## Updated at UTC 2026-08-05T18:24:56.457420

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-20304 9.9 0.00% 2 0 2026-08-05T17:16:50.890000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20303 9.9 0.00% 2 0 2026-08-05T17:16:50.513000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20272 9.8 0.00% 2 0 2026-08-05T17:16:49.053000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-20267 9.0 0.00% 2 0 2026-08-05T17:16:47.560000 As part of Cisco's ongoing commitment to proactive security and product quality,
CVE-2026-18898 8.8 0.47% 1 0 2026-08-05T17:16:45.797000 A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. Thi
CVE-2026-70619 8.8 0.36% 1 0 2026-08-05T16:17:05.093000 Odysseus before commit bf325f6 contains a missing authorization vulnerability th
CVE-2026-68981 7.5 0.32% 1 0 2026-08-05T15:33:14 Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the appl
CVE-2026-71287 8.8 0.00% 2 0 2026-08-05T15:32:29 Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER
CVE-2026-71285 8.1 0.00% 2 0 2026-08-05T15:32:29 Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js
CVE-2026-71294 7.6 0.00% 2 0 2026-08-05T15:32:29 Cotonti CMS's Comments plugin deserializes user-supplied data without restrictin
CVE-2026-71289 9.8 0.00% 2 0 2026-08-05T15:32:29 The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implement
CVE-2026-71269 7.2 0.00% 1 0 2026-08-05T15:32:20 Node-RED's local-filesystem library storage module (getLibraryEntry() and saveLi
CVE-2026-67857 7.5 0.35% 1 0 2026-08-05T15:32:14 open62541 1.5.5 contains an out-of-bounds read in the client-side function respo
CVE-2026-67858 7.5 0.49% 1 0 2026-08-05T15:32:14 Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery
CVE-2026-68979 9.8 0.35% 1 0 2026-08-05T15:32:09 Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API me
CVE-2026-66066 0 1.70% 4 7 2026-08-05T15:17:03.507000 Action Pack is a framework for handling and responding to web requests. In versi
CVE-2026-68580 7.5 0.24% 1 0 2026-08-05T14:17:10.217000 FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio inp
CVE-2026-66310 7.7 0.40% 1 0 2026-08-05T14:17:08.817000 External control of file name or path in Microsoft Edge for Android allows an un
CVE-2026-18933 7.2 0.00% 1 0 2026-08-05T13:20:39.580000 The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the
CVE-2026-66747 9.8 0.00% 2 0 2026-08-05T12:31:36 Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS,
CVE-2026-71245 7.1 0.00% 1 0 2026-08-05T12:31:36 Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxController.php)
CVE-2026-71254 9.8 0.00% 1 0 2026-08-05T12:31:34 nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-
CVE-2026-71214 9.8 0.34% 1 0 2026-08-05T09:31:27 The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-serve
CVE-2026-70378 7.5 0.28% 1 0 2026-08-05T09:31:26 imagecli's `carve <ratio>` pipeline operation (Carve::apply() in src/image_ops.r
CVE-2026-4431 9.1 0.33% 1 0 2026-08-05T09:31:26 The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modi
CVE-2026-9273 9.3 0.28% 1 0 2026-08-05T06:30:44 The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restr
CVE-2026-9198 9.8 17.05% 5 3 template 2026-08-05T05:17:15.823000 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain
CVE-2026-58073 0 0.22% 1 0 2026-08-05T05:17:02.413000 A vulnerability in Veeam Service Provider Console allowing an unauthenticated at
CVE-2026-18556 7.4 0.49% 6 0 2026-08-05T05:16:46.967000 Authentication bypass using an alternate path or channel vulnerability in N-able
CVE-2026-18897 8.8 0.57% 1 0 2026-08-05T03:30:28 A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. T
CVE-2026-18895 8.8 0.57% 1 0 2026-08-05T03:30:28 A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacte
CVE-2026-67859 7.5 0.47% 1 0 2026-08-05T00:30:46 Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to ca
CVE-2026-67861 7.5 0.42% 1 0 2026-08-05T00:30:39 An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a den
CVE-2026-45537 9.1 0.36% 1 0 2026-08-04T23:16:51.687000 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versio
CVE-2026-70554 9.8 0.85% 1 0 2026-08-04T21:30:42 MaxSite CMS contains a PHP object injection vulnerability that allows unauthenti
CVE-2026-70553 9.8 0.88% 2 0 2026-08-04T21:30:37 MaxSite CMS contains a remote code execution vulnerability that allows unauthent
CVE-2026-69703 9.8 0.46% 1 0 2026-08-04T21:30:29 Atlas-Livre contains an improper access control vulnerability in the admin contr
CVE-2026-66803 10.0 0.48% 1 0 2026-08-04T20:46:44.650000 Improper access control in Azure Cosmos DB allows an unauthorized attacker to ex
CVE-2026-49435 9.8 0.77% 1 0 2026-08-04T20:16:52.160000 Keysight IxChariot Endpoint and associated products contain a stack-based buffer
CVE-2026-70486 8.2 0.37% 1 0 2026-08-04T20:02:04 ## Summary Any authenticated user with access to a terminal server could get scr
CVE-2026-70482 8.1 0.34% 1 0 2026-08-04T19:52:03 ## Summary The OAuth token exchange endpoint accepts a raw provider access toke
CVE-2026-70478 None 0.38% 1 0 2026-08-04T19:37:38 ### Summary The OAuth2 token refresh endpoint (`POST /api/v1/oauth2-credential/
CVE-2026-70477 None 0.44% 1 0 2026-08-04T19:29:28 -- ABSTRACT ------------------------------------- Trend Micro's Zero Day Initia
CVE-2026-18830 8.1 0.29% 1 0 2026-08-04T19:16:45.433000 Insufficient input validation in Amazon Bedrock AgentCore harness might allow an
CVE-2026-15958 9.3 0.20% 1 0 2026-08-04T18:32:27 The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform
CVE-2026-24254 9.8 0.45% 1 0 2026-08-04T18:31:37 NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topol
CVE-2026-64633 None 0.34% 1 0 2026-08-04T18:31:36 A vulnerability allowing remote unauthenticated code execution on the agent host
CVE-2026-15920 6.1 0.30% 2 0 2026-08-04T18:31:31 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `djang
CVE-2026-15307 8.8 0.54% 1 0 2026-08-04T18:31:31 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDja
CVE-2026-24084 7.5 0.23% 1 0 2026-08-04T18:31:31 Weak configuration when UE does not verify the consistency of its additional sec
CVE-2026-24083 7.8 0.11% 1 0 2026-08-04T18:31:31 Memory Corruption while processing IOCTL device driver requests with invalid arg
CVE-2026-25292 7.6 0.16% 1 0 2026-08-04T18:31:31 Memory Corruption when processing untrusted user input in the fastboot command h
CVE-2026-69100 8.8 0.55% 1 0 2026-08-04T18:31:31 LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains
CVE-2026-69098 9.8 0.51% 1 0 2026-08-04T18:31:31 kotaemon through 0.12.0 contains an insecure deserialization vulnerability in th
CVE-2026-69110 9.1 0.55% 1 0 2026-08-04T17:16:59.733000 OpenCode Studio before 2.4.4 contains a missing authentication vulnerability tha
CVE-2026-18684 9.8 2.03% 1 0 2026-08-04T17:16:47.273000 A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affe
CVE-2026-48326 9.9 0.48% 1 0 2026-08-04T16:16:25.497000 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CVE-2026-18686 9.8 2.61% 1 0 2026-08-04T16:16:21.593000 A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected elem
CVE-2026-18577 8.1 4.10% 12 1 2026-08-04T15:33:20 An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco
CVE-2026-60007 None 0.45% 1 0 2026-08-04T15:32:29 In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns
CVE-2026-58061 0 0.21% 1 0 2026-08-04T14:50:12.360000 In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to calle
CVE-2026-58062 0 0.20% 2 1 2026-08-04T14:50:12.360000 In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without bi
CVE-2026-48331 10.0 0.47% 1 0 2026-08-04T14:48:22.933000 Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF)
CVE-2026-15721 9.8 0.23% 1 0 2026-08-04T14:16:30.620000 Cleartext storage of sensitive information vulnerability in Bilin Software and I
CVE-2026-14175 9.8 0.40% 2 0 2026-08-04T12:34:56 Unrestricted upload of file with dangerous type vulnerability in Bilin Software
CVE-2026-14804 9.1 0.30% 2 0 2026-08-04T12:34:56 Use of hard-coded cryptographic key vulnerability in Bilin Software and Informat
CVE-2026-17566 9.9 0.43% 1 1 2026-08-04T12:31:51.160000 pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by in
CVE-2026-18754 9.1 0.31% 1 0 2026-08-04T09:31:41 The product firmware contains an embedded, static RSA private key utilized by th
CVE-2026-6837 7.2 0.95% 1 0 2026-08-04T03:31:16 A post-authentication command injection vulnerability in the "export-cgi" CGI pr
CVE-2026-62354 None 0.26% 1 0 2026-08-04T00:35:57 Authorization handling for Parameter Context validation requests in Apache NiFi
CVE-2026-48333 9.8 0.47% 1 0 2026-08-04T00:35:01 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CVE-2026-48323 10.0 0.62% 2 0 2026-08-04T00:35:01 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CVE-2026-66318 8.1 0.37% 1 0 2026-08-04T00:35:01 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorize
CVE-2026-18685 9.8 1.99% 1 0 2026-08-04T00:35:01 A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Imp
CVE-2026-48330 10.0 0.68% 1 0 2026-08-04T00:35:01 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CVE-2026-66315 7.5 0.62% 1 0 2026-08-04T00:34:55 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke
CVE-2026-59913 7.8 0.11% 1 0 2026-08-03T21:31:44 Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, co
CVE-2026-59912 7.8 0.10% 1 0 2026-08-03T21:31:36 Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, co
CVE-2026-18108 9.8 0.22% 1 0 2026-08-03T21:31:35 Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _ve
CVE-2026-69240 9.8 0.32% 1 0 2026-08-03T20:29:52 ### Summary SQL Injection is possible with strings only **if dialect is set to `
CVE-2026-18589 9.8 0.61% 1 0 2026-08-03T20:17:15.910000 A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the
CVE-2026-18614 9.8 2.01% 1 0 2026-08-03T19:16:45.200000 A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the func
CVE-2026-16300 9.8 0.30% 1 0 2026-08-03T18:31:51 The ChamaWP WordPress plugin before 1.0.13 does not properly validate a passwor
CVE-2026-18574 None 0.99% 2 0 2026-08-03T15:32:49 An authentication bypass vulnerability in Check Point Security Management Server
CVE-2026-33591 None 0.52% 3 0 2026-08-03T12:32:43 A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unaut
CVE-2026-9593 6.7 0.11% 1 0 2026-08-03T09:32:46 A vulnerability in the iDTM FDI allows an attacker with elevated privileges and
CVE-2026-12816 None 0.16% 1 0 2026-08-03T09:32:36 In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via len
CVE-2026-8763 None 0.33% 2 1 2026-08-03T09:32:36 In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot
CVE-2026-12803 None 0.17% 1 0 2026-08-03T09:32:36 In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce w
CVE-2026-5674 8.8 0.13% 1 0 2026-08-03T08:17:20.920000 A flaw was found in PipeWire, a multimedia server. This vulnerability allows an
CVE-2026-59639 None 0.17% 1 0 2026-08-03T06:32:44 In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for Sig
CVE-2026-59650 None 0.26% 1 1 2026-08-03T06:32:44 In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalid
CVE-2026-59638 None 0.28% 1 1 2026-08-03T06:32:44 In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enable
CVE-2026-3245 7.5 0.24% 1 0 2026-08-03T00:30:35 A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that
CVE-2025-71399 8.6 0.31% 1 0 2026-08-02T15:30:21 Better Auth relies on better-call, which uses the rou3 router library. In affect
CVE-2026-64531 7.8 0.13% 2 4 2026-08-01T09:30:23 In the Linux kernel, the following vulnerability has been resolved: net: openvs
CVE-2026-9044 None 0.97% 2 0 2026-08-01T00:31:02 An OS command injection vulnerability exists in the VPN module of TP-Link AXE75
CVE-2026-63223 9.8 0.49% 1 2 2026-08-01T00:17:17.750000 CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and
CVE-2025-69935 9.8 0.26% 1 0 2026-07-31T21:32:56 CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the
CVE-2026-14319 7.5 0.32% 1 0 2026-07-31T21:32:56 The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to
CVE-2025-69933 9.8 0.26% 1 0 2026-07-31T21:32:55 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /me
CVE-2026-43831 7.5 0.24% 1 0 2026-07-31T21:32:55 Successful exploitation of the vulnerability could allow an unauthenticated atta
CVE-2026-43830 9.8 0.31% 1 0 2026-07-31T21:31:54 Successful exploitation of the command injection vulnerability could allow an at
CVE-2025-69936 9.8 0.26% 1 0 2026-07-31T21:31:53 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /ed
CVE-2026-56673 7.5 0.43% 1 0 2026-07-31T20:16:52.487000 ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node
CVE-2026-43832 7.5 0.24% 1 0 2026-07-31T20:16:50.777000 Full details and mitigation steps are currently restricted and will be published
CVE-2026-43829 7.5 0.24% 1 0 2026-07-31T20:16:50.317000 Full details and mitigation steps are currently restricted and will be published
CVE-2025-69934 9.8 0.26% 1 0 2026-07-31T19:17:03.113000 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /de
CVE-2026-12720 7.5 0.30% 1 1 2026-07-31T18:33:20 The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be
CVE-2026-12695 8.1 0.29% 1 0 2026-07-31T18:33:20 The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitte
CVE-2026-12721 8.6 0.26% 1 0 2026-07-31T18:33:20 The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape
CVE-2026-15969 9.8 0.98% 2 0 2026-07-31T18:33:17 SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via by
CVE-2026-58048 None 0.50% 1 1 2026-07-31T18:32:25 Improper preservation of SQL mode when renaming databases in cPanel allows exec
CVE-2026-14919 9.8 0.28% 1 0 2026-07-31T18:32:17 The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its
CVE-2026-35847 9.8 0.37% 1 0 2026-07-31T18:32:13 An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrar
CVE-2026-12251 8.1 0.23% 1 0 2026-07-31T18:17:09.777000 The Ultimate Member WordPress plugin before 2.12.1 does not filter administrato
CVE-2026-13609 8.8 0.25% 1 0 2026-07-31T17:16:32.347000 The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML ent
CVE-2025-69937 9.8 0.26% 1 0 2026-07-31T16:16:56.643000 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the
CVE-2026-14333 7.5 0.30% 1 0 2026-07-31T15:33:51 The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in
CVE-2026-14830 7.5 0.21% 1 0 2026-07-31T14:16:46.133000 The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment proces
CVE-2026-38709 9.8 2.67% 2 0 2026-07-31T12:31:33 TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, W
CVE-2026-52539 9.1 0.30% 1 0 2026-07-31T12:30:30 Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOK
CVE-2026-14483 9.8 0.61% 1 2 2026-07-31T09:31:25 The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulner
CVE-2026-63362 5.9 1.53% 1 0 2026-07-31T00:30:29 An unsigned integer underflow in the PubSub signature verification path in open
CVE-2026-12562 8.8 0.28% 1 0 2026-07-31T00:30:29 The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that
CVE-2026-66418 9.3 0.34% 1 1 2026-07-30T21:31:57 OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability t
CVE-2026-12943 9.8 0.92% 2 0 2026-07-30T21:31:50 IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1
CVE-2026-51291 9.8 0.00% 1 0 2026-07-30T21:31:47 sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert functi
CVE-2026-17191 9.1 2.83% 1 0 2026-07-30T19:10:52.250000 An input validation vulnerability exists in an API component of the orchestrator
CVE-2026-41709 2.7 0.38% 1 0 2026-07-30T19:07:59.843000 VMware ESX contains an insufficient logging vulnerability. A malicious administr
CVE-2026-59310 9.8 1.14% 1 0 2026-07-30T16:17:15.183000 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-47876 9.3 0.28% 1 0 2026-07-30T15:31:54 VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual
CVE-2026-59309 9.8 0.74% 1 0 2026-07-30T15:31:54 VMware vCenter contains an authentication bypass vulnerability in the VMware Dir
CVE-2026-41703 7.6 0.56% 1 0 2026-07-30T15:31:50 VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability.
CVE-2026-5491 7.5 1.54% 1 1 2026-07-30T14:18:46.477000 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera
CVE-2026-5487 7.5 1.54% 1 0 2026-07-30T14:18:46.477000 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera
CVE-2026-12935 0 0.81% 1 0 2026-07-30T14:12:18.697000 The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking
CVE-2026-14869 8.6 0.29% 1 0 2026-07-30T14:08:23.057000 The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side req
CVE-2026-16496 8.9 0.27% 1 0 2026-07-30T14:08:23.057000 The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization
CVE-2026-48449 10.0 0.54% 1 0 2026-07-30T03:31:28 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CVE-2026-5492 6.5 1.60% 1 0 2026-07-29T21:31:08 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera
CVE-2026-20316 5.3 0.79% 2 0 2026-07-29T21:31:00 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-53264 7.8 0.21% 1 1 2026-07-29T21:30:47 In the Linux kernel, the following vulnerability has been resolved: net/sched:
CVE-2026-67192 8.1 0.62% 1 0 2026-07-29T18:31:46 Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overfl
CVE-2026-16655 7.2 0.30% 1 0 2026-07-29T12:31:30 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Fo
CVE-2026-16498 10.0 0.33% 2 0 2026-07-28T21:31:39 The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant cr
CVE-2026-16462 9.8 0.42% 1 0 2026-07-28T12:31:27 In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This a
CVE-2026-11841 9.4 0.46% 1 0 2026-07-28T12:31:20 An attacker may perform unauthenticated read and write operations on sensitive f
CVE-2026-45112 7.5 1.94% 1 0 2026-07-27T21:32:25 Allocation of Resources Without Limits or Throttling vulnerability in Apache Thr
CVE-2026-17192 8.5 2.34% 1 0 2026-07-27T18:31:56 A VCO feature does not sufficiently validate caller-supplied input, allowing req
CVE-2026-12495 None 0.16% 1 0 2026-07-27T12:32:01 Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http
CVE-2026-46300 7.8 7.01% 1 15 2026-07-23T11:10:00.120000 In the Linux kernel, the following vulnerability has been resolved: net: skbuff
CVE-2026-50522 9.8 75.76% 1 5 2026-07-22T21:31:51 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-10702 4.3 0.72% 1 2 2026-07-22T19:10:00.120000 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w
CVE-2026-50343 7.8 3.50% 1 1 2026-07-22T16:17:42.747000 Improper privilege management in Microsoft Install Service allows an authorized
CVE-2026-54121 8.8 1.05% 1 12 2026-07-21T19:54:33.623000 Improper authorization in Active Directory Certificate Services (AD CS) allows a
CVE-2026-42533 8.1 3.60% 1 9 2026-07-15T15:33:14 A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive
CVE-2026-15409 10.0 78.44% 2 6 template 2026-07-14T21:32:22 A Server-side request forgery (SSRF) vulnerability has been identified in the SM
CVE-2026-15410 7.2 76.35% 2 3 2026-07-14T21:32:21 Post-authentication improper control of generation of code ('Code Injection') vu
CVE-2026-31431 7.8 94.55% 1 100 template 2026-07-14T15:32:55 In the Linux kernel, the following vulnerability has been resolved: crypto: alg
CVE-2026-43284 7.8 93.23% 1 44 2026-07-14T15:31:59 In the Linux kernel, the following vulnerability has been resolved: xfrm: esp:
CVE-2025-26399 9.8 88.33% 1 1 2026-06-17T09:01:42.407000 SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxP
CVE-2023-32233 7.8 12.97% 1 7 2026-06-17T05:58:22.273000 In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when
CVE-2026-48030 9.9 1.54% 1 1 2026-06-09T22:00:36 ### Summary An OS Command Injection vulnerability in the terminal action handle
CVE-2026-34486 7.5 81.16% 3 6 template 2026-06-08T23:28:56 Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the f
CVE-2026-42897 8.1 70.31% 2 1 2026-05-15T18:30:32 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2026-20079 10.0 37.67% 2 1 template 2026-03-04T18:32:03 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-1070 4.3 0.16% 1 2 2026-01-24T09:30:33 The Alex User Counter plugin for WordPress is vulnerable to Cross-Site Request F
CVE-2013-4786 7.5 78.57% 2 1 2025-04-11T04:12:49 The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (R
CVE-2026-44945 0 0.74% 1 0 N/A
CVE-2026-53921 0 0.00% 1 2 N/A
CVE-2026-59726 0 0.48% 2 1 N/A
CVE-2026-59774 0 0.00% 1 0 N/A
CVE-2026-65321 0 0.44% 2 1 N/A
CVE-2026-56670 0 0.22% 1 0 N/A
CVE-2026-56671 0 0.66% 1 0 N/A
CVE-2026-56672 0 0.24% 1 0 N/A
CVE-2026-63222 0 0.45% 1 0 N/A
CVE-2026-63221 0 0.38% 1 0 N/A
CVE-2026-4941 0 0.00% 1 2 N/A
CVE-2026-49413 0 0.15% 1 1 N/A

