## Updated at UTC 2026-08-10T10:18:35.240854

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-18786 0 0.00% 2 0 2026-08-10T07:16:50.487000 The CheckView WordPress plugin before 2.3.2 does not restrict its REST API auth
CVE-2026-16985 0 0.00% 2 0 2026-08-10T07:16:48.380000 The Squeeze WordPress plugin before 1.7.12 does not validate the file type or e
CVE-2026-19389 7.1 0.00% 2 0 2026-08-10T03:16:40.380000 Multiple integer overflow and underflow vulnerabilities were found in the GStrea
CVE-2026-19387 7.6 0.00% 2 0 2026-08-10T03:16:40.223000 A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-
CVE-2026-19381 7.8 0.00% 4 0 2026-08-10T01:16:48.367000 A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2
CVE-2026-15534 0 0.00% 2 0 2026-08-09T22:16:30.373000 Perl versions through 5.45.1 have out-of-bounds heap reads and writes during reg
CVE-2026-19348 9.8 0.00% 4 0 2026-08-09T12:32:52 A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea
CVE-2026-19346 8.8 0.00% 2 0 2026-08-09T10:17:10.567000 A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects
CVE-2026-19341 8.8 0.44% 1 0 2026-08-09T09:30:29 A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-17030
CVE-2026-19195 7.8 0.11% 2 1 2026-08-09T06:32:38 A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affec
CVE-2026-10595 7.5 0.49% 1 0 2026-08-09T06:31:42 A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specific
CVE-2026-15038 None 0.19% 1 1 2026-08-09T06:31:36 The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify th
CVE-2026-64561 8.8 0.12% 3 6 2026-08-09T06:31:34 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: C
CVE-2026-19193 7.8 0.11% 2 1 2026-08-09T06:19:12.620000 A flaw has been found in Jiangmin Antivirus 21. Impacted is the function Message
CVE-2026-64564 9.8 0.48% 10 3 2026-08-09T04:17:43.283000 In the Linux kernel, the following vulnerability has been resolved: sctp: don't
CVE-2026-71993 9.8 1.35% 4 0 2026-08-09T00:31:13 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71986 9.8 1.35% 3 0 2026-08-09T00:31:13 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71990 9.8 1.35% 2 0 2026-08-09T00:31:13 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71992 9.8 1.35% 2 0 2026-08-09T00:31:13 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71985 9.8 1.35% 1 0 2026-08-09T00:31:13 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71984 9.8 1.35% 1 0 2026-08-09T00:31:13 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71987 9.8 1.35% 4 0 2026-08-09T00:31:07 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71988 9.8 1.35% 3 0 2026-08-09T00:31:07 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71991 9.8 1.35% 2 0 2026-08-09T00:16:48.270000 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71989 9.8 1.35% 2 0 2026-08-09T00:16:47.953000 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71983 9.8 1.62% 1 0 2026-08-08T23:16:56.967000 MSI Radix AXE6600 router firmware version v781521 contains a command injection v
CVE-2026-71953 9.8 2.09% 1 0 2026-08-08T18:30:30 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71955 9.8 2.13% 1 0 2026-08-08T18:30:30 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CVE-2026-71954 9.8 2.13% 1 0 2026-08-08T18:30:30 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71950 9.8 2.09% 2 0 2026-08-08T18:30:29 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71945 9.8 2.09% 1 0 2026-08-08T18:30:29 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71944 9.8 2.09% 1 0 2026-08-08T18:30:29 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71952 9.8 2.09% 1 0 2026-08-08T18:30:29 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71948 9.8 2.09% 1 0 2026-08-08T18:30:29 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71957 9.8 0.59% 1 0 2026-08-08T18:30:29 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CVE-2026-71956 9.8 1.74% 1 0 2026-08-08T18:30:29 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CVE-2026-42170 7.8 0.19% 1 0 2026-08-08T18:30:29 A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Su
CVE-2026-71946 9.8 2.09% 1 0 2026-08-08T18:30:25 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71958 9.8 0.56% 1 0 2026-08-08T18:16:56.783000 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2
CVE-2026-71951 9.8 2.09% 1 0 2026-08-08T18:16:55.907000 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71949 9.8 2.09% 1 0 2026-08-08T18:16:55.660000 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-71947 9.8 2.09% 2 0 2026-08-08T18:16:55.410000 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1
CVE-2026-67620 7.7 0.43% 1 1 2026-08-08T16:16:49.420000 Flowise through 3.1.4 contains a server-side request forgery vulnerability in th
CVE-2026-14526 9.8 0.61% 3 0 2026-08-08T09:30:28 The AI Copilot – Content Generator plugin for WordPress is vulnerable to authori
CVE-2026-16948 None 0.13% 1 0 2026-08-08T09:30:28 The Solace Extra WordPress plugin before 1.6.1 does not perform capability check
CVE-2026-16955 0 0.16% 1 0 2026-08-08T07:17:11.440000 The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied
CVE-2026-16594 0 0.14% 1 0 2026-08-08T07:17:10.910000 The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorizatio
CVE-2026-8037 9.6 99.31% 5 2 template 2026-08-08T05:17:10.403000 OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC
CVE-2026-56793 7.7 0.31% 2 0 2026-08-08T05:17:09.880000 Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Im
CVE-2026-71851 9.0 0.32% 2 0 2026-08-08T04:17:55.850000 crypto-js is a JavaScript library of crypto standards. Versions of crypto-js pri
CVE-2026-71560 9.1 0.55% 1 0 2026-08-08T03:32:14 Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue
CVE-2026-71558 9.8 0.71% 1 0 2026-08-08T03:32:14 Heap type confusion vulnerability in Apache Fory C++ deserialization. This issu
CVE-2026-70558 9.8 0.60% 2 0 2026-08-08T03:16:46.910000 Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied pa
CVE-2026-5857 8.1 0.53% 2 0 2026-08-08T03:16:46.377000 Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c se
CVE-2026-19192 7.8 0.11% 1 0 2026-08-08T03:16:45.610000 A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affec
CVE-2026-52878 7.5 0.28% 1 0 2026-08-07T23:17:04.593000 Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1
CVE-2026-46409 9.6 0.36% 1 0 2026-08-07T23:17:03.243000 OpenYak is a local-first agent runtime for reliable tool-using models, with a de
CVE-2026-48170 9.1 0.25% 3 0 2026-08-07T22:16:59.170000 `scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs p
CVE-2026-16258 9.8 0.47% 1 0 2026-08-07T21:31:37 The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deseri
CVE-2026-16263 8.8 0.34% 1 0 2026-08-07T21:31:36 The WP Maps WordPress plugin before 4.9.7 does not perform a capability check i
CVE-2025-63235 7.5 0.32% 1 0 2026-08-07T21:30:40 In sol commit 373d848 (2024-12-12), the broker does not fully release resources
CVE-2026-15972 7.5 0.39% 1 0 2026-08-07T21:30:40 Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerab
CVE-2026-64636 7.7 0.21% 1 0 2026-08-07T21:30:37 An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Win
CVE-2026-15215 8.8 0.35% 1 0 2026-08-07T21:30:33 The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify
CVE-2026-16041 7.5 0.21% 1 0 2026-08-07T21:30:33 The MStore API WordPress plugin before 4.21.0 does not perform authorization or
CVE-2026-50540 9.6 0.38% 1 0 2026-08-07T21:17:28.827000 Kata Containers is an open source project focusing on a standard implementation
CVE-2026-19082 7.5 0.29% 1 0 2026-08-07T21:17:27.317000 Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap byte
CVE-2026-48169 8.8 0.26% 1 0 2026-08-07T21:16:58 ### Summary The PraisonAI Platform API has two authorization failures that toge
CVE-2026-48039 9.1 0.34% 2 0 2026-08-07T19:29:59 # Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token | Fi
CVE-2026-50481 9.9 0.46% 2 0 2026-08-07T19:29:09.813000 Modification of assumed-immutable data (maid) in Azure Active Directory allows a
CVE-2026-64638 0 0.77% 10 19 template 2026-08-07T19:18:51.610000 WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login s
CVE-2026-20346 7.5 0.33% 1 0 2026-08-07T19:17:41.360000 A vulnerability in the PDF file format parser of ClamAV could allow an unauthent
CVE-2026-16262 7.5 0.16% 1 0 2026-08-07T19:17:37.053000 The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its O
CVE-2026-16038 9.1 0.24% 1 0 2026-08-07T19:17:36.110000 The MStore API WordPress plugin before 4.21.0 does not verify the payment with
CVE-2026-15361 8.1 0.22% 1 0 2026-08-07T19:17:35.543000 The Content Views WordPress plugin before 4.5 does not perform a capability che
CVE-2026-59118 9.3 0.39% 1 0 2026-08-07T19:06:49.530000 Improper authorization in Microsoft Power Apps allows an unauthorized attacker t
CVE-2026-16030 8.1 0.23% 2 0 2026-08-07T18:32:49 The MStore API WordPress plugin before 4.21.0 does not correctly verify the cry
CVE-2026-71559 7.5 0.59% 1 0 2026-08-07T18:32:49 Deserialization of Untrusted Data vulnerability in the Go implementation of Apac
CVE-2026-67688 9.8 0.59% 2 0 2026-08-07T18:32:48 ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload
CVE-2026-67687 8.8 0.53% 2 1 2026-08-07T18:32:48 Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to
CVE-2026-70634 8.1 0.41% 2 0 2026-08-07T18:32:48 TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds r
CVE-2026-14943 7.5 0.26% 1 0 2026-08-07T18:32:48 The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial
CVE-2026-14205 9.8 0.27% 1 0 2026-08-07T18:32:48 The WP Events Manager WordPress plugin before 2.2.5 does not validate the reques
CVE-2026-64637 9.9 0.23% 2 0 2026-08-07T18:31:57 Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows
CVE-2026-20339 7.5 0.33% 2 0 2026-08-07T18:31:54 A vulnerability in the PESpin file format parser of ClamAV could allow an unauth
CVE-2026-20348 7.5 0.33% 1 0 2026-08-07T18:31:54 A vulnerability in the XAR file format parser of ClamAV could allow an unauthent
CVE-2026-20345 7.5 0.33% 1 0 2026-08-07T18:31:54 A vulnerability in the GPT file format parser of ClamAV could allow an unauthent
CVE-2026-20338 7.5 0.33% 2 0 2026-08-07T18:31:53 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat
CVE-2026-20347 7.5 0.33% 1 0 2026-08-07T18:31:53 A vulnerability in the Mach-O file format parser of ClamAV could allow an unauth
CVE-2026-68772 8.0 0.40% 1 0 2026-08-07T18:31:53 ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMa
CVE-2026-20337 7.5 0.36% 3 0 2026-08-07T18:31:52 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat
CVE-2026-67621 7.6 0.27% 2 0 2026-08-07T18:31:42 Flowise through 3.1.4 contains a missing authorization vulnerability that allows
CVE-2026-70628 7.8 0.15% 2 0 2026-08-07T18:31:42 FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer
CVE-2026-70632 7.8 0.21% 2 0 2026-08-07T18:31:42 FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds
CVE-2026-67622 9.9 0.25% 2 0 2026-08-07T18:31:41 Flowise through 3.1.4 contains an insecure direct object reference vulnerability
CVE-2026-15733 9.8 3.90% 2 0 2026-08-07T18:31:37 A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 a
CVE-2026-67422 7.5 0.58% 2 0 2026-08-07T18:26:08 ### Summary Four inline processors in pymdown-extensions contain regular expres
CVE-2026-53984 9.1 0.38% 2 0 2026-08-07T18:17:18.960000 Ground Station prior to 0.6.0 contains an unauthenticated database-destruction a
CVE-2026-45198 7.8 0.12% 2 0 2026-08-07T18:17:14.827000 Kernel software from a non-secure operating system on a platform with Trusted Ex
CVE-2026-14365 9.8 0.31% 2 0 2026-08-07T18:17:07.753000 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress i
CVE-2026-65667 10.0 0.44% 1 0 2026-08-07T18:11:23.330000 Missing authorization in Microsoft Teams allows an unauthorized attacker to elev
CVE-2026-50515 9.9 0.91% 2 0 2026-08-07T18:05:55.493000 Deserialization of untrusted data in Azure Service Bus allows an authorized atta
CVE-2026-5855 7.5 0.54% 2 0 2026-08-07T17:17:05.047000 Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c
CVE-2026-9169 8.8 0.14% 1 0 2026-08-07T16:17:28.807000 DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows a
CVE-2026-53983 8.6 0.33% 2 0 2026-08-07T16:17:25.673000 Ground Station prior to 0.6.0 contains an unauthenticated blind server-side requ
CVE-2026-49007 7.5 0.34% 1 0 2026-08-07T16:17:25.380000 By accessing unencrypted information in the device firmware, an attacker can obt
CVE-2026-48085 9.8 0.55% 2 0 2026-08-07T16:17:24.773000 OpenReception's appointment booking software provides an end-to-end encrypted ap
CVE-2026-67689 9.8 0.69% 2 1 2026-08-07T15:34:17 SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execut
CVE-2026-19264 9.8 0.63% 1 1 2026-08-07T15:33:32 Postiz is an open-source social media scheduling tool. The route that serves loc
CVE-2026-54212 0 0.47% 1 0 2026-08-07T15:17:01.830000 Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint
CVE-2026-15816 7.5 0.25% 1 0 2026-08-07T12:32:06 A flaw was found in dracut. The die() error-handling function writes its message
CVE-2026-54213 None 0.45% 1 0 2026-08-07T12:32:06 Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality tha
CVE-2026-54211 None 0.41% 1 0 2026-08-07T12:32:00 Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_
CVE-2026-14364 9.8 0.29% 2 0 2026-08-07T06:30:34 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress i
CVE-2026-19191 7.8 0.11% 1 0 2026-08-07T06:30:26 A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. T
CVE-2026-19190 7.8 0.14% 2 0 2026-08-07T06:30:25 A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an
CVE-2026-65400 7.1 0.30% 1 0 2026-08-07T03:31:32 An authentication issue was addressed with improved state management. This issue
CVE-2026-19189 7.8 0.11% 2 0 2026-08-07T03:30:38 A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected
CVE-2026-63508 10.0 0.44% 2 0 2026-08-07T00:31:33 Missing authentication for critical function in Microsoft Planetary Computer Pro
CVE-2026-62873 9.8 0.34% 1 0 2026-08-07T00:31:33 Improper verification of cryptographic signature in Microsoft 365 Admin Center a
CVE-2026-49163 8.8 0.62% 2 0 2026-08-07T00:31:28 Improper limitation of a pathname to a restricted directory ('path traversal') i
CVE-2026-56161 9.6 0.38% 2 0 2026-08-07T00:31:28 Improper access control in Azure Logic Apps allows an authorized attacker to dis
CVE-2026-59115 9.9 0.64% 1 0 2026-08-07T00:31:28 '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an autho
CVE-2026-70559 7.5 0.33% 2 1 2026-08-07T00:31:27 Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carri
CVE-2026-56162 10.0 0.48% 3 0 2026-08-07T00:31:27 Improper authentication in Azure SQL Database allows an unauthorized attacker to
CVE-2026-62836 8.7 0.36% 1 0 2026-08-07T00:31:27 Improper restriction of communication channel to intended endpoints in Azure SQL
CVE-2026-16633 None 0.00% 1 0 2026-08-06T21:12:27 ### Impact If PDF.js is used to load a malicious PDF, and PDF.js is configured
CVE-2026-64665 8.1 0.31% 2 0 2026-08-06T19:25:06 ### Impact When OAuth login is enabled with a provider that does not guarantee
CVE-2026-19036 7.2 2.47% 2 0 2026-08-06T15:32:48 A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the
CVE-2026-19034 7.2 2.47% 2 0 2026-08-06T12:31:21 A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vuln
CVE-2026-19035 7.2 2.47% 2 0 2026-08-06T12:31:21 A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issu
CVE-2026-5430 10.0 0.22% 1 0 2026-08-06T09:30:40 The JWT authentication mechanism accepts tokens signed with algorithms other tha
CVE-2026-17650 8.3 0.35% 2 0 2026-08-06T00:36:25.360000 Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a
CVE-2026-17656 9.6 0.40% 2 0 2026-08-06T00:30:24.850000 Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote
CVE-2026-63077 9.8 1.01% 2 4 template 2026-08-05T18:32:31 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-70374 8.8 2.52% 2 0 2026-08-05T15:32:14 HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-
CVE-2026-66747 9.8 0.58% 1 0 2026-08-05T15:17:04.690000 Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS,
CVE-2026-18902 7.2 2.38% 2 0 2026-08-05T06:30:32 A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerabilit
CVE-2026-18900 7.2 2.38% 2 0 2026-08-05T06:30:31 A weakness has been identified in H3C NX15 V100R017. This impacts the function f
CVE-2026-18814 7.2 2.71% 2 0 2026-08-05T00:30:41 A vulnerability was found in H3C NX15 V100R017. This impacts the function reload
CVE-2026-9198 9.8 17.05% 1 4 2026-08-04T21:30:25 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain
CVE-2026-64633 None 0.34% 1 1 2026-08-04T18:31:36 A vulnerability allowing remote unauthenticated code execution on the agent host
CVE-2026-18577 8.1 4.10% 1 2 2026-08-04T15:33:20 An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco
CVE-2026-29146 7.5 6.26% 1 0 2026-08-04T13:18:02.797000 Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default
CVE-2024-49039 8.8 13.72% 1 2 2026-08-04T05:16:30.980000 Windows Task Scheduler Elevation of Privilege Vulnerability
CVE-2026-18686 9.8 2.61% 2 0 2026-08-04T00:35:01 A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected elem
CVE-2026-18601 9.8 2.38% 2 0 2026-08-03T15:32:55 A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the fun
CVE-2026-64531 7.8 0.13% 1 4 2026-08-01T09:30:23 In the Linux kernel, the following vulnerability has been resolved: net: openvs
CVE-2026-28323 9.8 0.64% 1 0 2026-07-30T18:31:47 SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass
CVE-2026-64560 7.8 0.12% 3 1 2026-07-30T12:19:03.630000 In the Linux kernel, the following vulnerability has been resolved: posix-cpu-t
CVE-2025-68260 7.8 0.16% 1 0 2026-07-30T06:33:30 In the Linux kernel, the following vulnerability has been resolved: rust_binder
CVE-2026-60206 9.9 0.49% 1 4 2026-07-28T14:14:37.463000 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware
CVE-2025-68686 5.9 1.26% 1 0 2026-07-28T05:17:04.113000 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE
CVE-2026-60667 7.4 0.33% 1 0 2026-07-24T21:32:15 Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle
CVE-2026-65535 4.3 0.18% 1 0 2026-07-23T14:17:59.510000 Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
CVE-2026-34348 6.5 0.71% 1 0 2026-07-14T18:31:58 Protection mechanism failure in Windows Event Logging Service allows an authoriz
CVE-2026-0288 7.5 0.84% 1 0 2026-07-10T15:45:17.463000 Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (T
CVE-2025-8088 8.8 94.55% 1 31 2026-06-17T10:06:17.243000 A path traversal vulnerability affecting the Windows version of WinRAR allows th
CVE-2024-43451 6.5 81.82% 1 2 2026-06-17T07:51:04.273000 NTLM Hash Disclosure Spoofing Vulnerability
CVE-2024-38193 7.8 27.56% 1 1 2026-06-17T07:39:39.247000 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerabili
CVE-2024-38178 7.5 41.38% 1 0 2026-06-17T07:39:37.397000 Scripting Engine Memory Corruption Vulnerability
CVE-2024-36971 7.8 2.70% 1 1 2026-06-17T07:37:30.630000 In the Linux kernel, the following vulnerability has been resolved: net: fix __
CVE-2026-52880 7.5 0.29% 1 0 2026-06-09T18:40:45 ### Summary The Klever seednode REST API starts a Gin engine with `Engine.Run(r
CVE-2026-52879 7.5 0.29% 1 0 2026-06-09T18:40:42 ### Summary `networkMessenger.directMessageHandler` in `network/p2p/libp2p/netM
CVE-2026-34486 7.5 81.16% 1 6 2026-06-08T23:28:56 Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the f
CVE-2026-47249 7.5 0.28% 1 0 2026-06-05T15:27:42 ### Summary A connected peer can send a compressed `RequestDataType_HashArrayTyp
CVE-2026-28299 8.2 0.49% 1 0 2026-06-02T21:30:50 SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerab
CVE-2026-20685 6.5 0.19% 1 1 2026-05-18T18:31:37 An attacker in a privileged network position may be able to leak sensitive infor
CVE-2026-41679 10.0 2.95% 1 1 2026-04-27T16:19:05 ## Summary An unauthenticated attacker can achieve full remote code execution o
CVE-2024-23692 9.8 99.47% 1 14 2025-10-22T00:34:06 Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a t
CVE-2025-42999 9.1 11.28% 1 1 2025-10-22T00:33:19 SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged
CVE-2025-36852 None 0.20% 1 0 2025-10-14T19:17:03 A critical security vulnerability exists in remote cache extensions for common b
CVE-2021-26708 7.0 1.60% 1 3 2023-11-18T05:04:48 A local privilege escalation was discovered in the Linux kernel before 5.10.13.
CVE-2015-6609 None 2.17% 1 0 2023-01-27T05:08:18 libutils in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote
CVE-2026-63637 0 0.24% 2 0 N/A
CVE-2026-62296 0 0.28% 2 0 N/A
CVE-2026-60004 0 0.00% 1 8 template N/A
CVE-2026-48097 0 0.27% 1 0 N/A
CVE-2026-65819 0 0.37% 1 0 N/A
CVE-2026-48026 0 0.22% 1 0 N/A
CVE-2026-48120 0 0.14% 1 0 N/A
CVE-2026-62295 0 0.28% 1 0 N/A
CVE-2026-61808 0 0.34% 1 0 N/A
CVE-2026-33691 0 3.58% 1 0 N/A
CVE-2026-48024 0 0.00% 1 0 N/A
CVE-2026-48162 0 0.00% 1 0 N/A
CVE-2026-49441 0 0.00% 1 0 N/A
CVE-2026-18576 0 0.00% 1 0 N/A

