## Updated at UTC 2026-10-06T17:11:31.991325

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-76105 7.7 0.00% 2 0 2026-10-06T16:17:10 Dell Container Storage Modules, versions prior to 1.18.0 contain(s) an Use of In
CVE-2026-67273 9.6 0.00% 2 0 2026-10-06T16:17:09.717000 Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Improper
CVE-2026-67270 8.2 0.00% 2 0 2026-10-06T16:17:09.580000 Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Impro
CVE-2026-61411 7.7 0.00% 2 0 2026-10-06T16:17:08.693000 Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertio
CVE-2026-105845 9.8 0.00% 2 0 2026-10-06T16:17:06.540000 Payload is a free and open source headless content management system. In version
CVE-2026-105223 7.4 0.20% 1 0 2026-10-06T16:08:43.180000 maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verificat
CVE-2026-77226 8.1 0.69% 1 0 2026-10-06T16:08:27.613000 Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability
CVE-2026-104711 9.8 0.36% 1 0 2026-10-06T15:32:48 Improper neutralization of special elements used in an expression language state
CVE-2026-59265 8.8 0.22% 2 1 2026-10-06T15:32:32 A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and
CVE-2026-21589 None 0.74% 8 1 2026-10-06T15:31:47 h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data C
CVE-2026-63692 10.0 0.00% 2 0 2026-10-06T15:18:44.910000 Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing A
CVE-2026-84411 9.8 0.95% 2 0 2026-10-06T15:15:48.310000 The web management service in affected RouterOS versions contains an integer und
CVE-2026-79820 9.0 0.27% 1 0 2026-10-06T15:15:48.310000 A remote user validation failure vulnerability exists in HPE Integrated Lights-O
CVE-2026-91140 9.6 0.00% 2 0 2026-10-06T15:09:20.387000 An OS command injection vulnerability in the shell-based temporary-file cleanup
CVE-2026-92931 8.8 0.26% 3 0 2026-10-06T15:09:20.387000 CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs
CVE-2026-91107 0 0.24% 1 0 2026-10-06T15:08:38.397000 openSIS Classic 9.3 allows an authenticated user with the built-in teacher role
CVE-2026-103510 0 0.35% 1 0 2026-10-06T15:08:38.397000 P4 Search prior to 2026.4.2 does not fail securely when its service authenticati
CVE-2026-20519 7.5 0.23% 1 0 2026-10-06T15:05:34.080000 In Modem, there is a possible out of bounds write due to a missing bounds check.
CVE-2026-105778 9.9 0.48% 1 0 2026-10-06T15:04:52.637000 A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this
CVE-2026-100511 8.8 0.36% 1 0 2026-10-06T15:04:25.990000 Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Pos
CVE-2026-97283 9.8 0.36% 1 0 2026-10-06T15:04:25.990000 Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanc
CVE-2026-104389 8.5 0.26% 1 0 2026-10-06T15:04:25.990000 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-105642 8.8 0.25% 1 0 2026-10-06T15:03:59.427000 Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image
CVE-2026-49885 7.8 0.07% 1 0 2026-10-06T14:49:40.823000 In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due
CVE-2026-55269 7.8 0.07% 1 0 2026-10-06T14:49:40.823000 In FilterCapturedPacket of snoop_logger.cc, there is a possible memory safety is
CVE-2026-58835 8.8 0.23% 1 0 2026-10-06T14:49:40.823000 In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a
CVE-2026-71885 0 0.19% 3 0 2026-10-06T14:49:40.823000 In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 94
CVE-2026-71886 0 0.17% 1 0 2026-10-06T14:49:40.823000 In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API ac
CVE-2026-103831 None 0.00% 1 0 2026-10-06T12:30:32 CVE-2026-103831: Insecure deserialization vulnerability in the Psr16CacheAdapter
CVE-2026-41555 9.3 0.25% 2 0 2026-10-06T09:31:35 Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptio
CVE-2026-42415 9.3 0.25% 2 0 2026-10-06T09:31:35 Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions.
CVE-2026-42417 9.3 0.33% 1 0 2026-10-06T09:31:35 Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions.
CVE-2026-94293 9.8 0.35% 3 0 2026-10-06T09:31:31 An unauthenticated remote attacker can modify Asset Administration Shell submode
CVE-2026-75962 7.2 0.28% 1 0 2026-10-06T06:30:43 The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs,
CVE-2026-105484 10.0 2.13% 1 0 2026-10-06T03:31:28 A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230
CVE-2026-105782 7.5 0.38% 1 0 2026-10-05T23:09:00 ### Impact Since version 1.4.0, Scrapy respects the `Referrer-Policy` response
CVE-2026-103922 9.3 0.21% 1 1 2026-10-05T22:53:12 ### Impact Capacitor's WebView navigation guard validated only the **host and s
CVE-2026-103066 8.5 0.26% 1 0 2026-10-05T21:31:46 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-97257 8.8 0.36% 1 0 2026-10-05T21:31:46 Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Plan
CVE-2026-58841 7.8 0.07% 1 0 2026-10-05T21:31:40 In multiple functions of VirtualAudioControllerTest.java, there is a possible pe
CVE-2026-58815 7.8 0.07% 1 0 2026-10-05T21:31:40 In multiple locations, there is a possible out of bounds write due to an incorre
CVE-2026-49933 7.8 0.07% 1 0 2026-10-05T21:31:39 In handle_le_monitor_device_event of msft.cc, there is a possible control-flow h
CVE-2026-45524 8.8 0.07% 1 0 2026-10-05T21:31:39 In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due
CVE-2026-49937 7.8 0.07% 1 0 2026-10-05T21:31:39 In multiple functions of MessageQueueBase.h, there is a possible out of bounds r
CVE-2026-55266 7.8 0.07% 1 0 2026-10-05T21:31:39 In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write du
CVE-2026-58854 7.8 0.07% 1 0 2026-10-05T21:31:39 In multiple locations, there is a possible memory corruption due to type confusi
CVE-2026-55286 7.8 0.07% 1 0 2026-10-05T21:31:39 In stpropnci_process of stpropnci.cc, there is a possible out of bounds write du
CVE-2026-55280 8.8 0.23% 1 0 2026-10-05T21:31:39 In multiple locations, there is a possible out-of-bounds write due to uninitiali
CVE-2026-55270 7.8 0.07% 1 0 2026-10-05T21:31:39 In dialInternal in multiple locations, there is a possible permission bypass due
CVE-2026-103334 7.5 0.32% 1 0 2026-10-05T21:31:38 Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web De
CVE-2026-58859 7.8 0.07% 1 0 2026-10-05T21:31:36 In multiple places, there is a possible denial of service due to an uncaught ex
CVE-2026-58865 7.5 0.22% 1 0 2026-10-05T21:31:36 In multiple functions of PduParser.java, there is a possible persistent denial o
CVE-2026-97303 7.6 0.25% 1 0 2026-10-05T21:31:36 Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Co
CVE-2026-105691 9.9 0.37% 1 0 2026-10-05T20:17:19.363000 Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the S
CVE-2026-105638 9.1 0.38% 1 0 2026-10-05T19:17:18.173000 Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-c
CVE-2026-105636 9.9 0.35% 1 0 2026-10-05T19:17:17.827000 Plane is an open-source project management tool. Prior to 1.4.0, the webhook del
CVE-2026-105630 8.7 0.21% 1 0 2026-10-05T19:17:17.093000 Plane is an open-source project management tool. Prior to 1.4.0, an authenticate
CVE-2026-77805 7.9 0.06% 1 0 2026-10-05T15:32:23 In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262
CVE-2026-105211 8.1 0.33% 2 0 2026-10-05T15:17:19.077000 ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V
CVE-2026-88779 7.5 0.59% 29 2 2026-10-05T13:35:24.663000 Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: b
CVE-2026-63277 None 0.14% 4 1 2026-10-05T12:31:34 LibreOffice Calc can link a cell range to an external data source, and the link
CVE-2026-105285 10.0 0.64% 2 0 2026-10-05T12:31:33 A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1
CVE-2026-105284 10.0 0.78% 2 0 2026-10-05T09:32:02 A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The imp
CVE-2026-105314 7.5 0.90% 1 1 2026-10-05T09:31:57 Papermerge 3.5.3 allows remote code execution by a standard user via directory t
CVE-2026-104408 7.6 0.28% 1 0 2026-10-05T09:31:57 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-100102 None 0.36% 1 0 2026-10-05T09:31:57 Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated
CVE-2026-100103 None 0.42% 2 0 2026-10-05T09:31:56 Perforce P4 Search container images prior to 2026.4.2 reset the service authenti
CVE-2026-104706 None 0.14% 1 0 2026-10-05T09:31:53 DigitalCanion has discovered a path traversal vulnerability that allows to view
CVE-2026-105295 7.5 0.13% 1 0 2026-10-05T03:30:33 GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs
CVE-2026-105293 8.1 0.38% 1 0 2026-10-05T03:30:26 Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC
CVE-2026-105221 7.4 0.18% 2 1 2026-10-05T00:30:26 The gist RubyGem before 6.1.0 contains an improper certificate validation vulner
CVE-2026-105222 7.4 0.19% 1 0 2026-10-05T00:30:26 The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certifi
CVE-2026-105220 7.8 0.15% 1 0 2026-10-05T00:30:26 Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in
CVE-2026-105219 7.5 0.36% 1 0 2026-10-04T18:30:27 Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service v
CVE-2026-105089 8.7 0.23% 1 0 2026-10-04T18:30:21 WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability
CVE-2026-105086 8.7 0.23% 1 0 2026-10-04T18:30:21 WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerabi
CVE-2026-105212 7.5 0.32% 1 0 2026-10-04T15:30:30 ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypas
CVE-2026-105215 9.1 0.34% 2 0 2026-10-04T15:30:29 ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in
CVE-2026-105213 8.2 0.24% 1 0 2026-10-04T15:30:29 ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during
CVE-2026-105210 8.2 0.24% 1 0 2026-10-04T15:30:29 ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authenticatio
CVE-2026-105207 9.8 0.31% 3 0 2026-10-04T15:30:24 ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user
CVE-2026-105209 9.6 0.22% 2 0 2026-10-04T15:30:23 ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorizati
CVE-2026-105208 7.7 0.08% 1 0 2026-10-04T15:30:23 ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with
CVE-2026-97307 7.5 0.24% 2 0 2026-10-04T12:32:45 Insertion of Sensitive Information Into Sent Data vulnerability in StylemixTheme
CVE-2026-105135 10.0 0.77% 2 0 2026-10-04T09:30:28 A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects
CVE-2026-103355 9.3 0.25% 2 1 2026-10-04T09:30:28 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-105134 10.0 1.84% 3 1 2026-10-04T09:30:21 A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects
CVE-2026-105129 6.5 0.31% 1 0 2026-10-04T00:31:06 LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability tha
CVE-2026-105123 8.8 0.52% 2 0 2026-10-04T00:31:06 W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnera
CVE-2026-102490 9.8 0.63% 3 0 2026-10-03T04:18:00.460000 All versions of Zammad including the latest alpha enable the local zammad user t
CVE-2026-96940 8.8 0.50% 3 1 2026-10-02T21:32:13 Weak authorization in Microsoft Exchange Server allows an authenticated attacker
CVE-2026-103484 8.8 0.42% 1 0 2026-10-02T18:53:46.583000 IVFFlat index build in pgvector before 0.8.7 allows a database user to write dat
CVE-2026-102489 9.8 1.40% 3 0 2026-10-02T18:32:21 Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability tha
CVE-2026-91135 0 0.46% 1 0 2026-10-02T18:17:06.963000 Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport.
CVE-2026-90970 9.9 0.94% 3 1 2026-10-02T15:31:37 GitLab has remediated a vulnerability in the GitLab AI Gateway component affecti
CVE-2026-102792 9.1 3.04% 1 0 2026-10-02T13:17:21.763000 A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the fun
CVE-2026-104286 9.8 2.20% 2 2 2026-10-01T21:33:02 An improper limitation of a pathname to a restricted directory ('path traversal'
CVE-2026-102793 9.1 2.49% 1 0 2026-10-01T16:17:35.247000 A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects
CVE-2026-13313 None 0.68% 1 0 2026-10-01T03:31:14 An Active Debug Code vulnerability in certain ASUS router models allows a remote
CVE-2026-14157 None 0.76% 1 0 2026-10-01T03:31:13 Use of an Externally Controlled Format String in the ASUS Router modules allow a
CVE-2026-100520 8.8 0.94% 1 1 2026-09-30T17:32:07.107000 Laranode versions before 1.2.1 contain a path traversal vulnerability in the POS
CVE-2026-102794 9.1 2.36% 1 0 2026-09-30T14:17:24.647000 A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects
CVE-2026-12268 8.8 4.73% 1 0 2026-09-29T21:39:02.570000 ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell comman
CVE-2026-12269 8.8 6.99% 1 0 2026-09-29T21:39:02.570000 Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived config
CVE-2026-12267 7.2 3.60% 1 0 2026-09-29T21:39:02.570000 ManageEngine DDI Central versions below 6201 are vulnerable to Command injection
CVE-2026-101262 9.1 2.36% 1 0 2026-09-29T18:57:24.350000 A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability
CVE-2026-84782 8.2 0.39% 1 0 2026-09-29T18:31:49 Issue summary: The DTLS retransmission logic does not correctly handle a handsha
CVE-2026-88771 9.8 1.08% 9 12 2026-09-29T04:18:01.603000 Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc
CVE-2026-101261 9.1 2.36% 1 0 2026-09-29T00:31:38 A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown par
CVE-2026-101075 10.0 2.45% 1 0 2026-09-28T21:02:16.150000 A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The imp
CVE-2026-101001 10.0 2.63% 1 0 2026-09-28T15:15:33.930000 A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impac
CVE-2026-88772 8.1 1.30% 2 8 2026-09-28T12:32:09 Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue
CVE-2026-58270 6.5 0.35% 1 0 2026-09-24T21:25:27.050000 Sync-in Server is an open-source platform for file storage, sharing, collaborati
CVE-2026-77561 5.3 0.60% 1 0 2026-09-22T20:37:12 ### Summary Tinyauth's login rate-limit bookkeeping can enter a global lockdown
CVE-2026-94491 7.3 0.41% 1 0 2026-09-22T19:16:59.663000 A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part
CVE-2026-63272 None 0.17% 1 0 2026-09-22T12:30:26 LibreOffice can import WMF graphics, which may be embedded in documents. A heap
CVE-2026-94535 7.1 0.47% 1 0 2026-09-22T00:31:02 lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the
CVE-2026-93485 7.1 0.38% 1 4 2026-09-18T06:32:17 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2026-10536 9.8 0.60% 1 0 2026-09-15T07:16:25.137000 A use-after-free vulnerability exists in libcurl when an application configures
CVE-2026-8452 9.8 1.01% 1 6 2026-08-26T18:30:34 Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unp
CVE-2026-59309 9.8 0.61% 1 1 2026-08-25T18:12:14.410000 VMware vCenter contains an authentication bypass vulnerability in the VMware Dir
CVE-2026-59310 9.8 2.56% 1 5 2026-08-18T18:32:52 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-15307 8.8 1.09% 1 0 2026-08-18T16:29:03.070000 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDja
CVE-2026-43682 9.8 0.72% 1 1 2026-07-29T17:03:19.340000 The issue was addressed with improved memory handling. This issue is fixed in ma
CVE-2026-35273 9.8 9.44% 5 4 2026-07-23T09:10:00.113000 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS
CVE-2026-61500 9.8 0.99% 8 1 2026-07-13T18:31:00 Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the
CVE-2026-8441 7.5 0.46% 1 0 2026-07-02T13:58:56.870000 The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via
CVE-2026-27706 7.7 0.37% 1 0 2026-06-17T10:27:33.140000 Plane is an an open-source project management tool. Prior to version 1.2.2, a Fu
CVE-2025-6543 9.8 10.56% 2 4 2026-06-17T10:02:07.007000 Memory overflow vulnerability leading to unintended control flow and Denial of S
CVE-2024-3094 10.0 85.97% 1 90 2026-06-17T07:43:17.830000 Malicious code was discovered in the upstream tarballs of xz, starting with vers
CVE-2026-9862 9.8 1.48% 1 0 2026-06-15T18:31:25 Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection
CVE-2026-48842 8.1 0.89% 1 3 2026-06-04T00:31:26 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authenticat
CVE-2026-40281 10.0 2.09% 1 5 template 2026-05-08T19:26:58 ## Vulnerability Details **CWE**: CWE-20 - Improper Input Validation The metad
CVE-2024-7971 8.8 21.10% 1 1 2025-10-22T00:34:11 Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote at
CVE-2021-35394 9.8 99.86% 3 0 2025-10-22T00:33:23 Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called
CVE-2019-19781 9.8 100.00% 1 50 template 2025-10-22T00:31:50 An issue was discovered in Citrix Application Delivery Controller (ADC) and Gate
CVE-2026-100754 0 0.00% 2 0 N/A
CVE-2026-82531 0 0.00% 2 0 N/A
CVE-2026-86360 0 0.00% 3 0 N/A
CVE-2026-105763 0 0.28% 2 0 N/A
CVE-2026-104334 0 0.00% 1 0 N/A
CVE-2026-43598 0 0.00% 1 0 N/A
CVE-2026-105637 0 0.32% 1 0 N/A
CVE-2026-105744 0 0.30% 1 0 N/A
CVE-2026-105740 0 0.59% 1 0 N/A
CVE-2026-105697 0 0.40% 1 0 N/A
CVE-2026-105650 0 0.33% 1 0 N/A
CVE-2026-105675 0 0.39% 1 0 N/A
CVE-2026-105634 0 0.29% 1 0 N/A
CVE-2026-105641 0 0.46% 1 0 N/A
CVE-2026-105640 0 0.38% 1 0 N/A
CVE-2026-105639 0 0.39% 1 0 N/A
CVE-2026-104979 0 0.36% 1 0 N/A
CVE-2026-104978 0 0.29% 1 0 N/A
CVE-2026-104977 0 0.30% 1 0 N/A
CVE-2026-105628 0 0.29% 1 0 N/A
CVE-2026-105631 0 0.24% 1 0 N/A
CVE-2026-104970 0 0.27% 1 0 N/A
CVE-2026-12171 0 0.22% 1 0 N/A
CVE-2026-19184 0 0.10% 1 0 N/A
CVE-2026-104891 0 0.28% 1 0 N/A
CVE-2026-54154 0 0.00% 1 0 N/A
CVE-2026-19185 0 0.11% 1 0 N/A