CVE-2026-20304
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-08-05T17:16:50.890000

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are gr

CVE-2026-20303
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-08-05T17:16:50.513000

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are g

CVE-2026-20272
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-05T17:16:49.053000

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of spec

CVE-2026-20267
(9.0 CRITICAL)

EPSS: 0.00%

updated 2026-08-05T17:16:47.560000

2 posts

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by&nbsp;CVE-2026-20267 are related to improper access control issues that ar

CVE-2026-18898
(8.8 HIGH)

EPSS: 0.47%

updated 2026-08-05T17:16:45.797000

1 posts

A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did n

thehackerwire@mastodon.social at 2026-08-05T06:00:05.000Z ##

🟠 CVE-2026-18898 - High (8.8)

A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart results in stack-based buffer overflow. The attack can be l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70619
(8.8 HIGH)

EPSS: 0.36%

updated 2026-08-05T16:17:05.093000

1 posts

Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session authentication but omit the admin authorization guard. Attackers can supply an attacker-controlled URL to overwrite the embedding backend persisted in the endpoint con

thehackerwire@mastodon.social at 2026-08-04T22:59:59.000Z ##

🟠 CVE-2026-70619 - High (8.8)

Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session authentication...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68981
(7.5 HIGH)

EPSS: 0.32%

updated 2026-08-05T15:33:14

1 posts

Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommend

DailyCyberSecurity@infosec.exchange at 2026-08-04T01:52:18.000Z ##

Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption.

#ApacheNiFi #CyberSecurity #Vulnerabilities #CVE #InfoSec

securityonline.info/apache-nif

##

CVE-2026-71287
(8.8 HIGH)

EPSS: 0.00%

updated 2026-08-05T15:32:29

2 posts

Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex `preg_replace('/[^a-zA-Z0-9_().]/', '', $column)`. Because this allowlist retains letters, digits, underscore, parentheses, and dot (intended to support expressions like COUNT(id) and table.column), a payload such as `SLEEP(5)` passes through completely unmodified. The sanitized value is

thehackerwire@mastodon.social at 2026-08-05T14:00:30.000Z ##

🟠 CVE-2026-71287 - High (8.8)

Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex `preg_replace('/[^a-zA-Z0-9_().]/', '', $column)`. Because this allowlist retains letters, digits, underscore, parentheses, and dot (in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-05T14:00:30.000Z ##

🟠 CVE-2026-71287 - High (8.8)

Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex `preg_replace('/[^a-zA-Z0-9_().]/', '', $column)`. Because this allowlist retains letters, digits, underscore, parentheses, and dot (in...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71285
(8.1 HIGH)

EPSS: 0.00%

updated 2026-08-05T15:32:29

2 posts

Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo `siteId` value as a bare, unquoted JavaScript expression inside a <script> block rendered on every public status page: `_paq.push(['setSiteId', ${escapedSiteIdHTMLAttribute}]);`. The escaping pipeline used (jsesc with isScriptContext:true, then html-escaper.escape()) does not esc

thehackerwire@mastodon.social at 2026-08-05T14:00:20.000Z ##

🟠 CVE-2026-71285 - High (8.1)

Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo `siteId` value as a bare, unquoted JavaScript expression inside a block rendered on every public status page: `_paq.push(['set...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-05T14:00:20.000Z ##

🟠 CVE-2026-71285 - High (8.1)

Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo `siteId` value as a bare, unquoted JavaScript expression inside a block rendered on every public status page: `_paq.push(['set...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71294
(7.6 HIGH)

EPSS: 0.00%

updated 2026-08-05T15:32:29

2 posts

Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a `ci` POST parameter obtained via `cot_import('ci', 'P', 'TXT')` (trim-only sanitization) is passed to `unserialize(base64_decode($ci))` with no `allowed_classes` restriction, reachable by any member with write access to

thehackerwire@mastodon.social at 2026-08-05T14:00:10.000Z ##

🟠 CVE-2026-71294 - High (7.6)

Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a `ci` POST parameter obtained via `cot_import('ci', 'P', 'TXT')` (tr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-08-05T14:00:10.000Z ##

🟠 CVE-2026-71294 - High (7.6)

Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a `ci` POST parameter obtained via `cot_import('ci', 'P', 'TXT')` (tr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71289
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-05T15:32:29

2 posts

The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. "${ION_MGR_PORT:-8089}:8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypassing the CAM (Configuration and Access Manager) gateway that is otherwise the system's sole authentic

offseq at 2026-08-05T13:30:25.760Z ##

CVE-2026-71289 (CRITICAL, CVSS 9.8): NASA-AMMOS ANMS exposes amp-manager REST API w/ no auth. Remote attackers can control system & disrupt ops. Restrict access, avoid default configs, check vendor for patches. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-08-05T13:30:25.000Z ##

CVE-2026-71289 (CRITICAL, CVSS 9.8): NASA-AMMOS ANMS exposes amp-manager REST API w/ no auth. Remote attackers can control system & disrupt ops. Restrict access, avoid default configs, check vendor for patches. radar.offseq.com/threat/cve-20 #OffSeq #CVE #NASA #Infosec

##

CVE-2026-71269
(7.2 HIGH)

EPSS: 0.00%

updated 2026-08-05T15:32:20

1 posts

Node-RED's local-filesystem library storage module (getLibraryEntry() and saveLibraryEntry() in packages/node_modules/@node-red/runtime/lib/storage/localfilesystem/library.js), reachable via GET/POST /library/:lib/:type/*path, joins the user-supplied path parameter directly into the filesystem path via fspath.join(libDir, type, path) with no traversal sanitization, containment check, or path norma

hugovalters@mastodon.social at 2026-08-05T15:08:36.000Z ##

CVE-2026-71269 - Path traversal in Node-RED local-filesystem library storage. Authenticated users can read/write arbitrary files via GET/POST /library endpoints. CVSS 7.2. Unpatched - restrict access and monitor. #CVE #NodeRED #infosec

valtersit.com/cve/CVE-2026-712

##

CVE-2026-67857
(7.5 HIGH)

EPSS: 0.35%

updated 2026-08-05T15:32:14

1 posts

open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.

thehackerwire@mastodon.social at 2026-08-05T00:00:27.000Z ##

🟠 CVE-2026-67857 - High (7.5)

open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67858
(7.5 HIGH)

EPSS: 0.49%

updated 2026-08-05T15:32:14

1 posts

Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 request containing many unique discoveryUrls. This allows remote attackers to cause a denial of service.

thehackerwire@mastodon.social at 2026-08-04T23:00:09.000Z ##

🟠 CVE-2026-67858 - High (7.5)

Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 requ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68979
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-08-05T15:32:09

1 posts

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and write privileges on the Parameter Context itself. As a result of the missing auth

DailyCyberSecurity@infosec.exchange at 2026-08-04T01:52:18.000Z ##

Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption.

#ApacheNiFi #CyberSecurity #Vulnerabilities #CVE #InfoSec

securityonline.info/apache-nif

##

CVE-2026-66066
(0 None)

EPSS: 1.70%

updated 2026-08-05T15:17:03.507000

4 posts

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated a

7 repos

https://github.com/paveg/rails-activestorage-vips-audit

https://github.com/Zer0SumGam3/CVE-2026-66066-POC

https://github.com/HackSpeak/CVE-2026-66066

https://github.com/0xsha/KindaRails2Shell

https://github.com/0xBlackash/CVE-2026-66066

https://github.com/rails/rails-forensics-CVE-2026-66066

https://github.com/shinthink/CVE-2026-66066

sayzard@mastodon.sayzard.org at 2026-08-05T17:38:25.000Z ##

Zero-Day to Zero Doubt: AI-Powered CVE Forensics in an Afternoon

Rails Active Storage의 CVE-2026-66066(KindaRails2Shell)는 libvips·libmatio의 파일 형식 해석 불일치를 악용해 조작된 업로드 파일로 서버 파일을 읽고, 비밀값 탈취 시 서명된 ID·쿠키 위조를 통한 RCE로 이어질 수 있는 취약점이다. Rails 팀은 패치와 함께 Claude Code용 에이전트 스킬 기반 포렌식 도구를 제공해, 노출 기간 산정과 Active Storage 내 악성 파일 헤더 탐지를 지원한다. 이 도구는 운영 DB...

blog.quent.in/blog/2026/07/31/

##

DailyCyberSecurity@infosec.exchange at 2026-08-04T07:28:39.000Z ##

A critical KindaRails2Shell Rails RCE flaw (CVE-2026-66066) in Active Storage exposes servers to secret theft and remote code execution via image uploads.

#RubyOnRails #KindaRails2Shell #CVE202666066 #Cybersecurity #WebSecurity

meterpreter.org/kindarails2she

##

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

kuketzblog@social.tchncs.de at 2026-08-02T19:45:34.000Z ##

Ruby on Rails warnt vor CVE-2026-66066 in Active Storage. Angreifer können über präparierte Bild-Uploads Dateien des Servers auslesen und so an Schlüssel oder Zugangsdaten gelangen. Betroffen sind Anwendungen mit libvips. Updates und forensische Prüfwerkzeuge stehen bereit.

discuss.rubyonrails.org/t/cve-

1/2

#RubyOnRails #Sicherheitslücke #Websecurity #KuketzAugust

##

CVE-2026-68580
(7.5 HIGH)

EPSS: 0.24%

updated 2026-08-05T14:17:10.217000

1 posts

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all pl

thehackerwire@mastodon.social at 2026-08-02T14:01:32.000Z ##

🟠 CVE-2026-68580 - High (7.5)

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can su...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66310
(7.7 HIGH)

EPSS: 0.40%

updated 2026-08-05T14:17:08.817000

1 posts

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

thehackerwire@mastodon.social at 2026-08-04T01:00:15.000Z ##

🟠 CVE-2026-66310 - High (7.7)

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18933
(7.2 HIGH)

EPSS: 0.00%

updated 2026-08-05T13:20:39.580000

1 posts

The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation of any kind - no wp_check_filetype_and_ext(), no validate_file(), and no extension blocklist exist anywhere in the upload handler. The dest

hugovalters@mastodon.social at 2026-08-05T17:01:05.000Z ##

CVE-2026-18933 - Arbitrary file upload in WordPress wp-downloadmanager plugin. Admin-privileged RCE risk via unsanitized uploads. CVSS 7.2. Unpatched - disable plugin or restrict access now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-189

##

CVE-2026-66747
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-05T12:31:36

2 posts

Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP

sayzard@mastodon.sayzard.org at 2026-08-05T16:38:16.000Z ##

Endlessdoors Is Phoning Home. Pick Up

VulnCheck은 Zbtlink 및 OEM 재브랜딩 라우터 약 20개 모델의 펌웨어에 부팅 시 자동 실행되는 ENDLESSDOORS 백도어가 포함됐다고 공개했다. 이 임플란트는 `kworker`라는 위장 프로세스로 외부 C2에 TCP 연결을 건 뒤, 인증·암호화·명령 검증 없이 수신한 명령을 root 권한으로 `popen()` 실행하며, `rctlbash` 명령으로 대화형 root 셸도 제공한다. 공격자는 C2 경로 또는 DNS 해석을 탈취하면 NAT 뒤의 라우터에도 아웃바운드 연결을 통해 접근할 수 있으며, 연구진은 CVE-2026-66747을 할당했다. 해당 장비는 신뢰할 수 없는 펌웨어로 간주해 모델 번호 기준 자산 조...

vulncheck.com/blog/zbt-endless

##

catc0n@infosec.exchange at 2026-08-05T10:34:45.000Z ##

Today, VulnCheck is disclosing #ENDLESSDOORS, a phone-home implant CTO @albinolobster discovered in Zbtlink routers. ENDLESSDOORS starts automatically, runs with root privileges, and attempts to connect to command-and-control infrastructure roughly every 35 seconds. The backdoor ships by default across 20+ Zbtlink router models, which are white-labeled and sold on popular retail sites including Amazon, AliExpress, and Alibaba.

The implant and server implement no encryption or verification, meaning anyone along the network path can hijack the client-server communication and obtain a root shell on the device, regardless of the router's network position.

The VulnCheck CNA has assigned CVE-2026-66747 to track backdoored firmware versions; our blog also has guidance for defenders, including affected firmware images, hashes, network indicators, a YARA rule, and network signatures (Suricata / Snort).

vulncheck.com/blog/zbt-endless

##

CVE-2026-71245
(7.1 HIGH)

EPSS: 0.00%

updated 2026-08-05T12:31:36

1 posts

Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxController.php) reads a field parameter from the request, sanitizes it only with InputHelper::clean() (which HTML-entity-encodes quotes and angle brackets but does not restrict other characters), and passes it into LeadRepository::buildQueryForGetLeadsByFieldValue() where it is concatenated directly as a raw SQL column identifier ($c

hugovalters@mastodon.social at 2026-08-05T12:14:35.000Z ##

CVE-2026-71245 - SQL injection in Mautic via unsanitized field param in AjaxController. Improper validation leads to raw SQL concat. CVSS 7.1. Unpatched - update immediately. #CVE #Mautic #infosec

valtersit.com/cve/CVE-2026-712

##

CVE-2026-71254
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-08-05T12:31:34

1 posts

nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record() function (FC 0x14, Read File Record) in nanomodbus.c. The function validates that the total request size does not exceed 245 bytes and that each sub-request's record_length is at most 124, but it never validates the CUMULATIVE response size across all sub-requests before processing them.

offseq@infosec.exchange at 2026-08-05T12:00:26.000Z ##

CVE-2026-71254: CRITICAL out-of-bounds write in debevv nanoMODBUS (≤v1.23.0). Unauthenticated FC 0x14 requests can cause memory corruption, leading to DoS or RCE — especially on embedded targets. Patch/mitigate now. radar.offseq.com/threat/cve-20 #OffSeq #CVE #ICS #infosec

##

CVE-2026-71214
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-08-05T09:31:27

1 posts

The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession(), which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorization header's JWT claims, with no verification that the request actually originated from Hasura. By setting {"session_variab

offseq@infosec.exchange at 2026-08-05T07:30:25.000Z ##

CVE-2026-71214: NASA-AMMOS plandev sequencing-server has a CRITICAL vuln (CVSS 9.8) — unauthenticated users can inject commands by spoofing session roles or using whitelisted endpoints. Patch urgently. More: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #NASA #CyberSec #CVSS

##

CVE-2026-70378
(7.5 HIGH)

EPSS: 0.28%

updated 2026-08-05T09:31:26

1 posts

imagecli's `carve <ratio>` pipeline operation (Carve::apply() in src/image_ops.rs) only asserts `ratio <= 1.0`, never validating that the ratio is positive. A negative ratio (e.g. -5) causes the computed target width to saturate to 0 via Rust's defined float-to-uint cast, which is then passed to imageproc::seam_carving::shrink_width — a function that panics when given a width below 2, crashing the

hugovalters@mastodon.social at 2026-08-05T14:11:48.000Z ##

CVE-2026-70378 - DoS via negative ratio in Rust imagecli carve. Panic on width<2 crashes process. CVSS 7.5. Unpatched - restrict input validation now. #CVE #Rust #infosec

valtersit.com/cve/CVE-2026-703

##

CVE-2026-4431
(9.1 CRITICAL)

EPSS: 0.33%

updated 2026-08-05T09:31:26

1 posts

The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is due to the `rbsm_submit_post` AJAX action being registered for unauthenticated users via `wp_ajax_nopriv_rbsm_submit_post` without any authorization checks when a `postId` parameter is

offseq@infosec.exchange at 2026-08-05T09:00:27.000Z ##

CVE-2026-4431: CRITICAL vuln in Easy Post Submission ≤2.3.0 for WordPress. Missing auth lets unauthenticated attackers modify or unpublish any post via AJAX. No patch yet — disable plugin if possible. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #CVE20264431

##

CVE-2026-9273
(9.3 CRITICAL)

EPSS: 0.28%

updated 2026-08-05T06:30:44

1 posts

The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and including, 4.0.0. This is due to the legacy lost-password handler rc_process_lost_password_form() consuming the attacker-controlled rc_redirect POST parameter into two unvalidated sinks in legacy/includes/

offseq@infosec.exchange at 2026-08-05T06:00:32.000Z ##

Kadence Memberships (stellarwp) ≤4.0.0 suffers CRITICAL vuln (CVE-2026-9273, CVSS 9.3): attackers can hijack any account by poisoning password reset links. Restrict reset features & monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #Security

##

CVE-2026-9198
(9.8 CRITICAL)

EPSS: 17.05%

updated 2026-08-05T05:17:15.823000

5 posts

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

Nuclei template

3 repos

https://github.com/ywh-jfellus/CVE-2026-9198

https://github.com/0xgh057r3c0n/CVE-2026-9198

https://github.com/0xdak/CVE-2026-9198_exploit

Matchbook3469@mastodon.social at 2026-08-05T17:40:54.000Z ##

🔵 THREAT INTELLIGENCE

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

Vulnerability | CRITICAL
CVEs: CVE-2026-9198

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV)...

Full analysis:
yazoul.net/news/article/cisa-f

by Yazoul AI

#ThreatIntel #Malware #ThreatHunting

##

Analyst207@mastodon.social at 2026-08-05T17:34:13.000Z ##

IBM Langflow AI Platform Under Active Exploitation

A critical flaw in IBM's Langflow AI platform, tracked as CVE-2026-9198, is under active exploitation by hackers, who can use it to execute code remotely on vulnerable deployments. CISA has urged organizations to upgrade to Langflow OSS version 1.10.1 or later to mitigate the vulnerability.

osintsights.com/ibm-langflow-a

#LangflowAi #Cve20269198 #Cisa #Ibm #EmergingThreats

##

thecybermind@infosec.exchange at 2026-08-04T23:27:59.000Z ##

🚨 CISA KEV ALERT: CVE-2026-9198 identifies a critical unauthenticated code injection flaw in IBM Langflow allowing full RCE on default deployments. Active exploitation confirmed. Get the execution mechanics, CrowdStrike CQL detection, and compensating controls now: thecybermind.co/fi0v

##

secdb@infosec.exchange at 2026-08-04T19:00:11.000Z ##

🚨 [CISA-2026:0804] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-18556 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: uptime.n-able.com/ ; status.n-able.com/2026/08/02/n ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34486 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Tomcat
- Notes: lists.apache.org/thread/9510k5 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9198 (secdb.nttzen.cloud/cve/detail/)
- Name: IBM Langflow Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: IBM
- Product: Langflow
- Notes: ibm.com/support/pages/node/727 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260804 #cisa20260804 #cve_2026_18556 #cve_2026_34486 #cve_2026_9198 #cve202618556 #cve202634486 #cve20269198

##

cisakevtracker@mastodon.social at 2026-08-04T18:01:22.000Z ##

CVE ID: CVE-2026-9198
Vendor: IBM
Product: Langflow
Date Added: 2026-08-04
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-58073
(0 None)

EPSS: 0.22%

updated 2026-08-05T05:17:02.413000

1 posts

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.

CVE-2026-18556
(7.4 HIGH)

EPSS: 0.49%

updated 2026-08-05T05:16:46.967000

6 posts

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

thecybermind at 2026-08-05T17:08:36.266Z ##

🚨 CISA KEV ALERT: CVE-2026-18556 exposes N-able N-central installations to authentication bypass via alternate channel paths. Active exploitation confirmed. Get the forensic breakdown, Splunk/KQL/Chronicle detection logic, and hardening guidance now: thecybermind.co/radr

##

thecybermind@infosec.exchange at 2026-08-05T17:08:36.000Z ##

🚨 CISA KEV ALERT: CVE-2026-18556 exposes N-able N-central installations to authentication bypass via alternate channel paths. Active exploitation confirmed. Get the forensic breakdown, Splunk/KQL/Chronicle detection logic, and hardening guidance now: thecybermind.co/radr

##

secdb@infosec.exchange at 2026-08-04T19:00:11.000Z ##

🚨 [CISA-2026:0804] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-18556 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: uptime.n-able.com/ ; status.n-able.com/2026/08/02/n ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34486 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Tomcat
- Notes: lists.apache.org/thread/9510k5 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9198 (secdb.nttzen.cloud/cve/detail/)
- Name: IBM Langflow Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: IBM
- Product: Langflow
- Notes: ibm.com/support/pages/node/727 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260804 #cisa20260804 #cve_2026_18556 #cve_2026_34486 #cve_2026_9198 #cve202618556 #cve202634486 #cve20269198

##

cisakevtracker@mastodon.social at 2026-08-04T18:00:52.000Z ##

CVE ID: CVE-2026-18556
Vendor: N-able
Product: N-central
Date Added: 2026-08-04
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-08-04T14:33:24.000Z ##

CISA added this vulnerability to the catalogue yesterday, if you missed it:

CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability cve.org/CVERecord?id=CVE-2026-

Arctic Wolf: CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching arcticwolf.com/resources/blog/ #infosec #vulnerability #CISA

##

security_crawler_carl@infosec.exchange at 2026-08-02T15:39:21.000Z ##

🏆 New Achievement! Management Remotely Destroyed!

Today's dungeon crawl is brought to you by Deferred Patch Tuesdays — when you're too busy managing clients to manage yourself. N-able N-central, the RMM platform MSPs trust to run everyone else's networks, is harboring CVE-2026-18556, a CVSS 9.8 authentication bypass being actively exploited in the wild. Attackers are waltzing — no, sorry — strolling right through, dropping Cloudflare tunnels for cozy, persistent access. (1/2)

##

CVE-2026-18897
(8.8 HIGH)

EPSS: 0.57%

updated 2026-08-05T03:30:28

1 posts

A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of the argument tempName leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did no

thehackerwire@mastodon.social at 2026-08-05T06:00:24.000Z ##

🟠 CVE-2026-18897 - High (8.8)

A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of the argument tempName leads to stack-based buffer overflow. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18895
(8.8 HIGH)

EPSS: 0.57%

updated 2026-08-05T03:30:28

1 posts

A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argument cipher results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respon

thehackerwire@mastodon.social at 2026-08-05T06:00:15.000Z ##

🟠 CVE-2026-18895 - High (8.8)

A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argument cipher results in stack-based buffer overflow. It is possible to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67859
(7.5 HIGH)

EPSS: 0.47%

updated 2026-08-05T00:30:46

1 posts

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.

thehackerwire@mastodon.social at 2026-08-04T23:00:19.000Z ##

🟠 CVE-2026-67859 - High (7.5)

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67861
(7.5 HIGH)

EPSS: 0.42%

updated 2026-08-05T00:30:39

1 posts

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component

thehackerwire@mastodon.social at 2026-08-05T00:00:17.000Z ##

🟠 CVE-2026-67861 - High (7.5)

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45537
(9.1 CRITICAL)

EPSS: 0.36%

updated 2026-08-04T23:16:51.687000

1 posts

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI components (protocol, username, domain, port, params) into a fixed 1024-byte global BSS buffer without any bounds checking. When a routing script calls construct_uri() with an attacker-controlled username, a combined component lengt

thehackerwire@mastodon.social at 2026-08-05T00:00:07.000Z ##

🔴 CVE-2026-45537 - Critical (9.1)

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI components (protocol, username, domain, port, params) into a fixed 1024-byte gl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70554
(9.8 CRITICAL)

EPSS: 0.85%

updated 2026-08-04T21:30:42

1 posts

MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during obje

offseq@infosec.exchange at 2026-08-05T00:00:36.000Z ##

MaxSite CMS 0.78 is vulnerable (CVE-2026-70554, CRITICAL): PHP object injection via maxsite_comuser cookie enables unauthenticated RCE. No patch available. Restrict access, deploy WAF, and monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CMS #PHP #RCE

##

CVE-2026-70553
(9.8 CRITICAL)

EPSS: 0.88%

updated 2026-08-04T21:30:37

2 posts

MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply a malicious db_dbprefix value containing a single quote to break out of a PHP string literal in application/config/databa

offseq@infosec.exchange at 2026-08-05T01:30:32.000Z ##

CVE-2026-70553: CRITICAL RCE in MaxSite CMS 105.2 (CVSS 9.3). Attackers can inject PHP via POST to the install endpoint, gaining persistent code exec as www-data. Restrict endpoint & monitor traffic until patched. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #websecurity #RCE

##

thehackerwire@mastodon.social at 2026-08-04T21:00:03.000Z ##

🔴 CVE-2026-70553 - Critical (9.8)

MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69703
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-08-04T21:30:29

1 posts

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke destructive admin actions such as record deletion by requesting controller endpoints with GET parameters like supp, because t

thehackerwire@mastodon.social at 2026-08-04T20:00:02.000Z ##

🔴 CVE-2026-69703 - Critical (9.8)

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66803
(10.0 CRITICAL)

EPSS: 0.48%

updated 2026-08-04T20:46:44.650000

1 posts

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-08-02T22:59:51.000Z ##

🔴 CVE-2026-66803 - Critical (10)

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49435
(9.8 CRITICAL)

EPSS: 0.77%

updated 2026-08-04T20:16:52.160000

1 posts

Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.

thehackerwire@mastodon.social at 2026-08-04T20:00:14.000Z ##

🔴 CVE-2026-49435 - Critical (9.8)

Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70486
(8.2 HIGH)

EPSS: 0.37%

updated 2026-08-04T20:02:04

1 posts

## Summary Any authenticated user with access to a terminal server could get script of their choosing to run in the Open WebUI origin itself. The HTML file preview rendered terminal-served files in an iframe whose sandbox always granted `allow-same-origin` alongside `allow-scripts`, and the file is served from a path on the application's own origin, so the sandbox provided no isolation at all. Scr

thehackerwire@mastodon.social at 2026-08-04T21:00:23.000Z ##

🟠 CVE-2026-70486 - High (8.2)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files served from...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70482
(8.1 HIGH)

EPSS: 0.34%

updated 2026-08-04T19:52:03

1 posts

## Summary The OAuth token exchange endpoint accepts a raw provider access token and validates it by calling the provider's userinfo endpoint. A userinfo endpoint reports only that a token is valid, never which OAuth client it was issued to, and the endpoint performed no audience or client check of its own. Anyone holding an access token minted for any client registered with the same provider cou

thehackerwire@mastodon.social at 2026-08-04T21:00:13.000Z ##

🟠 CVE-2026-70482 - High (8.1)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it by calling ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-70478(CVSS UNKNOWN)

EPSS: 0.38%

updated 2026-08-04T19:37:38

1 posts

### Summary The OAuth2 token refresh endpoint (`POST /api/v1/oauth2-credential/refresh/:credentialId`) is in `WHITELIST_URLS`, meaning it requires **no authentication**. It decrypts the stored credential (containing `clientId`, `clientSecret`, `refresh_token`), sends a refresh request to the configured OAuth provider, and returns the new `access_token` directly in the response body. ### Root Cau

offseq@infosec.exchange at 2026-08-05T03:00:25.000Z ##

FlowiseAI Flowise (<3.1.3) has a CRITICAL vuln (CVE-2026-70478): unauthenticated POST endpoint leaks refreshed OAuth tokens if credential ID is known. Upgrade to 3.1.3+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202670478 #OAuth #infosec

##

CVE-2026-70477(CVSS UNKNOWN)

EPSS: 0.44%

updated 2026-08-04T19:29:28

1 posts

-- ABSTRACT ------------------------------------- Trend Micro's Zero Day Initiative has identified a vulnerability affecting the following products: Flowise - Flowise -- VULNERABILITY DETAILS ------------------------ * Version tested: 3.1.1 * Installer file: https://github.com/FlowiseAI/Flowise (npm install flowise@3.1.1) * Platform tested: Ubuntu 25.10 --- A prompt injection sent to a chatflo

offseq@infosec.exchange at 2026-08-05T04:30:25.000Z ##

FlowiseAI Flowise <3.1.3 is affected by CRITICAL CVE-2026-70477 (code injection, CVSS 9.5). Exploitation via CSV Agent node allows arbitrary Python execution. Patch to 3.1.3+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Infosec #CVE #AppSec

##

CVE-2026-18830
(8.1 HIGH)

EPSS: 0.29%

updated 2026-08-04T19:16:45.433000

1 posts

Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required.

awssecurityfeed@infosec.exchange at 2026-08-04T18:00:01.000Z ##

CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation

Bulletin ID: 2026-073-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 10:00 AM PDT
Description:
We have identified CVE-2026-18830 in the Amazon Bedrock AgentCore harness InvokeHarness API...

aws.amazon.com/security/securi

#aws #security

##

CVE-2026-15958
(9.3 CRITICAL)

EPSS: 0.20%

updated 2026-08-04T18:32:27

1 posts

The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account and to read the connected account and administrator email addresses.

offseq@infosec.exchange at 2026-08-04T07:30:25.000Z ##

CVE-2026-15958 (CRITICAL): Easy Integration for Dropbox <2.2.0 suffers from missing authorization, letting unauthenticated users manage Dropbox files and access account emails. Patch or disable plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE #Security

##

CVE-2026-24254
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-08-04T18:31:37

1 posts

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

CVE-2026-64633(CVSS UNKNOWN)

EPSS: 0.34%

updated 2026-08-04T18:31:36

1 posts

A vulnerability allowing remote unauthenticated code execution on the agent host.

CVE-2026-15920
(6.1 MEDIUM)

EPSS: 0.30%

updated 2026-08-04T18:31:31

2 posts

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is displayed as a link on changelist and read-only admin pages, which allows cross-site scripting against staff users who click the link. Exploitation req

CVE-2026-15307
(8.8 HIGH)

EPSS: 0.54%

updated 2026-08-04T18:31:31

1 posts

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a spatial lookup against a `GeometryField` or `RasterField` reaches this constructor, including untrusted input, for example a spatial-field filter subm

CVE-2026-24084
(7.5 HIGH)

EPSS: 0.23%

updated 2026-08-04T18:31:31

1 posts

Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.

thehackerwire@mastodon.social at 2026-08-04T17:01:22.000Z ##

🟠 CVE-2026-24084 - High (7.5)

Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-24083
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-04T18:31:31

1 posts

Memory Corruption while processing IOCTL device driver requests with invalid arguments.

thehackerwire@mastodon.social at 2026-08-04T17:01:12.000Z ##

🟠 CVE-2026-24083 - High (7.8)

Memory Corruption while processing IOCTL device driver requests with invalid arguments.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-25292
(7.6 HIGH)

EPSS: 0.16%

updated 2026-08-04T18:31:31

1 posts

Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.

thehackerwire@mastodon.social at 2026-08-04T17:01:01.000Z ##

🟠 CVE-2026-25292 - High (7.6)

Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69100
(8.8 HIGH)

EPSS: 0.55%

updated 2026-08-04T18:31:31

1 posts

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or influence the script field via message template endpoints to execute arbitrary Groovy code and OS commands on the backend

thehackerwire@mastodon.social at 2026-08-04T17:00:15.000Z ##

🟠 CVE-2026-69100 - High (8.8)

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitel...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69098
(9.8 CRITICAL)

EPSS: 0.51%

updated 2026-08-04T18:31:31

1 posts

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ field with subprocess.check_output and arbitrary arguments, achieving remote code execution with appli

thehackerwire@mastodon.social at 2026-08-04T17:00:04.000Z ##

🔴 CVE-2026-69098 - Critical (9.8)

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. A...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-69110
(9.1 CRITICAL)

EPSS: 0.55%

updated 2026-08-04T17:16:59.733000

1 posts

OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Attackers can retrieve intermediate audio, video artifacts, and subtitles belonging to other users' jobs, and additionall

thehackerwire@mastodon.social at 2026-08-04T17:00:25.000Z ##

🔴 CVE-2026-69110 - Critical (9.1)

OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18684
(9.8 CRITICAL)

EPSS: 2.03%

updated 2026-08-04T17:16:47.273000

1 posts

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure and confir

offseq@infosec.exchange at 2026-08-04T03:00:29.000Z ##

CVE-2026-18684 | CRITICAL command injection in GL.iNet GL-MT3000 (fw 4.4.0 – 4.4.5) 🛡️ Remote attackers can execute commands — no patch yet. Restrict access and watch for vendor updates. Info: radar.offseq.com/threat/cve-20 #OffSeq #CVE202618684 #IoTSecurity

##

CVE-2026-48326
(9.9 CRITICAL)

EPSS: 0.48%

updated 2026-08-04T16:16:25.497000

1 posts

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

thehackerwire@mastodon.social at 2026-08-04T00:00:13.000Z ##

🔴 CVE-2026-48326 - Critical (9.9)

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged at...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18686
(9.8 CRITICAL)

EPSS: 2.61%

updated 2026-08-04T16:16:21.593000

1 posts

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of

offseq@infosec.exchange at 2026-08-04T01:30:25.000Z ##

CVE-2026-18686: CRITICAL command injection in GL.iNet GL-MT3000 (4.4.0 – 4.4.5). Remote, unauthenticated code execution possible — no patch yet. Limit admin interface exposure & monitor for abuse. radar.offseq.com/threat/cve-20 #OffSeq #CVE #RouterSecurity

##

CVE-2026-18577
(8.1 HIGH)

EPSS: 4.10%

updated 2026-08-04T15:33:20

12 posts

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

1 repos

https://github.com/HORKimhab/CVE-2026-18577

secdb@infosec.exchange at 2026-08-04T19:00:11.000Z ##

🚨 [CISA-2026:0804] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-18556 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: uptime.n-able.com/ ; status.n-able.com/2026/08/02/n ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34486 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Tomcat
- Notes: lists.apache.org/thread/9510k5 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9198 (secdb.nttzen.cloud/cve/detail/)
- Name: IBM Langflow Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: IBM
- Product: Langflow
- Notes: ibm.com/support/pages/node/727 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260804 #cisa20260804 #cve_2026_18556 #cve_2026_34486 #cve_2026_9198 #cve202618556 #cve202634486 #cve20269198

##

AAKL@infosec.exchange at 2026-08-04T15:28:21.000Z ##

New.

Rapid7: CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #infosec #vulnerabiity

##

AAKL@infosec.exchange at 2026-08-04T14:33:24.000Z ##

CISA added this vulnerability to the catalogue yesterday, if you missed it:

CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability cve.org/CVERecord?id=CVE-2026-

Arctic Wolf: CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching arcticwolf.com/resources/blog/ #infosec #vulnerability #CISA

##

youranonnewsirc@nerdculture.de at 2026-08-04T04:26:32.000Z ##

Geopolitical: Trump indicates ongoing talks with Iran for Strait of Hormuz reopening (Aug 3-4), though Tehran denies. Gaza operations persist.
Technology: SK hynix & Sandisk unveil HBF standard for AI memory (Aug 4). White House schedules AI safety talks (Aug 4).
Cybersecurity: CISA alerts to active exploitation of N-able N-central flaw (CVE-2026-18577) (Aug 3). Interpol: AI fuels over 55% of African cybercrime (Aug 3).
#AnonNews_irc #Cybersecurity #News

##

thecybermind@infosec.exchange at 2026-08-03T23:17:37.000Z ##

URGENT C-SUITE BRIEF: Active exploitation verified on CISA KEV for CVE-2026-18577 (N-able N-central). Executive leadership must oversee immediate patch deployment, supply chain auditing, and trust model revalidation to safeguard organizational assets. Full strategic analysis: thecybermind.co/0156

#CyberRisk

##

oversecurity@mastodon.social at 2026-08-03T22:39:19.000Z ##

N-able warns of N-central auth bypass flaw exploited in attacks

N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-...

🔗️ [Bleepingcomputer] link.is.it/tS9UYV

##

oversecurity@mastodon.social at 2026-08-03T22:38:32.000Z ##

N-able warns of N-central auth bypass flaw exploited in attacks

N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-...

🔗️ [Bleepingcomputer] bleepingcomputer.com/news/secu

##

thecybermind@infosec.exchange at 2026-08-03T22:06:53.000Z ##

ALERT: Active exploitation verified for CVE-2026-18577 in N-able N-central. Unauthenticated attackers can execute account takeovers via alternate path manipulation. Access our complete threat breakdown, SPL/KQL detection logic, and hardening guidance here: thecybermind.co/jily

#CyberSecurity #ThreatIntel

##

secdb@infosec.exchange at 2026-08-03T21:00:14.000Z ##

🚨 [CISA-2026:0803] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-18577 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: documentation.n-able.com/N-cen ; status.n-able.com/2026/08/02/n ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260803 #cisa20260803 #cve_2026_18577 #cve202618577

##

cisakevtracker@mastodon.social at 2026-08-03T19:00:49.000Z ##

CVE ID: CVE-2026-18577
Vendor: N-able
Product: N-central
Date Added: 2026-08-03
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-08-03T16:25:47.000Z ##

CVE-2026-18577 is being exploited in the wild for N-central account takeover. An incomplete patch let attackers gain admin access. Update to 2026.3.1.7.

#Nable #Ncentral #CVE202618577 #AccountTakeover #RMM #CyberSecurity

securityonline.info/cve-2026-1

##

harrysintonen@infosec.exchange at 2026-08-03T10:48:19.000Z ##

Some time ago I discovered a meddler in the middle vulnerability between N-able agent and nCentral server that allowed full SYSTEM compromise of the endpoints, but this vulnerability in nCentral server is far far far worse:

status.n-able.com/2026/08/02/n

#nablencentral #CVE_2026_18577 #infosec #cybersecurity

##

CVE-2026-60007(CVSS UNKNOWN)

EPSS: 0.45%

updated 2026-08-04T15:32:29

1 posts

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use repeated unauthenticated `ActivateSession` requests as a padding oracle, recover the victim's password, and authenticate with

offseq@infosec.exchange at 2026-08-04T13:30:20.000Z ##

Eclipse Milo (0.6.0 – 1.1.4) faces a CRITICAL flaw (CVE-2026-60007): error messages in username-token RSA PKCS#1 v1.5 handling enable padding oracle attacks, risking password compromise. Patch status unclear. radar.offseq.com/threat/cve-20 #OffSeq #EclipseMilo #Vuln #Infosec

##

CVE-2026-58061
(0 None)

EPSS: 0.21%

updated 2026-08-04T14:50:12.360000

1 posts

In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

harrysintonen@infosec.exchange at 2026-08-04T09:28:16.000Z ##

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

#infosec #cybersecurity

##

CVE-2026-58062
(0 None)

EPSS: 0.20%

updated 2026-08-04T14:50:12.360000

2 posts

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

1 repos

https://github.com/xiaoqiMikko/bc-check

harrysintonen@infosec.exchange at 2026-08-04T09:28:16.000Z ##

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

#infosec #cybersecurity

##

offseq@infosec.exchange at 2026-08-03T03:00:27.000Z ##

CVE-2026-58062 (CRITICAL, CVSS 9.3): Bouncy Castle Java improperly validates stapled OCSP, risking cert trust. Affects =1.66, <1.85, LTS <2.73.12. Update to 1.85+ or LTS 2.73.12. Details: radar.offseq.com/threat/cve-20 #OffSeq #BouncyCastle #JavaSecurity

##

CVE-2026-48331
(10.0 CRITICAL)

EPSS: 0.47%

updated 2026-08-04T14:48:22.933000

1 posts

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-15721
(9.8 CRITICAL)

EPSS: 0.23%

updated 2026-08-04T14:16:30.620000

1 posts

Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

thehackerwire@mastodon.social at 2026-08-04T13:00:22.000Z ##

🔴 CVE-2026-15721 - Critical (9.8)

Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection.

This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14175
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-08-04T12:34:56

2 posts

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

thehackerwire@mastodon.social at 2026-08-04T13:00:33.000Z ##

🔴 CVE-2026-14175 - Critical (9.8)

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.

This issue affects HUMANIST Digital Human Resources: from...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-04T12:00:28.000Z ##

CVE-2026-14175 (CRITICAL, CVSS 9.8): HUMANIST Digital HR v26.0 has an unrestricted file upload flaw — attackers can deploy web shells for full compromise. No patch yet. Restrict uploads, monitor, and apply network controls. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #AppSec

##

CVE-2026-14804
(9.1 CRITICAL)

EPSS: 0.30%

updated 2026-08-04T12:34:56

2 posts

Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

thehackerwire@mastodon.social at 2026-08-04T13:00:08.000Z ##

🔴 CVE-2026-14804 - Critical (9.1)

Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable.

This issue affects HUMANIST Digital Human Resources: from ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-08-04T10:30:25.000Z ##

CVE-2026-14804: CRITICAL (CVSS 9.1) in HUMANIST Digital HR v26.0 🛡️ Hard-coded cryptographic key (CWE-321) allows data exposure & integrity loss. No official fix — limit access & track vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #CVE202614804

##

CVE-2026-17566
(9.9 CRITICAL)

EPSS: 0.43%

updated 2026-08-04T12:31:51.160000

1 posts

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wrapper, create_import_export_job() (route POST /import_export/job/<sid>, gated only by the ordinary, commonly-granted tools_import_export_data permission)

1 repos

https://github.com/HackSpeak/CVE-2026-17566

CVE-2026-18754
(9.1 CRITICAL)

EPSS: 0.31%

updated 2026-08-04T09:31:41

1 posts

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.

offseq@infosec.exchange at 2026-08-04T09:00:29.000Z ##

CVE-2026-18754: GeoVision GV-AS1620 (GV-Cloud) v1.16 has a CRITICAL bug — static RSA key in firmware lets attackers decrypt HTTPS & spoof server. No fix yet; restrict access & watch for vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Cybersecurity #TLS

##

CVE-2026-6837
(7.2 HIGH)

EPSS: 0.95%

updated 2026-08-04T03:31:16

1 posts

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

hugovalters@mastodon.social at 2026-08-04T14:06:53.000Z ##

CVE-2026-6837 - Post-auth command injection in Zyxel WAX650S export-cgi. Admin RCE. CVSS 7.2. Unpatched - restrict admin access now. #CVE #Zyxel #infosec

valtersit.com/cve/CVE-2026-683

##

CVE-2026-62354(CVSS UNKNOWN)

EPSS: 0.26%

updated 2026-08-04T00:35:57

1 posts

Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined component validation methods with alternative settings. Apache NiFi installations that do not implement different levels of

DailyCyberSecurity@infosec.exchange at 2026-08-04T01:52:18.000Z ##

Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption.

#ApacheNiFi #CyberSecurity #Vulnerabilities #CVE #InfoSec

securityonline.info/apache-nif

##

CVE-2026-48333
(9.8 CRITICAL)

EPSS: 0.47%

updated 2026-08-04T00:35:01

1 posts

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of this issue does not require user interaction.

offseq@infosec.exchange at 2026-08-04T06:00:24.000Z ##

CVE-2026-48333 (CRITICAL, CVSS 9.8): Incorrect Authorization in Adobe Campaign Classic enables attackers to escalate privileges without user interaction. No patch info yet — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #Adobe #Security #CVE202648333

##

CVE-2026-48323
(10.0 CRITICAL)

EPSS: 0.62%

updated 2026-08-04T00:35:01

2 posts

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

offseq@infosec.exchange at 2026-08-04T04:30:24.000Z ##

Adobe Campaign Classic is impacted by CVE-2026-48323 (CRITICAL, CVSS 10). Improper neutralization in the template engine allows remote code execution — no user interaction needed. No patch yet. Monitor advisories: radar.offseq.com/threat/cve-20 #OffSeq #Adobe #Vuln #CVE202648323

##

thehackerwire@mastodon.social at 2026-08-04T00:00:03.000Z ##

🔴 CVE-2026-48323 - Critical (10)

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vul...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66318
(8.1 HIGH)

EPSS: 0.37%

updated 2026-08-04T00:35:01

1 posts

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

thehackerwire@mastodon.social at 2026-08-04T01:00:05.000Z ##

🟠 CVE-2026-66318 - High (8.1)

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18685
(9.8 CRITICAL)

EPSS: 1.99%

updated 2026-08-04T00:35:01

1 posts

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure and confirmed the existence of t

offseq@infosec.exchange at 2026-08-04T00:00:36.000Z ##

CVE-2026-18685: CRITICAL command injection in GL.iNet GL-MT3000 (4.4.0 – 4.4.5). Remote, unauthenticated RCE possible. No patch yet — restrict access & monitor for abuse. Details: radar.offseq.com/threat/cve-20 #OffSeq #vuln #IoT #infosec

##

CVE-2026-48330
(10.0 CRITICAL)

EPSS: 0.68%

updated 2026-08-04T00:35:01

1 posts

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the application. Exploitation of this is

thehackerwire@mastodon.social at 2026-08-04T00:00:24.000Z ##

🔴 CVE-2026-48330 - Critical (10)

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66315
(7.5 HIGH)

EPSS: 0.62%

updated 2026-08-04T00:34:55

1 posts

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

thehackerwire@mastodon.social at 2026-08-04T01:00:25.000Z ##

🟠 CVE-2026-66315 - High (7.5)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59913
(7.8 HIGH)

EPSS: 0.11%

updated 2026-08-03T21:31:44

1 posts

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

thehackerwire@mastodon.social at 2026-08-03T20:00:25.000Z ##

🟠 CVE-2026-59913 - High (7.8)

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59912
(7.8 HIGH)

EPSS: 0.10%

updated 2026-08-03T21:31:36

1 posts

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and arbitrary code execution.

thehackerwire@mastodon.social at 2026-08-03T20:00:11.000Z ##

🟠 CVE-2026-59912 - High (7.8)

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18108
(9.8 CRITICAL)