CVE-2026-18786
(0 None)

EPSS: 0.00%

updated 2026-08-10T07:16:50.487000

2 posts

The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose URI merely contains a CheckView WordPress plugin before 2.3.2-specific string, making it possible for unauthenticated attackers to bypass the REST nonce check and perform any REST action available to

offseq at 2026-08-10T07:30:27.175Z ##

CVE-2026-18786: CRITICAL auth bypass in CheckView WP plugin ≤2.0.29. Attackers can exploit REST API via crafted links to perform admin actions if an admin clicks. Restrict plugin REST API & avoid suspicious links. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-10T07:30:27.000Z ##

CVE-2026-18786: CRITICAL auth bypass in CheckView WP plugin ≤2.0.29. Attackers can exploit REST API via crafted links to perform admin actions if an admin clicks. Restrict plugin REST API & avoid suspicious links. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202618786

##

CVE-2026-16985
(0 None)

EPSS: 0.00%

updated 2026-08-10T07:16:48.380000

2 posts

The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-update actions, allowing users with the upload_files capability (Author and above) to write an executable PHP file into the uploads directory and achieve remote code execution.

offseq at 2026-08-10T09:00:24.787Z ##

CVE-2026-16985: Squeeze WP plugin <1.7.12 has a CRITICAL vuln — users with upload_files can upload PHP files, enabling remote code execution. Restrict permissions, monitor uploads, and check for updates. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-10T09:00:24.000Z ##

CVE-2026-16985: Squeeze WP plugin <1.7.12 has a CRITICAL vuln — users with upload_files can upload PHP files, enabling remote code execution. Restrict permissions, monitor uploads, and check for updates. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026_16985 #infosec

##

CVE-2026-19389
(7.1 HIGH)

EPSS: 0.00%

updated 2026-08-10T03:16:40.380000

2 posts

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information

offseq at 2026-08-10T04:30:27.657Z ##

GStreamer gst-plugins-ugly (asfdemux) in Red Hat Enterprise Linux 10 is affected by CVE-2026-19389 (HIGH, CVSS 7.1). Parsing crafted ASF/WMV/WMA files may lead to DoS or info leaks. No patch yet — avoid untrusted media. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-10T04:30:27.000Z ##

GStreamer gst-plugins-ugly (asfdemux) in Red Hat Enterprise Linux 10 is affected by CVE-2026-19389 (HIGH, CVSS 7.1). Parsing crafted ASF/WMV/WMA files may lead to DoS or info leaks. No patch yet — avoid untrusted media. radar.offseq.com/threat/cve-20 #OffSeq #Linux #CVE #GStreamer

##

CVE-2026-19387
(7.6 HIGH)

EPSS: 0.00%

updated 2026-08-10T03:16:40.223000

2 posts

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code ex

thehackerwire@mastodon.social at 2026-08-10T03:59:51.000Z ##

🟠 CVE-2026-19387 - High (7.6)

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T03:59:51.000Z ##

🟠 CVE-2026-19387 - High (7.6)

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19381
(7.8 HIGH)

EPSS: 0.00%

updated 2026-08-10T01:16:48.367000

4 posts

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper privilege management. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The vendor was contacted e

thehackerwire@mastodon.social at 2026-08-10T01:59:49.000Z ##

🟠 CVE-2026-19381 - High (7.8)

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper privilege m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-10T01:30:28.432Z ##

Kingston FURY CTRL RGB Control Software v2.0.65.0 hit by HIGH severity vuln (CVE-2026-19381, CVSS 8.5). Local attackers can escalate privileges via NTIOLib_KSFX.sys. Exploit code is public; no patch yet. Restrict local access, monitor systems. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-10T01:59:49.000Z ##

🟠 CVE-2026-19381 - High (7.8)

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper privilege m...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-10T01:30:28.000Z ##

Kingston FURY CTRL RGB Control Software v2.0.65.0 hit by HIGH severity vuln (CVE-2026-19381, CVSS 8.5). Local attackers can escalate privileges via NTIOLib_KSFX.sys. Exploit code is public; no patch yet. Restrict local access, monitor systems. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Kingston

##

CVE-2026-15534
(0 None)

EPSS: 0.00%

updated 2026-08-09T22:16:30.373000

2 posts

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the sig

offseq at 2026-08-10T03:00:24.763Z ##

CVE-2026-15534: HIGH severity in LEONT perl (≤5.45.1) — Integer overflow in regex engine can cause heap corruption or crashes when large inputs and crafted patterns are processed. Avoid risky patterns until patched. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-10T03:00:24.000Z ##

CVE-2026-15534: HIGH severity in LEONT perl (≤5.45.1) — Integer overflow in regex engine can cause heap corruption or crashes when large inputs and crafted patterns are processed. Avoid risky patterns until patched. radar.offseq.com/threat/cve-20 #OffSeq #Perl #Vuln #AppSec

##

CVE-2026-19348
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-09T12:32:52

4 posts

A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be us

thehackerwire@mastodon.social at 2026-08-09T12:00:26.000Z ##

🔴 CVE-2026-19348 - Critical (9.8)

A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-08-09T12:00:24.211Z ##

CVE-2026-19348 in Shenzhen Aitemi M300 Wi-Fi Repeater: CRITICAL command injection via /protocol.csp (enable, name, mac). Public exploit code out; no patch yet. Restrict access & monitor traffic. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-08-09T12:00:26.000Z ##

🔴 CVE-2026-19348 - Critical (9.8)

A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-09T12:00:24.000Z ##

CVE-2026-19348 in Shenzhen Aitemi M300 Wi-Fi Repeater: CRITICAL command injection via /protocol.csp (enable, name, mac). Public exploit code out; no patch yet. Restrict access & monitor traffic. radar.offseq.com/threat/cve-20 #OffSeq #CVE202619348 #IoTSecurity

##

CVE-2026-19346
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-09T10:17:10.567000

2 posts

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

thehackerwire@mastodon.social at 2026-08-09T11:00:17.000Z ##

🟠 CVE-2026-19346 - High (8.8)

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T11:00:17.000Z ##

🟠 CVE-2026-19346 - High (8.8)

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19341
(8.8 HIGH)

EPSS: 0.44%

updated 2026-08-09T09:30:29

1 posts

A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulation of the argument EncryptionMode leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did n

thehackerwire@mastodon.social at 2026-08-09T08:00:02.000Z ##

🟠 CVE-2026-19341 - High (8.8)

A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulation of the argument EncryptionMode leads to stack-based buffer overflow. The...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19195
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-09T06:32:38

2 posts

A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond

1 repos

https://github.com/patrickt2017/CVE-2026-19195-PoC

thehackerwire@mastodon.social at 2026-08-09T08:00:56.000Z ##

🟠 CVE-2026-19195 - High (7.8)

A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T08:00:56.000Z ##

🟠 CVE-2026-19195 - High (7.8)

A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10595
(7.5 HIGH)

EPSS: 0.49%

updated 2026-08-09T06:31:42

1 posts

A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem path without sanitization or containment checks. URL-encoded dot-dot sequences (`%2e%2e`) bypass Starlette's built-in path

thehackerwire@mastodon.social at 2026-08-09T05:00:00.000Z ##

🟠 CVE-2026-10595 - High (7.5)

A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is dir...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15038(CVSS UNKNOWN)

EPSS: 0.19%

updated 2026-08-09T06:31:36

1 posts

The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.

1 repos

https://github.com/Polosss/By-Poloss..-..CVE-2026-15038-POC

offseq@infosec.exchange at 2026-08-09T07:30:24.000Z ##

CVE-2026-15038 (CRITICAL): InfiniteWP Client <1.13.6 has improper authentication in WordPress Multisite. Allows unauthenticated takeover & potential RCE. Restrict endpoint, monitor activity, upgrade ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #BlueTeam

##

CVE-2026-64561
(8.8 HIGH)

EPSS: 0.12%

updated 2026-08-09T06:31:34

3 posts

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. If reclaiming shadow pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to map memory into an invalid ro

6 repos

https://github.com/Aoripus-LTD/Zapscape-Fix

https://github.com/aarif450/aarif450.github.io

https://github.com/aarif450/Zapscape

https://github.com/chuzhongyun/CVE-2026-64561-Kernel-Fix

https://github.com/HORKimhab/CVE-2026-64561

https://github.com/HackSpeak/CVE-2026-64561

cadusilva@bolha.one at 2026-08-07T16:28:32.000Z ##

Instale já a correção para vulnerabilidade em máquinas virtuais

Se você usa Proxmox ou apenas tem um VPS, atualize já seu sistema. O problema permite o escape de máquinas virtuais e acesso à máquina física.

Se usa Debian, saiu o kernel 6.12.101-1 que corrige o problema. O Proxmox também já lançou atualização mesmo para quem não é assinante com o kernel 7.0.14-9.

:debian: security-tracker.debian.org/tr
:xp_secure_server: forum.proxmox.com/threads/prox
:xp_sys_info: cve.org/CVERecord?id=CVE-2026-
:github: github.com/V4bel/Zapscape

@fediadminbr

#FediAdminBR #MastoAdmin

##

DailyCyberSecurity@infosec.exchange at 2026-08-07T08:06:43.000Z ##

A new Linux Kernel KVM vulnerability threatens cloud servers with virtual machine escape risks. Learn about CVE-2026-64561 and secure your host machine now.

#LinuxKernel #KVMVulnerability #CVE202664561 #CloudSecurity #VMescape

securityexpress.info/linux-ker

##

ottoto2017@prattohome.com at 2026-08-07T04:19:17.000Z ##

「Zapscape KVMの新たな脆弱性により、特権を持つL1ゲストコードがLinuxホストに漏洩する可能性 」: #TheHackerNews

「Linuxカーネルの新たな脆弱性「Zapscape」 により、L1ゲスト仮想マシン(VM)内でカーネル権限を持つ攻撃者がKVM分離を回避し、ホスト上でコードを実行できる可能性があります。このリスクは、ネストされた仮想化が信頼できないゲストに公開されている場合に発生します。

この脆弱性は CVE-2026-64561 として追跡されており、ネストされたゲストメモリ変換に使用されるシャドウページテーブルを管理するKVM/x86のシャドウメモリ管理ユニット(MMU)に影響を与えます。

このバグを明らかにしたセキュリティ研究者の キム・ヒョヌ氏 は、実証されたエクスプロイト経路によって、カーネル権限、つまりroot権限でホスト上でコマンドを実行できると述べた。 」

thehackernews.com/2026/08/new-

#prattohome

##

CVE-2026-19193
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-09T06:19:12.620000

2 posts

A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

1 repos

https://github.com/patrickt2017/CVE-2026-19193-PoC

thehackerwire@mastodon.social at 2026-08-09T08:00:40.000Z ##

🟠 CVE-2026-19193 - High (7.8)

A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to be launch...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T08:00:40.000Z ##

🟠 CVE-2026-19193 - High (7.8)

A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to be launch...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64564
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-08-09T04:17:43.283000

10 posts

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds

3 repos

https://github.com/suominen/sctphantom

https://github.com/ethanolgolf/CVE-2026-64564

https://github.com/HackSpeak/CVE-2026-64564

linuxse@friendica.helvetet.eu at 2026-08-10T05:40:52.000Z ## En 18 år gammal sårbarhet i Linuxkärnans SCTP-kod kan ge lokala angripare fullständig rootåtkomst. Säkerhetsforskarna bakom upptäckten har även visat att felet under vissa förutsättningar kan användas för att ta sig ur en container och angripa värdsystemet. Sårbarheten har fått namnet SCTPhantom och registrerats som CVE-2026-64564. Den finns i Linuxkärnans stöd för nätverksprotokollet SCTP och […]
SCTPhantom – 18 år gammal Linux-bugg kan ge angripare rootåtkomst ##

DailyCyberSecurity at 2026-08-10T01:55:44.074Z ##

CVE-2026-64564: SCTP Flaw Enables Container Escape

securityonline.info/sctp-uaf-c

##

beyondmachines1 at 2026-08-09T14:01:06.971Z ##

SCTPhantom: 18-Year-Old Linux Kernel Flaw Allows Root Access and Container Escape

A use-after-free vulnerability in the Linux SCTP implementation (CVE-2026-64564) allows local attackers to gain root privileges and escape containers. The flaw has existed since 2008 and affects most major Linux distributions.

**If you run Linux (Debian, Ubuntu, RHEL, Rocky) on servers, containers or workstations, install the latest kernel update from your distribution vendor and reboot. The fix for CVE-2026-64564 only takes effect after the restart. If you don't use SCTP, also switch the module off (add both blacklist sctp and install sctp /bin/false to /etc/modprobe.d/sctp.conf, refresh the initramfs, and confirm with lsmod | grep sctp that nothing comes back).**

beyondmachines.net/event_detai

##

security_crawler_carl at 2026-08-09T09:05:59.267Z ##

🏆 New Achievement! SCTPhantom Menace: Eighteen Years In The Making!

ERROR: Kernel identity verification module returned incorrect value. Duration of incorrect value: eighteen years. Tencent researchers have confirmed CVE-2026-64564, a use-after-free in Linux's SCTP networking code, allows local users to escalate to root and escape containers entirely. The bug checks a delete request against the packet's source address, then acts on a different one. The kernel trusted the wrong address. (1/2)

##

linuxse@friendica.helvetet.eu at 2026-08-10T05:40:52.000Z ## En 18 år gammal sårbarhet i Linuxkärnans SCTP-kod kan ge lokala angripare fullständig rootåtkomst. Säkerhetsforskarna bakom upptäckten har även visat att felet under vissa förutsättningar kan användas för att ta sig ur en container och angripa värdsystemet. Sårbarheten har fått namnet SCTPhantom och registrerats som CVE-2026-64564. Den finns i Linuxkärnans stöd för nätverksprotokollet SCTP och […]
SCTPhantom – 18 år gammal Linux-bugg kan ge angripare rootåtkomst ##

DailyCyberSecurity@infosec.exchange at 2026-08-10T01:55:44.000Z ##

CVE-2026-64564: SCTP Flaw Enables Container Escape

securityonline.info/sctp-uaf-c

##

beyondmachines1@infosec.exchange at 2026-08-09T14:01:06.000Z ##

SCTPhantom: 18-Year-Old Linux Kernel Flaw Allows Root Access and Container Escape

A use-after-free vulnerability in the Linux SCTP implementation (CVE-2026-64564) allows local attackers to gain root privileges and escape containers. The flaw has existed since 2008 and affects most major Linux distributions.

**If you run Linux (Debian, Ubuntu, RHEL, Rocky) on servers, containers or workstations, install the latest kernel update from your distribution vendor and reboot. The fix for CVE-2026-64564 only takes effect after the restart. If you don't use SCTP, also switch the module off (add both blacklist sctp and install sctp /bin/false to /etc/modprobe.d/sctp.conf, refresh the initramfs, and confirm with lsmod | grep sctp that nothing comes back).**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

security_crawler_carl@infosec.exchange at 2026-08-09T09:05:59.000Z ##

🏆 New Achievement! SCTPhantom Menace: Eighteen Years In The Making!

ERROR: Kernel identity verification module returned incorrect value. Duration of incorrect value: eighteen years. Tencent researchers have confirmed CVE-2026-64564, a use-after-free in Linux's SCTP networking code, allows local users to escalate to root and escape containers entirely. The bug checks a delete request against the packet's source address, then acts on a different one. The kernel trusted the wrong address. (1/2)

##

ottoto2017@prattohome.com at 2026-08-08T07:27:58.000Z ##

「18年前のLinux SCTPの脆弱性により、ローカルユーザーがroot権限を取得し、コンテナから脱出できる可能性 」: #TheHackerNews

「LinuxのSCTPネットワークコードに存在する解放済みメモリ使用のバグを悪用すると、ホスト上で完全なroot権限を取得できる可能性がある。Tencentの研究者らは、このバグを利用してコンテナから脱出し、その下にあるマシンにアクセスしたと述べている。

この脆弱性は2008年から存在していました。修正版は既にリリースされており、8月3日にリリースされた安定版カーネル7.1.6、6.18.42、6.12.101、6.6.148で修正されています。SCTP接続可能な古いカーネルを使用しているユーザーはアップデートしてください。

CVE-2026-64564 として追跡され 、 発見者によってSCTPhantom と名付けられたこの脆弱性は、カーネルCVEチームが割り当てた2日後の8月6日に公表された。 」

thehackernews.com/2026/08/18-y

#prattohome

##

_r_netsec@infosec.exchange at 2026-08-08T02:28:05.000Z ##

SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free · Tencent Zhuque Lab matrix.tencent.com/en/2026/08/

##

CVE-2026-71993
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:31:13

4 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.

offseq at 2026-08-10T00:00:36.239Z ##

MSI Radix AXE6600 (firmware v781521) is affected by CVE-2026-71993 (CVSS 9.8): CRITICAL command injection in openvpn via macfilter allows remote root access. Restrict management access & monitor activity. Details: radar.offseq.com/threat/msi-ra

##

offseq@infosec.exchange at 2026-08-10T00:00:36.000Z ##

MSI Radix AXE6600 (firmware v781521) is affected by CVE-2026-71993 (CVSS 9.8): CRITICAL command injection in openvpn via macfilter allows remote root access. Restrict management access & monitor activity. Details: radar.offseq.com/threat/msi-ra #OffSeq #Vuln #RouterSecurity #CVE2026_71993

##

offseq@infosec.exchange at 2026-08-09T01:30:28.000Z ##

MSI Radix AXE6600 v781521 suffers CRITICAL CVE-2026-71993 (CVSS 9.3): OS Command Injection via macfilter allows remote root access. Restrict remote access & monitor openvpn/macfilter activity. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #RouterSecurity #Infosec

##

thehackerwire@mastodon.social at 2026-08-09T01:00:57.000Z ##

🔴 CVE-2026-71993 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71986
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:31:13

3 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the dmz function to execute malicious commands and obtain root privileges on the underlying system.

offseq at 2026-08-09T13:30:10.580Z ##

MSI Radix AXE6600 (v781521) is affected by CVE-2026-71986 (CRITICAL) — OS command injection in dmz function allows remote root access. No patch yet, monitor vendor updates. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-09T13:30:10.000Z ##

MSI Radix AXE6600 (v781521) is affected by CVE-2026-71986 (CRITICAL) — OS command injection in dmz function allows remote root access. No patch yet, monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec #RouterSecurity

##

thehackerwire@mastodon.social at 2026-08-09T01:59:56.000Z ##

🔴 CVE-2026-71986 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71990
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:31:13

2 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the SSH configuration interface to inject malicious commands and obtain root privileges on the underlying system.

offseq@infosec.exchange at 2026-08-09T04:30:25.000Z ##

MSI Radix AXE6600 (v781521) hit by CRITICAL OS command injection (CVE-2026-71990, CVSS 9.3). Remote attackers can gain root via SSH config. No patch yet — restrict SSH access & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE #infosec #router

##

thehackerwire@mastodon.social at 2026-08-09T01:00:00.000Z ##

🔴 CVE-2026-71990 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can expl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71992
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:31:13

2 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.

offseq@infosec.exchange at 2026-08-09T03:00:23.000Z ##

MSI Radix AXE6600 routers (v781521) affected by CRITICAL OS command injection (CVE-2026-71992, CVSS 9.3). Remote attackers can execute root commands — no auth needed. Restrict access, monitor logs. No patch yet. radar.offseq.com/threat/cve-20 #OffSeq #CVE202671992 #RouterSecurity

##

thehackerwire@mastodon.social at 2026-08-09T01:00:21.000Z ##

🔴 CVE-2026-71992 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71985
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:31:13

1 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the accesscontrol function to execute malicious commands and obtain root privileges on the underlying system.

thehackerwire@mastodon.social at 2026-08-09T01:01:18.000Z ##

🔴 CVE-2026-71985 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71984
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:31:13

1 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function to inject malicious commands and obtain root privileges on the underlying system.

thehackerwire@mastodon.social at 2026-08-09T01:01:07.000Z ##

🔴 CVE-2026-71984 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71987
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:31:07

4 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.

hugovalters@mastodon.social at 2026-08-09T17:07:38.000Z ##

CVE-2026-71987 - Critical unpatched RCE in MSI Radix AXE6600 routers via command injection in alg function. CVSS 9.8. Full root access possible. Update immediately or isolate devices. #CVE #MSI #infosec

valtersit.com/cve/CVE-2026-719

##

offseq at 2026-08-09T10:30:26.222Z ##

CVE-2026-71987: MSI Radix AXE6600 (v781521) suffers from a CRITICAL OS command injection vulnerability (CVSS 9.3). Remote, unauthenticated code execution possible with root privileges. Restrict device access and monitor! radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-09T10:30:26.000Z ##

CVE-2026-71987: MSI Radix AXE6600 (v781521) suffers from a CRITICAL OS command injection vulnerability (CVSS 9.3). Remote, unauthenticated code execution possible with root privileges. Restrict device access and monitor! radar.offseq.com/threat/cve-20 #OffSeq #CVE202671987 #Infosec #RouterSecurity

##

thehackerwire@mastodon.social at 2026-08-09T02:00:06.000Z ##

🔴 CVE-2026-71987 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71988
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:31:07

3 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.

offseq at 2026-08-09T09:00:23.182Z ##

MSI Radix AXE6600 (v781521) hit by CRITICAL OS command injection (CVE-2026-71988, CVSS 9.3). Remote attackers can gain root via portFw/alg — full device takeover possible. Patch status unconfirmed. More: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-09T09:00:23.000Z ##

MSI Radix AXE6600 (v781521) hit by CRITICAL OS command injection (CVE-2026-71988, CVSS 9.3). Remote attackers can gain root via portFw/alg — full device takeover possible. Patch status unconfirmed. More: radar.offseq.com/threat/cve-20 #OffSeq #CVE202671988 #Infosec #RouterSecurity

##

thehackerwire@mastodon.social at 2026-08-09T02:00:18.000Z ##

🔴 CVE-2026-71988 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71991
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:16:48.270000

2 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the Telnet configuration interface to inject malicious commands and obtain root privileges on the underlying system.

thehackerwire@mastodon.social at 2026-08-09T01:00:10.000Z ##

🔴 CVE-2026-71991 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-09T00:00:35.000Z ##

MSI Radix AXE6600 routers (v781521) affected by CRITICAL CVE-2026-71991 🛡️. OS command injection via TelnetSSH enables remote root access. Restrict Telnet, segment devices, monitor for vendor fixes. radar.offseq.com/threat/cve-20 #OffSeq #CVE202671991 #RouterSecurity

##

CVE-2026-71989
(9.8 CRITICAL)

EPSS: 1.35%

updated 2026-08-09T00:16:47.953000

2 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.

offseq@infosec.exchange at 2026-08-09T06:00:26.000Z ##

MSI Radix AXE6600 routers (v781521) impacted by CVE-2026-71989: CRITICAL OS command injection (CVSS 9.3) in porTrigger/alg enables unauthenticated root command execution. Patch status unknown. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CVE202671989 #RouterSecurity

##

thehackerwire@mastodon.social at 2026-08-09T02:00:55.000Z ##

🔴 CVE-2026-71989 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability thr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71983
(9.8 CRITICAL)

EPSS: 1.62%

updated 2026-08-08T23:16:56.967000

1 posts

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parameters. Attackers can exploit these unsanitized parameters to execute arbitrary commands on the affected device and obtain root privileges.

thehackerwire@mastodon.social at 2026-08-08T23:59:57.000Z ##

🔴 CVE-2026-71983 - Critical (9.8)

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parame...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71953
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-08T18:30:30

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T05:00:52.000Z ##

🔴 CVE-2026-71953 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpSe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71955
(9.8 CRITICAL)

EPSS: 2.13%

updated 2026-08-08T18:30:30

1 posts

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T00:01:03.000Z ##

🔴 CVE-2026-71955 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, ta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71954
(9.8 CRITICAL)

EPSS: 2.13%

updated 2026-08-08T18:30:30

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-08T18:00:44.000Z ##

🔴 CVE-2026-71954 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71950
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-08T18:30:29

2 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the action_value field, resulting in command execution with root privileges.

hugovalters@mastodon.social at 2026-08-09T23:08:04.000Z ##

CVE-2026-71950 - Critical RCE in D-Link DWR-M961. Command injection in formSmsManage, root access. CVSS 9.8. Unpatched. Disable remote access immediately. #CVE #DLink #infosec

valtersit.com/cve/CVE-2026-719

##

thehackerwire@mastodon.social at 2026-08-09T02:01:16.000Z ##

🔴 CVE-2026-71950 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71945
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-08T18:30:29

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T07:00:13.000Z ##

🔴 CVE-2026-71945 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious comma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71944
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-08T18:30:29

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T07:00:02.000Z ##

🔴 CVE-2026-71944 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious comma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71952
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-08T18:30:29

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T05:00:41.000Z ##

🔴 CVE-2026-71952 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands int...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71948
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-08T18:30:29

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T00:01:13.000Z ##

🔴 CVE-2026-71948 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71957
(9.8 CRITICAL)

EPSS: 0.59%

updated 2026-08-08T18:30:29

1 posts

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.

thehackerwire@mastodon.social at 2026-08-09T00:00:19.000Z ##

🔴 CVE-2026-71957 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71956
(9.8 CRITICAL)

EPSS: 1.74%

updated 2026-08-08T18:30:29

1 posts

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T00:00:07.000Z ##

🔴 CVE-2026-71956 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst fiel...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-42170
(7.8 HIGH)

EPSS: 0.19%

updated 2026-08-08T18:30:29

1 posts

A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an undersized heap buffer. Subsequent pixel data consumption at the real format's stride causes a write past the heap buffer boundary, leading to heap metadata corrupt

thehackerwire@mastodon.social at 2026-08-08T16:59:53.000Z ##

🟠 CVE-2026-42170 - High (7.8)

A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an undersized ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71946
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-08T18:30:25

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T07:00:23.000Z ##

🔴 CVE-2026-71946 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71958
(9.8 CRITICAL)

EPSS: 0.56%

updated 2026-08-08T18:16:56.783000

1 posts

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.

thehackerwire@mastodon.social at 2026-08-09T00:00:53.000Z ##

🔴 CVE-2026-71958 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71951
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-08T18:16:55.907000

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_value field, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T05:00:28.000Z ##

🔴 CVE-2026-71951 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71949
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-08T18:16:55.660000

1 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdValue and selectMenuValue fields, resulting in command execution with root privileges.

thehackerwire@mastodon.social at 2026-08-09T02:01:05.000Z ##

🔴 CVE-2026-71949 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71947
(9.8 CRITICAL)

EPSS: 2.09%

updated 2026-08-08T18:16:55.410000

2 posts

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with root privileges.

hugovalters@mastodon.social at 2026-08-09T14:01:00.000Z ##

CVE-2026-71947 - Critical command injection in D-Link DWR-M961 routers. Remote attackers can execute arbitrary commands as root via /boafrm/formTracerouteDiagnosticRun. CVSS 9.8. No patch available - isolate affected devices now. #CVE #DLink #infosec

valtersit.com/cve/CVE-2026-719

##

thehackerwire@mastodon.social at 2026-08-09T08:00:29.000Z ##

🔴 CVE-2026-71947 - Critical (9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious com...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67620
(7.7 HIGH)

EPSS: 0.43%

updated 2026-08-08T16:16:49.420000

1 posts

Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud metadata endpoint 100.100.100.200, allowing authenticated attackers to force the server to issue arbitrary GET requests to cloud instance metadata services.

1 repos

https://github.com/abdugafforov-bobur/CVE-2026-67620-poc

thehackerwire@mastodon.social at 2026-08-08T17:00:03.000Z ##

🟠 CVE-2026-67620 - High (7.7)

Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud meta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14526
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-08-08T09:30:28

3 posts

The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create a new administrator-level user account and achieve full site takeover by saving and executing a malic

hugovalters@mastodon.social at 2026-08-09T18:12:40.000Z ##

CVE-2026-14526 - Critical auth bypass in AI Copilot WordPress plugin. Unauthenticated attackers can create admin accounts and take over sites. CVSS 9.8. Unpatched. Disable plugin now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-145

##

offseq@infosec.exchange at 2026-08-08T13:30:27.000Z ##

CVE-2026-14526: AI Copilot – Content Generator <=1.5.6 has a CRITICAL auth bypass. Unauth attackers can create WordPress admin users via an exposed nonce, leading to site takeover. Disable [aiwu-form]/chatbot & check for vendor patch. radar.offseq.com/threat/cve-20 #OffSeq #CVE202614526 #WordPress

##

thehackerwire@mastodon.social at 2026-08-08T08:00:29.000Z ##

🔴 CVE-2026-14526 - Critical (9.8)

The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This make...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16948(CVSS UNKNOWN)

EPSS: 0.13%

updated 2026-08-08T09:30:28

1 posts

The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentation settings and delete imported site-builder content.

offseq@infosec.exchange at 2026-08-08T09:00:24.000Z ##

CVE-2026-16948 | HIGH severity in Solace Extra WP plugin <1.6.1: Missing capability checks on AJAX actions lets Subscribers change site settings & delete imported content. Patch status unknown — tighten role permissions. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026_16948

##

CVE-2026-16955
(0 None)

EPSS: 0.16%

updated 2026-08-08T07:17:11.440000

1 posts

The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature to be enabled; otherwise the same issue is

offseq@infosec.exchange at 2026-08-08T07:30:23.000Z ##

CVE-2026-16955: HIGH severity path traversal in AI Engine WP plugin <3.6.6. Subscribers can read arbitrary files if public API is enabled. Restrict API & admin privileges. Await patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026_16955 #Security

##

CVE-2026-16594
(0 None)

EPSS: 0.14%

updated 2026-08-08T07:17:10.910000

1 posts

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the WP Directory Kit WordPress plugin before 1.5.5 settings including sensitive API keys and secrets.

offseq@infosec.exchange at 2026-08-08T10:30:23.000Z ##

CVE-2026-16594: WP Directory Kit <1.5.5 has a HIGH severity info exposure flaw. Any authenticated user (even Subscribers) can access API keys/secrets due to missing authorization on AJAX action. Restrict user roles & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE

##

CVE-2026-8037
(9.6 CRITICAL)

EPSS: 99.31%

updated 2026-08-08T05:17:10.403000

5 posts

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

Nuclei template

2 repos

https://github.com/HORKimhab/CVE-2026-8037

https://github.com/Caster-chen/CVE-2026-8037-POC

netsecio@mastodon.social at 2026-08-09T17:59:27.000Z ##

📰 CISA Adds Progress Kemp LoadMaster Flaw to KEV Catalog After Exploits

🚨 CISA KEV ALERT: A critical command injection flaw in Progress Kemp LoadMaster (CVE-2026-8037, CVSS 9.6) is actively exploited. Unauthenticated attackers can gain full control. Federal agencies must patch by Aug 10. #CVE #CISA #KEV #PatchNow

🔗 cyber.netsecops.io/articles/pr

##

thecybermind@infosec.exchange at 2026-08-07T23:33:16.000Z ##

CRITICAL THREAT ALERT: Active exploitation of CVE-2026-8037 in Progress LoadMaster allows unauthenticated RCE via command injection. Securing your perimeter requires immediate SIEM detection updates and access restrictions. Review our full TSUITE analysis: thecybermind.co/5yde

##

secdb@infosec.exchange at 2026-08-07T19:00:11.000Z ##

🚨 [CISA-2026:0807] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-8037 (secdb.nttzen.cloud/cve/detail/)
- Name: Progress LoadMaster Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Progress
- Product: LoadMaster
- Notes: community.progress.com/s/artic ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260807 #cisa20260807 #cve_2026_8037 #cve20268037

##

cisakevtracker@mastodon.social at 2026-08-07T18:00:45.000Z ##

CVE ID: CVE-2026-8037
Vendor: Progress
Product: LoadMaster
Date Added: 2026-08-07
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-08-07T17:50:53.000Z ##

CISA has added one vulnerability to the KEV catalogue:

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Cisco:

NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi #Cisco

Palo Alto:

CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent security.paloaltonetworks.com/

Microsoft:

Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: msrc.microsoft.com/update-guid #Microsoft

Google:

New: Chrome Dev for Android Update chromereleases.googleblog.com/ #Google #Chrome

Broadcom:

One new advisory for a high-severity vulnerability that was first published on July 23 support.broadcom.com/web/ecx/s

Posted yesterday:

Apple security updates support.apple.com/en-us/100100 #Apple

AMD: Safe RET Interrupt Vulnerability amd.com/en/resources/product-s #AMD

Dell:

CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #infosec #vulnerability #Java #SQL

##

CVE-2026-56793
(7.7 HIGH)

EPSS: 0.31%

updated 2026-08-08T05:17:09.880000

2 posts

Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

hugovalters@mastodon.social at 2026-08-09T15:04:40.000Z ##

CVE-2026-56793 - High-severity improper authentication in Dell OpenManage Server Administrator (<11.1.0.2). Remote unauthenticated attackers can gain unauthorized access. CVSS 7.7. Update immediately. #CVE #Dell #infosec

valtersit.com/cve/CVE-2026-567

##

thehackerwire@mastodon.social at 2026-08-07T17:00:29.000Z ##

🟠 CVE-2026-56793 - High (7.7)

Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71851
(9.0 CRITICAL)

EPSS: 0.32%

updated 2026-08-08T04:17:55.850000

2 posts

crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math.random(), instead of a cryptographically secure source. This generator was introduced in version 3.1.2-4 and remained present in nearly every 3.x release

offseq@infosec.exchange at 2026-08-08T04:30:25.000Z ##

CVE-2026-71851 (CRITICAL, CVSS 9): brix crypto-js <4.0.0 uses weak RNG in WordArray.random(), risking private key recovery in wallet apps using BIP39. Upgrade to 4.0.0+ now. radar.offseq.com/threat/cve-20 #OffSeq #CryptoJS #InfoSec #Vulnerability

##

thehackerwire@mastodon.social at 2026-08-08T03:00:24.000Z ##

🔴 CVE-2026-71851 - Critical (9)

crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71560
(9.1 CRITICAL)

EPSS: 0.55%

updated 2026-08-08T03:32:14

1 posts

Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to

thehackerwire@mastodon.social at 2026-08-08T12:00:46.000Z ##

🔴 CVE-2026-71560 - Critical (9.1)

Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.

This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71558
(9.8 CRITICAL)

EPSS: 0.71%

updated 2026-08-08T03:32:14

1 posts

Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to den

thehackerwire@mastodon.social at 2026-08-08T11:00:28.000Z ##

🔴 CVE-2026-71558 - Critical (9.8)

Heap type confusion vulnerability in Apache Fory C++ deserialization.

This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserializat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70558
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-08-08T03:16:46.910000

2 posts

Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token interceptor, so the only guard is a header equality check against a dinkyToken value whose default (efda1551-7958-4e0f-80a8-dfd107df3e38) is hardcoded i

thehackerwire@mastodon.social at 2026-08-09T13:59:52.000Z ##

🔴 CVE-2026-70558 - Critical (9.8)

Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T13:59:52.000Z ##

🔴 CVE-2026-70558 - Critical (9.8)

Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5857
(8.1 HIGH)

EPSS: 0.53%

updated 2026-08-08T03:16:46.377000

2 posts

Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tcp_input() re-invokes the parser with topic_received==0, and the persisted topic_len_received==1 skips the length-reading block containing the guard, fall

thehackerwire@mastodon.social at 2026-08-10T02:00:37.000Z ##

🟠 CVE-2026-5857 - High (8.1)

Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T02:00:37.000Z ##

🟠 CVE-2026-5857 - High (8.1)

Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19192
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-08T03:16:45.610000

1 posts

A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit is now public and may be used.

thehackerwire@mastodon.social at 2026-08-08T17:00:57.000Z ##

🟠 CVE-2026-19192 - High (7.8)

A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access controls. The...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52878
(7.5 HIGH)

EPSS: 0.28%

updated 2026-08-07T23:17:04.593000

1 posts

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData sub-message is omitted. This omission causes RawData to decode to nil. Every transaction gossiped on the Klever-Go P2P network is decoded and validated synchronously inside the libp2p pubsub topic-valid

thehackerwire@mastodon.social at 2026-08-08T00:00:13.000Z ##

🟠 CVE-2026-52878 - High (7.5)

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData sub-message is omitted. This omission causes RawD...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-46409
(9.6 CRITICAL)

EPSS: 0.36%

updated 2026-08-07T23:17:03.243000

1 posts

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<random port>` (commonly 19141) without server-side Origin validation, loopback authentication, or Content-Type enforcement, and with a wildcard CORS policy. Any webpage a user visits while OpenYak is runni

thehackerwire@mastodon.social at 2026-08-08T00:01:16.000Z ##

🔴 CVE-2026-46409 - Critical (9.6)

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:` (commonly 19141) without server-side Origin validat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48170
(9.1 CRITICAL)

EPSS: 0.25%

updated 2026-08-07T22:16:59.170000

3 posts

`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`. After one such patch, `Object.prototype.someProp` is set process-wide, affecting every plain object in the Node process. Any service that calls `scimPatch()` on attacker-controlled JSON (i.e. any SCI

hugovalters@mastodon.social at 2026-08-09T11:14:34.000Z ##

CVE-2026-48170 - Critical prototype pollution in scim-patch <0.9.1. Attacker-controlled SCIM PATCH can pollute Object.prototype process-wide. CVSS 9.1. Unpatched - update immediately. #CVE #NodeJS #infosec

valtersit.com/cve/CVE-2026-481

##

offseq@infosec.exchange at 2026-08-08T00:00:37.000Z ##

CVE-2026-48170 (CRITICAL, CVSS 9.1): Prototype pollution in scim-patch <0.9.1 lets attackers alter Object.prototype globally in Node.js. Upgrade to 0.9.1+ or freeze prototypes for mitigation. radar.offseq.com/threat/cve-20 #OffSeq #CVE202648170 #NodeJS #InfoSec

##

thehackerwire@mastodon.social at 2026-08-07T23:00:11.000Z ##

🔴 CVE-2026-48170 - Critical (9.1)

`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`. After one such patch,
`Object.prototype.somePr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16258
(9.8 CRITICAL)

EPSS: 0.47%

updated 2026-08-07T21:31:37

1 posts

The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution.

thehackerwire@mastodon.social at 2026-08-08T13:00:00.000Z ##

🔴 CVE-2026-16258 - Critical (9.8)

The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Searc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16263
(8.8 HIGH)

EPSS: 0.34%

updated 2026-08-07T21:31:36

1 posts

The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server.

thehackerwire@mastodon.social at 2026-08-08T14:59:52.000Z ##

🟠 CVE-2026-16263 - High (8.8)

The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to includ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-63235
(7.5 HIGH)

EPSS: 0.32%

updated 2026-08-07T21:30:40

1 posts

In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets - either due to repeated attempts or failed authentication - the server may silently drop the connection or send a CONNACK but fail to close the session or deallocate internal resources. This behavior allows an attacker to c

thehackerwire@mastodon.social at 2026-08-08T07:00:48.000Z ##

🟠 CVE-2025-63235 - High (7.5)

In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets - either due to repeated attempts or failed authentication - the server...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15972
(7.5 HIGH)

EPSS: 0.39%

updated 2026-08-07T21:30:40

1 posts

Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent file descriptors, goroutines, and memory by opening many incomplete connections, potentially preventing legitimate clients from connecting. This vulnerability, CVE-2026-

thehackerwire@mastodon.social at 2026-08-08T03:00:14.000Z ##

🟠 CVE-2026-15972 - High (7.5)

Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent file descriptors...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64636
(7.7 HIGH)

EPSS: 0.21%

updated 2026-08-07T21:30:37

1 posts

An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.

thehackerwire@mastodon.social at 2026-08-08T07:00:58.000Z ##

🟠 CVE-2026-64636 - High (7.7)

An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15215
(8.8 HIGH)

EPSS: 0.35%

updated 2026-08-07T21:30:33

1 posts

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) t

thehackerwire@mastodon.social at 2026-08-08T15:00:03.000Z ##

🟠 CVE-2026-15215 - High (8.8)

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protecte...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16041
(7.5 HIGH)

EPSS: 0.21%

updated 2026-08-07T21:30:33

1 posts

The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners.

thehackerwire@mastodon.social at 2026-08-08T12:59:50.000Z ##

🟠 CVE-2026-16041 - High (7.5)

The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chose...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50540
(9.6 CRITICAL)

EPSS: 0.38%

updated 2026-08-07T21:17:28.827000

1 posts

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation. The runtime accepts an arbitrary io.katacontainers.config_path pod annotation and loads the referenced host TOML file without re

thehackerwire@mastodon.social at 2026-08-07T23:00:43.000Z ##

🔴 CVE-2026-50540 - Critical (9.6)

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated config...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19082
(7.5 HIGH)

EPSS: 0.29%

updated 2026-08-07T21:17:27.317000

1 posts

Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags. copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip the trailing NUL. A zero-count ASCII entry sets `entry->size` to 0, and the derived length reaches i_tags_add() as -1, which is interpreted as a request

thehackerwire@mastodon.social at 2026-08-08T08:00:50.000Z ##

🟠 CVE-2026-19082 - High (7.5)

Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags.

copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48169
(8.8 HIGH)

EPSS: 0.26%

updated 2026-08-07T21:16:58

1 posts

### Summary The PraisonAI Platform API has two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key lookups without checking workspace ownership, so any authenticated user can read, modify, and delete resources in any workspace just by swapping UUIDs in their API requests. On top of that, every member management endp

thehackerwire@mastodon.social at 2026-08-07T23:00:01.000Z ##

🟠 CVE-2026-48169 - High (8.8)

PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key lookups w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48039
(9.1 CRITICAL)

EPSS: 0.34%

updated 2026-08-07T19:29:59

2 posts

# Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token | Field | Value | | ---------------- | ----- | | Repository | pipeboard-co/meta-ads-mcp | | Affected version | ≤ 1.0.101 (commit 496c988 ~ 7d14226); Versions 1.0.102–1.0.105 lack git tags, so patch status is unconfirmed. | | Vulnerability | CWE-287 — Improper Authentication | | Severity | Critic

offseq@infosec.exchange at 2026-08-08T03:00:24.000Z ##

pipeboard-co meta-ads-mcp (<1.0.109) affected by CRITICAL auth bypass (CVE-2026-48039). Unauthenticated requests can access tools & leak access tokens via error responses. Patch to 1.0.109+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202648039 #infosec #vuln

##

thehackerwire@mastodon.social at 2026-08-08T03:00:04.000Z ##

🔴 CVE-2026-48039 - Critical (9.1)

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-50481
(9.9 CRITICAL)

EPSS: 0.46%

updated 2026-08-07T19:29:09.813000

2 posts

Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-08-09T12:59:55.000Z ##

🔴 CVE-2026-50481 - Critical (9.9)

Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T12:59:55.000Z ##

🔴 CVE-2026-50481 - Critical (9.9)

Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

decio at 2026-08-10T08:17:55.975Z ##

Dans la suite de wp2shell, encore une jolie chaîne WordPress : — CVE-2026-64638.

Au départ, on a “juste” une Reflected XSS pré-auth sur wp-login.php.

Sauf qu’en la chaînant avec plusieurs briques déjà présentes dans WordPress, on arrive à quelque chose de beaucoup moins sympa :

XSS → contexte admin → Application Password → REST API → upload de plugin → RCE 🐚

⚠️ À noter quand même : ce n’est pas du pre-auth zero-click.
Il faut qu’un admin déjà connecté clique sur un lien contrôlé par l’attaquant.

Encore un bon rappel : une “simple XSS” peut devenir franchement méchante une fois mise dans la bonne chaîne.

🩹 Corrigé dans WordPress 7.0.3.
👇
wordpress.org/news/2026/08/wor

En cas de doute sur une exploitation passée : petit coup d’œil aux Application Passwords, aux plugins récemment ajoutés et aux fichiers PHP inhabituels.

"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
👇
pwn.ai/blog/xss2shell

##

campuscodi@mastodon.social at 2026-08-09T19:57:58.000Z ##

Another one of those WordPress pre-auth RCEs

This one's named XSS2Shell, CVE-2026-64638, found with AI, patched in v7.0.3, released on Thursday

pwn.ai/blog/xss2shell

##

blog@securebulletin.com at 2026-08-09T13:08:08.000Z ##

New WordPress Flaw Turns a Failed Login Attempt Into Full Server Takeover

A newly disclosed WordPress vulnerability, dubbed XSS2Shell and tracked as CVE-2026-64638, chains a decade-old parsing quirk in the login page into full remote code execution, putting an estimated 500 million-plus sites at risk. WordPress has already shipped a patch backported all the way to version 4.7, and administrators are urged to update immediately.

securebulletin.com/new-wordpre

##

decio@infosec.exchange at 2026-08-10T08:17:55.000Z ##

Dans la suite de wp2shell, encore une jolie chaîne WordPress : #XSS2Shell — CVE-2026-64638.

Au départ, on a “juste” une Reflected XSS pré-auth sur wp-login.php.

Sauf qu’en la chaînant avec plusieurs briques déjà présentes dans WordPress, on arrive à quelque chose de beaucoup moins sympa :

XSS → contexte admin → Application Password → REST API → upload de plugin → RCE 🐚

⚠️ À noter quand même : ce n’est pas du pre-auth zero-click.
Il faut qu’un admin déjà connecté clique sur un lien contrôlé par l’attaquant.

Encore un bon rappel : une “simple XSS” peut devenir franchement méchante une fois mise dans la bonne chaîne.

🩹 Corrigé dans WordPress 7.0.3.
👇
wordpress.org/news/2026/08/wor

En cas de doute sur une exploitation passée : petit coup d’œil aux Application Passwords, aux plugins récemment ajoutés et aux fichiers PHP inhabituels.

"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
👇
pwn.ai/blog/xss2shell

#WordPress #XSS2Shell #CyberVeille

##

campuscodi@mastodon.social at 2026-08-09T19:57:58.000Z ##

Another one of those WordPress pre-auth RCEs

This one's named XSS2Shell, CVE-2026-64638, found with AI, patched in v7.0.3, released on Thursday

pwn.ai/blog/xss2shell

##

secdb@infosec.exchange at 2026-08-08T15:46:32.000Z ##

🚨 XSS2shell (CVE-2026-64638) has been identified as a notable vulnerability.

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.

Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim.

This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.

Discovered and responsibly disclosed by the team at pwn.ai.

ℹ️ Additional details on ZEN SecDB secdb.nttzen.cloud/updates/267

#infosec #xss2shell #wordpress #xss #rce
#nttdata #zen #secdb

##

bontchev@infosec.exchange at 2026-08-08T13:13:07.000Z ##

WordPress RCE. Every version ever released (except the latest, 7.0.3). 500+ million sites. 43% of the Internet-facing sites. Hacker's paradise.

"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)":

pwn.ai/blog/xss2shell

##

ottoto2017@prattohome.com at 2026-08-08T06:19:36.000Z ##

「WordPressの事前認証における新たなXSS脆弱性によりPHPコードの実行につながる可能性あり - 早急に修正を! 」: #TheHackerNews

「WordPressは、ログイン画面に存在する、認証前のリフレクテッドクロスサイトスクリプティング(XSS)の脆弱性を修正しました。この脆弱性は、コンテンツ管理システムのすべてのバージョンに影響を与えます。pwn.aiは、ログインした管理者が攻撃者によって制御されたページを操作する際に、この脆弱性がサーバー上でPHPコードの実行に連鎖的に繋がる仕組みを実証しました。

CVE-2026-64638 (CVSSスコア:8.9)として追跡されている この深刻な脆弱性は、攻撃者に特別な権限を必要としません。 」

thehackernews.com/2026/08/new-

#prattohome

##

modrobert@infosec.exchange at 2026-08-08T03:04:41.000Z ##

"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
pwn.ai/blog/xss2shell

##

DarkWebInformer@infosec.exchange at 2026-08-07T20:00:07.000Z ##

🚨 WordPress patches XSS2Shell flaw that could lead to server code execution

CVE-2026-64638 is a CVSS 8.9 pre-authentication XSS vulnerability in the WordPress login screen.

The XSS itself requires no account. Researchers at pwn.ai demonstrated how it can be chained against a logged-in administrator to reach PHP code execution after social engineering the admin into interacting with an attacker-controlled page.

A successful chain could potentially allow attackers to:

• Create API credentials
• Gain authenticated REST access
• Upload malicious plugin files
• Execute PHP on the server
• Access WordPress secrets and database credentials

WordPress 7.0.3 fixes the flaw, with patches backported through the 4.7 branch.

NHS England says exploitation is likely following the release of technical details and a PoC.

WordPress has not reported confirmed exploitation in the wild as of August 7.

Update immediately.

##

CVE-2026-20346
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-07T19:17:41.360000

1 posts

A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PDF files during scanning, which may result in an out-of-bounds buffer read. An attacker could exploit

thehackerwire@mastodon.social at 2026-08-08T09:00:57.000Z ##

🟠 CVE-2026-20346 - High (7.5)

A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device.

This vulnerability ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16262
(7.5 HIGH)

EPSS: 0.16%

updated 2026-08-07T19:17:37.053000

1 posts

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the attacker.

thehackerwire@mastodon.social at 2026-08-08T13:00:10.000Z ##

🟠 CVE-2026-16262 - High (7.5)

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16038
(9.1 CRITICAL)

EPSS: 0.24%

updated 2026-08-07T19:17:36.110000

1 posts

The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free.

thehackerwire@mastodon.social at 2026-08-08T16:00:02.000Z ##

🔴 CVE-2026-16038 - Critical (9.1)

The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order ful...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15361
(8.1 HIGH)

EPSS: 0.22%

updated 2026-08-07T19:17:35.543000

1 posts

The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks.

thehackerwire@mastodon.social at 2026-08-08T15:00:13.000Z ##

🟠 CVE-2026-15361 - High (8.1)

The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscrib...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59118
(9.3 CRITICAL)

EPSS: 0.39%

updated 2026-08-07T19:06:49.530000

1 posts

Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-08-07T03:00:28.000Z ##

🔴 CVE-2026-59118 - Critical (9.3)

Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16030
(8.1 HIGH)

EPSS: 0.23%

updated 2026-08-07T18:32:49

2 posts

The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts.

thehackerwire@mastodon.social at 2026-08-08T15:59:53.000Z ##

🟠 CVE-2026-16030 - High (8.1)

The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-07T09:00:26.000Z ##

MStore API WordPress plugin (<4.21.0) hit by CRITICAL vuln (CVE-2026-16030): improper phone token checks enable account takeover, incl. admins. Restrict endpoints & monitor logins until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026_16030 #Vuln

##

CVE-2026-71559
(7.5 HIGH)

EPSS: 0.59%

updated 2026-08-07T18:32:49

1 posts

Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0 before 1.5.0.  Users of other language implementations are not affected. Users are recommended to upgrade to version 1.5.0

thehackerwire@mastodon.social at 2026-08-08T12:00:29.000Z ##

🟠 CVE-2026-71559 - High (7.5)

Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic.

This issue aff...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67688
(9.8 CRITICAL)

EPSS: 0.59%

updated 2026-08-07T18:32:48

2 posts

ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.

thehackerwire@mastodon.social at 2026-08-09T14:59:59.000Z ##

🔴 CVE-2026-67688 - Critical (9.8)

ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T14:59:59.000Z ##

🔴 CVE-2026-67688 - Critical (9.8)

ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67687
(8.8 HIGH)

EPSS: 0.53%

updated 2026-08-07T18:32:48

2 posts

Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java

1 repos

https://github.com/qflksheep/CVE-2026-67687-ICS-Park-Smart-Park-Management-System-v2.0

thehackerwire@mastodon.social at 2026-08-09T14:59:50.000Z ##

🟠 CVE-2026-67687 - High (8.8)

Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T14:59:50.000Z ##

🟠 CVE-2026-67687 - High (8.8)

Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70634
(8.1 HIGH)

EPSS: 0.41%

updated 2026-08-07T18:32:48

2 posts

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path uses an assertion compiled out of release builds, leaving the 64-bit Simple8b index unvalidated and the read offset attacker-controlled. Attackers with DML

thehackerwire@mastodon.social at 2026-08-09T13:00:15.000Z ##

🟠 CVE-2026-70634 - High (8.1)

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path us...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T13:00:15.000Z ##

🟠 CVE-2026-70634 - High (8.1)

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path us...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14943
(7.5 HIGH)

EPSS: 0.26%

updated 2026-08-07T18:32:48

1 posts

The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors to bypass the sitewide password gate and read otherwise-protected content and account identifiers via the REST API. This re-introduces a previously-fixed i

thehackerwire@mastodon.social at 2026-08-08T17:00:37.000Z ##

🟠 CVE-2026-14943 - High (7.5)

The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14205
(9.8 CRITICAL)

EPSS: 0.27%

updated 2026-08-07T18:32:48

1 posts

The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.

thehackerwire@mastodon.social at 2026-08-08T16:00:12.000Z ##

🔴 CVE-2026-14205 - Critical (9.8)

The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed book...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64637
(9.9 CRITICAL)

EPSS: 0.23%

updated 2026-08-07T18:31:57

2 posts

Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.

thehackerwire@mastodon.social at 2026-08-08T08:00:39.000Z ##

🔴 CVE-2026-64637 - Critical (9.9)

Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-08T06:00:24.000Z ##

CVE-2026-64637 (CRITICAL, CVSS 9.9): WebPros Plesk <18.0.80 allows authenticated resellers to escalate privileges to root via XML-RPC API. Patch not confirmed — restrict access, monitor API use. radar.offseq.com/threat/cve-20 #OffSeq #Plesk #Vuln #PrivilegeEscalation

##

CVE-2026-20339
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-07T18:31:54

2 posts

A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. An attacker could exploit this

thehackerwire@mastodon.social at 2026-08-08T11:00:18.000Z ##

🟠 CVE-2026-20339 - High (7.5)

A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device.

This vulnerabili...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

AAKL@infosec.exchange at 2026-08-07T17:50:53.000Z ##

CISA has added one vulnerability to the KEV catalogue:

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Cisco:

NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi #Cisco

Palo Alto:

CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent security.paloaltonetworks.com/

Microsoft:

Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: msrc.microsoft.com/update-guid #Microsoft

Google:

New: Chrome Dev for Android Update chromereleases.googleblog.com/ #Google #Chrome

Broadcom:

One new advisory for a high-severity vulnerability that was first published on July 23 support.broadcom.com/web/ecx/s

Posted yesterday:

Apple security updates support.apple.com/en-us/100100 #Apple

AMD: Safe RET Interrupt Vulnerability amd.com/en/resources/product-s #AMD

Dell:

CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #infosec #vulnerability #Java #SQL

##

CVE-2026-20348
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-07T18:31:54

1 posts

A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in XAR files during scanning. An attacker could exploit this vulnerability by submitting a crafted file that

thehackerwire@mastodon.social at 2026-08-08T10:00:28.000Z ##

🟠 CVE-2026-20348 - High (7.5)

A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device.

This vulnerability ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20345
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-07T18:31:54

1 posts

A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper handling of an endian conversion operation, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerabil

thehackerwire@mastodon.social at 2026-08-08T09:00:42.000Z ##

🟠 CVE-2026-20345 - High (7.5)

A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device.

This vulnerability ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20338
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-07T18:31:53

2 posts

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to ca

thehackerwire@mastodon.social at 2026-08-08T11:00:08.000Z ##

🟠 CVE-2026-20338 - High (7.5)

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.

This vulnerability is due to improper memory handling when processing content in zip files durin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

AAKL@infosec.exchange at 2026-08-07T17:50:53.000Z ##

CISA has added one vulnerability to the KEV catalogue:

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Cisco:

NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi #Cisco

Palo Alto:

CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent security.paloaltonetworks.com/

Microsoft:

Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: msrc.microsoft.com/update-guid #Microsoft

Google:

New: Chrome Dev for Android Update chromereleases.googleblog.com/ #Google #Chrome

Broadcom:

One new advisory for a high-severity vulnerability that was first published on July 23 support.broadcom.com/web/ecx/s

Posted yesterday:

Apple security updates support.apple.com/en-us/100100 #Apple

AMD: Safe RET Interrupt Vulnerability amd.com/en/resources/product-s #AMD

Dell:

CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #infosec #vulnerability #Java #SQL

##

CVE-2026-20347
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-07T18:31:53

1 posts

A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in Mach-O files during scanning, which may result in an out-of-bounds buffer read. An attacker could expl

thehackerwire@mastodon.social at 2026-08-08T10:00:12.000Z ##

🟠 CVE-2026-20347 - High (7.5)

A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device.

This vulnerabili...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68772
(8.0 HIGH)

EPSS: 0.40%

updated 2026-08-07T18:31:53

1 posts

ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can replace a stored artifact.pkl file with a crafted cloudpickle payload containing a malicious __reduce__ method, which executes arbitrary system commands wh

thehackerwire@mastodon.social at 2026-08-08T09:00:31.000Z ##

🟠 CVE-2026-68772 - High (8)

ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20337
(7.5 HIGH)

EPSS: 0.36%

updated 2026-08-07T18:31:52

3 posts

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A success

hugovalters@mastodon.social at 2026-08-08T14:02:58.000Z ##

CVE-2026-20337 - Memory corruption in ClamAV ZIP parsing, out-of-bounds write DoS. CVSS 7.5. Unpatched. Update or mitigate immediately. #CVE #Cisco #infosec

valtersit.com/cve/CVE-2026-203

##

thehackerwire@mastodon.social at 2026-08-08T10:00:41.000Z ##

🟠 CVE-2026-20337 - High (7.5)

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.

This vulnerability is due to improper boundary checks for content in zip files during scanning, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

AAKL@infosec.exchange at 2026-08-07T17:50:53.000Z ##

CISA has added one vulnerability to the KEV catalogue:

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Cisco:

NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi #Cisco

Palo Alto:

CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent security.paloaltonetworks.com/

Microsoft:

Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: msrc.microsoft.com/update-guid #Microsoft

Google:

New: Chrome Dev for Android Update chromereleases.googleblog.com/ #Google #Chrome

Broadcom:

One new advisory for a high-severity vulnerability that was first published on July 23 support.broadcom.com/web/ecx/s

Posted yesterday:

Apple security updates support.apple.com/en-us/100100 #Apple

AMD: Safe RET Interrupt Vulnerability amd.com/en/resources/product-s #AMD

Dell:

CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #infosec #vulnerability #Java #SQL

##

CVE-2026-67621
(7.6 HIGH)

EPSS: 0.27%

updated 2026-08-07T18:31:42

2 posts

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP requests to the upsert and refresh document store routes to trigger document ingestion, refresh vector database contents, con

thehackerwire@mastodon.social at 2026-08-09T15:59:50.000Z ##

🟠 CVE-2026-67621 - High (7.6)

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T15:59:50.000Z ##

🟠 CVE-2026-67621 - High (7.6)

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70628
(7.8 HIGH)

EPSS: 0.15%

updated 2026-08-07T18:31:42

2 posts

FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-c

thehackerwire@mastodon.social at 2026-08-09T14:00:12.000Z ##

🟠 CVE-2026-70628 - High (7.8)

FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T14:00:12.000Z ##

🟠 CVE-2026-70628 - High (7.8)

FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70632
(7.8 HIGH)

EPSS: 0.21%

updated 2026-08-07T18:31:42

2 posts

FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing

thehackerwire@mastodon.social at 2026-08-09T13:00:05.000Z ##

🟠 CVE-2026-70632 - High (7.8)

FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T13:00:05.000Z ##

🟠 CVE-2026-70632 - High (7.8)

FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67622
(9.9 CRITICAL)

EPSS: 0.25%

updated 2026-08-07T18:31:41

2 posts

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without workspace ownership verification. Attackers can enumerate cross-workspace assistant metadata, retrieve file and vector s

thehackerwire@mastodon.social at 2026-08-10T00:59:51.000Z ##

🔴 CVE-2026-67622 - Critical (9.9)

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T00:59:51.000Z ##

🔴 CVE-2026-67622 - Critical (9.9)

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15733
(9.8 CRITICAL)

EPSS: 3.90%

updated 2026-08-07T18:31:37

2 posts

A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root.

secdb at 2026-08-10T00:01:32.141Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-67422
(7.5 HIGH)

EPSS: 0.58%

updated 2026-08-07T18:26:08

2 posts

### Summary Four inline processors in pymdown-extensions contain regular expressions with exponential backtracking. A single untrusted Markdown line under 50 bytes drives `markdown.markdown()` into unbounded CPU on the rendering thread (seconds at ~45 bytes, growing exponentially with each added character). All four fire in the extension's **default configuration** and are reachable through the d

thehackerwire@mastodon.social at 2026-08-10T01:00:00.000Z ##

🟠 CVE-2026-67422 - High (7.5)

pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can partition a run...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T01:00:00.000Z ##

🟠 CVE-2026-67422 - High (7.5)

pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can partition a run...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53984
(9.1 CRITICAL)

EPSS: 0.38%

updated 2026-08-07T18:17:18.960000

2 posts

Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the entire SQLite database by sending a single full_restore command with a caller-supplied SQL blob. Attackers can connect to the Socket.IO server on port 700

thehackerwire@mastodon.social at 2026-08-10T02:59:59.000Z ##

🔴 CVE-2026-53984 - Critical (9.1)

Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T02:59:59.000Z ##

🔴 CVE-2026-53984 - Critical (9.1)

Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45198
(7.8 HIGH)

EPSS: 0.12%

updated 2026-08-07T18:17:14.827000

2 posts

Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory. The GPU thread of control (Firmware) uses a pointer from non-secure memory belonging to the Rich Execution Environment (REE) when saving or retrieving internal data between the tightly coupled private memory to main mem

thehackerwire@mastodon.social at 2026-08-09T10:00:10.000Z ##

🟠 CVE-2026-45198 - High (7.8)

Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory.

The GPU thread of control (Firmware) uses a pointer from non-secur...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T10:00:10.000Z ##

🟠 CVE-2026-45198 - High (7.8)

Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory.

The GPU thread of control (Firmware) uses a pointer from non-secur...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14365
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-08-07T18:17:07.753000

2 posts

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to change the password of arbitrary user accounts, including administrators, which can b

thehackerwire@mastodon.social at 2026-08-09T09:00:10.000Z ##

🔴 CVE-2026-14365 - Critical (9.8)

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perfo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T09:00:10.000Z ##

🔴 CVE-2026-14365 - Critical (9.8)

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perfo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65667
(10.0 CRITICAL)

EPSS: 0.44%

updated 2026-08-07T18:11:23.330000

1 posts

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

AAKL@infosec.exchange at 2026-08-07T16:00:15.000Z ##

If you missed these yesterday.

"Three of the issues, CVE-2026-63508, CVE-2026-56162, and CVE-2026-65667, have a maximum severity rating of 10/10."

Security Week: Microsoft, Apple Release Fresh Security Updates securityweek.com/microsoft-app #Microsoft #Apple #infosec #vylnerability #Apple

##

CVE-2026-50515
(9.9 CRITICAL)

EPSS: 0.91%

updated 2026-08-07T18:05:55.493000

2 posts

Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-08-09T10:00:32.000Z ##

🔴 CVE-2026-50515 - Critical (9.9)

Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T10:00:32.000Z ##

🔴 CVE-2026-50515 - Critical (9.9)

Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5855
(7.5 HIGH)

EPSS: 0.54%

updated 2026-08-07T17:17:05.047000

2 posts

Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check. The caller in lwm2m-engine.c iterates while there is at least one byte remaining, so a crafted CoAP WRITE to any LwM2M endpoint whose final TLV supplies exactly one byte triggers up to five out-of-bo

thehackerwire@mastodon.social at 2026-08-10T02:00:26.000Z ##

🟠 CVE-2026-5855 - High (7.5)

Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check. The caller in lwm2m-engine.c iterates while th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T02:00:26.000Z ##

🟠 CVE-2026-5855 - High (7.5)

Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check. The caller in lwm2m-engine.c iterates while th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9169
(8.8 HIGH)

EPSS: 0.14%

updated 2026-08-07T16:17:28.807000

1 posts

DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a required dependency is not found locally.

thehackerwire@mastodon.social at 2026-08-07T17:00:51.000Z ##

🟠 CVE-2026-9169 - High (8.8)

DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH en...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-53983
(8.6 HIGH)

EPSS: 0.33%

updated 2026-08-07T16:17:25.673000

2 posts

Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to cause the ground-station process to issue outbound HTTP requests to attacker-chosen destinations. Attackers can connect to the Socket.IO server on port 7000 without credentials due to disabled authenti

thehackerwire@mastodon.social at 2026-08-10T02:59:50.000Z ##

🟠 CVE-2026-53983 - High (8.6)

Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to cause the ground-station process to issue outb...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T02:59:50.000Z ##

🟠 CVE-2026-53983 - High (8.6)

Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path that allows any unauthenticated Socket.IO client to cause the ground-station process to issue outb...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49007
(7.5 HIGH)

EPSS: 0.34%

updated 2026-08-07T16:17:25.380000

1 posts

By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface.

thehackerwire@mastodon.social at 2026-08-08T12:00:57.000Z ##

🟠 CVE-2026-49007 - High (7.5)

By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48085
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-08-07T16:17:24.773000

2 posts

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-account` and creates additional GLOBAL_ADMIN accounts without verifying that an admin already exists. Any unauthenticated network attacker who can submit a same-or

thehackerwire@mastodon.social at 2026-08-10T03:00:08.000Z ##

🔴 CVE-2026-48085 - Critical (9.8)

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-account` a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T03:00:08.000Z ##

🔴 CVE-2026-48085 - Critical (9.8)

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-account` a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67689
(9.8 CRITICAL)

EPSS: 0.69%

updated 2026-08-07T15:34:17

2 posts

SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints

1 repos

https://github.com/qflksheep/CVE-2026-67689-FineAdmin.Mvc-vulnerability

thehackerwire@mastodon.social at 2026-08-09T15:00:09.000Z ##

🔴 CVE-2026-67689 - Critical (9.8)

SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T15:00:09.000Z ##

🔴 CVE-2026-67689 - Critical (9.8)

SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19264
(9.8 CRITICAL)

EPSS: 0.63%

updated 2026-08-07T15:33:32

1 posts

Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no authentication. Raw dot-segments are collapsed before routing, but URL-encoded separators survive route matching and are decoded onl

1 repos

https://github.com/DarkLycn1976/CVE-2026-19264

thehackerwire@mastodon.social at 2026-08-07T17:00:06.000Z ##

🔴 CVE-2026-19264 - Critical (9.8)

Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54212
(0 None)

EPSS: 0.47%

updated 2026-08-07T15:17:01.830000

1 posts

Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow condition. By submitting a specially crafted JSON body, such as one that is at least 8 characters long and begins with a number, an unauthenticated attacker can cause the server to crash, resulting in denial of service. Depending on the stack state or if a stack canary can b

offseq@infosec.exchange at 2026-08-07T12:00:26.000Z ##

CVE-2026-54212: CRITICAL buffer overflow in Tobit TeamDavid Webbox API (≤ Rollout 524). Crafted JSON lets unauthenticated attackers crash servers; RCE possible if combined with other flaws. Restrict API, monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #CVE #bufferOverflow #infosec

##

CVE-2026-15816
(7.5 HIGH)

EPSS: 0.25%

updated 2026-08-07T12:32:06

1 posts

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time

thehackerwire@mastodon.social at 2026-08-07T17:00:41.000Z ##

🟠 CVE-2026-15816 - High (7.5)

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH opt...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54213(CVSS UNKNOWN)

EPSS: 0.45%

updated 2026-08-07T12:32:06

1 posts

Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This endpoint is accessible to unauthenticated users over the public Internet. Instead of “restarting”, the server shuts completely down. As a result, a remote attacker can trigger a persistent denial of service by shuttin

offseq@infosec.exchange at 2026-08-07T10:30:25.000Z ##

CVE-2026-54213: CRITICAL improper access control in Tobit TeamDavid Webbox — public /internalRestart endpoint lets remote attackers trigger persistent DoS by shutting down servers. No patch yet. Restrict access & monitor. radar.offseq.com/threat/cve-20 #OffSeq #Cybersecurity #Vuln

##

CVE-2026-54211(CVSS UNKNOWN)

EPSS: 0.41%

updated 2026-08-07T12:32:00

1 posts

Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer overflow vulnerability in multiple form data parameters. By submitting excessively long values in these parameters, an authenticated attacker can trigger a server crash, resulting in denial of service. Depending on the stack state or if a stack canary can be disclosed through

offseq@infosec.exchange at 2026-08-07T13:30:16.000Z ##

Tobit TeamDavid (Webbox ≤ Rollout 524) hit by CRITICAL buffer overflow (CVE-2026-54211). Authenticated attackers can crash servers; possible RCE if stack canary is disclosed. Restrict access & monitor. No patch yet. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #InfoSec

##

CVE-2026-14364
(9.8 CRITICAL)

EPSS: 0.29%

updated 2026-08-07T06:30:34

2 posts

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity before resetting their password. This makes it possible for unauthenticated attackers to reset the password of arbitrary user accounts,

thehackerwire@mastodon.social at 2026-08-09T08:59:59.000Z ##

🔴 CVE-2026-14364 - Critical (9.8)

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validatin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T08:59:59.000Z ##

🔴 CVE-2026-14364 - Critical (9.8)

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validatin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19191
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-07T06:30:26

1 posts

A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such manipulation leads to permission issues. The attack must be carried out locally. The exploit has been disclosed publicly and may be used.

thehackerwire@mastodon.social at 2026-08-08T17:00:47.000Z ##

🟠 CVE-2026-19191 - High (7.8)

A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such manipulation lead...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19190
(7.8 HIGH)

EPSS: 0.14%

updated 2026-08-07T06:30:25

2 posts

A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe of the component ScannerService. This manipulation causes permission issues. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks.

thehackerwire@mastodon.social at 2026-08-09T09:00:20.000Z ##

🟠 CVE-2026-19190 - High (7.8)

A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe of the component ScannerService. This manipulation causes permission iss...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T09:00:20.000Z ##

🟠 CVE-2026-19190 - High (7.8)

A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe of the component ScannerService. This manipulation causes permission iss...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65400
(7.1 HIGH)

EPSS: 0.30%

updated 2026-08-07T03:31:32

1 posts

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

nicd@masto.ahlcode.fi at 2026-08-08T21:51:23.000Z ##

Whoa, macOS Sequoia 15.7.9 changes:

> An attacker on the network may be able to authenticate to Screen Sharing without valid credentials

xcancel.com/calif_io/status/20

> If Screen Sharing is enabled, any network attacker can exploit the bug to log in as any account, without knowing the password.

Good thing it requires screen sharing to be enabled though.

CVE-2026-65400

##

CVE-2026-19189
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-07T03:30:38

2 posts

A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys of the component Kernel Driver. The manipulation results in improper privilege management. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The vendor

thehackerwire@mastodon.social at 2026-08-09T10:00:21.000Z ##

🟠 CVE-2026-19189 - High (7.8)

A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys of the component Kernel Driver. The manipulation results in improper ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T10:00:21.000Z ##

🟠 CVE-2026-19189 - High (7.8)

A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys of the component Kernel Driver. The manipulation results in improper ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63508
(10.0 CRITICAL)

EPSS: 0.44%

updated 2026-08-07T00:31:33

2 posts

Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.

AAKL@infosec.exchange at 2026-08-07T16:00:15.000Z ##

If you missed these yesterday.

"Three of the issues, CVE-2026-63508, CVE-2026-56162, and CVE-2026-65667, have a maximum severity rating of 10/10."

Security Week: Microsoft, Apple Release Fresh Security Updates securityweek.com/microsoft-app #Microsoft #Apple #infosec #vylnerability #Apple

##

offseq@infosec.exchange at 2026-08-07T04:30:24.000Z ##

CVE-2026-63508 (CRITICAL, CVSS 10): Microsoft Planetary Computer Pro (GeoCatalog) suffers from missing authentication, enabling remote privilege escalation. Immediate patching recommended. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Microsoft #Infosec

##

CVE-2026-62873
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-08-07T00:31:33

1 posts

Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.

offseq@infosec.exchange at 2026-08-07T03:00:26.000Z ##

CVE-2026-62873 (CRITICAL, CVSS 9.8) affects Microsoft 365 Admin Center: Improper cryptographic signature checks allow privilege escalation over the network. Microsoft has issued a fix — confirm your environment is patched. radar.offseq.com/threat/cve-20 #OffSeq #Microsoft365 #Vuln

##

CVE-2026-49163
(8.8 HIGH)

EPSS: 0.62%

updated 2026-08-07T00:31:28

2 posts

Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-08-09T11:01:06.000Z ##

🟠 CVE-2026-49163 - High (8.8)

Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T11:01:06.000Z ##

🟠 CVE-2026-49163 - High (8.8)

Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56161
(9.6 CRITICAL)

EPSS: 0.38%

updated 2026-08-07T00:31:28

2 posts

Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

thehackerwire@mastodon.social at 2026-08-09T11:00:47.000Z ##

🔴 CVE-2026-56161 - Critical (9.6)

Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T11:00:47.000Z ##

🔴 CVE-2026-56161 - Critical (9.6)

Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59115
(9.9 CRITICAL)

EPSS: 0.64%

updated 2026-08-07T00:31:28

1 posts

'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-08-07T03:00:17.000Z ##

🔴 CVE-2026-59115 - Critical (9.9)

'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70559
(7.5 HIGH)

EPSS: 0.33%

updated 2026-08-07T00:31:27

2 posts

Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-level @SaCheckLogin, so the Sa-Token interceptor lets the request through with no session or role check. Any remote unauthenticated caller who can reach the Dinky HTTP port (8888 by default) receives the full live system configuration (54 entries on a

1 repos

https://github.com/codeb0ssx/CVE-2026-70559-PoC

thehackerwire@mastodon.social at 2026-08-09T14:00:02.000Z ##

🟠 CVE-2026-70559 - High (7.5)

Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-level @SaCheckLogin, so the Sa-Token interceptor lets the request through with no session or role ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T14:00:02.000Z ##

🟠 CVE-2026-70559 - High (7.5)

Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-level @SaCheckLogin, so the Sa-Token interceptor lets the request through with no session or role ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56162
(10.0 CRITICAL)

EPSS: 0.48%

updated 2026-08-07T00:31:27

3 posts

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-08-09T11:00:57.000Z ##

🔴 CVE-2026-56162 - Critical (10)

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-09T11:00:57.000Z ##

🔴 CVE-2026-56162 - Critical (10)

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

AAKL@infosec.exchange at 2026-08-07T16:00:15.000Z ##

If you missed these yesterday.

"Three of the issues, CVE-2026-63508, CVE-2026-56162, and CVE-2026-65667, have a maximum severity rating of 10/10."

Security Week: Microsoft, Apple Release Fresh Security Updates securityweek.com/microsoft-app #Microsoft #Apple #infosec #vylnerability #Apple

##

CVE-2026-62836
(8.7 HIGH)

EPSS: 0.36%

updated 2026-08-07T00:31:27

1 posts

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-08-07T03:00:06.000Z ##

🟠 CVE-2026-62836 - High (8.7)

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16633(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-08-06T21:12:27

1 posts

### Impact If PDF.js is used to load a malicious PDF, and PDF.js is configured with `enableScripting` set to true (which is the default value) and no CSP for disallowing script-src, unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain. ### Patches ### Workarounds Set `enableScripting` to `false` or set a CSP.

offseq@infosec.exchange at 2026-08-07T06:00:24.000Z ##

Vulnerability in ngx-extended-pdf-viewer (HIGH): Bundled pdf.js exposes XFA (enabled by default), risking JS execution via malicious PDFs (CVE-2026-16633). Update to 29.0.0-rc.3 or disable XFA for mitigation. radar.offseq.com/threat/ngx-ex #OffSeq #Vulnerability #PDF #Infosec

##

CVE-2026-64665
(8.1 HIGH)

EPSS: 0.31%

updated 2026-08-06T19:25:06

2 posts

### Impact When OAuth login is enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user — potentially including a super admin — without their password. Exploitation requires OAuth to be explicitly enabled with such a provider. ### Patches Fixed in 5.74.1 and 6.24.0. ### Workarounds Only enable OAuth with providers

thehackerwire@mastodon.social at 2026-08-10T01:00:10.000Z ##

🟠 CVE-2026-64665 - High (8.1)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an exist...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T01:00:10.000Z ##

🟠 CVE-2026-64665 - High (8.1)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an exist...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19036
(7.2 HIGH)

EPSS: 2.47%

updated 2026-08-06T15:32:48

2 posts

A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This project is superseded by FreshTomato.

secdb at 2026-08-10T00:01:32.141Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-19034
(7.2 HIGH)

EPSS: 2.47%

updated 2026-08-06T12:31:21

2 posts

A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimittc_stop.sh. Executing a manipulation of the argument wan_iface can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato.

secdb at 2026-08-10T00:01:32.141Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-19035
(7.2 HIGH)

EPSS: 2.47%

updated 2026-08-06T12:31:21

2 posts

A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This project is superseded by FreshTomato.

secdb at 2026-08-10T00:01:32.141Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-5430
(10.0 CRITICAL)

EPSS: 0.22%

updated 2026-08-06T09:30:40

1 posts

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of adm

DailyCyberSecurity@infosec.exchange at 2026-08-07T13:05:48.000Z ##

WSO2 patched four critical account takeover flaws, including CVE-2026-5430 at CVSS 10 via JWT auth bypass. Details and fixes inside.

#WSO2 #AccountTakeover #CVE #APIsecurity #CyberSecurity

securityonline.info/wso2-accou

##

CVE-2026-17650
(8.3 HIGH)

EPSS: 0.35%

updated 2026-08-06T00:36:25.360000

2 posts

Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

security_crawler_carl at 2026-08-10T03:03:06.734Z ##

🏆 New Achievement! Three Hundred and Seventy Reasons to Click Update!

Here, in its natural habitat, the unpatched browser clings stubbornly to an older Chrome build while the predator closes in. Google released Chrome 151 on July 28, 2026, correcting 370 vulnerabilities in a single migration — seven rated critical, spanning CVE-2026-17650 through CVE-2026-17656, with another 71 rated high severity. Naturalists observe this is among the largest single-release security drops of the year. (1/2)

##

security_crawler_carl@infosec.exchange at 2026-08-10T03:03:06.000Z ##

🏆 New Achievement! Three Hundred and Seventy Reasons to Click Update!

Here, in its natural habitat, the unpatched browser clings stubbornly to an older Chrome build while the predator closes in. Google released Chrome 151 on July 28, 2026, correcting 370 vulnerabilities in a single migration — seven rated critical, spanning CVE-2026-17650 through CVE-2026-17656, with another 71 rated high severity. Naturalists observe this is among the largest single-release security drops of the year. (1/2)

##

CVE-2026-17656
(9.6 CRITICAL)

EPSS: 0.40%

updated 2026-08-06T00:30:24.850000

2 posts

Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

security_crawler_carl at 2026-08-10T03:03:06.734Z ##

🏆 New Achievement! Three Hundred and Seventy Reasons to Click Update!

Here, in its natural habitat, the unpatched browser clings stubbornly to an older Chrome build while the predator closes in. Google released Chrome 151 on July 28, 2026, correcting 370 vulnerabilities in a single migration — seven rated critical, spanning CVE-2026-17650 through CVE-2026-17656, with another 71 rated high severity. Naturalists observe this is among the largest single-release security drops of the year. (1/2)

##

security_crawler_carl@infosec.exchange at 2026-08-10T03:03:06.000Z ##

🏆 New Achievement! Three Hundred and Seventy Reasons to Click Update!

Here, in its natural habitat, the unpatched browser clings stubbornly to an older Chrome build while the predator closes in. Google released Chrome 151 on July 28, 2026, correcting 370 vulnerabilities in a single migration — seven rated critical, spanning CVE-2026-17650 through CVE-2026-17656, with another 71 rated high severity. Naturalists observe this is among the largest single-release security drops of the year. (1/2)

##

CVE-2026-63077
(9.8 CRITICAL)

EPSS: 1.01%

updated 2026-08-05T18:32:31

2 posts

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Nuclei template

4 repos

https://github.com/sfewer-r7/CVE-2026-63077

https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation

https://github.com/AnggaTechI/CVE-2026-63077

https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap

CVE-2026-70374
(8.8 HIGH)

EPSS: 2.52%

updated 2026-08-05T15:32:14

2 posts

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail() in src/Server/Entity/Resource/Media.js builds a temporary file path as 'thumbnail' + Path.extname(filename) and passes it, unescaped, into a shell command executed via AppService.exec() ('convert ' + tempFile + ...). The MIME-type filter in

secdb at 2026-08-10T00:01:32.141Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-66747
(9.8 CRITICAL)

EPSS: 0.58%

updated 2026-08-05T15:17:04.690000

1 posts

Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP

DailyCyberSecurity@infosec.exchange at 2026-08-07T02:30:41.000Z ##

CVE-2026-66747: a Zbtlink router backdoor named ENDLESSDOORS gives unauthenticated remote code execution as root. No fix exists. CVSS 9.8.

#Zbtlink #RouterBackdoor #CVE #IoT #CyberSecurity

securityonline.info/zbtlink-ro

##

CVE-2026-18902
(7.2 HIGH)

EPSS: 2.38%

updated 2026-08-05T06:30:32

2 posts

A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. Performing a manipulation of the argument my2P4key results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure.

secdb at 2026-08-10T00:01:32.141Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18900
(7.2 HIGH)

EPSS: 2.38%

updated 2026-08-05T06:30:31

2 posts

A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This manipulation of the argument File causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.

secdb at 2026-08-10T00:01:32.141Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18814
(7.2 HIGH)

EPSS: 2.71%

updated 2026-08-05T00:30:41

2 posts

A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. The manipulation results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.

secdb at 2026-08-10T00:01:32.141Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-9198
(9.8 CRITICAL)

EPSS: 17.05%

updated 2026-08-04T21:30:25

1 posts

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

4 repos

https://github.com/rmhowe425/PoC-CVE-2026-9198

https://github.com/0xdak/CVE-2026-9198_exploit

https://github.com/ywh-jfellus/CVE-2026-9198

https://github.com/0xgh057r3c0n/CVE-2026-9198

security_crawler_carl@infosec.exchange at 2026-08-07T07:27:32.000Z ##

🏆 New Achievement! Patch Notes From Hell!

Version 2026.08 changelog: ADDED — Chinese-speaking threat actor manually planting reverse shells on Apache Tomcat servers via CVE-2026-34486, itself an incomplete fix for the 9.8-rated CVE-2026-29146. ADDED — unauthenticated admin account hijacking on N-able's N-central via CVE-2026-18576. ADDED — critical 9.8-rated remote code execution at root on IBM Langflow via CVE-2026-9198. (1/2)

##

CVE-2026-64633(CVSS UNKNOWN)

EPSS: 0.34%

updated 2026-08-04T18:31:36

1 posts

A vulnerability allowing remote unauthenticated code execution on the agent host.

1 repos

https://github.com/tfawnies/CVE-2026-64633

beyondmachines1@infosec.exchange at 2026-08-07T09:01:07.000Z ##

Veeam ONE Patches Critical Remote Code Execution and SQL Injection Flaws

Veeam ONE version 13 contains six vulnerabilities, including a CVSS 10.0 critical remote code execution flaw and a high-severity SQL injection bug. These vulnerabilities allow unauthenticated attackers to take over agent hosts, read arbitrary files, and extract sensitive database information.

**If you run Veeam ONE version 13, update it to build 13.1.0.7034. One of these flaws (CVE-2026-64633) lets an attacker take over the system remotely without any login or clicks from you. While you're at it, make sure Veeam ONE is only reachable from your trusted admin network, not from the internet or the general user network.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-18577
(8.1 HIGH)

EPSS: 4.10%

updated 2026-08-04T15:33:20

1 posts

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

2 repos

https://github.com/CreamyG31337/ncentral-compromise-ioc-triage

https://github.com/HORKimhab/CVE-2026-18577

ransomnews.online@bsky.brid.gy at 2026-08-08T07:37:08.000Z ##

⚠️ N-central auth bypass exploited in attacks

CVE-2026-18577 enables admin takeover; N-able issued an urgent hotfix.
🔗 read more: www.bleepingcomputer...

#ransomNews #cybersecurity


N-able warns of N-central auth...

##

CVE-2026-29146
(7.5 HIGH)

EPSS: 6.26%

updated 2026-08-04T13:18:02.797000

1 posts

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

security_crawler_carl@infosec.exchange at 2026-08-07T07:27:32.000Z ##

🏆 New Achievement! Patch Notes From Hell!

Version 2026.08 changelog: ADDED — Chinese-speaking threat actor manually planting reverse shells on Apache Tomcat servers via CVE-2026-34486, itself an incomplete fix for the 9.8-rated CVE-2026-29146. ADDED — unauthenticated admin account hijacking on N-able's N-central via CVE-2026-18576. ADDED — critical 9.8-rated remote code execution at root on IBM Langflow via CVE-2026-9198. (1/2)

##

CVE-2024-49039
(8.8 HIGH)

EPSS: 13.72%

updated 2026-08-04T05:16:30.980000

1 posts

Windows Task Scheduler Elevation of Privilege Vulnerability

2 repos

https://github.com/je5442804/WPTaskScheduler_CVE-2024-49039

https://github.com/razureink/cve-2024-49039-task_scheduler_eop_reproduction

infosecbot@mastodon.hofud.com at 2026-08-10T06:50:32.000Z ##

[1/4]

Most impactful security incidents and vulnerabilities reported in the last ≈ 30 days (up to 2024‑09‑03)

1
• CVE‑2024‑49039
• Windows Task Scheduler (TaskScheduler service)
• Privilege‑escalation: a low‑privileged AppContainer can break out and invoke privileged RPC functions. CVSS ≈ 8.8; actively exploited by ransomware groups.
• All supported Windows 10/11 and Server 2019/2022 builds released before the 2024‑09‑03 patch.
• <msrc.microsoft.com/update-guid>

2
• CVE‑2024‑43451
• Microsoft Windows NTLMv2 authentication (hash handling)
• Remote attacker can force a file‑open that leaks the user’s NTLMv2 hash, enabling pass‑the‑hash attacks. CVSS ≈ 8.1; directly compromises credential confidentiality.
• All supported Windows 10/11 and Server editions up to build 22631 (pre‑2024‑09‑03).
• <msrc.microsoft.com/update-guid>

3
• CVE‑2024‑38193
• Windows Ancillary Function Driver for WinSock (AFD)
• Unspecified kernel flaw that grants SYSTEM privileges to a local attacker. CVSS ≈ 8.5; part of the “privilege‑escalation” wave in the networking stack.
• Windows 10 22H2, Windows 11 and Server 2022 before 2024‑09‑03.
• <msrc.microsoft.com/update-guid>

4
• CVE‑2024‑38178
• Windows Scripting Engine (JScript/VBScript)
• Memory‑corruption bug that enables remote code execution via a crafted URL, bypassing same‑origin protections. CVSS ≈ 8.6; network‑reachable RCE.
• All supported Windows 10/11 and Server releases prior to 2024‑09‑03.
• <msrc.microsoft.com/update-guid>

5
• CVE‑2024‑36971
• Android kernel (Linux)
• Remote‑code‑execution via use‑after‑free/heap overflow in the core OS. CVSS ≈ 9.0; affects billions of smartphones and can be weaponised by ransomware.
• Android 13 & 14 builds with kernel ≤ 5.15.112 before September 2024 patch.
• <nvd.nist.gov/vuln/detail/CVE-2>

#infosecnews

##

CVE-2026-18686
(9.8 CRITICAL)

EPSS: 2.61%

updated 2026-08-04T00:35:01

2 posts

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of

secdb at 2026-08-10T00:01:32.141Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-18601
(9.8 CRITICAL)

EPSS: 2.38%

updated 2026-08-03T15:32:55

2 posts

A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Performing a manipulation of the argument filename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about

secdb at 2026-08-10T00:01:32.141Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-08-10T00:01:32.000Z ##

📈 CVE Published in last 7 days (2026-08-03 - 2026-08-03)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 278
- High: 722
- Medium: 598
- Low: 162
- None: 112

Status:
- : 16
- Analyzed: 213
- Awaiting Analysis: 104
- Modified: 15
- Received: 1433
- Rejected: 37
- Undergoing Analysis: 54

CISA KEVs:
- CISA-2026:0803 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0805 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0804 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0807 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- GitHub, Inc.: 256
- VulDB: 195
- WPScan: 179
- VulnCheck: 146
- Patchstack: 99
- TuranSec: 89
- Apache Software Foundation: 61
- Wordfence: 60
- MITRE: 57
- kernel.org: 46

Top Affected Products:
- UNKNOWN: 1580
- Google Chrome: 38
- Langflow: 24
- Nvidia Dynamo: 15
- Microsoft Edge Chromium: 14
- Apache Cxf: 12
- Wso2 Api Manager: 10
- Qualcomm Qca6696 Firmware: 9
- Qualcomm Wsa8845 Firmware: 9
- Qualcomm Wsa8840 Firmware: 9

Top EPSS Score:
- CVE-2026-15733 - 3.90 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18814 - 2.71 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18686 - 2.61 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-70374 - 2.52 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19034 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19035 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-19036 - 2.47 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18900 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18902 - 2.38 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-18601 - 2.38 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-64531
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-01T09:30:23

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guar

4 repos

https://github.com/suominen/ovswrap

https://github.com/HackSpeak/CVE-2026-64531

https://github.com/mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool

https://github.com/0xBlackash/CVE-2026-64531

sigint@fosstodon.org at 2026-08-09T23:45:08.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-08-10

CVE-2026-64531 hits hosts even if they never touch OVS, with a public PoC across ~800 builds. Local privesc to root on any container or VM host running the module means patch now, not next maintenance window.

🔗 thehackernews.com/2026/08/new-

#Ubuntu #Linux #infosec

##

CVE-2026-28323
(9.8 CRITICAL)

EPSS: 0.64%

updated 2026-07-30T18:31:47

1 posts

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

AAKL@infosec.exchange at 2026-08-07T17:20:10.000Z ##

This post is from yesterday.

Note: Arctic Wolf will sell your data without consent. You need to scroll to the bottom and opt out of being sold to unscrupulous third-parties.

Arctic Wolf: SolarWinds Web Help Desk Vulnerabilities: CVE-2026-28323 and CVE-2026-28299 arcticwolf.com/resources/blog/ #infosec #vulnerability #privacy

##

CVE-2026-64560
(7.8 HIGH)

EPSS: 0.12%

updated 2026-07-30T12:19:03.630000

3 posts

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sys_timer_delete() exec() posix_cpu_timer_del() // Observes old leader p = pid_task(pid, pid_type); de_thread() switch_leader(); release

1 repos

https://github.com/villager1314/CVE-2026-64560-Analysis

nemo@mas.to at 2026-08-08T11:54:34.000Z ##

🚨 Tails has released an emergency security update: Tails 7.10.1, patching critical flaws that could enable privilege escalation and potentially deanonymize users. It fixes CVE-2026-64560 (Linux kernel) and multiple Expat XML library issues. 🔐➡️ cyberinsider.com/tails-emergen #Tails #Tor #Cybersecurity #Privacy #SecurityUpdate

##

DailyCyberSecurity@infosec.exchange at 2026-08-07T12:44:55.000Z ##

Tails 7.10.1 patches CVE-2026-64560, a Linux kernel race condition letting a compromised Tor Browser gain root and deanonymize users via a malicious website.

#Tails #CVE202664560 #LinuxKernel #TorBrowser #Deanonymization #PrivilegeEscalation #AnonymityOS #TailsOS

meterpreter.org/tails-cve-2026

##

DailyCyberSecurity@infosec.exchange at 2026-08-07T10:22:14.000Z ##

Tails 7.10.1 patches CVE-2026-64560 in the Linux kernel and expat library flaws that could let attackers deanonymize users and gain admin privileges.

#Tails #Linux #Privacy #CVE202664560 #Cybersecurity #AnonymousOS

securityonline.info/tails-7-10

##

CVE-2025-68260
(7.8 HIGH)

EPSS: 0.16%

updated 2026-07-30T06:33:30

1 posts

In the Linux kernel, the following vulnerability has been resolved: rust_binder: fix race condition on death_list Rust Binder contains the following unsafe operation: // SAFETY: A `NodeDeath` is never inserted into the death list // of any node other than its owner, so it is either in this // death list or in no death list. unsafe { node_inner.death_list.remove(self) }; This operation is u

mrmasterkeyboard@mastodon.social at 2026-08-07T02:22:44.000Z ##

@cloudskater

For one, Rust is vibecoded now. There are Claude commits in it and probably more than GitHub is willing to tell me.
Two, users try to rewrite everything to Rust when there is no point. When Rust was no longer experimental in Linux it caused CVEs (CVE-2025-68260).
Three, Rust projects can take 10 seconds to compile or 20 minutes.
Four, it uses LLVM and that's bloated and vibecoded now.
Five, I generally just don't like it either. I prefer C and some other similar langs much more.

##

CVE-2026-60206
(9.9 CRITICAL)

EPSS: 0.49%

updated 2026-07-28T14:14:37.463000

1 posts

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SAML to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significa

4 repos

https://github.com/Debajyoti0-0/CVE-2026-60206

https://github.com/tc4dy/CVE-2026-60206-PoC-Exploit

https://github.com/imbas007/POC-CVE-2026-60206

https://github.com/0xBlackash/CVE-2026-60206

bitsontape@privacysafe.social at 2026-08-09T07:20:04.000Z ##

🔬 The best bytes of #science & #tech across the #fediverse

“Interesting Git repos of the week:Detection:* github․com/Yamato-Security/WELA - improve your Windows loggingBugs:* github․com/timb-machine-mirrors/imbas007-POC-CVE-2026-60206 - popping WebLogic via SAMLExploitat…”

infosec.exchange/@timb_machine

🤖 via RSS feed. Not an endorsement.

##

CVE-2025-68686
(5.9 MEDIUM)

EPSS: 1.26%

updated 2026-07-28T05:17:04.113000

1 posts

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases

daniel1820815@infosec.exchange at 2026-08-07T08:36:00.000Z ##

Hackers bypass patch using new FortiOS vulnerability

An actively exploited #vulnerability in #FortiOS allows for the bypass of a previous protection mechanism against manipulated symbolic links. Affected systems should be updated and checked for prior compromise.

Sensitive information on potentially compromised #FortiGate systems running FortiOS with SSL-VPN enabled may be at risk.

euvd.enisa.europa.eu/vulnerabi

Source: security-insider.de/fortios-ss

#Fortinet #CVE

##

CVE-2026-60667
(7.4 HIGH)

EPSS: 0.33%

updated 2026-07-24T21:32:15

1 posts

Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Core). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise PeopleSoft Enterprise HCM Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion

AwkwardTuring@infosec.exchange at 2026-08-07T08:07:34.000Z ##

@da_667 oh the number of times my sleep deprived brain tried to understand how the text in front of me relates to the CVE I thought to analyse *UNTIL I FIGURED THE SEARCH RESULTS WERE BORKED AND CVE-2026-60667 IS IN FACT NOT THE CVE I WAS ORIGINALLY LOOKING FOR* gave me serious PTSD.

Relieved to see I'm not the dumbo after all.

##

CVE-2026-65535
(4.3 MEDIUM)

EPSS: 0.18%

updated 2026-07-23T14:17:59.510000

1 posts

Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.

dan@discuss.systems at 2026-08-08T02:15:49.000Z ##

CVE-2026-65535: Ranch Overflow

##

CVE-2026-34348
(6.5 MEDIUM)

EPSS: 0.71%

updated 2026-07-14T18:31:58

1 posts

Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.

obivan@infosec.exchange at 2026-08-08T16:23:05.000Z ##

@adamshostack @gsuberland the main vulnerability is CVE-2026-34348. As I understood, a signature of sign-in is stored in event log, which can be replayed and used for impersonation, as there is no validation of reused signatures in Entra ID.

##

CVE-2026-0288
(7.5 HIGH)

EPSS: 0.84%

updated 2026-07-10T15:45:17.463000

1 posts

Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server

AAKL@infosec.exchange at 2026-08-07T17:50:53.000Z ##

CISA has added one vulnerability to the KEV catalogue:

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability cve.org/CVERecord?id=CVE-2026- #CISA

Cisco:

NEW: CVE-2026-20337, CVE-2026-20338, and CVE-2026-20339: ClamAV Vulnerabilities Affecting Cisco Products: August 2026 sec.cloudapps.cisco.com/securi #Cisco

Palo Alto:

CRITICAL, NEW: CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent security.paloaltonetworks.com/

Microsoft:

Several updates for a slew of vulnerabilities were posted today on the Microsoft Update Guide: msrc.microsoft.com/update-guid #Microsoft

Google:

New: Chrome Dev for Android Update chromereleases.googleblog.com/ #Google #Chrome

Broadcom:

One new advisory for a high-severity vulnerability that was first published on July 23 support.broadcom.com/web/ecx/s

Posted yesterday:

Apple security updates support.apple.com/en-us/100100 #Apple

AMD: Safe RET Interrupt Vulnerability amd.com/en/resources/product-s #AMD

Dell:

CRITICAL, last updated yesterday: Dell PowerMaxOS, Dell PowerMax EEM, Dell Unisphere for PowerMax, Dell Solutions Enabler Security Update for Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #infosec #vulnerability #Java #SQL

##

CVE-2025-8088
(8.8 HIGH)

EPSS: 94.55%

updated 2026-06-17T10:06:17.243000

1 posts

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

31 repos

https://github.com/nuky-alt/CVE-2025-8088

https://github.com/pentestfunctions/CVE-2025-8088-Multi-Document

https://github.com/sxyrxyy/CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit-

https://github.com/pentestfunctions/best-CVE-2025-8088

https://github.com/walidpyh/CVE-2025-8088

https://github.com/nhattanhh/CVE-2025-8088

https://github.com/jordan922/CVE-2025-8088

https://github.com/AdityaBhatt3010/CVE-2025-8088-WinRAR-Zero-Day-Path-Traversal

https://github.com/Lewis-Ricardo/Amaranth-Project

https://github.com/lennertdefauw/CVE-2025-8088

https://github.com/travisbgreen/cve-2025-8088

https://github.com/papcaii2004/CVE-2025-8088-WinRAR-builder

https://github.com/IsmaelCosma/CVE-2025-8088

https://github.com/pexlexity/WinRAR-CVE-2025-8088-Path-Traversal-PoC

https://github.com/ghostn4444/CVE-2025-8088

https://github.com/hexsecteam/CVE-2025-8088-Winrar-Tool

https://github.com/Syrins/CVE-2025-8088-Winrar-Tool-Gui

https://github.com/Shinkirou789/Cve-2025-8088-WinRar-vulnerability

https://github.com/xi0onamdev/WinRAR-CVE-2025-8088-Exploitation-Toolkit

https://github.com/aldisakti2/CVE-2025-8088-BUILDER-Winrar-Tool

https://github.com/techcorp/CVE-2025-8088-Exploit

https://github.com/undefined-name12/CVE-2025-8088-Winrar

https://github.com/ilhamrzr/RAR-Anomaly-Inspector

https://github.com/pescada-dev/-CVE-2025-8088

https://github.com/kitsuneshade/WinRAR-Exploit-Tool---Rust-Edition

https://github.com/starfallreverie/winrar-exploit

https://github.com/onlytoxi/CVE-2025-8088-Winrar-Tool

https://github.com/shaheeryasirofficial/CVE-2025-8088

https://github.com/0xAbolfazl/CVE-2025-8088-WinRAR-PathTraversal-PoC

https://github.com/hbesljx/CVE-2025-8088-EXP

https://github.com/knight0x07/WinRAR-CVE-2025-8088-PoC-RAR

kev_Stalker@infosec.exchange at 2026-08-07T04:40:25.000Z ##

CVE-2025-8088 - Changed to Known Ransomware Status

RARLAB WinRAR Path Traversal VulnerabilityVendor: RARLABProduct: WinRARRARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 06, 2026 at 14:08:17 UTCDate nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2024-43451
(6.5 MEDIUM)

EPSS: 81.82%

updated 2026-06-17T07:51:04.273000

1 posts

NTLM Hash Disclosure Spoofing Vulnerability

2 repos

https://github.com/RonF98/CVE-2024-43451-POC

https://github.com/razureink/cve-2024-43451-ntlm_hash_disclosure_reproduction

infosecbot@mastodon.hofud.com at 2026-08-10T06:50:32.000Z ##

[1/4]

Most impactful security incidents and vulnerabilities reported in the last ≈ 30 days (up to 2024‑09‑03)

1
• CVE‑2024‑49039
• Windows Task Scheduler (TaskScheduler service)
• Privilege‑escalation: a low‑privileged AppContainer can break out and invoke privileged RPC functions. CVSS ≈ 8.8; actively exploited by ransomware groups.
• All supported Windows 10/11 and Server 2019/2022 builds released before the 2024‑09‑03 patch.
• <msrc.microsoft.com/update-guid>

2
• CVE‑2024‑43451
• Microsoft Windows NTLMv2 authentication (hash handling)
• Remote attacker can force a file‑open that leaks the user’s NTLMv2 hash, enabling pass‑the‑hash attacks. CVSS ≈ 8.1; directly compromises credential confidentiality.
• All supported Windows 10/11 and Server editions up to build 22631 (pre‑2024‑09‑03).
• <msrc.microsoft.com/update-guid>

3
• CVE‑2024‑38193
• Windows Ancillary Function Driver for WinSock (AFD)
• Unspecified kernel flaw that grants SYSTEM privileges to a local attacker. CVSS ≈ 8.5; part of the “privilege‑escalation” wave in the networking stack.
• Windows 10 22H2, Windows 11 and Server 2022 before 2024‑09‑03.
• <msrc.microsoft.com/update-guid>

4
• CVE‑2024‑38178
• Windows Scripting Engine (JScript/VBScript)
• Memory‑corruption bug that enables remote code execution via a crafted URL, bypassing same‑origin protections. CVSS ≈ 8.6; network‑reachable RCE.
• All supported Windows 10/11 and Server releases prior to 2024‑09‑03.
• <msrc.microsoft.com/update-guid>

5
• CVE‑2024‑36971
• Android kernel (Linux)
• Remote‑code‑execution via use‑after‑free/heap overflow in the core OS. CVSS ≈ 9.0; affects billions of smartphones and can be weaponised by ransomware.
• Android 13 & 14 builds with kernel ≤ 5.15.112 before September 2024 patch.
• <nvd.nist.gov/vuln/detail/CVE-2>

#infosecnews

##

CVE-2024-38193
(7.8 HIGH)

EPSS: 27.56%

updated 2026-06-17T07:39:39.247000

1 posts

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

1 repos

https://github.com/killvxk/CVE-2024-38193-Nephster

infosecbot@mastodon.hofud.com at 2026-08-10T06:50:32.000Z ##

[1/4]

Most impactful security incidents and vulnerabilities reported in the last ≈ 30 days (up to 2024‑09‑03)

1
• CVE‑2024‑49039
• Windows Task Scheduler (TaskScheduler service)
• Privilege‑escalation: a low‑privileged AppContainer can break out and invoke privileged RPC functions. CVSS ≈ 8.8; actively exploited by ransomware groups.
• All supported Windows 10/11 and Server 2019/2022 builds released before the 2024‑09‑03 patch.
• <msrc.microsoft.com/update-guid>

2
• CVE‑2024‑43451
• Microsoft Windows NTLMv2 authentication (hash handling)
• Remote attacker can force a file‑open that leaks the user’s NTLMv2 hash, enabling pass‑the‑hash attacks. CVSS ≈ 8.1; directly compromises credential confidentiality.
• All supported Windows 10/11 and Server editions up to build 22631 (pre‑2024‑09‑03).
• <msrc.microsoft.com/update-guid>

3
• CVE‑2024‑38193
• Windows Ancillary Function Driver for WinSock (AFD)
• Unspecified kernel flaw that grants SYSTEM privileges to a local attacker. CVSS ≈ 8.5; part of the “privilege‑escalation” wave in the networking stack.
• Windows 10 22H2, Windows 11 and Server 2022 before 2024‑09‑03.
• <msrc.microsoft.com/update-guid>

4
• CVE‑2024‑38178
• Windows Scripting Engine (JScript/VBScript)
• Memory‑corruption bug that enables remote code execution via a crafted URL, bypassing same‑origin protections. CVSS ≈ 8.6; network‑reachable RCE.
• All supported Windows 10/11 and Server releases prior to 2024‑09‑03.
• <msrc.microsoft.com/update-guid>

5
• CVE‑2024‑36971
• Android kernel (Linux)
• Remote‑code‑execution via use‑after‑free/heap overflow in the core OS. CVSS ≈ 9.0; affects billions of smartphones and can be weaponised by ransomware.
• Android 13 & 14 builds with kernel ≤ 5.15.112 before September 2024 patch.
• <nvd.nist.gov/vuln/detail/CVE-2>

#infosecnews

##

CVE-2024-38178
(7.5 HIGH)

EPSS: 41.38%

updated 2026-06-17T07:39:37.397000

1 posts

Scripting Engine Memory Corruption Vulnerability

infosecbot@mastodon.hofud.com at 2026-08-10T06:50:32.000Z ##

[1/4]

Most impactful security incidents and vulnerabilities reported in the last ≈ 30 days (up to 2024‑09‑03)

1
• CVE‑2024‑49039
• Windows Task Scheduler (TaskScheduler service)
• Privilege‑escalation: a low‑privileged AppContainer can break out and invoke privileged RPC functions. CVSS ≈ 8.8; actively exploited by ransomware groups.
• All supported Windows 10/11 and Server 2019/2022 builds released before the 2024‑09‑03 patch.
• <msrc.microsoft.com/update-guid>

2
• CVE‑2024‑43451
• Microsoft Windows NTLMv2 authentication (hash handling)
• Remote attacker can force a file‑open that leaks the user’s NTLMv2 hash, enabling pass‑the‑hash attacks. CVSS ≈ 8.1; directly compromises credential confidentiality.
• All supported Windows 10/11 and Server editions up to build 22631 (pre‑2024‑09‑03).
• <msrc.microsoft.com/update-guid>

3
• CVE‑2024‑38193
• Windows Ancillary Function Driver for WinSock (AFD)
• Unspecified kernel flaw that grants SYSTEM privileges to a local attacker. CVSS ≈ 8.5; part of the “privilege‑escalation” wave in the networking stack.
• Windows 10 22H2, Windows 11 and Server 2022 before 2024‑09‑03.
• <msrc.microsoft.com/update-guid>

4
• CVE‑2024‑38178
• Windows Scripting Engine (JScript/VBScript)
• Memory‑corruption bug that enables remote code execution via a crafted URL, bypassing same‑origin protections. CVSS ≈ 8.6; network‑reachable RCE.
• All supported Windows 10/11 and Server releases prior to 2024‑09‑03.
• <msrc.microsoft.com/update-guid>

5
• CVE‑2024‑36971
• Android kernel (Linux)
• Remote‑code‑execution via use‑after‑free/heap overflow in the core OS. CVSS ≈ 9.0; affects billions of smartphones and can be weaponised by ransomware.
• Android 13 & 14 builds with kernel ≤ 5.15.112 before September 2024 patch.
• <nvd.nist.gov/vuln/detail/CVE-2>

#infosecnews

##

CVE-2024-36971
(7.8 HIGH)

EPSS: 2.70%

updated 2026-06-17T07:37:30.630000

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first clear sk->sk_dst_cache, then call dst_release(old_dst). Note that sk_dst_reset(sk) is implementing this protocol correctly, while __dst_ne

1 repos

https://github.com/M4G1XX/CVE-2024-36971

infosecbot@mastodon.hofud.com at 2026-08-10T06:50:32.000Z ##

[1/4]

Most impactful security incidents and vulnerabilities reported in the last ≈ 30 days (up to 2024‑09‑03)

1
• CVE‑2024‑49039
• Windows Task Scheduler (TaskScheduler service)
• Privilege‑escalation: a low‑privileged AppContainer can break out and invoke privileged RPC functions. CVSS ≈ 8.8; actively exploited by ransomware groups.
• All supported Windows 10/11 and Server 2019/2022 builds released before the 2024‑09‑03 patch.
• <msrc.microsoft.com/update-guid>

2
• CVE‑2024‑43451
• Microsoft Windows NTLMv2 authentication (hash handling)
• Remote attacker can force a file‑open that leaks the user’s NTLMv2 hash, enabling pass‑the‑hash attacks. CVSS ≈ 8.1; directly compromises credential confidentiality.
• All supported Windows 10/11 and Server editions up to build 22631 (pre‑2024‑09‑03).
• <msrc.microsoft.com/update-guid>

3
• CVE‑2024‑38193
• Windows Ancillary Function Driver for WinSock (AFD)
• Unspecified kernel flaw that grants SYSTEM privileges to a local attacker. CVSS ≈ 8.5; part of the “privilege‑escalation” wave in the networking stack.
• Windows 10 22H2, Windows 11 and Server 2022 before 2024‑09‑03.
• <msrc.microsoft.com/update-guid>

4
• CVE‑2024‑38178
• Windows Scripting Engine (JScript/VBScript)
• Memory‑corruption bug that enables remote code execution via a crafted URL, bypassing same‑origin protections. CVSS ≈ 8.6; network‑reachable RCE.
• All supported Windows 10/11 and Server releases prior to 2024‑09‑03.
• <msrc.microsoft.com/update-guid>

5
• CVE‑2024‑36971
• Android kernel (Linux)
• Remote‑code‑execution via use‑after‑free/heap overflow in the core OS. CVSS ≈ 9.0; affects billions of smartphones and can be weaponised by ransomware.
• Android 13 & 14 builds with kernel ≤ 5.15.112 before September 2024 patch.
• <nvd.nist.gov/vuln/detail/CVE-2>

#infosecnews

##

CVE-2026-52880
(7.5 HIGH)

EPSS: 0.29%

updated 2026-06-09T18:40:45

1 posts

### Summary The Klever seednode REST API starts a Gin engine with `Engine.Run(restAPIInterface)`. In Gin v1.9.1, `Engine.Run` calls Go's default `http.ListenAndServe`, which constructs an HTTP server without application-level `ReadHeaderTimeout`, `ReadTimeout`, or `MaxHeaderBytes` limits. An unauthenticated client that can reach a REST listener bound with Klever's documented `--rest-api-interfac

thehackerwire@mastodon.social at 2026-08-08T00:01:03.000Z ##

🟠 CVE-2026-52880 - High (7.5)

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both REST APIs are started with the Gin Engine.Run convenience method, which serv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52879
(7.5 HIGH)

EPSS: 0.29%

updated 2026-06-09T18:40:42

1 posts

### Summary `networkMessenger.directMessageHandler` in `network/p2p/libp2p/netMessenger.go` spawns a fresh goroutine for every incoming direct message before the antiflood layer makes an admission decision. There is no semaphore, throttler, or bound on concurrent in-flight spawns. A single connected libp2p peer can open a `DirectSendID` stream and send well-formed `TopicMessage` envelopes with v

thehackerwire@mastodon.social at 2026-08-08T00:00:25.000Z ##

🟠 CVE-2026-52879 - High (7.5)

Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a new goroutine for every incoming direct message before the processor-level antiflood layer makes a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-34486
(7.5 HIGH)

EPSS: 81.16%

updated 2026-06-08T23:28:56

1 posts

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

6 repos

https://github.com/404-src/CVE-2026-34486

https://github.com/anonmrc/CVE-2026-34486-e-Tomcat-Tribes

https://github.com/razureink/cve-2026-34486-tomcat_encrypt_bypass_reproduction

https://github.com/AirSkye/CVE-2026-34486-poc

https://github.com/striga-ai/CVE-2026-34486

https://github.com/punitdarji/tomcat-cve-2026-34486

security_crawler_carl@infosec.exchange at 2026-08-07T07:27:32.000Z ##

🏆 New Achievement! Patch Notes From Hell!

Version 2026.08 changelog: ADDED — Chinese-speaking threat actor manually planting reverse shells on Apache Tomcat servers via CVE-2026-34486, itself an incomplete fix for the 9.8-rated CVE-2026-29146. ADDED — unauthenticated admin account hijacking on N-able's N-central via CVE-2026-18576. ADDED — critical 9.8-rated remote code execution at root on IBM Langflow via CVE-2026-9198. (1/2)

##

CVE-2026-47249
(7.5 HIGH)

EPSS: 0.28%

updated 2026-06-05T15:27:42

1 posts

### Summary A connected peer can send a compressed `RequestDataType_HashArrayType` direct request that is only `442` bytes on the wire but expands into `200000` decoded hash entries inside the resolver path. On `klever-go` `v1.7.17`, this allows remote memory and CPU amplification against nodes that accept P2P peer connections. ### Details Resolver antiflood logic accounts only one logical messag

thehackerwire@mastodon.social at 2026-08-08T00:01:25.000Z ##

🟠 CVE-2026-47249 - High (7.5)

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-array amplification. A connected peer can send a compressed RequestDataType_HashArrayType direct r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-28299
(8.2 HIGH)

EPSS: 0.49%

updated 2026-06-02T21:30:50

1 posts

SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to crash due to insufficient memory.

AAKL@infosec.exchange at 2026-08-07T17:20:10.000Z ##

This post is from yesterday.

Note: Arctic Wolf will sell your data without consent. You need to scroll to the bottom and opt out of being sold to unscrupulous third-parties.

Arctic Wolf: SolarWinds Web Help Desk Vulnerabilities: CVE-2026-28323 and CVE-2026-28299 arcticwolf.com/resources/blog/ #infosec #vulnerability #privacy

##

CVE-2026-20685
(6.5 MEDIUM)

EPSS: 0.19%

updated 2026-05-18T18:31:37

1 posts

An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation. This issue is fixed in PCC Release 5E290.3.

1 repos

https://github.com/HORKimhab/CVE-2026-20685

sayzard@mastodon.sayzard.org at 2026-08-10T00:38:47.000Z ##

Beyond Prompt Injection: Hacking Apple's Private Cloud Compute

Sentry Applied Research Center 연구자가 Apple Private Cloud Compute(PCC)의 부팅 프로세스 `darwin-init`에서 발생하는 경로 순회 취약점 CVE-2026-20685를 공개했다. 악성 tar 기반 cryptex의 엔트리 경로를 검증 없이 추출하는 문제로, 공격자는 PCC 노드의 영속 데이터 볼륨(`/var/db`)에 root 권한으로 파일을 쓸 수 있다. 연구 환경(VRE)에서 공격자는 이 쓰기 권한을 이용해 `splunkloggingd` 설정을 변조하...

blog.sentry.security/beyond-pr

##

CVE-2026-41679
(10.0 CRITICAL)

EPSS: 2.95%

updated 2026-04-27T16:19:05

1 posts

## Summary An unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. No user interaction, no credentials, just the target's address. The entire chain is six API calls. I verified every step against the latest version. I have a fully automated PoC script and a video recording availabl

1 repos

https://github.com/bartfroklage/cve-2026-41679

raul@mastodon.in4matics.cat at 2026-08-07T08:59:53.000Z ##

Vuln critica (CVSS 10.0) a Paperclip, orquestracio d'agents d'IA

CVE-2026-41679: RCE via bypass d'autenticacio. Registrar-se sense verificar email, aconseguir token d'API persistent, i importar un .paperclip.yaml malicios que executa comandes al servidor

Tambe afecta el mode local_trusted: DNS rebinding des del navegador executa comandes al PC del dev.

Actualitza ja.

blog.elhacker.net/2026/08/vuln

#Seguridad #CVE #AgentesIA #InfoSec #RCE

##

kev_Stalker@infosec.exchange at 2026-08-07T04:29:17.000Z ##

CVE-2024-23692 - Changed to Known Ransomware Status

Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine VulnerabilityVendor: RejettoProduct: HTTP File ServerRejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2025-42999
(9.1 CRITICAL)

EPSS: 11.28%

updated 2025-10-22T00:33:19

1 posts

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.

1 repos

https://github.com/Onapsis/Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment

kev_Stalker@infosec.exchange at 2026-08-07T04:34:15.000Z ##

CVE-2025-42999 - Changed to Known Ransomware Status

SAP NetWeaver Deserialization VulnerabilityVendor: SAPProduct: NetWeaverSAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content.Status changed from Unknown to Known for ransomware campaign nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2025-36852(CVSS UNKNOWN)

EPSS: 0.20%

updated 2025-10-14T19:17:03

1 posts

A critical security vulnerability exists in remote cache extensions for common build systems utilizing bucket-based remote cache (such as those using Amazon S3, Google Cloud Storage, or similar object storage) that allows any contributor with pull request privileges to inject compromised artifacts from an untrusted environment into trusted production environments without detection.  The vulnerabi

dominykas@fosstodon.org at 2026-08-09T09:20:04.000Z ##

This bothers me.

Nx v1 was released in 2018, yet nx.dev/blog/cve-2025-36852-cri (CREEP) was only discovered in 2025 (and is, disingenuously, described as a "race condition", which it is not - it's just inappropriate use of shared resources without trust boundaries).

##

CVE-2021-26708
(7.0 None)

EPSS: 1.60%

updated 2023-11-18T05:04:48

1 posts

A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock/af_vsock.c. The race conditions were implicitly introduced in the commits that added VSOCK multi-transport support.

3 repos

https://github.com/azpema/CVE-2021-26708

https://github.com/kungaocode/vulnerability-analysis-

https://github.com/jordan9001/vsock_poc

hackmag@infosec.exchange at 2026-08-09T00:30:10.000Z ##

⚪️ Four Bytes of Power: How I Found the CVE-2021-26708 Vulnerability in the Linux Kernel

🗨️ In January 2021, I discovered and fixed five vulnerabilities in the Linux kernel’s virtual socket (vsock) implementation, collectively tracked as CVE-2021-26708. In this article, I will show how they can be used to compromise the entire operating system while bypassing the platform’s security mec…

🔗 hackmag.com/unix/linux-core-cv

#unix

##

CVE-2015-6609(CVSS UNKNOWN)

EPSS: 2.17%

updated 2023-01-27T05:08:18

1 posts

libutils in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted audio file, aka internal bug 22953624.

GrapheneOS@grapheneos.social at 2026-08-08T15:04:04.000Z ##

The paper has a table listing the patches they're inaccurately claiming are missing in GrapheneOS. They claim the ones marked as green were manually verified to be missing. The first patch listed in the table is CVE-2015-6609, which we reported to Google in 2015.

source.android.com/docs/securi

##

CVE-2026-63637
(0 None)

EPSS: 0.24%

2 posts

N/A

thehackerwire@mastodon.social at 2026-08-10T02:00:16.000Z ##

🟠 CVE-2026-63637 - High (8.6)

Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without quoting or validating the /pattern/flags form, allowing crafted Grap...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-10T02:00:16.000Z ##

🟠 CVE-2026-63637 - High (8.6)

Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without quoting or validating the /pattern/flags form, allowing crafted Grap...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62296
(0 None)

EPSS: 0.28%

2 posts

N/A

hugovalters@mastodon.social at 2026-08-09T12:07:31.000Z ##

CVE-2026-62296 - DoS in HAPI FHIR via deeply nested XHTML. Unbounded recursion crashes parser threads. CVSS 7.5. Fixed in 6.9.11. Update now. #CVE #HAPI #infosec

valtersit.com/cve/CVE-2026-622

##

thehackerwire@mastodon.social at 2026-08-08T02:00:16.000Z ##

🟠 CVE-2026-62296 - High (7.5)

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded recursion...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

phillip@social.lol at 2026-08-08T19:01:48.000Z ##

Welp. My Forgejo instance got popped by CVE-2026-60004. Hooray for RCE 🙃

My two screw-ups were
1. I pinned it to v13 "for stability" forever ago, then forgot about it.
2. I accidentally left sign-ups enabled.

Grabbed the seemingly obfuscated payload script from the attacker's server. Looks like it hits a different IP and grabs one of three different binaries depending on the victim's CPU architecture. You best believe I'm grabbing those too

Will probably write a blog post on what I find, but I'll at least post updates here, too

#Homelab #SelfHosted #PatchYourShit #Forgejo

##

CVE-2026-48097
(0 None)

EPSS: 0.27%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-08T07:00:27.000Z ##

🟠 CVE-2026-48097 - High (7.8)

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a command execution vulnerability due to unsafe use of `shell=True` with commands that rely on executa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65819
(0 None)

EPSS: 0.37%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-08T02:00:30.000Z ##

🟠 CVE-2026-65819 - High (7.5)

gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffers, allowing a crafted packet decoded through De...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48026
(0 None)

EPSS: 0.22%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-08T02:00:05.000Z ##

🟠 CVE-2026-48026 - High (8.7)

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects withou...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48120
(0 None)

EPSS: 0.14%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-08T00:00:01.000Z ##

🟠 CVE-2026-48120 - High (8.6)

Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Ka...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62295
(0 None)

EPSS: 0.28%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-07T23:01:03.000Z ##

🟠 CVE-2026-62295 - High (7.5)

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arrays or obje...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61808
(0 None)

EPSS: 0.34%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-07T23:00:53.000Z ##

🔴 CVE-2026-61808 - Critical (9.8)

LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-33691
(0 None)

EPSS: 3.58%

1 posts

N/A

secdb@infosec.exchange at 2026-08-07T19:00:11.000Z ##

🚨 [CISA-2026:0807] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-8037 (secdb.nttzen.cloud/cve/detail/)
- Name: Progress LoadMaster Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Progress
- Product: LoadMaster
- Notes: community.progress.com/s/artic ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260807 #cisa20260807 #cve_2026_8037 #cve20268037

##

CVE-2026-48024
(0 None)

EPSS: 0.00%

1 posts

N/A

moltenbit@infosec.exchange at 2026-08-07T13:47:18.000Z ##

three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.

CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.

CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.

CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.

patched in 4.14.6.

github.com/wazuh/wazuh/securit

github.com/wazuh/wazuh/securit

github.com/wazuh/wazuh/securit

#Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity

##

CVE-2026-48162
(0 None)

EPSS: 0.00%

1 posts

N/A

moltenbit@infosec.exchange at 2026-08-07T13:47:18.000Z ##

three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.

CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.

CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.

CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.

patched in 4.14.6.

github.com/wazuh/wazuh/securit

github.com/wazuh/wazuh/securit

github.com/wazuh/wazuh/securit

#Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity

##

CVE-2026-49441
(0 None)

EPSS: 0.00%

1 posts

N/A

moltenbit@infosec.exchange at 2026-08-07T13:47:18.000Z ##

three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.

CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.

CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.

CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.

patched in 4.14.6.

github.com/wazuh/wazuh/securit

github.com/wazuh/wazuh/securit

github.com/wazuh/wazuh/securit

#Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity

##

CVE-2026-18576
(0 None)

EPSS: 0.00%

1 posts

N/A

security_crawler_carl@infosec.exchange at 2026-08-07T07:27:32.000Z ##

🏆 New Achievement! Patch Notes From Hell!

Version 2026.08 changelog: ADDED — Chinese-speaking threat actor manually planting reverse shells on Apache Tomcat servers via CVE-2026-34486, itself an incomplete fix for the 9.8-rated CVE-2026-29146. ADDED — unauthenticated admin account hijacking on N-able's N-central via CVE-2026-18576. ADDED — critical 9.8-rated remote code execution at root on IBM Langflow via CVE-2026-9198. (1/2)

##

Visit counter For Websites