## Updated at UTC 2026-07-27T11:57:21.699088

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-14837 7.8 0.00% 2 0 2026-07-27T08:16:17.463000 Multiple Lenze products are affected by an improper signature verification vulne
CVE-2026-64600 7.8 0.72% 13 4 2026-07-27T05:16:56.870000 In the Linux kernel, the following vulnerability has been resolved: xfs: resamp
CVE-2026-57990 7.4 0.00% 1 0 2026-07-26T18:30:24 Files or directories accessible to external parties in Microsoft Edge (Chromium-
CVE-2026-57989 7.4 0.00% 1 0 2026-07-26T18:18:25.033000 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorize
CVE-2026-17496 8.1 0.00% 3 0 2026-07-26T15:30:33 NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with
CVE-2026-17497 8.3 0.00% 3 0 2026-07-26T15:30:32 NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capabili
CVE-2026-17457 4.3 0.32% 2 0 2026-07-26T12:30:21 A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by t
CVE-2026-17458 6.3 0.00% 2 0 2026-07-26T12:30:21 A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the f
CVE-2026-17459 4.3 0.00% 2 0 2026-07-26T12:30:21 A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerabilit
CVE-2026-63720 7.5 0.42% 4 0 2026-07-26T05:16:23.927000 datamodel-code-generator prior to version 0.70.0 contains a code injection vulne
CVE-2026-15962 8.8 0.38% 3 0 2026-07-26T03:30:31 The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Objec
CVE-2026-64329 None 0.18% 1 0 2026-07-25T12:31:38 In the Linux kernel, the following vulnerability has been resolved: usb: typec:
CVE-2026-64275 None 0.21% 1 0 2026-07-25T12:31:34 In the Linux kernel, the following vulnerability has been resolved: Input: elan
CVE-2026-64377 None 0.17% 1 0 2026-07-25T12:31:34 In the Linux kernel, the following vulnerability has been resolved: cpufreq: qc
CVE-2026-64309 None 0.21% 1 0 2026-07-25T12:31:30 In the Linux kernel, the following vulnerability has been resolved: crypto: ccp
CVE-2026-66012 10.0 0.44% 2 1 2026-07-25T11:17:19.053000 SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST
CVE-2026-10818 8.1 0.42% 2 1 2026-07-25T07:17:08.880000 The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in a
CVE-2026-66034 7.5 0.25% 1 0 2026-07-25T05:16:42.773000 libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check
CVE-2026-56163 10.0 0.92% 2 0 2026-07-25T05:16:35.420000 Missing authentication for critical function in Microsoft Azure Kubernetes Servi
CVE-2026-66374 8.1 0.39% 1 1 2026-07-25T03:30:55 Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer
CVE-2026-66041 8.8 0.42% 1 0 2026-07-25T02:16:40.150000 FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds
CVE-2026-66373 7.5 0.47% 1 0 2026-07-25T01:16:26.277000 Redis before 8.8.0, in the unusual case where an authenticated attacker can exec
CVE-2026-61884 9.8 0.66% 3 0 2026-07-25T00:31:53 The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perf
CVE-2026-60134 8.8 0.32% 1 0 2026-07-25T00:31:53 Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elev
CVE-2025-71408 7.8 0.16% 1 0 2026-07-25T00:31:53 NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection
CVE-2026-61892 8.8 0.27% 1 0 2026-07-24T23:16:51.333000 Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate p
CVE-2026-14603 7.5 0.24% 1 0 2026-07-24T21:33:30 The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have
CVE-2026-45811 7.5 0.25% 1 0 2026-07-24T21:33:30 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerabi
CVE-2026-45815 7.5 0.37% 1 0 2026-07-24T21:33:30 Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read
CVE-2026-66144 7.5 0.33% 1 0 2026-07-24T21:33:30 Although remote policy references are not retrieved during policy normalization,
CVE-2026-12877 9.1 0.24% 1 0 2026-07-24T21:33:29 The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5
CVE-2026-66142 7.5 0.33% 1 0 2026-07-24T21:33:29 Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that
CVE-2026-62835 9.3 1.03% 3 0 2026-07-24T21:32:28 Improper authorization in Azure Portal allows an unauthorized attacker to disclo
CVE-2026-66039 8.8 0.42% 1 0 2026-07-24T21:32:28 FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflo
CVE-2026-66036 8.8 0.29% 1 0 2026-07-24T21:32:28 FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds wri
CVE-2026-66040 8.8 0.55% 1 0 2026-07-24T21:32:28 FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds wri
CVE-2026-17107 8.5 0.23% 1 0 2026-07-24T21:32:28 A flaw was found in the cluster-proxy service-proxy component used in Red Hat Ad
CVE-2026-12981 7.5 0.30% 1 0 2026-07-24T20:48:39.923000 The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication
CVE-2026-12497 7.5 0.23% 1 0 2026-07-24T20:48:39.923000 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User
CVE-2026-16804 8.3 0.29% 1 0 2026-07-24T20:47:41.790000 Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remot
CVE-2026-45816 7.5 0.38% 1 0 2026-07-24T20:47:41.790000 NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Requ
CVE-2026-45813 8.8 0.27% 1 0 2026-07-24T20:47:41.790000 Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apa
CVE-2026-66143 7.5 0.33% 1 0 2026-07-24T20:47:41.790000 It is possible to bypass the maximum number of normalized policy alternatives th
CVE-2026-49745 7.8 0.11% 1 0 2026-07-24T18:32:33 Kernel software installed and running inside a Guest VM may post improper comman
CVE-2026-49743 7.8 0.11% 1 0 2026-07-24T18:32:33 Software installed and run as a non-privileged user may conduct improper GPU sys
CVE-2026-16800 8.8 0.29% 1 0 2026-07-24T18:32:33 Improper control of generation of code ('Code Injection') in the schedule featur
CVE-2026-16801 8.8 0.29% 1 0 2026-07-24T18:32:32 Improper control of generation of code ('Code Injection') in the variables featu
CVE-2026-65711 7.2 2.41% 2 0 2026-07-24T18:31:41 sysPass through version 3.2.11 contains an OS command injection vulnerability th
CVE-2026-65709 8.3 0.22% 1 0 2026-07-24T18:31:41 sysPass through version 3.2.11 contains a missing object-level authorization vul
CVE-2026-66035 7.5 0.32% 1 0 2026-07-24T18:31:41 libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication h
CVE-2026-66033 7.5 0.39% 1 0 2026-07-24T18:31:41 libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication i
CVE-2026-66032 8.8 0.29% 1 0 2026-07-24T18:31:37 libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerab
CVE-2026-65708 8.1 0.22% 1 0 2026-07-24T18:18:08.653000 sysPass through version 3.2.11 contains an insecure direct object reference vuln
CVE-2026-49744 7.8 0.11% 1 0 2026-07-24T18:16:59.660000 Kernel software installed and running inside a Guest VM may post improper comman
CVE-2026-66027 8.3 0.26% 1 0 2026-07-24T17:17:34.993000 Suna before 0.9.102 contains a broken access control vulnerability in the messag
CVE-2026-16807 8.8 0.29% 1 0 2026-07-24T15:34:00 Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a
CVE-2026-16806 8.8 0.43% 1 0 2026-07-24T15:34:00 Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remo
CVE-2026-16805 8.8 0.34% 1 0 2026-07-24T15:34:00 Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remot
CVE-2026-8789 8.1 0.22% 1 0 2026-07-24T15:33:10 The Easy Appointments plugin for WordPress is vulnerable to unauthorized modific
CVE-2026-58630 10.0 0.81% 3 0 2026-07-24T15:33:09 Improper access control in Azure App Service allows an unauthorized attacker to
CVE-2026-57106 10.0 0.92% 2 0 2026-07-24T15:33:03 Server-side request forgery (ssrf) in Data Quality allows an unauthorized attack
CVE-2026-12503 None 0.14% 1 0 2026-07-24T15:33:02 Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-
CVE-2026-14172 7.8 0.11% 1 0 2026-07-24T09:32:22 Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables
CVE-2026-16870 8.8 0.36% 1 0 2026-07-24T06:34:17 Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior
CVE-2026-66140 8.4 0.27% 1 0 2026-07-24T06:34:11 Exim before 4.99.5 allows directory traversal to access files outside of the spo
CVE-2026-62145 7.5 7.54% 2 1 2026-07-24T05:16:45.940000 A vulnerability in Check Point Gaia Portal allows an authenticated attacker with
CVE-2026-62144 9.1 20.62% 2 1 2026-07-24T05:16:45.793000 An authentication bypass vulnerability in Check Point Security Management and Mu
CVE-2026-35425 8.0 0.48% 1 0 2026-07-24T03:32:01 Improper access control in Azure API Management (APIM) allows an authorized atta
CVE-2026-54120 9.9 0.71% 2 0 2026-07-24T03:31:56 Improper input validation in Microsoft Surface allows an authorized attacker to
CVE-2026-56167 8.5 0.38% 1 0 2026-07-24T03:31:56 Server-side request forgery (ssrf) in Azure AI Search allows an authorized attac
CVE-2026-56160 9.1 0.65% 1 0 2026-07-24T03:31:56 Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized att
CVE-2026-50517 9.9 1.25% 1 0 2026-07-24T03:31:55 Deserialization of untrusted data in M365 Copilot allows an authorized attacker
CVE-2026-6516 10.0 4.73% 2 0 2026-07-23T18:31:54 Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthen
CVE-2026-16723 9.0 0.41% 9 2 2026-07-23T15:01:24.377000 A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.
CVE-2026-16232 9.1 12.68% 6 1 2026-07-22T21:32:05 An authentication bypass vulnerability in the Check Point SmartConsole login pro
CVE-2026-50522 9.8 57.10% 5 2 2026-07-22T21:31:51 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-53359 8.8 0.91% 1 6 2026-07-22T21:31:50 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: F
CVE-2026-49176 7.8 0.40% 5 1 2026-07-22T16:17:28.753000 Improper privilege management in Windows WalletService allows an authorized atta
CVE-2026-8985 None 4.19% 2 0 2026-07-22T00:32:44 Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command
CVE-2026-64879 9.9 2.59% 2 0 2026-07-21T21:32:47 A filename supplied during file upload is not properly sanitized before being us
CVE-2026-15226 8.4 0.12% 1 0 2026-07-21T15:30:58 A sandbox confinement bypass vulnerability exists in Canonical snapd within its
CVE-2026-8933 7.8 0.18% 2 0 2026-07-21T15:30:51 A local privilege escalation vulnerability exists in snap-confine, a set-capabil
CVE-2026-63766 9.8 1.75% 2 1 2026-07-20T21:31:57 GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability
CVE-2026-63108 8.8 1.92% 2 0 2026-07-20T21:31:57 Roo Code through 3.54.0 contains a command injection vulnerability in the auto-a
CVE-2026-16242 9.4 0.37% 1 0 2026-07-20T09:31:15 A flaw was found in the Konnectivity proxy-server configuration for hosted contr
CVE-2026-58644 9.8 5.06% 1 0 2026-07-17T05:16:40.470000 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-25089 9.8 69.83% 1 2 2026-07-16T18:32:24 A improper neutralization of special elements used in an os command ('os command
CVE-2026-39808 9.8 89.69% 1 6 template 2026-07-16T18:32:24 A improper neutralization of special elements used in an os command ('os command
CVE-2026-42530 8.1 3.68% 2 3 2026-07-16T12:33:31 NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGI
CVE-2026-42533 8.1 2.79% 3 7 2026-07-16T05:16:19.247000 A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive
CVE-2026-46817 9.8 13.31% 1 2 2026-07-15T18:32:50 Vulnerability in the Oracle Payments product of Oracle E-Business Suite (compone
CVE-2023-4346 7.5 0.91% 1 0 2026-07-15T18:32:50 KNX devices that use KNX Connection Authorization and support Option 1 are, depe
CVE-2026-42945 8.1 61.47% 5 42 2026-07-15T02:21:38.583000 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo
CVE-2026-56155 7.8 2.33% 1 0 2026-07-14T21:32:52 Insufficient granularity of access control in Active Directory Federation Servic
CVE-2026-15410 7.2 76.35% 2 3 2026-07-14T21:32:21 Post-authentication improper control of generation of code ('Code Injection') vu
CVE-2026-54121 8.8 1.05% 8 6 2026-07-14T18:32:37 Improper authorization in Active Directory Certificate Services (AD CS) allows a
CVE-2026-50454 7.8 0.44% 1 0 2026-07-14T18:32:32 Relative path traversal in Windows User Interface Core allows an authorized atta
CVE-2026-55255 8.4 29.05% 1 1 2026-07-08T13:39:12.593000 Langflow is a tool for building and deploying AI-powered agents and workflows. P
CVE-2026-12569 9.8 2.26% 7 1 2026-06-30T18:16:43.113000 A critical remote code execution (RCE) vulnerability has been reported in PTC Wi
CVE-2025-0679 4.3 0.29% 1 0 2026-06-17T08:26:57.313000 An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 be
CVE-2026-47668 10.0 4.34% 2 1 template 2026-06-05T16:25:28 ### Summary DbGate's JSON script runner (`POST /runners/start`) allows remote co
CVE-2026-32194 9.8 0.70% 1 1 2026-03-20T00:31:34 Improper neutralization of special elements used in a command ('command injectio
CVE-2026-32191 9.8 0.56% 1 0 2026-03-19T21:30:31 Improper neutralization of special elements used in an os command ('os command i
CVE-2025-66376 7.2 21.62% 2 0 2026-03-18T18:31:10 Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Clas
CVE-2025-29827 9.9 1.25% 2 0 2025-06-05T15:32:29 Improper Authorization in Azure Automation allows an authorized attacker to elev
CVE-2026-61511 0 0.00% 2 0 N/A
CVE-2026-16766 0 0.68% 1 0 N/A
CVE-2026-48021 0 0.12% 2 0 N/A
CVE-2026-54342 0 0.12% 1 0 N/A

CVE-2026-14837
(7.8 HIGH)

EPSS: 0.00%

updated 2026-07-27T08:16:17.463000

2 posts

Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.

certvde at 2026-07-27T07:01:06.983Z ##

VDE-2026-077
Lenze: Incorrect signature validation in the enable SSH routine

The affected products belong to the Controller or Servo Drive product family and contain a vulnerability in a security-critical activation mechanism for service access. The signature verification of a file used for SSH activation can be compromised, which could allow unauthorized access to the device.
CVE-2026-14837

certvde.com/en/advisories/vde-

lenze.csaf-tp.certvde.com/.wel

##

certvde@infosec.exchange at 2026-07-27T07:01:06.000Z ##

#OT #Advisory VDE-2026-077
Lenze: Incorrect signature validation in the enable SSH routine

The affected products belong to the Controller or Servo Drive product family and contain a vulnerability in a security-critical activation mechanism for service access. The signature verification of a file used for SSH activation can be compromised, which could allow unauthorized access to the device.
#CVE CVE-2026-14837

certvde.com/en/advisories/vde-

#CSAF lenze.csaf-tp.certvde.com/.wel

##

CVE-2026-64600
(7.8 HIGH)

EPSS: 0.72%

updated 2026-07-27T05:16:56.870000

13 posts

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently

4 repos

https://github.com/Debajyoti0-0/CVE-2026-64600

https://github.com/0xBlackash/CVE-2026-64600

https://github.com/HORKimhab/CVE-2026-64600

https://github.com/vulnquest58/VQ-RefluxCore

benzogaga33@mamot.fr at 2026-07-27T09:40:02.000Z ##

RefluXFS : cette faille dans XFS donne un accès root sur RHEL, CentOS et AlmaLinux it-connect.fr/refluxfs-cve-202 #ActuCybersécurité #Cybersécurité #Vulnérabilité #Linux

##

hackmag at 2026-07-27T06:30:14.030Z ##

⚪️ New RefluXFS Vulnerability Enables Root Access on Linux

🗨️ Researchers at Qualys have discovered a nine-year-old vulnerability in the XFS file system. The bug, tracked as CVE-2026-64600 and dubbed RefluXFS, allows a local unprivileged user to overwrite protected files and gain root privileges. According to researchers, the bug was…

🔗 hackmag.com/news/refluxfs?utm_

##

sigint@fosstodon.org at 2026-07-26T23:02:30.000Z ##

🐛 SIGINT // Cybersecurity Watch — 2026-07-27
Nine-year-old Linux kernel XFS flaw (RefluXFS, CVE-2026-64600) lets local users gain root on default RHEL, Oracle Linux, Rocky & AlmaLinux installs.
thehackernews.com/2026/07/nine
#CVE #Linux #InfoSec #Cybersecurity

##

cyberveille@mastobot.ping.moi at 2026-07-26T17:30:15.000Z ##

📢 RefluXFS (CVE-2026-64600) : élévation de privilèges locale vers root dans le noyau Linux via XFS
📝 ## 🔍 Contexte

Le 22 juillet 2026...
📖 cyberveille : cyberveille.ch/posts/2026-07-2
🌐 source : blog.qualys.com/vulnerabilitie
#CVE_2026_64600 #IOC #Cyberveille

##

security_crawler_carl at 2026-07-26T02:24:57.214Z ##

CVE-2026-64600, dubbed RefluXFS by Qualys Threat Research Unit, is a nine-year-old race condition that lets a local attacker clone a root-owned file — /etc/passwd, a SUID binary, you name it — then hammer it with concurrent O_DIRECT writes until they win the race and own the box. Highly reliable exploitation. Survives reboot. A beautiful, silent corpse. (2/3)

##

benzogaga33@mamot.fr at 2026-07-27T09:40:02.000Z ##

RefluXFS : cette faille dans XFS donne un accès root sur RHEL, CentOS et AlmaLinux it-connect.fr/refluxfs-cve-202 #ActuCybersécurité #Cybersécurité #Vulnérabilité #Linux

##

hackmag@infosec.exchange at 2026-07-27T06:30:14.000Z ##

⚪️ New RefluXFS Vulnerability Enables Root Access on Linux

🗨️ Researchers at Qualys have discovered a nine-year-old vulnerability in the XFS file system. The bug, tracked as CVE-2026-64600 and dubbed RefluXFS, allows a local unprivileged user to overwrite protected files and gain root privileges. According to researchers, the bug was…

🔗 hackmag.com/news/refluxfs?utm_

#news

##

cyberveille@mastobot.ping.moi at 2026-07-26T17:30:15.000Z ##

📢 RefluXFS (CVE-2026-64600) : élévation de privilèges locale vers root dans le noyau Linux via XFS
📝 ## 🔍 Contexte

Le 22 juillet 2026...
📖 cyberveille : cyberveille.ch/posts/2026-07-2
🌐 source : blog.qualys.com/vulnerabilitie
#CVE_2026_64600 #IOC #Cyberveille

##

security_crawler_carl@infosec.exchange at 2026-07-26T02:24:57.000Z ##

CVE-2026-64600, dubbed RefluXFS by Qualys Threat Research Unit, is a nine-year-old race condition that lets a local attacker clone a root-owned file — /etc/passwd, a SUID binary, you name it — then hammer it with concurrent O_DIRECT writes until they win the race and own the box. Highly reliable exploitation. Survives reboot. A beautiful, silent corpse. (2/3)

##

secdb@infosec.exchange at 2026-07-25T12:52:05.000Z ##

🚨 RefluXFS (CVE-2026-64600) has been identified as a notable vulnerability.

In the Linux kernel, the following vulnerability has been resolved:

xfs: resample the data fork mapping after cycling ILOCK

RefluXFS is a local privilege escalation vulnerability in the Linux kernel's XFS filesystem copy-on-write path. It allows local users to overwrite protected files and gain root access.

ℹ️ Additional details on ZEN SecDB secdb.nttzen.cloud/updates/1d2

#infosec #refluxfs #linux #kernel #xfs #lpe
#nttdata #zen #secdb

##

schwerdtfegr.wordpress.com@schwerdtfegr.wordpress.com at 2026-07-25T11:41:44.000Z ##

Aber linux ist doch sicherer als linux…

Sicherheitsforscher von Qualys haben mithilfe von Claude Mythos eine neun Jahre alte und RefluXFS genannte Sicherheitslücke im Linux-Kernel entdeckt, mit der Angreifer durch das überschreiben geschützter Dateien Root-Zugriff erlangen können. Viele Linux-Distributionen sind in der Standardkonfiguration angreifbar, darunter Red Hat Enterprise Linux (RHEL), CentOS, Fedora und Oracle Linux. Admins sollten ihre Systeme absichern […] anfällig sind alle Linux-Kernel ab Version 4.11, welche im April 2017 veröffentlicht wurde. Voraussetzung ist jedoch, dass ein anvisiertes Linux-System über ein XFS-Volume mit aktiver Reflink-Funktion verfügt […] es gebe keinen alternativen Workaround, der zuverlässig vor CVE-2026-64600 schütze

Na, zumindest das kriegen die angelernten neuronalen netzwerke sehr zuverlässig hin: einen haufen uralter fehler in linux aufzufinden. Schön die sicherheitsaktualisierungen einspielen!

#Epic #Fail #Golem #Link #Linux #Security ##

threatnoir@infosec.exchange at 2026-07-25T07:05:45.000Z ##

⚠️ CRITICAL: New RefluXFS Linux flaw lets attackers gain root privileges

A nine-year-old race condition in the Linux XFS filesystem (CVE-2026-64600) allows local attackers to overwrite protected files and escalate to root. Systems running kernel v4.11+ with XFS and reflink enabled are vulnerable. The exploit leaves no kernel logs and persists across reboots, making dete…

threatnoir.com/focus

#infosec #cybersecurity

##

DailyCyberSecurity@infosec.exchange at 2026-07-24T13:31:15.000Z ##

Discover the RefluXFS Linux vulnerability (CVE-2026-64600) in XFS that allows local users to overwrite protected files and gain root privileges.

#RefluXFS #CVE202664600 #LinuxKernel #Cybersecurity #XFS

meterpreter.org/refluxfs-linux

##

CVE-2026-57990
(7.4 HIGH)

EPSS: 0.00%

updated 2026-07-26T18:30:24

1 posts

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

hugovalters@mastodon.social at 2026-07-26T23:07:58.000Z ##

CVE-2026-57990 - High-severity information disclosure in Microsoft Edge (Chromium). Unauthorized access to files over network. CVSS 7.4. No patch yet—restrict network access. #CVE #Microsoft #edge

valtersit.com/cve/CVE-2026-579

##

CVE-2026-57989
(7.4 HIGH)

EPSS: 0.00%

updated 2026-07-26T18:18:25.033000

1 posts

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

hugovalters@mastodon.social at 2026-07-27T11:00:57.000Z ##

CVE-2026-57989 - Information disclosure in Microsoft Edge (Chromium). Origin validation error. CVSS 7.4. Await patches. #CVE #Microsoft #infosec

valtersit.com/cve/CVE-2026-579

##

CVE-2026-17496
(8.1 HIGH)

EPSS: 0.00%

updated 2026-07-26T15:30:33

3 posts

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to inc

hugovalters@mastodon.social at 2026-07-26T17:00:18.000Z ##

CVE-2026-17496 - Stored XSS in NoteGen. AI chat renders HTML unsafely via dangerouslySetInnerHTML. CVSS 8.1. No patch yet—restrict model prompts immediately. #CVE #infosec #NoteGen

valtersit.com/cve/CVE-2026-174

##

thehackerwire@mastodon.social at 2026-07-26T15:59:49.000Z ##

🟠 CVE-2026-17496 - High (8.1)

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-26T15:59:49.000Z ##

🟠 CVE-2026-17496 - High (8.1)

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17497
(8.3 HIGH)

EPSS: 0.00%

updated 2026-07-26T15:30:32

3 posts

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in

hugovalters@mastodon.social at 2026-07-26T18:07:20.000Z ##

CVE-2026-17497 - Remote Code Execution in NoteGen. Tauri shell plugin allows command execution via JS. CVSS 8.3. No patch available; restrict permissions. #CVE #NoteGen #infosec

valtersit.com/cve/CVE-2026-174

##

thehackerwire@mastodon.social at 2026-07-26T15:59:58.000Z ##

🟠 CVE-2026-17497 - High (8.3)

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-26T15:59:58.000Z ##

🟠 CVE-2026-17497 - High (8.3)

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17457
(4.3 MEDIUM)

EPSS: 0.32%

updated 2026-07-26T12:30:21

2 posts

A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component Scheme Handler. Such manipulation of the argument url leads to information disclosure. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project

offseq at 2026-07-26T13:30:26.455Z ##

mf-yang openclaw-cn (v0.2.0, 0.2.1) faces a MEDIUM info disclosure issue (CVE-2026-17457). Remote, no user interaction needed. No patch yet — restrict access & monitor for updates. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-26T13:30:26.000Z ##

mf-yang openclaw-cn (v0.2.0, 0.2.1) faces a MEDIUM info disclosure issue (CVE-2026-17457). Remote, no user interaction needed. No patch yet — restrict access & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #InfoSec #CVE202617457

##

CVE-2026-17458
(6.3 MEDIUM)

EPSS: 0.00%

updated 2026-07-26T12:30:21

2 posts

A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server-side request forgery. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem

offseq at 2026-07-26T12:00:25.432Z ##

SSRF in mf-yang openclaw-cn (CVE-2026-17458) affects v0.2.0 & v0.2.1. MEDIUM severity, CVSS 5.3. Exploit details public, no patch yet. Restrict outbound server requests as interim mitigation. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-26T12:00:25.000Z ##

SSRF in mf-yang openclaw-cn (CVE-2026-17458) affects v0.2.0 & v0.2.1. MEDIUM severity, CVSS 5.3. Exploit details public, no patch yet. Restrict outbound server requests as interim mitigation. radar.offseq.com/threat/cve-20 #OffSeq #SSRF #Vuln #mfyang

##

CVE-2026-17459
(4.3 MEDIUM)

EPSS: 0.00%

updated 2026-07-26T12:30:21

2 posts

A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. Executing a manipulation can lead to symlink following. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The proj

offseq at 2026-07-26T10:30:25.993Z ##

CVE-2026-17459: perwendel spark 2.9.0 – 2.9.4 affected by symlink following in staticFiles.externalLocation. Exploit public, MEDIUM severity. Restrict external resource access and monitor for patches. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-26T10:30:25.000Z ##

CVE-2026-17459: perwendel spark 2.9.0 – 2.9.4 affected by symlink following in staticFiles.externalLocation. Exploit public, MEDIUM severity. Restrict external resource access and monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #CVE202617459 #Java #Security

##

CVE-2026-63720
(7.5 HIGH)

EPSS: 0.42%

updated 2026-07-26T05:16:23.927000

4 posts

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines and a dot-free Python expression. The crafted value is emitted verbatim into a generated 'from ... import ...' statement without identifier validation, cau

offseq at 2026-07-26T06:00:24.365Z ##

CVE-2026-63720 (HIGH): koxudaxi datamodel-code-generator <0.70.0 is vulnerable to code injection. Malicious input schemas can trigger remote Python code execution. Avoid untrusted schemas & update when possible. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-07-26T05:59:49.000Z ##

🟠 CVE-2026-63720 - High (7.5)

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-26T06:00:24.000Z ##

CVE-2026-63720 (HIGH): koxudaxi datamodel-code-generator <0.70.0 is vulnerable to code injection. Malicious input schemas can trigger remote Python code execution. Avoid untrusted schemas & update when possible. radar.offseq.com/threat/cve-20 #OffSeq #infosec #Python #CVE202663720

##

thehackerwire@mastodon.social at 2026-07-26T05:59:49.000Z ##

🟠 CVE-2026-63720 - High (7.5)

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15962
(8.8 HIGH)

EPSS: 0.38%

updated 2026-07-26T03:30:31

3 posts

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over a

hugovalters@mastodon.social at 2026-07-26T11:10:16.000Z ##

CVE-2026-15962 - Insecure Deserialization in Fluent Forms Pro allows authenticated attackers to escalate to admin account takeover. CVSS 8.8. No patch yet – disable user update integration to mitigate. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-159

##

thehackerwire@mastodon.social at 2026-07-26T03:00:20.000Z ##

🟠 CVE-2026-15962 - High (8.8)

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-lev...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-26T03:00:20.000Z ##

🟠 CVE-2026-15962 - High (8.8)

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-lev...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64329(CVSS UNKNOWN)

EPSS: 0.18%

updated 2026-07-25T12:31:38

1 posts

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove The threaded IRQ handler ccg_irq_handler() calls ucsi_notify_common(), which on a connector-change event calls ucsi_connector_change() and schedules connector work. In ucsi_ccg_remove(), ucsi_destroy() frees uc->ucsi (kfree) before free_irq() is called, so a handler in

hugovalters@mastodon.social at 2026-07-26T12:00:47.000Z ##

CVE-2026-64329 - Use-after-free in Linux kernel USB Type-C UCSI driver. CVSS 0.0. Risk of memory corruption. Apply kernel patch when available. #CVE #Linux #kernel

valtersit.com/cve/CVE-2026-643

##

CVE-2026-64275(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-07-25T12:31:34

1 posts

In the Linux kernel, the following vulnerability has been resolved: Input: elan_i2c - prevent division by zero and arithmetic underflow The Elan I2C touchpad driver queries the device for its physical dimensions and trace counts to calculate the device resolution and width. However, if the device firmware or device tree provides invalid zero values for x_traces or y_traces, it results in a fatal

hugovalters@mastodon.social at 2026-07-26T14:01:47.000Z ##

CVE-2026-64275 - DoS in Linux kernel (Elan I2C touchpad). Division by zero causes kernel panic on probe. CVSS 0. No patch yet. Monitor for updates. #CVE #Linux #infosec

valtersit.com/cve/CVE-2026-642

##

CVE-2026-64377(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-07-25T12:31:34

1 posts

In the Linux kernel, the following vulnerability has been resolved: cpufreq: qcom-cpufreq-hw: Fix possible double free qcom_cpufreq.data is allocated with devm_kzalloc() in probe() as an array of per-domain data. qcom_cpufreq_hw_cpu_init() stores a pointer to one element of this array in policy->driver_data. qcom_cpufreq_hw_cpu_exit() currently calls kfree() on policy->driver_data. This is not

hugovalters@mastodon.social at 2026-07-25T23:05:05.000Z ##

CVE-2026-64377 - Double free in Linux kernel cpufreq driver (qcom-cpufreq-hw). Potential system crash or exploitation. CVSS 0. No patch yet. Monitor your distro for updates. #CVE #Linux #infosec

valtersit.com/cve/CVE-2026-643

##

CVE-2026-64309(CVSS UNKNOWN)

EPSS: 0.21%

updated 2026-07-25T12:31:30

1 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT) Sashiko notes: > if SEV initialization fails and KVM is actively running normal VMs, could a > userspace process trigger this code path via /dev/sev ioctls (e.g., > SEV_PDH_GEN) and zero out MSR_VM_HSAVE_PA globally? Would the next VMRUN > execution for an active VM trig

hugovalters@mastodon.social at 2026-07-26T15:01:07.000Z ##

CVE-2026-64309 - Linux kernel crypto/ccp flaw. SNP initialization bug can cause host crash. CVSS 0.0. No patch yet - stay vigilant. #CVE #Linux #infosec

valtersit.com/cve/CVE-2026-643

##

CVE-2026-66012
(10.0 CRITICAL)

EPSS: 0.44%

updated 2026-07-25T11:17:19.053000

2 posts

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy actions across the entire workspace. When the Publish server is enabled in anonymous mode (Conf.Publis

1 repos

https://github.com/Hunt-Benito/siyuan-mcp-admin-takeover-cve-2026-66012-missing-authorization

offseq@infosec.exchange at 2026-07-25T12:00:26.000Z ##

CVE-2026-66012: CRITICAL flaw in siyuan-note siyuan (<3.7.2). Missing authorization on /mcp lets remote attackers read secrets & plant malicious plugins for admin takeover. Disable anonymous Publish mode & restrict /mcp access. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec

##

thehackerwire@mastodon.social at 2026-07-25T12:00:01.000Z ##

🔴 CVE-2026-66012 - Critical (10)

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10818
(8.1 HIGH)

EPSS: 0.42%

updated 2026-07-25T07:17:08.880000

2 posts

The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the assembled file not being deleted upon validation failure. This makes it possible for unauthenticated

1 repos

https://github.com/Nxploited/CVE-2026-10818

offseq@infosec.exchange at 2026-07-25T13:30:10.000Z ##

CVE-2026-10818: WPForms Pro <=1.10.1.1 has a HIGH severity file upload vuln (CVSS 8.1). Unauthenticated RCE possible via ajax_chunk_upload_finalize. Restrict access & monitor uploads until a patch is released. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #CVE202610818

##

thehackerwire@mastodon.social at 2026-07-25T07:59:48.000Z ##

🟠 CVE-2026-10818 - High (8.1)

The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66034
(7.5 HIGH)

EPSS: 0.25%

updated 2026-07-25T05:16:42.773000

1 posts

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without

thehackerwire@mastodon.social at 2026-07-24T18:00:34.000Z ##

🟠 CVE-2026-66034 - High (7.5)

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsy...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56163
(10.0 CRITICAL)

EPSS: 0.92%

updated 2026-07-25T05:16:35.420000

2 posts

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

offseq@infosec.exchange at 2026-07-25T04:30:23.000Z ##

CVE-2026-56163: CRITICAL (CVSS 10) in Azure Kubernetes Service — Missing authentication allows remote privilege escalation. Microsoft has released a fix; verify your AKS is updated. radar.offseq.com/threat/cve-20 #OffSeq #Azure #Kubernetes #CloudSecurity

##

thehackerwire@mastodon.social at 2026-07-24T22:01:21.000Z ##

🔴 CVE-2026-56163 - Critical (10)

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66374
(8.1 HIGH)

EPSS: 0.39%

updated 2026-07-25T03:30:55

1 posts

Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.

1 repos

https://github.com/venglin/knot-doq

thehackerwire@mastodon.social at 2026-07-25T03:00:16.000Z ##

🟠 CVE-2026-66374 - High (8.1)

Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66041
(8.8 HIGH)

EPSS: 0.42%

updated 2026-07-25T02:16:40.150000

1 posts

FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data excee

thehackerwire@mastodon.social at 2026-07-24T22:00:14.000Z ##

🟠 CVE-2026-66041 - High (8.8)

FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimension...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66373
(7.5 HIGH)

EPSS: 0.47%

updated 2026-07-25T01:16:26.277000

1 posts

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.

thehackerwire@mastodon.social at 2026-07-25T03:00:05.000Z ##

🟠 CVE-2026-66373 - High (7.5)

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both cons...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61884
(9.8 CRITICAL)

EPSS: 0.66%

updated 2026-07-25T00:31:53

3 posts

The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, dev

offseq@infosec.exchange at 2026-07-25T00:00:40.000Z ##

CVE-2026-61884 (CRITICAL, CVSS 9.8) in Tycon TPDIN-Monitor-WEB2 v2.3.9: Server-side auth validation missing — empty creds grant admin access. Restrict management interface, monitor for unauthorized logins. radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoT #Infosec

##

thehackerwire@mastodon.social at 2026-07-24T23:00:11.000Z ##

🔴 CVE-2026-61884 - Critical (9.8)

The web management interface of Tycon Systems TPDIN-Monitor-WEB2

 does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can byp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-07-24T13:04:35.000Z ##

Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8

securityonline.info/tycon-auth

##

CVE-2026-60134
(8.8 HIGH)

EPSS: 0.32%

updated 2026-07-25T00:31:53

1 posts

Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.

thehackerwire@mastodon.social at 2026-07-25T00:00:13.000Z ##

🟠 CVE-2026-60134 - High (8.8)

Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-71408
(7.8 HIGH)

EPSS: 0.16%

updated 2026-07-25T00:31:53

1 posts

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or san

thehackerwire@mastodon.social at 2026-07-24T23:00:01.000Z ##

🟠 CVE-2025-71408 - High (7.8)

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is inv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61892
(8.8 HIGH)

EPSS: 0.27%

updated 2026-07-24T23:16:51.333000

1 posts

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

thehackerwire@mastodon.social at 2026-07-25T00:00:02.000Z ##

🟠 CVE-2026-61892 - High (8.8)

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14603
(7.5 HIGH)

EPSS: 0.24%

updated 2026-07-24T21:33:30

1 posts

The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the database.

thehackerwire@mastodon.social at 2026-07-25T10:00:01.000Z ##

🟠 CVE-2026-14603 - High (7.5)

The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45811
(7.5 HIGH)

EPSS: 0.25%

updated 2026-07-24T21:33:30

1 posts

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. Severity is low: exploitation requires either a misconfigured pool size or a malicious/compromised controller on the other end of the HCI socket l

thehackerwire@mastodon.social at 2026-07-25T08:00:47.000Z ##

🟠 CVE-2026-45811 - High (7.5)

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE.
The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer ove...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45815
(7.5 HIGH)

EPSS: 0.37%

updated 2026-07-24T21:33:30

1 posts

Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser. Severity is medium as this requires DUT to first send ATT Read Multiple Variable Request. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

thehackerwire@mastodon.social at 2026-07-25T08:00:24.000Z ##

🟠 CVE-2026-45815 - High (7.5)

Reachable Assertion vulnerability in Apache NimBLE.
A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser.

Severity is medium as this requires DUT to first send ATT Read Multiple ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66144
(7.5 HIGH)

EPSS: 0.33%

updated 2026-07-24T21:33:30

1 posts

Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, which fixes this issue by imposing a default maximum size on data read from remote policy references.

thehackerwire@mastodon.social at 2026-07-25T06:00:17.000Z ##

🟠 CVE-2026-66144 - High (7.5)

Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12877
(9.1 CRITICAL)

EPSS: 0.24%

updated 2026-07-24T21:33:29

1 posts

The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0's standard front-end issue-tracker configuration.

thehackerwire@mastodon.social at 2026-07-25T10:00:21.000Z ##

🔴 CVE-2026-12877 - Critical (9.1)

The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is expl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66142
(7.5 HIGH)

EPSS: 0.33%

updated 2026-07-24T21:33:29

1 posts

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue.

thehackerwire@mastodon.social at 2026-07-25T05:00:24.000Z ##

🟠 CVE-2026-66142 - High (7.5)

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recom...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62835
(9.3 CRITICAL)

EPSS: 1.03%

updated 2026-07-24T21:32:28

3 posts

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

offseq@infosec.exchange at 2026-07-25T01:30:24.000Z ##

CVE-2026-62835 (CRITICAL, CVSS 9.3) affects Microsoft Azure Portal: improper authorization enables remote info disclosure with high confidentiality impact. Microsoft has fixed server-side. More at radar.offseq.com/threat/cve-20 #OffSeq #Azure #Vuln #CloudSecurity

##

thehackerwire@mastodon.social at 2026-07-24T22:01:11.000Z ##

🔴 CVE-2026-62835 - Critical (9.3)

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DarkWebInformer@infosec.exchange at 2026-07-24T20:45:57.000Z ##

🚨 CVE-2026-62835: Microsoft Azure Portal Information Disclosure Vulnerability

CVE-2026-62835 involves a flaw in the authorization process of Online Services, enabling attackers to access restricted information. The vulnerability documented by this CVE requires no customer action to resolve.

CVSS: 9.3

More information: msrc.microsoft.com/update-guid

##

CVE-2026-66039
(8.8 HIGH)

EPSS: 0.42%

updated 2026-07-24T21:32:28

1 posts

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_fra

thehackerwire@mastodon.social at 2026-07-24T22:01:01.000Z ##

🟠 CVE-2026-66039 - High (8.8)

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attack...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66036
(8.8 HIGH)

EPSS: 0.29%

updated 2026-07-24T21:32:28

1 posts

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() a

thehackerwire@mastodon.social at 2026-07-24T22:00:24.000Z ##

🟠 CVE-2026-66036 - High (8.8)

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66040
(8.8 HIGH)

EPSS: 0.55%

updated 2026-07-24T21:32:28

1 posts

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output

thehackerwire@mastodon.social at 2026-07-24T22:00:03.000Z ##

🟠 CVE-2026-66040 - High (8.8)

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17107
(8.5 HIGH)

EPSS: 0.23%

updated 2026-07-24T21:32:28

1 posts

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an

thehackerwire@mastodon.social at 2026-07-24T20:00:24.000Z ##

🟠 CVE-2026-17107 - High (8.5)

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12981
(7.5 HIGH)

EPSS: 0.30%

updated 2026-07-24T20:48:39.923000

1 posts

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.

thehackerwire@mastodon.social at 2026-07-25T10:59:50.000Z ##

🟠 CVE-2026-12981 - High (7.5)

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12497
(7.5 HIGH)

EPSS: 0.23%

updated 2026-07-24T20:48:39.923000

1 posts

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. The set of roles offered to the visitor and the set of roles the registration handler accepts are derived by two different parsers, and for some v

thehackerwire@mastodon.social at 2026-07-25T10:00:11.000Z ##

🟠 CVE-2026-12497 - High (7.5)

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16804
(8.3 HIGH)

EPSS: 0.29%

updated 2026-07-24T20:47:41.790000

1 posts

Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-07-25T12:59:53.000Z ##

🟠 CVE-2026-16804 - High (8.3)

Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45816
(7.5 HIGH)

EPSS: 0.38%

updated 2026-07-24T20:47:41.790000

1 posts

NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

thehackerwire@mastodon.social at 2026-07-25T08:00:36.000Z ##

🟠 CVE-2026-45816 - High (7.5)

NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.

This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low.

This...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45813
(8.8 HIGH)

EPSS: 0.27%

updated 2026-07-24T20:47:41.790000

1 posts

Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS service  "Add Source" and "Modify Source" operation PDU could results in stack buffer overflow or arbitrary out-of-bound read. This can be triggered by nearby devices over Bluetooth connection, however pairing is required prior to accessing BASS service,

thehackerwire@mastodon.social at 2026-07-25T06:00:27.000Z ##

🟠 CVE-2026-45813 - High (8.8)

Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service.
Improper validation when parsing BASS service  "Add Source" and "Modify Source" operation PDU could results in stack buffer overflow or arbit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66143
(7.5 HIGH)

EPSS: 0.33%

updated 2026-07-24T20:47:41.790000

1 posts

It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to version 3.2.3, which fixes this issue.

thehackerwire@mastodon.social at 2026-07-25T06:00:07.000Z ##

🟠 CVE-2026-66143 - High (7.5)

It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49745
(7.8 HIGH)

EPSS: 0.11%

updated 2026-07-24T18:32:33

1 posts

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.

thehackerwire@mastodon.social at 2026-07-25T09:00:25.000Z ##

🟠 CVE-2026-49745 - High (7.8)

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.

Software installed and run under a Guest VM can send commands to the G...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49743
(7.8 HIGH)

EPSS: 0.11%

updated 2026-07-24T18:32:33

1 posts

Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission involving a fence exported by the GPU driver, the reference count of the underlying synchronisation primitive is not properly incremented. This can be exploited, by destroying the ex

thehackerwire@mastodon.social at 2026-07-25T09:00:05.000Z ##

🟠 CVE-2026-49743 - High (7.8)

Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs.

During workload submission involving a fence exported by...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16800
(8.8 HIGH)

EPSS: 0.29%

updated 2026-07-24T18:32:33

1 posts

Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names concatenated into a script invocation.

thehackerwire@mastodon.social at 2026-07-25T05:00:14.000Z ##

🟠 CVE-2026-16800 - High (8.8)

Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via craf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16801
(8.8 HIGH)

EPSS: 0.29%

updated 2026-07-24T18:32:32

1 posts

Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the variables configuration file.

thehackerwire@mastodon.social at 2026-07-25T05:00:04.000Z ##

🟠 CVE-2026-16801 - High (8.8)

Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a craf...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65711
(7.2 HIGH)

EPSS: 2.41%

updated 2026-07-24T18:31:41

2 posts

sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands as the web server process user by setting a malicious backup path and triggering a backup. The FileBackupService builds a tar shell command via string concatenation, inserting the admin-configurable siteBackupPath setting without escapeshellarg() or e

secdb at 2026-07-27T00:01:21.635Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-65709
(8.3 HIGH)

EPSS: 0.22%

updated 2026-07-24T18:31:41

1 posts

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account access control. Attackers can invoke AccountController methods such as viewAction, editAction, deleteAction, and editPassAction without Account

thehackerwire@mastodon.social at 2026-07-24T20:01:19.000Z ##

🟠 CVE-2026-65709 - High (8.3)

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without pe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66035
(7.5 HIGH)

EPSS: 0.32%

updated 2026-07-24T18:31:41

1 posts

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffe

thehackerwire@mastodon.social at 2026-07-24T20:00:59.000Z ##

🟠 CVE-2026-66035 - High (7.5)

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66033
(7.5 HIGH)

EPSS: 0.39%

updated 2026-07-24T18:31:41

1 posts

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to

thehackerwire@mastodon.social at 2026-07-24T18:00:20.000Z ##

🟠 CVE-2026-66033 - High (7.5)

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AE...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66032
(8.8 HIGH)

EPSS: 0.29%

updated 2026-07-24T18:31:37

1 posts

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call retur

thehackerwire@mastodon.social at 2026-07-24T18:00:10.000Z ##

🟠 CVE-2026-66032 - High (8.8)

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a serv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65708
(8.1 HIGH)

EPSS: 0.22%

updated 2026-07-24T18:18:08.653000

1 posts

sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing authorization checks in AccountFileController. Attackers can supply arbitrary numeric file IDs through the download, view, delete, upload, and list actions

thehackerwire@mastodon.social at 2026-07-24T20:01:09.000Z ##

🟠 CVE-2026-65708 - High (8.1)

sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing au...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49744
(7.8 HIGH)

EPSS: 0.11%

updated 2026-07-24T18:16:59.660000

1 posts

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries.

thehackerwire@mastodon.social at 2026-07-25T09:00:15.000Z ##

🟠 CVE-2026-49744 - High (7.8)

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.

Out of bounds accesses triggered by malware introduced to a Guest KMD ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66027
(8.3 HIGH)

EPSS: 0.26%

updated 2026-07-24T17:17:34.993000

1 posts

Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read pending prompt queues of all users, read or delete individual sessions, and inject arbitrary prompts into another user's sess

thehackerwire@mastodon.social at 2026-07-24T16:59:50.000Z ##

🟠 CVE-2026-66027 - High (8.3)

Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16807
(8.8 HIGH)

EPSS: 0.29%

updated 2026-07-24T15:34:00

1 posts

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-07-25T13:59:50.000Z ##

🟠 CVE-2026-16807 - High (8.8)

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16806
(8.8 HIGH)

EPSS: 0.43%

updated 2026-07-24T15:34:00

1 posts

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-07-25T13:00:13.000Z ##

🟠 CVE-2026-16806 - High (8.8)

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16805
(8.8 HIGH)

EPSS: 0.34%

updated 2026-07-24T15:34:00

1 posts

Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-07-25T13:00:03.000Z ##

🟠 CVE-2026-16805 - High (8.8)

Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8789
(8.1 HIGH)

EPSS: 0.22%

updated 2026-07-24T15:33:10

1 posts

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary connection records from the `

thehackerwire@mastodon.social at 2026-07-24T17:00:27.000Z ##

🟠 CVE-2026-8789 - High (8.1)

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58630
(10.0 CRITICAL)

EPSS: 0.81%

updated 2026-07-24T15:33:09

3 posts

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

offseq@infosec.exchange at 2026-07-25T06:00:25.000Z ##

CVE-2026-58630: Improper access control in Azure App Service for Linux (CVSS 10, CRITICAL) lets remote attackers escalate privileges with no auth or user action. Patched by Microsoft — verify updates. Details: radar.offseq.com/threat/cve-20 #OffSeq #Azure #Infosec #CVE2026_58630

##

DarkWebInformer@infosec.exchange at 2026-07-24T19:09:34.000Z ##

‼️ CVE-2026-58630: Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

CVSS: 10

Details: msrc.microsoft.com/update-guid

##

thehackerwire@mastodon.social at 2026-07-24T17:00:38.000Z ##

🔴 CVE-2026-58630 - Critical (10)

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57106
(10.0 CRITICAL)

EPSS: 0.92%

updated 2026-07-24T15:33:03

2 posts

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

offseq@infosec.exchange at 2026-07-25T07:30:24.000Z ##

Microsoft Purview Data Governance is impacted by CVE-2026-57106 (SSRF, CVSS 10, CRITICAL). Remote attackers can escalate privileges — patch ASAP using the official fix: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #SSRF #Microsoft #CyberSec

##

thehackerwire@mastodon.social at 2026-07-24T17:00:48.000Z ##

🔴 CVE-2026-57106 - Critical (10)

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12503(CVSS UNKNOWN)

EPSS: 0.14%

updated 2026-07-24T15:33:02

1 posts

Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to make `/etc/passwd` writable by the `larmapp` group (leading to root privilege escalation) via a symlink attack on `/etc/lighttpd/ssl/server.pem`.

offseq@infosec.exchange at 2026-07-25T10:30:26.000Z ##

CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #ICS #Loytec #CVE2026

##

CVE-2026-14172
(7.8 HIGH)

EPSS: 0.11%

updated 2026-07-24T09:32:22

1 posts

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0.

thehackerwire@mastodon.social at 2026-07-24T12:00:22.000Z ##

🟠 CVE-2026-14172 - High (7.8)

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYS...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16870
(8.8 HIGH)

EPSS: 0.36%

updated 2026-07-24T06:34:17

1 posts

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a crafted encryption metadata field to a shared internal stage that a victim proces

thehackerwire@mastodon.social at 2026-07-24T12:00:32.000Z ##

🟠 CVE-2026-16870 - High (8.8)

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66140
(8.4 HIGH)

EPSS: 0.27%

updated 2026-07-24T06:34:11

1 posts

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

thehackerwire@mastodon.social at 2026-07-25T11:00:00.000Z ##

🟠 CVE-2026-66140 - High (8.4)

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62145
(7.5 HIGH)

EPSS: 7.54%

updated 2026-07-24T05:16:45.940000

2 posts

A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.

1 repos

https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

secdb at 2026-07-27T00:01:21.635Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-62144
(9.1 CRITICAL)

EPSS: 20.62%

updated 2026-07-24T05:16:45.793000

2 posts

An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a conf

1 repos

https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

secdb at 2026-07-27T00:01:21.635Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-35425
(8.0 HIGH)

EPSS: 0.48%

updated 2026-07-24T03:32:01

1 posts

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-07-25T12:00:43.000Z ##

🟠 CVE-2026-35425 - High (8)

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54120
(9.9 CRITICAL)

EPSS: 0.71%

updated 2026-07-24T03:31:56

2 posts

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-07-25T12:00:23.000Z ##

🔴 CVE-2026-54120 - Critical (9.9)

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-24T13:30:30.000Z ##

CVE-2026-54120 (CRITICAL, CVSS 9.9): Improper input validation in Microsoft Surface Management Services lets authorized attackers run code remotely. Patch now: radar.offseq.com/threat/cve-20 🖥️ #OffSeq #infosec #Microsoft #CVE202654120

##

CVE-2026-56167
(8.5 HIGH)

EPSS: 0.38%

updated 2026-07-24T03:31:56

1 posts

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-07-25T11:00:10.000Z ##

🟠 CVE-2026-56167 - High (8.5)

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56160
(9.1 CRITICAL)

EPSS: 0.65%

updated 2026-07-24T03:31:56

1 posts

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

offseq@infosec.exchange at 2026-07-24T12:00:29.000Z ##

CRITICAL improper authorization vuln (CVE-2026-56160) in Azure Red Hat OpenShift (ARO): privilege escalation risk for authorized users. No active exploits. Microsoft has released a fix — ensure your ARO instances are updated. Details: radar.offseq.com/threat/cve-20 #OffSeq #Azure #CVE202656160

##

CVE-2026-50517
(9.9 CRITICAL)

EPSS: 1.25%

updated 2026-07-24T03:31:55

1 posts

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-07-25T12:00:33.000Z ##

🔴 CVE-2026-50517 - Critical (9.9)

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-6516
(10.0 CRITICAL)

EPSS: 4.73%

updated 2026-07-23T18:31:54

2 posts

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

secdb at 2026-07-27T00:01:21.635Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-16723
(9.0 CRITICAL)

EPSS: 0.41%

updated 2026-07-23T15:01:24.377000

9 posts

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

2 repos

https://github.com/dinosn/fastjson-jsontype-rce-lab

https://github.com/HORKimhab/CVE-2026-16723

threatnoir at 2026-07-27T08:06:02.689Z ##

⚠️ CRITICAL: Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Attackers are actively exploiting CVE-2026-16723, a critical RCE in Alibaba Fastjson 1.x used by Spring Boot applications. Unauthenticated code execution is possible with Java process privileges. No patch exists for 1.x versions yet.

threatnoir.com/focus

##

security_crawler_carl at 2026-07-26T12:49:23.180Z ##

🏆 New Achievement! Critical Hit: JSON and the Argonauts!

You have looted a CURSED ITEM: Fastjson 1.x (versions 1.2.68–1.2.83). Equip penalty: unauthenticated attackers may now execute arbitrary code on your Spring Boot applications via crafted JSON requests, bypassing default security configurations entirely. CVE-2026-16723 is active in the wild, no patch exists for the 1.x branch, and yes, that means you.

Inventory is full of regret. (1/2)

##

obivan at 2026-07-26T10:57:36.551Z ##

FastJson 1.2.83 RCE (CVE-2026-16723) fearsoff.org/research/fastjson

##

beyondmachines1 at 2026-07-26T10:01:41.518Z ##

Critical Fastjson 1.x Zero-Day RCE Exploited in the Wild

Alibaba's Fastjson 1.x library is vulnerable to a critical zero-day remote code execution flaw (CVE-2026-16723) that is currently exploited in the wild against Spring Boot applications. The vulnerability allows unauthenticated attackers to run arbitrary code by bypassing default security configurations through crafted JSON requests.

**If you run Java apps using Fastjson 1.x (versions 1.2.68–1.2.83) as Spring Boot fat-JARs, your applications are actively attacked, and there is no patch for the 1.x branch. Migrate to Fastjson2 ASAP. If you can't migrate, immediately enable SafeMode by adding `-Dfastjson.parser.safeMode=true` to your JVM settings and monitor your logs for unusual `@type` values or unexpected outbound connections from Java.**

beyondmachines.net/event_detai

##

threatnoir@infosec.exchange at 2026-07-27T08:06:02.000Z ##

⚠️ CRITICAL: Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Attackers are actively exploiting CVE-2026-16723, a critical RCE in Alibaba Fastjson 1.x used by Spring Boot applications. Unauthenticated code execution is possible with Java process privileges. No patch exists for 1.x versions yet.

threatnoir.com/focus

#infosec #cybersecurity

##

security_crawler_carl@infosec.exchange at 2026-07-26T12:49:23.000Z ##

🏆 New Achievement! Critical Hit: JSON and the Argonauts!

You have looted a CURSED ITEM: Fastjson 1.x (versions 1.2.68–1.2.83). Equip penalty: unauthenticated attackers may now execute arbitrary code on your Spring Boot applications via crafted JSON requests, bypassing default security configurations entirely. CVE-2026-16723 is active in the wild, no patch exists for the 1.x branch, and yes, that means you.

Inventory is full of regret. (1/2)

##

obivan@infosec.exchange at 2026-07-26T10:57:36.000Z ##

FastJson 1.2.83 RCE (CVE-2026-16723) fearsoff.org/research/fastjson

##

beyondmachines1@infosec.exchange at 2026-07-26T10:01:41.000Z ##

Critical Fastjson 1.x Zero-Day RCE Exploited in the Wild

Alibaba's Fastjson 1.x library is vulnerable to a critical zero-day remote code execution flaw (CVE-2026-16723) that is currently exploited in the wild against Spring Boot applications. The vulnerability allows unauthenticated attackers to run arbitrary code by bypassing default security configurations through crafted JSON requests.

**If you run Java apps using Fastjson 1.x (versions 1.2.68–1.2.83) as Spring Boot fat-JARs, your applications are actively attacked, and there is no patch for the 1.x branch. Migrate to Fastjson2 ASAP. If you can't migrate, immediately enable SafeMode by adding `-Dfastjson.parser.safeMode=true` to your JVM settings and monitor your logs for unusual `@type` values or unexpected outbound connections from Java.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-07-25T02:24:01.000Z ##

FastJson RCE vulnerability CVE-2026-16723 is exploited in the wild. Details and PoC exploit code are public for this critical remote code execution flaw.

#FastJson #CVE202616723 #RCE #ZeroDay

securityonline.info/fastjson-r

##

CVE-2026-16232
(9.1 CRITICAL)

EPSS: 12.68%

updated 2026-07-22T21:32:05

6 posts

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server I

1 repos

https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

secdb at 2026-07-27T00:01:21.635Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

##

DailyCyberSecurity at 2026-07-26T15:30:52.246Z ##

Discover the critical CVE-2026-16232 vulnerability in Check Point Security Management servers, allowing remote attackers to gain full administrative privileges without a password.

meterpreter.org/check-point-se

##

netsecio@mastodon.social at 2026-07-25T19:15:49.000Z ##

📰 Analysis Highlights Attacks on "Management Layer" Infrastructure

Analysis reveals a trend of attacks on the "management layer." Recent incidents involving an Iranian APT, a Check Point zero-day (CVE-2026-16232), and a SharePoint RCE (CVE-2026-50522) highlight this high-impact strategy. #CyberSecurity #ThreatIntel ...

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/an

##

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

DailyCyberSecurity@infosec.exchange at 2026-07-26T15:30:52.000Z ##

Discover the critical CVE-2026-16232 vulnerability in Check Point Security Management servers, allowing remote attackers to gain full administrative privileges without a password.

#CheckPoint #CyberSecurity #CVE202616232 #NetworkSecurity #Vulnerability

meterpreter.org/check-point-se

##

DarkWebInformer@infosec.exchange at 2026-07-24T19:30:19.000Z ##

‼️ CVE-2026-16232: An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

CVSS: 9.1

Scanner: github.com/WadesWeaponShed/Che

Details and Mitigation: support.checkpoint.com/results

##

CVE-2026-50522
(9.8 CRITICAL)

EPSS: 57.10%

updated 2026-07-22T21:31:51

5 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

2 repos

https://github.com/HORKimhab/CVE-2026-50522

https://github.com/4minx/CVE-2026-50522

security_crawler_carl at 2026-07-26T15:21:30.529Z ##

🏆 New Achievement! Stand In the Fire, Lose the SharePoint!

MOVE OUT OF THE DESERIALIZATION FLAW. I AM NOT KIDDING. CVE-2026-50522 is a CVSS 9.8 critical hole in on-premises Microsoft SharePoint — remote code execution, low complexity, no special system knowledge required. Researchers at watchTowr and Defused are screaming in chat right now because exploit code just dropped and attackers are already in your server. (1/2)

##

netsecio@mastodon.social at 2026-07-25T19:15:49.000Z ##

📰 Analysis Highlights Attacks on "Management Layer" Infrastructure

Analysis reveals a trend of attacks on the "management layer." Recent incidents involving an Iranian APT, a Check Point zero-day (CVE-2026-16232), and a SharePoint RCE (CVE-2026-50522) highlight this high-impact strategy. #CyberSecurity #ThreatIntel ...

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/an

##

security_crawler_carl@infosec.exchange at 2026-07-26T15:21:30.000Z ##

🏆 New Achievement! Stand In the Fire, Lose the SharePoint!

MOVE OUT OF THE DESERIALIZATION FLAW. I AM NOT KIDDING. CVE-2026-50522 is a CVSS 9.8 critical hole in on-premises Microsoft SharePoint — remote code execution, low complexity, no special system knowledge required. Researchers at watchTowr and Defused are screaming in chat right now because exploit code just dropped and attackers are already in your server. (1/2)

##

thecybermind@infosec.exchange at 2026-07-25T05:35:48.000Z ##

Active exploitation verified for CVE-2026-50522. Microsoft SharePoint's deserialization flaw demands immediate C-Suite oversight, patch prioritization, and strict endpoint hardening. Protect your enterprise assets today. thecybermind.co/kc88

##

thecybermind@infosec.exchange at 2026-07-24T15:22:59.000Z ##

(CISA TS-SOC) CVE-2026-50522 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Severity: CRITICAL Impact Summary: An unauthorized attacker can execute code over a network via deserialization of untrusted data....

thecybermind.co/2026/07/24/cis

##

CVE-2026-53359
(8.8 HIGH)

EPSS: 0.91%

updated 2026-07-22T21:31:50

1 posts

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. Th

6 repos

https://github.com/ndouglas-cloudsmith/CVE-2026-53359

https://github.com/HORKimhab/CVE-2026-53359

https://github.com/Aoripus-LTD/Januscape-Hotfix

https://github.com/chuzhongyun/CVE-2026-53359-Kernel-Fix

https://github.com/xj2268-TA/KVM-Januscape

https://github.com/0xBlackash/CVE-2026-53359

benoit@benoit.jp.net at 2026-07-25T12:29:58.000Z ##

I wonder how many hosters are vulnerable to CVE-2026-53359 (Januscape). Probably a lot.

##

CVE-2026-49176
(7.8 HIGH)

EPSS: 0.40%

updated 2026-07-22T16:17:28.753000

5 posts

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

1 repos

https://github.com/DavidCarliez/CVE-2026-49176_LPE_POC

undercodenews@mastodon.social at 2026-07-27T09:00:05.000Z ##

Windows WalletService Zero-Day Risk: How CVE-2026-49176 Lets Ordinary Users Become SYSTEM Administrators + Video

Introduction: A Hidden Windows Trust Failure That Turns Low Privilege Into Full Control Windows security is built around a strict separation between ordinary users and highly privileged system components. A standard account should not be able to force a trusted Windows service to execute attacker-controlled code with the highest operating system privileges.…

undercodenews.com/windows-wall

##

DailyCyberSecurity at 2026-07-27T01:40:33.795Z ##

CVE-2026-49176 is a Windows WalletService elevation of privilege flaw. Full details and a public PoC exploit are out, so patch Windows now.

securityonline.info/cve-2026-4

##

sayzard@mastodon.sayzard.org at 2026-07-26T13:38:41.000Z ##

CVE-2026-49176 Exploit Development: WalletService to System

CVE-2026-49176은 Windows WalletService의 로컬 권한 상승 취약점으로, 일반 사용자가 Documents 알려진 폴더 경로를 바꾼 뒤 공격자가 준비한 ESE 데이터베이스를 LocalSystem 서비스가 열도록 유도할 수 있습니다. WalletService가 ESE의 persisted callback을 활성화한 상태로 공격자 소유 DB의 Cards 테이블을 열면서, 지정된 DLL이 svchost.exe 내 SYSTEM 권한으로 로드되는 완전한 코드 실행 체인이 성립합니다. Microsoft는 CVSS 7.8(Impo...

davidcarliez.github.io/blog/cv

##

DailyCyberSecurity@infosec.exchange at 2026-07-27T01:40:33.000Z ##

CVE-2026-49176 is a Windows WalletService elevation of privilege flaw. Full details and a public PoC exploit are out, so patch Windows now.

#CVE202649176 #WalletService #Windows #PrivilegeEscalation #EoP #PoC #Microsoft

securityonline.info/cve-2026-4

##

lobsters@mastodon.social at 2026-07-25T14:30:15.000Z ##

CVE-2026-49176 Exploit Development: WalletService to SYSTEM lobste.rs/s/dxhdqx #security #windows
davidcarliez.github.io/blog/cv

##

CVE-2026-8985(CVSS UNKNOWN)

EPSS: 4.19%

updated 2026-07-22T00:32:44

2 posts

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.

secdb at 2026-07-27T00:01:21.635Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-64879
(9.9 CRITICAL)

EPSS: 2.59%

updated 2026-07-21T21:32:47

2 posts

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.

secdb at 2026-07-27T00:01:21.635Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-15226
(8.4 HIGH)

EPSS: 0.12%

updated 2026-07-21T15:30:58

1 posts

A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine to restrict system calls do not filter or reject process operations capable of creating or manipulating file execution flags with set-user-ID attributes. Consequently, an application running within a

sigint@fosstodon.org at 2026-07-26T23:45:06.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-07-27

Related seccomp hardening fix for the snap-confine mess: blocks sandboxed snaps from creating or executing setuid binaries. If you run snaps on servers, patch this alongside CVE-2026-8933, not separately.

🔗 ubuntu.com/security/CVE-2026-1

#Ubuntu #Linux #infosec

##

CVE-2026-8933
(7.8 HIGH)

EPSS: 0.18%

updated 2026-07-21T15:30:51

2 posts

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or secur

sigint@fosstodon.org at 2026-07-26T23:45:06.000Z ##

🐧 SIGINT // Ubuntu Watch — 2026-07-27

Related seccomp hardening fix for the snap-confine mess: blocks sandboxed snaps from creating or executing setuid binaries. If you run snaps on servers, patch this alongside CVE-2026-8933, not separately.

🔗 ubuntu.com/security/CVE-2026-1

#Ubuntu #Linux #infosec

##

security_crawler_carl@infosec.exchange at 2026-07-25T11:12:26.000Z ##

CVE-2026-8933, lovingly documented by the Qualys Threat Research Unit, lets a local user squeeze through that gap, drop a malicious AppArmor rules file, prod systemd-udevd into running commands as root, and collect full root access like a door prize. Ubuntu Desktop 24.04, 25.10, and 26.04 ship this by default. It is a trap room with the pressure plate installed by the architect. (2/3)

##

CVE-2026-63766
(9.8 CRITICAL)

EPSS: 1.75%

updated 2026-07-20T21:31:57

2 posts

GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into shell commands executed with shell=True. Attackers can inject shell metacharacters through path parameters to execute arbitrary OS commands as the server process user without authentication.

1 repos

https://github.com/0xdak/CVE-2026-63766_exploit

secdb at 2026-07-27T00:01:21.635Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-63108
(8.8 HIGH)

EPSS: 1.92%

updated 2026-07-20T21:31:57

2 posts

Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions inside parameter expansion defaults. The command parser in parse-command.ts replaces parameter expansions with opaque placeholders before extracting command substitutions, causing the containsDangerous

secdb at 2026-07-27T00:01:21.635Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-16242
(9.4 CRITICAL)

EPSS: 0.37%

updated 2026-07-20T09:31:15

1 posts

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy,

CVE-2026-58644
(9.8 CRITICAL)

EPSS: 5.06%

updated 2026-07-17T05:16:40.470000

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

thecybermind@infosec.exchange at 2026-07-25T06:16:56.000Z ##

(CISA TS-SOC) CVE-2026-58644 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Severity: CRITICAL Impact Summary: An unauthorized attacker can execute code over a network via deserialization of untrusted data....

thecybermind.co/2026/07/18/__t

##

CVE-2026-25089
(9.8 CRITICAL)

EPSS: 69.83%

updated 2026-07-16T18:32:24

1 posts

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP req

2 repos

https://github.com/0xBlackash/CVE-2026-25089

https://github.com/HORKimhab/CVE-2026-25089

thecybermind@infosec.exchange at 2026-07-25T06:21:34.000Z ##

(CISA TS-SOC) CVE-2026-25089 – Fortinet FortiSandbox OS Command Injection Vulnerability

Severity: CRITICAL Impact Summary: Allows remote, unauthenticated attackers to execute arbitrary operating system commands on affected FortiSandbox products via HTTP....

thecybermind.co/2026/07/25/cis

##

CVE-2026-39808
(9.8 CRITICAL)

EPSS: 89.69%

updated 2026-07-16T18:32:24

1 posts

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

Nuclei template

6 repos

https://github.com/samu-delucas/CVE-2026-39808

https://github.com/0xBlackash/CVE-2026-39808

https://github.com/Lechansky/CVE-2026-39808

https://github.com/error-inside/CVE-2026-39808

https://github.com/ynsmroztas/FortiSandbox-RCE-Exploit-CVE-2026-39808

https://github.com/HORKimhab/CVE-2026-39808

thecybermind@infosec.exchange at 2026-07-25T06:08:41.000Z ##

(CISA TS-SOC) CVE-2026-39808 – Fortinet FortiSandbox OS Command Injection Vulnerability

Severity: CRITICAL Impact Summary: Allows unauthenticated attackers to execute unauthorized code or commands on the affected system via crafted HTTP requests....

thecybermind.co/2026/07/25/cis

##

CVE-2026-42530
(8.1 HIGH)

EPSS: 3.68%

updated 2026-07-16T12:33:31

2 posts

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers

3 repos

https://github.com/HORKimhab/CVE-2026-42530

https://github.com/0xBlackash/CVE-2026-42530

https://github.com/v4ltonn/CVE-2026-42530

obivan at 2026-07-26T11:05:33.368Z ##

PoC's for nginx RCE (CVE-2026-42530, CVE-2026-42533) github.com/DepthFirstDisclosur

##

obivan@infosec.exchange at 2026-07-26T11:05:33.000Z ##

PoC's for nginx RCE (CVE-2026-42530, CVE-2026-42533) github.com/DepthFirstDisclosur

##

CVE-2026-42533
(8.1 HIGH)

EPSS: 2.79%

updated 2026-07-16T05:16:19.247000

3 posts

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyon

7 repos

https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner

https://github.com/gagaltotal/CVE-2026-42533-nginx

https://github.com/seguridadentrerios/CVE-2026-42533

https://github.com/Daniyal48/ghostlock-vagrant-box

https://github.com/srkyn/nginx-map-risk-audit

https://github.com/imbas007/CVE-2026-42533

https://github.com/suominen/CVE-2026-42533

obivan at 2026-07-26T11:05:33.368Z ##

PoC's for nginx RCE (CVE-2026-42530, CVE-2026-42533) github.com/DepthFirstDisclosur

##

obivan@infosec.exchange at 2026-07-26T11:05:33.000Z ##

PoC's for nginx RCE (CVE-2026-42530, CVE-2026-42533) github.com/DepthFirstDisclosur

##

ChrisShort@hachyderm.io at 2026-07-24T15:29:13.000Z ##

15-Year-Old Pre-Auth nginx RCE Across 13 Call Sites: Two-Pass Capture Clobbering CVE-2026-42533 – cyberstan #devopsish cyberstan.co.uk/nginx-rce/

##

CVE-2026-46817
(9.8 CRITICAL)

EPSS: 13.31%

updated 2026-07-15T18:32:50

1 posts

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Con

2 repos

https://github.com/HORKimhab/CVE-2026-46817

https://github.com/0xBlackash/CVE-2026-46817

thecybermind@infosec.exchange at 2026-07-25T17:07:36.000Z ##

(CISA TS-MAN) CVE-2026-46817 – Oracle E-Business Suite Improper Privilege Management Vulnerability

Severity: CRITICAL Impact Summary: Allows unauthenticated attacker to compromise Oracle Payments, potentially resulting in full takeover....

thecybermind.co/2026/07/25/cis

##

CVE-2023-4346
(7.5 HIGH)

EPSS: 0.91%

updated 2026-07-15T18:32:50

1 posts

KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to in

thecybermind@infosec.exchange at 2026-07-25T17:04:55.000Z ##

(CISA TS-MAN) CVE-2023-4346 – KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability

Severity: HIGH Impact Summary: An attacker could purge all devices and set a BCU key to lock the device, potentially resulting in denial of service if additional security options are not enabled....

thecybermind.co/2026/07/25/cis

##

CVE-2026-42945
(8.1 HIGH)

EPSS: 61.47%

updated 2026-07-15T02:21:38.583000

5 posts

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond it

42 repos

https://github.com/hnytgl/CVE-2026-42945

https://github.com/fkj-src/fix_nginx_cve_2026_42945

https://github.com/rheodev/CVE-2026-42945

https://github.com/aratane/CVE-2026-42945

https://github.com/RedCrazyGhost/CVE-2026-42945

https://github.com/josephfelix/CVE-2026-42945-nginx-rift

https://github.com/yusufdalbudak/CVE-2026-42945

https://github.com/Renison-Gohel/CVE-2026-42945-NGINX-Rift

https://github.com/iammerrida-source/nginx-rift-detect

https://github.com/0xBlackash/CVE-2026-42945

https://github.com/cipherspy/CVE-2026-42945-POC

https://github.com/jelasin/CVE-2026-42945

https://github.com/nanwinata/nginxrift-CVE-2026-42945

https://github.com/soksofos/wazuh-nginx-cve-2026-42945-sca-lab

https://github.com/azilRababe/CVE-2026-42945

https://github.com/simota/nginx-rift-scanner

https://github.com/F2u0a0d3/CVE-2026-42945-nginx-rift-poc

https://github.com/nu0l/NGINX-Rift

https://github.com/BarAppTeam/nginx-cve-fix

https://github.com/oseasfr/Scanner_CVE_2026-42945

https://github.com/byezero/nginx-cve-2026-42945-check

https://github.com/hulina9900-boop/DIY-CVE-2026-42945-POC

https://github.com/tal7aouy/nginx-cve-2026-42945

https://github.com/MateusVerass/nGixshell

https://github.com/sec-sys/CVE-2026-42945-Reverse-Shell-POC

https://github.com/p3Nt3st3r-sTAr/CVE-2026-42945-POC

https://github.com/chenqin231/CVE-2026-42945

https://github.com/quantumworld-dpdns-io/CVE-2026-42945

https://github.com/limo57640-crypto/nginx-rift-detector

https://github.com/strivepan/Nginx_cve-2026-42945-scanner-gui

https://github.com/imSre9/CVE-2026-42945

https://github.com/ChamsBouzaiene/ai-vuln-rediscovery-nginx-cve-2026-42945

https://github.com/forxiucn/nginx-cve-2026-42945-poc

https://github.com/friparia/NGINX_RIFT_SCAN_CVE_2026_42945

https://github.com/LiaoZiqi-GZFLS/CVE-2026-42945

https://github.com/gagaltotal/CVE-2026-42945-NGINX-Rift-Toolkit

https://github.com/lowilol/CVE-2026-42945-NGINX-Rift-Check-Script

https://github.com/edgecases-PurpleHax/cve-images

https://github.com/dinosn/cve-2026-42945-nginx32-lab

https://github.com/sibersan/web-server-audit_CVE-2026-42945

https://github.com/webdev75950-ux/nginx-rce-cve-2026-42945

https://github.com/realityone/cve-2026-42945-scan

security_crawler_carl at 2026-07-27T05:03:52.270Z ##

You do not get to respawn. The debuff is applied to all servers simultaneously. Enjoy your stay.

Patch NGINX now to address CVE-2026-42945 before the PoC makes your threat landscape significantly more crowded.

Reward: You've received the Mandatory Participation Trophy — it's just a heap of broken memory.

(2/2)

##

security_crawler_carl at 2026-07-27T05:03:51.973Z ##

🏆 New Achievement! Heap Today, Gone Tomorrow!

Welcome, new player, to the NGINX Rift tutorial! This mandatory onboarding introduces CVE-2026-42945, a critical heap buffer overflow in NGINX that enables remote code execution. A proof-of-concept exploit has now been published publicly, which means this mechanic is fully unlocked for every participant — including the ones you did not invite.

Think of it like Minecraft's Hardcore Mode, except the world was already on fire when you loaded in. (1/2)

##

netalexx.bsky.social@bsky.brid.gy at 2026-07-26T12:37:03.614Z ##

RCE Proof of concept for CVE-2026-42945, a critical heap buffer overflow in NGINX

GitHub - DepthFirstDisclosures...

##

security_crawler_carl@infosec.exchange at 2026-07-27T05:03:52.000Z ##

You do not get to respawn. The debuff is applied to all servers simultaneously. Enjoy your stay.

Patch NGINX now to address CVE-2026-42945 before the PoC makes your threat landscape significantly more crowded.

Reward: You've received the Mandatory Participation Trophy — it's just a heap of broken memory.

#Nginx #RCE #CyberSecurity #ZeroDay #BufferOverflow #ExploitUnlocked (2/2)

##

security_crawler_carl@infosec.exchange at 2026-07-27T05:03:51.000Z ##

🏆 New Achievement! Heap Today, Gone Tomorrow!

Welcome, new player, to the NGINX Rift tutorial! This mandatory onboarding introduces CVE-2026-42945, a critical heap buffer overflow in NGINX that enables remote code execution. A proof-of-concept exploit has now been published publicly, which means this mechanic is fully unlocked for every participant — including the ones you did not invite.

Think of it like Minecraft's Hardcore Mode, except the world was already on fire when you loaded in. (1/2)

##

CVE-2026-56155
(7.8 HIGH)

EPSS: 2.33%

updated 2026-07-14T21:32:52

1 posts

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

thecybermind@infosec.exchange at 2026-07-25T16:43:09.000Z ##

(CISA TS-MAN) CVE-2026-56155 – Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Severity: HIGH Impact Summary: Allows an authorized attacker to locally elevate privileges due to insufficient granularity of access control....

thecybermind.co/2026/07/25/cis

##

CVE-2026-15410
(7.2 HIGH)

EPSS: 76.35%

updated 2026-07-14T21:32:21

2 posts

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

3 repos

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

https://github.com/HORKimhab/CVE-2026-15410

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

thecybermind at 2026-07-26T17:26:03.961Z ##

🚨 Active Exploit Warning: SonicWall SMA1000 appliances are under fire from a high-severity code injection flaw (CVE-2026-15410). Our latest TSUITE brief breaks down the CrowdStrike detection logic and immediate hardening steps to secure your management interfaces. Command the wire: thecybermind.co/jily

##

thecybermind@infosec.exchange at 2026-07-26T17:26:03.000Z ##

🚨 Active Exploit Warning: SonicWall SMA1000 appliances are under fire from a high-severity code injection flaw (CVE-2026-15410). Our latest TSUITE brief breaks down the CrowdStrike detection logic and immediate hardening steps to secure your management interfaces. Command the wire: thecybermind.co/jily

#SOC

##

CVE-2026-54121
(8.8 HIGH)

EPSS: 1.05%

updated 2026-07-14T18:32:37

8 posts

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

6 repos

https://github.com/HORKimhab/CVE-2026-54121

https://github.com/aniqfakhrul/CVE-2026-54121

https://github.com/marcgoam/CVE-2026-54121-CertiGhost

https://github.com/GlendonNotGlen/certighost-cve-2026-54121-slides

https://github.com/tc4dy/CVE-2026-54121-PoC-Exploit

https://github.com/0xBlackash/CVE-2026-54121

al3x-n3ff.bsky.social@bsky.brid.gy at 2026-07-26T17:51:24.488Z ##

Detect the Certighost with NetExec🔥

Thanks to Xed_sama, the enum_cve module of NetExec will now detect if a host has not been patched and is potentially vulnerable to the Certighost vulnerability (CVE-2026-54121)🚀

##

guru@thecybersecguru.com at 2026-07-26T05:47:01.000Z ##

CertiGhost Exploit Allows Low-Privileged Active Directory Users to Impersonate a Domain Controller

A newly disclosed AD CS vulnerability, Certighost (CVE-2026-54121), allows low-privileged domain users to impersonate a Domain Controller

thecybersecguru.com/news/certi

##

al3x-n3ff.bsky.social@bsky.brid.gy at 2026-07-26T17:51:24.488Z ##

Detect the Certighost with NetExec🔥

Thanks to Xed_sama, the enum_cve module of NetExec will now detect if a host has not been patched and is potentially vulnerable to the Certighost vulnerability (CVE-2026-54121)🚀

##

guru@thecybersecguru.com at 2026-07-26T05:47:01.000Z ##

Certighost Exploit Allows Low-Privileged Active Directory Users to Impersonate a Domain Controller

A newly disclosed AD CS vulnerability, Certighost (CVE-2026-54121), allows low-privileged domain users to impersonate a Domain Controller

thecybersecguru.com/news/certi

##

benzogaga33@mamot.fr at 2026-07-25T09:40:03.000Z ##

Certighost (CVE-2026-54121) : un compte AD standard suffit pour usurper un contrôleur de domaine it-connect.fr/certighost-cve-2 #ActuCybersécurité #ActiveDirectory #Cybersécurité #Vulnérabilité #Microsoft

##

threatnoir@infosec.exchange at 2026-07-25T07:05:43.000Z ##

⚠️ CRITICAL: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Certighost (CVE-2026-54121) allows any domain user to obtain a Domain Controller certificate and execute DCSync attacks to steal the krbtgt secret without admin rights. This gives attackers a direct path to full domain compromise. Any organization running unpatched Active Directory is at immediate…

threatnoir.com/focus

#infosec #cybersecurity

##

DarkWebInformer@infosec.exchange at 2026-07-24T19:55:21.000Z ##

‼️ PoC released for CVE-2026-54121 codenamed Certighost

CVE-2026-54121 is a privilege escalation vulnerability in Active Directory Certificate Services that enables authorized attackers to elevate privileges.

GitHub: github.com/aniqfakhrul/cve-202

##

AAKL@infosec.exchange at 2026-07-24T15:49:06.000Z ##

New.

GitHub/H0j3n: Certighost (CVE-2026-54121) gist.github.com/H0j3n/a5ef2609

More:

The Hacker News: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller thehackernews.com/2026/07/cert @thehackernews #infosec #vulnerability #Microsoft #Windows

##

CVE-2026-50454
(7.8 HIGH)

EPSS: 0.44%

updated 2026-07-14T18:32:32

1 posts

Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

CVE-2026-55255
(8.4 HIGH)

EPSS: 29.05%

updated 2026-07-08T13:39:12.593000

1 posts

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.

1 repos

https://github.com/rootdirective-sec/CVE-2026-55255-Lab

thecybermind@infosec.exchange at 2026-07-25T17:06:29.000Z ##

(CISA TS-MAN) CVE-2026-55255 – Langflow Authorization Bypass Through User-Controlled Key Vulnerability

Severity: HIGH Impact Summary: An authenticated attacker can execute any flow belonging to another user by specifying the victim's flow ID in the request, bypassing authorization controls....

thecybermind.co/2026/07/25/cis

##

CVE-2026-12569
(9.8 CRITICAL)

EPSS: 2.26%

updated 2026-06-30T18:16:43.113000

7 posts

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

1 repos

https://github.com/west-wind/Threat-Hunting-With-Splunk

threatnoir at 2026-07-27T08:05:59.991Z ##

⚠️ CRITICAL: Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Cl0p ransomware affiliates are actively exploiting unauthenticated RCE vulnerabilities in internet-exposed PTC Windchill and FlexPLM instances by chaining CVE-2026-12569 with a separate information disclosure flaw. Affected organizations in manufacturing, automotive, aerospace, and retail face data…

threatnoir.com/focus

##

threatcodex at 2026-07-26T18:35:42.875Z ##

Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)

ransom-isac.org/blog/clop-wind

##

threatnoir at 2026-07-26T05:15:05.016Z ##

2026-W30 — Weekly Threat Roundup

🦅 Russian APT Laundry Bear exploited a Zimbra zero-click XSS flaw (CVE-2025-66376) to steal emails and MFA tokens from NATO, US, and Ukrainian targets with no user interaction required.
🏭 Clop affiliates are mass-exploiting PTC Windchill and FlexPLM (CVE-2026-12569) for unauthenticated RCE and da…

threatnoir.com/weekly/2026-w30

##

threatnoir@infosec.exchange at 2026-07-27T08:05:59.000Z ##

⚠️ CRITICAL: Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Cl0p ransomware affiliates are actively exploiting unauthenticated RCE vulnerabilities in internet-exposed PTC Windchill and FlexPLM instances by chaining CVE-2026-12569 with a separate information disclosure flaw. Affected organizations in manufacturing, automotive, aerospace, and retail face data…

threatnoir.com/focus

#infosec #cybersecurity

##

threatcodex@infosec.exchange at 2026-07-26T18:35:42.000Z ##

Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)
#Cl0p #CVE_2026_12569
ransom-isac.org/blog/clop-wind

##

threatnoir@infosec.exchange at 2026-07-26T05:15:05.000Z ##

2026-W30 — Weekly Threat Roundup

🦅 Russian APT Laundry Bear exploited a Zimbra zero-click XSS flaw (CVE-2025-66376) to steal emails and MFA tokens from NATO, US, and Ukrainian targets with no user interaction required.
🏭 Clop affiliates are mass-exploiting PTC Windchill and FlexPLM (CVE-2026-12569) for unauthenticated RCE and da…

threatnoir.com/weekly/2026-w30

#infosec #cybersecurity #threatintel

##

kev_Stalker@infosec.exchange at 2026-07-25T04:14:10.000Z ##

CVE-2026-12569 - Changed to Known Ransomware Status

PTC Windchill and FlexPLM Improper Input Validation VulnerabilityVendor: PTCProduct: Windchill and FlexPLMPTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: July 24,nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2025-0679
(4.3 MEDIUM)

EPSS: 0.29%

updated 2026-06-17T08:26:57.313000

1 posts

An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured.

security_crawler_carl@infosec.exchange at 2026-07-24T12:21:18.000Z ##

CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.

Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.

Reward: You've received a hollow Authenticator Token — pre-drained.

#ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)

##

CVE-2026-47668
(10.0 CRITICAL)

EPSS: 4.34%

updated 2026-06-05T16:25:28

2 posts

### Summary DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. ### Details #### Step 1:

Nuclei template

1 repos

https://github.com/Nxploited/CVE-2026-47668

secdb at 2026-07-27T00:01:21.635Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

##

secdb@infosec.exchange at 2026-07-27T00:01:21.000Z ##

📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478

Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651

CISA KEVs:
- CISA-2026:0721 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0722 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53

Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23

Top EPSS Score:
- CVE-2026-62144 - 20.62 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-16232 - 12.68 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-62145 - 7.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-6516 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-47668 - 4.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-8985 - 4.19 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-64879 - 2.59 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-65711 - 2.41 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63108 - 1.92 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63766 - 1.75 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-32194
(9.8 CRITICAL)

EPSS: 0.70%

updated 2026-03-20T00:31:34

1 posts

Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

1 repos

https://github.com/HORKimhab/CVE-2026-32194

threatnoir@infosec.exchange at 2026-07-25T06:06:27.000Z ##

⚠️ CRITICAL: Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

Microsoft patched two critical RCE flaws in Bing Images (CVE-2026-32194, CVE-2026-32191) that allowed unauthenticated attackers to execute arbitrary commands as SYSTEM/root via malicious SVG files processed by ImageMagick. Exploit details were published publicly in July 2026. Anyone who uploaded im…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-32191
(9.8 CRITICAL)

EPSS: 0.56%

updated 2026-03-19T21:30:31

1 posts

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

threatnoir@infosec.exchange at 2026-07-25T06:06:27.000Z ##

⚠️ CRITICAL: Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

Microsoft patched two critical RCE flaws in Bing Images (CVE-2026-32194, CVE-2026-32191) that allowed unauthenticated attackers to execute arbitrary commands as SYSTEM/root via malicious SVG files processed by ImageMagick. Exploit details were published publicly in July 2026. Anyone who uploaded im…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2025-66376
(7.2 HIGH)

EPSS: 21.62%

updated 2026-03-18T18:31:10

2 posts

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

threatnoir at 2026-07-26T05:15:05.016Z ##

2026-W30 — Weekly Threat Roundup

🦅 Russian APT Laundry Bear exploited a Zimbra zero-click XSS flaw (CVE-2025-66376) to steal emails and MFA tokens from NATO, US, and Ukrainian targets with no user interaction required.
🏭 Clop affiliates are mass-exploiting PTC Windchill and FlexPLM (CVE-2026-12569) for unauthenticated RCE and da…

threatnoir.com/weekly/2026-w30

##

threatnoir@infosec.exchange at 2026-07-26T05:15:05.000Z ##

2026-W30 — Weekly Threat Roundup

🦅 Russian APT Laundry Bear exploited a Zimbra zero-click XSS flaw (CVE-2025-66376) to steal emails and MFA tokens from NATO, US, and Ukrainian targets with no user interaction required.
🏭 Clop affiliates are mass-exploiting PTC Windchill and FlexPLM (CVE-2026-12569) for unauthenticated RCE and da…

threatnoir.com/weekly/2026-w30

#infosec #cybersecurity #threatintel

##

CVE-2025-29827
(9.9 CRITICAL)

EPSS: 1.25%

updated 2025-06-05T15:32:29

2 posts

Improper Authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.

security_crawler_carl at 2026-07-26T16:52:38.334Z ##

By continuing to run Azure Automation with default settings, you hereby agree to the following terms: (1) your tenant identity may be made available to any registered Azure user who wishes to borrow it, (2) your credentials, cloud workloads, and data shall be considered shared resources, and (3) you waive all complaints regarding CVE-2025-29827, CVSS 9.9, which allowed any attacker with their own Azure Automation account to vault the trust boundary and impersonate another tenant entirely. (2/3)

##

security_crawler_carl@infosec.exchange at 2026-07-26T16:52:38.000Z ##

By continuing to run Azure Automation with default settings, you hereby agree to the following terms: (1) your tenant identity may be made available to any registered Azure user who wishes to borrow it, (2) your credentials, cloud workloads, and data shall be considered shared resources, and (3) you waive all complaints regarding CVE-2025-29827, CVSS 9.9, which allowed any attacker with their own Azure Automation account to vault the trust boundary and impersonate another tenant entirely. (2/3)

##

CVE-2026-61511
(0 None)

EPSS: 0.00%

2 posts

N/A

CVE-2026-16766
(0 None)

EPSS: 0.68%

1 posts

N/A

offseq@infosec.exchange at 2026-07-25T09:00:28.000Z ##

CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+ or migrate. radar.offseq.com/threat/cve-20 #OffSeq #infosec #perl #vuln

##

CVE-2026-48021
(0 None)

EPSS: 0.12%

2 posts

N/A

offseq@infosec.exchange at 2026-07-25T03:00:25.000Z ##

CVE-2026-48021 in med-united epa4all (<2026-05-20): CRITICAL TLS cert validation flaw lets attackers decrypt/modify patient records & tokens. Upgrade to 2026-05-20+ ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #HealthcareSecurity #Vuln #CVE202648021

##

thehackerwire@mastodon.social at 2026-07-24T20:00:12.000Z ##

🔴 CVE-2026-48021 - Critical (9.1)

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traff...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54342
(0 None)

EPSS: 0.12%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-24T20:00:02.000Z ##

🟠 CVE-2026-54342 - High (8.1)

In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnek...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites