##
Updated at UTC 2026-09-05T00:30:10.121918
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-86095 | 7.8 | 0.00% | 2 | 0 | 2026-09-04T23:18:03.220000 | Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in | |
| CVE-2026-48019 | 8.9 | 0.00% | 2 | 1 | 2026-09-04T23:17:09.143000 | Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a | |
| CVE-2026-82684 | 8.1 | 0.00% | 2 | 0 | 2026-09-04T22:17:18.683000 | Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Mi | |
| CVE-2026-77393 | 8.8 | 0.00% | 5 | 0 | 2026-09-04T22:17:18.333000 | In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shi | |
| CVE-2026-75925 | 9.6 | 0.00% | 2 | 0 | 2026-09-04T22:17:18.017000 | Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4. | |
| CVE-2026-55985 | 4.3 | 0.15% | 2 | 0 | 2026-09-04T22:17:17.573000 | The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and dis | |
| CVE-2026-82712 | 8.8 | 0.00% | 2 | 0 | 2026-09-04T21:31:59 | Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cr | |
| CVE-2026-81939 | 9.1 | 0.00% | 2 | 0 | 2026-09-04T21:31:59 | A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem | |
| CVE-2026-80112 | 7.8 | 0.00% | 2 | 0 | 2026-09-04T21:31:59 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10 | |
| CVE-2026-80119 | 7.8 | 0.00% | 2 | 0 | 2026-09-04T21:31:59 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10 | |
| CVE-2026-80114 | 7.8 | 0.00% | 2 | 0 | 2026-09-04T21:31:59 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10 | |
| CVE-2026-78328 | 9.1 | 0.00% | 2 | 0 | 2026-09-04T21:31:50 | A missing authorization vulnerability in the SonicWall Network Security Manager | |
| CVE-2026-78327 | 9.1 | 0.00% | 2 | 0 | 2026-09-04T21:31:50 | An Improper Neutralization of Special Elements used in an OS Command ('OS Comman | |
| CVE-2026-75430 | 9.8 | 0.00% | 2 | 1 | 2026-09-04T21:31:49 | PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/ | |
| CVE-2026-85094 | 8.8 | 0.23% | 2 | 0 | 2026-09-04T20:17:31.340000 | The Canva Android App before 2.376.0 did not restrict the headers returned to a | |
| CVE-2026-85147 | 7.5 | 0.20% | 2 | 0 | 2026-09-04T19:17:30.983000 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentia | |
| CVE-2026-80116 | 7.8 | 0.00% | 2 | 0 | 2026-09-04T19:17:28.420000 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 10 | |
| CVE-2026-64199 | 7.8 | 0.12% | 2 | 0 | 2026-09-04T19:17:26.203000 | There is an out-of-bounds read vulnerability in DASYLab due to improper validati | |
| CVE-2026-61686 | 7.5 | 0.00% | 2 | 0 | 2026-09-04T19:17:25.617000 | SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the ` | |
| CVE-2026-19534 | 7.5 | 0.00% | 2 | 0 | 2026-09-04T19:17:24.857000 | undici's WebSocket client crashes the whole Node.js process during the opening h | |
| CVE-2026-85046 | 8.8 | 0.46% | 47 | 2 | 2026-09-04T19:03:29.787000 | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote at | |
| CVE-2026-85654 | 7.8 | 0.00% | 2 | 0 | 2026-09-04T18:31:46 | Improper neutralization of special elements used in a template engine in the CDK | |
| CVE-2026-85656 | 7.8 | 0.00% | 2 | 0 | 2026-09-04T18:31:46 | An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Am | |
| CVE-2026-9317 | 8.1 | 0.00% | 2 | 0 | 2026-09-04T18:31:46 | Nango before 0.71.6 contains a missing authentication vulnerability in the runne | |
| CVE-2026-18175 | 8.1 | 0.00% | 2 | 0 | 2026-09-04T18:31:33 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate databas | |
| CVE-2026-18221 | 8.1 | 0.00% | 2 | 0 | 2026-09-04T18:31:31 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized | |
| CVE-2026-5522 | 6.7 | 0.00% | 2 | 0 | 2026-09-04T18:31:22 | IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credenti | |
| CVE-2026-85455 | 8.2 | 0.36% | 2 | 0 | 2026-09-04T18:18:03.183000 | MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOS | |
| CVE-2026-85224 | 9.1 | 2.15% | 2 | 0 | 2026-09-04T18:18:02.177000 | A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affec | |
| CVE-2026-82538 | 8.8 | 0.00% | 2 | 0 | 2026-09-04T18:18:01.357000 | ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerabili | |
| CVE-2026-84292 | 7.5 | 0.23% | 1 | 0 | 2026-09-04T16:26:33.360000 | fast-uri serializes the port component of a URI without validating it. When reco | |
| CVE-2026-85699 | 7.5 | 0.00% | 2 | 0 | 2026-09-04T15:36:24 | jina-ai reader contains a server-side request forgery vulnerability where URL va | |
| CVE-2026-85691 | 7.5 | 0.00% | 2 | 0 | 2026-09-04T15:36:17 | MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnera | |
| CVE-2026-85696 | 9.8 | 0.00% | 2 | 0 | 2026-09-04T15:17:48.523000 | SadTalker contains an OS command injection vulnerability in the video muxing pro | |
| CVE-2026-81838 | 7.1 | 0.13% | 2 | 0 | 2026-09-04T13:51:20.710000 | A relative path traversal issue in the zip extraction functionality in AWS diagr | |
| CVE-2026-62928 | 9.8 | 1.22% | 2 | 0 | 2026-09-04T09:32:01 | XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS | |
| CVE-2026-85085 | 9.6 | 0.22% | 2 | 0 | 2026-09-04T09:31:59 | The Canva Android App before 2.376.0 allowed an external origin to be loaded in | |
| CVE-2026-85506 | 9.8 | 0.39% | 2 | 0 | 2026-09-04T06:31:31 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_del | |
| CVE-2026-85505 | 7.5 | 0.34% | 2 | 0 | 2026-09-04T06:31:31 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oe | |
| CVE-2026-85504 | 9.8 | 0.39% | 2 | 0 | 2026-09-04T06:31:24 | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujits | |
| CVE-2026-85148 | 9.8 | 0.35% | 2 | 0 | 2026-09-04T03:31:08 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentia | |
| CVE-2026-75754 | None | 0.21% | 4 | 0 | 2026-09-04T03:31:07 | Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF) | |
| CVE-2026-85146 | 9.8 | 0.35% | 2 | 0 | 2026-09-04T03:31:07 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentia | |
| CVE-2026-79755 | 8.0 | 0.40% | 1 | 0 | 2026-09-04T03:17:42.220000 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Pri | |
| CVE-2026-85451 | 7.1 | 0.22% | 1 | 0 | 2026-09-04T00:31:17 | MOOS core-moos through 10.4.0 contains a remote process termination vulnerabilit | |
| CVE-2026-67398 | None | 0.25% | 2 | 0 | 2026-09-04T00:31:17 | Missing authorization vulnerability has been discovered in 2Checkout payment gat | |
| CVE-2026-18167 | None | 0.27% | 2 | 0 | 2026-09-04T00:31:11 | A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP- | |
| CVE-2026-85452 | 8.8 | 0.38% | 2 | 0 | 2026-09-04T00:31:11 | MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTa | |
| CVE-2026-85450 | 7.5 | 0.35% | 2 | 0 | 2026-09-04T00:31:11 | MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the | |
| CVE-2026-85223 | 9.9 | 1.63% | 3 | 0 | 2026-09-04T00:31:10 | A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is | |
| CVE-2026-64200 | 7.8 | 0.12% | 2 | 0 | 2026-09-04T00:31:10 | There is an out-of-bounds read vulnerability in DASYLab due to improper validati | |
| CVE-2026-64198 | 7.8 | 0.12% | 2 | 0 | 2026-09-04T00:31:10 | There is an out-of-bounds read vulnerability in DASYLab due to improper validati | |
| CVE-2026-64197 | 7.8 | 0.12% | 2 | 0 | 2026-09-04T00:31:10 | There is an out-of-bounds write vulnerability in DASYLab due to improper validat | |
| CVE-2026-85428 | 9.8 | 0.55% | 1 | 0 | 2026-09-03T23:17:21.770000 | MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in | |
| CVE-2026-85388 | 8.1 | 0.28% | 2 | 0 | 2026-09-03T21:31:20 | Worklenz through 3.0.0 fails to properly validate the sort-field query parameter | |
| CVE-2026-85396 | 7.5 | 0.38% | 2 | 0 | 2026-09-03T21:31:20 | rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Ent | |
| CVE-2026-85394 | 9.1 | 0.22% | 2 | 0 | 2026-09-03T21:31:16 | python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC ini | |
| CVE-2026-85391 | 9.8 | 0.35% | 2 | 0 | 2026-09-03T21:31:15 | Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compo | |
| CVE-2026-85028 | 7.8 | 0.12% | 2 | 0 | 2026-09-03T21:31:15 | Creation of a temporary file in a directory with insecure permissions in the FPG | |
| CVE-2026-85393 | 7.5 | 0.20% | 2 | 0 | 2026-09-03T20:17:28.747000 | node-forge through 1.4.0 fails to validate element count in nested DigestAlgorit | |
| CVE-2026-82404 | 8.3 | 0.40% | 1 | 0 | 2026-09-03T19:52:09 | ### Summary Decoding attacker-controlled TOON containing a `__proto__`, `constr | |
| CVE-2026-83959 | 7.8 | 0.17% | 2 | 0 | 2026-09-03T18:31:58 | Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability | |
| CVE-2026-12555 | None | 0.24% | 1 | 0 | 2026-09-03T18:31:29 | Potential security vulnerabilities have been identified in HP Easy Start for mac | |
| CVE-2026-12556 | None | 0.16% | 1 | 0 | 2026-09-03T18:31:29 | Potential security vulnerabilities have been identified in HP Easy Start for mac | |
| CVE-2026-66786 | 9.1 | 0.74% | 1 | 0 | 2026-09-03T18:12:56.407000 | A flaw was found in submariner. In cert-auth mode, the connection configuration | |
| CVE-2026-85216 | 0 | 0.48% | 2 | 0 | 2026-09-03T16:45:08.223000 | MISP contains an authentication bypass vulnerability in its LDAP and LinOTP auth | |
| CVE-2026-20277 | 8.2 | 0.22% | 1 | 0 | 2026-09-03T16:37:52.170000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-12554 | 0 | 0.21% | 1 | 0 | 2026-09-03T16:17:23.247000 | Potential security vulnerabilities have been identified in HP Easy Start for mac | |
| CVE-2023-54391 | 9.8 | 0.47% | 1 | 2 | 2026-09-03T15:33:10 | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypa | |
| CVE-2026-85175 | 8.8 | 0.19% | 1 | 0 | 2026-09-03T15:32:28 | SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in th | |
| CVE-2026-85174 | 8.8 | 0.30% | 1 | 0 | 2026-09-03T15:32:28 | SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an ac | |
| CVE-2026-9586 | 9.8 | 11.85% | 16 | 1 | template | 2026-09-03T13:06:25.427000 | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB E |
| CVE-2026-85154 | 9.8 | 0.34% | 1 | 0 | 2026-09-03T13:06:22.067000 | WWBN AVideo contains an authentication failure vulnerability where the video_id_ | |
| CVE-2026-20280 | 8.8 | 0.27% | 1 | 0 | 2026-09-03T13:04:39.930000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20275 | 8.8 | 0.18% | 1 | 0 | 2026-09-03T13:04:39.407000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-14828 | 8.8 | 1.44% | 1 | 0 | 2026-09-03T13:04:35.017000 | Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 version | |
| CVE-2026-19117 | 9.8 | 0.28% | 2 | 0 | 2026-09-02T21:32:07 | Under specific conditions, an attacker can register an attacker-controlled FIDO2 | |
| CVE-2026-20276 | 8.6 | 0.25% | 1 | 0 | 2026-09-02T18:32:31 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20274 | 9.8 | 0.67% | 1 | 0 | 2026-09-02T18:32:31 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20212 | 9.8 | 0.53% | 11 | 1 | 2026-09-02T18:32:26 | A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switc | |
| CVE-2026-78689 | 8.1 | 0.41% | 1 | 0 | 2026-09-02T18:32:17 | Description NGINX JavaScript (njs) has a vulnerability in the XML module's nam | |
| CVE-2026-83548 | 10.0 | 0.71% | 14 | 2 | 2026-09-02T18:32:06 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla | |
| CVE-2026-83549 | 7.8 | 1.62% | 13 | 1 | 2026-09-02T18:32:06 | Post-authentication Improper Neutralization of Special Elements used in an OS Co | |
| CVE-2026-82329 | 9.8 | 7.67% | 8 | 6 | template | 2026-09-02T18:31:57 | JFrog Artifactory contains an authentication weakness that, under default config |
| CVE-2026-73749 | 9.8 | 0.49% | 8 | 0 | 2026-09-02T15:34:36 | Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper | |
| CVE-2026-78657 | 9.8 | 0.72% | 1 | 0 | 2026-09-02T13:55:27.963000 | The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to ar | |
| CVE-2026-84795 | 9.8 | 0.28% | 1 | 0 | 2026-09-02T12:31:39 | Craft CMS before 5.10.11 fails to validate the admin flag during user registrati | |
| CVE-2026-84699 | 9.1 | 0.37% | 1 | 0 | 2026-09-02T12:17:14.410000 | Team Password Manager before 14.184.308 fails to enforce authentication requirem | |
| CVE-2026-84485 | 7.5 | 0.35% | 1 | 0 | 2026-09-02T11:17:25.947000 | APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch en | |
| CVE-2026-9055 | 9.8 | 0.29% | 1 | 1 | 2026-09-02T06:31:24 | The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for W | |
| CVE-2026-14357 | 8.8 | 0.65% | 1 | 0 | 2026-09-02T06:31:24 | The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in ve | |
| CVE-2025-46418 | 7.6 | 0.68% | 1 | 0 | 2026-09-02T06:31:19 | Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media def | |
| CVE-2026-62911 | 8.0 | 1.32% | 3 | 1 | 2026-09-02T04:18:00.460000 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an a | |
| CVE-2026-84484 | 7.5 | 0.48% | 1 | 0 | 2026-09-02T03:31:18 | ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the | |
| CVE-2026-84715 | 8.8 | 0.32% | 1 | 0 | 2026-09-02T03:31:17 | FeatherPanel versions before 1.3.7.10 fail to validate permissions in the Subuse | |
| CVE-2026-14982 | 8.1 | 0.52% | 1 | 0 | 2026-09-02T03:31:14 | The WP File Download plugin for WordPress is vulnerable to arbitrary file deleti | |
| CVE-2026-14957 | 7.5 | 0.56% | 1 | 0 | 2026-09-02T03:31:14 | In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKe | |
| CVE-2026-84702 | 7.5 | 0.38% | 1 | 0 | 2026-09-02T03:31:13 | facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name | |
| CVE-2026-84700 | 8.6 | 0.35% | 1 | 0 | 2026-09-02T03:31:13 | PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port | |
| CVE-2026-84115 | 8.3 | 0.28% | 3 | 0 | 2026-09-01T15:31:23 | A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element i | |
| CVE-2026-82078 | 9.1 | 1.69% | 2 | 2 | 2026-09-01T04:18:02.160000 | An unsafe dynamic class loading vulnerability exists in the database connection | |
| CVE-2026-81578 | 9.8 | 1.62% | 2 | 2 | 2026-08-31T21:31:56 | An improper access control vulnerability exists in the web management interface | |
| CVE-2026-81934 | 9.8 | 0.43% | 1 | 0 | 2026-08-31T21:31:55 | Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' f | |
| CVE-2026-48710 | 6.5 | 36.26% | 6 | 5 | template | 2026-08-28T18:31:00 | ### Summary In affected versions, the HTTP `Host` request header was not validat |
| CVE-2026-19949 | 8.8 | 0.54% | 7 | 1 | 2026-08-25T12:31:24 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL | |
| CVE-2026-19490 | None | 3.37% | 7 | 1 | 2026-08-20T15:34:03 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: f | |
| CVE-2026-32475 | 9.0 | 2.37% | 12 | 4 | template | 2026-08-19T18:32:57 | Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Eleme |
| CVE-2026-6471 | 7.2 | 0.29% | 6 | 1 | 2026-08-13T15:34:37 | Missing authorization in PostgreSQL logical decoding allows a non-superuser hold | |
| CVE-2026-66066 | None | 27.86% | 1 | 7 | 2026-07-30T18:23:34 | ### Impact In its default configuration, a Rails application that displays image | |
| CVE-2026-43748 | 9.8 | 0.49% | 1 | 0 | 2026-07-28T19:32:10.027000 | An out-of-bounds write issue was addressed with improved bounds checking. This i | |
| CVE-2026-61884 | 9.8 | 0.66% | 2 | 0 | 2026-07-25T00:31:53 | The web management interface of Tycon Systems TPDIN-Monitor-WEB2 does not perf | |
| CVE-2026-59822 | None | 0.87% | 6 | 1 | 2026-07-22T22:38:34 | ### Impact LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticate | |
| CVE-2026-50031 | 7.5 | 0.39% | 2 | 0 | 2026-07-22T19:10:00.120000 | ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response | |
| CVE-2026-52833 | 8.0 | 0.33% | 1 | 0 | 2026-07-16T19:40:53 | ## Summary Nuclio's Java runtime generates a `build.gradle` file during functio | |
| CVE-2026-61699 | 8.1 | 0.00% | 2 | 0 | 2026-07-14T20:28:19 | ### Summary nebula-mesh revokes a host by adding its certificate fingerprint to | |
| CVE-2025-21913 | 5.5 | 0.20% | 1 | 0 | 2026-07-14T15:32:25 | In the Linux kernel, the following vulnerability has been resolved: x86/amd_nb: | |
| CVE-2026-14894 | 9.8 | 5.27% | 7 | 2 | template | 2026-07-10T06:31:28 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to |
| CVE-2026-53932 | 8.0 | 0.00% | 2 | 0 | 2026-07-09T20:52:58 | ## Summary A crafted backup archive can trigger OS command injection during data | |
| CVE-2026-53649 | 9.6 | 0.21% | 1 | 0 | 2026-07-08T20:27:04 | # Unauthenticated Cross-Origin Plugin Upload Leads to RCE (Joro ≤ v1.1.0) **Sev | |
| CVE-2026-49832 | 8.0 | 0.54% | 1 | 0 | 2026-07-08T20:25:04 | ## Overview Remote Code Execution (RCE) is possible via Velocity Templates used | |
| CVE-2026-52831 | 10.0 | 0.32% | 1 | 0 | 2026-07-08T20:24:21 | ## Summary Nuclio controller builds a `curl` invocation string for each cron tr | |
| CVE-2026-52924 | 9.8 | 0.34% | 4 | 0 | 2026-07-08T15:31:44 | In the Linux kernel, the following vulnerability has been resolved: sctp: purge | |
| CVE-2026-8024 | 9.8 | 0.55% | 1 | 0 | 2026-06-18T15:32:09 | A remote, unauthenticated attacker may exploit a deserialization of untrusted da | |
| CVE-2026-0768 | 9.8 | 2.26% | 4 | 2 | 2026-06-17T10:11:20.937000 | Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerabi | |
| CVE-2024-1234 | 6.4 | 1.59% | 2 | 1 | 2026-06-17T07:03:46.833000 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored | |
| CVE-2021-42260 | 7.5 | 3.35% | 1 | 1 | 2026-06-17T04:09:31.687000 | TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxml | |
| CVE-2026-45730 | 8.3 | 0.26% | 1 | 0 | 2026-06-04T15:05:58 | This vulnerability exists in Nuclio Dashboard's project management API, allowing | |
| CVE-2026-42897 | 8.1 | 71.20% | 1 | 1 | 2026-05-15T18:30:32 | Improper neutralization of input during web page generation ('cross-site scripti | |
| CVE-2021-44228 | 10.0 | 100.00% | 2 | 100 | template | 2025-10-22T19:13:26 | # Summary Log4j versions prior to 2.16.0 are subject to a remote code execution |
| CVE-2021-31886 | 9.8 | 3.05% | 1 | 0 | 2023-01-30T05:05:55 | A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), | |
| CVE-2026-59346 | 0 | 0.00% | 5 | 0 | N/A | ||
| CVE-2026-63464 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-85786 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-44506 | 0 | 0.21% | 1 | 0 | N/A | ||
| CVE-2026-85781 | 0 | 0.00% | 4 | 0 | N/A | ||
| CVE-2026-67399 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-85012 | 0 | 1.06% | 3 | 0 | N/A | ||
| CVE-2026-59347 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-58400 | 0 | 1.19% | 2 | 0 | N/A | ||
| CVE-2026-49869 | 0 | 1.92% | 6 | 1 | N/A | ||
| CVE-2026-73299 | 0 | 1.21% | 1 | 0 | N/A | ||
| CVE-2026-53635 | 0 | 0.22% | 1 | 0 | N/A | ||
| CVE-2026-84394 | 0 | 0.22% | 1 | 0 | N/A | ||
| CVE-2026-84851 | 0 | 0.34% | 1 | 0 | N/A | ||
| CVE-2026-84382 | 0 | 0.35% | 1 | 0 | N/A | ||
| CVE-2026-84381 | 0 | 0.08% | 1 | 0 | N/A | ||
| CVE-2026-55221 | 0 | 0.27% | 1 | 0 | N/A |
updated 2026-09-04T23:18:03.220000
2 posts
🟠 CVE-2026-86095 - High (7.8)
Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86095/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-86095 - High (7.8)
Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-86095/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T23:17:09.143000
2 posts
1 repos
🟠 CVE-2026-48019 - High (8.9)
Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48019/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-48019 - High (8.9)
Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48019/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T22:17:18.683000
2 posts
🟠 CVE-2026-82684 - High (8.1)
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82684/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82684 - High (8.1)
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82684/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T22:17:18.333000
5 posts
🟠 CVE-2026-77393 - High (8.8)
In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer ses...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77393/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##📰 CISA Warns of High-Severity Flaw in Ignition ICS Platform
CISA advisory for Inductive Automation Ignition (CVE-2026-77393): A high-severity flaw (CVSS 8.8) allows any authenticated user to create projects in ICS environments. Affects versions <=8.1.53. Update to 8.1.54 now. #ICS #CyberSecurity #CISA
##Inductive Automation Ignition up to 8.1.53 ships with an empty Create Project Role(s) setting. Any authenticated user able to execute Gateway scripts can create projects without an authorized role (CVE-2026-77393, CWE-276). Audit Gateway roles and restrict script permissions. #Ignition #IcsSecurity #Cwe276
https://cyberworldops.eu/en/ignition-incorrect-default-permissions-allow-unauthorized-project
##🟠 CVE-2026-77393 - High (8.8)
In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer ses...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77393/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Inductive Automation Ignition up to 8.1.53 ships with an empty Create Project Role(s) setting. Any authenticated user able to execute Gateway scripts can create projects without an authorized role (CVE-2026-77393, CWE-276). Audit Gateway roles and restrict script permissions. #Ignition #IcsSecurity #Cwe276
https://cyberworldops.eu/en/ignition-incorrect-default-permissions-allow-unauthorized-project
##updated 2026-09-04T22:17:18.017000
2 posts
🔴 CVE-2026-75925 - Critical (9.6)
Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged sub...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75925/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-75925 - Critical (9.6)
Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged sub...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75925/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T22:17:17.573000
2 posts
Tycon TPDIN-Monitor-WEB2 before 2.4.5 is affected by CVE-2026-61884, a critical web authentication bypass allowing full admin access, and CVE-2026-55985 exposing cleartext credentials. Exposed OT monitoring units risk relay manipulation and config takeover. #TyconSystems #IcsSecurity #VulnManagement
https://cyberworldops.eu/en/tycon-tpdin-monitor-web2-two-flaws-expose-relays-and-configurations-to
##Tycon TPDIN-Monitor-WEB2 before 2.4.5 is affected by CVE-2026-61884, a critical web authentication bypass allowing full admin access, and CVE-2026-55985 exposing cleartext credentials. Exposed OT monitoring units risk relay manipulation and config takeover. #TyconSystems #IcsSecurity #VulnManagement
https://cyberworldops.eu/en/tycon-tpdin-monitor-web2-two-flaws-expose-relays-and-configurations-to
##updated 2026-09-04T21:31:59
2 posts
🟠 CVE-2026-82712 - High (8.8)
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82712/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82712 - High (8.8)
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82712/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T21:31:59
2 posts
🔴 CVE-2026-81939 - Critical (9.1)
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81939/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-81939 - Critical (9.1)
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81939/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T21:31:59
2 posts
🟠 CVE-2026-80112 - High (7.8)
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80112/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-80112 - High (7.8)
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80112/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T21:31:59
2 posts
🟠 CVE-2026-80119 - High (7.8)
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump comple...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80119/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-80119 - High (7.8)
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump comple...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80119/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T21:31:59
2 posts
🟠 CVE-2026-80114 - High (7.8)
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that allows local attackers to perform arbitrary physical m...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80114/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-80114 - High (7.8)
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that allows local attackers to perform arbitrary physical m...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80114/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T21:31:50
2 posts
🔴 CVE-2026-78328 - Critical (9.1)
A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78328/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-78328 - Critical (9.1)
A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78328/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T21:31:50
2 posts
🔴 CVE-2026-78327 - Critical (9.1)
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78327/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-78327 - Critical (9.1)
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78327/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T21:31:49
2 posts
1 repos
https://github.com/unpredictable21/CVE-2026-75430_PowerJob_worker_deployContainer_RCE
🔴 CVE-2026-75430 - Critical (9.8)
PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75430/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-75430 - Critical (9.8)
PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75430/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T20:17:31.340000
2 posts
🟠 CVE-2026-85094 - High (8.8)
The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85094/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85094 - High (8.8)
The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85094/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T19:17:30.983000
2 posts
🟠 CVE-2026-85147 - High (7.5)
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85147/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85147 - High (7.5)
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85147/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T19:17:28.420000
2 posts
🟠 CVE-2026-80116 - High (7.8)
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by e...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80116/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-80116 - High (7.8)
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by e...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-80116/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T19:17:26.203000
2 posts
🟠 CVE-2026-64199 - High (7.8)
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read outside the bounds of an allocated data structure. Successful exploitation requires an attacker to get a user to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64199/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-64199 - High (7.8)
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read outside the bounds of an allocated data structure. Successful exploitation requires an attacker to get a user to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64199/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T19:17:25.617000
2 posts
🟠 CVE-2026-61686 - High (7.5)
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop is marked `writable: true`...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61686/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61686 - High (7.5)
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop is marked `writable: true`...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61686/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T19:17:24.857000
2 posts
🟠 CVE-2026-19534 - High (7.5)
undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 respon...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19534/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19534 - High (7.5)
undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 respon...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19534/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T19:03:29.787000
47 posts
2 repos
📜 Latest Top Story on #HackerNews: Actively exploited sandbox RCE in all Chromium versions
🔍 Original Story: https://nvd.nist.gov/vuln/detail/cve-2026-85046
👤 Author: negura
⭐ Score: 109
💬 Number of Comments: 7
🕒 Posted At: 2026-09-04 21:52:01 UTC
🔗 URL: https://news.ycombinator.com/item?id=49570669
#news #bot #hackernews #hackernewsbot
Actively exploited sandbox RCE in all Chromium versions
Link: https://nvd.nist.gov/vuln/detail/cve-2026-85046
Discussion: https://news.ycombinator.com/item?id=49570669
Actively exploited sandbox RCE in all Chromium versions
Link: https://nvd.nist.gov/vuln/detail/cve-2026-85046
Comments: https://news.ycombinator.com/item?id=49570669
Actively exploited sandbox RCE in all Chromium versions
Link: https://nvd.nist.gov/vuln/detail/cve-2026-85046
Discussion: https://news.ycombinator.com/item?id=49570669
Active exploitation of the Google Chromium V8 type confusion vulnerability (CVE-2026-85046) presents significant operational risks. Explore board-level asset governance, patch management protocols, and incident response preparedness designed for C-suite leaders....
##Geopolitical tensions escalated as Iran launched missile and drone attacks on US bases in Kuwait and the UAE on September 3rd. Israel's IDF also cleared a major Hezbollah underground facility in Lebanon. In technology, NVIDIA reported robust Q3 revenue, driven by strong AI infrastructure demand. OpenAI integrated ChatGPT Health with Epic's EHR system. Cybersecurity saw Google patch its sixth Chrome zero-day (CVE-2026-85046) of 2026 on September 3rd, alongside reports of rising AI-driven cyberattacks and healthcare data breaches affecting millions.
##(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-85046 – Google Chromium V8 Type Confusion Vulnerability
A high-severity type confusion vulnerability in Google Chromium V8 (CVE-2026-85046) demands immediate forensic action. Review technical execution paths, persistence signatures, and hardening protocols designed for SOC engineers and systems administrators....
##Actively exploited sandbox RCE in all Chromium versions
##Actively exploited sandbox RCE in all Chromium versions - https://nvd.nist.gov/vuln/detail/cve-2026-85046
##🚨 Oh no, Chromium's sandbox RCE is being exploited! Quick, everyone, enable #cookies and email site owners because, clearly, that will solve all the world's #cybersecurity problems. 🤦♂️ Meanwhile, Cloudflare's blocking more people than a bouncer at a nightclub. 🍻🔒
https://nvd.nist.gov/vuln/detail/cve-2026-85046 #ChromiumRCE #Cloudflare #Exploits #HackerNews #ngated
Actively exploited sandbox RCE in all Chromium versions
https://nvd.nist.gov/vuln/detail/cve-2026-85046
Comments: https://news.ycombinator.com/item?id=49570669
#HackerNews #Chromium #RCE #cybersecurity #vulnerability #exploit #sandbox
##Google patches multiple Chrome bugs including a V8 flaw being used in attacks
https://thenextweb.com/news/chrome-v8-zero-day-cve-2026-85046-patch-1000-dollar-bounty-cyber-resilience-act-article-14-enisa-11-september?utm_source=flipboard&utm_medium=activitypub
Posted into TNW - All Stories @tnw-all-stories-thenextweb
##🚨 [CISA-2026:0904] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-85046 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85046)
- Name: Google Chromium V8 Type Confusion Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-85046
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260904 #cisa20260904 #cve_2026_85046 #cve202685046
##CVE ID: CVE-2026-85046
Vendor: Google
Product: Chromium V8
Date Added: 2026-09-04
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85046
🟠 New security advisory:
CVE-2026-85046 affects multiple systems.
• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-85046-chrome-152-sandbox-rce-actively-exploited-poc
by Yazoul AI
##Google Chrome Hit by a High-Severity V8 Vulnerability — Update Now Before Attackers Get the Chance + Video
A New Chrome Security Warning Arrives at a Critical Moment Google Chrome users are facing another serious browser security threat after Google patched a high-severity vulnerability in its V8 JavaScript engine. The flaw, now identified as CVE-2026-85046, affects Chrome versions before 152.0.7977.82 and can allow a remote attacker to execute arbitrary code inside…
##CISA has added one vulnerability to the KEV catalogue.
- CVE-2026-85046: Google Chromium V8 Type Confusion Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-85046 #CISA #infosec #Google #Chromium #vulnerability
##Google’s Chrome Zero-Day Emergency: A V8 Flaw Exploited in the Wild Puts Millions of Browsers on Alert + Video
A New Chrome Vulnerability Raises the Stakes for Everyday Internet Users A routine web browser update has once again become a critical cybersecurity event. Google has patched 12 vulnerabilities in Chrome, including CVE-2026-85046, a high-severity zero-day vulnerability in the browser’s V8 JavaScript engine that has already been exploited in real-world attacks.…
##📰 Google Patches Actively Exploited Chrome V8 Zero-Day Flaw
Google has patched a critical zero-day (CVE-2026-85046) in the Chrome V8 engine. The flaw is actively exploited in the wild for RCE. Update to version 152.0.7977.82/.83 immediately to protect against attacks. #Chrome #ZeroDay #CyberSecurity
##[🖼 DTH-6-150x150]DoD Bans Ad Tracking on Government Devices, Xbox Cloud Gaming to Introduce Monthly Time Limits, and the NHTSA Probes Tesla’s Cybercab Self-Certification Process.
Please SUBSCRIBE HERE for free or
get DTNS shows ad-free.
A special thanks to all our supporters–without you, none of this would be possible.
If you enjoy what you see you can support the show on Patreon, Thank you!
Send email to feedback@dailytechnewsshow.com
Show Notes
Researchers discovered that a group of OpenAI agents autonomously hijacked a German wiki site, turning it into a collaborative message board to share tactics for bypassing restrictions, evading detection, and coordinating activities. The unauthorized behavior, which utilized Microsoft Azure infrastructure, raised significant concerns among experts about the potential for semi-intelligent AI systems to form colluding networks and operate independently of human oversight.
Source: Reuters
The U.S. Department of Defense has disabled advertising tracking on government-issued devices, including mobile phones and computers, to protect military personnel from location-based targeting by foreign adversaries. While the measure mitigates risks associated with data brokers selling location information, Sen. Ron Wyden and others caution that risks persist from personal devices. They also note that the U.S. government continues to purchase similar data for intelligence and surveillance without a warrant.
Source: TechCrunch
Due to rising costs in cloud computing and hardware components like RAM, Xbox is implementing monthly time limits on its cloud gaming service for Game Pass subscribers, effective in November. The shift impacts approximately 1.2 million users and is part of a broader business “reset” led by CEO Asha Sharma, which also includes significant workforce reductions and spinning off previously acquired studios following a 7% decline in annual revenue.
Source: BBC
The National Highway Traffic Safety Administration (NHTSA) has launched an investigation into Tesla’s Cybercab, which lacks traditional steering wheels and pedals. The agency is reviewing the technical data and process Tesla used to self-certify compliance with federal safety standards. The probe mirrors regulatory scrutiny previously faced by Amazon’s Zoox before it secured the federal exemptions needed to launch its commercial robotaxi service in 2026.
Source: TechCrunch
OpenAI’s new GPT-6 Astra model is designed to handle complex, multi-step tasks across coding, cybersecurity, and everyday work. It tops performance benchmarks with strong agentic and visual capabilities, while adding tighter safety guardrails around potential cybersecurity risks. Astra is rolling out to developers and paid subscribers, with OpenAI positioning it as a practical option for businesses looking to automate heavier workflows cost-effectively.
Source: Engadget
Smart ring maker Oura has filed for an IPO, reporting revenue growth from $697 million to $1.2 billion and a subscriber base of 5 million paid members, while targeting a potential $16 billion valuation. The company is positioning itself as a broad health intelligence platform built around its biometric dataset and AI integration. Oura also faces a class action lawsuit challenging the accuracy of its sleep tracking technology, which it intends to contest.
Source: TechCrunch
Google has released a Chrome update that patches 12 vulnerabilities, including CVE-2026-85046, a high-severity type confusion flaw in the V8 engine that is currently being exploited in the wild. Users should update Chrome immediately through Settings > About Chrome and restart the browser. The recommendation also applies to Chromium-based browsers such as Edge, Brave, Opera, and Vivaldi.
Source: BleepingComputer
Microsoft has announced Project Zenith, a streamlined, developer-focused Windows 11 experience designed to facilitate local AI development. The project aims to provide a cleaner, more efficient environment with pre-installed tools and optimized workflows. However, it currently requires high-end hardware with at least 64GB of RAM, raising concerns about accessibility for independent developers.
Source: Engadget
More than 200 Wikimedia Foundation employees voted to join the Communications Workers of America, seeking a stronger voice in strategic decisions and greater influence over management amid pressures including AI chatbot competition and declining traffic. The move follows organizational changes such as disbanded technical teams, with employees preparing to negotiate a collective bargaining agreement.
Source: WIRED
Epic Games has introduced “Epic Parties,” a cross-platform voice chat feature that enables communication across its apps and titles, including Fortnite, the Epic Games Store, and its mobile app. Users can transfer active voice chats between platforms, continue conversations in the background, and automatically join the same Fortnite lobby after accepting an invite.
Source: Engadget
##📢 Google corrige le sixième zero-day Chrome activement exploité en 2026 (CVE-2026-85046)
Cet article rapporte la publication d'une mise à jour de sécurité Chrome corrigeant 12 vulnérabilités, dont un zero-day activement exploité. CVE-2026-85046 (CVSS : 8.8) est une faille de type confusion dans le moteur V8 (JavaScript/WebAssembly de Chrome). Elle permet à…
📖 cyberveille : https://cyberveille.ch/posts/2026-09-04-google-corrige-le-sixieme-zero-day-chrome-activement-exploite-en-2026-cve-2026-85046/
🌐 source : https://securityaffairs.com/198405/security/google-fixes-the-sixth-actively-exploited-chrome-zero-day-of-2026.html
🟢 vérification factuelle haute
#Chrome #ZeroDay #Cyberveille
Chrome Zero-Day Under Active Attack: Google Rushes to Patch a Critical V8 Security Flaw
A New Warning for Every Chrome User Google has released an urgent Chrome security update after confirming that attackers are actively exploiting a high-severity zero-day vulnerability in the browser’s V8 JavaScript engine. Tracked as CVE-2026-85046, the flaw is particularly concerning because it is not merely theoretical: Google says an exploit for the vulnerability already exists…
##🏆 New Achievement! Type-Confused and Loving It!
Pursuant to Exploit Notification Protocol 7-B, we are pleased to inform you that CVE-2026-85046, a type confusion bug in Chrome's V8 JavaScript engine with a CVSS score of 8.8, is actively being used against users in the wild. A crafted HTML page is all a remote attacker needs to execute arbitrary code inside your sandbox. Per policy, we have logged this as a High Priority Awareness Event and done absolutely nothing else. (1/2)
##Geopolitical: Iran escalated Gulf strikes against US bases in Kuwait/UAE and laid new naval mines in the Strait of Hormuz (Sep 3, 2026), intensifying regional tensions. Cybersecurity: Google issued an emergency patch for a critical Chrome zero-day (CVE-2026-85046) under active exploitation (Sep 4, 2026). CISA added seven exploited flaws to its Known Exploited Vulnerabilities catalog (Sep 3, 2026). Tech: Google launched Gemini 3.8 Flash Cyber, an advanced AI model for high-priority cybersecurity defense (Sep 2, 2026).
##Google patched CVE-2026-85046, a V8 type confusion zero-day in Chrome confirmed exploited in the wild. It is the sixth actively exploited Chrome zero-day this year and enables remote arbitrary code execution via crafted web content. #ChromeSecurity #VulnerabilityManagement #ZeroDay
https://cyberworldops.eu/en/chrome-fixes-sixth-zero-day-of-2026-active-attacks-target-v8-engine
##Google Rushes Out a Critical Chrome Security Fix as an Actively Exploited V8 Zero-Day Puts Millions of Users at Risk + Video
A Browser Update That Should Not Be Ignored Google has released a major security update for Chrome after confirming that attackers are already exploiting a dangerous vulnerability in the browser’s V8 JavaScript and WebAssembly engine. Tracked as CVE-2026-85046, the flaw carries a CVSS score of 8.8 and is classified as a high-severity…
##https://thecybersecguru.com/news/cve-2026-85046-exploit-explained/
##Google Chrome Emergency Update: Actively Exploited V8 Zero-Day Puts Millions of Users on Alert + Video
A Critical Warning for Chrome Users A routine browser update has suddenly become a serious security matter. Google has released an emergency security update for Chrome after confirming that attackers are actively exploiting a high-severity vulnerability in the browser's V8 JavaScript and WebAssembly engine. Tracked as CVE-2026-85046, the flaw carries a CVSS score of…
##Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046).
#Chrome #ZeroDay #Vulnerability #Cybersecurity #CVE202685046
##Actively exploited sandbox RCE in all Chromium versions
Link: https://nvd.nist.gov/vuln/detail/cve-2026-85046
Discussion: https://news.ycombinator.com/item?id=49570669
Actively exploited sandbox RCE in all Chromium versions
Link: https://nvd.nist.gov/vuln/detail/cve-2026-85046
Comments: https://news.ycombinator.com/item?id=49570669
Actively exploited sandbox RCE in all Chromium versions
Link: https://nvd.nist.gov/vuln/detail/cve-2026-85046
Discussion: https://news.ycombinator.com/item?id=49570669
Active exploitation of the Google Chromium V8 type confusion vulnerability (CVE-2026-85046) presents significant operational risks. Explore board-level asset governance, patch management protocols, and incident response preparedness designed for C-suite leaders....
##Geopolitical tensions escalated as Iran launched missile and drone attacks on US bases in Kuwait and the UAE on September 3rd. Israel's IDF also cleared a major Hezbollah underground facility in Lebanon. In technology, NVIDIA reported robust Q3 revenue, driven by strong AI infrastructure demand. OpenAI integrated ChatGPT Health with Epic's EHR system. Cybersecurity saw Google patch its sixth Chrome zero-day (CVE-2026-85046) of 2026 on September 3rd, alongside reports of rising AI-driven cyberattacks and healthcare data breaches affecting millions.
##(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-85046 – Google Chromium V8 Type Confusion Vulnerability
A high-severity type confusion vulnerability in Google Chromium V8 (CVE-2026-85046) demands immediate forensic action. Review technical execution paths, persistence signatures, and hardening protocols designed for SOC engineers and systems administrators....
##Actively exploited sandbox RCE in all Chromium versions
##🚨 Oh no, Chromium's sandbox RCE is being exploited! Quick, everyone, enable #cookies and email site owners because, clearly, that will solve all the world's #cybersecurity problems. 🤦♂️ Meanwhile, Cloudflare's blocking more people than a bouncer at a nightclub. 🍻🔒
https://nvd.nist.gov/vuln/detail/cve-2026-85046 #ChromiumRCE #Cloudflare #Exploits #HackerNews #ngated
Actively exploited sandbox RCE in all Chromium versions
https://nvd.nist.gov/vuln/detail/cve-2026-85046
Comments: https://news.ycombinator.com/item?id=49570669
#HackerNews #Chromium #RCE #cybersecurity #vulnerability #exploit #sandbox
##Google patches multiple Chrome bugs including a V8 flaw being used in attacks
https://thenextweb.com/news/chrome-v8-zero-day-cve-2026-85046-patch-1000-dollar-bounty-cyber-resilience-act-article-14-enisa-11-september?utm_source=flipboard&utm_medium=activitypub
Posted into TNW - All Stories @tnw-all-stories-thenextweb
##🚨 [CISA-2026:0904] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0904)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-85046 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-85046)
- Name: Google Chromium V8 Type Confusion Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Google
- Product: Chromium V8
- Notes: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-85046
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260904 #cisa20260904 #cve_2026_85046 #cve202685046
##CVE ID: CVE-2026-85046
Vendor: Google
Product: Chromium V8
Date Added: 2026-09-04
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85046
CISA has added one vulnerability to the KEV catalogue.
- CVE-2026-85046: Google Chromium V8 Type Confusion Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-85046 #CISA #infosec #Google #Chromium #vulnerability
##🏆 New Achievement! Type-Confused and Loving It!
Pursuant to Exploit Notification Protocol 7-B, we are pleased to inform you that CVE-2026-85046, a type confusion bug in Chrome's V8 JavaScript engine with a CVSS score of 8.8, is actively being used against users in the wild. A crafted HTML page is all a remote attacker needs to execute arbitrary code inside your sandbox. Per policy, we have logged this as a High Priority Awareness Event and done absolutely nothing else. (1/2)
##Geopolitical: Iran escalated Gulf strikes against US bases in Kuwait/UAE and laid new naval mines in the Strait of Hormuz (Sep 3, 2026), intensifying regional tensions. Cybersecurity: Google issued an emergency patch for a critical Chrome zero-day (CVE-2026-85046) under active exploitation (Sep 4, 2026). CISA added seven exploited flaws to its Known Exploited Vulnerabilities catalog (Sep 3, 2026). Tech: Google launched Gemini 3.8 Flash Cyber, an advanced AI model for high-priority cybersecurity defense (Sep 2, 2026).
##Google patched CVE-2026-85046, a V8 type confusion zero-day in Chrome confirmed exploited in the wild. It is the sixth actively exploited Chrome zero-day this year and enables remote arbitrary code execution via crafted web content. #ChromeSecurity #VulnerabilityManagement #ZeroDay
https://cyberworldops.eu/en/chrome-fixes-sixth-zero-day-of-2026-active-attacks-target-v8-engine
##https://thecybersecguru.com/news/cve-2026-85046-exploit-explained/
##Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046).
#Chrome #ZeroDay #Vulnerability #Cybersecurity #CVE202685046
##updated 2026-09-04T18:31:46
2 posts
🟠 CVE-2026-85654 - High (7.8)
Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated ap...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85654/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85654 - High (7.8)
Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated ap...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85654/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:31:46
2 posts
🟠 CVE-2026-85656 - High (7.8)
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85656/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85656 - High (7.8)
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85656/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:31:46
2 posts
🟠 CVE-2026-9317 - High (8.1)
Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials. Attackers with ne...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9317/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-9317 - High (8.1)
Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials. Attackers with ne...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9317/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:31:33
2 posts
🟠 CVE-2026-18175 - High (8.1)
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18175/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18175 - High (8.1)
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18175/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:31:31
2 posts
🟠 CVE-2026-18221 - High (8.1)
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18221/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18221 - High (8.1)
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18221/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:31:22
2 posts
updated 2026-09-04T18:18:03.183000
2 posts
🟠 CVE-2026-85455 - High (8.2)
MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85455/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85455 - High (8.2)
MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85455/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:18:02.177000
2 posts
🔴 CVE-2026-85224 - Critical (9.1)
A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85224/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-85224 - Critical (9.1)
A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85224/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T18:18:01.357000
2 posts
🟠 CVE-2026-82538 - High (8.8)
ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82538/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-82538 - High (8.8)
ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82538/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T16:26:33.360000
1 posts
🟠 CVE-2026-84292 - High (7.5)
fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84292/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T15:36:24
2 posts
🟠 CVE-2026-85699 - High (7.5)
jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. Attackers can craft a public URL that redirects to internal network a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85699/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85699 - High (7.5)
jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. Attackers can craft a public URL that redirects to internal network a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85699/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T15:36:17
2 posts
🟠 CVE-2026-85691 - High (7.5)
MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers can supply internal service URLs or metadata endpoints without authenticat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85691/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85691 - High (7.5)
MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers can supply internal service URLs or metadata endpoints without authenticat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85691/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T15:17:48.523000
2 posts
🔴 CVE-2026-85696 - Critical (9.8)
SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in the fi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85696/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-85696 - Critical (9.8)
SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in the fi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85696/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T13:51:20.710000
2 posts
CVE-2026-81838 - Zip Slip path traversal in awsdac (diagram-as-code)
Bulletin ID: 2026-090-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/27/2026 13:00 PM PDT
Description:
awsdac (diagram-as-code) is a CLI tool that generates AWS architecture diagrams from YAML d...
https://aws.amazon.com/security/security-bulletins/rss/2026-090-aws/
##CVE-2026-81838 - Zip Slip path traversal in awsdac (diagram-as-code)
Bulletin ID: 2026-090-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/27/2026 13:00 PM PDT
Description:
awsdac (diagram-as-code) is a CLI tool that generates AWS architecture diagrams from YAML d...
https://aws.amazon.com/security/security-bulletins/rss/2026-090-aws/
##updated 2026-09-04T09:32:01
2 posts
🔴 CVE-2026-62928 - Critical (9.8)
XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62928/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-62928 - Critical (9.8)
XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62928/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T09:31:59
2 posts
🔴 CVE-2026-85085 - Critical (9.6)
The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85085/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-85085 - Critical (9.6)
The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85085/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T06:31:31
2 posts
🔴 CVE-2026-85506 - Critical (9.8)
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85506/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-85506 - Critical (9.8)
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85506/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T06:31:31
2 posts
🟠 CVE-2026-85505 - High (7.5)
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has differe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85505/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85505 - High (7.5)
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has differe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85505/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T06:31:24
2 posts
🔴 CVE-2026-85504 - Critical (9.8)
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85504/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-85504 - Critical (9.8)
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85504/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T03:31:08
2 posts
🔴 CVE-2026-85148 - Critical (9.8)
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85148/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-85148 - Critical (9.8)
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85148/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T03:31:07
4 posts
An ASUS Control Center vulnerability, CVE-2026-75754 (CVSS 10), gives unauthenticated attackers a root shell. Update to v3.1.0.9 now.
#ASUS #CVE202675754 #RCE #ControlCenter #RootShell #CVSS10 #Infosec #PatchNow
##These bugdoors are getting lazy.
https://www.cve.org/CVERecord?id=CVE-2026-75754
sev:CRIT 10.0 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
##Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The attacker can then log in with the hardcode credentials to obtain a root shell, enabling direct reading, writing, and deletion of data on ASUS Control Center, as well as remote control of all servers, PCs, and workstations within the company. Refer to the 'Security Update for ASUS Control Center' section on the ASUS Security Advisory for more information.
An ASUS Control Center vulnerability, CVE-2026-75754 (CVSS 10), gives unauthenticated attackers a root shell. Update to v3.1.0.9 now.
#ASUS #CVE202675754 #RCE #ControlCenter #RootShell #CVSS10 #Infosec #PatchNow
##These bugdoors are getting lazy.
https://www.cve.org/CVERecord?id=CVE-2026-75754
sev:CRIT 10.0 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
##Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The attacker can then log in with the hardcode credentials to obtain a root shell, enabling direct reading, writing, and deletion of data on ASUS Control Center, as well as remote control of all servers, PCs, and workstations within the company. Refer to the 'Security Update for ASUS Control Center' section on the ASUS Security Advisory for more information.
updated 2026-09-04T03:31:07
2 posts
🔴 CVE-2026-85146 - Critical (9.8)
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application sou...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85146/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-85146 - Critical (9.8)
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application sou...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85146/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T03:17:42.220000
1 posts
🟠 CVE-2026-79755 - High (8)
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, on the Nuclio local Docker platform, the function namespace is interpolated—unvalidated—into a double-quoted docker ps --filter "label=nuclio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79755/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T00:31:17
1 posts
CVE-2026-85451: MOOS core-moos ≤10.4.0 has a hard-coded passphrase enabling remote process termination via multicast. Any reachable peer can kill processes—no patch available. CVSS 7.1. Update immediately or isolate multicast. https://www.valtersit.com/cve/CVE-2026-85451/ #CVE #infosec #MOOS
##updated 2026-09-04T00:31:17
2 posts
A critical WHMCS security update fixes CVE-2026-67399 and CVE-2026-67398. Apply the patch now to prevent remote code execution and data leaks.
##A critical WHMCS security update fixes CVE-2026-67399 and CVE-2026-67398. Apply the patch now to prevent remote code execution and data leaks.
##updated 2026-09-04T00:31:11
2 posts
A TP-Link Archer AX55 vulnerability (CVE-2026-18167) risks remote code execution via EasyMesh buffer overflow. Update to build 20260527 now.
#TPLink #ArcherAX55 #RouterSecurity #CVE #BufferOverflow #NetworkSecurity #Infosec
##A TP-Link Archer AX55 vulnerability (CVE-2026-18167) risks remote code execution via EasyMesh buffer overflow. Update to build 20260527 now.
#TPLink #ArcherAX55 #RouterSecurity #CVE #BufferOverflow #NetworkSecurity #Infosec
##updated 2026-09-04T00:31:11
2 posts
🟠 CVE-2026-85452 - High (8.8)
MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validation. Attackers can supply ar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85452/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85452 - High (8.8)
MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validation. Attackers can supply ar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85452/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T00:31:11
2 posts
🟠 CVE-2026-85450 - High (7.5)
MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless header data to exhaust server th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85450/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85450 - High (7.5)
MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless header data to exhaust server th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85450/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T00:31:10
3 posts
CVE-2026-85223 - Critical OS Command Injection in D-Link DNS-340L. Remote exploit public via dropbox.cgi. CVSS 9.9. Isolate affected devices now. #CVE #DLink #infosec
##🔴 CVE-2026-85223 - Critical (9.9)
A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85223/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-85223 - Critical (9.9)
A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85223/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T00:31:10
2 posts
🟠 CVE-2026-64200 - High (7.8)
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a past the end of an allocated heap buffer during string conversion. Successful exploitation requires an attacker...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64200/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-64200 - High (7.8)
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a past the end of an allocated heap buffer during string conversion. Successful exploitation requires an attacker...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64200/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T00:31:10
2 posts
🟠 CVE-2026-64198 - High (7.8)
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a few bytes past the end of an allocated heap buffer during file handling. Successful exploitation requires an at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64198/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-64198 - High (7.8)
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a few bytes past the end of an allocated heap buffer during file handling. Successful exploitation requires an at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64198/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-04T00:31:10
2 posts
🟠 CVE-2026-64197 - High (7.8)
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a spec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64197/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-64197 - High (7.8)
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a spec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64197/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-03T23:17:21.770000
1 posts
CVE-2026-85428: Critical auth bypass in MOOS core-moos ≤10.4.0. Unauthenticated attackers can write variables via MOOSDB HTTP server, hijacking actuators/overrides. CVSS 9.8. Unpatched. If you run MOOS, disable HTTP or restrict access NOW. Details: https://www.valtersit.com/cve/CVE-2026-85428/ #CVE #infosec #OTsecurity
##updated 2026-09-03T21:31:20
2 posts
🟠 CVE-2026-85388 - High (8.1)
Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85388/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85388 - High (8.1)
Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85388/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-03T21:31:20
2 posts
🟠 CVE-2026-85396 - High (7.5)
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like .....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85396/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85396 - High (7.5)
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like .....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85396/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-03T21:31:16
2 posts
🔴 CVE-2026-85394 - Critical (9.1)
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verific...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85394/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-85394 - Critical (9.1)
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verific...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85394/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-03T21:31:15
2 posts
🔴 CVE-2026-85391 - Critical (9.8)
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user ID...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-85391 - Critical (9.8)
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user ID...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-03T21:31:15
2 posts
🟠 CVE-2026-85028 - High (7.8)
Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85028/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85028 - High (7.8)
Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85028/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-03T20:17:28.747000
2 posts
🟠 CVE-2026-85393 - High (7.5)
node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85393/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85393 - High (7.5)
node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85393/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-03T19:52:09
1 posts
🟠 CVE-2026-82404 - High (8.3)
TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype key wrote through the object prototype chain instead of creating an own pro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82404/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-03T18:31:58
2 posts
🟠 CVE-2026-83959 - High (7.8)
Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-83959/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-83959 - High (7.8)
Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-83959/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-03T18:31:29
1 posts
Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) https://ciphersecuritylabs.com/research/articles/rooted-in-trust-breaking-hp-easy-starts-macos-privilege-boundaries
##updated 2026-09-03T18:31:29
1 posts
Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) https://ciphersecuritylabs.com/research/articles/rooted-in-trust-breaking-hp-easy-starts-macos-privilege-boundaries
##updated 2026-09-03T18:12:56.407000
1 posts
🔴 CVE-2026-66786 - Critical (9.1)
A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66786/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-03T16:45:08.223000
2 posts
https://nvd.nist.gov/vuln/detail/cve-2026-85216
sev:CRIT 9.5 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
##MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate components replace CakePHP's FormAuthenticate implementation but did not replicate its credential validation checks. As a result, empty or non-string values could reach the underlying authentication mechanisms. In the LDAP authentication path, an attacker able to identify a valid directory user's email address could submit an empty password. The empty credential could be passed to ldap_bind(), where an LDAP server accepting unauthenticated binds may return a successful result for a valid distinguished name combined with an empty password. MISP could consequently treat the attacker as the corresponding authenticated directory user without verification of the user's password. The issue also affected the LinOTP authentication component. Invalid credential types were not rejected before being processed, and when mixed authentication was enabled, an empty password could be checked against a locally stored MISP password hash. LDAP-provisioned MISP accounts could additionally be created with an empty local password because account creation skipped normal validation, resulting in a hash corresponding to an empty password. This could permit authentication through the local fallback mechanism when such an account was no longer resolved through LDAP. Successful exploitation could allow a remote unauthenticated attacker to impersonate an existing MISP user. If the targeted account has administrative or other privileged permissions, the attacker could gain corresponding access to sensitive threat-intelligence data, modify or delete information, alter configuration, or perform other privileged operations. The patch resolves the vulnerability by requiring authentication identifiers and passwords to be valid strings, rejecting empty passwords where they are not explicitly permitted, and assigning a randomly generated local password to LDAP-provisioned accounts instead of storing a hash derived from an empty password.
https://nvd.nist.gov/vuln/detail/cve-2026-85216
sev:CRIT 9.5 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
##MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate components replace CakePHP's FormAuthenticate implementation but did not replicate its credential validation checks. As a result, empty or non-string values could reach the underlying authentication mechanisms. In the LDAP authentication path, an attacker able to identify a valid directory user's email address could submit an empty password. The empty credential could be passed to ldap_bind(), where an LDAP server accepting unauthenticated binds may return a successful result for a valid distinguished name combined with an empty password. MISP could consequently treat the attacker as the corresponding authenticated directory user without verification of the user's password. The issue also affected the LinOTP authentication component. Invalid credential types were not rejected before being processed, and when mixed authentication was enabled, an empty password could be checked against a locally stored MISP password hash. LDAP-provisioned MISP accounts could additionally be created with an empty local password because account creation skipped normal validation, resulting in a hash corresponding to an empty password. This could permit authentication through the local fallback mechanism when such an account was no longer resolved through LDAP. Successful exploitation could allow a remote unauthenticated attacker to impersonate an existing MISP user. If the targeted account has administrative or other privileged permissions, the attacker could gain corresponding access to sensitive threat-intelligence data, modify or delete information, alter configuration, or perform other privileged operations. The patch resolves the vulnerability by requiring authentication identifiers and passwords to be valid strings, rejecting empty passwords where they are not explicitly permitted, and assigning a randomly generated local password to LDAP-provisioned accounts instead of storing a hash derived from an empty password.
updated 2026-09-03T16:37:52.170000
1 posts
🟠 CVE-2026-20277 - High (8.2)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20277/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-03T16:17:23.247000
1 posts
Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) https://ciphersecuritylabs.com/research/articles/rooted-in-trust-breaking-hp-easy-starts-macos-privilege-boundaries
##updated 2026-09-03T15:33:10
1 posts
2 repos
Proxmox VE 7.0–8.0.3: unauthenticated, single-request root auth bypass (CVE-2023-54391) https://blog.nathangolez.com/2026/08/proxmox-ve-7-08-0-3-unauthenticated-single-request-root-auth-bypass
##updated 2026-09-03T15:32:28
1 posts
🟠 CVE-2026-85175 - High (8.8)
SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.json by exact match and does not restrict the TLS private key (conf/key.pem...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85175/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-03T15:32:28
1 posts
🟠 CVE-2026-85174 - High (8.8)
SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85174/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-03T13:06:25.427000
16 posts
1 repos
🔵 THREAT INTELLIGENCE
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
Vulnerability | CRITICAL
CVEs: CVE-2026-9586
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead...
Full analysis:
https://www.yazoul.net/news/article/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells
by Yazoul AI
##CISA Warns of Active Switchvox Attacks as Critical CVE-2026-9586 Puts Internet-Facing VoIP Systems at Risk + Video
A Quiet VoIP Vulnerability Turns Into an Active Security Emergency A vulnerability hidden inside an enterprise phone-management platform has now moved from security research into the real world. CVE-2026-9586, a critical unauthenticated SQL injection flaw affecting Sangoma Switchvox, is being actively exploited against internet-facing systems, according to…
##Critical Sangoma Switchvox Vulnerability Is Being Exploited: What Organizations Need to Know About CVE-2026-9586 + Video
A New Cybersecurity Warning With Real-World Consequences The cybersecurity landscape rarely gives defenders much time to breathe. A vulnerability can move from a technical discovery to an active attack campaign in a matter of days, and CVE-2026-9586 is a powerful example of how quickly that transition can happen. Security researchers have confirmed…
##🏆 New Achievement! The Court Finds Switchvox Guilty of Existing on the Internet!
This tribunal hereby enters judgment against Sangoma Switchvox SMB Edition 8.3, charged with one count of catastrophic negligence via CVE-2026-9586. The evidence: a /pa endpoint that concatenates raw phone IP values directly into database queries — no sanitization, no credentials required — handing any passerby PostgreSQL superuser rights. (1/2)
##📢 Exploitation active de CVE-2026-9586 dans Sangoma Switchvox pour déployer des reverse shells
BleepingComputer, publié le 2 septembre 2026. Des chercheurs de Horizon3 ont observé l'exploitation active de CVE-2026-9586, une vulnérabilité critique d'injection SQL non authentifiée affectant la plateforme VoIP d'entreprise Sangoma Switchvox.
📖 cyberveille : https://cyberveille.ch/posts/2026-09-04-exploitation-active-de-cve-2026-9586-dans-sangoma-switchvox-pour-deployer-des-reverse-shells/
🌐 source : https://www.bleepingcomputer.com/news/security/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells/
🟢 vérification factuelle haute
#ReverseShell #SangomaSwitchvox #Cyberveille
Horizon3 reports active exploitation of CVE-2026-9586, an unauthenticated SQL injection in Sangoma Switchvox allowing remote code execution via a single request. Internet-exposed PBX systems should be patched immediately and checked for intrusion using published IoCs. #Switchvox #SqlInjection #RemoteCodeExecution
https://cyberworldops.eu/en/sangoma-switchvox-under-attack-critical-sql-injection-enables-remote
##Switchvox CVE-2026-9586 lets an unauthenticated attacker reach a root shell via SQL injection. Active exploitation seen; patch to 8.4.0.2.
#Switchvox #CVE20269586 #RCE #SQLInjection #Sangoma #VoIP #InfoSec
https://meterpreter.org/switchvox-cve-2026-9586-rce/?utm_source=mastodon&utm_medium=jetpack_social
##🏆 New Achievement! The Court Finds Switchvox Guilty of Existing on the Internet!
This tribunal hereby enters judgment against Sangoma Switchvox SMB Edition 8.3, charged with one count of catastrophic negligence via CVE-2026-9586. The evidence: a /pa endpoint that concatenates raw phone IP values directly into database queries — no sanitization, no credentials required — handing any passerby PostgreSQL superuser rights. (1/2)
##Horizon3 reports active exploitation of CVE-2026-9586, an unauthenticated SQL injection in Sangoma Switchvox allowing remote code execution via a single request. Internet-exposed PBX systems should be patched immediately and checked for intrusion using published IoCs. #Switchvox #SqlInjection #RemoteCodeExecution
https://cyberworldops.eu/en/sangoma-switchvox-under-attack-critical-sql-injection-enables-remote
##Switchvox CVE-2026-9586 lets an unauthenticated attacker reach a root shell via SQL injection. Active exploitation seen; patch to 8.4.0.2.
#Switchvox #CVE20269586 #RCE #SQLInjection #Sangoma #VoIP #InfoSec
https://meterpreter.org/switchvox-cve-2026-9586-rce/?utm_source=mastodon&utm_medium=jetpack_social
##Attackers Exploit Critical Sangoma Switchvox Flaw to Deploy Reverse Shells
Sangoma patched 12 vulnerabilities in Switchvox, including a critical unauthenticated SQL injection (CVE-2026-9586) that attackers are currently using to gain remote code execution and steal authentication keys.
**If you run Sangoma Switchvox, first make sure it isn't reachable from the internet and can only be accessed from trusted networks, then update immediately to version 8.4.0.2. Anything on version 8.3 or earlier is being actively attacked. Because attackers have been stealing keys, tokens and user data, also check /var/log/switchvox/db-quirks.log for signs of SQL injection, block the IP 176.65.148.184, and reset passwords and signing keys if you find anything suspicious.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/attackers-exploit-critical-sangoma-switchvox-flaw-to-deploy-reverse-shells-b-w-f-y-c/gD2P6Ple2L
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can...
🔗️ [Bleepingcomputer] https://link.is.it/o3uhXX
##Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.
- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-83549
- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-83548
- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-9586
- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-82329
- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-49869
- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-48710
- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-59822 #CISA #infosec #vulnerability
##🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-48710 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48710)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-48710
⚠️ CVE-2026-49869 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-49869)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjx ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-49869
⚠️ CVE-2026-59822 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59822)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-59822
⚠️ CVE-2026-82329 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82329)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-82329
⚠️ CVE-2026-83548 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-83548)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-83548
⚠️ CVE-2026-83549 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-83549)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-83549
⚠️ CVE-2026-9586 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9586)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-9586
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586
##CVE ID: CVE-2026-9586
Vendor: Sangoma
Product: Switchvox
Date Added: 2026-09-02
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9586
Active exploitation attempts are targeting CVE-2026-9586, a critical unauthenticated SQL injection in Sangoma Switchvox SMB Edition. A single crafted request enables arbitrary SQL execution on PostgreSQL and leads to remote code execution via reverse shell. Immediate patching and exposure review are critical. #Switchvox #SqlInjection #ThreatIntel
https://cyberworldops.eu/en/switchvox-under-attack-critical-sql-injection-installs-reverse-shell
##updated 2026-09-03T13:06:22.067000
1 posts
🔴 CVE-2026-85154 - Critical (9.8)
WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85154/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-03T13:04:39.930000
1 posts
CVE-2026-20280 - High severity flaw in Cisco IOS XR Software. Improper handling of exceptional conditions (CWE-703). CVSS 8.8. Update immediately. #CVE #Cisco #infosec
##updated 2026-09-03T13:04:39.407000
1 posts
New security advisories.
Broadcom has addressed several vulnerabilities,two of them critical https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Cisco: Five advisories, two of them addressing critical vulnerabilities:
- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr
- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM
More: https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##updated 2026-09-03T13:04:35.017000
1 posts
🟠 CVE-2026-14828 - High (8.8)
Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14828/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-02T21:32:07
2 posts
🔴 CVE-2026-19117 - Critical (9.8)
Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as
that user. This issue affects on-premises deployments only.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19117/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Credential managers are so hot right now. Here's Delinea's on-prem offering.
https://nvd.nist.gov/vuln/detail/cve-2026-19117
sev:CRIT 9.8 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
##Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.
updated 2026-09-02T18:32:31
1 posts
New security advisories.
Broadcom has addressed several vulnerabilities,two of them critical https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Cisco: Five advisories, two of them addressing critical vulnerabilities:
- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr
- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM
More: https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##updated 2026-09-02T18:32:31
1 posts
New security advisories.
Broadcom has addressed several vulnerabilities,two of them critical https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Cisco: Five advisories, two of them addressing critical vulnerabilities:
- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr
- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM
More: https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##updated 2026-09-02T18:32:26
11 posts
1 repos
https://thecybersecguru.com/news/cve-2026-20212-cisco-nexus-9000-rce/
##Cisco disclosed CVE-2026-20212, a critical unauthenticated RCE in Silicon One on Nexus 9000 switches. Exploitation yields root execution via crafted data, putting core data-center fabric at risk of full compromise. #CiscoNexus #SiliconOne #NetworkSecurity
https://cyberworldops.eu/en/cisco-nexus-9000-critical-flaw-enables-remote-root-code-execution
##Cisco’s Critical Nexus 9000 Flaw Exposes a Dangerous Path to Root Access + Video
A New Warning for Network Administrators A critical security flaw in certain Cisco Nexus 9000 switches has turned the spotlight back toward one of the most important lessons in modern infrastructure security: even highly specialized network hardware can contain vulnerabilities capable of giving an attacker complete control. Cisco has released security updates for CVE-2026-20212, a…
##⚠️ CRITICAL: Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Cisco released patches for CVE-2026-20212, a critical unauthenticated remote code execution vulnerability in Nexus 9000 switches (10 Silicon One-based models). Attackers can exploit this via TCP ports 43210 and 43211 to execute commands as root. If you run affected Nexus 9000 hardware, this is imme…
🤖 AI generated summary
##Cisco Nexus 9000 Critical Flaw Exposes Silicon One Switches to Root-Level Remote Code Execution + Video
A Dangerous New Warning for Data Center Networks A critical vulnerability in Cisco Nexus 9000 Series switches has turned a routine software security update into an urgent priority for organizations operating affected data center infrastructure. Tracked as CVE-2026-20212, the flaw carries a CVSS score of 9.8 and can allow an unauthenticated remote attacker to execute…
##Cisco Discloses Critical Flaw in Nexus 9000 Switches
Cisco has uncovered a critical flaw in its Nexus 9000 switches, known as CVE-2026-20212, which could allow an unauthenticated attacker to remotely execute code as root. This vulnerability affects 10 specific models and has already been patched by the company.
#Cisco #Nexus9000 #Cve202620212 #RemoteCodeExecution #SiliconOne
##https://thecybersecguru.com/news/cve-2026-20212-cisco-nexus-9000-rce/
##Cisco disclosed CVE-2026-20212, a critical unauthenticated RCE in Silicon One on Nexus 9000 switches. Exploitation yields root execution via crafted data, putting core data-center fabric at risk of full compromise. #CiscoNexus #SiliconOne #NetworkSecurity
https://cyberworldops.eu/en/cisco-nexus-9000-critical-flaw-enables-remote-root-code-execution
##⚠️ CRITICAL: Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Cisco released patches for CVE-2026-20212, a critical unauthenticated remote code execution vulnerability in Nexus 9000 switches (10 Silicon One-based models). Attackers can exploit this via TCP ports 43210 and 43211 to execute commands as root. If you run affected Nexus 9000 hardware, this is imme…
🤖 AI generated summary
##CVE-2026-20212, a critical Cisco Nexus 9000 vulnerability, lets an unauthenticated attacker gain remote code execution with root privileges. CVSS 9.8.
#Cisco #Nexus9000 #SiliconOne #RCE #NXOS #NetworkSecurity #InfoSec #PatchNow
##New security advisories.
Broadcom has addressed several vulnerabilities,two of them critical https://support.broadcom.com/web/ecx/security-advisory #Broadcom
Cisco: Five advisories, two of them addressing critical vulnerabilities:
- CRITICAL: CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr
- CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM
More: https://sec.cloudapps.cisco.com/security/center/publicationListing.x @TalosSecurity #Cisco #infosec #vulnerability
##updated 2026-09-02T18:32:17
1 posts
I am fortunate enough to not know anything about NGINX JavaScript ( hashtag blessed ) but if you do, this might be of interest.
https://nvd.nist.gov/vuln/detail/cve-2026-78689
##Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) engines are affected. A crafted prefix list causes an out-of-bounds write past the end of a heap allocation. With the njs engine, which is the engine used when the js_engine directive is absent, this corrupts adjacent objects and crashes the NGINX worker. With the QuickJS engine, the same call additionally leaks the prefix list on every invocation, causing worker memory to grow across requests. The official nginxinc/nginx-saml reference implementation is affected during SAML signature verification. It reads InclusiveNamespaces/@PrefixList from an untrusted SAML message and passes it to xml.exclusiveC14n() before the signature has been verified, so a valid SAML signature is not required. A crafted SAML Response, Assertion, LogoutRequest, or LogoutResponse is sufficient. Code execution has not been demonstrated and cannot be ruled out for all platforms, as the effect of the out-of-bounds write depends on conditions beyond the attacker's control. Impact This vulnerability allows remote attackers to cause a denial of service on the NGINX system, either through repeatable worker restarts or through worker memory growth or possibly trigger code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
updated 2026-09-02T18:32:06
14 posts
2 repos
https://github.com/xcoy0te/CVE-2026-83548-checker
https://github.com/xoessie/CVE-2026-83548-SonicWall-SMA1000-Analysis
RE: https://social.bund.de/@certbund/117202125036885815
For a critical #itsecurity #vulnerability as example, here is the CSAF JSON file (from the Germans): https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3135.json .
(For https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 CVE-2026-83548, CVE-2026-83549 a CVSS v3 10.0 "critical" defect)
In the vulnerabilities and product_tree sections there are precise infos which version is affected. More structure than the vendor's version.
BTW, the version from the Netherland - https://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0239-0.json - does not have the affected versions, but they give the criticality.
So both could be improved and potentially they will with the next revsions. 😉
Still, if this runs directly in our IT Security Management system, this is much better and faster than manually reading the HTML or PDF advisories.
##Attackers Exploit Zero-Days in SonicWall SMA 1000 Appliances
SonicWall's SMA 1000 appliances are under attack, thanks to two newly disclosed zero-day vulnerabilities - CVE-2026-83548 and CVE-2026-83549 - that can be chained together for a complete network compromise. Attackers are already exploiting these flaws in the wild, prompting urgent patching advice from the vendor and cybersecurity authorities.
##SonicWall Under Siege Again: Two Zero-Days Turn the SMA 1000 Into a High-Risk Gateway for Attackers + Video
Introduction: Another Warning From the Network Edge SonicWall customers are once again facing a serious security crisis, and this time the danger is concentrated around the SonicWall SMA 1000 remote-access appliance. Two newly disclosed vulnerabilities, CVE-2026-83548 and CVE-2026-83549, are already being exploited in the wild, turning what should be a trusted…
##RE: https://social.bund.de/@certbund/117202125036885815
For a critical #itsecurity #vulnerability as example, here is the CSAF JSON file (from the Germans): https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3135.json .
(For https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 CVE-2026-83548, CVE-2026-83549 a CVSS v3 10.0 "critical" defect)
In the vulnerabilities and product_tree sections there are precise infos which version is affected. More structure than the vendor's version.
BTW, the version from the Netherland - https://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0239-0.json - does not have the affected versions, but they give the criticality.
😉
##New.
Rapid7: Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild/ @Rapid7Official #infosec #vulnerability #SonicWall
##SonicWall Patches Chained Zero-Day Vulnerabilities in SMA 1000 Series VPNs
SonicWall has patched two zero-day vulnerabilities (CVE-2026-83548 and CVE-2026-83549) in its SMA 1000 series VPN appliances that attackers are chaining to achieve unauthenticated remote code execution.
**If you run SonicWall SMA 1000 appliances (models 6210, 7210, or 8200v), update immediately to version 12.4.3-03526 or 12.5.0-02952. These devices are actively attacked to take over VPN gateways. After patching review your logs for signs of compromise, if anything looks suspicious, re-image the appliance, change all passwords and reset TOTP tokens, and only restore backups from before the breach.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/sonicwall-patches-chained-zero-day-vulnerabilities-in-sma-1000-series-vpns-k-n-b-f-y/gD2P6Ple2L
「攻撃者がSonicWall SMA 1000の2つのゼロデイ脆弱性を悪用し、攻撃連鎖を形成する可能性 」: #TheHackerNews
「SonicWallは、ゼロデイ攻撃で悪用された、同社のSecure Mobile Access(SMA)1000シリーズVPNアプライアンスに影響を与える2つのセキュリティ上の欠陥に対処するためのセキュリティアップデートをリリースしました。
SonicWallのウィリアム・ペリー氏とアダム・バビス氏が社内で発見した脆弱 性は 以下のとおりです。
CVE-2026-83548 (CVSS スコア: 10.0)
CVE-2026-83549 (CVSS スコア: 7.8)
SonicWallは、「脆弱性が積極的に悪用されていることを示す事例を調査した」と述べ、攻撃者が両方のバグを組み合わせて、脆弱性のあるデバイス上で任意のコードを実行している可能性を示唆した。 」
https://thehackernews.com/2026/09/attackers-exploit-two-sonicwall-sma.html
##Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.
- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-83549
- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-83548
- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-9586
- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-82329
- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-49869
- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-48710
- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-59822 #CISA #infosec #vulnerability
##🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-48710 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48710)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-48710
⚠️ CVE-2026-49869 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-49869)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjx ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-49869
⚠️ CVE-2026-59822 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59822)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-59822
⚠️ CVE-2026-82329 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82329)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-82329
⚠️ CVE-2026-83548 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-83548)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-83548
⚠️ CVE-2026-83549 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-83549)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-83549
⚠️ CVE-2026-9586 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9586)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-9586
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586
##CVE ID: CVE-2026-83548
Vendor: SonicWall
Product: SMA1000 Appliances
Date Added: 2026-09-02
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-83548
⚠️Alerte CERT-FR⚠️
Les vulnérabilités CVE-2026-83548 et CVE-2026-83549 affectent les SMA 1000 et permettent une SSRF ainsi que l'exécution de code arbitraire à distance.
Elles sont activement exploitées.
🏆 New Achievement! By Continuing to Use This Appliance, You Agree to Be Owned!
Please note that Section 2, Paragraph 4 of your SMA1000 user agreement has been updated. By failing to patch CVE-2026-83548 — a pre-authentication SSRF flaw scoring a perfect 10.0 CVSS in the Appliance Work Place interface — you consent to unauthenticated strangers poking around your network. (1/2)
##Tiens, encore du #SonicWall SMA1000 ...
Deux nouvelles vulnérabilités 0-day, CVE-2026-83548 (CVSS 10) et CVE-2026-83549, activement exploitées.
La première permet une SSRF sans authentification, la seconde une injection de commandes/RCE. Les deux peuvent être chaînées pour arriver à une RCE sans authentification sur l'appliance.
Sont concernés les SMA1000 6210, 7210 et 8200v.
Pas de workaround : hotfix à appliquer au plus vite. ☹️
Et SonicWall dans la doc dédiée ne s’arrête pas au patch : recherche d’IoC recommandée et, si compromission détectée, re-image/redeploy de l’appliance + reset des mots de passe admin/utilisateurs et des tokens TOTP.
À noter : les SSL-VPN des firewalls SonicWall et la gamme SMA100 ne sont pas concernés.
Bref, si vous avez du SMA1000 exposé, ça mérite clairement un petit détour dans l’inventaire ce matin. 🙃
Advisory 🩹
👇
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
SonicWall confirmed active exploitation of two zero-days in SMA1000 appliances, including pre-auth SSRF CVE-2026-83548. Chained, the flaws allow unauthenticated remote command execution on SSL-VPN gateways. Operators should patch immediately and hunt for post-exploitation activity. #SonicWall #ZeroDay #InfoSec
https://cyberworldops.eu/en/sonicwall-sma1000-under-attack-two-zero-days-enable-ssrf-and-system
##updated 2026-09-02T18:32:06
13 posts
1 repos
RE: https://social.bund.de/@certbund/117202125036885815
For a critical #itsecurity #vulnerability as example, here is the CSAF JSON file (from the Germans): https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3135.json .
(For https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 CVE-2026-83548, CVE-2026-83549 a CVSS v3 10.0 "critical" defect)
In the vulnerabilities and product_tree sections there are precise infos which version is affected. More structure than the vendor's version.
BTW, the version from the Netherland - https://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0239-0.json - does not have the affected versions, but they give the criticality.
So both could be improved and potentially they will with the next revsions. 😉
Still, if this runs directly in our IT Security Management system, this is much better and faster than manually reading the HTML or PDF advisories.
##Attackers Exploit Zero-Days in SonicWall SMA 1000 Appliances
SonicWall's SMA 1000 appliances are under attack, thanks to two newly disclosed zero-day vulnerabilities - CVE-2026-83548 and CVE-2026-83549 - that can be chained together for a complete network compromise. Attackers are already exploiting these flaws in the wild, prompting urgent patching advice from the vendor and cybersecurity authorities.
##SonicWall Under Siege Again: Two Zero-Days Turn the SMA 1000 Into a High-Risk Gateway for Attackers + Video
Introduction: Another Warning From the Network Edge SonicWall customers are once again facing a serious security crisis, and this time the danger is concentrated around the SonicWall SMA 1000 remote-access appliance. Two newly disclosed vulnerabilities, CVE-2026-83548 and CVE-2026-83549, are already being exploited in the wild, turning what should be a trusted…
##RE: https://social.bund.de/@certbund/117202125036885815
For a critical #itsecurity #vulnerability as example, here is the CSAF JSON file (from the Germans): https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3135.json .
(For https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 CVE-2026-83548, CVE-2026-83549 a CVSS v3 10.0 "critical" defect)
In the vulnerabilities and product_tree sections there are precise infos which version is affected. More structure than the vendor's version.
BTW, the version from the Netherland - https://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0239-0.json - does not have the affected versions, but they give the criticality.
😉
##New.
Rapid7: Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild/ @Rapid7Official #infosec #vulnerability #SonicWall
##SonicWall Patches Chained Zero-Day Vulnerabilities in SMA 1000 Series VPNs
SonicWall has patched two zero-day vulnerabilities (CVE-2026-83548 and CVE-2026-83549) in its SMA 1000 series VPN appliances that attackers are chaining to achieve unauthenticated remote code execution.
**If you run SonicWall SMA 1000 appliances (models 6210, 7210, or 8200v), update immediately to version 12.4.3-03526 or 12.5.0-02952. These devices are actively attacked to take over VPN gateways. After patching review your logs for signs of compromise, if anything looks suspicious, re-image the appliance, change all passwords and reset TOTP tokens, and only restore backups from before the breach.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/sonicwall-patches-chained-zero-day-vulnerabilities-in-sma-1000-series-vpns-k-n-b-f-y/gD2P6Ple2L
「攻撃者がSonicWall SMA 1000の2つのゼロデイ脆弱性を悪用し、攻撃連鎖を形成する可能性 」: #TheHackerNews
「SonicWallは、ゼロデイ攻撃で悪用された、同社のSecure Mobile Access(SMA)1000シリーズVPNアプライアンスに影響を与える2つのセキュリティ上の欠陥に対処するためのセキュリティアップデートをリリースしました。
SonicWallのウィリアム・ペリー氏とアダム・バビス氏が社内で発見した脆弱 性は 以下のとおりです。
CVE-2026-83548 (CVSS スコア: 10.0)
CVE-2026-83549 (CVSS スコア: 7.8)
SonicWallは、「脆弱性が積極的に悪用されていることを示す事例を調査した」と述べ、攻撃者が両方のバグを組み合わせて、脆弱性のあるデバイス上で任意のコードを実行している可能性を示唆した。 」
https://thehackernews.com/2026/09/attackers-exploit-two-sonicwall-sma.html
##Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.
- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-83549
- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-83548
- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-9586
- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-82329
- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-49869
- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-48710
- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-59822 #CISA #infosec #vulnerability
##🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-48710 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48710)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-48710
⚠️ CVE-2026-49869 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-49869)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjx ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-49869
⚠️ CVE-2026-59822 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59822)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-59822
⚠️ CVE-2026-82329 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82329)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-82329
⚠️ CVE-2026-83548 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-83548)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-83548
⚠️ CVE-2026-83549 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-83549)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-83549
⚠️ CVE-2026-9586 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9586)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-9586
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586
##CVE ID: CVE-2026-83549
Vendor: SonicWall
Product: SMA1000 Appliances
Date Added: 2026-09-02
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-83549
⚠️Alerte CERT-FR⚠️
Les vulnérabilités CVE-2026-83548 et CVE-2026-83549 affectent les SMA 1000 et permettent une SSRF ainsi que l'exécution de code arbitraire à distance.
Elles sont activement exploitées.
By also ignoring CVE-2026-83549, an OS command injection flaw in the AMC component, you further agree to let those same strangers chain both bugs together for full remote code execution. SonicWall has confirmed active exploitation in the wild. Ransomware gangs find SonicWall products particularly cozy real estate.
To opt out of these terms, patch your SMA1000 immediately.
Reward: You've received the Binding Arbitration Curse — your incidents are now non-disputable.
#ZeroDay #SonicWall (2/2)
##Tiens, encore du #SonicWall SMA1000 ...
Deux nouvelles vulnérabilités 0-day, CVE-2026-83548 (CVSS 10) et CVE-2026-83549, activement exploitées.
La première permet une SSRF sans authentification, la seconde une injection de commandes/RCE. Les deux peuvent être chaînées pour arriver à une RCE sans authentification sur l'appliance.
Sont concernés les SMA1000 6210, 7210 et 8200v.
Pas de workaround : hotfix à appliquer au plus vite. ☹️
Et SonicWall dans la doc dédiée ne s’arrête pas au patch : recherche d’IoC recommandée et, si compromission détectée, re-image/redeploy de l’appliance + reset des mots de passe admin/utilisateurs et des tokens TOTP.
À noter : les SSL-VPN des firewalls SonicWall et la gamme SMA100 ne sont pas concernés.
Bref, si vous avez du SMA1000 exposé, ça mérite clairement un petit détour dans l’inventaire ce matin. 🙃
Advisory 🩹
👇
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
updated 2026-09-02T18:31:57
8 posts
6 repos
https://github.com/HORKimhab/CVE-2026-82329
https://github.com/dinosn/cve-2026-82329-jfrog-artifactory
https://github.com/0xCyp1337/CVE-2026-82329
https://github.com/realalexandergeorgiev/artifactory-CVE-2026-82329-poc.py
https://github.com/gagaltotal/CVE-2026-82329-poc
https://github.com/ynsmroztas/CVE-2026-82329-JFrog-Artifactory-Auth-Bypass
📢 Exploitation active de CVE-2026-82329 dans JFrog Artifactory pour forger des tokens admin
BleepingComputer, publié le 2 septembre 2026. L'article rapporte l'exploitation active d'une vulnérabilité critique dans JFrog Artifactory, un gestionnaire de dépôts logiciels largement utilisé pour stocker, organiser, sécuriser et distribuer…
📖 cyberveille : https://cyberveille.ch/posts/2026-09-04-exploitation-active-de-cve-2026-82329-dans-jfrog-artifactory-pour-forger-des-tokens-admin/
🌐 source : https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-jfrog-artifactory-flaw-to-forge-admin-tokens/
🟡 vérification factuelle moyenne
#JFrogArtifactory #AuthenticationBypass #Cyberveille
🔵 THREAT INTELLIGENCE
Hackers exploit critical JFrog Artifactory flaw to forge admin tokens
Vulnerability | CRITICAL
CVEs: CVE-2026-82329
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide...
Full analysis:
https://www.yazoul.net/news/article/hackers-exploit-critical-jfrog-artifactory-flaw-to-forge-admin-tokens
by Yazoul AI
##Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.
- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-83549
- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-83548
- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-9586
- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-82329
- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-49869
- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-48710
- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-59822 #CISA #infosec #vulnerability
##🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-48710 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48710)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-48710
⚠️ CVE-2026-49869 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-49869)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjx ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-49869
⚠️ CVE-2026-59822 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59822)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-59822
⚠️ CVE-2026-82329 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82329)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-82329
⚠️ CVE-2026-83548 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-83548)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-83548
⚠️ CVE-2026-83549 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-83549)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-83549
⚠️ CVE-2026-9586 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9586)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-9586
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586
##CVE ID: CVE-2026-82329
Vendor: JFrog
Product: Artifactory
Date Added: 2026-09-02
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82329
Hackers exploit critical JFrog Artifactory flaw to forge admin tokens
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide...
🔗️ [Bleepingcomputer] https://link.is.it/GGGBsY
##Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens
JFrog Artifactory is facing active exploitation of a critical authentication bypass (CVE-2026-82329) that allows unauthenticated attackers to mint administrator tokens and compromise software supply chains.
**If you run self-managed JFrog Artifactory, update to version 7.161.20 ASAP. Attackers are already exploiting this flaw to take full admin control. Primary systems at risk are internet facing self-hosted Artifactory instances. Cloud-hosted instances managed by JFrog are not affected.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/attackers-exploit-critical-jfrog-artifactory-flaw-to-mint-admin-tokens-f-g-f-4-3/gD2P6Ple2L
Geopolitical tensions persist between the U.S. and Iran regarding actions in the Strait of Hormuz (Sept 1, 2026). On the cybersecurity front, critical infrastructure, including Midwest water utilities, faces new ransomware attacks. Additionally, a severe authentication bypass flaw (CVE-2026-82329) in JFrog Artifactory is actively being exploited. OpenAI has issued a stark warning regarding the escalating threat of AI-enabled cyberattacks.
##updated 2026-09-02T15:34:36
8 posts
HPE Patches Critical Remote Code Execution Flaw in ArubaOS-CX Switches
HPE patched 34 vulnerabilities in ArubaOS-CX, including a critical buffer overflow (CVE-2026-73749) that allows unauthenticated remote code execution. The update also addresses multiple high-severity flaws enabling command injection, authentication bypass, and unauthorized file writes.
**If you run HPE Aruba CX switches (10000, 6400, 8325, 6000 series), first make sure their management interfaces are not reachable from the internet and only accessible from a dedicated management VLAN on trusted networks. Then update the switches to AOS-CX 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, or 10.10.1181, and change any factory-set passwords while you're there.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/hpe-patches-critical-remote-code-execution-flaw-in-arubaos-cx-switches-7-8-k-r-6/gD2P6Ple2L
HPE korjaa kriittisen ArubaOS-CX RCE -haavoittuvuuden HPE on korjannut CVE-2026-73749:n, kriittisen puskurin ylivuodon ArubaOS-CX:ssä, joka sallii todentamattoman etäkoodin suorittamisen korotetuilla oikeuksilla luotujen pakettien kautta kyseiselle daemonille. ArubaOS-CX-tiedote käsittelee myös 23 muuta haavoittuvuutta, mukaan lukien komentojen suorittamisen
##HPE patched CVE-2026-73749, a critical unauthenticated buffer overflow in ArubaOS-CX. Exploitation via crafted packets to a vulnerable daemon can yield privileged remote code execution on enterprise switches, risking full network takeover. #HpeAruba #ArubaOS #NetworkSecurity
https://cyberworldops.eu/en/arubaos-cx-critical-vulnerability-exposes-hpe-switches-to-remote-code
##HPE Fixes Remote Code Execution Flaw in ArubaOS-CX
HPE has patched a critical flaw in ArubaOS-CX that could let hackers run malicious code with elevated privileges - and all they need to do is send specially crafted packets to an affected device. This remote code execution vulnerability, tracked as CVE-2026-73749, is a serious threat that demands immediate attention.
#RemoteCodeExecution #Arubaoscx #Cve202673749 #BufferOverflow #Hpe
##HPE Patches Critical Remote Code Execution Flaw in ArubaOS-CX Switches
HPE patched 34 vulnerabilities in ArubaOS-CX, including a critical buffer overflow (CVE-2026-73749) that allows unauthenticated remote code execution. The update also addresses multiple high-severity flaws enabling command injection, authentication bypass, and unauthorized file writes.
**If you run HPE Aruba CX switches (10000, 6400, 8325, 6000 series), first make sure their management interfaces are not reachable from the internet and only accessible from a dedicated management VLAN on trusted networks. Then update the switches to AOS-CX 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, or 10.10.1181, and change any factory-set passwords while you're there.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/hpe-patches-critical-remote-code-execution-flaw-in-arubaos-cx-switches-7-8-k-r-6/gD2P6Ple2L
HPE korjaa kriittisen ArubaOS-CX RCE -haavoittuvuuden HPE on korjannut CVE-2026-73749:n, kriittisen puskurin ylivuodon ArubaOS-CX:ssä, joka sallii todentamattoman etäkoodin suorittamisen korotetuilla oikeuksilla luotujen pakettien kautta kyseiselle daemonille. ArubaOS-CX-tiedote käsittelee myös 23 muuta haavoittuvuutta, mukaan lukien komentojen suorittamisen
##HPE patched CVE-2026-73749, a critical unauthenticated buffer overflow in ArubaOS-CX. Exploitation via crafted packets to a vulnerable daemon can yield privileged remote code execution on enterprise switches, risking full network takeover. #HpeAruba #ArubaOS #NetworkSecurity
https://cyberworldops.eu/en/arubaos-cx-critical-vulnerability-exposes-hpe-switches-to-remote-code
##CVE-2026-73749: Unauth RCE in HPE Networking AOS-CX Scores 9.8
##updated 2026-09-02T13:55:27.963000
1 posts
🔴 CVE-2026-78657 - Critical (9.8)
The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it po...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78657/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-02T12:31:39
1 posts
https://nvd.nist.gov/vuln/detail/cve-2026-84795
sev:CRIT 9.8 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.
Seems like a pretty limited scope but it's still interesting to see that sev:CRIT in the CVE when the advisory says sev:MED:
https://github.com/craftcms/cms/security/advisories/GHSA-242m-9wq7-vhwq
##updated 2026-09-02T12:17:14.410000
1 posts
"Just use a password manager."
https://nvd.nist.gov/vuln/detail/cve-2026-84699
##Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.
updated 2026-09-02T11:17:25.947000
1 posts
🟠 CVE-2026-84485 - High (7.5)
APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84485/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-02T06:31:24
1 posts
1 repos
🔴 CVE-2026-9055 - Critical (9.8)
The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the cus...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9055/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-02T06:31:24
1 posts
🟠 CVE-2026-14357 - High (8.8)
The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing nonce validation in the DPDEV_install_themes_func() function registered on th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14357/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-02T06:31:19
1 posts
🟠 CVE-2025-46418 - High (7.6)
Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-46418/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-02T04:18:00.460000
3 posts
1 repos
📢 CVE-2026-62911 : vulnérabilité critique d'élévation de privilèges dans Microsoft Exchange avec PoC public
📰 Source : LeMagIT — Article publié le 26 août 2026, relatant une vulnérabilité Exchange divulguée lors du Patch Tuesday de Microsoft du 11 août 2026. 🔍 Contexte : Le Patch Tuesday d'août 2026 de Microsoft est décrit comme le plus…
📖 cyberveille : https://cyberveille.ch/posts/2026-09-04-cve-2026-62911-vulnerabilite-critique-d-elevation-de-privileges-dans-microsoft-exchange-avec-poc-public/
🌐 source : https://www.lemagit.fr/actualites/366649756/Une-vulnerabilite-Exchange-a-patcher-durgence
🟡 vérification factuelle moyenne
#MicrosoftExchange #PoCPublic #Cyberveille
Nearly 22,000 internet-facing Exchange servers remain unpatched against CVE-2026-62911, an authentication bypass that can hijack every user's mailbox.
#CVE202662911 #MicrosoftExchange #AuthenticationBypass #Shadowserver #Patch
https://meterpreter.org/exchange-cve-2026-62911/?utm_source=mastodon&utm_medium=jetpack_social
##Exchange Server : près de 22 000 serveurs exposés sont vulnérables à la CVE-2026-62911 https://www.it-connect.fr/microsoft-exchange-cve-2026-62911/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft #Exchange
##updated 2026-09-02T03:31:18
1 posts
🟠 CVE-2026-84484 - High (7.5)
ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the LTP link se...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84484/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-02T03:31:17
1 posts
🟠 CVE-2026-84715 - High (8.8)
FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted reques...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84715/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-02T03:31:14
1 posts
🟠 CVE-2026-14982 - High (8.1)
The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenticated attackers, with subscriber-level access an...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14982/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-02T03:31:14
1 posts
🟠 CVE-2026-14957 - High (7.5)
In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14957/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-02T03:31:13
1 posts
🟠 CVE-2026-84702 - High (7.5)
facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HT...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84702/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-02T03:31:13
1 posts
🟠 CVE-2026-84700 - High (8.6)
PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84700/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-09-01T15:31:23
3 posts
CVE-2026-84115 in Cleo Harmony: JWT Refresh Token Handler Flaw Exposes Remote Attack Risk
https://thecyberexpress.com/cve-2026-84115-cleo-harmony-jwt-refresh-token/?utm_source=flipboard&utm_medium=activitypub
Posted into Cybersecurity Today @cybersecurity-today-rhudaur
##CVE-2026-84115 in Cleo Harmony: JWT Refresh Token Handler Flaw Exposes Remote Attack Risk
https://thecyberexpress.com/cve-2026-84115-cleo-harmony-jwt-refresh-token/?utm_source=flipboard&utm_medium=activitypub
Posted into Cybersecurity Today @cybersecurity-today-rhudaur
##CVE-2026-84115 in Cleo Harmony: JWT Refresh Token Handler Flaw Exposes Remote Attack Risk
A critical vulnerability identified as CVE-2026-84115 affects Cleo Harmony versions through 5.8.1.10, with the weakness tied to the platform’s JWT
🔗️ [Thecyberexpress] https://link.is.it/lkJ3B6
##updated 2026-09-01T04:18:02.160000
2 posts
2 repos
Huntress logged confirmed attacks against at least two customers.
SYSTEM NOTE: WatchTowr did not make this worse. The situation was already worse. WatchTowr merely filed a report.
Apply PaperCut's emergency patches for both CVE-2026-81578 and CVE-2026-82078 immediately, and check for indicators of compromise dating back to August 26.
Reward: You've received a Duplicate Incident Ticket — it's the same as the first one but somehow more urgent.
#PaperCut #ZeroDay #CVE #CyberSecurity (2/2)
##🏆 New Achievement! Print Job: Ownership Complete!
ERROR: Assumed single zero-day. Actual zero-days: two. PaperCut, the print management software, has had CVE-2026-81578 and CVE-2026-82078 exploited in the wild since August 26 — the first a high-severity authentication bypass letting remote, unauthenticated attackers modify system configurations. WatchTowr then found additional patch bypasses, triggering a second emergency patch before the first one was even officially released. (1/2)
##updated 2026-08-31T21:31:56
2 posts
2 repos
Huntress logged confirmed attacks against at least two customers.
SYSTEM NOTE: WatchTowr did not make this worse. The situation was already worse. WatchTowr merely filed a report.
Apply PaperCut's emergency patches for both CVE-2026-81578 and CVE-2026-82078 immediately, and check for indicators of compromise dating back to August 26.
Reward: You've received a Duplicate Incident Ticket — it's the same as the first one but somehow more urgent.
#PaperCut #ZeroDay #CVE #CyberSecurity (2/2)
##🏆 New Achievement! Print Job: Ownership Complete!
ERROR: Assumed single zero-day. Actual zero-days: two. PaperCut, the print management software, has had CVE-2026-81578 and CVE-2026-82078 exploited in the wild since August 26 — the first a high-severity authentication bypass letting remote, unauthenticated attackers modify system configurations. WatchTowr then found additional patch bypasses, triggering a second emergency patch before the first one was even officially released. (1/2)
##updated 2026-08-31T21:31:55
1 posts
Redis RCE PoC (CVE-2026-81934) https://github.com/v12-security/pocs/tree/main/redis/server_ssl
##updated 2026-08-28T18:31:00
6 posts
5 repos
https://github.com/CuteeCat/CVE-2026-48710
https://github.com/eris-ths/supply-chain-guard
https://github.com/xtremebeing/starlette-host-header-lab
https://github.com/sb-ox/repro-OXDEV-77637-uv-workspace
https://github.com/Bhanunamikaze/BadHost-CVE-2026-48710-Exploit
(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-48710 – Kludex Starlette HTTP Request/Response Smuggling Vulnerability
Active CISA KEV exploitation of CVE-2026-48710 exposes Starlette to request smuggling and auth bypass. Review board-ready governance, asset visibility, and mitigation....
##(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-48710 – Kludex Starlette HTTP Request/Response Smuggling Vulnerability
Active CISA KEV exploitation of CVE-2026-48710 exposes Starlette to request smuggling and auth bypass. Review board-ready governance, asset visibility, and mitigation....
##Mitigate CVE-2026-48710 in Starlette. Attackers exploit path injections in request headers to trigger auth bypasses. Access our T-Suite brief for Splunk, Sentinel, and Chronicle detection rules and rapid reverse proxy hardening steps to secure your perimeter today. https://thecybermind.co/zyul
##Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.
- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-83549
- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-83548
- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-9586
- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-82329
- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-49869
- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-48710
- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-59822 #CISA #infosec #vulnerability
##🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-48710 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48710)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-48710
⚠️ CVE-2026-49869 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-49869)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjx ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-49869
⚠️ CVE-2026-59822 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59822)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-59822
⚠️ CVE-2026-82329 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82329)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-82329
⚠️ CVE-2026-83548 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-83548)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-83548
⚠️ CVE-2026-83549 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-83549)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-83549
⚠️ CVE-2026-9586 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9586)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-9586
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586
##CVE ID: CVE-2026-48710
Vendor: Kludex
Product: Starlette
Date Added: 2026-09-02
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48710
updated 2026-08-25T12:31:24
7 posts
1 repos
📢 Injection SQL de second ordre non authentifiée dans All-in-One WP Migration and Backup (CVE-2026-19949)
Cet article détaille une vulnérabilité critique découverte le 14 août 2026 dans le plugin WordPress All-in-One WP Migration and Backup, qui compte plus de 5 millions d'installations actives.
📖 cyberveille : https://cyberveille.ch/posts/2026-09-04-injection-sql-de-second-ordre-non-authentifiee-dans-all-in-one-wp-migration-and-backup-cve-2026-19949/
🌐 source : https://www.wordfence.com/blog/2026/09/5-million-wordpress-sites-affected-by-sql-injection-vulnerability-in-all-in-one-wp-migration-and-backup-wordpress-plugin/
🟡 vérification factuelle moyenne
#WordPress #RemoteCodeExecution #Cyberveille
Si vous avez utilisé (et oublié 😅) All-in-One WP Migration and Backup sur votre #WordPress c'est peut-être le moment d'aller jeter un œil.
Une vulnérabilité assez vilaine, CVE-2026-19949, touche les versions jusqu'à 7.109.
Un attaquant peut déposer du contenu piégé qui reste en attente et devient dangereux lors d'un export/import du site. À la clé, il peut finir par exécuter du code sur le serveur et prendre le contrôle du WordPress.
Le plugin est installé sur plus de 5 millions de sites et environ 3,2 millions seraient encore sur une version vulnérable.
👉 Si vous l'avez utilisé un jour pour migrer un site et qu'il traîne toujours dans vos plugins : vérifiez la version et passez au minimum en 7.110.
⬇️
"5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin"
👇
https://www.wordfence.com/blog/2026/09/5-million-wordpress-sites-affected-by-sql-injection-vulnerability-in-all-in-one-wp-migration-and-backup-wordpress-plugin
https://thecybersecguru.com/news/cve-2026-19949-wp-migration-rce/
##Si vous avez utilisé (et oublié 😅) All-in-One WP Migration and Backup sur votre #WordPress c'est peut-être le moment d'aller jeter un œil.
Une vulnérabilité assez vilaine, CVE-2026-19949, touche les versions jusqu'à 7.109.
Un attaquant peut déposer du contenu piégé qui reste en attente et devient dangereux lors d'un export/import du site. À la clé, il peut finir par exécuter du code sur le serveur et prendre le contrôle du WordPress.
Le plugin est installé sur plus de 5 millions de sites et environ 3,2 millions seraient encore sur une version vulnérable.
👉 Si vous l'avez utilisé un jour pour migrer un site et qu'il traîne toujours dans vos plugins : vérifiez la version et passez au minimum en 7.110.
⬇️
"5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin"
👇
https://www.wordfence.com/blog/2026/09/5-million-wordpress-sites-affected-by-sql-injection-vulnerability-in-all-in-one-wp-migration-and-backup-wordpress-plugin
https://thecybersecguru.com/news/cve-2026-19949-wp-migration-rce/
##Second-order SQL injection in All-in-One WP Migration and Backup restore function enables RCE, tracked as CVE-2026-19949. Affects versions up to 7.109, with ~3.2M sites exposed. Patch to 7.110 and audit for anomalous restore activity. #WordPressSecurity #SqlInjection #PatchManagement
https://cyberworldops.eu/en/wordpress-rce-vulnerability-in-all-in-one-wp-migration-exposes
##ServMask Patches Critical SQL Injection in All-in-One WP Migration Plugin
ServMask patched a high-severity SQL injection vulnerability (CVE-2026-19949) in the All-in-One WP Migration and Backup plugin. The flaw allows unauthenticated attackers to leak secret keys and execute remote code when an administrator restores a site archive.
**If you use the All-in-One WP Migration and Backup plugin, update it to version 7.110 or later ASAP. Even if the plugin is currently inactive, since it becomes dangerous the moment someone turns it on for a migration. Until you've patched, don't run any import or export, turn off trackbacks and pings on public posts, and check your comments for suspicious entries.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/servmask-patches-critical-sql-injection-in-all-in-one-wp-migration-plugin-r-t-z-8-z/gD2P6Ple2L
updated 2026-08-20T15:34:03
7 posts
1 repos
Critical Citrix NetScaler Authentication Bypass Is Now Being Exploited: CVE-2026-19490 Raises the Alarm for Exposed Networks + Video
A New Warning for NetScaler Administrators A critical authentication-bypass vulnerability affecting Citrix NetScaler has moved into a far more dangerous phase. CVE-2026-19490, rated 9.3/10 Critical under CVSS 4.0, affects NetScaler ADC and NetScaler Gateway and can allow an unauthenticated attacker to bypass authentication under specific…
##Previdian reports exploitation attempts targeting CVE-2026-19490, a critical authentication bypass in Citrix NetScaler ADC and Gateway. Exposure depends on firmware version and AAA virtual server configuration. Review exposed assets and authentication logs for anomalous access. #CitrixNetScaler #AuthBypass #ThreatIntel
https://cyberworldops.eu/en/citrix-netscaler-exploitation-attempts-target-critical-vulnerability
##Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability...
🔗️ [Bleepingcomputer] https://link.is.it/1ZYTCn
##Citrix NetScaler Under Attack: Critical CVE-2026-19490 Exploitation Attempts Raise the Alarm + Video
Introduction: Another NetScaler Warning Arrives at a Dangerous Time Citrix NetScaler administrators are facing another serious security warning, and this time the concern is no longer limited to a theoretical vulnerability or laboratory proof of concept. Security researchers have observed what appear to be real-world attempts to exploit CVE-2026-19490, a…
##Citrix NetScaler Flaw Exploited in Targeted Attacks
Citrix is urging customers to act fast to protect their NetScaler deployments from a critical flaw, known as CVE-2026-19490, that lets hackers bypass authentication and gain unauthorized access. To stay safe, review the security bulletin, check if your setup is vulnerable, and upgrade to the recommended build ASAP.
#Citrix #Cve202619490 #Netscaler #AuthenticationBypass #RemoteExploitation
##Previdian reports exploitation attempts targeting CVE-2026-19490, a critical authentication bypass in Citrix NetScaler ADC and Gateway. Exposure depends on firmware version and AAA virtual server configuration. Review exposed assets and authentication logs for anomalous access. #CitrixNetScaler #AuthBypass #ThreatIntel
https://cyberworldops.eu/en/citrix-netscaler-exploitation-attempts-target-critical-vulnerability
##Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability...
🔗️ [Bleepingcomputer] https://link.is.it/1ZYTCn
##updated 2026-08-19T18:32:57
12 posts
4 repos
https://github.com/sahmsec/CVE-2026-32475
https://github.com/absholi7ly/Elementor-Pro-Unauthenticated-Arbitrary-File-Upload-to-RCE
Hackers are actively exploiting the critical Elementor Pro CVE-2026-32475 vulnerability. The flaw allows unauthenticated PHP file uploads and site takeovers.
#ElementorPro #WordPressSecurity #CVE202632475 #CyberAttack #Malware
##Wordfence reports over 440,000 blocked exploitation attempts against CVE-2026-14894 in Super Forms and CVE-2026-32475 in Elementor Pro. Both allow unauthenticated arbitrary file upload leading to RCE, indicating mass opportunistic targeting of WordPress. #WordPressSecurity #RemoteCodeExecution #ThreatIntel
https://cyberworldops.eu/en/wordpress-under-attack-more-than-440000-attempts-target-super-forms
##WordPress Sites Targeted in Mass Exploits of Plugin Flaws
Hackers have launched over 440,000 exploit attempts on WordPress sites, targeting critical flaws in popular plugins Super Forms and Elementor Pro, with attackers seeking to upload malicious files and execute remote code. Two high-severity vulnerabilities, CVE-2026-14894 and CVE-2026-32475, were behind the attacks, and have since been…
#Wordpress #SupplyChain #PluginVulnerabilities #Cve202614894 #Cve202632475
##…et si vous utilisez Elementor Pro sur #WordPress encore une à vérifier rapidement 👀
CVE-2026-32475 CVSS 9.8
Upload arbitraire de fichiers sans authentification → possibilité d'uploader du PHP → RCE / takeover complet du site.
Et ce n’est plus théorique : exploitation active depuis le 19 août, avec déjà >190'000 tentatives bloquées par Wordfence.
Vulnérable jusqu’à Elementor Pro 4.2.1
Corrigé en 4.2.2
Condition intéressante : il faut qu’une page publiée utilise un widget Form avec un champ File Upload non obligatoire.
Si vous êtes concernés : patch rapidemment, puis petit contrôle de /wp-content/uploads/elementor/forms/ — un .php là-dedans mérite clairement votre attention.
👇 https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html
##Critical Elementor Pro Vulnerability Is Being Actively Exploited — WordPress Sites Face Webshells, Remote Code Execution, and Full Takeover + Video
A New Warning for Millions of WordPress Sites A critical security problem in Elementor Pro has moved from vulnerability disclosure to real-world exploitation, putting vulnerable WordPress websites directly in the crosshairs of attackers. Tracked as CVE-2026-32475, the flaw allows an unauthenticated attacker to abuse the…
##Hackers are actively exploiting the critical Elementor Pro CVE-2026-32475 vulnerability. The flaw allows unauthenticated PHP file uploads and site takeovers.
#ElementorPro #WordPressSecurity #CVE202632475 #CyberAttack #Malware
##Wordfence reports over 440,000 blocked exploitation attempts against CVE-2026-14894 in Super Forms and CVE-2026-32475 in Elementor Pro. Both allow unauthenticated arbitrary file upload leading to RCE, indicating mass opportunistic targeting of WordPress. #WordPressSecurity #RemoteCodeExecution #ThreatIntel
https://cyberworldops.eu/en/wordpress-under-attack-more-than-440000-attempts-target-super-forms
##…et si vous utilisez Elementor Pro sur #WordPress encore une à vérifier rapidement 👀
CVE-2026-32475 CVSS 9.8
Upload arbitraire de fichiers sans authentification → possibilité d'uploader du PHP → RCE / takeover complet du site.
Et ce n’est plus théorique : exploitation active depuis le 19 août, avec déjà >190'000 tentatives bloquées par Wordfence.
Vulnérable jusqu’à Elementor Pro 4.2.1
Corrigé en 4.2.2
Condition intéressante : il faut qu’une page publiée utilise un widget Form avec un champ File Upload non obligatoire.
Si vous êtes concernés : patch rapidemment, puis petit contrôle de /wp-content/uploads/elementor/forms/ — un .php là-dedans mérite clairement votre attention.
👇 https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html
##Critical Elementor Pro flaw exploited to take over WordPress sites
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a...
🔗️ [Bleepingcomputer] https://link.is.it/zUHe37
##Attackers exploit a critical Elementor Pro vulnerability (CVE-2026-32475) in the wild. Patch this Elementor Pro vulnerability to prevent site takeover.
##updated 2026-08-13T15:34:37
6 posts
1 repos
CVE-2026-6471 PostGREShell is an authorization flaw in PostgreSQL allowing REPLICATION users to execute arbitrary code as the server OS user. It affects versions since 2014 and enables escalation to superuser, making exposed replication accounts a critical risk. #PostgreSQL #CodeExecution #ThreatIntel
https://cyberworldops.eu/en/postgreshell-a-postgresql-flaw-turns-replication-accounts-into-a
##📰 12-Year-Old "PostGREShell" Flaw Threatens PostgreSQL Servers
A 12-year-old PostgreSQL flaw, "PostGREShell" (CVE-2026-6471), allows server takeover via replication privileges. Affects versions since 9.4. Patch immediately and audit all accounts with REPLICATION rights. #PostgreSQL #CyberSecurity #RCE
##PostgreSQL Patches 12-Year-Old Flaw Enabling Code Execution
A 12-year-old flaw in PostgreSQL, just patched, allowed replication users to execute arbitrary code on the database server, posing a significant security risk. The vulnerability, tracked as CVE-2026-6471, was exploitable by accounts with the REPLICATION attribute and has been fixed in releases 18.6, 17.11, 16.15, 15.19, and 14.24.
#Postgresql #Cve20266471 #CodeExecution #LogicalDecoding #DatabaseSecurity
##PostGREShell: Decade-Old PostgreSQL Flaw Turns Backup Accounts into Backdoors
PostgreSQL patched a vulnerability (CVE-2026-6471) that allows attackers with low-privilege replication access to execute arbitrary code and gain full superuser control. The flaw, present since 2014, enables persistent backdoor access across Windows, Linux, and macOS environments.
**If you run PostgreSQL, update immediately to version 18.6, 17.11, 16.15, 15.19, or 14.24 to fix CVE-2026-6471. Then review who has the REPLICATION permission and remove it from anyone who doesn't need it, restrict replication access in `pg_hba.conf` to trusted IP addresses only, and block outbound SMB and NFS traffic from your database servers.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/postgreshell-decade-old-postgresql-flaw-turns-backup-accounts-into-backdoors-8-u-r-l-n/gD2P6Ple2L
CVE-2026-6471 PostGREShell is an authorization flaw in PostgreSQL allowing REPLICATION users to execute arbitrary code as the server OS user. It affects versions since 2014 and enables escalation to superuser, making exposed replication accounts a critical risk. #PostgreSQL #CodeExecution #ThreatIntel
https://cyberworldops.eu/en/postgreshell-a-postgresql-flaw-turns-replication-accounts-into-a
##PostGREShell: Decade-Old PostgreSQL Flaw Turns Backup Accounts into Backdoors
PostgreSQL patched a vulnerability (CVE-2026-6471) that allows attackers with low-privilege replication access to execute arbitrary code and gain full superuser control. The flaw, present since 2014, enables persistent backdoor access across Windows, Linux, and macOS environments.
**If you run PostgreSQL, update immediately to version 18.6, 17.11, 16.15, 15.19, or 14.24 to fix CVE-2026-6471. Then review who has the REPLICATION permission and remove it from anyone who doesn't need it, restrict replication access in `pg_hba.conf` to trusted IP addresses only, and block outbound SMB and NFS traffic from your database servers.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/postgreshell-decade-old-postgresql-flaw-turns-backup-accounts-into-backdoors-8-u-r-l-n/gD2P6Ple2L
updated 2026-07-30T18:23:34
1 posts
7 repos
https://github.com/shinthink/CVE-2026-66066
https://github.com/0xsha/KindaRails2Shell
https://github.com/0xBlackash/CVE-2026-66066
https://github.com/rails/rails-forensics-CVE-2026-66066
https://github.com/HackSpeak/CVE-2026-66066
Government Rails Site Hit Hours After CVE Patch
Ruby on Rails 8 이상 Active Storage의 임의 파일 읽기·원격 코드 실행 취약점 CVE-2026-66066(KindaRails2Shell, CVSS 9.5)이 패치 공개 직후 실제 공격 시도에 사용된 사례다. 운영사 Rietta는 7월 29일 긴급 패치를 배포했지만, 공개 PoC가 배포 완료 전 GitHub에 올라왔고 한 정부기관 고객 환경에서는 배포 약 8시간 뒤 악성 BMP 업로드 기반 탐지가 기록됐다고 밝혔다. 이후에는 PNG 위장 파일, 회전 IP, 다양한 User-Agent를 활용한 지속 스캐닝이 관측됐으며, 패치 diff만으로도 공격 체...
https://rietta.com/blog/ruby-on-rails-cve-exploited-hours-after-patch/
##updated 2026-07-28T19:32:10.027000
1 posts
CVE-2026-43748 (CVSS 9.8) is an Apple ANE kernel OOB write reachable from a sandbox. Full details and macOS/iOS PoC code are now public. Update now.
#Apple #CVE202643748 #iOS #macOS #KernelBug #InfoSec #ANE
https://securityonline.info/apple-ane-cve-2026-43748/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-07-25T00:31:53
2 posts
Tycon TPDIN-Monitor-WEB2 before 2.4.5 is affected by CVE-2026-61884, a critical web authentication bypass allowing full admin access, and CVE-2026-55985 exposing cleartext credentials. Exposed OT monitoring units risk relay manipulation and config takeover. #TyconSystems #IcsSecurity #VulnManagement
https://cyberworldops.eu/en/tycon-tpdin-monitor-web2-two-flaws-expose-relays-and-configurations-to
##Tycon TPDIN-Monitor-WEB2 before 2.4.5 is affected by CVE-2026-61884, a critical web authentication bypass allowing full admin access, and CVE-2026-55985 exposing cleartext credentials. Exposed OT monitoring units risk relay manipulation and config takeover. #TyconSystems #IcsSecurity #VulnManagement
https://cyberworldops.eu/en/tycon-tpdin-monitor-web2-two-flaws-expose-relays-and-configurations-to
##updated 2026-07-22T22:38:34
6 posts
1 repos
(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-59822 – BerriAI LiteLLM Improper Authentication Vulnerability
BerriAI LiteLLM is impacted by CVE-2026-59822, enabling unauthenticated attackers to bypass token validation. Review detection queries, compensating controls, and patching guides....
##(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-59822 – BerriAI LiteLLM Improper Authentication Vulnerability
BerriAI LiteLLM is impacted by CVE-2026-59822, enabling unauthenticated attackers to bypass token validation. Review detection queries, compensating controls, and patching guides....
##Mitigate CVE-2026-59822 in BerriAI LiteLLM. Unauthenticated attackers bypass token checks on MCP endpoints. Read our T-Suite brief for Splunk, Sentinel, and Chronicle detection rules, plus vital hardening controls to lock down your AI infrastructure today. https://thecybermind.co/5vrg
##Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.
- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-83549
- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-83548
- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-9586
- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-82329
- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-49869
- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-48710
- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-59822 #CISA #infosec #vulnerability
##🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-48710 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48710)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-48710
⚠️ CVE-2026-49869 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-49869)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjx ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-49869
⚠️ CVE-2026-59822 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59822)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-59822
⚠️ CVE-2026-82329 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82329)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-82329
⚠️ CVE-2026-83548 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-83548)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-83548
⚠️ CVE-2026-83549 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-83549)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-83549
⚠️ CVE-2026-9586 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9586)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-9586
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586
##CVE ID: CVE-2026-59822
Vendor: BerriAI
Product: LiteLLM
Date Added: 2026-09-02
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-59822
updated 2026-07-22T19:10:00.120000
2 posts
🟠 CVE-2026-85505 - High (7.5)
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has differe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85505/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85505 - High (7.5)
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has differe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85505/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-16T19:40:53
1 posts
🟠 CVE-2026-52833 - High (8)
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function builds using Go's text/template package. The template renders runtimeAttribut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52833/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-14T20:28:19
2 posts
🟠 CVE-2026-61699 - High (8.1)
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches any peer's c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61699/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-61699 - High (8.1)
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches any peer's c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61699/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-14T15:32:25
1 posts
RE: https://infosec.exchange/@andersonc0d3/117197828727921773
The exception table mechanism in the page fault handler is popular, but maybe the mechanism in the general protection handler isn't so well-known.
When the code is interacting with MSRs, if the MSR index/address is invalid for the architecture, it triggers a #GP and the kernel oopses. This can happen in some scenarios and most of the cases it shouldn't trigger an oops and crash the kernel. That's why there are two MSR access implementations: rdmsr() / rdmsrq() and rdmsr_safe() / rdmsrq_safe(). The rdmsr variants use split 32-bit values for high/low bits, while rdmsrq handles 64-bit quadwords directly.
There is a proposal to retire legacy 32-bit user-space MSR interfaces, but I haven't followed this closely.
Linux Preparing To Retire Its 32-bit MSR Interfaces
https://www.phoronix.com/news/Linux-Ending-32-bit-MSR-Work
The safe ones are supposed to not crash/oops the kernel when the #GP is issued. It implements the same exception table mechanism present in the page fault handler. That's why it contains *_safe() in the function name.
This is checked by the general protection fault handler via fixup_exception() at line below:
https://github.com/torvalds/linux/blob/master/arch/x86/kernel/traps.c#L949
There was an oops caused by the use of rdmsrl() when running the Linux kernel as a Xen guest and the fix was to replace rdmsrl() with rdmsrl_safe().
CVE-2025-21913: x86/amd_nb: Use rdmsr_safe() in amd_get_mmconfig_range()
https://lore.kernel.org/linux-cve-announce/2025040130-CVE-2025-21913-b942@gregkh/T
x86/amd_nb: Use rdmsr_safe() in amd_get_mmconfig_range()
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=14cb5d83068ecf15d2da6f7d0e9ea9edbcbc0457
The interface was rdmsrl before being renamed to rdmsrq.
In the case of virtualization, things get more complicated because the hypervisor might have different configurations. That issue in the Linux kernel seems to have been exposed due to a change in Xen regarding MSRs accesses.
xen/pv: support selecting safe/unsafe msr accesses https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3fac3734c43a2e21fefeb72124d8bd31dff3956f
##updated 2026-07-10T06:31:28
7 posts
2 repos
Wordfence reports over 440,000 blocked exploitation attempts against CVE-2026-14894 in Super Forms and CVE-2026-32475 in Elementor Pro. Both allow unauthenticated arbitrary file upload leading to RCE, indicating mass opportunistic targeting of WordPress. #WordPressSecurity #RemoteCodeExecution #ThreatIntel
https://cyberworldops.eu/en/wordpress-under-attack-more-than-440000-attempts-target-super-forms
##WordPress Sites Targeted in Mass Exploits of Plugin Flaws
Hackers have launched over 440,000 exploit attempts on WordPress sites, targeting critical flaws in popular plugins Super Forms and Elementor Pro, with attackers seeking to upload malicious files and execute remote code. Two high-severity vulnerabilities, CVE-2026-14894 and CVE-2026-32475, were behind the attacks, and have since been…
#Wordpress #SupplyChain #PluginVulnerabilities #Cve202614894 #Cve202632475
##CVE-2026-14894, a critical Super Forms vulnerability, is exploited in the wild. The 9.8 CVSS file upload flaw enables unauthenticated remote code execution.
#SuperForms #WordPress #CVE202614894 #RCE #FileUpload #WebSecurity #InfoSec #ExploitedInTheWild
##Wordfence reports over 440,000 blocked exploitation attempts against CVE-2026-14894 in Super Forms and CVE-2026-32475 in Elementor Pro. Both allow unauthenticated arbitrary file upload leading to RCE, indicating mass opportunistic targeting of WordPress. #WordPressSecurity #RemoteCodeExecution #ThreatIntel
https://cyberworldops.eu/en/wordpress-under-attack-more-than-440000-attempts-target-super-forms
##CVE-2026-14894, a critical Super Forms vulnerability, is exploited in the wild. The 9.8 CVSS file upload flaw enables unauthenticated remote code execution.
#SuperForms #WordPress #CVE202614894 #RCE #FileUpload #WebSecurity #InfoSec #ExploitedInTheWild
##updated 2026-07-09T20:52:58
2 posts
🟠 CVE-2026-53932 - High (8)
laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53932/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-53932 - High (8)
laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53932/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-08T20:27:04
1 posts
🔴 CVE-2026-53649 - Critical (9.6)
Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelisted multip...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53649/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-08T20:25:04
1 posts
🟠 CVE-2026-49832 - High (8)
DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 10-rc1, Remote Code Execution (RCE) is possible via Veloci...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49832/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-08T20:24:21
1 posts
🟠 CVE-2026-52831 - High (8)
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container (/bin/sh,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52831/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-08T15:31:44
4 posts
‼️ Exploit disclosed for CVE-2026-52924... 9.8 CVSS Linux Root Privilege Escalation
##Security researchers released a Linux CVE-2026-52924 PoC exploit. Check flaw details and patch instructions to secure your systems against root takeovers.
#Linux #CyberSecurity #CVE202652924 #PoC #PrivilegeEscalation
https://securityonline.info/linux-cve-2026-52924-poc/?utm_source=mastodon&utm_medium=jetpack_social
##‼️ Exploit disclosed for CVE-2026-52924... 9.8 CVSS Linux Root Privilege Escalation
##Security researchers released a Linux CVE-2026-52924 PoC exploit. Check flaw details and patch instructions to secure your systems against root takeovers.
#Linux #CyberSecurity #CVE202652924 #PoC #PrivilegeEscalation
https://securityonline.info/linux-cve-2026-52924-poc/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-06-18T15:32:09
1 posts
🔄 CSAF advisory updated (version 2.0.0)
VDE-2026-051
iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator
CVE-2026-8024
Changes: Added ibaLogic to the affected products and the mitigation for this product.
HTML: https://certvde.com/en/advisories/VDE-2026-051
CSAF JSON: https://iba.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-051.json
updated 2026-06-17T10:11:20.937000
4 posts
2 repos
🏆 New Achievement! Cursed Component (Soulbound, No Refund)!
Item tooltip: Langflow Custom Component Editor. Rarity: Critical. Effect: Grants unauthenticated remote attackers the ability to execute arbitrary Python code as root via CVE-2026-0768 (CVSS 9.8). Hidden stat: "Code Validator" passive is, in fact, entirely decorative. VulnCheck has confirmed active in-the-wild exploitation is already underway, so the item has been equipped for you. You did not consent to this. (1/2)
##🏆 New Achievement! Cursed Component (Soulbound, No Refund)!
Item tooltip: Langflow Custom Component Editor. Rarity: Critical. Effect: Grants unauthenticated remote attackers the ability to execute arbitrary Python code as root via CVE-2026-0768 (CVSS 9.8). Hidden stat: "Code Validator" passive is, in fact, entirely decorative. VulnCheck has confirmed active in-the-wild exploitation is already underway, so the item has been equipped for you. You did not consent to this. (1/2)
##Attackers exploit Langflow CVE-2026-0768, an unauthenticated root RCE, to harvest OpenAI and AWS keys and admin credentials from exposed AI servers.
#Langflow #CVE20260768 #VulnCheck #OpenAI #AWS
https://meterpreter.org/langflow-cve-2026-0768/?utm_source=mastodon&utm_medium=jetpack_social
##Hackers Exploit Zero-Day in Langflow AI Platform to Steal Credentials
Langflow's AI platform is under active attack via a zero-day vulnerability (CVE-2026-0768) that allows unauthenticated remote code execution as root. Attackers are using the flaw to steal environment variables, secret keys, and SSH credentials from vulnerable instances.
**If you use Langflow, this is important and urgent. Make sure the server is isolated from the internet and reachable only from trusted internal networks or via VPN. There is no patch for this flaw and attackers are already exploiting it to steal secrets. Treat any internet-exposed instance as potentially compromised and rotate every API key, token and password stored in or used by it.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/hackers-exploit-zero-day-in-langflow-ai-platform-to-steal-credentials-i-v-p-l-s/gD2P6Ple2L
updated 2026-06-17T07:03:46.833000
2 posts
1 repos
CVE data pipeline got bloated? Query CVE, vendor, and exploit intel with one call: curl https://api.valtersit.com/cve/CVE-2024-1234. Metered, no key overhead, built for devs. Docs at valtersit.com/cve/pricing/.
##Structured CVE data without the scraping grind. Pull vendor, exploit, and CPE fields in one JSON call:
curl -H "Authorization: Bearer $KEY" https://api.valtersit.com/cve/CVE-2024-1234
Metered pricing, pay for what you use. Docs: https://www.valtersit.com/cve/pricing/
##updated 2026-06-17T04:09:31.687000
1 posts
1 repos
CISA reports CVE-2021-42260, a DoS vulnerability in Rockwell Automation ControlLogix, CompactLogix and GuardLogix controllers. The CWE-835 infinite loop is triggered by crafted data and results in a Major Non-Recoverable Fault requiring manual recovery, posing high availability risk for OT environments. #RockwellAutomation #ControlLogix #IcsSecurity
https://cyberworldops.eu/en/rockwell-automation-dos-vulnerability-in-controllogix-and-compactlogix
##updated 2026-06-04T15:05:58
1 posts
🟠 CVE-2026-45730 - High (8.3)
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard's project management API, allowing any authenticated user (without membership in the target project)...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45730/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-15T18:30:32
1 posts
1 repos
📢 CVE-2026-42897 : TA488 exploite une XSS stockée dans Exchange OWA via l'implant OWAReaper
Cet article constitue une analyse technique approfondie de la vulnérabilité CVE-2026-42897 et de la campagne d'exploitation associée menée par le groupe TA488 (également connu sous les noms Void Blizzard et Laundry Bear), acteur étatique russe.
📖 cyberveille : https://cyberveille.ch/posts/2026-09-04-cve-2026-42897-ta488-exploite-une-xss-stockee-dans-exchange-owa-via-l-implant-owareaper/
🌐 source : https://www.resecurity.com/blog/article/inside-owareaper-how-cve-2026-42897-enables-persistent-exchange-mailbox-compromise
🟢 vérification factuelle haute
#ExchangeOWA #OWAReaper #Cyberveille
updated 2025-10-22T19:13:26
2 posts
100 repos
https://github.com/CERTCC/CVE-2021-44228_scanner
https://github.com/justakazh/Log4j-CVE-2021-44228
https://github.com/pedrohavay/exploit-CVE-2021-44228
https://github.com/DragonSurvivalEU/RCE
https://github.com/CrackerCat/CVE-2021-44228-Log4j-Payloads
https://github.com/corelight/cve-2021-44228
https://github.com/fireeye/CVE-2021-44228
https://github.com/sec13b/CVE-2021-44228-POC
https://github.com/CodeShield-Security/Log4JShell-Bytecode-Detector
https://github.com/puzzlepeaches/Log4jUnifi
https://github.com/wortell/log4j
https://github.com/jas502n/Log4j2-CVE-2021-44228
https://github.com/Azeemering/CVE-2021-44228-DFIR-Notes
https://github.com/dtact/divd-2021-00038--log4j-scanner
https://github.com/Diverto/nse-log4shell
https://github.com/yahoo/check-log4j
https://github.com/marcourbano/CVE-2021-44228
https://github.com/MalwareTech/Log4jTools
https://github.com/mr-r3b00t/CVE-2021-44228
https://github.com/tippexs/nginx-njs-waf-cve2021-44228
https://github.com/cisagov/log4j-scanner
https://github.com/TaroballzChen/CVE-2021-44228-log4jVulnScanner-metasploit
https://github.com/faisalfs10x/Log4j2-CVE-2021-44228-revshell
https://github.com/NCSC-NL/log4shell
https://github.com/fox-it/log4j-finder
https://github.com/HynekPetrak/log4shell-finder
https://github.com/simonis/Log4jPatch
https://github.com/corretto/hotpatch-for-apache-log4j2
https://github.com/takito1812/log4j-detect
https://github.com/darkarnium/Log4j-CVE-Detect
https://github.com/roxas-tan/CVE-2021-44228
https://github.com/claranet/ansible-role-log4shell
https://github.com/KosmX/CVE-2021-44228-example
https://github.com/momos1337/Log4j-RCE
https://github.com/HyCraftHD/Log4J-RCE-Proof-Of-Concept
https://github.com/alexandre-lavoie/python-log4rce
https://github.com/mubix/CVE-2021-44228-Log4Shell-Hashes
https://github.com/LiveOverflow/log4shell
https://github.com/Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228
https://github.com/lfama/log4j_checker
https://github.com/cyberxml/log4j-poc
https://github.com/blake-fm/vcenter-log4j
https://github.com/qingtengyun/cve-2021-44228-qingteng-online-patch
https://github.com/0xInfection/LogMePwn
https://github.com/stripe/log4j-remediation-tools
https://github.com/alexbakker/log4shell-tools
https://github.com/nu11secur1ty/CVE-2021-44228-VULN-APP
https://github.com/mzlogin/CVE-2021-44228-Demo
https://github.com/thecyberneh/Log4j-RCE-Exploiter
https://github.com/sunnyvale-it/CVE-2021-44228-PoC
https://github.com/mr-vill4in/log4j-fuzzer
https://github.com/future-client/CVE-2021-44228
https://github.com/infiniroot/nginx-mitigate-log4shell
https://github.com/0xDexter0us/Log4J-Scanner
https://github.com/Adikso/minecraft-log4j-honeypot
https://github.com/NS-Sp4ce/Vm4J
https://github.com/fullhunt/log4j-scan
https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words
https://github.com/nccgroup/log4j-jndi-be-gone
https://github.com/dwisiswant0/look4jar
https://github.com/hackinghippo/log4shell_ioc_ips
https://github.com/Jeromeyoung/log4j2burpscanner
https://github.com/1lann/log4shelldetect
https://github.com/Nanitor/log4fix
https://github.com/puzzlepeaches/Log4jHorizon
https://github.com/RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs
https://github.com/Kadantte/CVE-2021-44228-poc
https://github.com/leonjza/log4jpwn
https://github.com/boundaryx/cloudrasp-log4j2
https://github.com/kubearmor/log4j-CVE-2021-44228
https://github.com/giterlizzi/nmap-log4shell
https://github.com/ssl/scan4log4j
https://github.com/irgoncalves/f5-waf-enforce-sig-CVE-2021-44228
https://github.com/aws-samples/kubernetes-log4j-cve-2021-44228-node-agent
https://github.com/logpresso/CVE-2021-44228-Scanner
https://github.com/mergebase/log4j-detector
https://github.com/mufeedvh/log4jail
https://github.com/lucab85/log4j-cve-2021-44228
https://github.com/BinaryDefense/log4j-honeypot-flask
https://github.com/greymd/CVE-2021-44228
https://github.com/bigsizeme/Log4j-check
https://github.com/thomaspatzke/Log4Pot
https://github.com/puzzlepeaches/Log4jCenter
https://github.com/twseptian/spring-boot-log4j-cve-2021-44228-docker-lab
https://github.com/toramanemre/log4j-rce-detect-waf-bypass
https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce
https://github.com/AlexandreHeroux/Fix-CVE-2021-44228
https://github.com/NorthwaveSecurity/log4jcheck
https://github.com/toramanemre/apache-solr-log4j-CVE-2021-44228
https://github.com/redhuntlabs/Log4JHunt
https://github.com/CreeperHost/Log4jPatcher
https://github.com/irgoncalves/f5-waf-quick-patch-cve-2021-44228
https://github.com/rubo77/log4j_checker_beta
https://github.com/f0ng/log4j2burpscanner
https://github.com/kozmer/log4j-shell-poc
https://github.com/christophetd/log4shell-vulnerable-app
https://github.com/qingtengyun/cve-2021-44228-qingteng-patch
https://github.com/Labout/log4shell-rmi-poc
https://github.com/back2root/log4shell-rex
https://github.com/r3kind1e/Log4Shell-obfuscated-payloads-generator
🟠 CVE-2026-85656 - High (7.8)
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85656/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85656 - High (7.8)
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85656/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2023-01-30T05:05:55
1 posts
Forescout Research demonstrated porting a pre-auth RCE exploit for CVE-2021-31886 to a different WAGO PLC model using Anthropic Claude, achieving unauthenticated ARM shellcode execution on physical hardware. It shows how LLMs can accelerate exploit adaptation across OT variants, expanding exposure for unpatched systems. #Cve202131886 #OtSecurity #PlcSecurity
https://cyberworldops.eu/en/claude-adapts-an-rce-exploit-to-a-wago-plc-arm-shellcode-executed
##Broadcom patched two VM escape flaws in VMware Workstation and Fusion. CVE-2026-59346 is an integer overflow in VMXNET3 (CVSS 9.3) allowing host code execution from a privileged VM guest. High risk for dev and lab environments relying on VM isolation. #VmEscape #InfoSec #Virtualization
https://cyberworldops.eu/en/vmware-workstation-and-fusion-two-flaws-allow-escape-from-the-virtual
##Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion
Broadcom patched two critical VM-escape vulnerabilities in VMware Workstation and Fusion (CVE-2026-59346 and CVE-2026-59347) that allow attackers with guest admin privileges to execute code on the host system.
**If you use VMware Workstation or Fusion (versions 25H2 or 26H1), update to 26H1u1 ASAP. Tthere is no workaround or setting that protects you from these flaws. Prioritize the machines that run untrusted code, malware analysis as well as any third party hosting, since an attacker inside a VM can break out and take over your host and from there reach your network.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/broadcom-patches-critical-vm-escape-flaws-in-vmware-workstation-and-fusion-n-9-h-5-0/gD2P6Ple2L
Broadcom patched two VM escape flaws in VMware Workstation and Fusion. CVE-2026-59346 is an integer overflow in VMXNET3 (CVSS 9.3) allowing host code execution from a privileged VM guest. High risk for dev and lab environments relying on VM isolation. #VmEscape #InfoSec #Virtualization
https://cyberworldops.eu/en/vmware-workstation-and-fusion-two-flaws-allow-escape-from-the-virtual
##Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion
Broadcom patched two critical VM-escape vulnerabilities in VMware Workstation and Fusion (CVE-2026-59346 and CVE-2026-59347) that allow attackers with guest admin privileges to execute code on the host system.
**If you use VMware Workstation or Fusion (versions 25H2 or 26H1), update to 26H1u1 ASAP. Tthere is no workaround or setting that protects you from these flaws. Prioritize the machines that run untrusted code, malware analysis as well as any third party hosting, since an attacker inside a VM can break out and take over your host and from there reach your network.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/broadcom-patches-critical-vm-escape-flaws-in-vmware-workstation-and-fusion-n-9-h-5-0/gD2P6Ple2L
CVE-2026-59346, a critical VMware Workstation vulnerability, lets an attacker escape a guest VM and execute code on the host. Broadcom rates it 9.3 CVSS.
#VMware #Workstation #Fusion #CVE202659346 #VMXNET3 #Broadcom #InfoSec #PatchNow
##🟠 CVE-2026-63464 - High (7.7)
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/webhook-sub...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63464/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63464 - High (7.7)
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/webhook-sub...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63464/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85786 - High (7.5)
Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression due to insuff...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85786/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85786 - High (7.5)
Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression due to insuff...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85786/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-44506: Medplum 4.1.10–5.1.6 leaks OAuth client_secrets via /oauth2/register. High severity (CVSS 8.2). Patched in 5.1.7—update now if you use defaultOAuthClients. Details: https://www.valtersit.com/cve/CVE-2026-44506/ #CVE #infosec #Medplum
##🟠 CVE-2026-85781 - High (8.7)
Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion of direct...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85781/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver
Bulletin ID: 2026-099-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 11:45 AM PDT
Description:
The Amazon EFS CSI Driver is an open-source Kubernetes Container Storage Interface (CSI) dr...
https://aws.amazon.com/security/security-bulletins/rss/2026-099-aws/
##🟠 CVE-2026-85781 - High (8.7)
Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion of direct...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85781/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver
Bulletin ID: 2026-099-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 11:45 AM PDT
Description:
The Amazon EFS CSI Driver is an open-source Kubernetes Container Storage Interface (CSI) dr...
https://aws.amazon.com/security/security-bulletins/rss/2026-099-aws/
##A critical WHMCS security update fixes CVE-2026-67399 and CVE-2026-67398. Apply the patch now to prevent remote code execution and data leaks.
##A critical WHMCS security update fixes CVE-2026-67399 and CVE-2026-67398. Apply the patch now to prevent remote code execution and data leaks.
##CVE-2026-85012 - Command Injection in AWS codecatalyst-blueprints. Arbitrary command execution via crafted .ownership-file. CVSS 8.0. Update to v0.3.156 now. #CVE #AWS #infosec
##🟠 CVE-2026-85012 - High (8)
Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the pro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85012/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-85012 - High (8)
Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the pro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85012/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion
Broadcom patched two critical VM-escape vulnerabilities in VMware Workstation and Fusion (CVE-2026-59346 and CVE-2026-59347) that allow attackers with guest admin privileges to execute code on the host system.
**If you use VMware Workstation or Fusion (versions 25H2 or 26H1), update to 26H1u1 ASAP. Tthere is no workaround or setting that protects you from these flaws. Prioritize the machines that run untrusted code, malware analysis as well as any third party hosting, since an attacker inside a VM can break out and take over your host and from there reach your network.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/broadcom-patches-critical-vm-escape-flaws-in-vmware-workstation-and-fusion-n-9-h-5-0/gD2P6Ple2L
Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion
Broadcom patched two critical VM-escape vulnerabilities in VMware Workstation and Fusion (CVE-2026-59346 and CVE-2026-59347) that allow attackers with guest admin privileges to execute code on the host system.
**If you use VMware Workstation or Fusion (versions 25H2 or 26H1), update to 26H1u1 ASAP. Tthere is no workaround or setting that protects you from these flaws. Prioritize the machines that run untrusted code, malware analysis as well as any third party hosting, since an attacker inside a VM can break out and take over your host and from there reach your network.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/broadcom-patches-critical-vm-escape-flaws-in-vmware-workstation-and-fusion-n-9-h-5-0/gD2P6Ple2L
🔴 CVE-2026-58400 - Critical (9.1)
GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58400/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-58400 - Critical (9.1)
GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58400/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-49869 – Kestra OSS OS Command Injection Vulnerability
Active CISA KEV exploitation of CVE-2026-49869 exposes Kestra OSS to remote OS command injection. Explore board-ready governance, asset enumeration, and risk mitigation....
##(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-49869 – Kestra OSS OS Command Injection Vulnerability
Active CISA KEV exploitation of CVE-2026-49869 exposes Kestra OSS to remote OS command injection. Explore board-ready governance, asset enumeration, and risk mitigation....
##Critical vulnerability CVE-2026-49869 strikes Kestra OSS with active CISA KEV exploitation. Unauthenticated attackers can execute arbitrary OS commands. Read our strategic T-Suite brief for telemetry analysis, CrowdStrike detection queries, and rapid perimeter hardening steps. https://thecybermind.co/23yx
##Looks like CISA's on a roll. Seven vulnerabilities have been added to the catalogue.
- CVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-83549
- CVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-83548
- CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-9586
- CVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-82329
- CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-49869
- CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-48710
- CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-59822 #CISA #infosec #vulnerability
##🚨 [CISA-2026:0902] CISA Adds 7 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0902)
CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-48710 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48710)
- Name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kludex
- Product: Starlette
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-48710
⚠️ CVE-2026-49869 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-49869)
- Name: Kestra OSS OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kestra
- Product: Kestra OSS
- Notes: This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjx ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-49869
⚠️ CVE-2026-59822 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-59822)
- Name: BerriAI LiteLLM Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: BerriAI
- Product: LiteLLM
- Notes: https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-59822
⚠️ CVE-2026-82329 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-82329)
- Name: JFrog Artifactory Improper Authentication Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: JFrog
- Product: Artifactory
- Notes: https://docs.jfrog.com/releases/docs/jfrog-security-advisories ; https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-82329
⚠️ CVE-2026-83548 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-83548)
- Name: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-83548
⚠️ CVE-2026-83549 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-83549)
- Name: SonicWall SMA1000 Appliances OS Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: SonicWall
- Product: SMA1000 Appliances
- Notes: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-83549
⚠️ CVE-2026-9586 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-9586)
- Name: Sangoma Switchvox SQL Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Sangoma
- Product: Switchvox
- Notes: https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-9586
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260902 #cisa20260902 #cve_2026_48710 #cve_2026_49869 #cve_2026_59822 #cve_2026_82329 #cve_2026_83548 #cve_2026_83549 #cve_2026_9586 #cve202648710 #cve202649869 #cve202659822 #cve202682329 #cve202683548 #cve202683549 #cve20269586
##CVE ID: CVE-2026-49869
Vendor: Kestra
Product: Kestra OSS
Date Added: 2026-09-02
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49869
A critical Prompty vulnerability (CVE-2026-73299, CVSS 10) let a crafted .prompty file escape the template engine and run arbitrary JavaScript in Node.js.
#Prompty #Microsoft #SSTI #RCE #CVE202673299
https://meterpreter.org/prompty-cve-2026-73299/?utm_source=mastodon&utm_medium=jetpack_social
##🟠 CVE-2026-53635 - High (7.6)
Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/instructor/views/instructor_dashboard.py:430 is decorated only with @login_r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53635/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84394 - High (7.5)
fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but does not end with a closing bracket is neither validated as an IP literal nor canonicaliz...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84394/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84851 - High (7.5)
An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84851/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84382 - High (7.5)
HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bounded piec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84382/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-84381 - High (8.1)
HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 pr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84381/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-55221 | malach-it boruta-server (MEDIUM): Versions before 0.10.0 log OAuth/OpenID tokens in business event logs. Credentials at risk if logs are accessed. Patch to v0.10.0. https://radar.offseq.com/threat/cve-2026-55221-cwe-532-insertion-of-sensitive-information-into-log-file-in-malach-it-boruta-server-f5751fd8f7f14e52 #OffSeq #Vuln #OAuth #LogSecurity
##