchTowr Labs (Piotr Bazy...
📖 cyberveille : cyberveille.ch/posts/2026-06-1
🌐 source : labs.watchtowr.com/why-use-app
#CVE_2026_20253 #IOC #Cyberveille

##

cisakevtracker@mastodon.social at 2026-06-18T17:00:47.000Z ##

CVE ID: CVE-2026-20253
Vendor: Splunk
Product: Enterprise
Date Added: 2026-06-18
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-06-18T17:00:12.000Z ##

🚨 [CISA-2026:0618] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-20253 (secdb.nttzen.cloud/cve/detail/)
- Name: Splunk Enterprise Missing Authentication for Critical Function Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Splunk
- Product: Enterprise
- Notes: advisory.splunk.com/advisories ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260618 #cisa20260618 #cve_2026_20253 #cve202620253

##

AAKL@infosec.exchange at 2026-06-18T16:34:07.000Z ##

CISA has added one vulnerability to the KEV catalogue.

- CVE-2026-20253: Splunk Enterprise Missing Authentication for Critical Function Vulnerability cve.org/CVERecord?id=CVE-2026- #infosec #vulnerability

##

CVE-2026-42530
(8.1 HIGH)

EPSS: 2.39%

updated 2026-06-18T04:16:48.520000

5 posts

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers

3 repos

https://github.com/HORKimhab/CVE-2026-42530

https://github.com/v4ltonn/CVE-2026-42530

https://github.com/0xBlackash/CVE-2026-42530

hackmag@infosec.exchange at 2026-06-22T04:30:02.000Z ##

⚪️ NGINX Patches Two Critical RCE Vulnerabilities

🗨️ F5 developers have released out-of-band patches for two critical issues in NGINX that, under certain conditions, allowed remote execution of arbitrary code. The vulnerabilities have been assigned identifiers CVE-2026-42530 and CVE-2026-42055, and each received a CVSS score of 9.2. They…

🔗 hackmag.com/news/two-nginx-rce

#news

##

_r_netsec@infosec.exchange at 2026-06-19T19:28:05.000Z ##

Use-after-free in the QPACK encoder of nginx HTTP/3 - CVE-2026-42530 cystack.net/vi/research/cve-20

##

jerry@infosec.exchange at 2026-06-19T12:34:49.000Z ##

@c0dec0dec0de RCEs this time, not DoS. CVE-2026-42530 & CVE-2026-42055

##

beyondmachines1@infosec.exchange at 2026-06-19T08:01:21.000Z ##

F5 Patches Critical Remote Code Execution Flaws in NGINX Open Source and Plus

F5 addressed two critical vulnerabilities (CVE-2026-42530 and CVE-2026-42055) in NGINX that allow unauthenticated remote code execution or denial-of-service. The flaws affect NGINX Open Source, NGINX Plus, and several related gateway and controller products.

**If you run NGINX (Open Source, Plus, Ingress Controller, Gateway Fabric, Instance Manager, or App Protect WAF), update immediately to the fixed versions F5 released: NGINX Open Source 1.31.2 or 1.30.3, and NGINX Plus 37.0.2.1 or R36 P6. If you can't patch right away, temporarily disable HTTP/3 by removing "quic" from all listen directives, and remove the "ignore_invalid_headers off" directive or shrink "large_client_header_buffers" to block these attacks until you update.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

threatnoir@infosec.exchange at 2026-06-18T18:06:26.000Z ##

⚠️ CRITICAL: F5 Patches Critical, High-Severity NGINX Vulnerabilities

F5 released patches for critical unauthenticated RCE and DoS vulnerabilities in NGINX (CVE-2026-42530, CVE-2026-42055) affecting NGINX Plus, Controller, and related products. Attackers can exploit heap buffer overflows and use-after-free flaws without credentials to crash services or execute arbitr…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-42055
(8.1 HIGH)

EPSS: 1.82%

updated 2026-06-18T04:16:48.367000

4 posts

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attack

1 repos

https://github.com/HORKimhab/CVE-2026-42055

hackmag@infosec.exchange at 2026-06-22T04:30:02.000Z ##

⚪️ NGINX Patches Two Critical RCE Vulnerabilities

🗨️ F5 developers have released out-of-band patches for two critical issues in NGINX that, under certain conditions, allowed remote execution of arbitrary code. The vulnerabilities have been assigned identifiers CVE-2026-42530 and CVE-2026-42055, and each received a CVSS score of 9.2. They…

🔗 hackmag.com/news/two-nginx-rce

#news

##

jerry@infosec.exchange at 2026-06-19T12:34:49.000Z ##

@c0dec0dec0de RCEs this time, not DoS. CVE-2026-42530 & CVE-2026-42055

##

beyondmachines1@infosec.exchange at 2026-06-19T08:01:21.000Z ##

F5 Patches Critical Remote Code Execution Flaws in NGINX Open Source and Plus

F5 addressed two critical vulnerabilities (CVE-2026-42530 and CVE-2026-42055) in NGINX that allow unauthenticated remote code execution or denial-of-service. The flaws affect NGINX Open Source, NGINX Plus, and several related gateway and controller products.

**If you run NGINX (Open Source, Plus, Ingress Controller, Gateway Fabric, Instance Manager, or App Protect WAF), update immediately to the fixed versions F5 released: NGINX Open Source 1.31.2 or 1.30.3, and NGINX Plus 37.0.2.1 or R36 P6. If you can't patch right away, temporarily disable HTTP/3 by removing "quic" from all listen directives, and remove the "ignore_invalid_headers off" directive or shrink "large_client_header_buffers" to block these attacks until you update.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

threatnoir@infosec.exchange at 2026-06-18T18:06:26.000Z ##

⚠️ CRITICAL: F5 Patches Critical, High-Severity NGINX Vulnerabilities

F5 released patches for critical unauthenticated RCE and DoS vulnerabilities in NGINX (CVE-2026-42530, CVE-2026-42055) affecting NGINX Plus, Controller, and related products. Attackers can exploit heap buffer overflows and use-after-free flaws without credentials to crash services or execute arbitr…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-54388
(9.1 CRITICAL)

EPSS: 0.39%

updated 2026-06-17T21:34:45

1 posts

Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing values, forwarding all duplicate headers to the backend while using the first value to determine how many request body bytes to consume. Remote attackers can desynchronize the proxy and backend parser state, allowing injection of arbitrary HTTP requests to the backe

DailyCyberSecurity@infosec.exchange at 2026-06-23T06:49:29.000Z ##

Three critical Tinyproxy request smuggling vulnerabilities, including CVE-2026-54388, expose networks to severe attacks. Update your proxy servers immediately.

#Tinyproxy #RequestSmuggling #CVE202654388 #CVE202655202 #CVE202654387
securityonline.info/tinyproxy-

##

CVE-2026-23243
(7.8 HIGH)

EPSS: 0.12%

updated 2026-06-17T19:17:16.593000

1 posts

In the Linux kernel, the following vulnerability has been resolved: RDMA/umad: Reject negative data_len in ib_umad_write ib_umad_write computes data_len from user-controlled count and the MAD header sizes. With a mismatched user MAD header size and RMPP header length, data_len can become negative and reach ib_create_send_mad(). This can make the padding calculation exceed the segment size and tr

offseq@infosec.exchange at 2026-06-23T01:30:26.000Z ##

CRITICAL kernel vulnerabilities in RHEL 7 ELS (e.g., CVE-2026-23243) risk DoS, memory corruption, and network/filesystem instability. Update & reboot required per RHSA-2026:27729. radar.offseq.com/threat/red-ha #OffSeq #Linux #RedHat #Infosec

##

CVE-2026-50656
(7.8 HIGH)

EPSS: 3.39%

updated 2026-06-17T19:10:40.163000

1 posts

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;RoguePlanet &quot;. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

1 repos

https://github.com/0xBlackash/CVE-2026-50656

youranonnewsirc@nerdculture.de at 2026-06-22T22:23:57.000Z ##

Geopolitical tensions escalate as US-Iran talks stall amidst renewed Israel-Hezbollah strikes and Trump's Strait of Hormuz threats; Iran reportedly closed the waterway. In technology, Anthropic's Fable 5 AI models remain offline due to a US export ban. Cybersecurity alerts include active exploitation of Microsoft Defender zero-day (CVE-2026-50656), Cisco SD-WAN, and Splunk flaws.

#AnonNews_irc #Cybersecurity #News

##

oversecurity@mastodon.social at 2026-06-19T13:01:02.000Z ##

CVE-2026-48907 and LiteSpeed cPanel Plugin Flaws Come Under Active Attack

Attackers are exploiting CVE-2026-48907 in Joomla JCE and a LiteSpeed cPanel plugin flaw, enabling PHP code execution and privilege escalation.

🔗️ [Thecyberexpress] link.is.it/SGbmfn

##

threatnoir@infosec.exchange at 2026-06-18T18:06:31.000Z ##

⚠️ CRITICAL: Joomla, LiteSpeed Vulnerabilities Exploited in Attacks

Attackers are actively exploiting CVE-2026-48907 in Joomla Content Editor (JCE) to upload malicious PHP files and execute arbitrary code on all versions before 2.9.99.5. CVE-2026-54420 in LiteSpeed's cPanel plugin allows privilege escalation to root on shared hosting environments. Both vulnerabilit…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-20190
(7.5 HIGH)

EPSS: 0.41%

updated 2026-06-17T18:36:07

2 posts

A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive

AAKL@infosec.exchange at 2026-06-19T17:19:43.000Z ##

New advisory.

This relates to critical CVE-2026-20181 and CVE-2026-20190 vulnerabilities, published on the 17th.

Cisco: CRITICAL: Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

@cR0w

##

beyondmachines1@infosec.exchange at 2026-06-19T09:01:22.000Z ##

Cisco Patches Critical Root RCE and Credential Theft Flaws in ISE

Cisco patched a critical root RCE vulnerability (CVE-2026-20181) and a high-severity information disclosure flaw (CVE-2026-20190) in its Identity Services Engine. These vulnerabilities allow authenticated root access or theft of hashed credentials.

**Make sure your Cisco ISE and ISE-PIC systems are isolated from the internet and reachable only from trusted management networks. Apply the latest patches immediately (ISE 3.3 Patch 11, 3.4 Patch 6, or 3.5 Patch 3) and for the 3.5 command-execution fix, request the hotfix from Cisco TAC now. Don't wait for Patch 4 in August 2026.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-53876
(7.2 HIGH)

EPSS: 1.79%

updated 2026-06-17T18:35:59

1 posts

RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary command execution with the root privilege by a user who logs in to the web console as an administrator.

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-5667
(0 None)

EPSS: 0.15%

updated 2026-06-17T16:21:32.403000

1 posts

Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump Water Heaters / HEMS-Compatible Adapters / Wireless LAN Adapters (for Japan); Bat

_r_netsec@infosec.exchange at 2026-06-18T18:13:05.000Z ##

CVE-2026-5667: Unauthenticated Remote Control of Mitsubishi MAC-577IF-2E WiFi Adapters via Probe Request Reconnaissance innerfirez.github.io/posts/the

##

CVE-2026-20262
(6.5 MEDIUM)

EPSS: 1.37%

updated 2026-06-17T13:20:04.900000

2 posts

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by s

2 repos

https://github.com/HORKimhab/CVE-2026-20262

https://github.com/fevar54/CVE-2026-20262-Cisco-Catalyst-SD-WAN-Manager-Arbitrary-File-Write-

hackmag@infosec.exchange at 2026-06-22T08:00:04.000Z ##

⚪️ Cisco Patches Zero‑Day Vulnerability in SD‑WAN

🗨️ Cisco specialists have released patches for vulnerability CVE-2026-20262 in Catalyst SD-WAN Manager (formerly SD-WAN vManage). According to the company, the issue has already been exploited in real-world attacks and allowed attackers to escalate privileges to the root level. Since the…

🔗 hackmag.com/news/sd-wan-patch?

#news

##

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-9271
(5.9 MEDIUM)

EPSS: 0.14%

updated 2026-06-17T11:04:59.717000

1 posts

Vulnerability Title

CVE-2026-7473
(5.8 MEDIUM)

EPSS: 0.84%

updated 2026-06-17T11:02:29.070000

1 posts

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not ver

1 repos

https://github.com/fevar54/CVE-2026-7473---Arista-EOS-Tunnel-Decapsulation-Bypass

thecybermind@infosec.exchange at 2026-06-23T07:20:31.000Z ##

🚨 New CSUITE Brief: Arista EOS vulnerability CVE-2026-7473 requires immediate executive oversight. Understand the organizational risk and the strategic governance required to protect your infrastructure. Read the full risk assessment here: thecybermind.co/tugq

#CyberSecurity #ExecutiveRisk #AristaEOS

##

CVE-2026-54420
(8.5 HIGH)

EPSS: 1.26%

updated 2026-06-17T10:58:13.830000

1 posts

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

4 repos

https://github.com/HORKimhab/CVE-2026-54420

https://github.com/mahfuzreham/litespeed-cpanel-cve-2026-54420-fix

https://github.com/fevar54/CVE-2026-54420-LiteSpeed-Symlink-Exploit

https://github.com/Resellnom/litespeed-cpanel-cve-2026-54420-fix

threatnoir@infosec.exchange at 2026-06-18T18:06:31.000Z ##

⚠️ CRITICAL: Joomla, LiteSpeed Vulnerabilities Exploited in Attacks

Attackers are actively exploiting CVE-2026-48907 in Joomla Content Editor (JCE) to upload malicious PHP files and execute arbitrary code on all versions before 2.9.99.5. CVE-2026-54420 in LiteSpeed's cPanel plugin allows privilege escalation to root on shared hosting environments. Both vulnerabilit…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-48970
(8.1 HIGH)

EPSS: 0.32%

updated 2026-06-17T10:55:25.967000

1 posts

Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.

wpguyuk@infosec.exchange at 2026-06-22T07:05:50.000Z ##

Really Simple Security below 9.5.10.1 has a high-severity vulnerability (CVE-2026-48970, disclosed 15 June 2026) that requires no admin credentials to exploit. I find it particularly concerning given this plugin exists specifically to harden WordPress security. If your site is running an older version, update it now.

#WordPress #SecurityHardening #WordPressSecurity #CVE #SSL

wpguy.uk/blog/high-vulnerabili

##

CVE-2026-48558
(10.0 CRITICAL)

EPSS: 0.72%

updated 2026-06-17T10:55:05.230000

1 posts

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary

cyberveille@mastobot.ping.moi at 2026-06-18T18:30:12.000Z ##

📢 ~14 000 serveurs SimpleHelp exposés via un contournement d'authentification critique (CVE-2026-48558)
📝 📰 **Source** : CybersecurityNews.com — **Date de publication** : 16 juin 2026

...
📖 cyberveille : cyberveille.ch/posts/2026-06-1
🌐 source : cybersecuritynews.com/simplehe
#CVE_2026_48558 #IOC #Cyberveille

##

CVE-2026-45504
(8.8 HIGH)

EPSS: 0.43%

updated 2026-06-17T10:52:10.200000

2 posts

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

1 repos

https://github.com/hawktrace/CVE-2026-45504

obivan at 2026-06-24T18:49:48.422Z ##

CVE-2026-45504 Microsoft Exchange SSRF via File Read hawktrace.com/blog/CVE-2026-45

##

obivan@infosec.exchange at 2026-06-24T18:49:48.000Z ##

CVE-2026-45504 Microsoft Exchange SSRF via File Read hawktrace.com/blog/CVE-2026-45

##

CVE-2026-20245
(7.8 HIGH)

EPSS: 9.92%

updated 2026-06-17T10:17:19.370000

5 posts

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of us

3 repos

https://github.com/0xBlackash/CVE-2026-20245

https://github.com/HORKimhab/CVE-2026-20245

https://github.com/fevar54/CVE-2026-20245---Cisco-SD-WAN-Privilege-Escalation-Exploit

Analyst207@mastodon.social at 2026-06-24T21:44:01.000Z ##

Mandiant Exposes Cisco SD-WAN Zero-Day Attacks' Root Access Methods

Cisco's SD-WAN system was exploited in active attacks using a high-severity flaw, allowing hackers to create a rogue root account and take full control of targeted devices. This vulnerability, tracked as CVE-2026-20245, was triggered through a simple tenant-upload feature in the command-line interface.

osintsights.com/mandiant-expos

#CiscoSdwan #ZeroDay #Cve202620245 #CommandInjection #RootAccess

##

oversecurity@mastodon.social at 2026-06-24T21:40:06.000Z ##

Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access

New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to...

🔗️ [Bleepingcomputer] link.is.it/gbIA4V

##

oversecurity@mastodon.social at 2026-06-24T21:40:06.000Z ##

Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access

New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to...

🔗️ [Bleepingcomputer] link.is.it/gbIA4V

##

AAKL@infosec.exchange at 2026-06-24T15:57:48.000Z ##

New.

Mandiant: Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager cloud.google.com/blog/topics/t #Google

Microsoft:

StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them microsoft.com/en-us/security/b

Kaspersky:

StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader securelist.com/strikeshark-cam @Kaspersky

Symantec: Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker security.com/threat-intelligen

Picus:

The ShinyHunters Domino Effect: One Breach, Hundreds of Victims picussecurity.com/resource/blo

Proofpoint:

StealC You Later: Proofpoint and IBM X-Force Support Operation Endgame Disruptions proofpoint.com/us/blog/threat- #threatresearch #cybercrime #Microsoft #infosec #threatintelligence #Cisco #vulnerability #zeroday #ransomware

##

Mozilla@activitypub.awakari.com at 2026-06-24T14:15:55.000Z ## Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan Introduction to Malware Binary Triage (IMBT) ...

#Malware #News

Origin | Interest | Match ##

CVE-2025-8088
(8.8 HIGH)

EPSS: 85.78%

updated 2026-06-17T10:06:17.243000

1 posts

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

31 repos

https://github.com/Shinkirou789/Cve-2025-8088-WinRar-vulnerability

https://github.com/hbesljx/CVE-2025-8088-EXP

https://github.com/AdityaBhatt3010/CVE-2025-8088-WinRAR-Zero-Day-Path-Traversal

https://github.com/0xAbolfazl/CVE-2025-8088-WinRAR-PathTraversal-PoC

https://github.com/travisbgreen/cve-2025-8088

https://github.com/aldisakti2/CVE-2025-8088-BUILDER-Winrar-Tool

https://github.com/xi0onamdev/WinRAR-CVE-2025-8088-Exploitation-Toolkit

https://github.com/kitsuneshade/WinRAR-Exploit-Tool---Rust-Edition

https://github.com/Syrins/CVE-2025-8088-Winrar-Tool-Gui

https://github.com/sxyrxyy/CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit-

https://github.com/nuky-alt/CVE-2025-8088

https://github.com/walidpyh/CVE-2025-8088

https://github.com/hexsecteam/CVE-2025-8088-Winrar-Tool

https://github.com/undefined-name12/CVE-2025-8088-Winrar

https://github.com/pentestfunctions/CVE-2025-8088-Multi-Document

https://github.com/lennertdefauw/CVE-2025-8088

https://github.com/techcorp/CVE-2025-8088-Exploit

https://github.com/DeepBlue-dot/CVE-2025-8088-WinRAR-Startup-PoC

https://github.com/jordan922/CVE-2025-8088

https://github.com/ghostn4444/CVE-2025-8088

https://github.com/IsmaelCosma/CVE-2025-8088

https://github.com/ilhamrzr/RAR-Anomaly-Inspector

https://github.com/papcaii2004/CVE-2025-8088-WinRAR-builder

https://github.com/pescada-dev/-CVE-2025-8088

https://github.com/onlytoxi/CVE-2025-8088-Winrar-Tool

https://github.com/knight0x07/WinRAR-CVE-2025-8088-PoC-RAR

https://github.com/nhattanhh/CVE-2025-8088

https://github.com/shaheeryasirofficial/CVE-2025-8088

https://github.com/starfallreverie/winrar-exploit

https://github.com/pentestfunctions/best-CVE-2025-8088

https://github.com/pexlexity/WinRAR-CVE-2025-8088-Path-Traversal-PoC

CVE-2026-50874
(8.1 HIGH)

EPSS: 1.12%

updated 2026-06-16T21:33:04

1 posts

An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input.

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-38065
(9.8 CRITICAL)

EPSS: 1.34%

updated 2026-06-16T21:32:59

1 posts

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter.

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-53753
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-06-16T20:13:08

1 posts

### Summary The `_safe_eval_expression()` function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore. Python generator and frame object attributes (`gi_frame`, `f_back`, `f_builtins`) do NOT start with underscore, enabling a complete sandbox escape to achieve arbitrary code execution. The attack requires no authentication (JWT disabled by d

offseq@infosec.exchange at 2026-06-24T01:30:27.000Z ##

CVE-2026-53753: CRITICAL code injection in unclecode crawl4ai (<0.8.7). Unauthenticated RCE via /crawl POST request due to insufficient AST validation. Patch to 0.8.7 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202653753 #infosec #vuln

##

CVE-2026-50871
(9.8 CRITICAL)

EPSS: 1.57%

updated 2026-06-16T15:33:48

1 posts

An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input.

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12219
(6.3 MEDIUM)

EPSS: 1.52%

updated 2026-06-15T06:31:46

1 posts

A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is the function mod_diagnose.CommandShellByType of the file /api/diagnosis/start of the component Web FastCGI Service. This manipulation of the argument Time causes command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12223
(5.5 MEDIUM)

EPSS: 1.53%

updated 2026-06-15T06:31:41

1 posts

A vulnerability was identified in Yealink SIP-T46U 108.86.0.118. Affected by this vulnerability is the function mod_webd.TFTPUploadIperf of the file /api/inner/tftpuploadiperf of the component Web FastCGI Service. The manipulation of the argument ip/port leads to command injection. The attack needs to be initiated within the local network. The exploit is publicly available and might be used. The v

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12197
(7.2 HIGH)

EPSS: 2.38%

updated 2026-06-15T00:31:55

1 posts

A security flaw has been discovered in Ruijie EG105G-P 2.340. The impacted element is the function nslookup of the file /cgi-bin/luci/api/diagnose of the component JSON-RPC Diagnose Endpoint. Performing a manipulation of the argument params.target results in command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. T

secdb@infosec.exchange at 2026-06-22T00:07:05.000Z ##

📈 CVE Published in last days (2026-06-15 - 2026-06-15)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 374
- High: 827
- Medium: 471
- Low: 67
- None: 235

Status:
- : 204
- Analyzed: 394
- Awaiting Analysis: 88
- Deferred: 744
- Modified: 35
- Received: 417
- Rejected: 14
- Undergoing Analysis: 78

CISA KEVs:
- CISA-2026:0615 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0616 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0618 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Patchstack: 489
- Oracle: 240
- N/A: 204
- VulnCheck: 202
- GitHub, Inc.: 133
- MITRE: 84
- Wordfence: 64
- VulDB: 49
- Mozilla Corporation: 44
- Google Devices: 39

Top Affected Products:
- UNKNOWN: 1471
- Google Android: 55
- Mozilla Thunderbird: 42
- Mozilla Firefox: 42
- Google Chrome: 33
- Oracle Webcenter Content: 32
- Openclaw: 27
- Oracle Jd Edwards Enterpriseone Tools: 14
- Oracle Enterprise Manager Base Platform: 14
- Oracle Weblogic Server: 13

Top EPSS Score:
- CVE-2026-11409 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-11410 - 2.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12197 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-53876 - 1.79 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50871 - 1.57 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12223 - 1.53 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12219 - 1.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38065 - 1.35 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-20262 - 1.15 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-50874 - 1.12 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-10520
(10.0 CRITICAL)

EPSS: 98.94%

updated 2026-06-11T21:31:50

1 posts

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

Nuclei template

6 repos

https://github.com/error-inside/CVE-2026-10520

https://github.com/0xBlackash/CVE-2026-10520

https://github.com/gagaltotal/CVE-2026-10523-Ivanti-sentry

https://github.com/HORKimhab/CVE-2026-10520-10523

https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523

https://github.com/ogenich/CVE-2026-10520

CVE-2026-34182
(9.1 CRITICAL)

EPSS: 0.24%

updated 2026-06-10T18:32:45

1 posts

Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises. Impact Summary: Attackers making use of these vulnerabilities may achieve key-equivalent functionality for a given CMS recipient and/or bypass integrity validation for a given mess

redsakana@infosec.exchange at 2026-06-23T15:44:53.000Z ##

this-is-fine dog of the week (from oss-sec):

blog.calif.io/p/how-to-format- discusses how the issue that OpenSSL disclosed on June 9 as CVE-2026-34182 similarly affected the PKCS#7 / CMS parsing implementations from WolfSSL, Bouncy Castle, & GnuPG.

The common failure is accepting the sender provided length for the authentication tag, and not enforcing the minimum length specified in the RFC - allowing an attacker to specify a one-byte tag length and then use brute force to determine which of the 256 possible values matches the first byte of the actual tag.

##

CVE-2026-25860
(6.1 MEDIUM)

EPSS: 0.29%

updated 2026-06-10T00:31:50

1 posts

OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that allows attackers to execute arbitrary JavaScript in a victim's browser by embedding malicious payloads in DICOM file metadata fields. Attackers can craft a DICOM file with JavaScript payloads in metadata fields such as Study Description, which are reflected without sanitization in

1 repos

https://github.com/partywavesec/CVE-2026-25860

CVE-2026-26980
(9.4 CRITICAL)

EPSS: 70.00%

updated 2026-06-08T23:22:35

1 posts

### Impact A SQL injection vulnerability existed in Ghost's Content API that allowed unauthenticated attackers to read arbitrary data from the database. ### Vulnerable Versions This vulnerability is present in Ghost v3.24.0 to v6.19.0. ### Patches v6.19.1 contains a fix for this issue. **Note:** as this vulnerability lets an attacker gain access to a site's API keys, we recommend reviewing

Nuclei template

4 repos

https://github.com/Kulik-Labs-Development/Ghost-CMS-Code-Injection-Audit-CVE-2026-26980

https://github.com/EQSTLab/CVE-2026-26980

https://github.com/vognik/CVE-2026-26980

https://github.com/dinosn/ghost-cve-2026-26980

oversecurity@mastodon.social at 2026-06-23T14:51:51.000Z ##

Ghost Stories: investigating an undocumented ClickFix C2 in Ghost CMS

Read-only research into an active campaign that exploits CVE-2026-26980 in Ghost CMS. Every result below comes from public GET requests. We did not...

🔗️ [Sicuranext] link.is.it/r78ZkS

##

CVE-2026-45034(CVSS UNKNOWN)

EPSS: 0.35%

updated 2026-06-08T23:00:17

1 posts

## Summary CVE-2026-34084 was patched by the helper `File::prohibitWrappers`. The helper calls `parse_url($filename, PHP_URL_SCHEME)` and then checks `is_string($scheme) && strlen($scheme) > 1` to reject stream wrappers such as `phar://`, `php://`, `data://` or `expect://`. The check is not equivalent to "does the path contain a wrapper". When the input has the form `phar:///path/file.phar/inner`

1 repos

https://github.com/Cyber-DarkNay/CVE-2026-45034

offseq@infosec.exchange at 2026-06-22T21:00:12.000Z ##

CVE-2026-45034: CRITICAL deserialization of untrusted data in PHPOffice PhpSpreadsheet allows RCE via phar stream wrappers. Patch to 1.30.5 to mitigate. PHP 7.x at highest risk. radar.offseq.com/threat/cve-20 #OffSeq #CVE202645034 #PHP #infosec

##

CVE-2026-8206
(9.8 CRITICAL)

EPSS: 1.26%

updated 2026-06-02T06:30:33

1 posts

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered

3 repos

https://github.com/Jenderal92/CVE-2026-8206

https://github.com/izxci/CVE-2026-8206

https://github.com/rootdirective-sec/CVE-2026-8206-Lab

mstankiewicz@mastodon.com.pl at 2026-06-19T06:40:15.000Z ##

🚨 KTRYTYCZNA PODSTNOŚĆ WE WTYCZCE #WORDPRESS!
Jak podaje #Sekurak, we wtyczce #Kirki wykryto lukę, pozwalającą na przejęcie dowolnego konta, w tym administratora.
Jeśli masz to rozszerzenie, zaktualizuj je natychmiast do najnowszej wersji!

CVE-2026-8206
CVSS: 9.8

sekurak.pl/blad-w-popularnej-w

##

CVE-2026-47717
(7.5 HIGH)

EPSS: 0.00%

updated 2026-05-27T22:51:19

1 posts

### Summary The GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. ### Details File: `server/api/projects/index.js` ```javascript prjApp.get("/api/project", secureFnc, function(req, res) { const permission = checkGroupsFnc(req); runtime.project.getProject(req.userId, permission).then(result => { i

Nuclei template

halildeniz@mastodon.social at 2026-06-19T18:55:00.000Z ##

🚨 CVE-2026-47717: Dive into my deep technical analysis of the FUXA SCADA API logic flaw that allows unauthenticated attackers to leak critical project configurations and operational data.

Read the full analysis here: 👇 denizhalil.com/2026/06/19/cve-

#SCADA #infosec

##

CVE-2026-39987
(9.8 CRITICAL)

EPSS: 95.64%

updated 2026-04-27T16:30:09

1 posts

## Summary Marimo (19.6k stars) has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint `/terminal/ws` lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., `/ws`) that correctly call `validate_auth()` for authentication, the `/terminal/ws` endpoint only checks the

Nuclei template

12 repos

https://github.com/rootdirective-sec/CVE-2026-39987-Lab

https://github.com/mki9/CVE-2026-39987_exploit

https://github.com/0xdeadroot/CVE-2026-39987-marimo-rce

https://github.com/h3raklez/CVE-2026-39987

https://github.com/M3PH1569/CVE-2026-39987-POC

https://github.com/Nxploited/CVE-2026-39987

https://github.com/HORKimhab/CVE-2026-39987

https://github.com/Dhiaelhak-Rached/CVE-2026-39987-lab-or-marimo-cve-lab

https://github.com/0xBlackash/CVE-2026-39987

https://github.com/keraattin/CVE-2026-39987

https://github.com/jenniferreire26/CVE-2026-39987

https://github.com/fevar54/marimo_CVE-2026-39987_RCE_PoC

tugatech@masto.pt at 2026-06-21T15:19:42.000Z ##

Plataforma Marimo sofre falha crítica que permite acesso a servidores sem credenciais. A vulnerabilidade CVE-2026-39987 foi ativamente explorada em menos de dez horas após divulgação pública 🔒

🔗 tugatech.com.pt/t85899-platafo

#falha #plataforma #sem 

##

CVE-2026-41175
(8.1 HIGH)

EPSS: 0.30%

updated 2026-04-24T20:52:07

1 posts

### Impact Manipulating query parameters on Control Panel and REST API endpoints, or arguments in GraphQL queries, could result in the loss of content, assets, and user accounts. The Control Panel requires authentication with minimal permissions in order to exploit. e.g. "view entries" permission to delete entries, or "view users" permission to delete users, etc. The REST and GraphQL API exploi

hugovalters@mastodon.social at 2026-06-21T14:02:20.000Z ##

CVE-2026-49287 - Supply chain risk in Statamic. Unaddressed incomplete fix from CVE-2026-41175. Sort param manipulation could delete content/assets. CVSS 7.4. No patch; review templates immediately. #CVE #Statamic #infosec

valtersit.com/cve/CVE-2026-492

##

CVE-2026-4020
(7.5 HIGH)

EPSS: 39.70%

updated 2026-03-31T03:31:35

3 posts

The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor to access it. When the ?page=gravitysmtp-settings query parameter is appended, th

Nuclei template

1 repos

https://github.com/HORKimhab/CVE-2026-4020

beyondmachines1@infosec.exchange at 2026-06-23T08:01:05.000Z ##

Attackers Mass-Exploit Gravity SMTP Plugin to Steal WordPress API Keys

Attackers are mass-exploiting a sensitive information exposure vulnerability (CVE-2026-4020) in the Gravity SMTP WordPress plugin to steal API keys and system configuration data. Over 17 million exploit attempts have been blocked as threat actors target approximately 100,000 active installations.

**If you run the Gravity SMTP plugin for WordPress, update it to version 2.1.5 or later right away, since attackers are actively stealing API keys and credentials through older versions. After updating, rotate all your third-party email API keys and secrets (like Amazon SES, Google, Mailjet, Resend, and Zoho), and check your web server logs for any suspicious requests to the "mock-data" endpoint.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

rhudaur@flipboard.com at 2026-06-20T17:49:26.000Z ##

Hackers are mass-exploiting a Gravity SMTP flaw to steal API keys from 100,000 WordPress sites
thenextweb.com/news/gravity-sm

Posted into Cybersecurity Today @cybersecurity-today-rhudaur

##

thenextweb@flipboard.com at 2026-06-20T16:56:45.000Z ##

Hackers are mass-exploiting a Gravity SMTP flaw to steal API keys from 100,000 WordPress sites
thenextweb.com/news/gravity-sm

Posted into Sustainability @sustainability-thenextweb

##

CVE-2026-20971
(7.8 HIGH)

EPSS: 0.13%

updated 2026-01-15T21:31:44

2 posts

Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code.

_r_netsec@infosec.exchange at 2026-06-24T10:58:06.000Z ##

CVE-2026-20971: Samsung Android kernel UAF affecting Galaxy S9-S25 lucidbitlabs.com/blog/when-def

##

informapirata@mastodon.uno at 2026-06-23T23:06:19.000Z ##

La vulnerabilità UAF del kernel KNOX di Samsung espone milioni di dispositivi Galaxy.

La vulnerabilità KNOX di Samsung (CVE-2026-20971) è una UAF del kernel in PROCA/FIVE che può consentire la corruzione [della memoria] tramite una race condition; Samsung l'ha corretta nel gennaio 2026.

securityaffairs.com/194090/sec

@informatica

infosec.exchange/@securityaffa

##

CVE-2024-40766
(9.3 CRITICAL)

EPSS: 15.69%

updated 2025-10-22T00:33:06

1 posts

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

sans_isc@infosec.exchange at 2026-06-23T03:05:21.000Z ##

CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration. isc.sans.edu/diary/33094

##

CVE-2014-9223(CVSS UNKNOWN)

EPSS: 6.03%

updated 2025-04-12T12:44:27

1 posts

Multiple buffer overflows in AllegroSoft RomPager, as used in Huawei Home Gateway products and other vendors and products, allow remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors related to authorization.

certvde@infosec.exchange at 2026-06-23T07:37:32.000Z ##

#OT #Advisory VDE-2026-071
JUMO: Allegro RomPager webserver vulnerability in JUMO mTRONT, DICON touch, AQUIS touch devices

Multiple products from JUMO are affected by webserver vulnerability "CVE-2013-6786, CVE-2014-9222, CVE-2014-9223. This vulnerability leads to DOS of the device by using a misfortune cookie and reflected XSS attacks.
#CVE CVE-2014-9222, CVE-2013-6786, CVE-2014-9223

certvde.com/en/advisories/vde-

#CSAF jumo.csaf-tp.certvde.com/.well

##

CVE-2014-9222(CVSS UNKNOWN)

EPSS: 63.50%

updated 2025-04-12T12:44:27

1 posts

AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gain privileges via a crafted cookie that triggers memory corruption, aka the "Misfortune Cookie" vulnerability.

2 repos

https://github.com/donfanning/MIPS-CVE-2014-9222

https://github.com/mercul1ninna/MIPS-CVE-2014-9222

certvde@infosec.exchange at 2026-06-23T07:37:32.000Z ##

#OT #Advisory VDE-2026-071
JUMO: Allegro RomPager webserver vulnerability in JUMO mTRONT, DICON touch, AQUIS touch devices

Multiple products from JUMO are affected by webserver vulnerability "CVE-2013-6786, CVE-2014-9222, CVE-2014-9223. This vulnerability leads to DOS of the device by using a misfortune cookie and reflected XSS attacks.
#CVE CVE-2014-9222, CVE-2013-6786, CVE-2014-9223

certvde.com/en/advisories/vde-

#CSAF jumo.csaf-tp.certvde.com/.well

##

CVE-2019-1003037
(6.5 MEDIUM)

EPSS: 1.30%

updated 2023-12-14T18:25:14

1 posts

An information exposure vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMCloud.java that allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

nyanbinary@infosec.exchange at 2026-06-22T14:44:21.000Z ##

Ok, so. Originally CVE IDs where 4 digits. At some point in the mid '10s it went "4+ digits". There is a chance we'll require 6 digits this or next year.

Meanwhile, in 2019: Fuck it, we ball: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2013-6786(CVSS UNKNOWN)

EPSS: 2.17%

updated 2023-01-28T05:02:55

1 posts

Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the "forbidden author header" protection mechanism is bypassed, allows remote attackers to inject arbitrary web script or HTML by requesting a nonexistent URI in conjunction with a crafted HTTP Referer head

certvde@infosec.exchange at 2026-06-23T07:37:32.000Z ##

#OT #Advisory VDE-2026-071
JUMO: Allegro RomPager webserver vulnerability in JUMO mTRONT, DICON touch, AQUIS touch devices

Multiple products from JUMO are affected by webserver vulnerability "CVE-2013-6786, CVE-2014-9222, CVE-2014-9223. This vulnerability leads to DOS of the device by using a misfortune cookie and reflected XSS attacks.
#CVE CVE-2014-9222, CVE-2013-6786, CVE-2014-9223

certvde.com/en/advisories/vde-

#CSAF jumo.csaf-tp.certvde.com/.well

##

CVE-2026-47729
(0 None)

EPSS: 0.00%

4 posts

N/A

1 repos

https://github.com/0xBlackash/CVE-2026-47729

sayzard@mastodon.sayzard.org at 2026-06-24T19:44:35.000Z ##

Mythos discovers 'Squidbleed,' a memory leak thats gone undetected since Clinton

Mythos와 연구원 Lam Jun Rong이 29년간 발견되지 않았던 Squid 오픈소스 프록시 서버의 메모리 누수 취약점 'Squidbleed'(CVE-2026-47729)를 발견했다. 이 취약점은 FTP 디렉터리 리스트 파서의 버그로 인해 HTTP 요청 내 민감 정보가 공격자에게 노출될 수 있었으며, 1997년 코드 커밋에서 비롯되었다. Squid 7.6 버전에서 패치되었으며, FTP 기...

theregister.com/security/2026/

##

benzogaga33@mamot.fr at 2026-06-23T09:40:04.000Z ##

Squidbleed : une faille vieille de 29 ans fait fuiter les identifiants des utilisateurs du proxy Squid it-connect.fr/squidbleed-faill #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

campuscodi@mastodon.social at 2026-06-20T20:59:02.000Z ##

29-year-old bug in Squid that can leak internal memory, works in default configs

blog.calif.io/p/squidbleed-cve

##

_r_netsec@infosec.exchange at 2026-06-19T10:28:05.000Z ##

Squidbleed (CVE-2026-47729) - Heartbleed-style vulnerability that leaks internal memory from every version of Squid Proxy, in its default configuration blog.calif.io/p/squidbleed-cve

##

CVE-2026-50000
(0 None)

EPSS: 0.00%

1 posts

N/A

legoktm@wikis.world at 2026-06-24T14:57:43.000Z ##

RE: social.freedom.press/@securedr

The low priority issue we disclosed today managed to get assigned CVE-2026-50000.

Didn't include this in the writeup, but just for the purpose of keeping score, this would likely not have happened if it was written in #Rust because mutability is part of the type system, so you don't end up accidentally mutating what should be an immutable object!

github.com/freedomofpress/secu

##

CVE-2026-8932
(0 None)

EPSS: 0.00%

1 posts

N/A

bagder@mastodon.social at 2026-06-24T07:20:34.000Z ##

CVE-2026-8932 is the oldest #curl vulnerability reported so far. 25.25 years old. Shipped in releases since curl version 7.7, released on March 22 2001

Still rather benign and it probably hurt about three users, at most.

curl.se/docs/CVE-2026-8932.html

##

CVE-2026-53662
(0 None)

EPSS: 0.24%

1 posts

N/A

offseq@infosec.exchange at 2026-06-24T03:00:27.000Z ##

immich-app suffers CRITICAL reflected XSS (CVE-2026-53662) in /auth/login (commits 4ffa26c9 – 4eb1003). Exploitation = persistent account takeover via API key minting. Update to commit 4eb1003 or later. radar.offseq.com/threat/cve-20 #OffSeq #CVE202653662 #XSS #infosec

##

CVE-2026-28496
(0 None)

EPSS: 1.89%

1 posts

N/A

Nuclei template

AAKL@infosec.exchange at 2026-06-23T18:20:05.000Z ##

New.

"Today VulnCheck is disclosing CVE-2026-28496, an unauthenticated remote code execution chain in FOSSBilling, the open-source billing and client-management platform."

VulnCheck: CVE-2026-28496 - FOSSBilling Auth Bypass and Twig SSTI to Unauthenticated RCE vulncheck.com/blog/fossbilling @vulncheck #infosec #opensource #vulnerability

##

CVE-2026-50160
(0 None)

EPSS: 0.00%

1 posts

N/A

_r_netsec@infosec.exchange at 2026-06-23T17:43:05.000Z ##

CVE-2026-50160: Four Independent Weaknesses Combine Into a CVSS 10.0 Full Compromise in Hoppscotch offgridsec.com/blog-hoppscotch

##

CVE-2026-12958
(0 None)

EPSS: 0.14%

1 posts

N/A

awssecurityfeed@infosec.exchange at 2026-06-23T16:30:01.000Z ##

CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins

Bulletin ID: 2026-047-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/23/2026 09:30 AM PDT
Description:
Language Servers for AWS provide the underlying language-server runtime that powers Amazon ...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-12957
(0 None)

EPSS: 0.12%

1 posts

N/A

awssecurityfeed@infosec.exchange at 2026-06-23T16:30:01.000Z ##

CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins

Bulletin ID: 2026-047-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/23/2026 09:30 AM PDT
Description:
Language Servers for AWS provide the underlying language-server runtime that powers Amazon ...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-10658
(0 None)

EPSS: 0.17%

1 posts

N/A

offseq@infosec.exchange at 2026-06-23T04:30:29.000Z ##

Zephyr <=4.4.0 Bluetooth Host ISO path has CVE-2026-10658 (HIGH). Missing SDU header length checks can cause denial of service (kernel assert) or OOB reads if CONFIG_BT_ISO_RX is enabled. Evaluate mitigations now. radar.offseq.com/threat/cve-20 #OffSeq #Zephyr #CVE #Bluetooth

##

CVE-2026-49287
(0 None)

EPSS: 0.27%

1 posts

N/A

hugovalters@mastodon.social at 2026-06-21T14:02:20.000Z ##

CVE-2026-49287 - Supply chain risk in Statamic. Unaddressed incomplete fix from CVE-2026-41175. Sort param manipulation could delete content/assets. CVSS 7.4. No patch; review templates immediately. #CVE #Statamic #infosec

valtersit.com/cve/CVE-2026-492

##

CVE-2026-9142
(0 None)

EPSS: 0.31%

1 posts

N/A

offseq@infosec.exchange at 2026-06-20T07:30:30.000Z ##

NI grpc-device ≤2.17.0 hit by CRITICAL vuln (CVE-2026-9142, CVSS 9.1) 🛡️ Missing authentication when TLS isn't set & server exposed beyond loopback. Unauthenticated LAN access possible. Mitigate by enabling TLS & restricting binding. radar.offseq.com/threat/cve-20 #OffSeq #NI #Vuln

##

CVE-2026-48773
(0 None)

EPSS: 0.36%

1 posts

N/A

offseq@infosec.exchange at 2026-06-20T06:00:22.000Z ##

ProxySQL (2.0.18 – 3.0.8) hit by CRITICAL CVE-2026-48773: pre-auth heap memory corruption (CWE-787) allows remote unauthenticated attackers to trigger out-of-bounds write. Upgrade to 3.0.9 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #ProxySQL #CVE202648773 #infosec

##

CVE-2025-60467
(0 None)

EPSS: 0.00%

2 posts

N/A

sigdevel@infosec.exchange at 2026-06-20T04:41:57.000Z ##

Security Advisory: CVE-2025-60467 - Use-After-Free in GPAC MP4Box Filter PID Cleanup

A use-after-free vulnerability exists in GPAC MP4Box when processing a crafted MPEG-2 TS/MP4 file. The issue is triggered during filter teardown in `gf_filter_pid_inst_swap_delete_task()` and can cause MP4Box to crash.

Summary:
AddressSanitizer confirms a heap-use-after-free in `filter_core/filter_pid.c:580`, where code reads from a PID instance object after it has already been freed during swap/delete cleanup.
The crafted file contains malformed MPEG-2 TS structures, including broken PMT descriptors and invalid PID metadata. While MP4Box processes the file with `-info`, the filter core performs PID instance cleanup. During this cleanup path, a PID instance is freed and later accessed again by `gf_filter_pid_inst_swap_delete_task()`.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filter_core/filter_pid.c:580
Function: gf_filter_pid_inst_swap_delete_task()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
```
2.5-DEV-rev1593-gfe88c3545-master
Commit: fe88c3545aadd597b250ccf23271d5d3de50ccc8
```

Attack Conditions:
An attacker supplies a crafted input file that is processed by MP4Box. The issue can be reproduced locally with:
```
./MP4Box -info 39_gf_filter_pid_inst_swap_delete_task_filter_core_filter_pid_c_580
```

The prepared CVSS vector:
```
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
```

Impact:
denial of service via application crash; local triage notes also identify potential arbitrary code execution risk

Fix / mitigation status:
Users should update to a fixed GPAC release or apply the vendor-confirmed patch. Verify the final vendor fix commit before public release if the advisory is published independently.

References:

- Issue: github.com/gpac/gpac/issues/32
- Fix: github.com/gpac/gpac/commit/ae
- PoC: github.com/sigdevel/pocs/blob/
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

sigdevel@infosec.exchange at 2026-06-20T04:21:31.000Z ##

Security Advisory: CVE-2025-60467 - Use-After-Free in GPAC MP4Box PID Swap Delete Task

Processing a crafted media file with MP4Box `-info` can trigger a heap use-after-free in `gf_filter_pid_inst_swap_delete_task()`, causing a crash and potential code execution.

Summary:
The `gf_filter_pid_inst_swap_delete_task()` function in `filter_core/filter_pid.c` can access a `GF_FilterPidInstance` object after it has already been freed by `gf_filter_pid_inst_swap_delete()`. Crafted input that exercises filter reconfiguration and deferred teardown paths can cause the scheduler to process a delete task with a stale pointer.

AddressSanitizer reports a `heap-use-after-free` at `filter_core/filter_pid.c:574`, with a `READ of size 4` from a previously freed 336-byte heap region.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filter_core/filter_pid.c:574
Function: gf_filter_pid_inst_swap_delete_task()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:
```
GPAC version: 2.5-DEV-rev1570-g6208015df-master
Commit: 6208015dff3a6735a26e413c484c714666eb3ea2
```

The MITRE response states that GPAC Project/MP4Box before `26.02.0` is affected. Builds before the fix commit `976dacf65cb6986a4e4f350fb8d3ed0a17dc3a77` should be considered affected if they contain the vulnerable deferred PID swap delete task path.

Attack Conditions:
An attacker supplies a crafted media file or filter graph input that is processed by MP4Box through the info/import path and triggers PID reconfiguration and deferred teardown. The issue can be reproduced locally with:
```
./MP4Box -info 37_gf_filter_pid_inst_swap_delete_task_filter_core_filter_pid_c_574
```

No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

The prepared CVSS vector:
```
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
```

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is a heap use-after-free, memory corruption and potential arbitrary code execution are possible.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
976dacf65cb6986a4e4f350fb8d3ed0a17dc3a77
```

Users should update to a GPAC build containing this commit or later. The affected deferred task path should ensure that `GF_FilterPidInstance` lifetime remains valid before a scheduled delete task accesses it.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/97
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

CVE-2025-60474
(0 None)

EPSS: 0.00%

1 posts

N/A

sigdevel@infosec.exchange at 2026-06-20T04:33:55.000Z ##

Security Advisory: CVE-2025-60474 - Heap Buffer Overflow in GPAC MP4Box Media Import

A heap buffer overflow vulnerability exists in GPAC MP4Box when processing a crafted media file with the `-info` option. The issue occurs in `gf_media_import()` in `media_tools/media_import.c` and can be triggered by supplying a malformed input file to MP4Box.

Summary:
AddressSanitizer confirms an out-of-bounds read at `media_tools/media_import.c:1297`. The vulnerable code reads 1 byte at offset `[1]` from a 1-byte heap buffer allocated from an empty string via `strdup("")`, where only offset `[0]` is valid.
The crafted input reaches MP4Box media import handling and causes `gf_media_import()` to access memory immediately after a 1-byte heap allocation. The allocation originates from property handling for an empty string and is later read out of bounds during media import processing.

CWE:
CWE-122 - Heap-based Buffer Overflow

Affected Component:
```
media_tools/media_import.c:1297
Function: gf_media_import()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
```
2.5-DEV-rev1570-g6208015df-master
Commit: 6208015dff3a6735a26e413c484c714666eb3ea2
```

Attack Conditions:
An attacker supplies a crafted input file that is processed by MP4Box. The issue can be reproduced locally with:
```
./MP4Box -info 38_gf_media_import_media_tools_media_import_c_1297
```

The prepared CVSS vector:
```
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
```

Impact:
denial of service via application crash; local triage notes also identify potential code execution risk

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
bd7fd6be546e0cd9e599c6b262c338c5f2ecec5c
```
Users should update to a GPAC build containing this commit or later.

References:
- Issue: github.com/gpac/gpac/issues/32
- Fix: github.com/gpac/gpac/commit/bd
- PoC: github.com/sigdevel/pocs/blob/
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

CVE-2026-48772
(0 None)

EPSS: 0.18%

1 posts

N/A

offseq@infosec.exchange at 2026-06-20T04:30:25.000Z ##

CVE-2026-48772 (CRITICAL): ProxySQL 2.0.0 – 3.0.8 lets attackers spoof source IPs via PROXY protocol v1, bypassing routing & ACLs. Upgrade to 3.0.9 or later. Restrict frontend port access. Details: radar.offseq.com/threat/cve-20 #OffSeq #ProxySQL #CVE202648772 #Security

##

CVE-2025-60473
(0 None)

EPSS: 0.00%

1 posts

N/A

sigdevel@infosec.exchange at 2026-06-20T04:09:34.000Z ##

Security Advisory: CVE-2025-60473 - NULL Pointer Dereference in GPAC MP4Box Filter Parent Chain

Processing a crafted media file with MP4Box `-info` can trigger a NULL pointer dereference in `gf_filter_in_parent_chain()`, causing a Denial of Service.

Summary:
The `gf_filter_in_parent_chain()` function in `filter_core/filter_pid.c` does not sufficiently validate a parent filter pointer before dereferencing it. When MP4Box processes a specially crafted media file with malformed MPEG-2 TS data and a corrupted PID/filter chain, the vulnerable path can attempt to read from address `0x000000000008`.

CWE:
CWE-476 - NULL Pointer Dereference

Affected Component:
```
filter_core/filter_pid.c:2145
Function: gf_filter_in_parent_chain()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:
```
GPAC version: 2.5-DEV-rev1570-g6208015df-master
Commit: 6208015dff3a6735a26e413c484c714666eb3ea2
```

The MITRE response states that GPAC Project/MP4Box before `26.02.0` is affected. Builds before the fix commit `b8d80b44718de10b101e1d7fc17c84d69feb092e` should be considered affected if they contain the vulnerable filter parent-chain validation path.

Attack Conditions:
An attacker supplies a crafted media file with malformed MPEG-2 TS packet data and a corrupted PID/filter chain. The issue can be reproduced locally with:
```
./MP4Box -info 36_gf_filter_in_parent_chain_filter_core_filter_pid_c_2145
```

No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

The prepared CVSS vector:
```
AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
```

Impact:
The immediate observed impact is Denial of Service due to process termination. The local MITRE/BDU data also notes potential arbitrary code execution, although the available ASAN evidence shows a NULL pointer dereference crash.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
b8d80b44718de10b101e1d7fc17c84d69feb092e
```

Users should update to a GPAC build containing this commit or later. The affected filter graph code should validate parent filter pointers before dereferencing them during PID initialization.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/b8
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

CVE-2025-60466
(0 None)

EPSS: 0.00%

1 posts

N/A

sigdevel@infosec.exchange at 2026-06-20T03:52:04.000Z ##

Security Advisory: CVE-2025-60466 - Expired Pointer Dereference in GPAC MP4Box Packet Retrieval

Processing a crafted media file with MP4Box `-info` can trigger an expired pointer dereference in `gf_filter_pid_get_packet()`, causing a heap use-after-free crash and potential code execution.

Summary:
The `gf_filter_pid_get_packet()` function in `filter_core/filter_pid.c` may operate on an invalidated Packet ID (PID) object after it has been freed by `gf_filter_pid_del()`. When MP4Box processes a specially crafted media file through the filter graph, the `inspect` filter can request packets from a stale PID object, leading to access to freed heap memory.

CWE:
CWE-825 - Expired Pointer Dereference

Affected Component:
```
filter_core/filter_pid.c:6827
Function: gf_filter_pid_get_packet()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:
```
GPAC version: 2.5-DEV-rev1570-g6208015df-master
Commit: 6208015dff3a6735a26e413c484c714666eb3ea2
```

The MITRE response states that GPAC Project/MP4Box before `26.02.0` is affected. Builds before the fix commit `4a7ea06dd1b2cc65fe0dabc60189eb6bc814f7bb` should be considered affected if they contain the vulnerable PID packet retrieval path.

Attack Conditions:
An attacker supplies a crafted media file that is processed by MP4Box through the info/import path and drives the inspect/filter pipeline through PID deletion and packet retrieval paths. The issue can be reproduced locally with:

```
./MP4Box -info 35_gf_filter_pid_get_packet_filter_core_filter_pid_c_6827
```
No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

The prepared CVSS vector in the local BDU data is:
```
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
```

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is a heap use-after-free / expired pointer dereference, memory corruption and potential arbitrary code execution are possible.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
4a7ea06dd1b2cc65fe0dabc60189eb6bc814f7bb
```

Users should update to a GPAC build containing this commit or later. The fix adds checks to ignore tasks when PID or filter objects have been removed or finalized, preventing stale object use.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/4a
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

CVE-2025-60465
(0 None)

EPSS: 0.00%

1 posts

N/A

sigdevel@infosec.exchange at 2026-06-19T19:46:49.000Z ##

Security Advisory: CVE-2025-60465 - Use-After-Free in GPAC MP4Box PID Instance Swap

Processing a crafted media file with MP4Box `-info` can trigger a heap use-after-free in `gf_filter_pid_inst_swap()`, causing a crash and potential code execution.

Summary:
The `gf_filter_pid_inst_swap()` function in `filter_core/filter_pid.c` does not reset `ctx->pid_inst` to NULL after freeing the PID instance. Subsequent PID configuration and reconfiguration steps can reuse this dangling pointer, leading to access to freed heap memory.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filter_core/filter_pid.c:633
Function: gf_filter_pid_inst_swap()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:
```
GPAC version: 2.5-DEV-rev1570-g6208015df-master
Commit: 6208015dff3a6735a26e413c484c714666eb3ea2
```
The MITRE response states that GPAC Project/MP4Box before `26.02.0` is affected. Builds before the fix commit `55b351bd078c950592544ab4c708a613c1725b9b` should be considered affected if they contain the vulnerable PID instance swap path.

Attack Conditions:
An attacker supplies a crafted media or MPEG-2 TS input that is processed by MP4Box through the info/import path and triggers filter PID reconfiguration. The issue can be reproduced locally with:
```
./MP4Box -info 34_gf_filter_pid_inst_swap_filter_core_filter_pid_c_633
```

No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

The prepared CVSS vector in the local BDU data is:
```
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
```

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is a heap use-after-free, memory corruption and potential arbitrary code execution are possible.

Fix / mitigation status:
The issue was fixed in GPAC commit:
```
55b351bd078c950592544ab4c708a613c1725b9b
```
Users should update to a GPAC build containing this commit or later. The affected PID instance swap path should clear `ctx->pid_inst` after freeing it and avoid later use of stale PID object pointers.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/55
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

CVE-2025-60464
(0 None)

EPSS: 0.00%

1 posts

N/A

sigdevel@infosec.exchange at 2026-06-19T19:15:28.000Z ##

Security Advisory: CVE-2025-60464 - Use-After-Free in GPAC MP4Box SEI State Handling

Processing a crafted MPEG-2 TS file with MP4Box `-info` can trigger a heap use-after-free in `gf_sei_load_from_state_internal()`, causing a crash and potential code execution.

Summary:
The `gf_sei_load_from_state_internal()` function in `filters/sei_load.c` can access codec/SEI state after the related heap buffer has been freed by the NALU demuxer setup path. When MP4Box processes a specially crafted MPEG-2 Transport Stream file containing malformed AVC/HEVC/VVC NAL units and corrupted PMT descriptors, `naludmx_configure_pid()` can release a state buffer that is later read during SEI state loading.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filters/sei_load.c:225
Function: gf_sei_load_from_state_internal()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
The issue was reproduced on:
```
GPAC version: 2.5-DEV-rev1557-g62714f27c-master
Commit: 62714f27c64a3d1eb7e880f9eed2d38673cb43ce
```

The MITRE response states that GPAC Project/MP4Box before `26.02.0` is affected. Builds before the fix commit `8f404bd581e455267482f86272169a742f654b97` should be considered affected if they contain the vulnerable SEI state handling path.

Attack Conditions:
An attacker supplies a crafted MPEG-2 TS file containing malformed AVC/HEVC/VVC bitstream data, corrupted PMT descriptors, and invalid NAL/SEI state. The issue can be reproduced locally with:
```
./MP4Box -info 32_filters_sei_load_c_225_in_gf_sei_load_from_state_internal
```

No elevated privileges are required. User interaction is required when the victim manually processes the malicious file, or an automated media workflow invokes MP4Box on attacker-controlled input.

The prepared CVSS vector in the local BDU data is:

```
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
```

Impact:
The immediate observed impact is Denial of Service due to process termination. Because the vulnerability is a heap use-after-free, memory corruption and potential arbitrary code execution are possible.

Fix / mitigation status:
The issue was fixed in GPAC commit:

```
8f404bd581e455267482f86272169a742f654b97
```
Users should update to a GPAC build containing this commit or later. The affected SEI/NALU handling path should ensure state buffers remain valid before SEI parsing reads from them.

References:

- Issue: github.com/gpac/gpac/issues/32
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/8f
- CVE record: cve.org/CVERecord?id=CVE-2025-

Credit
Alexander A. Shvedov (@sigdevel)

#fuzzing #infosec #security #aflplusplus #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory #media #gpac

##

CVE-2026-49252
(0 None)

EPSS: 0.27%

1 posts

N/A

offseq@infosec.exchange at 2026-06-19T03:00:30.000Z ##

deepstream.io <10.0.5 has a CRITICAL Prototype Pollution flaw (CVE-2026-49252, CVSS 9.9). Authenticated users with write access can escalate privileges. Patch to 10.0.5+ ASAP! radar.offseq.com/threat/cve-20 #OffSeq #CVE202649252 #deepstreamio #infosec

##

CVE-2026-49454
(0 None)

EPSS: 0.14%

1 posts

N/A

offseq@infosec.exchange at 2026-06-19T01:30:26.000Z ##

CVE-2026-49454: szTheory relyra (<1.2.0) has a CRITICAL SAML authentication flaw — improper signature verification lets attackers forge responses & impersonate users. Fixed in v1.2.0. Patch now! radar.offseq.com/threat/cve-20 #OffSeq #CVE202649454 #SAML #Elixir #InfoSec

##

CVE-2026-49257
(0 None)

EPSS: 0.50%

1 posts

N/A

offseq@infosec.exchange at 2026-06-18T21:30:12.000Z ##

CVE-2026-49257: startreedata mcp-pinot <=3.0.1 has a CRITICAL auth bypass. MCP server exposes full read/write access to Pinot clusters on 0.0.0.0:8080. Upgrade to 3.1.0 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #CVE202649257 #Infosec

##

CVE-2026-55074
(0 None)

EPSS: 0.00%

1 posts

N/A

Larvitz@burningboard.net at 2026-06-18T20:21:44.000Z ##

I'm more than 25 years into IT at this point, but this is a first for me. Not one I'm proud of, but one I take responsibility for:

My project ansible_jailexec (an Ansible connection plugin for FreeBSD Jails) had a bug that turned out to be a vulnerability. Improper Link Resolution Before File Access (CWE-59), a jail escape. It's been assigned CVE-2026-55074 so people can scan for it (I know it's bundled into Collections out there).

If you're running < 2.0.0: please upgrade. 2.0.0 fixes it.

Advisory: github.com/chofstede/ansible_j
Release: github.com/chofstede/ansible_j

#ansible #cve #security #freebsd

##

CVE-2026-47846
(0 None)

EPSS: 0.34%

1 posts

N/A

offseq@infosec.exchange at 2026-06-18T20:00:13.000Z ##

Bitnami Cassandra container images (4.0.0, 4.1.0, 5.0.0) have a CRITICAL flaw (CVE-2026-47846): default cassandra:cassandra superuser may remain after custom admin setup. Update urgently! radar.offseq.com/threat/cve-20 #OffSeq #Cassandra #Vuln #CloudSecurity

##

Visit counter For Websites