EPSS: 0.22%

updated 2026-08-03T21:31:35

1 posts

Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature. _verify_encrypted_assertion decrypts the EncryptedAssertion and returns it as verified when it carries no signature, via "return $xml unless $xpath->exists('dsig:Signature', $assert);". The signature check and the trus

hugovalters@mastodon.social at 2026-08-03T23:11:09.000Z ##

CVE-2026-18108 - Critical auth bypass in Perl Net::SAML2. Encrypted assertions without signatures accepted. CVSS 9.8. Upgrade to >=0.86 now. #CVE #Perl #infosec

valtersit.com/cve/cve-2026-181

##

CVE-2026-69240
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-08-03T20:29:52

1 posts

### Summary SQL Injection is possible with strings only **if dialect is set to `oracle`**. The vulnerability was confirmed on Sequelize v6.37.3. ### Details The `escape` function defined in `sql-string.js` does not escape quotes if the value starts with `TO_TIMESTAMP` or `TO_DATE`. ```javascript } else if (dialect === 'oracle' && typeof val === 'string') { if (val.startsWith('TO_TIMESTAMP'

thehackerwire@mastodon.social at 2026-08-03T22:00:08.000Z ##

🔴 CVE-2026-69240 - Critical (9.8)

Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18589
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-08-03T20:17:15.910000

1 posts

A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. The affected component should be upgraded. The vendor was contacted early, responded in a very prof

offseq@infosec.exchange at 2026-08-03T07:30:28.000Z ##

CVE-2026-18589 (CRITICAL, CVSS 9.3) in Wavlink WL-NU516U1: Stack buffer overflow in nas.cgi enables unauthenticated RCE/DoS. Patch available — update ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202618589 #IoTSecurity #PatchManagement

##

CVE-2026-18614
(9.8 CRITICAL)

EPSS: 2.01%

updated 2026-08-03T19:16:45.200000

1 posts

A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and conf

thehackerwire@mastodon.social at 2026-08-03T20:00:35.000Z ##

🔴 CVE-2026-18614 - Critical (9.8)

A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16300
(9.8 CRITICAL)

EPSS: 0.30%

updated 2026-08-03T18:31:51

1 posts

The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

offseq@infosec.exchange at 2026-08-03T09:00:24.000Z ##

CVE-2026-16300: ChamaWP (<1.0.13) is vulnerable to missing authorization — attackers can reset any user’s password, including admins. Risk: full site takeover. Patch status unconfirmed; restrict password resets & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

CVE-2026-18574(CVSS UNKNOWN)

EPSS: 0.99%

updated 2026-08-03T15:32:49

2 posts

An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered

DailyCyberSecurity@infosec.exchange at 2026-08-03T16:16:01.000Z ##

CVE-2026-18574 is a Check Point authentication bypass rated CVSS 9.3, letting attackers run commands as admin. Patch via the latest Jumbo Hotfix.

#CheckPoint #CVE202618574 #AuthenticationBypass #SecurityManagement #CyberSecurity #Firewall

securityonline.info/cve-2026-1

##

offseq@infosec.exchange at 2026-08-03T13:30:28.000Z ##

CRITICAL auth bypass (CVE-2026-18574, CVSS 9.3) affects Check Point Security Management Server & MDS. Remote attackers can execute commands w/o auth. No patch yet — restrict management access. radar.offseq.com/threat/cve-20 #OffSeq #CVE202618574 #CheckPoint #Infosec 🔒

##

CVE-2026-33591(CVSS UNKNOWN)

EPSS: 0.52%

updated 2026-08-03T12:32:43

3 posts

A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.

cyberveille@mastobot.ping.moi at 2026-08-05T13:00:06.000Z ##

📢 [VULN] WAPT Server : cette faille permet de contourner l'authentification (CVE-2026-33591)

La faille de sécurité CVE-2026-33591 affecte certaines versions de WAPT Server, la solution de déploiement logiciel éditée par Tranquil IT. En l'exploitant, un attaquant distant non authentifié peut contourner une restriction de sécurité et récupérer un jeton de session valide pour le compte ciblé.

🔗 it-connect.fr/wapt-server-cve-
💬 discussion : infosec.pub/post/50502015
#Vulnérabilité #CVE #Cyberveille

##

benzogaga33@mamot.fr at 2026-08-04T09:40:04.000Z ##

WAPT Server (CVE-2026-33591) : une faille permet de contourner l’authentification it-connect.fr/wapt-server-cve- #ActuCybersécurité #Cybersécurité #Vulnérabilité

##

offseq@infosec.exchange at 2026-08-03T12:00:25.000Z ##

Tranquil IT WAPT Server 2.6.0.16767 hit by CVE-2026-33591 (CRITICAL, CVSS 10). Remote attackers can bypass authentication & grab session tokens via crafted packets. No patch yet — restrict access & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #CVE202633591 #Infosec #Vulnerability

##

CVE-2026-9593
(6.7 MEDIUM)

EPSS: 0.11%

updated 2026-08-03T09:32:46

1 posts

A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory, potentially resulting in unauthorized access to connected devices and exposure, modification, or disruption of device data or operation.

certvde@infosec.exchange at 2026-08-03T06:30:53.000Z ##

#OT #Advisory VDE-2026-065
Endress+Hauser: iDTM Debug Interface Vulnerability in the FDI Package Library

A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory.
#CVE CVE-2026-9593

certvde.com/en/advisories/vde-

#CSAF endress-hauser.csaf-tp.certvde

##

CVE-2026-12816(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-08-03T09:32:36

1 posts

In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

harrysintonen@infosec.exchange at 2026-08-04T09:28:16.000Z ##

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

#infosec #cybersecurity

##

CVE-2026-8763(CVSS UNKNOWN)

EPSS: 0.33%

updated 2026-08-03T09:32:36

2 posts

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

1 repos

https://github.com/xiaoqiMikko/bc-check

harrysintonen@infosec.exchange at 2026-08-04T09:28:16.000Z ##

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

#infosec #cybersecurity

##

offseq@infosec.exchange at 2026-08-03T06:00:34.000Z ##

CVE-2026-8763: CRITICAL vuln in Bouncy Castle BC-JAVA (<1.85, 2.73.0-2.73.11). Improper cert validation via trailing dot bypasses name constraints — risk of MITM attacks. No patch yet. Monitor vendor for updates. radar.offseq.com/threat/cve-20 #OffSeq #BouncyCastle #Vuln #CVE20268763

##

CVE-2026-12803(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-08-03T09:32:36

1 posts

In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.

harrysintonen@infosec.exchange at 2026-08-04T09:28:16.000Z ##

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

#infosec #cybersecurity

##

CVE-2026-5674
(8.8 HIGH)

EPSS: 0.13%

updated 2026-08-03T08:17:20.920000

1 posts

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.

jfkimmes@tinycyber.space at 2026-08-05T07:02:17.000Z ##

Simple Flatpak sandbox escape through pipewire:
1. Missing auth 2. Insecure default module loader

Vulns like these do not exist because devs lack the capability to look for them, but they lack the capacity.

I predict this class of issue will soon™️ cease to exist. LLM harnesses like the one used by Johann are getting productized at scale currently. The question is just how cheap can we make them and how quickly can we get them into CI pipelines.
embracethered.com/blog/posts/2

#AI #LLM #InfoSec

##

CVE-2026-59639(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-08-03T06:32:44

1 posts

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).

harrysintonen@infosec.exchange at 2026-08-04T09:28:16.000Z ##

Bouncy Castle Java 1.85 has been released. It includes fixes to various rather significant vulnerabilities and weaknesses. Some highlights:

- CVE-2026-8763 - Name Constraints bypass via trailing dot in rfc822Name and URI.
- CVE-2026-12803 - KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery).
- CVE-2026-12816 - IESEngine stream-mode MAC forgery via length-dependent KDF split.
- CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check.
- CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate.
- CVE-2026-59639 - CMS verifySignatures returns true for SignedData with zero signers.

bouncycastle.org/resources/new

#infosec #cybersecurity

##

CVE-2026-59650(CVSS UNKNOWN)

EPSS: 0.26%

updated 2026-08-03T06:32:44

1 posts

In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

1 repos

https://github.com/xiaoqiMikko/bc-check

offseq@infosec.exchange at 2026-08-03T04:30:26.000Z ##

BC-JAVA users: CVE-2026-59650 (CRITICAL, CVSS 9.3) exposes MTI/A0 Diffie-Hellman via improper input validation. Affects <1.85, 2.73.0 – 2.73.11. No patch yet — avoid affected versions & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Java #Cryptography

##

CVE-2026-59638(CVSS UNKNOWN)

EPSS: 0.28%

updated 2026-08-03T06:32:44

1 posts

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).

1 repos

https://github.com/xiaoqiMikko/bc-check

offseq@infosec.exchange at 2026-08-03T01:30:23.000Z ##

CVE-2026-59638 (CRITICAL, CVSS 9.3) in BC-JAVA: Improper cert validation due to default CN-fallback can expose TLS connections to MITM. Affects <1.85, LTS <2.73.12. Patch status unknown — monitor vendor & consider disabling fallback. radar.offseq.com/threat/cve-20 #OffSeq #CVE202659638 #infosec

##

CVE-2026-3245
(7.5 HIGH)

EPSS: 0.24%

updated 2026-08-03T00:30:35

1 posts

A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

thehackerwire@mastodon.social at 2026-08-03T00:59:47.000Z ##

🟠 CVE-2026-3245 - High (7.5)

A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-71399
(8.6 HIGH)

EPSS: 0.31%

updated 2026-08-02T15:30:21

1 posts

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass disabledPaths configuration and path-based rate limits by submitting requests with extr

thehackerwire@mastodon.social at 2026-08-02T15:00:06.000Z ##

🟠 CVE-2025-71399 - High (8.6)

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64531
(7.8 HIGH)

EPSS: 0.13%

updated 2026-08-01T09:30:23

2 posts

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guar

4 repos

https://github.com/mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool

https://github.com/HackSpeak/CVE-2026-64531

https://github.com/suominen/ovswrap

https://github.com/0xBlackash/CVE-2026-64531

guru@thecybersecguru.com at 2026-08-05T15:43:42.000Z ##

OVSwrap (CVE-2026-64531): How a 13-Year-Old Open vSwitch Bug Became a Reliable Linux Root Exploit

OVSwrap (CVE-2026-64531) is a Linux kernel privilege escalation flaw affecting Open vSwitch. Explore the vulnerability, exploit chain and more

thecybersecguru.com/news/ovswr

##

Analyst207@mastodon.social at 2026-08-05T12:34:36.000Z ##

Linux Flaw Exposes Local Users to Root via Open vSwitch

A newly discovered Linux flaw, CVE-2026-64531, lets local users potentially gain root access via Open vSwitch, even without an existing OVS bridge, running ovs-vswitchd, or host-level CAP_NET_ADMIN privileges. This vulnerability, with a CVSS score of 7.8, was quickly patched after being responsibly disclosed.

osintsights.com/linux-flaw-exp

#Cve202664531 #OpenVswitch #LinuxKernel #MemoryCorruption #Ovswrap

##

CVE-2026-9044(CVSS UNKNOWN)

EPSS: 0.97%

updated 2026-08-01T00:31:02

2 posts

An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises from improper filtering of special characters.  Successful exploitation of this vulnerability may enable an attacker to

CVE-2026-63223
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-08-01T00:17:17.750000

1 posts

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads in a web-accessible script-enabled directory. Applications are impacted when they validate uploads u

2 repos

https://github.com/imbas007/CVE-2026-63223-POC

https://github.com/shinthink/CVE-2026-63223

thehackerwire@mastodon.social at 2026-08-02T17:59:58.000Z ##

🔴 CVE-2026-63223 - Critical (9.8)

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an applicat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-69935
(9.8 CRITICAL)

EPSS: 0.26%

updated 2026-07-31T21:32:56

1 posts

CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.

thehackerwire@mastodon.social at 2026-08-03T00:00:13.000Z ##

🔴 CVE-2025-69935 - Critical (9.8)

CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14319
(7.5 HIGH)

EPSS: 0.32%

updated 2026-07-31T21:32:56

1 posts

The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their name and subscription details.

thehackerwire@mastodon.social at 2026-08-02T16:00:39.000Z ##

🟠 CVE-2026-14319 - High (7.5)

The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their n...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-69933
(9.8 CRITICAL)

EPSS: 0.26%

updated 2026-07-31T21:32:55

1 posts

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.

thehackerwire@mastodon.social at 2026-08-02T23:59:52.000Z ##

🔴 CVE-2025-69933 - Critical (9.8)

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43831
(7.5 HIGH)

EPSS: 0.24%

updated 2026-07-31T21:32:55

1 posts

Successful exploitation of the vulnerability could allow an unauthenticated attacker to exploit a stack-based buffer overflow in the log message functionality to conduct code execution.

thehackerwire@mastodon.social at 2026-08-02T21:00:00.000Z ##

🟠 CVE-2026-43831 - High (7.5)

Full details and mitigation steps are currently restricted and will be published at a later date.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43830
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-07-31T21:31:54

1 posts

Successful exploitation of the command injection vulnerability could allow an attacker to execute arbitrary commands during the firmware upgrade file verification process.

thehackerwire@mastodon.social at 2026-08-02T20:59:50.000Z ##

🔴 CVE-2026-43830 - Critical (9.8)

Full details and mitigation steps are currently restricted and will be published at a later date.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-69936
(9.8 CRITICAL)

EPSS: 0.26%

updated 2026-07-31T21:31:53

1 posts

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.

thehackerwire@mastodon.social at 2026-08-03T01:00:09.000Z ##

🔴 CVE-2025-69936 - Critical (9.8)

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56673
(7.5 HIGH)

EPSS: 0.43%

updated 2026-07-31T20:16:52.487000

1 posts

ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without a containment check, allowing an unauthenticated crafted POST /prompt workflow using LoadImage or sibling nodes to probe arbitrary host paths and exfilt

thehackerwire@mastodon.social at 2026-08-02T19:00:09.000Z ##

🟠 CVE-2026-56673 - High (7.5)

ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43832
(7.5 HIGH)

EPSS: 0.24%

updated 2026-07-31T20:16:50.777000

1 posts

Full details and mitigation steps are currently restricted and will be published at a later date.

thehackerwire@mastodon.social at 2026-08-02T20:00:09.000Z ##

🟠 CVE-2026-43832 - High (7.5)

Full details and mitigation steps are currently restricted and will be published at a later date.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43829
(7.5 HIGH)

EPSS: 0.24%

updated 2026-07-31T20:16:50.317000

1 posts

Full details and mitigation steps are currently restricted and will be published at a later date.

thehackerwire@mastodon.social at 2026-08-02T21:00:11.000Z ##

🟠 CVE-2026-43829 - High (7.5)

Full details and mitigation steps are currently restricted and will be published at a later date.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-69934
(9.8 CRITICAL)

EPSS: 0.26%

updated 2026-07-31T19:17:03.113000

1 posts

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.

thehackerwire@mastodon.social at 2026-08-03T00:00:02.000Z ##

🔴 CVE-2025-69934 - Critical (9.8)

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12720
(7.5 HIGH)

EPSS: 0.30%

updated 2026-07-31T18:33:20

1 posts

The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. With a suitable gadget chain present on the site (via another installed Kirki WordPress plugin before 6.0.13, , or an outdated WordPress v

1 repos

https://github.com/webshellseo8/CVE-2026-12720-Proof-of-Concept

thehackerwire@mastodon.social at 2026-08-02T17:59:49.000Z ##

🟠 CVE-2026-12720 - High (7.5)

The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12695
(8.1 HIGH)

EPSS: 0.29%

updated 2026-07-31T18:33:20

1 posts

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's password to bypass two-factor authentication and gain access to the victim's account, including administrators.

thehackerwire@mastodon.social at 2026-08-02T17:00:32.000Z ##

🟠 CVE-2026-12695 - High (8.1)

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12721
(8.6 HIGH)

EPSS: 0.26%

updated 2026-07-31T18:33:20

1 posts

The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

thehackerwire@mastodon.social at 2026-08-02T15:00:53.000Z ##

🟠 CVE-2026-12721 - High (8.6)

The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15969
(9.8 CRITICAL)

EPSS: 0.98%

updated 2026-07-31T18:33:17

2 posts

SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.

DailyCyberSecurity at 2026-08-05T14:27:11.173Z ##

Six SGLang vulnerabilities include unauthenticated RCE via CVE-2026-15969, plus data and model-weight theft. No patch exists yet.

securityonline.info/sglang-vul

##

DailyCyberSecurity@infosec.exchange at 2026-08-05T14:27:11.000Z ##

Six SGLang vulnerabilities include unauthenticated RCE via CVE-2026-15969, plus data and model-weight theft. No patch exists yet.

#SGLang #RCE #LLMSecurity #CVE202615969 #InfoSec

securityonline.info/sglang-vul

##

CVE-2026-58048(CVSS UNKNOWN)

EPSS: 0.50%

updated 2026-07-31T18:32:25

1 posts

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

1 repos

https://github.com/imbas007/POC-CVE-2026-58048

CVE-2026-14919
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-07-31T18:32:17

1 posts

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control and take over the administrator account.

thehackerwire@mastodon.social at 2026-08-02T15:00:43.000Z ##

🔴 CVE-2026-14919 - Critical (9.8)

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to red...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-35847
(9.8 CRITICAL)

EPSS: 0.37%

updated 2026-07-31T18:32:13

1 posts

An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file

thehackerwire@mastodon.social at 2026-08-02T23:00:11.000Z ##

🔴 CVE-2026-35847 - Critical (9.8)

An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12251
(8.1 HIGH)

EPSS: 0.23%

updated 2026-07-31T18:17:09.777000

1 posts

The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default, allowing unauthenticated users to register with a site-defined role that carries administrator capabilities and gain administrative access, when such a

thehackerwire@mastodon.social at 2026-08-02T17:00:22.000Z ##

🟠 CVE-2026-12251 - High (8.1)

The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13609
(8.8 HIGH)

EPSS: 0.25%

updated 2026-07-31T17:16:32.347000

1 posts

The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthenticated visitor is therefore stored as a live tag and later output without escaping on the Frontend Admin by DynamiApps WordPress plugin before 3.29.9'

thehackerwire@mastodon.social at 2026-08-02T16:00:29.000Z ##

🟠 CVE-2026-13609 - High (8.8)

The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-69937
(9.8 CRITICAL)

EPSS: 0.26%

updated 2026-07-31T16:16:56.643000

1 posts

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.

thehackerwire@mastodon.social at 2026-08-03T01:00:19.000Z ##

🔴 CVE-2025-69937 - Critical (9.8)

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14333
(7.5 HIGH)

EPSS: 0.30%

updated 2026-07-31T15:33:51

1 posts

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes.

thehackerwire@mastodon.social at 2026-08-02T16:00:52.000Z ##

🟠 CVE-2026-14333 - High (7.5)

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14830
(7.5 HIGH)

EPSS: 0.21%

updated 2026-07-31T14:16:46.133000

1 posts

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without paying.

thehackerwire@mastodon.social at 2026-08-02T15:00:32.000Z ##

🟠 CVE-2026-14830 - High (7.5)

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without pa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-38709
(9.8 CRITICAL)

EPSS: 2.67%

updated 2026-07-31T12:31:33

2 posts

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input.

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

thehackerwire@mastodon.social at 2026-08-02T22:00:17.000Z ##

🔴 CVE-2026-38709 - Critical (9.8)

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulne...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-52539
(9.1 CRITICAL)

EPSS: 0.30%

updated 2026-07-31T12:30:30

1 posts

Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this by forging JWT session tokens with arbitrary user data and full administrative permissions.

thehackerwire@mastodon.social at 2026-08-02T23:00:02.000Z ##

🔴 CVE-2026-52539 - Critical (9.1)

Outstatic CMS &lt;= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14483
(9.8 CRITICAL)

EPSS: 0.61%

updated 2026-07-31T09:31:25

1 posts

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly accessible I/O endpoint authenticated solely by static, plugin-seeded API credentials that are identical across all installation

2 repos

https://github.com/0xdak/CVE-2026-14483_exploit

https://github.com/MadExploits/CVE-2026-14483

thehackerwire@mastodon.social at 2026-08-02T17:00:12.000Z ##

🔴 CVE-2026-14483 - Critical (9.8)

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63362
(5.9 MEDIUM)

EPSS: 1.53%

updated 2026-07-31T00:30:29

1 posts

An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cause a denial of service via a crafted UDP packet.

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12562
(8.8 HIGH)

EPSS: 0.28%

updated 2026-07-31T00:30:29

1 posts

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. This vulnerability stems from a network-accessible port running a Target Communications Framework (TCF) service that does not require any authentication, allowing an attacker to directly interact with the Linux environment that power

thehackerwire@mastodon.social at 2026-08-02T22:00:27.000Z ##

🟠 CVE-2026-12562 - High (8.8)

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated
service that exposes a debug interface granting full root-level access
to the embedded system. This vulnerability stems from a
network-accessible port running a Target Communica...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66418
(9.3 CRITICAL)

EPSS: 0.34%

updated 2026-07-30T21:31:57

1 posts

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the notification panel, the unescaped log entry is rendered via innerHTML with a permissive C

1 repos

https://github.com/theopaid/CVE-2026-66418-OpenClaw-Dashboard-v3.0.0-Stored-XSS-via-Failed-Login-Username-Field

thehackerwire@mastodon.social at 2026-08-02T22:00:37.000Z ##

🔴 CVE-2026-66418 - Critical (9.3)

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is reco...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12943
(9.8 CRITICAL)

EPSS: 0.92%

updated 2026-07-30T21:31:50

2 posts

IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

DailyCyberSecurity at 2026-08-05T13:47:16.694Z ##

IBM critical vulnerabilities hit App Connect, Power HMC, and webMethods. CVE-2026-12943 lets attackers execute arbitrary commands at CVSS 9.8.

securityonline.info/ibm-critic

##

DailyCyberSecurity@infosec.exchange at 2026-08-05T13:47:16.000Z ##

IBM critical vulnerabilities hit App Connect, Power HMC, and webMethods. CVE-2026-12943 lets attackers execute arbitrary commands at CVSS 9.8.

#IBM #CVE202612943 #RCE #InfoSec #VulnerabilityManagement

securityonline.info/ibm-critic

##

CVE-2026-51291
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-07-30T21:31:47

1 posts

sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert function of the JSON cache management module.

nyanbinary@infosec.exchange at 2026-08-03T18:39:18.000Z ##

Ok, the first one is absolutely it:

Furthermore, we deploy MLG-UAF to conduct large-scale security auditing on mainstream open-source software such as libtiff, LibRaw, SQLite, ImageMagick and Zephyr RTOS. In real-world industrial source code scanning, our framework successfully discovered 17 unique confirmed UAF vulnerabilities assigned with independent Common Vulnerabilities and Exposures (CVE) IDs (CVE-2026 series, RESERVED and not yet publicized), covering cross-functional kernel UAF, intra-procedural cache UAF, race-condition UAF and multimedia parsing UAF scenarios.Real CVE case studies on CVE-2026-51291 (SQLite JSON cache flaw) and CVE-2023-32233 (Linux netfilter kernel vulnerability) demonstrate that MLG-UAF can precisely capture the fixed free-then-use spatial topological fingerprint of UAF defects and accurately resolve ambiguous multi-level pointer aliasing, even under heavy control-flow obfuscation.

##

CVE-2026-17191
(9.1 CRITICAL)

EPSS: 2.83%

updated 2026-07-30T19:10:52.250000

1 posts

An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections. This issue was discovered internally by Arista and the company is not awa

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-41709
(2.7 LOW)

EPSS: 0.38%

updated 2026-07-30T19:07:59.843000

1 posts

VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.

AAKL@infosec.exchange at 2026-08-04T14:53:52.000Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #Apache

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s #google #infosec #vulnerability

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 1.14%

updated 2026-07-30T16:17:15.183000

1 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

AAKL@infosec.exchange at 2026-08-04T14:53:52.000Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #Apache

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s #google #infosec #vulnerability

##

CVE-2026-47876
(9.3 CRITICAL)

EPSS: 0.28%

updated 2026-07-30T15:31:54

1 posts

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

AAKL@infosec.exchange at 2026-08-04T14:53:52.000Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #Apache

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s #google #infosec #vulnerability

##

CVE-2026-59309
(9.8 CRITICAL)

EPSS: 0.74%

updated 2026-07-30T15:31:54

1 posts

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

AAKL@infosec.exchange at 2026-08-04T14:53:52.000Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #Apache

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s #google #infosec #vulnerability

##

CVE-2026-41703
(7.6 HIGH)

EPSS: 0.56%

updated 2026-07-30T15:31:50

1 posts

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.

AAKL@infosec.exchange at 2026-08-04T14:53:52.000Z ##

New;

Broadcom has released advisories relating to several high and medium-severity vulnerabilities support.broadcom.com/web/ecx/s #Broadcom

Nvidia:

CRITICAL: NVIDIA Dynamo - July 2026 nvidia.custhelp.com/app/answer

NVIDIA Triton Inference Server - June 2026 nvidia.custhelp.com/app/answer #Nvidia

Dell:

Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities dell.com/support/kbdoc/en-us/0 #Dell #Apache

Google:

This CRITICAL vulnerability was updated yesterday: VMSA-2026-0006.1: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) support.broadcom.com/web/ecx/s #google #infosec #vulnerability

##

CVE-2026-5491
(7.5 HIGH)

EPSS: 1.54%

updated 2026-07-30T14:18:46.477000

1 posts

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 6067 by default. The issue results from the lack of proper validation of a us

1 repos

https://github.com/BiiTts/CVE-2026-54917-SeaweedFS-Cross-Bucket-Traversal

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-5487
(7.5 HIGH)

EPSS: 1.54%

updated 2026-07-30T14:18:46.477000

1 posts

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4568 by default. The issue results from the lack of proper validation of a us

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12935
(0 None)

EPSS: 0.81%

updated 2026-07-30T14:12:18.697000

1 posts

The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based buffer overflow. The issue occurs when a LAN client initiates a connection to a malicious RTSP server controlled by an attacker. A specially crafted RTSP message may trigger improper memory handling within the kernel module Successful exploitation of this vulnerability ma

DailyCyberSecurity@infosec.exchange at 2026-08-03T01:48:42.000Z ##

A TP-Link TL-WR940N flaw, CVE-2026-12935, allows unauthenticated remote code execution via an RTSP stack buffer overflow. Update the router firmware now.

#TPLink #TLWR940N #CVE202612935 #RCE #RouterSecurity #InfoSec

securityonline.info/tp-link-wr

##

CVE-2026-14869
(8.6 HIGH)

EPSS: 0.29%

updated 2026-07-30T14:08:23.057000

1 posts

The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This vulnerability, CVE-2026-14869, is fixed in terraform-mcp-server 1.1.0.

sayzard@mastodon.sayzard.org at 2026-08-05T17:43:20.000Z ##

Hcsec-2026-23: Multiple vulnerabilities impacting HashiCorp Terraform MCP Server

HashiCorp Terraform MCP Server 0.2.1~1.0.0의 streamable-HTTP 전송 계층에서 SSRF 및 멀티테넌트 자격증명 격리 실패를 포함한 3건의 취약점이 발견됐습니다. CVE-2026-14869는 인증 없이 쿼리 파라미터로 Terraform 엔드포인트를 바꿔 서버의 bearer token을 공격자 서버로 유출할 수 있는 SSRF이며, CVE-2026-16496은 stateful 모드에서 탈취한...

discuss.hashicorp.com/t/hcsec-

##

CVE-2026-16496
(8.9 HIGH)

EPSS: 0.27%

updated 2026-07-30T14:08:23.057000

1 posts

The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed in terraform-mcp-server 1.1.0.

sayzard@mastodon.sayzard.org at 2026-08-05T17:43:20.000Z ##

Hcsec-2026-23: Multiple vulnerabilities impacting HashiCorp Terraform MCP Server

HashiCorp Terraform MCP Server 0.2.1~1.0.0의 streamable-HTTP 전송 계층에서 SSRF 및 멀티테넌트 자격증명 격리 실패를 포함한 3건의 취약점이 발견됐습니다. CVE-2026-14869는 인증 없이 쿼리 파라미터로 Terraform 엔드포인트를 바꿔 서버의 bearer token을 공격자 서버로 유출할 수 있는 SSRF이며, CVE-2026-16496은 stateful 모드에서 탈취한...

discuss.hashicorp.com/t/hcsec-

##

CVE-2026-48449
(10.0 CRITICAL)

EPSS: 0.54%

updated 2026-07-30T03:31:28

1 posts

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

DailyCyberSecurity@infosec.exchange at 2026-08-03T15:02:08.000Z ##

Adobe fixes a CVSS 10 RCE in Campaign Classic (CVE-2026-48449) and eight critical flaws in Bridge. Update to build 9398 and Bridge 15.1.7 or 16.0.6 now.

#AdobeCampaign #CVE202648449 #AdobeBridge #CriticalPatch #RCE

securityexpress.info/adobe-cam

##

CVE-2026-5492
(6.5 MEDIUM)

EPSS: 1.60%

updated 2026-07-29T21:31:08

1 posts

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4568 by default. The issue results from the lack of proper validation of a user-s

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-20316
(5.3 MEDIUM)

EPSS: 0.79%

updated 2026-07-29T21:31:00

2 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vuln

AAKL at 2026-08-05T15:17:35.586Z ##

Broadcom has addressed several vulnerabilities published yesterday, all of them ranked high-severity support.broadcom.com/web/ecx/s

Cisco has a new advisory for a critical vulnerability that was published yesterday:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

This addresses a vulnerability that was first published on July 29:

High: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity

##

AAKL@infosec.exchange at 2026-08-05T15:17:35.000Z ##

Broadcom has addressed several vulnerabilities published yesterday, all of them ranked high-severity support.broadcom.com/web/ecx/s #Broadcom

Cisco has a new advisory for a critical vulnerability that was published yesterday:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

This addresses a vulnerability that was first published on July 29:

High: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-53264
(7.8 HIGH)

EPSS: 0.21%

updated 2026-07-29T21:30:47

1 posts

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: use RCU with deferred freeing for action lifecycle When NEWTFILTER and DELFILTER are run concurrently it is possible to create a race with an associated action. Let's illustrate with CPU0 running NEWTFILTER and CPU1 running DELFILTER: 0: mutex_lock() <-- holds the idr lock 0: rcu_read_lock() 0: p = idr_f

1 repos

https://github.com/HORKimhab/CVE-2026-53264

DailyCyberSecurity@infosec.exchange at 2026-08-04T13:03:09.000Z ##

A Linux kernel vulnerability, CVE-2026-53264, lets a local user run arbitrary code via a net/sched use-after-free. A public PoC is now available.

#CVE202653264 #LinuxKernel #UseAfterFree #PrivilegeEscalation #InfoSec

securityonline.info/linux-kern

##

CVE-2026-67192
(8.1 HIGH)

EPSS: 0.62%

updated 2026-07-29T18:31:46

1 posts

Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets when a GCM cipher is negotiated. Attackers can craft packets with an unvalidated length field passed directly to the GCM decrypt function, overwriting the stack cookie and return address to potentially achiev

CVE-2026-16655
(7.2 HIGH)

EPSS: 0.30%

updated 2026-07-29T12:31:30

1 posts

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that

wpguyuk@infosec.exchange at 2026-08-03T07:04:35.000Z ##

Fluent Forms CVE-2026-16655 scores 7.2 on the CVSS scale — High severity — and allows data manipulation or extraction without admin credentials. If my sites were running Fluent Forms below 6.2.8, updating would be my immediate priority. Check your version now and update to 6.2.8.

#WordPress #WordPressSecurity #FluentForms #CVE #WebSecurity

wpguy.uk/blog/high-vulnerabili

##

CVE-2026-16498
(10.0 CRITICAL)

EPSS: 0.33%

updated 2026-07-28T21:31:39

2 posts

The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. This vulnerability, CVE-2026-16498, is fixed in terraform-mcp-server 1.1.0.

Analyst207@mastodon.social at 2026-08-05T15:34:46.000Z ##

Veeam, HashiCorp, Django Patch Flaws

A critical security flaw, CVE-2026-16498, with a perfect CVSS score of 10.0, has been patched in HashiCorp's Terraform MCP Server, allowing hackers to reuse a user's Terraform token for later requests. This bug, now fixed in version 1.1.0, has also prompted patches from Veeam and Django.

osintsights.com/veeam-hashicor

#TerraformSecurityFlaws #Hashicorp #Veeam #Django #Geodjango

##

DailyCyberSecurity@infosec.exchange at 2026-08-04T14:12:49.000Z ##

Terraform MCP Server Flaw CVE-2026-16498 Scores CVSS 10.0

securityonline.info/terraform-

##

CVE-2026-16462
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-07-28T12:31:27

1 posts

In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.

DailyCyberSecurity@infosec.exchange at 2026-08-03T01:03:11.000Z ##

CVE-2026-16462 is a critical SQL injection in Weidmueller PROCON-WEB SCADA, rated CVSS 9.8. An unauthenticated attacker can run SQL commands. Patch now.

#PROCONWEB #Weidmueller #CVE202616462 #SQLInjection #SCADA #CyberSecurity

securityonline.info/procon-web

##

CVE-2026-11841
(9.4 CRITICAL)

EPSS: 0.46%

updated 2026-07-28T12:31:20

1 posts

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify applic

DailyCyberSecurity@infosec.exchange at 2026-08-03T13:45:45.000Z ##

CVE-2026-11841 lets an unauthenticated attacker reach internal files on SICK InspectorP6xx devices, risking device compromise. CVSS 9.4. Update to 5.4.0.

#SICK #InspectorP6xx #CVE202611841 #OTSecurity #ICS #CyberSecurity

securityonline.info/sick-inspe

##

CVE-2026-45112
(7.5 HIGH)

EPSS: 1.94%

updated 2026-07-27T21:32:25

1 posts

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-17192
(8.5 HIGH)

EPSS: 2.34%

updated 2026-07-27T18:31:56

1 posts

A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer net

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-12495(CVSS UNKNOWN)

EPSS: 0.16%

updated 2026-07-27T12:32:01

1 posts

Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration se

certvde@infosec.exchange at 2026-08-04T07:02:03.000Z ##

#OT #Advisory VDE-2026-072
Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI

The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.
#CVE CVE-2026-43284, CVE-2026-46300, CVE-2026-31431

certvde.com/en/advisories/vde-

#CSAF pilz.csaf-tp.certvde.com/.well

##

CVE-2026-50522
(9.8 CRITICAL)

EPSS: 75.76%

updated 2026-07-22T21:31:51

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

5 repos

https://github.com/webshellseo8/CVE-2026-50522-Proof-of-Concept

https://github.com/4minx/CVE-2026-50522

https://github.com/ChPratik/CVE-2026-50522

https://github.com/HORKimhab/CVE-2026-50522

https://github.com/darses/CVE-2026-50522

thecybermind@infosec.exchange at 2026-08-03T17:27:38.000Z ##

(CISA TS-SOC) CVE-2026-50522 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Severity: CRITICAL Impact Summary: An unauthorized attacker could exploit a deserialization vulnerability in Microsoft SharePoint to execute arbitrary code over a network....

thecybermind.co/2026/08/03/cis

##

CVE-2026-10702
(4.3 MEDIUM)

EPSS: 0.72%

updated 2026-07-22T19:10:00.120000

1 posts

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.

2 repos

https://github.com/HORKimhab/CVE-2026-10702

https://github.com/raihants/cve-2026-10702

hackmag@infosec.exchange at 2026-08-03T09:30:17.000Z ##

⚪️ A Single Visit to a Malicious Page Could Compromise Tor Browser

🗨️ Researchers at Nebula Security have disclosed details of CVE-2026-10702, a vulnerability in Firefox’s JIT compiler. To carry out an attack, it was enough for a victim to open a specially crafted page; no settings changes, clicks, or other actions were…

🔗 hackmag.com/news/cve-2026-1070

#news

##

CVE-2026-50343
(7.8 HIGH)

EPSS: 3.50%

updated 2026-07-22T16:17:42.747000

1 posts

Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

1 repos

https://github.com/Rat5ak/CVE-2026-50343-InstallService-EoP

DailyCyberSecurity@infosec.exchange at 2026-08-04T13:03:56.000Z ##

Details and proof-of-concept exploit code for CVE-2026-50343 are now public. The Windows privilege escalation flaw hands standard users SYSTEM privileges.

#CVE202650343 #Windows #PrivilegeEscalation #LPE #InfoSec

securityonline.info/cve-2026-5

##

tugatech@masto.pt at 2026-08-03T16:30:24.000Z ##

A Microsoft acaba de corrigir a falha Certighost, que permitia a um utilizador com acessos básicos manipular o sistema de cadastro e obter um certificado válido em nome de um Controlador de Domínio, assumindo a gestão absoluta de uma rede Windows. A falha, classificada como de gravidade alta, foi corrigida com a CVE-2026-54121. 🛡️

🔗 tugatech.com.pt/t88505-microso

#controlo #falha #microsoft 

##

CVE-2026-42533
(8.1 HIGH)

EPSS: 3.60%

updated 2026-07-15T15:33:14

1 posts

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyon

9 repos

https://github.com/ChPratik/NGINX_2026_CVE_Bundle_CTI_Report

https://github.com/Daniyal48/ghostlock-vagrant-box

https://github.com/gagaltotal/CVE-2026-42533-nginx

https://github.com/srkyn/nginx-map-risk-audit

https://github.com/jelasin/CVE-2026-42533

https://github.com/imbas007/CVE-2026-42533

https://github.com/suominen/CVE-2026-42533

https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner

https://github.com/seguridadentrerios/CVE-2026-42533

rolle@mementomori.social at 2026-08-02T20:52:27.000Z ##

Here's my five-week holiday, June 27 - August 2. This is the evidence trail of a man who does not know how to stop.

Running (11 runs, ~131 km):
- Jun 27: 12 km
- Jun 29: 6.5 km easy
- Jul 1: 8.37 km Mile Repeats treadmill
- Jul 4: 15.14 km trail long run
- Jul 6: 5.33 km easy hill run in drizzle
- Jul 11: 10.33 km long run in +30°C heat
- Jul 17: 6.26 km Zwift Hill Repeats
- Jul 18: 21.90 km half marathon
- Jul 21: 6.01 km Tempo 2-1 outdoors
- Jul 23: 5.05 km Current Pace Calibration 5K
- Jul 25: 25.03 km "Lost in the Swamp" 25K trail, 397m elevation
- Jul 27: 5.04 km Zwift Lutece Express, Paris
- Jul 28: 6.16 km Zwift On Off Ks
- Jul 30: 5.04 km 5x1km intervals
- Aug 1: 26.41 km 26K trail adventure, 415m elevation, 211 min

Health setbacks:
- Jun 27: 9/10 migraine at 23:55
- Jul 18: 9/10 migraine
- Jul 19: terrible postdrome
- Jun 28: postdrome day

Linux desktop deep dive (the real holiday project):
- Switched compositor from Hyprland to driftwm (infinite canvas + DMS shell)
- Built the "quantum realm" living wallpaper - transparent evolving fbm fog/stream/void over a NASA starmap
- Fixed driftwm animated blur GPU overheating (PR #220), stale pointer constraint, VRR support
- Submitted PRs for driftwm blur mask caching (#185) and animate_fps background cap (#184)
- Tried and rejected niri (tile columns kill floating workflow I'm fond of)
- Tried and abandoned Nourish/Y5 Dev session (no XWayland, launcher friction)
- Wrote a full compositor alternatives comparison doc

RAM saga:
- Diagnosed OW2 FPS collapse on Arch: 30 GB demand vs 16 GB RAM, swap full issue
- Survived earlyoom killing the compositor under a ~21 GB DMS shell leak, since fixed
- Ordered Corsair LPX 2x16 GB DDR4-3200, installed to 48 GB total
- Fixed accidentally forgotten MemoryHigh=3G shell cap that had throttled 1.3M times and forced 10 GB into swap

Gaming:
- Started Red Dead Redemption 2 (Jul 4)
- Overwatch 2: fixed dead-zone click bug, recovered corrupted update (75 GB repair), played several comps
- Played RV There Yet? with my son, laughed our assess off (Jul 22)
- Deeper gaming and compatibility optimizations on Linux

Mementomori ry association:
- Filed Mementomori ry association application to PRH - registered Jul 7
- Applied for bank account, handled phone calls, paperwork, meeting minutes
- Set up emails
- Rewrote mementomori.social terms of service
- Decided membership fees, signed board minutes
- Built sophisticated signup-report-monitor (Mastodon to Matrix forwarder)
- Built members.mementomori.social MVP
- Mementods Mastodon fork upgrades from upstream to v4.7.0-alpha.1 and alpha.2

Open source contributions:
- Halloy IRC client: timestamp position PR (#2206), blank space fix PR (#2221), ISO-8859-1 decode PR (#2254)
- Sidra music player: Last.fm scrobbling PR (#145)
- DMS plugin registry: CPU, Disk, I/O monitors submitted
- Released dms-cpu-monitor, dms-disk-monitor, dms-ram-monitor, dms-vram-monitor, dms-gpu-monitor (all from 1.0.0 through multiple releases)
- Released lc (linux-cleaner) among other side projects

Server / infra:
- 2 server maintenance windows
- Upgraded 31 servers in total
- One dist-upgrade from Ubuntu server 20.04 through 22.04 to 24.04 LTS
- Built another personal dedicated server for side projects, migrated some services to it from other servers
- Fixed some StorageBox issues, shipped open source tool backup-to-storagebox v3.0.0
- Fixed minor DNS/Redis issues on multiple servers
- Addressed nginx CVE-2026-42533
- Fixed some failing certs, stale mounts, CIFS hangs due incident calls

Customer client work (yes, on holiday, I'm an entrepreneur):
- ~25 tickets handled
- Fixed issues for 14 sites
- Sent 2 quotes
- Handled 5 job applications
- Fixed one unauthenticated nonce type confusion vulnerability
- Fixed one caching issue

Personal infra / tools:
- Built and iterated dough (open source personal budgeting app): releases 3.3.0 through 3.16.0
- Built dough-mcp (releases 0.2.0 through 0.3.0)
- Nanoclaw (Son of Anton) fork releases 1.19.0 through 1.30.0 (12 releases)
- Personal day planner tool releases 1.22.0 through 1.24.0
- Dotfiles releases 2.10.7 through 2.42.2 (relentless)
- Rewrote completelty our home weather system c.rolle.wtf with precipitation and better forecast
- Set up quick tool based on ff2mpv + mpv for instant adless YouTube playback
- Ungoogled-chromium optimization pass with NVDEC hardware decode
- Fixed home WiFi dropouts (5 GHz DFS, channel splitting, RSSI deauth) with Ubiquity router
- Tested alternative browsers: Thorium, Zen, Brave Origin Nightly, Orion
- Tried dozens of new alternative AI models
- Released lc 0.1.0, omnishuffle 1.3.1, lastfm-recommendations 2.1.0
- Released Luku for iOS 1.2.3
- Fixed some technical challenges long overdue

Finance / admin:
- Paid taxes
- Paid bills
- Categorized and flagged hundreds of transactions
- Daily dough reconciliations
- Company finance review
- Updated company finance sheets

Family:
- 18th anniversary with my wife (Jul 2) - pizza and movie at home
- Weekly café dates with my wife (Jul 5, 12, 19, 26)
- Sushi lunch with my wife (Jul 1)
- Coffee with a friend (Jul 10, sat down for 4 hours)
- Family lunch (Jul 31)
- Trip to mom's place for a few days with kids, strawberries, pancakes, summer days (Jul 13)

Other:
- Migrated off Google Photos to PixelUnion, cancelled Google One
- Wrote a blog post about the Google Photos migration
- Completed CRM migration off Pipedrive (yes, work stuff but a fun one)
- Completed GitBook to Outline tech doc migration (also fun work stuff)

Zero actual rest days that contained zero commits. Oops.

This is everything I have documented.

Tomorrow, I get to rest at the office 😂

##

CVE-2026-15409
(10.0 CRITICAL)

EPSS: 78.44%

updated 2026-07-14T21:32:22

2 posts

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

Nuclei template

6 repos

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

https://github.com/remmons-r7/rapid7-CVE-2026-15409

https://github.com/HORKimhab/CVE-2026-15409

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

https://github.com/0xBlackash/CVE-2026-15409

https://github.com/Ch4120N/CVE-2026-15409

kev_Stalker@infosec.exchange at 2026-08-04T02:35:33.000Z ##

CVE-2026-15409 - Changed to Known Ransomware Status

SonicWall SMA1000 Appliances Server-Side Request Forgery VulnerabilityVendor: SonicWallProduct: SMA1000 AppliancesSonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.Status changed from Unknown to Known for ransomware campaign usage.Flip nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-08-03T02:29:59.000Z ##

A SonicWall SMA exploit chain (CVE-2026-15409, CVE-2026-15410) grants root access and now feeds INC Ransomware attacks. Patch to 12.5.0-02835+.

#SonicWall #INCRansomware #CVE202615409 #VPNSecurity #CyberSecurity #UTA0533

securityonline.info/sonicwall-

##

CVE-2026-15410
(7.2 HIGH)

EPSS: 76.35%

updated 2026-07-14T21:32:21

2 posts

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

3 repos

https://github.com/HORKimhab/CVE-2026-15410

https://github.com/tc4dy/CVE-2026-15409-15410-Framework

https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

kev_Stalker@infosec.exchange at 2026-08-04T02:40:18.000Z ##

CVE-2026-15410 - Changed to Known Ransomware Status

SonicWall SMA1000 Appliances Code Injection VulnerabilityVendor: SonicWallProduct: SMA1000 AppliancesSonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: nvd.nist.gov/vuln/detail/CVE-2

##

DailyCyberSecurity@infosec.exchange at 2026-08-03T02:29:59.000Z ##

A SonicWall SMA exploit chain (CVE-2026-15409, CVE-2026-15410) grants root access and now feeds INC Ransomware attacks. Patch to 12.5.0-02835+.

#SonicWall #INCRansomware #CVE202615409 #VPNSecurity #CyberSecurity #UTA0533

securityonline.info/sonicwall-

##

CVE-2026-31431
(7.8 HIGH)

EPSS: 94.55%

updated 2026-07-14T15:32:55

1 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just

Nuclei template

100 repos

https://github.com/Juguitos/copy-fail

https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail

https://github.com/kadir/copy-fail-CVE-2026-31431-IOC

https://github.com/wgnet/wg.copyfail.patch

https://github.com/Xerxes-2/CVE-2026-31431-rs

https://github.com/Iamliuxiaozhen/copy_fail

https://github.com/tgies/copy-fail-c

https://github.com/JnamerZ/CopyFail-CVE-2026-31431

https://github.com/mrunalp/block-copyfail

https://github.com/ExploitEoom/CVE-2026-31431

https://github.com/ncmprbll/copy-fail-rs

https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431

https://github.com/sgkdev/page_inject

https://github.com/bigwario/copy-fail-CVE-2026-31431-C

https://github.com/malwarekid/CVE-2026-31431

https://github.com/Alfredooe/CVE-2026-31431

https://github.com/lonelyor/CVE-2026-31431-exp

https://github.com/H1d3r/copy-fail_LPE_Interactive

https://github.com/SeanRickerd/cve-2026-31431

https://github.com/xeloxa/copyfail-exploit

https://github.com/professional-slacker/alg_check

https://github.com/insomnisec/Detections-CVE-2026-31431

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC

https://github.com/theori-io/copy-fail-CVE-2026-31431

https://github.com/cs8425/copy-fail-go

https://github.com/b5null/CVE-2026-31431-C

https://github.com/jbnetwork-git/copy-fail-check

https://github.com/philfry/cve-2026-31431-ftrace

https://github.com/novysodope/copy-fail-CVE-2026-31431-C

https://github.com/aestechno/cve-2026-31431-ansible

https://github.com/MrAriaNet/cPanel-Fix

https://github.com/desultory/CVE-2026-31431

https://github.com/sgkdev/ptrace_may_dream

https://github.com/wuwu001/CVE-2026-31431-exploit

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431

https://github.com/Smarttfoxx/copyfail

https://github.com/sammwyy/copyfail-rs

https://github.com/povzayd/CVE-2026-31431

https://github.com/1neptune/CopyFail

https://github.com/yuspring/cve-2026-31431-poc

https://github.com/0xBlackash/CVE-2026-31431

https://github.com/AdityaBhatt3010/CVE-2026-31431

https://github.com/rvzsec/CVE-2026-31431

https://github.com/0xShe/CVE-2026-31431

https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs

https://github.com/4xura/CVE-2026-31431-Copy-Fail

https://github.com/TheMalwareGuardian/CVE-2026-31431

https://github.com/wesmar/CVE-2026-31431

https://github.com/rootsecdev/cve_2026_31431

https://github.com/badsectorlabs/copyfail-go

https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script

https://github.com/ben-slates/CVE-2026-31431-Exploit

https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431

https://github.com/cozystack/copy-fail-blocker

https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized

https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit

https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

https://github.com/qi4L/CVE-2026-31431-Container-Escape

https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431

https://github.com/diemoeve/copyfail-rs

https://github.com/Huchangzhi/autorootlinux

https://github.com/erlangparasu/mitigate_cve_2026_31431-sh

https://github.com/cyber-joker/copy-fail-python

https://github.com/kvakirsanov/CVE-2026-31431-live-process-code-injection

https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE

https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite

https://github.com/pedromizz/copy-fail

https://github.com/Boos4721/copyfail-rs

https://github.com/sec17br/CVE-2026-31431-Copy-Fail

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/AliHzSec/CVE-2026-31431

https://github.com/bootsareme/copyfail-deconstructed

https://github.com/luotian2/CVE-2026-31431

https://github.com/pascal-gujer/CVE-2026-31431

https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail

https://github.com/Sl4cK0TH/CVE-2026-31431-PoC

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/atgreen/block-copyfail

https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4

https://github.com/Dabbleam/CVE-2026-31431-mitigation

https://github.com/XsanFlip/CVE-2026-31431-Patch

https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit

https://github.com/yxdm02/CVE-2026-31431

https://github.com/guiimoraes/CVE-2026-31431

https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

https://github.com/JuanBindez/CVE-2026-31431

https://github.com/samanzamani/copy-fail-checker

https://github.com/st4rburn/public-passwd

https://github.com/MartinPham/copy-fail-CVE-2026-31431-php

https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit

https://github.com/ZephrFish/CopyFail-CVE-2026-31431

https://github.com/ErdemOzgen/copy-fail-cve-2026-31431

https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell

https://github.com/abdullaabdullazade/CVE-2026-31431

https://github.com/kinryulabs/rootpacket-cve-2026-31431

https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation

https://github.com/haydenjames/CVE-2026-31431-check

https://github.com/adysec/cve-2026-31431

certvde@infosec.exchange at 2026-08-04T07:02:03.000Z ##

#OT #Advisory VDE-2026-072
Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI

The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.
#CVE CVE-2026-43284, CVE-2026-46300, CVE-2026-31431

certvde.com/en/advisories/vde-

#CSAF pilz.csaf-tp.certvde.com/.well

##

CVE-2026-43284
(7.8 HIGH)

EPSS: 93.23%

updated 2026-07-14T15:31:59

1 posts

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when

44 repos

https://github.com/armircetaj/tetragon-dirtyfrag

https://github.com/DylanClaudio/Reporte-de-Escalada-de-Privilegios-Local-Dirty-Frag

https://github.com/metalx1993/dirtyfrag-patches

https://github.com/MadExploits/CVE-2026-46300

https://github.com/ryan2929/CVE-2026-43284-

https://github.com/XRSecCD/202605_dirty_frag

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/0xlane/pagecache-guard

https://github.com/nonameuserosint-hue/DirtyFrag-go

https://github.com/AK777177/Dirty-Frag-Analysis

https://github.com/scriptzteam/Paranoid-Dirty-Frag-CVE-2026-43284

https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC

https://github.com/cumakurt/linuxpi

https://github.com/nabhan-mohy/Dirty-Frag-Research-CVE-2026-43284-

https://github.com/AtlasVector/Dirty-Frag-CVE-2026-43284

https://github.com/liamromanis101/DirtyFrag-Detector

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/1neptune/DirtyFrag

https://github.com/suominen/CVE-2026-43284

https://github.com/mym0us3r/DIRTY-FRAG-Detection-with-Wazuh-4.14.4

https://github.com/LucasPDiniz/CVE-2026-43284

https://github.com/First-John/cve_2026_frag_family_fix

https://github.com/t1ckprivate/CVE-2026-43284-Dirty-Frag

https://github.com/attaattaatta/CVE-2026-43500

https://github.com/linnemanlabs/dirtyfrag-arm64

https://github.com/krisiasty/vcheck

https://github.com/kuniyal08/Dirty-Frag-CVE-2026-43284

https://github.com/haydenjames/dirty-frag-check

https://github.com/dixyes/dirtypatch

https://github.com/grabesec/XCP_ng_CVE-2026-43284_tester

https://github.com/aettern/copyfrag-fuse

https://github.com/RevyHub/CVE-2026-43284---DirtyFrag-Analysis-THM-

https://github.com/gagaltotal/CVE-2026-43284-CVE-2026-43500-scan

https://github.com/6abc/Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284

https://github.com/ChernStepanov/DirtyFrag-for-dummies

https://github.com/Aiyakami/rust_dirtyfrag

https://github.com/millikanjohnl-blip/dirtyfrag-detection-rules

https://github.com/jayhutajulu1/CVE-2026-43284-DirtyFrag-PoC

https://github.com/xd20111/CVE-2026-43284

https://github.com/lukeslp/redtail-ioc

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/g0thamRabb1t/CVE-2026-43284-dirtyfrag-detection

https://github.com/FrosterDL/CVE-2026-43284

https://github.com/0xBlackash/CVE-2026-43284

certvde@infosec.exchange at 2026-08-04T07:02:03.000Z ##

#OT #Advisory VDE-2026-072
Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI

The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.
#CVE CVE-2026-43284, CVE-2026-46300, CVE-2026-31431

certvde.com/en/advisories/vde-

#CSAF pilz.csaf-tp.certvde.com/.well

##

CVE-2025-26399
(9.8 CRITICAL)

EPSS: 88.33%

updated 2026-06-17T09:01:42.407000

1 posts

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.

1 repos

https://github.com/rxerium/CVE-2025-26399

kev_Stalker@infosec.exchange at 2026-08-05T02:59:14.000Z ##

CVE-2025-26399 - Changed to Known Ransomware Status

SolarWinds Web Help Desk Deserialization of Untrusted Data VulnerabilityVendor: SolarWindsProduct: Web Help DeskSolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 04, 2026 at 18:08:17 UTCDate nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2023-32233
(7.8 HIGH)

EPSS: 12.97%

updated 2026-06-17T05:58:22.273000

1 posts

In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.

7 repos

https://github.com/void0red/CVE-2023-32233

https://github.com/Liuk3r/CVE-2023-32233

https://github.com/oferchen/POC-CVE-2023-32233

https://github.com/Destawell/gemini-2.5-pro-nf-tables-red-teamin

https://github.com/PIDAN-HEIDASHUAI/CVE-2023-32233

https://github.com/RogelioPumajulca/TEST-CVE-2023-32233

https://github.com/Destawell/gemini-2.5-pro-nf-tables-red-teaming

nyanbinary@infosec.exchange at 2026-08-03T18:39:18.000Z ##

Ok, the first one is absolutely it:

Furthermore, we deploy MLG-UAF to conduct large-scale security auditing on mainstream open-source software such as libtiff, LibRaw, SQLite, ImageMagick and Zephyr RTOS. In real-world industrial source code scanning, our framework successfully discovered 17 unique confirmed UAF vulnerabilities assigned with independent Common Vulnerabilities and Exposures (CVE) IDs (CVE-2026 series, RESERVED and not yet publicized), covering cross-functional kernel UAF, intra-procedural cache UAF, race-condition UAF and multimedia parsing UAF scenarios.Real CVE case studies on CVE-2026-51291 (SQLite JSON cache flaw) and CVE-2023-32233 (Linux netfilter kernel vulnerability) demonstrate that MLG-UAF can precisely capture the fixed free-then-use spatial topological fingerprint of UAF defects and accurately resolve ambiguous multi-level pointer aliasing, even under heavy control-flow obfuscation.

##

CVE-2026-48030
(9.9 CRITICAL)

EPSS: 1.54%

updated 2026-06-09T22:00:36

1 posts

### Summary An OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS commands by injecting shell metacharacters into the 'dir' POST parameter, completely bypassing the TERMINAL_COMMANDS whitelist and achieving full Remote Code Execution with web server privileges. ### Details The terminal handler in pheditor.php accepts two POST

1 repos

https://github.com/muslimbek-0x/CVE-2026-48030

secdb@infosec.exchange at 2026-08-03T00:04:00.000Z ##

📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at secdb.nttzen.cloud/dashboard

Total CVEs:

Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294

Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510

CISA KEVs:
- CISA-2026:0727 (secdb.nttzen.cloud/security-ad)
- CISA-2026:0729 (secdb.nttzen.cloud/security-ad)

Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68

Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19

Top EPSS Score:
- CVE-2026-17191 - 2.83 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-38709 - 2.67 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-17192 - 2.34 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-45112 - 1.94 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-66066 - 1.70 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5492 - 1.60 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-48030 - 1.55 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5491 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-5487 - 1.54 % (secdb.nttzen.cloud/cve/detail/)
- CVE-2026-63362 - 1.53 % (secdb.nttzen.cloud/cve/detail/)

#ZEN #SecDB #InfoSec

##

CVE-2026-34486
(7.5 HIGH)

EPSS: 81.16%

updated 2026-06-08T23:28:56

3 posts

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

Nuclei template

6 repos

https://github.com/anonmrc/CVE-2026-34486-e-Tomcat-Tribes

https://github.com/razureink/cve-2026-34486-tomcat_encrypt_bypass_reproduction

https://github.com/404-src/CVE-2026-34486

https://github.com/AirSkye/CVE-2026-34486-poc

https://github.com/punitdarji/tomcat-cve-2026-34486

https://github.com/striga-ai/CVE-2026-34486

thecybermind@infosec.exchange at 2026-08-05T11:47:47.000Z ##

🚨 CISA KEV ALERT: CVE-2026-34486 exposes Apache Tomcat installations to EncryptInterceptor bypasses and data interception. Active exploitation confirmed. Get the forensic breakdown, Splunk/KQL/Chronicle detection queries, and hardening steps: thecybermind.co/it1p

Top-of-the-Line LinkedIn Post

##

secdb@infosec.exchange at 2026-08-04T19:00:11.000Z ##

🚨 [CISA-2026:0804] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-18556 (secdb.nttzen.cloud/cve/detail/)
- Name: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: N-able
- Product: N-central
- Notes: uptime.n-able.com/ ; status.n-able.com/2026/08/02/n ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-34486 (secdb.nttzen.cloud/cve/detail/)
- Name: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Tomcat
- Notes: lists.apache.org/thread/9510k5 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-9198 (secdb.nttzen.cloud/cve/detail/)
- Name: IBM Langflow Code Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: IBM
- Product: Langflow
- Notes: ibm.com/support/pages/node/727 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260804 #cisa20260804 #cve_2026_18556 #cve_2026_34486 #cve_2026_9198 #cve202618556 #cve202634486 #cve20269198

##

cisakevtracker@mastodon.social at 2026-08-04T18:01:07.000Z ##

CVE ID: CVE-2026-34486
Vendor: Apache
Product: Tomcat
Date Added: 2026-08-04
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-42897
(8.1 HIGH)

EPSS: 70.31%

updated 2026-05-15T18:30:32

2 posts

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

1 repos

https://github.com/atiilla/CVE-2026-42897

oversecurity@mastodon.social at 2026-08-03T17:59:54.000Z ##

Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati

Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...

🔗️ [Cybersecurity360] link.is.it/ssYZlG

##

oversecurity@mastodon.social at 2026-08-03T17:59:52.000Z ##

Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati

Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...

🔗️ [Cybersecurity360] link.is.it/ssYZlG

##

CVE-2026-20079
(10.0 CRITICAL)

EPSS: 37.67%

updated 2026-03-04T18:32:03

2 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerab

Nuclei template

1 repos

https://github.com/0xBlackash/CVE-2026-20079

AAKL at 2026-08-05T15:17:35.586Z ##

Broadcom has addressed several vulnerabilities published yesterday, all of them ranked high-severity support.broadcom.com/web/ecx/s

Cisco has a new advisory for a critical vulnerability that was published yesterday:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

This addresses a vulnerability that was first published on July 29:

High: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity

##

AAKL@infosec.exchange at 2026-08-05T15:17:35.000Z ##

Broadcom has addressed several vulnerabilities published yesterday, all of them ranked high-severity support.broadcom.com/web/ecx/s #Broadcom

Cisco has a new advisory for a critical vulnerability that was published yesterday:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

This addresses a vulnerability that was first published on July 29:

High: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #infosec #vulnerability

##

CVE-2026-1070
(4.3 MEDIUM)

EPSS: 0.16%

updated 2026-01-24T09:30:33

1 posts

The Alex User Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0. This is due to missing nonce validation on the alex_user_counter_function() function. This makes it possible for unauthenticated attackers to update the plugin settings via a forged request granted they can trick a site administrator into performing an action such as cl

2 repos

https://github.com/HORKimhab/CVE-2026-10702

https://github.com/raihants/cve-2026-10702

hackmag@infosec.exchange at 2026-08-03T09:30:17.000Z ##

⚪️ A Single Visit to a Malicious Page Could Compromise Tor Browser

🗨️ Researchers at Nebula Security have disclosed details of CVE-2026-10702, a vulnerability in Firefox’s JIT compiler. To carry out an attack, it was enough for a victim to open a specially crafted page; no settings changes, clicks, or other actions were…

🔗 hackmag.com/news/cve-2026-1070

#news

##

CVE-2013-4786
(7.5 HIGH)

EPSS: 78.57%

updated 2025-04-11T04:12:49

2 posts

The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.

1 repos

https://github.com/fin3ss3g0d/CosmicRakp

threatnoir@infosec.exchange at 2026-08-04T10:06:06.000Z ##

⚠️ CRITICAL: Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

CVE-2013-4786 in IPMI 2.0 allows unauthenticated attackers to harvest password hashes from Baseboard Management Controllers via UDP 623, then crack them offline. Over 24,000 internet-exposed BMCs are vulnerable, and many run weak or predictable default credentials. Compromised BMCs give attackers d…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

DailyCyberSecurity@infosec.exchange at 2026-08-03T15:01:55.000Z ##

LAVA found 36,872 exposed BMCs leaking IPMI password hashes via CVE-2013-4786. Some are already exploited in the wild. Here is how to lock them down.

#BMC #IPMI #CVE20134786 #DataCenter #Supermicro #CyberSecurity

securityonline.info/exposed-bm

##

CVE-2026-44945
(0 None)

EPSS: 0.74%

1 posts

N/A

offseq@infosec.exchange at 2026-08-05T10:30:25.000Z ##

SUSE Rancher CVE-2026-44945 (CRITICAL, CVSS 9.1): Privilege escalation flaw lets authenticated users with default global role gain full admin on Rancher & clusters. Restrict access & monitor pending patch. radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE202644945 #Kubernetes

##

hackmag@infosec.exchange at 2026-08-04T22:00:07.000Z ##

⚪️ OpenWrt Fixes Critical Vulnerability in DHCPv6 Server

🗨️ OpenWrt developers have released updates that fix a critical vulnerability in the DHCPv6 server. The flaw allowed an unauthenticated attacker to execute arbitrary code with root privileges and potentially fully compromise a vulnerable router. The issue, tracked as CVE-2026-53921 (CVSS…

🔗 hackmag.com/news/openwrt-patch

#news

##

CVE-2026-59726
(0 None)

EPSS: 0.48%

2 posts

N/A

1 repos

https://github.com/HORKimhab/CVE-2026-59726

DailyCyberSecurity@infosec.exchange at 2026-08-04T12:32:47.000Z ##

RufRoot CVE-2026-59726: Unauthenticated RCE in Ruflo MCP Bridge Exposes AI Agent Keys

meterpreter.org/rufroot-cve-20

##

security_crawler_carl@infosec.exchange at 2026-08-04T07:04:17.000Z ##

🏆 New Achievement! RufRoot Has Entered The Arena!

PHASE ONE BEGINS. The challenger: CVE-2026-59726, alias RufRoot, a CVSS 10.0 critical flaw in the open-source AI agent platform Ruflo. Its special move — exploiting an exposed Model Context Protocol bridge to hand unauthenticated attackers full control of enterprise AI environments. No credentials required. No mercy shown. Noma Security surfaced this beast hiding in every Ruflo version before 3.16.3.

This is not a warm-up encounter. (1/2)

##

CVE-2026-59774
(0 None)

EPSS: 0.00%

1 posts

N/A

offseq@infosec.exchange at 2026-08-03T00:00:37.000Z ##

CRITICAL: PyAthena <3.35.4 is vulnerable to SQL injection (CVE-2026-65321). Improper escaping allows unauthenticated attackers to inject SQL, risking data loss/exfiltration. Patch status unconfirmed — restrict DELETE/CTAS use. radar.offseq.com/threat/cve-20 #OffSeq #CVE202665321 #PyAthena

##

thehackerwire@mastodon.social at 2026-08-02T16:00:01.000Z ##

🔴 CVE-2026-65321 - Critical (9.8)

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56670
(0 None)

EPSS: 0.22%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-02T19:59:58.000Z ##

🟠 CVE-2026-56670 - High (8.2)

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56671
(0 None)

EPSS: 0.66%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-02T19:59:49.000Z ##

🟠 CVE-2026-56671 - High (7.5)

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py joins an unrestricted filename route capture to a selected model directory without a containment che...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56672
(0 None)

EPSS: 0.24%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-02T18:59:58.000Z ##

🟠 CVE-2026-56672 - High (8.2)

ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and acc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63222
(0 None)

EPSS: 0.45%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-02T18:59:49.000Z ##

🟠 CVE-2026-63222 - High (7.5)

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63221
(0 None)

EPSS: 0.38%

1 posts

N/A

thehackerwire@mastodon.social at 2026-08-02T18:00:08.000Z ##

🔴 CVE-2026-63221 - Critical (9.4)

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49413
(0 None)

EPSS: 0.15%

1 posts

N/A

1 repos

https://github.com/ii4gsp/CVE-2026-49413

Visit counter For Websites