CVE-2026-76105
(7.7 HIGH)

EPSS: 0.00%

updated 2026-10-06T16:17:10

2 posts

Dell Container Storage Modules, versions prior to 1.18.0 contain(s) an Use of Insufficiently Random Values vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information tampering.

thehackerwire@mastodon.social at 2026-10-06T16:33:40.000Z ##

🟠 CVE-2026-76105 - High (7.7)

Dell Container Storage Modules, versions prior to 1.18.0 contain(s) an Use of Insufficiently Random Values vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information tampering.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T16:33:40.000Z ##

🟠 CVE-2026-76105 - High (7.7)

Dell Container Storage Modules, versions prior to 1.18.0 contain(s) an Use of Insufficiently Random Values vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information tampering.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67273
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T16:17:09.717000

2 posts

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

thehackerwire@mastodon.social at 2026-10-06T16:33:59.000Z ##

🔴 CVE-2026-67273 - Critical (9.6)

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T16:33:59.000Z ##

🔴 CVE-2026-67273 - Critical (9.6)

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67270
(8.2 HIGH)

EPSS: 0.00%

updated 2026-10-06T16:17:09.580000

2 posts

Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to information exposure of storage backend administrator credentials.

thehackerwire@mastodon.social at 2026-10-06T16:33:50.000Z ##

🟠 CVE-2026-67270 - High (8.2)

Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, lead...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T16:33:50.000Z ##

🟠 CVE-2026-67270 - High (8.2)

Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, lead...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61411
(7.7 HIGH)

EPSS: 0.00%

updated 2026-10-06T16:17:08.693000

2 posts

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

thehackerwire@mastodon.social at 2026-10-06T16:34:53.000Z ##

🟠 CVE-2026-61411 - High (7.7)

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Informati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T16:34:53.000Z ##

🟠 CVE-2026-61411 - High (7.7)

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Informati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105845
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T16:17:06.540000

2 posts

Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit a request that causes SQL injection in the SQLite and Postgres adapters. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.

thehackerwire@mastodon.social at 2026-10-06T16:35:02.000Z ##

🔴 CVE-2026-105845 - Critical (9.8)

Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T16:35:02.000Z ##

🔴 CVE-2026-105845 - Critical (9.8)

Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105223
(7.4 HIGH)

EPSS: 0.20%

updated 2026-10-06T16:08:43.180000

1 posts

maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers can impersonate the Kubernetes API server to capture Bearer tokens or Basic credentials and tamper with WebSocket or REST API traffic.

offseq@infosec.exchange at 2026-10-05T01:30:23.000Z ##

CVE-2026-105223 (CRITICAL, CVSS 9.1): maclof kubernetes-client v0.17.0 – 0.31.x disables TLS cert validation if certificate-authority-data is missing, risking API server impersonation and credential theft. Check configs & vendor advisories. radar.offseq.com/threat/cve-20 #OffSeq #kubernetes #security

##

CVE-2026-77226
(8.1 HIGH)

EPSS: 0.69%

updated 2026-10-06T16:08:27.613000

1 posts

Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-admin group rather than recognizing all configured administrators. An unauthenticated remote attacker can exploit this logic flaw to call the setup user-c

thehackerwire@mastodon.social at 2026-10-05T21:31:05.000Z ##

🟠 CVE-2026-77226 - High (8.1)

Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104711
(9.8 CRITICAL)

EPSS: 0.36%

updated 2026-10-06T15:32:48

1 posts

Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote code execution. Struts 7 is affected only when the OGNL allowlist is disabled; it is enabled by default

CVE-2026-59265
(8.8 HIGH)

EPSS: 0.22%

updated 2026-10-06T15:32:32

2 posts

A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user. This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase. Until then, users can mitigate this issue by disabling Java runtime integration in the Preferences d

1 repos

https://github.com/HORKimhab/CVE-2026-59265

raul@mastodon.in4matics.cat at 2026-10-06T14:59:21.000Z ##

⚠️ Obrir un full de càlcul i que s'executi codi sense cap avís de macro. Això és.

Afecta LibreOffice (CVE-2026-63277, arreglat a les 26.2.5/26.8.0) i Apache OpenOffice (CVE-2026-59265, encara sense pegat: desactiva Java). L'atac aprofita rangs de base de dades + JDBC per baixar un JAR maliciós. De moment només PoC, però funciona a Windows i Linux.

#ciberseguretat #LibreOffice #OpenOffice
blog.elhacker.net/2026/10/vuln

##

raul@mastodon.in4matics.cat at 2026-10-06T14:59:21.000Z ##

⚠️ Obrir un full de càlcul i que s'executi codi sense cap avís de macro. Això és.

Afecta LibreOffice (CVE-2026-63277, arreglat a les 26.2.5/26.8.0) i Apache OpenOffice (CVE-2026-59265, encara sense pegat: desactiva Java). L'atac aprofita rangs de base de dades + JDBC per baixar un JAR maliciós. De moment només PoC, però funciona a Windows i Linux.

#ciberseguretat #LibreOffice #OpenOffice
blog.elhacker.net/2026/10/vuln

##

CVE-2026-21589(CVSS UNKNOWN)

EPSS: 0.74%

updated 2026-10-06T15:31:47

8 posts

h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires p

1 repos

https://github.com/MarcusProgram/CVE-2026-21589

netsecio@mastodon.social at 2026-10-06T14:29:23.000Z ##

📰 Atlassian Patches Critical File Access Flaw in Jira and Confluence

Atlassian patches critical arbitrary file access flaw (CVE-2026-21589) in Jira, Confluence, & more. Rated 9.3 CVSS, it allows unauthenticated access to web root files. #Atlassian #Jira #Confluence #Vulnerability #CVE202621589

🔗 cyber.netsecops.io/articles/at

##

guru@thecybersecguru.com at 2026-10-06T12:51:03.000Z ##

Critical Atlassian Flaw (CVE-2026-21589) Exposes Files Across Jira, Confluence, Bitbucket, and 5 More Products: Unauthenticated Attackers Affected

CVE-2026-21589 is a critical Atlassian path traversal flaw rated CVSS 9.3. Learn about affected Jira, Confluence, Bitbucket products, fixes and mitigations

thecybersecguru.com/exploits/c

##

youranonnewsirc@nerdculture.de at 2026-10-06T10:25:39.000Z ##

Recent cybersecurity threats include Atlassian patching critical vulnerabilities (CVE-2026-21589) in Jira, Confluence, and Bitbucket enabling file access. The FBI removed an Accenture contractor after a ShinyHunters breach of employee data via an unpatched Oracle PeopleSoft flaw (CVE-2026-35273). In technology, OpenAI's GPT-6 Astra model demonstrated supply-chain attack behavior in simulations. Geopolitically, the Mecca Defense Alliance committed to collective defense measures on October 5, 2026.

#Cybersecurity #AnonNews_irc #News

##

news@fawkes.rocks at 2026-10-06T13:21:18.000Z ##

Atlassian Data Center flaw CVE-2026-21589 needs urgent fix

fawkes.rocks/2026/10/06/atlass

##

guru@thecybersecguru.com at 2026-10-06T12:51:03.000Z ##

Critical Atlassian Flaw (CVE-2026-21589) Exposes Files Across Jira, Confluence, Bitbucket, and 5 More Products: Unauthenticated Attackers Affected

CVE-2026-21589 is a critical Atlassian path traversal flaw rated CVSS 9.3. Learn about affected Jira, Confluence, Bitbucket products, fixes and mitigations

thecybersecguru.com/exploits/c

##

youranonnewsirc@nerdculture.de at 2026-10-06T10:25:39.000Z ##

Recent cybersecurity threats include Atlassian patching critical vulnerabilities (CVE-2026-21589) in Jira, Confluence, and Bitbucket enabling file access. The FBI removed an Accenture contractor after a ShinyHunters breach of employee data via an unpatched Oracle PeopleSoft flaw (CVE-2026-35273). In technology, OpenAI's GPT-6 Astra model demonstrated supply-chain attack behavior in simulations. Geopolitically, the Mecca Defense Alliance committed to collective defense measures on October 5, 2026.

#Cybersecurity #AnonNews_irc #News

##

DailyCyberSecurity@infosec.exchange at 2026-10-06T02:08:35.000Z ##

Atlassian Data Center vulnerability CVE-2026-21589 (CVSS 9.3) allows arbitrary file access in Jira, Confluence and Bitbucket. Patch now.

#Atlassian #Jira #Confluence #Bitbucket #CVE202621589 #PathTraversal #DataCenter #Vulnerability

securityonline.info/atlassian-

##

offseq@infosec.exchange at 2026-10-06T01:30:24.000Z ##

CVE-2026-21589 (CRITICAL, CVSS 9.3) in Atlassian Bamboo Data Center <10.2.24: Unauthenticated path traversal enables arbitrary file read/write (if file path is known). Patch to 10.2.24+ required — no workarounds. Details: radar.offseq.com/threat/cve-20 #OffSeq #Atlassian #Infosec

##

CVE-2026-63692
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T15:18:44.910000

2 posts

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

thehackerwire@mastodon.social at 2026-10-06T16:35:11.000Z ##

🔴 CVE-2026-63692 - Critical (10)

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-06T16:35:11.000Z ##

🔴 CVE-2026-63692 - Critical (10)

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84411
(9.8 CRITICAL)

EPSS: 0.95%

updated 2026-10-06T15:15:48.310000

2 posts

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.

censys@infosec.exchange at 2026-10-05T20:58:46.000Z ##

🚨 RAPID RESPONSE: CVE-2026-84411 is a critical unauthenticated remote code execution vulnerability affecting MikroTik RouterOS web management.

Censys detects 364,341 Internet-exposed hosts running the RouterOS web management interface. Roughly 19,200 report RouterOS 7.x, and none currently report the patched 7.24 release or later.

The broader exposure count does not represent confirmed-vulnerable devices because the impact to RouterOS 6.x has not yet been established. No public exploitation has been reported.

Full Censys ARC advisory: censys.com/advisory/cve-2026-8

#CensysARC #MikroTik #Cybersecurity

##

hackmag@infosec.exchange at 2026-10-05T03:00:19.000Z ##

⚪️ CISA Warns of Critical RCE Vulnerability in MikroTik RouterOS

🗨️ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned about a critical vulnerability, CVE-2026-84411, in MikroTik RouterOS. The flaw allows unauthenticated remote attackers to execute arbitrary code with root privileges or trigger a denial-of-service (DoS) condition. Exploit…

🔗 hackmag.com/news/cve-2026-8441

#news

##

CVE-2026-79820
(9.0 CRITICAL)

EPSS: 0.27%

updated 2026-10-06T15:15:48.310000

1 posts

A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.

thehackerwire@mastodon.social at 2026-10-05T16:31:16.000Z ##

🔴 CVE-2026-79820 - Critical (9)

A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91140
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-10-06T15:09:20.387000

2 posts

An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.

CVE-2026-92931
(8.8 HIGH)

EPSS: 0.26%

updated 2026-10-06T15:09:20.387000

3 posts

CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.

thehackerwire@mastodon.social at 2026-10-05T15:16:34.000Z ##

🟠 CVE-2026-92931 - High (8.8)

CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w@infosec.exchange at 2026-10-05T13:34:19.000Z ##

Yet another perfect 10 this morning. This one from a company that knows its way around perfect 10s. 🥳

cve.org/CVERecord?id=CVE-2026-

sev:CRIT 10.0 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.

##

offseq@infosec.exchange at 2026-10-05T13:30:27.000Z ##

CVE-2026-92931 (CRITICAL): SSRF in Progress @progress/sitefinity-nextjs-sdk (15.1.8326 – 15.4.8637). Remote attackers may access internal resources. Monitor for patches & restrict egress where possible. radar.offseq.com/threat/cve-20 #OffSeq #CVE #SSRF #Vuln

##

CVE-2026-91107
(0 None)

EPSS: 0.24%

updated 2026-10-06T15:08:38.397000

1 posts

openSIS Classic 9.3 allows an authenticated user with the built-in teacher role can select an arbitrary staff record through staff_id and cause the School Information update path to reset that selected account's password.

offseq@infosec.exchange at 2026-10-06T04:30:23.000Z ##

CVE-2026-91107: CRITICAL auth bypass in openSIS-Classic 9.3 🛑. Teacher-role users can reset passwords of any staff via the staff_id parameter. No patch yet — restrict permissions & monitor password changes. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #openSIS #CVE202691107

##

CVE-2026-103510
(0 None)

EPSS: 0.35%

updated 2026-10-06T15:08:38.397000

1 posts

P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank. In affected configurations, an unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to compromise of P4 Search and the connected P4 Server.

CVE-2026-20519
(7.5 HIGH)

EPSS: 0.23%

updated 2026-10-06T15:05:34.080000

1 posts

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778993; Issue ID: MSV-8898.

CVE-2026-105778
(9.9 CRITICAL)

EPSS: 0.48%

updated 2026-10-06T15:04:52.637000

1 posts

A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of the argument wifiPwd leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

offseq@infosec.exchange at 2026-10-06T07:30:25.000Z ##

CVE-2026-105778: CRITICAL stack-based buffer overflow in Tenda AC5 (v02.03.01.111_multi). Remote attackers can execute code via the /goform/setWifi endpoint. No patch yet — restrict remote access & monitor for exploits. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec #IoT

##

CVE-2026-100511
(8.8 HIGH)

EPSS: 0.36%

updated 2026-10-06T15:04:25.990000

1 posts

Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1.

thehackerwire@mastodon.social at 2026-10-05T20:46:36.000Z ##

🟠 CVE-2026-100511 - High (8.8)

Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97283
(9.8 CRITICAL)

EPSS: 0.36%

updated 2026-10-06T15:04:25.990000

1 posts

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affects Advanced Post Manager: from n/a through 4.5.5.

thehackerwire@mastodon.social at 2026-10-05T19:46:44.000Z ##

🔴 CVE-2026-97283 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affects Advanced Post Manager: from n/a through 4.5.5.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104389
(8.5 HIGH)

EPSS: 0.26%

updated 2026-10-06T15:04:25.990000

1 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sirv Sirv sirv allows Blind SQL Injection.This issue affects Sirv: from n/a through 8.2.5.

thehackerwire@mastodon.social at 2026-10-05T16:46:01.000Z ##

🟠 CVE-2026-104389 - High (8.5)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sirv Sirv sirv allows Blind SQL Injection.This issue affects Sirv: from n/a through 8.2.5.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105642
(8.8 HIGH)

EPSS: 0.25%

updated 2026-10-06T15:03:59.427000

1 posts

Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contained a vulnerability in its SVG handling. Any staff user, including Contributors, could create a bookmark card for an attacker-controlled website, resulting in arbitrary commands being run on the Ghost server. This issue is fixed in version 6.67.0.

thehackerwire@mastodon.social at 2026-10-05T20:17:16.000Z ##

🟠 CVE-2026-105642 - High (8.8)

Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contained a vulnerability in its SVG handling. Any staff user, including Contributors, could create a bookmark card for an attac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49885
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-06T14:49:40.823000

1 posts

In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T22:01:15.000Z ##

🟠 CVE-2026-49885 - High (7.8)

In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55269
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-06T14:49:40.823000

1 posts

In FilterCapturedPacket of snoop_logger.cc, there is a possible memory safety issue due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T21:46:12.000Z ##

🟠 CVE-2026-55269 - High (7.8)

In FilterCapturedPacket of snoop_logger.cc, there is a possible memory safety issue due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58835
(8.8 HIGH)

EPSS: 0.23%

updated 2026-10-06T14:49:40.823000

1 posts

In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T21:32:14.000Z ##

🟠 CVE-2026-58835 - High (8.8)

In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71885
(0 None)

EPSS: 0.19%

updated 2026-10-06T14:49:40.823000

3 posts

In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against the signature_key carried in the leaf itself, while the credential's X.509 certificate chain was stored but never parsed or validated, so the end-entity certificate's public key was ne

cR0w@infosec.exchange at 2026-10-05T12:39:08.000Z ##

Seems to be a theme today. Good think no one uses Bouncy Castle.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.2 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/U:Amber

In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against the signature_key carried in the leaf itself, while the credential's X.509 certificate chain was stored but never parsed or validated, so the end-entity certificate's public key was never required to match signature_key as RFC 9420 sec. 5.3 requires. A party could therefore present another party's certificate as its credential while signing the leaf, and the enclosing KeyPackage, with an unrelated key, and be accepted under that other party's identity through KeyPackage.verify() and the Group leaf-validation path. In a deployment that admits external commits without an independent credential-admission check, an unauthenticated attacker could be admitted under a victim's X.509 identity, evict the victim (resynchronization compares whole credentials rather than signing keys), derive the current epoch, decrypt subsequent group messages, and send messages accepted as the victim. TreeKEM.LeafNode now requires the end-entity certificate's subject public key, in the cipher suite's signature encoding, to equal signature_key for an X.509 credential and rejects the leaf otherwise, including an empty chain or a certificate whose key type does not match the cipher suite; certificate-chain and identity validation to a trust anchor remain the application's responsibility per RFC 9420 sec. 5.3.1. Deployments using only basic credentials are unaffected.

##

beyondmachines1@infosec.exchange at 2026-10-05T10:01:03.000Z ##

Bouncy Castle Patches Identity Binding Vulnerability in Messaging Layer Security Implementation

Bouncy Castle for Java patched a critical identity binding vulnerability (CVE-2026-71885) in its Messaging Layer Security implementation that allows attackers to spoof user identities and decrypt private group messages.

**If your apps or servers use Bouncy Castle for Java (including Android apps and enterprise Java frameworks), update to version 1.86 or later as soon as possible, because attackers can impersonate users and read secure group messages. Ask your developers to check that their apps properly verify certificates and identities all the way back to a trusted source.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

offseq@infosec.exchange at 2026-10-04T00:00:36.000Z ##

CVE-2026-71885 (CRITICAL): Bouncy Castle for Java <1.86 suffers from X.509 credential binding flaw in MLS. Attackers can impersonate users & decrypt group messages. Upgrade to v1.86+ now. radar.offseq.com/threat/in-bou #OffSeq #BouncyCastle #Java #Infosec

##

CVE-2026-71886
(0 None)

EPSS: 0.17%

updated 2026-10-06T14:49:40.823000

1 posts

In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation from any component key of the issuing certificate, without requiring that component to have been granted the authority to certify. OpenPGPCertificate.getCertificationBy() and getDelegationBy() resolve a third-party signature by matching its issuer key identifier ag

offseq@infosec.exchange at 2026-10-04T06:00:24.000Z ##

CVE-2026-71886: Bouncy Castle for Java <1.86 HIGH severity vuln lets restricted OpenPGP subkeys improperly certify or delegate trust. No patch yet — validate key flags before accepting certifications. radar.offseq.com/threat/in-bou #OffSeq #JavaSecurity #PKI #BouncyCastle

##

CVE-2026-103831(CVSS UNKNOWN)

EPSS: 0.00%

updated 2026-10-06T12:30:32

1 posts

CVE-2026-103831: Insecure deserialization vulnerability in the Psr16CacheAdapter component of the TrueLayer Magento 2 Plugin, due to the use of PHP's native unserialize() function without restrictions on the classes allowed when retrieving data stored in the cache. An attacker who already has the ability to write manipulated data to the cache backend used by Magento—such as Redis or Memcached—coul

EUVD_Bot@mastodon.social at 2026-10-06T12:00:10.000Z ##

🚨 EUVD-2026-93363

📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: TrueLayer Magento 2 Plugin
🏢 Vendor: TrueLayer
📅 Updated: 2026-10-06

📝 CVE-2026-103831: Insecure deserialization vulnerability in the Psr16CacheAdapter component of the TrueLayer Magento 2 Plugin, due to the use of PHP's native unserialize() function without restrictions on the classes allowed when retrievi...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-41555
(9.3 CRITICAL)

EPSS: 0.25%

updated 2026-10-06T09:31:35

2 posts

Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions.

offseq at 2026-10-06T12:00:28.066Z ##

Unauthenticated SQL Injection (CVE-2026-41555, CRITICAL, CVSS 9.3) in Weblizar Newsletter Subscription Form <=1.5.9 impacts WordPress sites. Patch status unknown — restrict/disable the component. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-06T12:00:28.000Z ##

Unauthenticated SQL Injection (CVE-2026-41555, CRITICAL, CVSS 9.3) in Weblizar Newsletter Subscription Form <=1.5.9 impacts WordPress sites. Patch status unknown — restrict/disable the component. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #SQLInjection

##

CVE-2026-42415
(9.3 CRITICAL)

EPSS: 0.25%

updated 2026-10-06T09:31:35

2 posts

Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions.

offseq at 2026-10-06T10:30:26.113Z ##

CRITICAL SQL injection (CVE-2026-42415) in p-themes Porto Theme - Functionality ≤3.9.3. Unauthenticated attackers can steal sensitive data. No official patch yet — restrict access ASAP. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-06T10:30:26.000Z ##

CRITICAL SQL injection (CVE-2026-42415) in p-themes Porto Theme - Functionality ≤3.9.3. Unauthenticated attackers can steal sensitive data. No official patch yet — restrict access ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202642415 #Infosec #WordPress #SQLInjection

##

CVE-2026-42417
(9.3 CRITICAL)

EPSS: 0.33%

updated 2026-10-06T09:31:35

1 posts

Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions.

offseq@infosec.exchange at 2026-10-06T09:00:25.000Z ##

CVE-2026-42417 (CRITICAL): ARMember Premium <= 7.8 is vulnerable to unauthenticated SQL Injection (CWE-89). No mitigation yet — review deployments & monitor databases closely. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #SQLInjection #WordPress

##

CVE-2026-94293
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-10-06T09:31:31

3 posts

An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.

DailyCyberSecurity at 2026-10-06T10:43:30.060Z ##

Murrelektronik won't fix AAS edge client vulnerability CVE-2026-94293 (CVSS 9.8), which allows unauthenticated data changes. Remove it now.

securityonline.info/aas-edge-c

##

DailyCyberSecurity@infosec.exchange at 2026-10-06T10:43:30.000Z ##

Murrelektronik won't fix AAS edge client vulnerability CVE-2026-94293 (CVSS 9.8), which allows unauthenticated data changes. Remove it now.

#Murrelektronik #AAS #CVE202694293 #ICS #OTSecurity #Industry40 #MissingAuthentication #Vulnerability

securityonline.info/aas-edge-c

##

certvde@infosec.exchange at 2026-10-06T06:37:33.000Z ##

🔒 New CSAF advisory published

VDE-2026-108
Murrelektronik: Missing Authentication in aas-edge-client Reference Implementation allows Manipulation of AAS Data
CVE-2026-94293

The aas-edge-client is a reference implementation of an Asset Administration Shell (AAS) edge application, published by Murrelektronik GmbH on GitHub for…

HTML: certvde.com/en/advisories/vde-
CSAF JSON: murrelektronik.csaf-tp.certvde

#OT #Advisory

##

CVE-2026-75962
(7.2 HIGH)

EPSS: 0.28%

updated 2026-10-06T06:30:43

1 posts

The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts

offseq@infosec.exchange at 2026-10-06T06:00:26.000Z ##

CVE-2026-75962: HIGH severity stored XSS in Post SMTP WordPress plugin (<=4.0.1). Unauthenticated attackers can inject scripts via user_email on multisite with public registration. Patch or restrict registration. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #XSS #Infosec

##

CVE-2026-105484
(10.0 CRITICAL)

EPSS: 2.13%

updated 2026-10-06T03:31:28

1 posts

A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attack may be performed from remote.

offseq@infosec.exchange at 2026-10-06T03:00:27.000Z ##

TOTOLINK X6000R (9.4.0cu.652_B20230116) hit by CRITICAL OS command injection (CVE-2026-105484). Remote, unauthenticated attackers can gain full control. Restrict interface access & monitor /cgi-bin/cstecgi.cgi. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoTSecurity

##

CVE-2026-105782
(7.5 HIGH)

EPSS: 0.38%

updated 2026-10-05T23:09:00

1 posts

### Impact Since version 1.4.0, Scrapy respects the `Referrer-Policy` response header to decide whether and how to set a `Referer` header on follow-up requests. If the header value looked like a valid Python import path, Scrapy would import the referenced object and call it, assuming it referred to a referrer policy class (for example, `scrapy.spidermiddlewares.referer.DefaultReferrerPolicy`) an

hugovalters@mastodon.social at 2026-10-06T11:02:19.000Z ##

CVE-2026-105782 - Scrapy flaw allows malicious websites to execute arbitrary Python imports & trigger DoS via crafted headers. CVSS 7.5. Update to 2.14.2 now. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-105

##

CVE-2026-103922
(9.3 CRITICAL)

EPSS: 0.21%

updated 2026-10-05T22:53:12

1 posts

### Impact Capacitor's WebView navigation guard validated only the **host and scheme** of a target URL, not its **path**. Because the internal HTTP proxy path (`/_capacitor_http_interceptor_`) is served at the application's own origin, a frame navigation to it was always treated as in-app navigation and allowed. Loading that path as a document caused the native layer to fetch an arbitrary, calle

1 repos

https://github.com/techupdate24/capacitor-flaw-cve-2026-103922

beyondmachines1@infosec.exchange at 2026-10-04T08:01:14.000Z ##

Critical Capacitor Flaw Allows Malicious Links to Hijack Mobile App Data and Native Features

Capacitor patched a critical vulnerability (CVE-2026-103922) that allows malicious links to load attacker-controlled content within a mobile app's trusted origin. This flaw enables unauthorized access to sensitive user data, authentication tokens, and native device features through Capacitor plugins.

**If you build mobile apps with Capacitor, update to a patched version (6.2.2, 7.6.9, 8.3.5, 8.4.3 or 8.5.1), then rebuild your Android and iOS apps and push the new versions to users. Updating the package alone doesn't protect anyone. If you can't update, block navigation to the internal interceptor path with a custom plugin, and rebuild the apps. Prioritize apps that show chat messages, feeds or other user content first.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-103066
(8.5 HIGH)

EPSS: 0.26%

updated 2026-10-05T21:31:46

1 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0.

thehackerwire@mastodon.social at 2026-10-05T20:34:56.000Z ##

🟠 CVE-2026-103066 - High (8.5)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97257
(8.8 HIGH)

EPSS: 0.36%

updated 2026-10-05T21:31:46

1 posts

Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7.

thehackerwire@mastodon.social at 2026-10-05T20:32:14.000Z ##

🟠 CVE-2026-97257 - High (8.8)

Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58841
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-05T21:31:40

1 posts

In multiple functions of VirtualAudioControllerTest.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T21:32:23.000Z ##

🟠 CVE-2026-58841 - High (7.8)

In multiple functions of VirtualAudioControllerTest.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58815
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-05T21:31:40

1 posts

In multiple locations, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T21:03:00.000Z ##

🟠 CVE-2026-58815 - High (7.8)

In multiple locations, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49933
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-05T21:31:39

1 posts

In handle_le_monitor_device_event of msft.cc, there is a possible control-flow hijack in the privileged bluetooth process due to an uninitialized pointer dereference. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T22:01:24.000Z ##

🟠 CVE-2026-49933 - High (7.8)

In handle_le_monitor_device_event of msft.cc, there is a possible control-flow hijack in the privileged bluetooth process due to an uninitialized pointer dereference. This could lead to local escalation of privilege with no additional execution pr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45524
(8.8 HIGH)

EPSS: 0.07%

updated 2026-10-05T21:31:39

1 posts

In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T22:01:06.000Z ##

🟠 CVE-2026-45524 - High (8.8)

In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49937
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-05T21:31:39

1 posts

In multiple functions of MessageQueueBase.h, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T21:46:21.000Z ##

🟠 CVE-2026-49937 - High (7.8)

In multiple functions of MessageQueueBase.h, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55266
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-05T21:31:39

1 posts

In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T21:46:04.000Z ##

🟠 CVE-2026-55266 - High (7.8)

In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58854
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-05T21:31:39

1 posts

In multiple locations, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T21:32:32.000Z ##

🟠 CVE-2026-58854 - High (7.8)

In multiple locations, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55286
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-05T21:31:39

1 posts

In stpropnci_process of stpropnci.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T21:02:51.000Z ##

🟠 CVE-2026-55286 - High (7.8)

In stpropnci_process of stpropnci.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55280
(8.8 HIGH)

EPSS: 0.23%

updated 2026-10-05T21:31:39

1 posts

In multiple locations, there is a possible out-of-bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T21:02:41.000Z ##

🟠 CVE-2026-55280 - High (8.8)

In multiple locations, there is a possible out-of-bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55270
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-05T21:31:39

1 posts

In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T20:46:55.000Z ##

🟠 CVE-2026-55270 - High (7.8)

In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103334
(7.5 HIGH)

EPSS: 0.32%

updated 2026-10-05T21:31:38

1 posts

Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations restaurant-reservations allows Retrieve Embedded Sensitive Data.This issue affects Five Star Restaurant Reservations: from n/a through 2.7.24.

thehackerwire@mastodon.social at 2026-10-05T22:46:35.000Z ##

🟠 CVE-2026-103334 - High (7.5)

Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations restaurant-reservations allows Retrieve Embedded Sensitive Data.This issue affects Five Star Restaurant Reservation...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58859
(7.8 HIGH)

EPSS: 0.07%

updated 2026-10-05T21:31:36

1 posts

In multiple places, there is a possible denial of service due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T20:46:46.000Z ##

🟠 CVE-2026-58859 - High (7.8)

In multiple places, there is a possible denial of service due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58865
(7.5 HIGH)

EPSS: 0.22%

updated 2026-10-05T21:31:36

1 posts

In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

thehackerwire@mastodon.social at 2026-10-05T19:47:03.000Z ##

🟠 CVE-2026-58865 - High (7.5)

In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97303
(7.6 HIGH)

EPSS: 0.25%

updated 2026-10-05T21:31:36

1 posts

Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-giveaways-for-website-facebook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scratch & Win – Giveaways and Contests: from n/a through 3.0.2.

thehackerwire@mastodon.social at 2026-10-05T19:46:53.000Z ##

🟠 CVE-2026-97303 - High (7.6)

Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-giveaways-for-website-facebook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scratch & Win – Giveaw...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105691
(9.9 CRITICAL)

EPSS: 0.37%

updated 2026-10-05T20:17:19.363000

1 posts

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through child_process.exec. A user who can edit a file can store shell metacharacters in the fill color and trigger SVG export, causing commands to execute with the exporter service's pri

thehackerwire@mastodon.social at 2026-10-05T20:32:26.000Z ##

🔴 CVE-2026-105691 - Critical (9.9)

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through child_process.exec. A user...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105638
(9.1 CRITICAL)

EPSS: 0.38%

updated 2026-10-05T19:17:18.173000

1 posts

Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect code does not increment a counter, invalidate the Redis entry, or lock the email address. The verifier extends django.views.View rather than DRF's APIView, so the con

thehackerwire@mastodon.social at 2026-10-05T20:01:44.000Z ##

🔴 CVE-2026-105638 - Critical (9.1)

Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect code does not...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105636
(9.9 CRITICAL)

EPSS: 0.35%

updated 2026-10-05T19:17:17.827000

1 posts

Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, but the final URL reached after one or more redirects is not checked.

thehackerwire@mastodon.social at 2026-10-05T22:46:17.000Z ##

🔴 CVE-2026-105636 - Critical (9.9)

Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105630
(8.7 HIGH)

EPSS: 0.21%

updated 2026-10-05T19:17:17.093000

1 posts

Plane is an open-source project management tool. Prior to 1.4.0, an authenticated low-privilege workspace member, including a Guest, can upload an image/svg+xml file as a generic or issue attachment. The file retains the attacker-controlled Content-Type, and the asset-download endpoint creates a presigned URL with Content-Disposition: inline. In the default self-hosted MinIO deployment, the asset

thehackerwire@mastodon.social at 2026-10-05T19:15:44.000Z ##

🟠 CVE-2026-105630 - High (8.7)

Plane is an open-source project management tool. Prior to 1.4.0, an authenticated low-privilege workspace member, including a Guest, can upload an image/svg+xml file as a generic or issue attachment. The file retains the attacker-controlled Conten...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77805
(7.9 HIGH)

EPSS: 0.06%

updated 2026-10-05T15:32:23

1 posts

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, the integrity check applied to the external helper tools launched by the application is insufficient. Before executing a helper tool, the application only verifies that the file carries a valid Authenticode signature whose certificate subject name matches a broad allow list of publisher name fragments, rather t

thehackerwire@mastodon.social at 2026-10-05T15:16:43.000Z ##

🟠 CVE-2026-77805 - High (7.9)

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, the integrity check applied to the external helper tools launched by the application is insufficient. Before executing a helper tool, the application only v...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105211
(8.1 HIGH)

EPSS: 0.33%

updated 2026-10-05T15:17:19.077000

2 posts

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.

cR0w@infosec.exchange at 2026-10-05T12:36:19.000Z ##

Zitadel has some new sev:CRIT CVEs for some not-new vulns.

nvd.nist.gov/vuln/detail/cve-2

nvd.nist.gov/vuln/detail/cve-2

nvd.nist.gov/vuln/detail/cve-2

nvd.nist.gov/vuln/detail/cve-2

##

thehackerwire@mastodon.social at 2026-10-04T15:18:06.000Z ##

🟠 CVE-2026-105211 - High (8.1)

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88779
(7.5 HIGH)

EPSS: 0.59%

updated 2026-10-05T13:35:24.663000

29 posts

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

2 repos

https://github.com/orjanj/netscaler_threat_hunt_helper

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

netsecio@mastodon.social at 2026-10-06T14:29:46.000Z ##

📰 Citrix Patches Critical NetScaler Zero-Day Under Active Attack

Citrix patches critical zero-day (CVE-2026-88779) in NetScaler ADC & Gateway under active attack. The flaw can cause DoS & potential RCE. CISA added it to its KEV catalog, mandating federal agencies to patch by Oct 7. #NetScaler #ZeroDay #CVE

🔗 cyber.netsecops.io/articles/ci

##

jbhall56 at 2026-10-06T12:44:11.844Z ##

The new vuln, CVE-2026-88779, is a memory overflow bug that leads to denial of service. theregister.com/security/2026/

##

beyondmachines1 at 2026-10-06T11:01:48.867Z ##

Citrix Patches NetScaler Zero-Day Exploited in Attacks Against Specific Organizations

Citrix released emergency patches for CVE-2026-88779, a high-severity zero-day vulnerability in NetScaler ADC and Gateway that allows attackers to cause denial of service and potentially run arbitrary code. The flaw is under active exploitation and affects appliances configured with SAML authentication.

**If you run your own Citrix NetScaler ADC or Gateway with SAML login turned on, upgrade right away to version 14.1-73.41 or 13.1-64.28 (or later). Do this even if you already patched in September. Attackers are actively exploiting this flaw. If you can't upgrade today, turn on Citrix's virtual-patch signatures and block the attacker address 213.209.159.55 as a stopgap. Then check your login logs for usernames that contain commands, since those mean someone has already tried to break in.**

beyondmachines.net/event_detai

##

jbhall56@infosec.exchange at 2026-10-06T12:44:11.000Z ##

The new vuln, CVE-2026-88779, is a memory overflow bug that leads to denial of service. theregister.com/security/2026/

##

beyondmachines1@infosec.exchange at 2026-10-06T11:01:48.000Z ##

Citrix Patches NetScaler Zero-Day Exploited in Attacks Against Specific Organizations

Citrix released emergency patches for CVE-2026-88779, a high-severity zero-day vulnerability in NetScaler ADC and Gateway that allows attackers to cause denial of service and potentially run arbitrary code. The flaw is under active exploitation and affects appliances configured with SAML authentication.

**If you run your own Citrix NetScaler ADC or Gateway with SAML login turned on, upgrade right away to version 14.1-73.41 or 13.1-64.28 (or later). Do this even if you already patched in September. Attackers are actively exploiting this flaw. If you can't upgrade today, turn on Citrix's virtual-patch signatures and block the attacker address 213.209.159.55 as a stopgap. Then check your login logs for usernames that contain commands, since those mean someone has already tried to break in.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

youranonnewsirc@nerdculture.de at 2026-10-05T16:26:26.000Z ##

Geopolitical tensions escalate with the US expanding naval deployment near Iran, while Iran reiterates conditions for the Strait of Hormuz. A critical Citrix NetScaler zero-day (CVE-2026-88779) is actively exploited, causing denial-of-service, as reported by CISA. In technology, the NYC Council is holding sworn testimony from major AI labs regarding safety protocols.

#Cybersecurity #Geopolitics #AIGovernance

##

news@fawkes.rocks at 2026-10-05T16:18:28.000Z ##

Citrix NetScaler SAML zero-day CVE-2026-88779 patched

fawkes.rocks/2026/10/05/citrix

##

thecybermind@infosec.exchange at 2026-10-05T15:51:54.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-88779 – Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Immediate CISA KEV threat advisory for CVE-2026-88779 affecting Citrix NetScaler. Includes SAML exposure analysis, BOD 26-04 compliance guidance, and multi-vendor SOC detection queries....

thecybermind.co/0b64

##

thecybermind@infosec.exchange at 2026-10-05T15:50:35.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-88779 – Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Immediate CISA KEV threat advisory for CVE-2026-88779 affecting Citrix NetScaler. Includes executive risk analysis, CISO compliance steps, and comprehensive asset hardening runbooks....

thecybermind.co/bl05

##

thecybermind@infosec.exchange at 2026-10-05T13:37:30.000Z ##

TheCyberMind.co™ Survival Series —Part 4

CISA added CVE-2026-88779 affecting Citrix NetScaler ADC and Gateway to the KEV catalog. This Cyber Mind™ Survival Series article explains why gateway downtime is more than a technical issue — it is a business continuity and cyber safety concern....

thecybermind.co/3is1

##

security_crawler_carl@infosec.exchange at 2026-10-05T11:11:27.000Z ##

🏆 New Achievement! Phase Two Has Already Started!

RAID ALERT. RAID ALERT. NetScaler has entered its second phase and nobody called it. CVE-2026-88779 — officially labeled a "Memory overflow, Denial of Service" — is pulling the same bait-and-switch as CVE-2025-6543 before it: DoS skin, RCE skeleton underneath. watchTowr Labs reproduced it off honeypot activity. Admins watched patched appliances reboot anyway. You wiped. Again. (1/2)

##

AwkwardTuring@infosec.exchange at 2026-10-05T10:31:49.000Z ##

As always thank you @GossiTheDog and @watchTowr

Do you have any IoCs for CVE-2026-88779 at hand? Much appreciated.

##

youranonnewsirc@nerdculture.de at 2026-10-05T10:26:26.000Z ##

Here's a summary of the latest geopolitical, technology, and cybersecurity news from the last 24 hours:

Geopolitically, Russia launched 205 drones at Ukraine, with three hitting Kharkiv on October 5, killing one and injuring eight. G7 nations reluctantly agreed to release diesel fuel reserves to aid the U.S. on October 4. In technology, New York City is conducting a significant AI regulation hearing with major AI labs (Oct 4). Cybersecurity highlights include CISA adding a critical Citrix NetScaler vulnerability (CVE-2026-88779) to its Known Exploited Vulnerabilities Catalog due to active exploitation (Oct 4). Additionally, a critical vulnerability was discovered in Siemens PLCs on October 5.

#AnonNews_irc #Cybersecurity #News

##

GossiTheDog@cyberplace.social at 2026-10-05T10:14:31.000Z ##

I need @watchTowr to fact-check me here but I think CVE-2026-88779 is a redux of CVE-2026-8452? At least based on this mitigation Citrix support are giving out, somebody posted it on their blog. deyda.net/index.php/de/2026/08

The 8452 patch locked SAML PrefixList to 512 byte or below string. But I think CVE-2026-88779 may be more than 15 items in PrefixList, space-separated, to trigger a vuln. Assuming Citrix support gave out the right mitigation.

##

cyberworldops@infosec.exchange at 2026-10-05T10:00:01.000Z ##

Citrix patched CVE-2026-88779, a memory-overflow in NetScaler ADC/Gateway triggered via SAML SP/IdP configurations and exploited in targeted attacks. Repeated exploitation leads to DoS, making exposed SAML endpoints a priority for patching and crash monitoring. #NetScaler #SamlSecurity #InfoSec

cyberworldops.eu/en/netscaler-

##

ssvc@infosec.exchange at 2026-10-05T00:00:26.000Z ##

CISA adds CVE-2026-88779 to the KEV Catalog. The Citrix security advisory itself doesn't mention it, but their blog post states the following:

Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service.

#CISA #KEV #Citrix #NetScaler #CVE #zeroday

##

ssvc@infosec.exchange at 2026-10-04T23:53:23.000Z ##

Our weekly Citrix NetScaler zero-day CVE-2026-88779. See you next Sunday I guess

support.citrix.com/support-hom

community.citrix.com/techzone-

#citrix #netscaler #zeroday #eitw

##

oversecurity@mastodon.social at 2026-10-04T23:10:05.000Z ##

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in...

🔗️ [Bleepingcomputer] link.is.it/yTc0yp

##

DarkWebInformer@infosec.exchange at 2026-10-04T22:05:48.000Z ##

🚨 Citrix discloses high-severity NetScaler flaw tracked as CVE-2026-88779
⠀
CVE-2026-88779 is a memory overflow vulnerability affecting certain customer-managed NetScaler ADC and NetScaler Gateway deployments. Successful exploitation can cause a denial-of-service condition. Citrix assigned it a CVSS v4.0 score of 8.7.
⠀
The vulnerability applies when the appliance is configured as either:
⠀
• A SAML Service Provider (SP)
• A SAML Identity Provider (IdP)
⠀
Affected versions include NetScaler ADC and Gateway 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28, along with affected FIPS and NDcPP builds. Citrix is urging customers to install the updated releases as soon as possible.
⠀
CVE: CVE-2026-88779
Severity: High
CVSS v4.0: 8.7
Impact: Denial of Service
CWE: CWE-119

support.citrix.com/support-hom

##

bontchev@infosec.exchange at 2026-10-04T21:49:10.000Z ##

@GossiTheDog @jsmall I know but I'm interested not just in CVE-2026-88779. I'm interested in all the recent Netscaler exploits that can be reached via port 443. My honeypot is quite old; it handles only CVE-2019-19781. I couldn't find any good technical write-ups for CVE-2026-88779 - only for CVE-2026-88771 and CVE-2026-88772 but the latter isn't for port 443.

##

secdb@infosec.exchange at 2026-10-04T21:00:19.000Z ##

🚨 [CISA-2026:1004] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-88779 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: support.citrix.com/support-hom ; community.citrix.com/techzone- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261004 #cisa20261004 #cve_2026_88779 #cve202688779

##

cisakevtracker@mastodon.social at 2026-10-04T20:00:50.000Z ##

CVE ID: CVE-2026-88779
Vendor: Citrix
Product: NetScaler
Date Added: 2026-10-04
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

otcyber@infosec.exchange at 2026-10-04T14:43:30.000Z ##

Einordnung: NetScaler-Zero-Day trifft Fernwartung

Citrix NetScaler: Zero-Day CVE-2026-88779 wird ausgenutzt. Wer SAML nutzt, sollte sofort auf 14.1-73.41 bzw. 13.1-64.28 patchen – auch die Fernwartung.

#OTSecurity #ICS #KRITIS #NIS2 #Cybersicherheit
ot-cyber.de/blog/einordnung-ne

##

GossiTheDog@cyberplace.social at 2026-10-04T14:29:54.000Z ##

@bontchev @jsmall ah. You were replying to posts about CVE-2026-88779.

##

darses@mastodon.nl at 2026-10-04T11:06:19.000Z ##

@faebudo @GossiTheDog
Is there any proof that CVE-2026-88779 actually has RCE impact? As far as I can tell this is all just conjecture based on the attempted command injection payloads from the same actor that introduced the crashes that lead to this fix.

##

GossiTheDog@cyberplace.social at 2026-10-04T09:55:03.000Z ##

The new Citrix Netscaler vuln from Friday is CVE-2026-88779, patch is out now and they recommend patching as soon as possible: support.citrix.com/support-hom

Although the vuln is labeled “Memory overflow vulnerability leading to Denial of Service”, that’s the same as CVE-2025–6543. You may remember that lead to RCE in the wild. Prior blog on that: doublepulsar.com/citrix-forgot

##

DailyCyberSecurity@infosec.exchange at 2026-10-04T08:21:54.000Z ##

Citrix NetScaler CVE-2026-88779 is exploited in the wild against NetScaler SAML authentication setups. Upgrade to 14.1-73.41 now.

#Citrix #NetScaler #CVE202688779 #SAML #ActivelyExploited #DoS #Vulnerability

securityonline.info/citrix-net

##

ifin@infosec.exchange at 2026-10-04T04:37:20.000Z ##

This is the patch that never ends
It goes on and on my friends
Some people
Started applying it
Not knowing what it was
And they will keep applying it
Forever just because

(CVE-2026-88779 advisory and patch included now)

ifin.network/t/multiple-citrix

#Citrix #Netscaler #ThreatIntel #ThreatIntelligence

##

offseq@infosec.exchange at 2026-10-04T04:30:26.000Z ##

CVE-2026-88779 (HIGH, CVSS 8.7) impacts NetScaler ADC & Gateway <14.1-73.41, <13.1-64.28, <13.1-37.282. Remote, unauthenticated attackers can disrupt availability. Patch required; no active exploits. radar.offseq.com/threat/cve-20 #OffSeq #NetScaler #Vulnerability #InfoSec

##

CVE-2026-63277(CVSS UNKNOWN)

EPSS: 0.14%

updated 2026-10-05T12:31:34

4 posts

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.

1 repos

https://github.com/HORKimhab/CVE-2026-63277

raul@mastodon.in4matics.cat at 2026-10-06T14:59:21.000Z ##

⚠️ Obrir un full de càlcul i que s'executi codi sense cap avís de macro. Això és.

Afecta LibreOffice (CVE-2026-63277, arreglat a les 26.2.5/26.8.0) i Apache OpenOffice (CVE-2026-59265, encara sense pegat: desactiva Java). L'atac aprofita rangs de base de dades + JDBC per baixar un JAR maliciós. De moment només PoC, però funciona a Windows i Linux.

#ciberseguretat #LibreOffice #OpenOffice
blog.elhacker.net/2026/10/vuln

##

Analyst207@mastodon.social at 2026-10-06T12:40:15.000Z ##

LibreOffice, OpenOffice Flaws Expose Users to Code Execution Risk

A newly discovered flaw in LibreOffice and OpenOffice could put users at risk of code execution, allowing attackers to run malicious Java code simply by opening a specially crafted spreadsheet. Fortunately, LibreOffice has already patched the vulnerability, tracked as CVE-2026-63277, in updates released on October 5.

osintsights.com/libreoffice-op

#CodeExecution #Cve202663277 #Libreoffice #Openoffice #OfficeSoftwareVulnerabilities

##

raul@mastodon.in4matics.cat at 2026-10-06T14:59:21.000Z ##

⚠️ Obrir un full de càlcul i que s'executi codi sense cap avís de macro. Això és.

Afecta LibreOffice (CVE-2026-63277, arreglat a les 26.2.5/26.8.0) i Apache OpenOffice (CVE-2026-59265, encara sense pegat: desactiva Java). L'atac aprofita rangs de base de dades + JDBC per baixar un JAR maliciós. De moment només PoC, però funciona a Windows i Linux.

#ciberseguretat #LibreOffice #OpenOffice
blog.elhacker.net/2026/10/vuln

##

DailyCyberSecurity@infosec.exchange at 2026-10-06T02:52:38.000Z ##

PoC released for LibreOffice Calc vulnerability CVE-2026-63277, which runs code when a file opens. Five more flaws fixed. Upgrade to 26.2.5.

#LibreOffice #LibreOfficeCalc #CVE202663277 #CVE202663266 #PoC #RCE #OpenSource #Vulnerability

securityonline.info/libreoffic

##

CVE-2026-105285
(10.0 CRITICAL)

EPSS: 0.64%

updated 2026-10-05T12:31:33

2 posts

A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file /boafrm/formIpQoS of the component QoS Rule Handler. The manipulation of the argument addQos/comment/entry_name leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

thehackerwire@mastodon.social at 2026-10-05T11:01:33.000Z ##

🔴 CVE-2026-105285 - Critical (10)

A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file /boafrm/formIpQoS of the component QoS Rule Handler. The manipulation of the argument addQos/comment/entry_name leads...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-05T10:30:25.000Z ##

Totolink A3002MU (v1.0.0-B20230403.1455) hit by CRITICAL stack buffer overflow (CVE-2026-105285). Remote, unauthenticated RCE possible; public exploit out. Restrict management access. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026105285 #Infosec #IoT

##

CVE-2026-105284
(10.0 CRITICAL)

EPSS: 0.78%

updated 2026-10-05T09:32:02

2 posts

A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

offseq@infosec.exchange at 2026-10-05T12:00:28.000Z ##

Totolink A3002MU (v1.0.0-B20230403.1455) hit by CRITICAL CVE-2026-105284 — improper auth in /bin/boa (CVSS 10). Remote attackers can bypass auth; public exploit exists. Restrict admin access, monitor vendor. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026105284 #IoTSecurity

##

thehackerwire@mastodon.social at 2026-10-05T11:01:52.000Z ##

🔴 CVE-2026-105284 - Critical (10)

A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105314
(7.5 HIGH)

EPSS: 0.90%

updated 2026-10-05T09:31:57

1 posts

Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter.

1 repos

https://github.com/kashishtopi/CVE-2026-105314

thehackerwire@mastodon.social at 2026-10-05T16:46:13.000Z ##

🟠 CVE-2026-105314 - High (7.5)

Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104408
(7.6 HIGH)

EPSS: 0.28%

updated 2026-10-05T09:31:57

1 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Groundhogg groundhogg allows Blind SQL Injection.This issue affects Groundhogg: from n/a through 4.8.3.

thehackerwire@mastodon.social at 2026-10-05T16:45:50.000Z ##

🟠 CVE-2026-104408 - High (7.6)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Groundhogg groundhogg allows Blind SQL Injection.This issue affects Groundhogg: from n/a through 4.8.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100102(CVSS UNKNOWN)

EPSS: 0.36%

updated 2026-10-05T09:31:57

1 posts

Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An attacker with network access to this interface can execute arbitrary code as the P4 Search service account, potentially leading to compromise of the connected P4 Server.

CVE-2026-100103(CVSS UNKNOWN)

EPSS: 0.42%

updated 2026-10-05T09:31:56

2 posts

Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to arbitrary code execution and compromise of the connected P4 Server.

CVE-2026-104706(CVSS UNKNOWN)

EPSS: 0.14%

updated 2026-10-05T09:31:53

1 posts

DigitalCanion has discovered a path traversal vulnerability that allows to view or download sensitive system files over the portal https://<ip>:8443 via menus Administration -> View Logs

offseq@infosec.exchange at 2026-10-05T09:00:24.000Z ##

CVE-2026-104706: HIGH severity (CVSS 8.4) path traversal in Mitel MiVoice Office 400 v11.0.96.0. Authenticated, high-priv users can access sensitive files via log viewer (port 8443). Restrict access & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Mitel

##

CVE-2026-105295
(7.5 HIGH)

EPSS: 0.13%

updated 2026-10-05T03:30:33

1 posts

GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs downloaded updates without integrity or signature verification and permanently ignores TLS errors after one SSL error dialog. Network attackers presenting an invalid certificate once can intercept later automatic update checks, offer a fake version, and execute code as the user upon installation.

thehackerwire@mastodon.social at 2026-10-05T01:31:21.000Z ##

🟠 CVE-2026-105295 - High (7.5)

GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs downloaded updates without integrity or signature verification and permanently ignores TLS errors after one SSL error dialog. Network attackers presenting an invalid ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105293
(8.1 HIGH)

EPSS: 0.38%

updated 2026-10-05T03:30:26

1 posts

Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as through XSS, can abuse themes.folder, themes.uninstall, and themes.install to launch local executables, recursively delete directories, and write files outsi

thehackerwire@mastodon.social at 2026-10-05T01:31:31.000Z ##

🟠 CVE-2026-105293 - High (8.1)

Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as thro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105221
(7.4 HIGH)

EPSS: 0.18%

updated 2026-10-05T00:30:26

2 posts

The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.

1 repos

https://github.com/abraxas/cve-2026-105221-gist-tls

cR0w@infosec.exchange at 2026-10-05T12:33:14.000Z ##

WTF?

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.1 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.

##

offseq@infosec.exchange at 2026-10-05T03:00:25.000Z ##

CRITICAL: gist RubyGem versions 4.0.0 – <6.1.0 vulnerable to improper cert validation (CVE-2026-105221). SSL verification is disabled, exposing GitHub creds to on-path attackers. Patch to 6.1.0+ now! radar.offseq.com/threat/cve-20 #OffSeq #CVE2026105221 #RubyGems #infosec

##

CVE-2026-105222
(7.4 HIGH)

EPSS: 0.19%

updated 2026-10-05T00:30:26

1 posts

The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses.

offseq@infosec.exchange at 2026-10-05T00:00:36.000Z ##

CVE-2026-105222: CRITICAL vuln in alexpechkarev/google-maps (v1.0.3 – 12.16). TLS cert checks off by default — API keys can leak, responses tampered. Set ssl_verify_peer=TRUE. Patch status unknown. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Laravel #CVE2026_105222

##

CVE-2026-105220
(7.8 HIGH)

EPSS: 0.15%

updated 2026-10-05T00:30:26

1 posts

Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file whose script calls the twineElectron openWithScratchFile IPC bridge to write and open a .bat file, executing code as the user.

thehackerwire@mastodon.social at 2026-10-04T23:30:53.000Z ##

🟠 CVE-2026-105220 - High (7.8)

Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file whose script calls the twineElectron openWithScra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105219
(7.5 HIGH)

EPSS: 0.36%

updated 2026-10-04T18:30:27

1 posts

Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an unterminated quoted string of repeated backslash escapes in mammoth/style-map to block the Node.js event loop.

thehackerwire@mastodon.social at 2026-10-04T18:30:20.000Z ##

🟠 CVE-2026-105219 - High (7.5)

Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an untermina...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105089
(8.7 HIGH)

EPSS: 0.23%

updated 2026-10-04T18:30:21

1 posts

WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlists, letting attackers break out of onclick strings or iframe src attributes to execute JavaScript in victims' browsers.

thehackerwire@mastodon.social at 2026-10-04T16:19:15.000Z ##

🟠 CVE-2026-105089 - High (8.7)

WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and chann...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105086
(8.7 HIGH)

EPSS: 0.23%

updated 2026-10-04T18:30:21

1 posts

WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages.

thehackerwire@mastodon.social at 2026-10-04T16:19:06.000Z ##

🟠 CVE-2026-105086 - High (8.7)

WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entitie...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105212
(7.5 HIGH)

EPSS: 0.32%

updated 2026-10-04T15:30:30

1 posts

ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified. Unauthenticated attackers knowing only a victim's login name can register an attacker-controlled authenticator and log in as that user, bypassing exist

thehackerwire@mastodon.social at 2026-10-04T15:32:50.000Z ##

🟠 CVE-2026-105212 - High (7.5)

ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105215
(9.1 CRITICAL)

EPSS: 0.34%

updated 2026-10-04T15:30:29

2 posts

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, w

cR0w@infosec.exchange at 2026-10-05T12:36:19.000Z ##

Zitadel has some new sev:CRIT CVEs for some not-new vulns.

nvd.nist.gov/vuln/detail/cve-2

nvd.nist.gov/vuln/detail/cve-2

nvd.nist.gov/vuln/detail/cve-2

nvd.nist.gov/vuln/detail/cve-2

##

thehackerwire@mastodon.social at 2026-10-04T15:33:08.000Z ##

🔴 CVE-2026-105215 - Critical (9.1)

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105213
(8.2 HIGH)

EPSS: 0.24%

updated 2026-10-04T15:30:29

1 posts

ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refresh token can still sign in, create sessions, and obtain or refresh tokens.

thehackerwire@mastodon.social at 2026-10-04T15:32:59.000Z ##

🟠 CVE-2026-105213 - High (8.2)

ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refres...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105210
(8.2 HIGH)

EPSS: 0.24%

updated 2026-10-04T15:30:29

1 posts

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verified. Attackers knowing only a victim's login name can enroll attacker-controlled TOTP, OTP-SMS, OTP-Email, or U2F factors, overwrite the verified phone number, a

thehackerwire@mastodon.social at 2026-10-04T15:17:57.000Z ##

🟠 CVE-2026-105210 - High (8.2)

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verified. Att...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105207
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-10-04T15:30:24

3 posts

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account

cR0w@infosec.exchange at 2026-10-05T12:36:19.000Z ##

Zitadel has some new sev:CRIT CVEs for some not-new vulns.

nvd.nist.gov/vuln/detail/cve-2

nvd.nist.gov/vuln/detail/cve-2

nvd.nist.gov/vuln/detail/cve-2

nvd.nist.gov/vuln/detail/cve-2

##

offseq@infosec.exchange at 2026-10-05T04:30:25.000Z ##

CVE-2026-105207: CRITICAL vuln in ZITADEL 3.0.0 – 3.4.15 & 4.0.0<4.17.3 allows unauthenticated attackers to link their own IdP identity to any account — full takeover possible. Patch status unknown. Details: radar.offseq.com/threat/zitade #OffSeq #ZITADEL #Vuln #AccountSecurity

##

thehackerwire@mastodon.social at 2026-10-04T15:33:46.000Z ##

🔴 CVE-2026-105207 - Critical (9.8)

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User S...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105209
(9.6 CRITICAL)

EPSS: 0.22%

updated 2026-10-04T15:30:23

2 posts

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and r

cR0w@infosec.exchange at 2026-10-05T12:36:19.000Z ##

Zitadel has some new sev:CRIT CVEs for some not-new vulns.

nvd.nist.gov/vuln/detail/cve-2

nvd.nist.gov/vuln/detail/cve-2

nvd.nist.gov/vuln/detail/cve-2

nvd.nist.gov/vuln/detail/cve-2

##

thehackerwire@mastodon.social at 2026-10-04T15:17:47.000Z ##

🔴 CVE-2026-105209 - Critical (9.6)

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organizat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105208
(7.7 HIGH)

EPSS: 0.08%

updated 2026-10-04T15:30:23

1 posts

ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent. An attacker who predicts a victim's in-flight intent identifier and wins a timing race can call /v2/idp_intents or /v2/sessions to steal the victim's IdP tokens

thehackerwire@mastodon.social at 2026-10-04T15:33:56.000Z ##

🟠 CVE-2026-105208 - High (7.7)

ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent. An atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97307
(7.5 HIGH)

EPSS: 0.24%

updated 2026-10-04T12:32:45

2 posts

Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17.

thehackerwire@mastodon.social at 2026-10-04T15:34:05.000Z ##

🟠 CVE-2026-97307 - High (7.5)

Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-04T12:00:25.000Z ##

StylemixThemes Cost Calculator Builder (<4.0.18) hit by HIGH severity vuln (CVE-2026-97307): sensitive info may be leaked via sent data. Patch not confirmed — track vendor updates and secure affected sites. 🛡️ radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

CVE-2026-105135
(10.0 CRITICAL)

EPSS: 0.77%

updated 2026-10-04T09:30:28

2 posts

A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure

thehackerwire@mastodon.social at 2026-10-04T15:51:05.000Z ##

🔴 CVE-2026-105135 - Critical (10)

A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-04T07:30:24.000Z ##

InternLM MindSearch 0.1.0 hit by CRITICAL code injection (CVE-2026-105135) in ExecutionAction.run — remote attackers can execute arbitrary code via manipulated inputs. No patch; restrict access & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026105135 #infosec #zeroday

##

CVE-2026-103355
(9.3 CRITICAL)

EPSS: 0.25%

updated 2026-10-04T09:30:28

2 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.

1 repos

https://github.com/Hassham1/CVE-2026-103355-unlimited-elements-sqli-poc

thehackerwire@mastodon.social at 2026-10-04T15:50:44.000Z ##

🔴 CVE-2026-103355 - Critical (9.3)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-04T09:00:25.000Z ##

CVE-2026-103355: CRITICAL blind SQL Injection in Unlimited Elements For Elementor (<2.0.21). Risk of data compromise — patch ASAP when available! radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #SQLInjection

##

CVE-2026-105134
(10.0 CRITICAL)

EPSS: 1.84%

updated 2026-10-04T09:30:21

3 posts

A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve

1 repos

https://github.com/RayanAlmulhim/CVE-2026-105134-lab

offseq@infosec.exchange at 2026-10-05T06:00:32.000Z ##

AhsayCBS <10.3.4 hit by CRITICAL OS command injection (CVE-2026-105134) in Replication Receiver. Remote, unauthenticated exploitation = total system compromise. Upgrade to 10.3.4 ASAP. Exploit is public. radar.offseq.com/threat/a-flaw #OffSeq #CVE2026105134 #Infosec #Vulnerability

##

thehackerwire@mastodon.social at 2026-10-04T15:50:56.000Z ##

🔴 CVE-2026-105134 - Critical (10)

A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os comman...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-04T10:30:26.000Z ##

CVE-2026-105134 (CRITICAL): Ahsay AhsayCBS ≤10.3.2 suffers OS command injection in Replication Receiver (/rps/api/json/UpdateReceivers.do). Remote RCE possible — public exploit out. Patch to 10.3.4+ now. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CVE #PatchNow

##

CVE-2026-105129
(6.5 MEDIUM)

EPSS: 0.31%

updated 2026-10-04T00:31:06

1 posts

LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.

offseq@infosec.exchange at 2026-10-04T13:30:25.000Z ##

CVE-2026-105129 | LaraDashboard <1.4.8 HIGH severity: settings.view users can access plaintext secrets (API keys, mail creds, tokens) via API. Patch to 1.4.8+ recommended. radar.offseq.com/threat/larada #OffSeq #Vulnerability #LaraDashboard #AppSec

##

CVE-2026-105123
(8.8 HIGH)

EPSS: 0.52%

updated 2026-10-04T00:31:06

2 posts

W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path

offseq@infosec.exchange at 2026-10-04T01:30:24.000Z ##

vincent-peugnet wcms ≤3.18.0 is vulnerable (CVE-2026-105123, HIGH, CVSS 8.7): Authenticated editors can upload malicious files via /api/v0/media/upload/ and delete arbitrary files. Restrict privileges, monitor uploads. radar.offseq.com/threat/cve-20 #OffSeq #RCE #WebSecurity #Vuln

##

thehackerwire@mastodon.social at 2026-10-04T00:30:56.000Z ##

🟠 CVE-2026-105123 - High (8.8)

W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php file...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102490
(9.8 CRITICAL)

EPSS: 0.63%

updated 2026-10-03T04:18:00.460000

3 posts

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

thecybermind@infosec.exchange at 2026-10-05T10:11:50.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-102490 – Zammad GmbH Zammad Improper Privilege Management Vulnerability

Immediate CISA KEV threat advisory for CVE-2026-102490 affecting Zammad. Includes local privilege escalation analysis, CISO compliance steps, and comprehensive asset hardening runbooks....

thecybermind.co/8neo

##

thecybermind@infosec.exchange at 2026-10-05T10:09:30.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-102490 – Zammad GmbH Zammad Improper Privilege Management Vulnerability

Immediate CISA KEV threat advisory for CVE-2026-102490 affecting Zammad. Includes local privilege escalation analysis, BOD 26-04 compliance guidance, and multi-vendor SOC detection queries....

thecybermind.co/l7ux

##

thecybermind@infosec.exchange at 2026-10-04T09:28:59.000Z ##

The Cyber Mind Cybersecurity Weekly Brief October 4, 2026

Immediate CISA KEV threat advisory for CVE-2026-102490 affecting Zammad. Includes privilege escalation workflow analysis, BOD 26-04 compliance steps, and production-ready SOC detection queries....

thecybermind.co/9km9

##

CVE-2026-96940
(8.8 HIGH)

EPSS: 0.50%

updated 2026-10-02T21:32:13

3 posts

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

1 repos

https://github.com/HORKimhab/CVE-2026-96940

netsecio@mastodon.social at 2026-10-06T14:29:35.000Z ##

📰 Microsoft Patches High-Severity Exchange Privilege Escalation Flaw

Microsoft issues out-of-band patch for high-severity Exchange Server flaw (CVE-2026-96940). The 8.8 CVSS bug allows authenticated attackers to read other users' mailboxes. #Microsoft #Exchange #PatchTuesday #InfoSec

🔗 cyber.netsecops.io/articles/mi

##

guru@thecybersecguru.com at 2026-10-06T05:39:09.000Z ##

Microsoft Exchange Server Flaw (CVE-2026-96940) Lets Authenticated Attackers Hijack Mailboxes: What You Need to Patch Right Now

CVE-2026-96940 is a high-severity Microsoft Exchange Server flaw that lets authenticated attackers read other users' mailboxes. See affected versions and patches

thecybersecguru.com/exploits/c

##

news@fawkes.rocks at 2026-10-05T11:22:43.000Z ##

Exchange Server CVE-2026-96940 gets out-of-band patch

fawkes.rocks/2026/10/05/exchan

##

CVE-2026-103484
(8.8 HIGH)

EPSS: 0.42%

updated 2026-10-02T18:53:46.583000

1 posts

IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.

sayzard@mastodon.sayzard.org at 2026-10-06T16:42:53.000Z ##

Christophe Pettus: The Vector That Lied About Its Dimensions

pgvector 0.8.7은 IVFFlat 인덱스 빌드 중 벡터 헤더의 차원 수와 컬럼 타입 수정자(vector(1536))가 불일치할 때 발생하던 out-of-bounds write 취약점(CVE-2026-103484)을 수정했다. IVFFlat 인덱스를 생성하거나 REINDEX를 실행할 수 있는 PostgreSQL 역할은 백엔드 임의 코드 실행으로 이어질 가능성이 있으므로, 특히 애플리케이션 DB 역할이 테이블 소유자·마이그레이션 권한을 함께 가진 환경은 노출 여부를 점검해야 한다. 패키지 업그레이드만으로는 부족하며, 이전 pgvector 공유...

thebuild.com/blog/the-vector-t

##

CVE-2026-102489
(9.8 CRITICAL)

EPSS: 1.40%

updated 2026-10-02T18:32:21

3 posts

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

thecybermind@infosec.exchange at 2026-10-04T15:05:08.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-102489 – Zammad GmbH Zammad Session Fixation Vulnerability

Immediate CISA KEV threat advisory for CVE-2026-102489 affecting Zammad. Includes session fixation RCE analysis, CISO compliance steps, and comprehensive asset hardening runbooks....

thecybermind.co/qfru

##

thecybermind@infosec.exchange at 2026-10-04T15:02:52.000Z ##

(CISA TwS) The Cyber Mind TSUITE Brief: CVE-2026-102489 – Zammad GmbH Zammad Session Fixation Vulnerability

Immediate CISA KEV threat advisory for CVE-2026-102489 affecting Zammad. Includes session fixation RCE analysis, BOD 26-04 compliance guidance, and multi-vendor SOC detection queries....

thecybermind.co/l7ux

##

secpoint@mastodon.social at 2026-10-04T12:26:03.000Z ##

Zammad security alert: session hijacking and remote code execution

CVE-2026-102489 concerns session hijacking that can lead to code execution as the Zammad service account on affected older installations. DIVD reports exploitation in a real incident.

Zammad states that version 7.0 and later are not exploitable through this issue and recommends upgrading to 7.2.0.

#Zammad #CyberSecurity #VulnerabilityManagement #SecPoint #Penetrator

##

CVE-2026-91135
(0 None)

EPSS: 0.46%

updated 2026-10-02T18:17:06.963000

1 posts

Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport. When an application enables the ZLIB transform for the frames it sends, THeaderTransport::transform() copies the compressed frame into the write buffer without making sure it fits. Data that does not compress, such as content a remote peer supplied, grows under compression, so the copy writes past the end of the hea

CVE-2026-90970
(9.9 CRITICAL)

EPSS: 0.94%

updated 2026-10-02T15:31:37

3 posts

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command

1 repos

https://github.com/techupdate24/gitlab-ai-gateway-cve-2026-90970

security_crawler_carl@infosec.exchange at 2026-10-04T12:31:23.000Z ##

🏆 New Achievement! Duo-pocalypse Now!

Thank you for contacting GitLab Support. I see you're running a self-hosted AI Gateway. Great choice! Have you tried letting authenticated users execute arbitrary commands on it? Because CVE-2026-90970, CVSS 9.9, has gone ahead and enabled that feature for you. You're welcome. We've escalated your ticket to "catastrophic." (1/3)

##

threatnoir@infosec.exchange at 2026-10-04T10:05:57.000Z ##

⚠️ CRITICAL: GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab disclosed CVE-2026-90970, a critical RCE in AI Gateway that lets authenticated users with Duo Agent Platform access break out of prompt sandbox and run arbitrary commands. Self-hosted deployments are vulnerable; cloud instances are already patched. This is the second critical GitLab vuln in…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

mohith808@mastodon.social at 2026-10-04T09:45:15.000Z ##

POV: you shipped an AI gateway

the prompt template: "hi {{name}}"

a logged in user with a crafted flow config: "what if i was a shell"

gitlab patched a CVSS 9.9 prompt template sandbox escape in its self-hosted AI gateway (CVE-2026-90970). affected: 18.1.6 to 19.2.3, 19.3.0 to 19.3.1, 19.4.0. fixed in 19.2.4, 19.3.2, 19.4.1. gitlab.com and dedicated already patched

#InfoSec #GitLab #AI #DevSecOps

##

CVE-2026-102792
(9.1 CRITICAL)

EPSS: 3.04%

updated 2026-10-02T13:17:21.763000

1 posts

A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the function set_syslog of the file /api/ZRnetwork/set_syslog. The manipulation of the argument conloglevel/log_size results in command injection. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-104286
(9.8 CRITICAL)

EPSS: 2.20%

updated 2026-10-01T21:33:02

2 posts

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

2 repos

https://github.com/techupdate24/fortimail-zero-day-cve-2026-104286

https://github.com/ShadowForge-Cyber/CVE-2026-104286-POC

youranonnewsirc@nerdculture.de at 2026-10-04T16:26:20.000Z ##

Geopolitical tensions are escalating with intensified fighting in Yemen, as Iran reiterates that there is "no military solution" to the ongoing conflict. In technology, OpenAI has halted the release of its GPT-6.1 Astra model citing safety concerns, highlighting the growing scrutiny of advanced AI. On the cybersecurity front, a suspected ShinyHunters hacker has been detained in Jordan, assisting the FBI. Urgent action is also advised for an exploited critical FortiMail zero-day vulnerability (CVE-2026-104286).

#AnonNews_irc #Cybersecurity #News

##

threatnoir@infosec.exchange at 2026-10-04T05:15:04.000Z ##

2026-W40 — Weekly Threat Roundup

🔥 A zero-day in Fortinet FortiMail (CVE-2026-104286) is actively exploited with no patch available yet, demanding immediate workarounds.
🏴‍☠️ Operation KillSwitch dismantled the KillSec ransomware gang, allegedly run by a 16-year-old, seizing 110TB of stolen victim data.
🇨🇳 China-linked Warlock…

threatnoir.com/weekly/2026-w40

#infosec #cybersecurity #threatintel

🤖 AI generated summary

##

CVE-2026-102793
(9.1 CRITICAL)

EPSS: 2.49%

updated 2026-10-01T16:17:35.247000

1 posts

A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function set_time_zone of the file /api/ZRFirmware/set_time_zone. This manipulation of the argument hostname/zonename causes command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-13313(CVSS UNKNOWN)

EPSS: 0.68%

updated 2026-10-01T03:31:14

1 posts

An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby executing arbitrary commands with root privileges and potentially affecting other devices connected to the router. Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security

beyondmachines1@infosec.exchange at 2026-10-05T08:01:14.000Z ##

ASUS Patches Critical Vulnerabilities in Router Firmware Triggered by Malicious VPN Files

ASUS patched two vulnerabilities (CVE-2026-14157 and CVE-2026-13313) in its router firmware that allow authenticated attackers to execute arbitrary commands and gain root privileges via malicious VPN configuration files or active debug code.

**If you have an ASUS router, update its firmware ASAP from the official ASUS support page, and make sure its admin page can only be reached from your trusted internal network, never from the internet. Only import VPN configuration files from providers you trust, and if your router is on ASUS's end-of-life list, plan to replace it since it will not be patched.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-14157(CVSS UNKNOWN)

EPSS: 0.76%

updated 2026-10-01T03:31:13

1 posts

Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface.

beyondmachines1@infosec.exchange at 2026-10-05T08:01:14.000Z ##

ASUS Patches Critical Vulnerabilities in Router Firmware Triggered by Malicious VPN Files

ASUS patched two vulnerabilities (CVE-2026-14157 and CVE-2026-13313) in its router firmware that allow authenticated attackers to execute arbitrary commands and gain root privileges via malicious VPN configuration files or active debug code.

**If you have an ASUS router, update its firmware ASAP from the official ASUS support page, and make sure its admin page can only be reached from your trusted internal network, never from the internet. Only import VPN configuration files from providers you trust, and if your router is on ASUS's end-of-life list, plan to replace it since it will not be patched.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-100520
(8.8 HIGH)

EPSS: 0.94%

updated 2026-09-30T17:32:07.107000

1 posts

Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal sequences in the path parameter to write PHP files into other tenants' web roots and execute code as those tenants.

1 repos

https://github.com/wvllxe/CVE-2026-100520-laranode-path-traversal

DarkWebInformer@infosec.exchange at 2026-10-03T21:40:01.000Z ##

🚨 Public PoC released for CVE-2026-100520 affecting Laranode

github.com/wvllxe/CVE-2026-100

CVE-2026-100520 is a high-severity path traversal flaw in the Laranode multi-tenant hosting control panel that can let a low-privileged authenticated user write files outside their own home directory.

A newly published proof of concept demonstrates how the issue can be chained into remote code execution by placing a PHP file inside another tenant’s web root.

Key details:
⠀
• CVE-2026-100520
• CVSS 3.1: 8.8 HIGH
• CVSS 4.0: 8.7 HIGH
• CWE-22 Path Traversal
• Authenticated exploitation required
• Arbitrary file write
• Cross-tenant impact
• Remote code execution possible
• Laranode versions before 1.2.1 affected
• Fixed in version 1.2.1
⠀
The vulnerability stems from attacker-controlled path values being used when constructing upload destinations without sufficient traversal protections.

The published PoC uses a valid low-privileged account and demonstrates writing a file into a sibling tenant’s web root.

The issue was publicly disclosed on September 21, 2026, and the CVE was published on September 26. The vendor fix was released before the PoC became public.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

##

CVE-2026-102794
(9.1 CRITICAL)

EPSS: 2.36%

updated 2026-09-30T14:17:24.647000

1 posts

A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRnetwork/ping. Such manipulation of the argument url leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12268
(8.8 HIGH)

EPSS: 4.73%

updated 2026-09-29T21:39:02.570000

1 posts

ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution.

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12269
(8.8 HIGH)

EPSS: 6.99%

updated 2026-09-29T21:39:02.570000

1 posts

Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host.

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12267
(7.2 HIGH)

EPSS: 3.60%

updated 2026-09-29T21:39:02.570000

1 posts

ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution.

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-101262
(9.1 CRITICAL)

EPSS: 2.36%

updated 2026-09-29T18:57:24.350000

1 posts

A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any wa

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-84782
(8.2 HIGH)

EPSS: 0.39%

updated 2026-09-29T18:31:49

1 posts

Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake

DailyCyberSecurity@infosec.exchange at 2026-10-05T12:56:02.000Z ##

Discover how the OpenSSL DTLS memory leak (CVE-2026-84782) allows out-of-bounds reads and denial-of-service attacks. Learn about the patch and affected versions.

#OpenSSL #DTLS #MemoryLeak #Cybersecurity #Vulnerability

meterpreter.org/openssl-dtls-m

##

AAKL at 2026-10-06T15:42:14.610Z ##

New.

eSentire: More Shells Than a Seafood Buffet: Tracking Citrix NetScaler Exploitation Activities (CVE-2026-88771) esentire.com/blog/more-shells-

##

blog@insicurezzadigitale.com at 2026-10-06T13:11:27.000Z ##

PitScaler: tre zero-day NetScaler sfruttati in una settimana, due già prima della patch

Tra fine settembre e inizio ottobre 2026 Citrix corregge in emergenza tre zero-day critici su NetScaler ADC/Gateway (CVE-2026-88771, 88772, 88779), tutti sfruttati attivamente prima della divulgazione. Coinvolti i malware inediti WHIPSHOT e SLAPSHOT individuati da Mandiant/GTIG.

insicurezzadigitale.com/pitsca

##

AAKL@infosec.exchange at 2026-10-06T15:42:14.000Z ##

New.

eSentire: More Shells Than a Seafood Buffet: Tracking Citrix NetScaler Exploitation Activities (CVE-2026-88771) esentire.com/blog/more-shells- #infosec #ClickFix #NetScaler #threatresearch #Citrix

##

blog@insicurezzadigitale.com at 2026-10-06T13:11:27.000Z ##

PitScaler: tre zero-day NetScaler sfruttati in una settimana, due già prima della patch

Tra fine settembre e inizio ottobre 2026 Citrix corregge in emergenza tre zero-day critici su NetScaler ADC/Gateway (CVE-2026-88771, 88772, 88779), tutti sfruttati attivamente prima della divulgazione. Coinvolti i malware inediti WHIPSHOT e SLAPSHOT individuati da Mandiant/GTIG.

insicurezzadigitale.com/pitsca

##

hasamba@infosec.exchange at 2026-10-05T15:06:10.000Z ##

----------------

🛠️ Tool
===================

Get-NetScalerTimeline: automated file system timelines for NetScaler ADC/Gateway disk images

Get-NetScalerTimeline.ps1 is a Windows-based DFIR utility from LETHAL-FORENSICS that builds a file system timeline directly from a NetScaler VMDK disk image. It detects the FreeBSD slice and its UFS partitions automatically, keeps native tool output byte-for-byte, normalizes timestamps to UTC ISO 8601, and imports the bodyfile into DuckDB so the result can be hunted with SQL. The stated focus is the persistent locations used by web shells and the log poisoning technique associated with CVE-2026-88771.

Key features
• Partition detection: finds the FreeBSD slice (0xa5) and all UFS partitions under its BSD disk label, including mount points such as /flash and /var.
• VMDK handling: flat extents (*-flat.vmdk), descriptor files, and split images across multiple extents.
• Timeline output: bodyfile via fls and timeline via mactime, UTC ISO 8601, exported as CSV and XLSX.
• DuckDB import: file type, allocated versus deleted status, orphan files, symlink targets, and human-readable timestamps; an interactive DuckDB UI session opens at the end of the run.
• Log extraction: ns.log, httpaccess.log, and httperror.log pulled byte-for-byte from the image, including rotated .gz archives, with SHA256 hashes of the evidence copies.
• Log poisoning detection: a search for fake pitboss heartbeat messages followed by shell operators, mapped to CVE-2026-88771.
• Log coverage reporting: shows how far back the local logs reach, since NetScaler rotates its logs quickly.
• Optional hashing: MD5 and SHA256 over allocated regular files, read from the image and hashed in memory with no file extraction.
• Evidence hygiene: non-UTF-8 filenames preserved, pipe characters in filenames handled, PowerShell re-encoding avoided entirely.

Dependencies and platform

Pinned versions per the README: The Sleuth Kit 4.14.0, Strawberry Perl 5.42.3.1, DuckDB CLI 1.5.6, and the ImportExcel PowerShell module 7.8.10. Tested on Windows 11 Pro x64 with Windows PowerShell 5.1 and PowerShell 7.6.6. Expect to re-validate these versions against current releases before deployment.

Evidence collection caveats

The collection guidance in the README is worth repeating: volatile data first. Generating an NSPPE core dump restarts the NetScaler and wipes the RAM disk (/etc, /netscaler), so run a live triage collection before triggering the dump. The dump itself is written to /var/core, which means free space on /var should be verified beforehand.

Use cases
• Post-imaging triage of suspected NetScaler compromises, with SQL queries over web shell persistence locations on /flash and /var.
• Auditing how much local log history survived rotation before deciding whether to pivot to remote log sources.
• Verifying CVE-2026-88771 log poisoning activity through the pitboss heartbeat heuristic.
• In-memory hashing of allocated files for quick malware screening.

Limitations

Windows-only workflow with pinned dependencies. Fast log rotation means short local coverage; the tool surfaces the gap rather than solving it. Analysis runs against an image, so volatiles need a separate collection step. Haven't tested it personally against a real image; worth validating on lab snapshots before relying on it in a case.

On paper, the DuckDB integration and the byte-for-byte evidence handling are the parts worth noting; validation on real images will tell.

🔹 DFIR #tool #NetScaler #DuckDB #Forensics

🔗 Source: github.com/LETHAL-FORENSICS/Ge

##

DailyCyberSecurity@infosec.exchange at 2026-10-05T07:23:15.000Z ##

Discover how hackers exploit CVE-2026-88771 in Citrix NetScaler to hide PHP web shells as CSS files, granting remote access and compromising networks.

#Citrix #NetScaler #Cybersecurity #WebShell #CVE202688771

meterpreter.org/hackers-camouf

##

bontchev@infosec.exchange at 2026-10-04T21:49:10.000Z ##

@GossiTheDog @jsmall I know but I'm interested not just in CVE-2026-88779. I'm interested in all the recent Netscaler exploits that can be reached via port 443. My honeypot is quite old; it handles only CVE-2019-19781. I couldn't find any good technical write-ups for CVE-2026-88779 - only for CVE-2026-88771 and CVE-2026-88772 but the latter isn't for port 443.

##

todb@infosec.exchange at 2026-10-04T18:47:59.000Z ##

I didn’t realize the EU CERT was so witty!

cert.europa.eu/blog/taking-exe

(analysis of the NetScaler thing from last week.)

##

bontchev@infosec.exchange at 2026-10-04T14:02:03.000Z ##

@GossiTheDog @jsmall I was talking about one of the previous ones (CVE-2026-88771, since it's easier to emulate than CVE-2026-88772). The Watchtowr article I was referring to is this one:

labs.watchtowr.com/oh-look-the

##

CVE-2026-101261
(9.1 CRITICAL)

EPSS: 2.36%

updated 2026-09-29T00:31:38

1 posts

A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the argument login_pwd can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-101075
(10.0 CRITICAL)

EPSS: 2.45%

updated 2026-09-28T21:02:16.150000

1 posts

A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about thi

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-101001
(10.0 CRITICAL)

EPSS: 2.63%

updated 2026-09-28T15:15:33.930000

1 posts

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about thi

secdb@infosec.exchange at 2026-10-05T00:01:27.000Z ##

📈 CVE Published in last 7 days (2026-09-28 - 2026-09-28)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 264
- High: 1061
- Medium: 941
- Low: 181
- None: 99

Status:
- : 37
- Analyzed: 207
- Awaiting Analysis: 736
- Deferred: 1237
- Received: 185
- Rejected: 12
- Undergoing Analysis: 132

CISA KEVs:
- CISA-2026:0929 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0930 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1001 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1002 (secdb.nttzen.cloud/security-ad)
- CISA-2026:1004 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- VulnCheck: 281
- Patchstack: 215
- VulDB: 204
- GitHub, Inc.: 169
- Apache Software Foundation: 155
- Chrome: 152
- Wordfence: 144
- NVIDIA Corporation: 116
- WPScan: 100
- MITRE: 98

Top Affected Products:
- UNKNOWN: 2107
- Google Chrome: 141
- Jetbrains Youtrack: 29
- Yeswiki: 26
- Ghost: 24
- Watchguard Fireware Os: 15
- Moodle: 12
- N8n: 12
- Zfnd Zebra: 11
- Pexip Infinity: 10

Top EPSS Score:
- CVE-2026-12269 - 6.99 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12268 - 4.73 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-12267 - 3.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102792 - 3.04 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101001 - 2.63 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102793 - 2.49 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101075 - 2.45 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101261 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-101262 - 2.36 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-102794 - 2.36 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-88772
(8.1 HIGH)

EPSS: 1.30%

updated 2026-09-28T12:32:09

2 posts

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

8 repos

https://github.com/technion/netscaler_scanner

https://github.com/emilstahl/pitscaler

https://github.com/orjanj/netscaler_threat_hunt_helper

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

https://github.com/securekomodo/citrixInspector

https://github.com/murrez/CVE-2026-88772

https://github.com/FollowerSeize/CVE-2026-88772-POC

bontchev@infosec.exchange at 2026-10-04T21:49:10.000Z ##

@GossiTheDog @jsmall I know but I'm interested not just in CVE-2026-88779. I'm interested in all the recent Netscaler exploits that can be reached via port 443. My honeypot is quite old; it handles only CVE-2019-19781. I couldn't find any good technical write-ups for CVE-2026-88779 - only for CVE-2026-88771 and CVE-2026-88772 but the latter isn't for port 443.

##

bontchev@infosec.exchange at 2026-10-04T14:02:03.000Z ##

@GossiTheDog @jsmall I was talking about one of the previous ones (CVE-2026-88771, since it's easier to emulate than CVE-2026-88772). The Watchtowr article I was referring to is this one:

labs.watchtowr.com/oh-look-the

##

CVE-2026-58270
(6.5 MEDIUM)

EPSS: 0.35%

updated 2026-09-24T21:25:27.050000

1 posts

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, the sync diff endpoint compiles a user-supplied string into a `RegExp` with no complexity validation. A catastrophic-backtracking pattern (e.g. `^(a+)+b`) blocks the Node.js event loop, making the entire server unresponsive to all users until the container is restarted. Version

hugovalters@mastodon.social at 2026-10-06T16:10:23.000Z ##

CVE-2026-58270: Sync-in Server ReDoS in the sync diff endpoint. A crafted regex pattern stalls the Node.js event loop, taking the whole server offline until restart. CVSS 6.5. Fixed in 2.4.0, patch still under review. valtersit.com/cve/CVE-2026-582
#CVE #infosec #cybersecurity

##

CVE-2026-77561
(5.3 MEDIUM)

EPSS: 0.60%

updated 2026-09-22T20:37:12

1 posts

### Summary Tinyauth's login rate-limit bookkeeping can enter a global lockdown mode when its in-memory login-attempt map reaches 256 distinct identifiers. Because unauthenticated `POST /api/user/login` requests for unknown usernames are recorded in this same map, a remote unauthenticated attacker can submit 257 unique bogus usernames and cause valid credentials for unrelated users to be treated

hugovalters@mastodon.social at 2026-10-06T14:30:02.000Z ##

CVE-2026-77561 Tinyauth: unauthenticated attacker can flood fake usernames to trigger a global login lockdown, denying access to all users. CVSS 5.3. Patch under review, no fix yet, so watch for 5.1.0. Details: valtersit.com/cve/CVE-2026-775 #CVE #infosec #Tinyauth

##

CVE-2026-94491
(7.3 HIGH)

EPSS: 0.41%

updated 2026-09-22T19:16:59.663000

1 posts

A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp. Executing a manipulation of the argument address can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in an

hugovalters@mastodon.social at 2026-10-06T13:00:24.000Z ##

CVE-2026-94491 Yonyou KSOA 9.0 SQLi in /cardcase/search_list.jsp via address param, CVSS 7.3. Public exploit, no vendor response, no patch. Isolate or block the endpoint now. valtersit.com/cve/CVE-2026-944 #CVE #infosec #Yonyou

##

CVE-2026-63272(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-09-22T12:30:26

1 posts

LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text were read separately from the file and were not required to agree, so drawing the text walked the advance array by character position and ran past its end when the a

hugovalters@mastodon.social at 2026-10-04T01:40:01.000Z ##

CVE-2026-63272 LibreOffice heap buffer overflow when importing WMF graphics in documents. CVSS 5.3. No patch yet. Avoid untrusted files and update as soon as a fix ships. valtersit.com/cve/CVE-2026-632 #CVE #infosec #LibreOffice

##

CVE-2026-94535
(7.1 HIGH)

EPSS: 0.47%

updated 2026-09-22T00:31:02

1 posts

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications. Attackers can call the DELETE /anyone/extendNotice/deleteMyNotice endpoint with arbitrary notice IDs to permanently remove notifications belonging to other users without recipient validation.

hugovalters@mastodon.social at 2026-10-06T11:20:22.000Z ##

CVE-2026-94535 lamp-cloud up to 5.10.0: auth bypass in deleteMyNotice endpoint lets any authenticated user delete other users' notifications. CVSS 7.1, no patch yet. Restrict endpoint access now. valtersit.com/cve/CVE-2026-945 #CVE #infosec #cybersecurity

##

CVE-2026-93485
(7.1 HIGH)

EPSS: 0.38%

updated 2026-09-18T06:32:17

1 posts

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.1

4 repos

https://github.com/HORKimhab/CVE-2026-93485

https://github.com/0xBlackash/CVE-2026-93485

https://github.com/DeathShotXD/Comment2Shell

https://github.com/686f6c61/POC-WP-CORE-CVE-2026-93485

sekurakbot@mastodon.com.pl at 2026-10-06T09:38:00.000Z ##

Podatność XSS w komentarzach WordPress mogła prowadzić do RCE

Badacz bezpieczeństwa Rafie Muhammad odkrył podatność XSS mogącą eskalować do RCE w systemie komentarzy WordPress. Dowolny nieuwierzytelniony użytkownik mógł dodać komentarz, który umieszczał na stronie ukryty skrypt. Jeśli stronę tę otworzył administrator zalogowany na swoim koncie, skrypt mógł wgrać złośliwą wtyczkę na serwer witryny. Podatność otrzymała numer CVE-2026-93485 i została...

#Aktualności #Podatność #Rce #Wordpress #XSS

sekurak.pl/podatnosc-xss-w-kom

##

CVE-2026-10536
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-09-15T07:16:25.137000

1 posts

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during

CVE-2026-8452
(9.8 CRITICAL)

EPSS: 1.01%

updated 2026-08-26T18:30:34

1 posts

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

6 repos

https://github.com/techupdate24/citrix-netscaler-cve-2026-8452-rce

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

https://github.com/maxprog-svg/CitrixBleedCVE-2026-8452-2025-5777

https://github.com/securekomodo/citrixInspector

https://github.com/BishopFox/CVE-2026-8452-check

https://github.com/derekpreston81/CVE_ADC_IOC_2026

GossiTheDog@cyberplace.social at 2026-10-05T10:14:31.000Z ##

I need @watchTowr to fact-check me here but I think CVE-2026-88779 is a redux of CVE-2026-8452? At least based on this mitigation Citrix support are giving out, somebody posted it on their blog. deyda.net/index.php/de/2026/08

The 8452 patch locked SAML PrefixList to 512 byte or below string. But I think CVE-2026-88779 may be more than 15 items in PrefixList, space-separated, to trigger a vuln. Assuming Citrix support gave out the right mitigation.

##

CVE-2026-59309
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-08-25T18:12:14.410000

1 posts

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

1 repos

https://github.com/chu0119/vc-strike

sayzard@mastodon.sayzard.org at 2026-10-06T10:39:59.000Z ##

Patch-diffing VMware vCenter to auth bypass and RCE

Mobeta 연구진은 VMware vCenter Server Appliance 8.0.3.00900과 수정본 8.0.3.01000을 파일 단위로 패치 디핑해, 인증 없이 악용 가능한 CVE-2026-59309와 CVE-2026-59310의 원인을 추적했다. CVE-2026-59310은 vCenter 내장 syslog 수신기의 rsyslog dynafile 템플릿이 공격자 제어 RFC 5424 `HOSTNAME` 및 `APP-NAME` 값을 경로 검증 없이 파일 경로에 삽입하는 디렉터리 트래버설 취약점으로, UDP/TCP 514에서 임의 파일 쓰기와 RCE로 이어질 수 있다. 특...

mobeta.fr/blog/vcenter-cve-202

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 2.56%

updated 2026-08-18T18:32:52

1 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

5 repos

https://github.com/vpxuser/CVE-2026-59310

https://github.com/chu0119/vc-strike

https://github.com/HORKimhab/CVE-2026-59310

https://github.com/ChinaRan0/CVE-2026-59310-POC

https://github.com/BiuTrap/CVE-2026-59310

sayzard@mastodon.sayzard.org at 2026-10-06T10:39:59.000Z ##

Patch-diffing VMware vCenter to auth bypass and RCE

Mobeta 연구진은 VMware vCenter Server Appliance 8.0.3.00900과 수정본 8.0.3.01000을 파일 단위로 패치 디핑해, 인증 없이 악용 가능한 CVE-2026-59309와 CVE-2026-59310의 원인을 추적했다. CVE-2026-59310은 vCenter 내장 syslog 수신기의 rsyslog dynafile 템플릿이 공격자 제어 RFC 5424 `HOSTNAME` 및 `APP-NAME` 값을 경로 검증 없이 파일 경로에 삽입하는 디렉터리 트래버설 취약점으로, UDP/TCP 514에서 임의 파일 쓰기와 RCE로 이어질 수 있다. 특...

mobeta.fr/blog/vcenter-cve-202

##

CVE-2026-15307
(8.8 HIGH)

EPSS: 1.09%

updated 2026-08-18T16:29:03.070000

1 posts

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a spatial lookup against a `GeometryField` or `RasterField` reaches this constructor, including untrusted input, for example a spatial-field filter subm

EUVD_Bot@mastodon.social at 2026-10-06T15:00:11.000Z ##

🚨 EUVD-2026-93388

📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: Django, Django, Django
🏢 Vendor: djangoproject
📅 Updated: 2026-10-06

📝 An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18.
An incomplete fix for CVE-2026-15307 in Django spatial lookups allows an attacker who can supply `bytes` values to cause the Django process to m...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-43682
(9.8 CRITICAL)

EPSS: 0.72%

updated 2026-07-29T17:03:19.340000

1 posts

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

1 repos

https://github.com/petermalone/CVE-2026-43682

CVE-2026-35273
(9.8 CRITICAL)

EPSS: 9.44%

updated 2026-07-23T09:10:00.113000

5 posts

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of Peopl

4 repos

https://github.com/HORKimhab/CVE-2026-35273

https://github.com/ekomsSavior/POC_cve_2026_35273

https://github.com/0xBlackash/CVE-2026-35273

https://github.com/12hrformat/CVE-2026-35273-POC

christopherkunz@chaos.social at 2026-10-06T11:45:54.000Z ##

Accenture, acting as a contractor for the FBI, allegedly failed to install updates for Oracle Peoplesoft after CVE-2026-35273 was published.

This was a "Missing Authentication for Critical Function" vulnerability and scored 9.8. If this didn't raise any flags, the CISA KEV listing should have. It was an n-day at release.

But no, interestingly enough the FBI is exempt from BOD 26-04 and wasn't even obliged to update?!

Man, if not even federal agencies fix their vulns, this is all pointless.

##

youranonnewsirc@nerdculture.de at 2026-10-06T10:25:39.000Z ##

Recent cybersecurity threats include Atlassian patching critical vulnerabilities (CVE-2026-21589) in Jira, Confluence, and Bitbucket enabling file access. The FBI removed an Accenture contractor after a ShinyHunters breach of employee data via an unpatched Oracle PeopleSoft flaw (CVE-2026-35273). In technology, OpenAI's GPT-6 Astra model demonstrated supply-chain attack behavior in simulations. Geopolitically, the Mecca Defense Alliance committed to collective defense measures on October 5, 2026.

#Cybersecurity #AnonNews_irc #News

##

christopherkunz@chaos.social at 2026-10-06T11:45:54.000Z ##

Accenture, acting as a contractor for the FBI, allegedly failed to install updates for Oracle Peoplesoft after CVE-2026-35273 was published.

This was a "Missing Authentication for Critical Function" vulnerability and scored 9.8. If this didn't raise any flags, the CISA KEV listing should have. It was an n-day at release.

But no, interestingly enough the FBI is exempt from BOD 26-04 and wasn't even obliged to update?!

Man, if not even federal agencies fix their vulns, this is all pointless.

##

youranonnewsirc@nerdculture.de at 2026-10-06T10:25:39.000Z ##

Recent cybersecurity threats include Atlassian patching critical vulnerabilities (CVE-2026-21589) in Jira, Confluence, and Bitbucket enabling file access. The FBI removed an Accenture contractor after a ShinyHunters breach of employee data via an unpatched Oracle PeopleSoft flaw (CVE-2026-35273). In technology, OpenAI's GPT-6 Astra model demonstrated supply-chain attack behavior in simulations. Geopolitically, the Mecca Defense Alliance committed to collective defense measures on October 5, 2026.

#Cybersecurity #AnonNews_irc #News

##

guru@thecybersecguru.com at 2026-10-06T09:54:06.000Z ##

Inside the FBI ShinyHunters Breach: How an Unpatched PeopleSoft Flaw and WAF Bypass Exposed Thousands of Agents

The FBI ShinyHunters breach exposed employee data through an unpatched Oracle PeopleSoft flaw, CVE-2026-35273, and a WAF bypass. Here's how it happened

thecybersecguru.com/news/fbi-s

##

CVE-2026-61500
(9.8 CRITICAL)

EPSS: 0.99%

updated 2026-07-13T18:31:00

8 posts

Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full admi

1 repos

https://github.com/aramosf/CVE-2026-61500

beyondmachines1 at 2026-10-06T14:01:49.278Z ##

Vulnerability in Rejetto HFS Leads to Remote Code Execution, Actively Exploited

A critical authentication bypass is reported in Rejetto HFS (CVE-2026-61500) that allows remote code execution. Attackers are actively exploiting the flaw to forge administrator sessions and take control of servers.

**If you run Rejetto HTTP File Server (versions 3.0.0 to 3.2.0), update to version 3.2.1 or later right away. Attackers are already using this flaw to take full control of servers. Make sure to isolate the admin panel from internet access (use a VPN or firewall), and check your logs for unexpected admin logins or changes to the `server_code` setting, which would mean you may already be compromised.**

beyondmachines.net/event_detai

##

DailyCyberSecurity at 2026-10-06T13:58:35.984Z ##

Discover how Anthropic's Mythos AI synthesized a remote code execution exploit for Rejetto HFS, exposing CVE-2026-61500 through mathematical state recovery.

meterpreter.org/anthropic-myth

##

threatnoir at 2026-10-06T10:06:22.157Z ##

⚠️ CRITICAL: Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Rejetto HFS vulnerability CVE-2026-61500 allows attackers to forge admin sessions and execute code via weak session cookie signing. Active exploitation detected in October 2026 targeting US organizations, despite a patch released in July 2026. Any unpatched HFS instance is immediately compromised.

threatnoir.com/focus

🤖 AI generated summary

##

beyondmachines1@infosec.exchange at 2026-10-06T14:01:49.000Z ##

Vulnerability in Rejetto HFS Leads to Remote Code Execution, Actively Exploited

A critical authentication bypass is reported in Rejetto HFS (CVE-2026-61500) that allows remote code execution. Attackers are actively exploiting the flaw to forge administrator sessions and take control of servers.

**If you run Rejetto HTTP File Server (versions 3.0.0 to 3.2.0), update to version 3.2.1 or later right away. Attackers are already using this flaw to take full control of servers. Make sure to isolate the admin panel from internet access (use a VPN or firewall), and check your logs for unexpected admin logins or changes to the `server_code` setting, which would mean you may already be compromised.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-10-06T13:58:35.000Z ##

Discover how Anthropic's Mythos AI synthesized a remote code execution exploit for Rejetto HFS, exposing CVE-2026-61500 through mathematical state recovery.

#Anthropic #MythosAI #CVE202661500 #Cybersecurity #RejettoHFS

meterpreter.org/anthropic-myth

##

threatnoir@infosec.exchange at 2026-10-06T10:06:22.000Z ##

⚠️ CRITICAL: Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Rejetto HFS vulnerability CVE-2026-61500 allows attackers to forge admin sessions and execute code via weak session cookie signing. Active exploitation detected in October 2026 targeting US organizations, despite a patch released in July 2026. Any unpatched HFS instance is immediately compromised.

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

oversecurity@mastodon.social at 2026-10-05T20:40:09.000Z ##

Rejetto HFS servers now actively scanned for critical RCE flaw

Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account...

🔗️ [Bleepingcomputer] link.is.it/CsBrJG

##

cyberworldops@infosec.exchange at 2026-10-05T11:10:00.000Z ##

VulnCheck observed active exploitation of CVE-2026-61500 in Rejetto HFS on October 1 against US hosts. The flaw leaks weak PRNG output allowing recovery of the session signing key and forged admin sessions leading to RCE. Treat internet-exposed HFS as potentially compromised and patch and hunt now. #RejettoHfs #SessionForgery #RemoteCodeExecution

cyberworldops.eu/en/rejetto-hf

##

CVE-2026-8441
(7.5 HIGH)

EPSS: 0.46%

updated 2026-07-02T13:58:56.870000

1 posts

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp_load_more_revs AJAX action in versions up to, and including, 12.7.2. The parameter is read via $_POST['notinstring'] and passed through sanitize_text_field() — which strips HTML and whitespace but does not provide SQL safety. The value is then concatenated directly into a numeri

hackmag@infosec.exchange at 2026-10-05T03:00:19.000Z ##

⚪️ CISA Warns of Critical RCE Vulnerability in MikroTik RouterOS

🗨️ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned about a critical vulnerability, CVE-2026-84411, in MikroTik RouterOS. The flaw allows unauthenticated remote attackers to execute arbitrary code with root privileges or trigger a denial-of-service (DoS) condition. Exploit…

🔗 hackmag.com/news/cve-2026-8441

#news

##

CVE-2026-27706
(7.7 HIGH)

EPSS: 0.37%

updated 2026-06-17T10:27:33.140000

1 posts

Plane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSRF) vulnerability has been identified in the "Add Link" feature. This flaw allows an authenticated attacker with general user privileges to send arbitrary GET requests to the internal network and exfiltrate the full response body. By exploiting this vulnerability, an attacker can

thehackerwire@mastodon.social at 2026-10-05T19:17:04.000Z ##

🟠 CVE-2026-104977 - High (7.7)

Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-27706 and GHSA-jcc6-f9v6-f7jw, an SSRF in work-item link unfurling shipped in v1.2.2, remains incomplete in the v1.3.1 GA release. Any authenticated project memb...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-6543
(9.8 CRITICAL)

EPSS: 10.56%

updated 2026-06-17T10:02:07.007000

2 posts

Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

4 repos

https://github.com/fox-it/citrix-netscaler-triage

https://github.com/lex1010/CVE-2025-6543

https://github.com/grupooruss/Citrix-cve-2025-6543

https://github.com/abrewer251/CVE-2025-6543_CitrixNetScaler_PoC

security_crawler_carl@infosec.exchange at 2026-10-05T11:11:27.000Z ##

🏆 New Achievement! Phase Two Has Already Started!

RAID ALERT. RAID ALERT. NetScaler has entered its second phase and nobody called it. CVE-2026-88779 — officially labeled a "Memory overflow, Denial of Service" — is pulling the same bait-and-switch as CVE-2025-6543 before it: DoS skin, RCE skeleton underneath. watchTowr Labs reproduced it off honeypot activity. Admins watched patched appliances reboot anyway. You wiped. Again. (1/2)

##

GossiTheDog@cyberplace.social at 2026-10-04T09:55:03.000Z ##

The new Citrix Netscaler vuln from Friday is CVE-2026-88779, patch is out now and they recommend patching as soon as possible: support.citrix.com/support-hom

Although the vuln is labeled “Memory overflow vulnerability leading to Denial of Service”, that’s the same as CVE-2025–6543. You may remember that lead to RCE in the wild. Prior blog on that: doublepulsar.com/citrix-forgot

##

CVE-2024-3094
(10.0 CRITICAL)

EPSS: 85.97%

updated 2026-06-17T07:43:17.830000

1 posts

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked

90 repos

https://github.com/hackingetico21/revisaxzutils

https://github.com/Mustafa1986/CVE-2024-3094

https://github.com/stevehenderson/lab_xz_backdoor

https://github.com/r0binak/xzk8s

https://github.com/robertdebock/ansible-role-cve_2024_3094

https://github.com/iheb2b/CVE-2024-3094-Checker

https://github.com/byinarie/CVE-2024-3094-info

https://github.com/24Owais/threat-intel-cve-2024-3094

https://github.com/Ava-Vispilio/CVE-2024-3094

https://github.com/robertdfrench/ifuncd-up

https://github.com/buluma/ansible-role-cve_2024_3094

https://github.com/M1lo25/CS50FinalProject

https://github.com/devjanger/CVE-2024-3094-XZ-Backdoor-Detector

https://github.com/spidygal/CVE-2024-3094-Nmap-NSE-script

https://github.com/wgetnz/CVE-2024-3094-check

https://github.com/encikayelwhitehat-glitch/CVE-2024-3094

https://github.com/michalAshurov/writeup-CVE-2024-3094

https://github.com/dah4k/CVE-2024-3094

https://github.com/Dermot-lab/TryHack

https://github.com/HackerHermanos/CVE-2024-3094_xz_check

https://github.com/pentestfunctions/CVE-2024-3094

https://github.com/ElinaNotElina/cve-2024-3094-analysis

https://github.com/Security-Phoenix-demo/CVE-2024-3094-fix-exploits

https://github.com/neuralinhibitor/xzwhy

https://github.com/KaminaDuck/ansible-CVE-2024-3094

https://github.com/ThomRgn/xzutils_backdoor_obfuscation

https://github.com/nnatsopoulos/xz-backdoor-research

https://github.com/Titus-soc/-CVE-2024-3094-Vulnerability-Checker-Fixer-Public

https://github.com/felipecosta09/cve-2024-3094

https://github.com/0xlane/xz-cve-2024-3094

https://github.com/przemoc/xz-backdoor-links

https://github.com/namegabevictoire01-sys/cs50-cybersecurity-final-project

https://github.com/Yuma-Tsushima07/CVE-2024-3094

https://github.com/isuruwa/CVE-2024-3094

https://github.com/brinhosa/CVE-2024-3094-One-Liner

https://github.com/h3raklez/CVE-2024-3094

https://github.com/gustavorobertux/CVE-2024-3094

https://github.com/hackura/xz-cve-2024-3094

https://github.com/Preacher98/Report-XZ-Utils-CVE-2024-3094

https://github.com/ashwani95/CVE-2024-3094

https://github.com/AndreaCicca/Sicurezza-Informatica-Presentazione

https://github.com/hazemkya/CVE-2024-3094-checker

https://github.com/jbnetwork-git/CVE-2024-3094-XZ-Utils-Check

https://github.com/gensecaihq/CVE-2024-3094-Vulnerability-Checker-Fixer

https://github.com/vesjolyjd/Kaspersky_CVE-2024-3094

https://github.com/TheTorjanCaptain/CVE-2024-3094-Checker

https://github.com/mightysai1997/CVE-2024-3094-info

https://github.com/laxmikumari615/Linux---Security---Detect-and-Mitigate-CVE-2024-3094

https://github.com/harekrishnarai/xz-utils-vuln-checker

https://github.com/Michel-DV/xz-utils-backdoor-case-study

https://github.com/FabioBaroni/CVE-2024-3094-checker

https://github.com/MrBUGLF/XZ-Utils_CVE-2024-3094

https://github.com/BOSE122/CVE-2024-3094

https://github.com/ackemed/detectar_cve-2024-3094

https://github.com/shefirot/CVE-2024-3094

https://github.com/vnchk1/sec_review_cve-2024-3094

https://github.com/been22426/CVE-2024-3094

https://github.com/weltregie/liblzma-scan

https://github.com/mhicairo-hue/cs50-cybersecurity-final-project

https://github.com/mrk336/CVE-2024-3094

https://github.com/zpxlz/CVE-2024-3094

https://github.com/ScrimForever/CVE-2024-3094

https://github.com/Ikram124/CVE-2024-3094-analysis

https://github.com/extracoding-dozen/CVE-2024-3094

https://github.com/Bella-Bc/xz-backdoor-CVE-2024-3094-Check

https://github.com/MagpieRYL/CVE-2024-3094-backdoor-env-container

https://github.com/Fractal-Tess/CVE-2024-3094

https://github.com/0xBlackash/CVE-2024-3094

https://github.com/galacticquest/cve-2024-3094-detect

https://github.com/badsectorlabs/ludus_xz_backdoor

https://github.com/OpensourceICTSolutions/xz_utils-CVE-2024-3094

https://github.com/lypd0/CVE-2024-3094-Vulnerabity-Checker

https://github.com/bsekercioglu/cve2024-3094-Checker

https://github.com/emirkmo/xz-backdoor-github

https://github.com/teyhouse/CVE-2024-3094

https://github.com/hariskhalil555000-sketch/What-utility-does-CVE-2024-3094-refer-to-

https://github.com/Horizon-Software-Development/CVE-2024-3094

https://github.com/valeriot30/cve-2024-3094

https://github.com/Juul/xz-backdoor-scan

https://github.com/x-cmd-build/xz

https://github.com/jfrog/cve-2024-3094-tools

https://github.com/mesutgungor/xz-backdoor-vulnerability

https://github.com/Simplifi-ED/CVE-2024-3094-patcher

https://github.com/amlweems/xzbot

https://github.com/mightysai1997/CVE-2024-3094

https://github.com/robertdebock/ansible-playbook-cve-2024-3094

https://github.com/lockness-Ko/xz-vulnerable-honeypot

https://github.com/fevar54/Detectar-Backdoor-en-liblzma-de-XZ-utils-CVE-2024-3094-

https://github.com/bioless/xz_cve-2024-3094_detection

https://github.com/ykhurshudyan-blip/CVE-2024-3094

cvedatabase@techhub.social at 2026-10-06T10:30:04.000Z ##

As development shifts toward modular architecture, software supply chain attacks have become a top priority for security teams. Our latest analysis breaks down the technical mechanics of recent critical vulnerabilities like CVE-2024-3094 and Log4j. Stay ahead of the threat actors. 🛡️ Read the full deep-dive: cvedatabase.com/blog/the-invis #CyberSecurity #SupplyChain #InfoSec #DevSecOps #CVE

##

CVE-2026-9862
(9.8 CRITICAL)

EPSS: 1.48%

updated 2026-06-15T18:31:25

1 posts

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.

beyondmachines1@infosec.exchange at 2026-10-05T09:01:13.000Z ##

Fortra Patches Command Injection Flaw in BoKS Core PAM

Fortra fixed a command injection vulnerability (CVE-2026-9862) in its BoKS Core PAM that allows unauthenticated remote code execution. The flaw targets the autoregistration service and can lead to full system compromise.

**If you use Fortra BoKS Core 8.1 or 9.0, apply Fortra's security update ASAP. Attackers are already scanning for exposed systems and can take full control without a password. If you can't patch immediately, turn off the `boks_autoregisterd` service and block port 6507 so only trusted systems can reach it.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-48842
(8.1 HIGH)

EPSS: 0.89%

updated 2026-06-04T00:31:26

1 posts

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

3 repos

https://github.com/XsanFlip/POC-CVE-2026-48842

https://github.com/murrez/CVE-2026-48842

https://github.com/4minx/CVE-2026-48842

beyondmachines1@infosec.exchange at 2026-10-04T14:01:13.000Z ##

Roundcube Webmail SQL Injection Vulnerability CVE-2026-48842 Under Active Exploitation

Roundcube Webmail high-severity SQL injection vulnerability (CVE-2026-48842) in its virtuser_query plugin is being actively exploited, allowing unauthenticated attackers to compromise databases and steal sensitive email data.

**If you run Roundcube Webmail (common in cPanel and other web hosting), update immediately to version 1.6.16 or 1.7.1. The flaw is actively exploited to steal mail, passwords and accounts. If you can't update right away, disable the `virtuser_query` plugin, and check your database logs for anything unusual, since you may already have been breached.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-40281
(10.0 CRITICAL)

EPSS: 2.09%

updated 2026-05-08T19:26:58

1 posts

## Vulnerability Details **CWE**: CWE-20 - Improper Input Validation The metadata value sanitization introduced in v8.30.1 (commit 405f106) only validates metadata KEYS via safeKeyPattern regex. Metadata VALUES are passed unsanitized to go-exiftool SetString(), which writes them as fmt.Fprintln(e.stdin, "-"+k+"="+str). A newline (\n) in a value splits the ExifTool stdin line into two separate ar

Nuclei template

5 repos

https://github.com/codeb0ssx/CVE-2026-42589xCVE-2026-40281-PoC

https://github.com/0xgh057r3c0n/CVE-2026-40281

https://github.com/MRdark-ops/CVE-2026-40281-exploit

https://github.com/HackfutSecRoot/-GOTENBERG-RCE-CHAIN

https://github.com/rabakuku/CVE-2026-40281

DarkWebInformer@infosec.exchange at 2026-10-03T21:23:59.000Z ##

🚨 Public exploit released for CVE-2026-40281 affecting Gotenberg

github.com/MRdark-ops/CVE-2026

A proof-of-concept exploit has been published for CVE-2026-40281, a critical unauthenticated remote code execution vulnerability affecting Gotenberg versions prior to 8.31.0.

The flaw affects Gotenberg’s PDF metadata handling and can allow a remote attacker to inject commands through crafted metadata values sent to the /forms/pdfengines/metadata/write endpoint. No authentication or user interaction is required.

Key details:
⠀
• CVE-2026-40281
• CVSS: 9.1 Critical
• Gotenberg < 8.31.0 affected
• Unauthenticated remote code execution
• Network exploitable
• Low attack complexity
• Public PoC now available
• Fixed in Gotenberg 8.31.0
⠀
The published exploit supports vulnerability detection, single-command execution and an interactive shell against vulnerable instances.

Organizations running affected Gotenberg deployments should upgrade to version 8.31.0 or later.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

##

CVE-2024-7971
(8.8 HIGH)

EPSS: 21.10%

updated 2025-10-22T00:34:11

1 posts

Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

1 repos

https://github.com/mistymntncop/CVE-2024-7971

humancoders@mastodon.social at 2026-10-06T07:00:05.000Z ##

Un simple message Twitch a suffi à exécuter du code sur la machine d'un streamer : overlay affichant le chat en HTML brut, Chromium embarqué dans OBS sans sandbox, faille V8 déjà exploitée (CVE-2024-7971). ⬇️
news.humancoders.com/t/securit

##

CVE-2021-35394
(9.8 CRITICAL)

EPSS: 99.86%

updated 2025-10-22T00:33:23

3 posts

Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.

netsecio@mastodon.social at 2026-10-06T14:29:41.000Z ##

📰 "ClingSTUN" Botnet Exploits IoT Devices Using STUN Protocol for C2

New 'ClingSTUN' botnet targets routers & DVRs, exploiting flaws like CVE-2021-35394. Uniquely uses STUN protocol for C2 comms to evade detection, turning devices into proxy nodes. #Botnet #Malware #IoT #ClingSTUN

🔗 cyber.netsecops.io/articles/cl

##

threatnoir at 2026-10-06T10:06:19.859Z ##

⚠️ CRITICAL: Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Threat actors are actively exploiting CVE-2021-35394 in Realtek Jungle SDK to deploy the Cling botnet, which uses STUN protocol traffic to hide C2 communications as legitimate NAT traversal. Affected devices include routers and DVRs running vulnerable Realtek firmware. The malware achieves persiste…

threatnoir.com/focus

🤖 AI generated summary

##

threatnoir@infosec.exchange at 2026-10-06T10:06:19.000Z ##

⚠️ CRITICAL: Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Threat actors are actively exploiting CVE-2021-35394 in Realtek Jungle SDK to deploy the Cling botnet, which uses STUN protocol traffic to hide C2 communications as legitimate NAT traversal. Affected devices include routers and DVRs running vulnerable Realtek firmware. The malware achieves persiste…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

CVE-2019-19781
(9.8 CRITICAL)

EPSS: 100.00%

updated 2025-10-22T00:31:50

1 posts

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

Nuclei template

50 repos

https://github.com/L4r1k/CitrixNetscalerTriageScript

https://github.com/aqhmal/CVE-2019-19781

https://github.com/onSec-fr/CVE-2019-19781-Forensic

https://github.com/Castaldio86/Detect-CVE-2019-19781

https://github.com/MalwareTech/CitrixHoneypot

https://github.com/b510/CVE-2019-19781

https://github.com/hyunjin0334/CVE-2019-19781

https://github.com/oways/CVE-2019-19781

https://github.com/unknowndevice64/Exploits_CVE-2019-19781

https://github.com/trustedsec/cve-2019-19781

https://github.com/EliusHHimel/citrix-honeypot

https://github.com/jas502n/CVE-2019-19781

https://github.com/becrevex/Citrix_CVE-2019-19781

https://github.com/redscan/CVE-2019-19781

https://github.com/yukar1z0e/CVE-2019-19781

https://github.com/pwn3z/CVE-2019-19781-Citrix

https://github.com/digitalgangst/massCitrix

https://github.com/tpdlshdmlrkfmcla/CVE-2019-19781

https://github.com/hollerith/CVE-2019-19781

https://github.com/w4fz5uck5/CVE-2019-19781-CitrixRCE

https://github.com/0xams/citrixvulncheck

https://github.com/zgelici/CVE-2019-19781-Checker

https://github.com/autocode07/cisagov__check-cve-2019-19781.4142e02b

https://github.com/mekhalleh/citrix_dir_traversal_rce

https://github.com/34zY/APT-Backpack

https://github.com/projectzeroindia/CVE-2019-19781

https://github.com/cisagov/check-cve-2019-19781

https://github.com/awesome-security/citrixmash_scanner

https://github.com/citrix/ioc-scanner-CVE-2019-19781

https://github.com/Azeemering/CVE-2019-19781-DFIR-Notes

https://github.com/jamesjguthrie/Shitrix-CVE-2019-19781

https://github.com/Roshi99/Remote-Code-Execution-Exploit-for-Citrix-Application-Delivery-Controller-and-Citrix-Gateway-CVE-201

https://github.com/andripwn/CVE-2019-19781

https://github.com/k-fire/CVE-2019-19781-exploit

https://github.com/digitalshadows/CVE-2019-19781_IOCs

https://github.com/j81blog/ADC-19781

https://github.com/qiong-qi/CVE-2019-19781-poc

https://github.com/r4ulcl/CVE-2019-19781

https://github.com/L4r1k/CitrixNetscalerAnalysis

https://github.com/VladRico/CVE-2019-19781

https://github.com/darren646/CVE-2019-19781POC

https://github.com/mandiant/ioc-scanner-CVE-2019-19781

https://github.com/zerobytesecure/CVE-2019-19781

https://github.com/LeapBeyond/cve_2019_19781

https://github.com/ianxtianxt/CVE-2019-19781

https://github.com/DanielWep/CVE-NetScalerFileSystemCheck

https://github.com/nmanzi/webcvescanner

https://github.com/mpgn/CVE-2019-19781

https://github.com/SharpHack/CVE-2019-19781

https://github.com/Vulnmachines/Ctirix_RCE-CVE-2019-19781

bontchev@infosec.exchange at 2026-10-04T21:49:10.000Z ##

@GossiTheDog @jsmall I know but I'm interested not just in CVE-2026-88779. I'm interested in all the recent Netscaler exploits that can be reached via port 443. My honeypot is quite old; it handles only CVE-2019-19781. I couldn't find any good technical write-ups for CVE-2026-88779 - only for CVE-2026-88771 and CVE-2026-88772 but the latter isn't for port 443.

##

CVE-2026-100754
(0 None)

EPSS: 0.00%

2 posts

N/A

CVE-2026-82531
(0 None)

EPSS: 0.00%

2 posts

N/A

offseq at 2026-10-06T13:30:51.390Z ##

CVE-2026-82531: CRITICAL code injection bug in smarty-php Smarty (<4.5.8, 5.0.0<5.8.5). Exploitation enables remote PHP code execution via forged nocache markers. Patch to 4.5.8/5.8.5 ASAP. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-06T13:30:51.000Z ##

CVE-2026-82531: CRITICAL code injection bug in smarty-php Smarty (<4.5.8, 5.0.0<5.8.5). Exploitation enables remote PHP code execution via forged nocache markers. Patch to 4.5.8/5.8.5 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE #infosec #php

##

CVE-2026-86360
(0 None)

EPSS: 0.00%

3 posts

N/A

benzogaga33@mamot.fr at 2026-10-06T09:40:04.000Z ##

Dell PowerEdge : une faille critique permet d’exécuter du code en tant que root sur les serveurs it-connect.fr/dell-system-upda #ActuCybersécurité #Cybersécurité #Vulnérabilité #Dell

##

cyberworldops@infosec.exchange at 2026-10-05T16:00:00.000Z ##

Dell issued an advisory for CVE-2026-86360, a path-traversal flaw in System Update CLI allowing unauthenticated remote filesystem access and root code execution. It matters because DSU typically runs privileged, turning remote access into full compromise. Update immediately and audit exposed hosts. #DellSecurity #PathTraversal #PrivEsc

cyberworldops.eu/en/critical-d

##

news@fawkes.rocks at 2026-10-05T15:26:57.000Z ##

Dell System Update flaw CVE-2026-86360 grants root access

fawkes.rocks/2026/10/05/dell-s

##

CVE-2026-105763
(0 None)

EPSS: 0.28%

2 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-10-06T01:57:52.000Z ##

Twenty CRM vulnerability CVE-2026-105763 (CVSS 9.6) enables plaintext password disclosure of IMAP and SMTP accounts. Upgrade to 2.7.0.

#TwentyCRM #CRM #CVE2026105763 #GraphQL #CredentialLeak #OpenSource #EmailSecurity #Vulnerability

securityonline.info/twenty-crm

##

offseq@infosec.exchange at 2026-10-06T00:00:38.000Z ##

CVE-2026-105763 (CRITICAL): twentyhq twenty CRM v1.20.10 – 2.7.0 exposes plaintext IMAP/SMTP/CalDAV creds to any workspace user via GraphQL. Upgrade to 2.7.0 to prevent mail/calendar compromise. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CRM #twentyhq

##

CVE-2026-104334
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-43598
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-105637
(0 None)

EPSS: 0.32%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T22:46:25.000Z ##

🔴 CVE-2026-105637 - Critical (9.6)

Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves assets using id__in=asset_ids and workspace__slug=slug but does not constrain the query with project_i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105744
(0 None)

EPSS: 0.30%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T22:45:51.000Z ##

🟠 CVE-2026-105744 - High (7.5)

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.94.0 until 2.132.0, callers that opt into LatexBackendOptions(tikz_engine="tectonic") invoke docling/backend/late...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105740
(0 None)

EPSS: 0.59%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T21:31:24.000Z ##

🔴 CVE-2026-105740 - Critical (9.9)

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-suppl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105697
(0 None)

EPSS: 0.40%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T21:31:14.000Z ##

🔴 CVE-2026-105697 - Critical (9.9)

Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrappe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105650
(0 None)

EPSS: 0.33%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T20:34:47.000Z ##

🟠 CVE-2026-105650 - High (8.1)

Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored in post content. These scripts could run in the Ghost editor, on the publishe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105675
(0 None)

EPSS: 0.39%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T20:34:38.000Z ##

🟠 CVE-2026-105675 - High (7.5)

Ghost is a Node.js content management system. From 4.39.0 until 6.64.0, staff users with permission to view staff invites were able to discover the secret token of pending invites, including invites for roles with higher privileges than their own....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105634
(0 None)

EPSS: 0.29%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T20:17:25.000Z ##

🟠 CVE-2026-105634 - High (8.1)

Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization chec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105641
(0 None)

EPSS: 0.46%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T20:17:06.000Z ##

🔴 CVE-2026-105641 - Critical (9.8)

Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when operators...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105640
(0 None)

EPSS: 0.38%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T20:02:05.000Z ##

🔴 CVE-2026-105640 - Critical (9.1)

Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authentica...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105639
(0 None)

EPSS: 0.39%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T20:01:55.000Z ##

🔴 CVE-2026-105639 - Critical (9.8)

Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can call GET ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104979
(0 None)

EPSS: 0.36%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T19:17:21.000Z ##

🟠 CVE-2026-104979 - High (8.7)

Plane is an open-source project management tool. Prior to 1.4.0, IntakeIssuePublicViewSet.create in Plane v1.3.1 writes description_html through Issue.objects.create(...) without calling validate_html_content from nh3. Any authenticated user, incl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104978
(0 None)

EPSS: 0.29%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T19:17:13.000Z ##

🟠 CVE-2026-104978 - High (8.2)

Plane is an open-source project management tool. Prior to 1.4.0, Plane's project invitation list endpoint is accessible to any authenticated user who knows the workspace slug and project ID, while the public project invitation join endpoint accept...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104977
(0 None)

EPSS: 0.30%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T19:17:04.000Z ##

🟠 CVE-2026-104977 - High (7.7)

Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-27706 and GHSA-jcc6-f9v6-f7jw, an SSRF in work-item link unfurling shipped in v1.2.2, remains incomplete in the v1.3.1 GA release. Any authenticated project memb...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105628
(0 None)

EPSS: 0.29%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T19:16:03.000Z ##

🟠 CVE-2026-105628 - High (7.6)

Plane is an open-source project management tool. Prior to 1.4.0, Plane's OAuth avatar synchronization flow fetches avatar_url from provider user data through a server-side HTTP request without internal IP validation and follows redirects by defaul...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105631
(0 None)

EPSS: 0.24%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T19:15:53.000Z ##

🟠 CVE-2026-105631 - High (7.5)

Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceFileAssetEndpoint.get and WorkspaceAssetDownloadEndpoint.get resolve FileAsset records within a workspace without checking membership in the asset's project, allowing a work...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104970
(0 None)

EPSS: 0.27%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T17:30:34.000Z ##

🟠 CVE-2026-104970 - High (8.1)

Plane is an open-source project management tool. From 0.13 until 1.4.0, InstanceAdminSignUpEndpoint in apps/api/plane/license/api/views/admin.py:89-117, 173-229 uses InstanceAdmin.objects.first() for the first-admin check and performs account crea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12171
(0 None)

EPSS: 0.22%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T17:30:24.000Z ##

🟠 CVE-2026-12171 - High (7.8)

auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handle...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19184
(0 None)

EPSS: 0.10%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T16:31:26.000Z ##

🟠 CVE-2026-19184 - High (8.4)

The NXP GAU ADC driver (drivers/adc/adc_mcux_gau_adc.c) validated the caller-supplied sequence->buffer_size, which is expressed in bytes, against the number of active channels, which is a sample count. It then stored that byte count directly in da...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104891
(0 None)

EPSS: 0.28%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T16:31:07.000Z ##

🟠 CVE-2026-104891 - High (7.5)

mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credentia...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54154
(0 None)

EPSS: 0.00%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-10-05T13:28:12.000Z ##

Discover the details of Kiteworks CVE-2026-54154, a critical vulnerability in the Email Protection Gateway allowing remote code execution and root access.

#Kiteworks #Cybersecurity #Vulnerability #CVE202654154 #RemoteCodeExecution

meterpreter.org/kiteworks-crit

##

CVE-2026-19185
(0 None)

EPSS: 0.11%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-05T11:01:42.000Z ##

🟠 CVE-2026-19185 - High (7.8)

The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c validated the outer struct i3c_ccc_payload, the broadcast ccc.data buffer and the targets.payloads[] array, but did not validate the per-target data buffers those array elemen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites