## Updated at UTC 2026-07-31T18:19:40.988374

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-65313 8.1 0.18% 2 0 2026-07-31T17:16:34.970000 A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engin
CVE-2026-68500 7.5 0.38% 1 0 2026-07-31T16:52:41 ### Impact The shop payment webhook `POST /{_locale}/update-payment` (route
CVE-2026-67594 9.8 0.46% 1 0 2026-07-31T16:17:11.793000 Spikster through commit e1cdf8c contains a missing authentication vulnerability
CVE-2026-66066 0 1.70% 12 5 2026-07-31T16:17:10.160000 Action Pack is a framework for handling and responding to web requests. In versi
CVE-2026-20316 5.3 0.79% 16 0 2026-07-31T16:17:06.087000 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-18141 8.2 0.00% 2 0 2026-07-31T16:17:05.387000 A flaw was found in aap-gateway, a component of Ansible Automation Platform's Ev
CVE-2026-18064 7.5 0.34% 1 0 2026-07-31T16:17:05.247000 An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Healt
CVE-2026-17566 9.9 0.00% 2 0 2026-07-31T16:17:00.037000 pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by in
CVE-2026-17347 7.5 0.00% 2 0 2026-07-31T16:16:59.140000 The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administr
CVE-2026-68502 9.8 0.53% 1 0 2026-07-31T15:18:01.563000 LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framew
CVE-2026-10685 7.6 0.00% 2 0 2026-07-31T15:16:27.433000 The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp()
CVE-2026-18358 7.5 0.00% 2 0 2026-07-31T13:17:19.933000 A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux.
CVE-2026-17561 9.8 0.00% 4 0 2026-07-31T13:17:19.730000 Improper Control of Generation of Code ('Code Injection') vulnerability in Innot
CVE-2026-10079 8.5 0.17% 2 0 2026-07-31T12:30:30 A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Wh
CVE-2026-15722 7.5 0.51% 2 0 2026-07-31T12:30:30 A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). Th
CVE-2026-11770 7.5 0.51% 2 0 2026-07-31T12:30:30 A flaw was found in 389 Directory Server. An unauthenticated remote attacker can
CVE-2026-66416 8.8 0.16% 1 0 2026-07-31T12:16:55.820000 Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows u
CVE-2026-63223 9.8 0.49% 5 0 2026-07-31T06:16:32.297000 CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and
CVE-2026-6102 7.8 0.09% 1 0 2026-07-31T04:17:24.730000 MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulner
CVE-2026-66803 10.0 0.49% 2 0 2026-07-31T04:17:24.520000 Improper access control in Azure Cosmos DB allows an unauthorized attacker to ex
CVE-2026-5490 8.8 0.48% 1 1 2026-07-31T04:17:24.013000 DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability a
CVE-2026-58043 7.5 0.14% 4 0 2026-07-31T04:17:23.737000 A flaw in Node.js Permission Model enforcement can over-grant filesystem access
CVE-2026-16727 0 0.09% 1 0 2026-07-31T04:16:48.200000 Concurrent Execution using Shared Resource with Improper Synchronization (“Race
CVE-2026-14973 9.3 0.45% 1 0 2026-07-31T04:16:46.710000 IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow fil
CVE-2026-13435 9.9 0.29% 1 0 2026-07-31T04:16:46.393000 IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vuln
CVE-2026-18157 7.8 0.24% 2 0 2026-07-31T03:31:17 A flaw was found in yggdrasil-worker-package-manager. A local attacker with exis
CVE-2026-12562 8.8 0.28% 1 0 2026-07-31T00:30:29 The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that
CVE-2026-65423 8.8 0.60% 2 0 2026-07-31T00:30:29 An integer overflow in the UA_Variant arrayDimensions product computation in op
CVE-2026-66421 9.3 0.36% 1 0 2026-07-31T00:30:29 OpenClaw Dashboard contains a stored cross-site scripting vulnerability that all
CVE-2026-66420 8.8 0.17% 1 0 2026-07-31T00:30:29 MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass v
CVE-2026-66360 7.5 0.28% 1 0 2026-07-31T00:30:29 The ISO Presentation layer contains a flaw in the handling of specific paramete
CVE-2026-63559 7.5 0.43% 1 0 2026-07-31T00:30:29 An integer overflow in the UA_Variant arrayDimensions product computation in op
CVE-2026-63035 8.1 0.57% 2 0 2026-07-31T00:30:22 A heap use-after-free vulnerability in the TransferSubscriptions service in ope
CVE-2026-67206 8.8 0.44% 1 0 2026-07-30T21:31:57 Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileM
CVE-2026-66415 8.5 0.28% 1 0 2026-07-30T21:31:57 Leantime 3.6.2 contains a server-side request forgery and local file inclusion v
CVE-2026-17657 8.3 0.36% 2 0 2026-07-30T21:31:32 Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a r
CVE-2026-67207 8.8 0.30% 1 0 2026-07-30T20:27:26.867000 Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in Backu
CVE-2026-67201 8.6 0.39% 1 0 2026-07-30T20:16:05.187000 V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery
CVE-2026-59952 0 0.52% 1 0 2026-07-30T20:07:01.330000 Valibot helps validate data using a schema. Versions prior to 1.4.2 can throw a
CVE-2026-12942 7.5 0.42% 1 0 2026-07-30T19:31:02.643000 IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse
CVE-2026-67432 7.5 0.44% 1 0 2026-07-30T19:30:33.710000 MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and cli
CVE-2026-61536 7.5 0.30% 1 0 2026-07-30T19:26:51.190000 Banks generates meaningful LLM prompts using a simple template language. In vers
CVE-2026-64863 9.1 0.34% 1 0 2026-07-30T19:19:45.637000 goshs is a feature-rich single-binary file server for red teamers and developers
CVE-2026-9322 7.5 0.30% 1 0 2026-07-30T19:18:37.363000 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
CVE-2026-16771 8.8 0.25% 2 0 2026-07-30T19:10:06.847000 In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to en
CVE-2026-18197 0 0.27% 1 0 2026-07-30T19:07:59.843000 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2026-55391 7.5 0.20% 1 0 2026-07-30T19:07:59.843000 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, a
CVE-2026-55389 7.5 0.36% 1 0 2026-07-30T19:07:59.843000 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, a
CVE-2026-28323 9.8 0.64% 1 0 2026-07-30T18:31:47 SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass
CVE-2026-12940 9.8 0.48% 1 0 2026-07-30T18:31:47 IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote
CVE-2026-56850 4.1 0.08% 1 0 2026-07-30T16:33:59.580000 A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key co
CVE-2026-59310 9.8 1.14% 2 0 2026-07-30T16:17:15.183000 VMware vCenter contains a directory traversal vulnerability in the Syslog server
CVE-2026-44107 7.5 0.31% 2 0 2026-07-30T16:17:12.010000 A reboot of the charging controller can be triggered via Modbus TCP without auth
CVE-2026-16610 9.8 0.58% 2 0 2026-07-30T16:16:57.050000 The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to
CVE-2026-15435 9.8 0.73% 1 0 2026-07-30T15:31:59 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.
CVE-2026-47876 9.3 0.28% 3 0 2026-07-30T15:31:54 VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual
CVE-2026-59309 9.8 0.74% 3 0 2026-07-30T15:31:54 VMware vCenter contains an authentication bypass vulnerability in the VMware Dir
CVE-2026-44099 7.8 0.23% 1 0 2026-07-30T15:16:33.177000 A privilege escalation vulnerability in the system configuration allows a low-pr
CVE-2026-44094 8.6 0.26% 1 0 2026-07-30T15:16:33.033000 An unauthenticated remote attacker can enforce the system to fall back to a firm
CVE-2026-48449 10.0 0.54% 2 0 2026-07-30T14:54:03.443000 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi
CVE-2026-67428 8.5 0.34% 1 0 2026-07-30T14:48:09 ## Summary Numerous HTTP-emitting modules (`core.api.http_get`, `core.api.http_p
CVE-2026-67429 10.0 0.49% 1 0 2026-07-30T14:46:44 ## Summary `image.download` fetches a URL and writes the response to disk. It d
CVE-2026-44101 9.8 0.40% 1 0 2026-07-30T14:31:21.447000 Due to missing authentication the CHARX OCPP Agent service allows an unauthentic
CVE-2026-44090 9.8 0.40% 1 0 2026-07-30T14:31:21.447000 Due to missing authentication, an unauthenticated remote attacker may access the
CVE-2026-44091 9.1 0.33% 1 0 2026-07-30T14:31:21.447000 An unauthenticated remote attacker can post a malicious ID to the MQTT Broker re
CVE-2026-44100 9.4 0.28% 1 0 2026-07-30T14:31:21.447000 The CHARX JupiCore service allows an unauthenticated remote attacker to reconfig
CVE-2026-44095 7.8 0.23% 1 0 2026-07-30T14:31:21.447000 A privilege escalation vulnerability in a script used for network configuration
CVE-2026-35226 6.5 0.17% 1 0 2026-07-30T14:31:21.447000 An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows a
CVE-2026-67437 7.5 0.35% 1 0 2026-07-30T14:24:55 ## Summary OliveTin's OAuth2 login handler stores per-login state in an in-memo
CVE-2026-5487 7.5 1.54% 1 0 2026-07-30T14:18:46.477000 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera
CVE-2026-14356 8.8 0.27% 1 0 2026-07-30T14:16:46.943000 The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in a
CVE-2026-18220 7.8 0.19% 1 1 2026-07-30T14:15:31.167000 An out-of-bounds write vulnerability was found in the BFD library's DLX ELF back
CVE-2026-21655 0 0.17% 1 0 2026-07-30T14:15:31.167000 Deserialization of untrusted data vulnerability in Johnson Control victor on Win
CVE-2026-18363 0 0.30% 1 0 2026-07-30T14:12:18.697000 A logic vulnerability in the password reset token validation routine implemented
CVE-2026-14529 9.4 0.33% 2 0 2026-07-30T14:08:40.373000 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
CVE-2026-14512 9.8 0.54% 1 0 2026-07-30T14:08:40.373000 IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-a
CVE-2026-65883 0 0.50% 2 1 2026-07-30T14:06:56.363000 Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Ca
CVE-2026-64560 7.8 0.12% 1 0 2026-07-30T12:32:18 In the Linux kernel, the following vulnerability has been resolved: posix-cpu-t
CVE-2026-44106 7.8 0.23% 2 0 2026-07-30T09:31:25 A privilege escalation vulnerability in the init-script for user-applications al
CVE-2026-44105 6.6 0.09% 1 0 2026-07-30T09:31:25 The credentials for the local user "user-app" may be exposed in log files, poten
CVE-2026-44108 9.8 0.46% 2 0 2026-07-30T09:31:24 Due to a flaw in the execution order of scripts during shutdown, the firewall is
CVE-2026-7849 9.8 0.42% 2 0 2026-07-30T09:31:24 Due to improper neutralization of special elements, an unauthenticated remote at
CVE-2026-44103 5.3 0.24% 1 0 2026-07-30T09:31:24 An unauthenticated remote attacker can inject malicious firmware into the intern
CVE-2026-44093 7.8 0.23% 1 0 2026-07-30T09:31:24 A local privilege escalation vulnerability in the init-script for user-applicati
CVE-2026-44102 5.3 0.21% 1 0 2026-07-30T09:31:24 An unauthenticated remote attacker can trigger a firmware update download via th
CVE-2026-44092 9.1 0.38% 1 0 2026-07-30T09:31:24 An unauthenticated remote attacker can inject malicious input into the ModbusSer
CVE-2026-44104 9.8 0.24% 1 0 2026-07-30T09:31:24 The firmware update process for the basemodule of the charging controller only v
CVE-2026-44098 8.6 1.37% 1 0 2026-07-30T09:31:18 This vulnerability allows an unauthenticated remote attacker with control over t
CVE-2026-44097 7.1 0.24% 1 0 2026-07-30T09:31:18 A low-privileged remote attacker with "operator" access can upload arbitrary fil
CVE-2026-44096 7.8 0.23% 1 0 2026-07-30T09:31:18 A privilege escalation vulnerability in udhcpc allows a local user "charx-web" t
CVE-2026-64531 7.8 0.12% 2 1 2026-07-30T06:33:35 In the Linux kernel, the following vulnerability has been resolved: net: openvs
CVE-2026-58066 9.8 0.21% 1 0 2026-07-30T06:32:44 Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7,
CVE-2026-58046 9.9 0.31% 1 0 2026-07-30T06:32:44 Improper neutralization in the Plesk XML-RPC API allows a remote authenticated l
CVE-2026-1360 7.5 0.57% 1 0 2026-07-30T06:32:43 The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untruste
CVE-2026-48448 8.6 0.37% 1 0 2026-07-30T03:31:28 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia
CVE-2026-67595 8.1 0.42% 3 0 2026-07-30T00:31:19 VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript p
CVE-2026-6267 8.5 0.34% 2 0 2026-07-29T21:31:08 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.
CVE-2026-5056 7.8 0.43% 1 0 2026-07-29T21:31:08 GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerabilit
CVE-2026-13308 8.1 0.57% 1 0 2026-07-29T21:31:08 Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Executi
CVE-2026-15975 7.5 0.39% 1 0 2026-07-29T21:31:07 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8
CVE-2026-5057 7.5 0.48% 1 0 2026-07-29T21:31:07 ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability.
CVE-2026-5491 7.5 1.54% 1 0 2026-07-29T21:31:07 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera
CVE-2026-61511 9.8 1.27% 3 6 2026-07-29T20:17:10.347000 vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vul
CVE-2026-20079 10.0 37.67% 5 1 template 2026-07-29T17:16:51.683000 A vulnerability in the web interface of Cisco Secure Firewall Management Center
CVE-2026-67215 7.5 0.35% 1 0 2026-07-29T15:31:12 cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack ex
CVE-2026-0667 None 0.37% 1 0 2026-07-29T15:31:11 CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that
CVE-2026-45293 8.6 0.18% 1 0 2026-07-29T14:16:30.737000 WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enfor
CVE-2026-14270 8.8 0.55% 1 0 2026-07-29T12:31:30 The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCom
CVE-2026-18072 9.8 0.59% 2 0 2026-07-29T06:32:11 The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick
CVE-2026-12144 8.8 0.37% 1 0 2026-07-29T03:30:21 The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Es
CVE-2026-54650 8.6 0.36% 1 0 2026-07-28T22:20:54 ## Summary openhole-server forwarded the URL-decoded request path (`r.URL.Path`
CVE-2026-54658 9.8 0.40% 1 0 2026-07-28T22:19:24 ### Impact A SQL injection vulnerability exists in the `escapeValue()` function
CVE-2026-54638 7.5 0.35% 1 0 2026-07-28T22:15:29 ### Impact A remote, unauthenticated attacker can cause excessive memory alloca
CVE-2026-54719 7.5 0.28% 1 0 2026-07-28T21:59:49 GHSA-wvhv-qcqf-f3cx fixed the per-folder .goshs ACL bypass on the state-changing
CVE-2026-62325 9.1 0.34% 1 0 2026-07-28T21:57:19 ## Summary Start goshs v2.1.3 with `-b 'admin:' -sftp`. No `-fkf`. SFTP accepts
CVE-2026-15057 7.5 0.26% 1 0 2026-07-28T21:31:45 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerab
CVE-2026-14996 8.2 0.22% 1 0 2026-07-28T21:31:45 IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related
CVE-2026-14981 7.5 0.26% 1 0 2026-07-28T21:31:45 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv
CVE-2026-55390 7.5 0.36% 2 0 2026-07-28T21:26:42 ### Summary When generating models from an XML Schema (`--input-file-type xmlsc
CVE-2026-5674 8.8 0.12% 1 0 2026-07-28T17:16:52.923000 A flaw was found in PipeWire, a multimedia server. This vulnerability allows an
CVE-2026-16812 10.0 0.88% 1 0 2026-07-28T14:50:33.960000 VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may a
CVE-2025-15467 8.8 47.62% 1 6 2026-07-28T13:17:14.747000 Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with malic
CVE-2026-66373 7.5 0.47% 1 0 2026-07-28T05:17:17.507000 Redis before 8.8.0, in the unusual case where an authenticated attacker can exec
CVE-2026-63077 9.8 0.65% 7 1 2026-07-27T18:31:56 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe
CVE-2026-66013 None 0.39% 1 0 2026-07-25T12:31:47 OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the
CVE-2026-43499 7.8 0.73% 1 55 2026-07-24T15:17:20.787000 In the Linux kernel, the following vulnerability has been resolved: rtmutex: Us
CVE-2026-16232 9.1 69.97% 6 2 template 2026-07-23T15:44:54.743000 An authentication bypass vulnerability in the Check Point SmartConsole login pro
CVE-2026-16723 9.0 0.41% 2 6 2026-07-23T09:32:08 A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.
CVE-2026-50502 8.0 0.60% 1 0 2026-07-22T16:18:05.400000 Insufficient granularity of access control in Windows Event Logging Service allo
CVE-2026-49176 7.8 0.40% 2 2 2026-07-22T16:17:28.753000 Improper privilege management in Windows WalletService allows an authorized atta
CVE-2026-15352 7.5 0.43% 1 0 2026-07-17T18:31:44.140000 A vulnerability exists in the Health & Safety (HS) application of NASA's Core Fl
CVE-2026-42530 8.1 3.68% 1 3 2026-07-16T12:33:31 NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGI
CVE-2026-54121 8.8 1.05% 1 10 2026-07-14T18:32:37 Improper authorization in Active Directory Certificate Services (AD CS) allows a
CVE-2026-50469 7.8 0.27% 1 0 2026-07-14T18:32:32 Improper link resolution before file access ('link following') in Windows Projec
CVE-2026-58025 9.8 0.33% 1 1 2026-07-09T21:31:14 Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWik
CVE-2026-43503 8.8 0.34% 1 9 2026-07-02T12:31:55 In the Linux kernel, the following vulnerability has been resolved: net: skbuff
CVE-2026-12045 9.0 0.48% 1 0 2026-07-01T19:26:30.593000 Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker wh
CVE-2026-12044 8.8 0.71% 1 0 2026-07-01T19:23:39.010000 SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT O
CVE-2026-10702 4.3 0.72% 4 1 2026-06-30T03:36:54 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w
CVE-2026-42897 8.1 5.64% 9 1 2026-06-17T10:48:34.893000 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2026-1623 6.3 2.18% 1 1 2026-06-17T10:16:12.407000 A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the fu
CVE-2025-15435 7.3 0.35% 1 0 2026-06-17T08:37:46.203000 A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an u
CVE-2025-66518 None 0.89% 1 0 2026-01-29T03:42:38 Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols
CVE-2023-37327 7.6 1.71% 2 0 2025-11-04T21:32:34 GStreamer FLAC File Parsing Integer Overflow Remote Code Execution Vulnerability
CVE-2014-0160 7.5 100.00% 1 75 template 2025-10-22T03:31:11 The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not p
CVE-2026-62379 0 0.00% 2 0 N/A
CVE-2026-62261 0 0.00% 2 0 N/A
CVE-2026-46647 0 0.00% 2 0 N/A
CVE-2026-46648 0 0.00% 2 0 N/A
CVE-2026-63222 0 0.45% 3 0 N/A
CVE-2026-63220 0 0.14% 2 0 N/A
CVE-2026-63221 0 0.38% 2 0 N/A
CVE-2026-59726 0 0.48% 5 1 N/A
CVE-2026-17543 0 0.39% 1 0 N/A
CVE-2026-62246 0 0.27% 1 0 N/A
CVE-2026-68503 0 0.40% 1 0 N/A
CVE-2026-18245 0 0.52% 1 0 N/A
CVE-2026-18140 0 0.44% 1 0 N/A
CVE-2026-62663 0 0.34% 1 0 N/A
CVE-2026-58086 0 0.00% 1 0 N/A
CVE-2026-56848 0 0.00% 4 0 N/A
CVE-2026-56846 0 0.00% 2 0 N/A
CVE-2026-53921 0 0.00% 2 2 N/A
CVE-2026-65094 0 0.00% 1 0 N/A

CVE-2026-65313
(8.1 HIGH)

EPSS: 0.18%

updated 2026-07-31T17:16:34.970000

2 posts

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.

thehackerwire@mastodon.social at 2026-07-31T14:00:39.000Z ##

🟠 CVE-2026-65313 - High (8.1)

A provisioning script used when installing HIPASE-250 (formerly 250
SCALA) engineering workstations sets a fixed, hard-coded x11vnc
password. Because the same credential is applied to every workstation
provisioned this way, an attacker with adjace...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-31T14:00:39.000Z ##

🟠 CVE-2026-65313 - High (8.1)

A provisioning script used when installing HIPASE-250 (formerly 250
SCALA) engineering workstations sets a fixed, hard-coded x11vnc
password. Because the same credential is applied to every workstation
provisioned this way, an attacker with adjace...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68500
(7.5 HIGH)

EPSS: 0.38%

updated 2026-07-31T16:52:41

1 posts

### Impact The shop payment webhook `POST /{_locale}/update-payment` (route `sylius_mollie_shop_payment_webhook`) accepts two independent, attacker-controlled parameters: `id` (the Mollie payment ID, verified against Mollie's API) and `orderId` (the Sylius order ID, read directly from the database). The handler never verifies that the Mollie payment belongs to the referenced order. An

thehackerwire@mastodon.social at 2026-07-30T22:00:19.000Z ##

🟠 CVE-2026-68500 - High (7.5)

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but doe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67594
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-07-31T16:17:11.793000

1 posts

Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any route in the API routing configuration. Attackers can invoke approximately 50 unprotected API endpoints to enumerate and provision servers, reset root pass

thehackerwire@mastodon.social at 2026-07-30T20:59:58.000Z ##

🔴 CVE-2026-67594 - Critical (9.8)

Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any ro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66066
(0 None)

EPSS: 1.70%

updated 2026-07-31T16:17:10.160000

12 posts

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated a

5 repos

https://github.com/0xBlackash/CVE-2026-66066

https://github.com/paveg/rails-activestorage-vips-audit

https://github.com/0xsha/KindaRails2Shell

https://github.com/Zer0SumGam3/CVE-2026-66066-POC

https://github.com/rails/rails-forensics-CVE-2026-66066

sayzard@mastodon.sayzard.org at 2026-07-31T17:41:43.000Z ##

KindaRails2Shell attack details and tools to perform a forensic investigation

Rails Active Storage에서 `:vips` 변형 처리기를 사용할 때 발생하는 CVE-2026-66066(KindaRails2Shell) 임의 파일 읽기 취약점의 공격 경로와 포렌식 절차를 제공하는 저장소다. 직접 업로드에서 클라이언트가 지정한 MIME 타입과 libvips의 매직 바이트 기반 형식 판별이 불일치하는 점을 악용하며, MATLAB/HDF5 External File List 체인을 통해 서버의 임의 경로 파일 내용을 이미지 픽셀로 유출할 수 있다. 도구는 애플리케이션의 노출 기간을 산정하고, Active Storage...

github.com/rails/rails-forensi

##

flavorjones@ruby.social at 2026-07-31T01:01:12.000Z ##

RE: ruby.social/@flavorjones/11700

The Rails security team published attack details and -- more importantly -- tools and agent skills to run a forensic investigation to help you determine if you were exploited. Be careful out there.

discuss.rubyonrails.org/t/cve-

##

threatcodex@infosec.exchange at 2026-07-30T20:34:49.000Z ##

KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
#CVE_2026_66066
rapid7.com/blog/post/etr-kinda

##

AAKL@infosec.exchange at 2026-07-30T16:38:45.000Z ##

New.

Rapaid7: KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails rapid7.com/blog/post/etr-kinda @Rapid7Official

The related Ruby on Rails advisory was published yesterday: Possible arbitrary file read and remote code execution in Active Storage variant processing github.com/rails/rails/securit #infosec #vulnerability #Ruby

##

lobsters@mastodon.social at 2026-07-30T15:10:13.000Z ##

KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) lobste.rs/s/kkobew #ruby #security
ethiack.com/info-hub/research/

##

_r_netsec@infosec.exchange at 2026-07-30T14:13:05.000Z ##

KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066) ethiack.com/info-hub/research/

##

jbhall56@infosec.exchange at 2026-07-30T12:07:40.000Z ##

Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials, and API tokens. thehackernews.com/2026/07/crit

##

manyfold@3dp.chat at 2026-07-30T11:42:10.000Z ##

🚨 Manyfold v0.147.1 is out, with a security fix for #Rails CVE-2026-66066. Update your instances! 🚨

##

raul@mastodon.in4matics.cat at 2026-07-30T10:16:42.000Z ##

CVE-2026-66066: un atacant pot llegir fitxers del servidor Rails gràcies a Active Storage + libvips. secret_key_base, master.key, credencials de cloud — tot a l'abast. I després fer RCE amb les claus robades. 🎯

Parcheja a: activestorage 7.2.3.2 / 8.0.5.1 / 8.1.3.1 o libvips ≥ 8.13.0

Si encara uses libvips vell, posa VIPS_BLOCK_UNTRUSTED i resa.

#rails #cybersecurity #RCE #CVE

##

beyondmachines1@infosec.exchange at 2026-07-30T08:01:39.000Z ##

Critical Rails Active Storage Flaw Allows Unauthenticated Arbitrary File Read

Ruby on Rails patched a critical vulnerability (CVE-2026-66066) in Active Storage that allows unauthenticated attackers to read arbitrary server files and steal sensitive secrets.

**Update Rails immediately to a patched version (7.2.3.2, 8.0.5.1, or 8.1.3.1) and make sure libvips is upgraded to 8.13 or later. A public exploit is already available and attacks are expected soon. Because attackers may have already stolen your secrets, rotate every credential the app could access, including secret_key_base, the master key, database passwords, and all API tokens after patching.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

DailyCyberSecurity@infosec.exchange at 2026-07-30T03:01:51.000Z ##

A Rails Active Storage flaw, CVE-2026-66066 (CVSS 9.5), enables arbitrary file read and remote code execution. Patch Rails and rotate secrets now.

#RubyOnRails #ActiveStorage #CVE202666066 #RCE #libvips #InfoSec

securityonline.info/rails-cve-

##

christine@ruby.social at 2026-07-29T18:17:08.000Z ##

RE: christine-seeman.com/cve-2026-

Patch your #rails there's a new CVE out there specifically about active storage and if your app accepts image uploads.

#ruby #rubyonrails

##

CVE-2026-20316
(5.3 MEDIUM)

EPSS: 0.79%

updated 2026-07-31T16:17:06.087000

16 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vu

AAKL at 2026-07-31T16:19:58.449Z ##

There are two new advisories from Cisco, one addressing a critical vulnerability that was first published on March 4:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

The second is a high-severity vulnerability that was first published yesterday:

CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity

##

thecybermind at 2026-07-31T13:34:04.166Z ##

Executive alert: CVE-2026-20316 exposes Cisco Secure Firewall Management Center to active exploitation via hard-coded credentials. Review enterprise exposure metrics, zero-trust segmentation, and board-level risk mitigation strategies today. thecybermind.co/jily

##

oversecurity@mastodon.social at 2026-07-31T10:12:18.000Z ##

CVE-2026-20316 Zero-Day Actively Exploited, Cisco Releases Fix

Cisco has released security updates for an actively exploited zero-day vulnerability, CVE-2026-20316, affecting Cisco Secure FMC (Secure Firewall...

🔗️ [Thecyberexpress] link.is.it/FLOu9T

##

thecybermind at 2026-07-31T07:21:09.349Z ##

Critical advisory: CVE-2026-20316 exposes Cisco Secure Firewall Management Center to hard-coded credential abuse. Review active threat vectors, network access lockdowns, and system hardening playbooks to protect your perimeter. thecybermind.co/bkur

##

AAKL@infosec.exchange at 2026-07-31T16:19:58.000Z ##

There are two new advisories from Cisco, one addressing a critical vulnerability that was first published on March 4:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

The second is a high-severity vulnerability that was first published yesterday:

CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #vulnerability #Cisco

##

thecybermind@infosec.exchange at 2026-07-31T13:34:04.000Z ##

Executive alert: CVE-2026-20316 exposes Cisco Secure Firewall Management Center to active exploitation via hard-coded credentials. Review enterprise exposure metrics, zero-trust segmentation, and board-level risk mitigation strategies today. thecybermind.co/jily

##

oversecurity@mastodon.social at 2026-07-31T10:12:18.000Z ##

CVE-2026-20316 Zero-Day Actively Exploited, Cisco Releases Fix

Cisco has released security updates for an actively exploited zero-day vulnerability, CVE-2026-20316, affecting Cisco Secure FMC (Secure Firewall...

🔗️ [Thecyberexpress] link.is.it/FLOu9T

##

thecybermind@infosec.exchange at 2026-07-31T07:21:09.000Z ##

Critical advisory: CVE-2026-20316 exposes Cisco Secure Firewall Management Center to hard-coded credential abuse. Review active threat vectors, network access lockdowns, and system hardening playbooks to protect your perimeter. thecybermind.co/bkur

##

Bied@digitalhub.social at 2026-07-30T19:33:28.000Z ##

#Cisco - "We Never Learn". 🔥

Warum ein Konzern es noch immer notwendig findet eine #Backdoor in seine Produkte einzubauen ist mir völlig schleierhaft. 🙈

"Da CVE-2026-20316 bereits aktiv ausgenutzt wird, rät Cisco Administratoren, ihre FMC-Instanzen dringend zu aktualisieren."

"Gibt es Abhilfe?

"Die genannten Hotfix-Updates bessern auch bezüglich einer seit März bekannten kritischen Lücke (CVSS: 10) nach, mit der sich die Authentifizierung im Web-Interface von FMC umgehen lässt. Diese Lücke ist als CVE-2026-20079 registriert und verleiht Angreifern sogar einen direkten Root-Zugriff auf das zugrundeliegende Betriebssystem. "

Klar, eine Firewall ist ja nur zum Schutz der Kunden vorhanden, da kann man schon mal auch Kriminelle einladen, oder? 🤢

So eine persönliche Haftung des CEO und eine Strafe ab 5 % vom Konzernumsatz könnte möglicherweise zu einer Änderungen führen:

So stelle ich mir die Anweisung des CEO vor: 👍

"Ab sofort ist die Nutzung (auch während der Entwicklung) von Backdoors untersagt. Wer sich nicht daran hält wird fristlos entlassen und haftet für Schäden."

Und, natürlich sollte die Qualitätssicherung vorab prüfen ob die Entwickler sich auch daran halten. 😁

Es gibt erfahrene Spezialisten die gerne bei der Auswahl der Geräte helfen und für mehr Sicherheit sorgen. Einfach anfragen, dann weiß man mehr. 🙂

golem.de/news/kodierte-zugangs

#Backdoor

##

security_crawler_carl@infosec.exchange at 2026-07-30T11:45:32.000Z ##

🏆 New Achievement! Static Credentials, Static Fate!

RAID ALERT. RAID ALERT. Cisco Secure Firewall Management Center has a hardcoded low-privilege account baked right into the software — CVE-2026-20316 — and unauthenticated remote attackers are already using it to log in and harvest sensitive data. That's Phase One. Phase Two is the wipe: threat actors are chaining it with CVE-2026-20079, which hands them root access via arbitrary script execution. (1/2)

##

beyondmachines1@infosec.exchange at 2026-07-30T11:01:06.000Z ##

Cisco Patches Actively Exploited Hard-Coded Password in Secure Firewall Management Center

Cisco fixed a high-severity vulnerability (CVE-2026-20316) in Secure Firewall Management Center that allows unauthenticated remote attackers to log in using hard-coded credentials. CISA added the flaw to its KEV catalog following reports of zero-day exploitation targeting network security infrastructure.

**Make sure your Cisco Secure Firewall Management Center (FMC) is isolated from the internet and only reachable from trusted internal networks. Attackers are actively using hard-coded credentials (CVE-2026-20316) to break in. Apply Cisco's hotfix immediately (CISA requires it by August 1, 2026), and check your management logs for suspicious entries mentioning /var/tmp/license.tmp to spot any break-in.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

oversecurity@mastodon.social at 2026-07-29T22:20:25.000Z ##

Cisco warns of FMC static credential flaw exploited in zero-day attacks

Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was...

🔗️ [Bleepingcomputer] link.is.it/AKCr32

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T21:44:32.000Z ##

A Cisco FMC vulnerability, CVE-2026-20316, is exploited in the wild. Static credentials let attackers log in. CISA added it to KEV — patch now.

#Cisco #CVE202620316 #FMC #KEV #Vulnerability #InfoSec

securityonline.info/cisco-fmc-

##

secdb@infosec.exchange at 2026-07-29T21:00:20.000Z ##

🚨 [CISA-2026:0729] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-20316 (secdb.nttzen.cloud/cve/detail/)
- Name: Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC)
- Notes: sec.cloudapps.cisco.com/securi ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260729 #cisa20260729 #cve_2026_20316 #cve202620316

##

cisakevtracker@mastodon.social at 2026-07-29T20:00:46.000Z ##

CVE ID: CVE-2026-20316
Vendor: Cisco
Product: Secure Firewall Management Center (FMC)
Date Added: 2026-07-29
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

AAKL@infosec.exchange at 2026-07-29T17:36:00.000Z ##

New Cisco updates:

CRITICAL vulnerability, first released on March 4: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

High severity: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi

New informational advisory: Cisco Advance Notification for Publication of August 5, 2026, Security Advisories sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #vulnerability #Cisco

##

CVE-2026-18141
(8.2 HIGH)

EPSS: 0.00%

updated 2026-07-31T16:17:05.387000

2 posts

A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The system also inadvertently discloses the expected certificate subject in error me

thehackerwire@mastodon.social at 2026-07-31T17:00:21.000Z ##

🟠 CVE-2026-18141 - High (8.2)

A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by ma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-31T17:00:21.000Z ##

🟠 CVE-2026-18141 - High (8.2)

A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by ma...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18064
(7.5 HIGH)

EPSS: 0.34%

updated 2026-07-31T16:17:05.247000

1 posts

An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a denial-of-service condition and processor reset.

thehackerwire@mastodon.social at 2026-07-30T23:00:23.000Z ##

🟠 CVE-2026-18064 - High (7.5)

An incomplete fix for CVE-2026-15352 in the NASA core Flight System
(cFS) Health and Safety (HS) application leaves a separate NULL pointer
dereference reachable in versions through 7.0.1. An attacker who can
trigger the affected command under ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17566
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-07-31T16:17:00.037000

2 posts

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wrapper, create_import_export_job() (route POST /import_export/job/<sid>, gated only by the ordinary, commonly-granted tools_import_export_data permission)

thehackerwire@mastodon.social at 2026-07-31T17:00:30.000Z ##

🔴 CVE-2026-17566 - Critical (9.9)

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-31T17:00:30.000Z ##

🔴 CVE-2026-17566 - Critical (9.9)

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wra...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17347
(7.5 HIGH)

EPSS: 0.00%

updated 2026-07-31T16:16:59.140000

2 posts

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username directly into the command string and executed the result with subprocess.Popen(..., shell=True). Because the username can

thehackerwire@mastodon.social at 2026-07-31T17:00:41.000Z ##

🟠 CVE-2026-17347 - High (7.5)

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implement...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-31T17:00:41.000Z ##

🟠 CVE-2026-17347 - High (7.5)

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implement...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68502
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-07-31T15:18:01.563000

1 posts

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches data.get('value') to LazyOwnShell.one_cmd, reaching LazyOwnShell.do_cmd and subprocess.call(command, shell=True), allowing unauthenticated remote code execution in the C2 process. This issue is fixed in

thehackerwire@mastodon.social at 2026-07-30T22:00:28.000Z ##

🔴 CVE-2026-68502 - Critical (9.8)

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches data.get('value') to LazyOwnShell.one_cmd, reachi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10685
(7.6 HIGH)

EPSS: 0.00%

updated 2026-07-31T15:16:27.433000

2 posts

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called params->notify(conn, params, NULL, 0). Per the public GATT API, a notify callback with NULL data is the documented signal that the subscription has terminated and the bt_gatt_subscribe_params struct may

offseq at 2026-07-31T15:30:25.095Z ##

Zephyr Bluetooth GATT client (versions 2.4.0 to <4.5.0) faces a HIGH severity use-after-free (CVE-2026-10685) in gatt_write_ccc_rsp(). Risk: memory corruption, crash, or attacker-driven flow. Patch pending — apply mitigations. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-07-31T15:30:25.000Z ##

Zephyr Bluetooth GATT client (versions 2.4.0 to <4.5.0) faces a HIGH severity use-after-free (CVE-2026-10685) in gatt_write_ccc_rsp(). Risk: memory corruption, crash, or attacker-driven flow. Patch pending — apply mitigations. radar.offseq.com/threat/cve-20 #OffSeq #Zephyr #Bluetooth #CVE

##

CVE-2026-18358
(7.5 HIGH)

EPSS: 0.00%

updated 2026-07-31T13:17:19.933000

2 posts

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations

thehackerwire@mastodon.social at 2026-07-31T14:00:26.000Z ##

🟠 CVE-2026-18358 - High (7.5)

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-31T14:00:26.000Z ##

🟠 CVE-2026-18358 - High (7.5)

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17561
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-07-31T13:17:19.730000

4 posts

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.108.

thehackerwire@mastodon.social at 2026-07-31T14:00:16.000Z ##

🔴 CVE-2026-17561 - Critical (9.8)

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection.

This issue affects Logsign SIEM: before 6.4.108.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-07-31T14:00:25.387Z ##

CVE-2026-17561: Logsign SIEM <6.4.108 faces CRITICAL code injection (CWE-94, CVSS 9.8). Exploitable remotely, no patch yet. Full system compromise possible. Monitor for updates. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-07-31T14:00:16.000Z ##

🔴 CVE-2026-17561 - Critical (9.8)

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection.

This issue affects Logsign SIEM: before 6.4.108.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-31T14:00:25.000Z ##

CVE-2026-17561: Logsign SIEM <6.4.108 faces CRITICAL code injection (CWE-94, CVSS 9.8). Exploitable remotely, no patch yet. Full system compromise possible. Monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202617561 #SIEM #Vuln #BlueTeam

##

CVE-2026-10079
(8.5 HIGH)

EPSS: 0.17%

updated 2026-07-31T12:30:30

2 posts

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the workload as having empty UID, name and labels and namespace "default". This bypas

thehackerwire@mastodon.social at 2026-07-31T12:00:33.000Z ##

🟠 CVE-2026-10079 - High (8.5)

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to cr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-31T12:00:33.000Z ##

🟠 CVE-2026-10079 - High (8.5)

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to cr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15722
(7.5 HIGH)

EPSS: 0.51%

updated 2026-07-31T12:30:30

2 posts

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a repl

thehackerwire@mastodon.social at 2026-07-31T12:00:23.000Z ##

🟠 CVE-2026-15722 - High (7.5)

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds chec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-31T12:00:23.000Z ##

🟠 CVE-2026-15722 - High (7.5)

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds chec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-11770
(7.5 HIGH)

EPSS: 0.51%

updated 2026-07-31T12:30:30

2 posts

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication

thehackerwire@mastodon.social at 2026-07-31T12:00:13.000Z ##

🟠 CVE-2026-11770 - High (7.5)

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-31T12:00:13.000Z ##

🟠 CVE-2026-11770 - High (7.5)

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66416
(8.8 HIGH)

EPSS: 0.16%

updated 2026-07-31T12:16:55.820000

1 posts

Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel VerifyCsrfToken middleware from the global middleware stack in app/Http/Kernel.php. Attackers can craft malicious pages delivered via phishing emails or malicious websites to trigger unauthorized POST, P

thehackerwire@mastodon.social at 2026-07-30T20:00:11.000Z ##

🟠 CVE-2026-66416 - High (8.8)

Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel VerifyCsrfToken middleware from the global middlew...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63223
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-07-31T06:16:32.297000

5 posts

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads in a web-accessible script-enabled directory. Applications are impacted when they validate uploads u

hugovalters@mastodon.social at 2026-07-31T14:07:20.000Z ##

CVE-2026-63223 - Critical arbitrary file upload in CodeIgniter. Bypass of is_image/mime_in validation can lead to RCE. CVSS 9.8. Update to 4.7.4 immediately. #CVE #CodeIgniter #infosec

valtersit.com/cve/CVE-2026-632

##

AmmarSpaces at 2026-07-31T10:51:10.006Z ##

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

##

DailyCyberSecurity at 2026-07-31T09:19:52.799Z ##

CVE-2026-63223: CodeIgniter4 RCE Vulnerability Rated CVSS 9.8

securityonline.info/codeignite

##

AmmarSpaces@infosec.exchange at 2026-07-31T10:51:10.000Z ##

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

#cybersecurity #infosec #codeigniter #vulnerability

##

DailyCyberSecurity@infosec.exchange at 2026-07-31T09:19:52.000Z ##

CVE-2026-63223: CodeIgniter4 RCE Vulnerability Rated CVSS 9.8

securityonline.info/codeignite

##

CVE-2026-6102
(7.8 HIGH)

EPSS: 0.09%

updated 2026-07-31T04:17:24.730000

1 posts

MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the NTIOLib_X64.sys driver. The issue

thehackerwire@mastodon.social at 2026-07-29T21:00:10.000Z ##

🟠 CVE-2026-6102 - High (7.8)

MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An attacker must first obtain the ability to execute...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66803
(10.0 CRITICAL)

EPSS: 0.49%

updated 2026-07-31T04:17:24.520000

2 posts

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

hugovalters@mastodon.social at 2026-07-31T15:00:31.000Z ##

CVE-2026-66803 - Critical improper access control in Azure Cosmos DB allows remote code execution. CVSS 10. No patch yet - apply mitigations immediately. #CVE #Azure #infosec

valtersit.com/cve/CVE-2026-668

##

offseq@infosec.exchange at 2026-07-31T01:30:24.000Z ##

Azure Cosmos DB suffers a CRITICAL improper access control vulnerability (CVE-2026-66803) allowing unauthorized remote code execution. No patch yet — restrict network access & monitor Microsoft advisories. radar.offseq.com/threat/improp #OffSeq #Azure #Vuln #CyberSecurity

##

CVE-2026-5490
(8.8 HIGH)

EPSS: 0.48%

updated 2026-07-31T04:17:24.013000

1 posts

DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of DriveLock. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4568 by default. The issue results from the lack of proper validation of a user-supplied string befo

1 repos

https://github.com/HORKimhab/CVE-2026-54900

thehackerwire@mastodon.social at 2026-07-30T05:00:39.000Z ##

🟠 CVE-2026-5490 - High (8.8)

DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of DriveLock. Authentication is required to exploit this vulnerability.

The specific flaw exis...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58043
(7.5 HIGH)

EPSS: 0.14%

updated 2026-07-31T04:17:23.737000

4 posts

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.

thehackerwire@mastodon.social at 2026-07-30T07:00:10.000Z ##

🟠 CVE-2026-58043 - High (7.5)

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.

Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T17:29:15.000Z ##

2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:01.000Z ##

2026-07-29, Version 26.5.1 (Current), @RafaelGSS

This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:00.000Z ##

2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolito

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

CVE-2026-16727
(0 None)

EPSS: 0.09%

updated 2026-07-31T04:16:48.200000

1 posts

Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement. Refer to the ' Security Update for ASUS Armoury Crate ' section on the ASUS Security Advisory for more information.

offseq@infosec.exchange at 2026-07-30T03:00:24.000Z ##

CVE-2026-16727 (HIGH): Race condition in ASUS Armoury Crate 5.4.1 lets local users escalate privileges via improper synchronization. No patch available. Limit local access & monitor systems. radar.offseq.com/threat/cve-20 #OffSeq #CVE202616727 #ASUS #Vuln

##

CVE-2026-14973
(9.3 CRITICAL)

EPSS: 0.45%

updated 2026-07-31T04:16:46.710000

1 posts

IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.

DailyCyberSecurity@infosec.exchange at 2026-07-29T02:03:37.000Z ##

IBM Aspera vulnerabilities affect Faspex 5 and the Desktop App. CVE-2026-14973 and two RCE flaws rate up to 9.3. Update to Faspex 5.0.16 and Desktop 1.1.0.

#IBMAspera #AsperaFaspex #CVE202614973 #RCE #PathTraversal #CyberSecurity

securityonline.info/ibm-aspera

##

CVE-2026-13435
(9.9 CRITICAL)

EPSS: 0.29%

updated 2026-07-31T04:16:46.393000

1 posts

IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.

thehackerwire@mastodon.social at 2026-07-30T20:01:35.000Z ##

🔴 CVE-2026-13435 - Critical (9.9)

IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18157
(7.8 HIGH)

EPSS: 0.24%

updated 2026-07-31T03:31:17

2 posts

A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the

thehackerwire@mastodon.social at 2026-07-31T04:00:13.000Z ##

🟠 CVE-2026-18157 - High (7.8)

A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-31T04:00:13.000Z ##

🟠 CVE-2026-18157 - High (7.8)

A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen,...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12562
(8.8 HIGH)

EPSS: 0.28%

updated 2026-07-31T00:30:29

1 posts

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. This vulnerability stems from a network-accessible port running a Target Communications Framework (TCF) service that does not require any authentication, allowing an attacker to directly interact with the Linux environment that power

hugovalters@mastodon.social at 2026-07-31T12:10:03.000Z ##

CVE-2026-12562 – Unauthenticated TCF debug interface in Phoenix Contact RCU II+ and Multiload II+ grants full root access. CVSS 8.8. No patch yet. Isolate devices and restrict network exposure. #CVE #PhoenixContact #infosec

valtersit.com/cve/CVE-2026-125

##

CVE-2026-65423
(8.8 HIGH)

EPSS: 0.60%

updated 2026-07-31T00:30:29

2 posts

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write.

thehackerwire@mastodon.social at 2026-07-31T04:00:36.000Z ##

🟠 CVE-2026-65423 - High (8.8)

An integer overflow in the UA_Variant arrayDimensions product
computation in open62541 may allow a remote attacker to trigger an
out-of-bounds write.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-31T04:00:36.000Z ##

🟠 CVE-2026-65423 - High (8.8)

An integer overflow in the UA_Variant arrayDimensions product
computation in open62541 may allow a remote attacker to trigger an
out-of-bounds write.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66421
(9.3 CRITICAL)

EPSS: 0.36%

updated 2026-07-31T00:30:29

1 posts

OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message containing inline event handler payloads such as an img tag with an onerror attribute with

thehackerwire@mastodon.social at 2026-07-31T01:00:25.000Z ##

🔴 CVE-2026-66421 - Critical (9.3)

OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages pro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66420
(8.8 HIGH)

EPSS: 0.17%

updated 2026-07-31T00:30:29

1 posts

MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within webserver.js when self-signed certificates are in use. Attackers can open cross-origin WebSocket connections to any of th

thehackerwire@mastodon.social at 2026-07-31T01:00:14.000Z ##

🟠 CVE-2026-66420 - High (8.8)

MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebSer...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66360
(7.5 HIGH)

EPSS: 0.28%

updated 2026-07-31T00:30:29

1 posts

The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero length value to trigger a bounded heap over read. This condition occurs before MMS session establishment, a crafted TCP/102 connection attempt can trigger the

thehackerwire@mastodon.social at 2026-07-31T01:00:02.000Z ##

🟠 CVE-2026-66360 - High (7.5)

The ISO Presentation layer contains a flaw in the handling of specific
parameters during normal mode negotiation. A missing length check in the
processing of the encoded presentation data allows an attacker
controlled field with a zero length v...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63559
(7.5 HIGH)

EPSS: 0.43%

updated 2026-07-31T00:30:29

1 posts

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information.

thehackerwire@mastodon.social at 2026-07-30T23:00:12.000Z ##

🟠 CVE-2026-63559 - High (7.5)

An integer overflow in the UA_Variant arrayDimensions product
computation in open62541 may allow a remote attacker to read
out-of-bounds heap memory, potentially disclosing sensitive information.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63035
(8.1 HIGH)

EPSS: 0.57%

updated 2026-07-31T00:30:22

2 posts

A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code.

thehackerwire@mastodon.social at 2026-07-31T04:00:24.000Z ##

🟠 CVE-2026-63035 - High (8.1)

A heap use-after-free vulnerability in the TransferSubscriptions service
in open62541 may allow an authenticated attacker to cause a denial of
service or potentially execute arbitrary code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-31T04:00:24.000Z ##

🟠 CVE-2026-63035 - High (8.1)

A heap use-after-free vulnerability in the TransferSubscriptions service
in open62541 may allow an authenticated attacker to cause a denial of
service or potentially execute arbitrary code.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67206
(8.8 HIGH)

EPSS: 0.44%

updated 2026-07-30T21:31:57

1 posts

Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() functions. Attackers with the file_manager_mkfile capability can write malicious PHP content into the web-accessible FILES_DIR directory and trigger executio

thehackerwire@mastodon.social at 2026-07-30T21:00:08.000Z ##

🟠 CVE-2026-67206 - High (8.8)

Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() func...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66415
(8.5 HIGH)

EPSS: 0.28%

updated 2026-07-30T21:31:57

1 posts

Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::import() method without path validation. Attackers can submit crafted filenames containing URL wrappers or path traversal sequences through the JSON-RPC AP

thehackerwire@mastodon.social at 2026-07-30T20:00:00.000Z ##

🟠 CVE-2026-66415 - High (8.5)

Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::im...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17657
(8.3 HIGH)

EPSS: 0.36%

updated 2026-07-30T21:31:32

2 posts

Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

hrbrmstr@mastodon.social at 2026-07-31T12:22:30.000Z ##

Chrome CVE Report for the 2026-07-29 Stable channel: tbljrmp60k.joplinusercontent.c

Top vulnerability types: Inappropriate Implementation (34.5%), Insufficient Input Validation (19%), Use After Free (13.4%)

Most affected components: XR (36), Chrome for iOS (35), Input Handling (33), ANGLE Graphics (30)

Largest bounty: $36,000 — CVE-2026-17657 (Use after free in Navigation)

##

hrbrmstr@mastodon.social at 2026-07-31T12:22:30.000Z ##

Chrome CVE Report for the 2026-07-29 Stable channel: tbljrmp60k.joplinusercontent.c

Top vulnerability types: Inappropriate Implementation (34.5%), Insufficient Input Validation (19%), Use After Free (13.4%)

Most affected components: XR (36), Chrome for iOS (35), Input Handling (33), ANGLE Graphics (30)

Largest bounty: $36,000 — CVE-2026-17657 (Use after free in Navigation)

##

CVE-2026-67207
(8.8 HIGH)

EPSS: 0.30%

updated 2026-07-30T20:27:26.867000

1 posts

Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission check expression. Attackers can exploit the incorrect evaluation of the access control expression to create, download, and restore backups without admin

thehackerwire@mastodon.social at 2026-07-30T21:00:17.000Z ##

🟠 CVE-2026-67207 - High (8.8)

Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67201
(8.6 HIGH)

EPSS: 0.39%

updated 2026-07-30T20:16:05.187000

1 posts

V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploiting a parser differential between net.urllib and net.http. Attackers can craft a URL containing a backslash in the authority section such that net.urllib.parse() extracts the trusted host for allowlist validation while net.

thehackerwire@mastodon.social at 2026-07-29T20:00:35.000Z ##

🟠 CVE-2026-67201 - High (8.6)

V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploiting a parser differential between net.urllib and net.http. Attackers c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59952
(0 None)

EPSS: 0.52%

updated 2026-07-30T20:07:01.330000

1 posts

Valibot helps validate data using a schema. Versions prior to 1.4.2 can throw a TypeError inside its flatten() helper when validation issues contain attacker-controlled object keys such as toString, valueOf, or hasOwnProperty. The issue is reachable through normal record() validation. record() intentionally filters __proto__, prototype, and constructor, but it still accepts other own keys that col

offseq@infosec.exchange at 2026-07-30T01:30:28.000Z ##

CVE-2026-59952 | open-circle valibot <1.4.2 suffers from improper exception handling in flatten(), causing TypeErrors & potential DoS if attacker-controlled keys collide w/ Object.prototype methods. Severity: MEDIUM. Upgrade to 1.4.2+ radar.offseq.com/threat/cve-20 #OffSeq #Valibot #AppSec

##

CVE-2026-12942
(7.5 HIGH)

EPSS: 0.42%

updated 2026-07-30T19:31:02.643000

1 posts

IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.

hugovalters@mastodon.social at 2026-07-31T17:06:30.000Z ##

CVE-2026-12942 - Path Traversal in IBM Langflow OSS. Remote attackers can read arbitrary files via /../ sequences. CVSS 7.5. No patch yet - restrict access immediately. #CVE #Langflow #infosec

valtersit.com/cve/CVE-2026-129

##

CVE-2026-67432
(7.5 HIGH)

EPSS: 0.44%

updated 2026-07-30T19:30:33.710000

1 posts

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem reads and parses an entire JSON-RPC POST body without a size limit, allowing an unauthenticated remote attacker to exhaust process memory. This issue is fixed in version 0.23.0.

thehackerwire@mastodon.social at 2026-07-29T21:00:00.000Z ##

🟠 CVE-2026-67432 - High (7.5)

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem reads and parses an entire JSON-RPC POST body without a size limit, allowing an ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61536
(7.5 HIGH)

EPSS: 0.30%

updated 2026-07-30T19:26:51.190000

1 posts

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resolves their import_path field through importlib.import_module(...) + getattr(...) to obtain the callable that handles a tool call. There is no allowlist or sanitization on import_path, so any importable Py

thehackerwire@mastodon.social at 2026-07-30T20:00:25.000Z ##

🟠 CVE-2026-61536 - High (7.5)

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resolves their import_path field through importlib.impo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64863
(9.1 CRITICAL)

EPSS: 0.34%

updated 2026-07-30T19:19:45.637000

1 posts

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce --no-delete, allowing WebDAV clients to delete or overwrite files via MOVE with Overwrite: T. This issue is fixed in version 2.1.4.

thehackerwire@mastodon.social at 2026-07-29T00:00:21.000Z ##

🔴 CVE-2026-64863 - Critical (9.1)

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce --no-delete, allowing WebDAV clients to delete or ove...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9322
(7.5 HIGH)

EPSS: 0.30%

updated 2026-07-30T19:18:37.363000

1 posts

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.

thehackerwire@mastodon.social at 2026-07-30T18:00:27.000Z ##

🟠 CVE-2026-9322 - High (7.5)

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16771
(8.8 HIGH)

EPSS: 0.25%

updated 2026-07-30T19:10:06.847000

2 posts

In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent device settings, or trigger backend diagno

CVE-2026-18197
(0 None)

EPSS: 0.27%

updated 2026-07-30T19:07:59.843000

1 posts

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scripting (XSS). This issue affects Link Library: before 7.9.4.

AAKL@infosec.exchange at 2026-07-29T17:53:33.000Z ##

New.

Tenable Research Advisories: CVE-2026-18197: Link Library - Reflected Cross-Site Scripting tenable.com/security/research/

From yesterday:

Coordinated “cyberattack” on Minnesota water utilities: What you need to know tenable.com/blog/coordinated-c @tenable #infosec #cyberattack #Minnesota #threatresearch

##

CVE-2026-55391
(7.5 HIGH)

EPSS: 0.20%

updated 2026-07-30T19:07:59.843000

1 posts

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.63.0, datamodel-code-generator validates a URL host once in src/datamodel_code_generator/http.py through get_body, _validate_url_for_fetch, and _get_ips_from_host, but then lets httpx resolve the host again for

thehackerwire@mastodon.social at 2026-07-28T23:00:47.000Z ##

🟠 CVE-2026-55391 - High (7.5)

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.63.0, datamodel-code-generator validates a URL host once i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55389
(7.5 HIGH)

EPSS: 0.36%

updated 2026-07-30T19:07:59.843000

1 posts

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.62.0, datamodel-code-generator resolves JSON Schema $ref targets in src/datamodel_code_generator/parser/jsonschema.py through is_url and _get_ref_body without containing file:// or ../ traversal references to th

thehackerwire@mastodon.social at 2026-07-28T23:00:27.000Z ##

🟠 CVE-2026-55389 - High (7.5)

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.62.0, datamodel-code-generator resolves JSON Schema $ref t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-28323
(9.8 CRITICAL)

EPSS: 0.64%

updated 2026-07-30T18:31:47

1 posts

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

DailyCyberSecurity@infosec.exchange at 2026-07-31T02:53:50.000Z ##

A SolarWinds Web Help Desk SAML authentication bypass, CVE-2026-28323, scores a critical CVSS 9.8. Update to 2026.2.1 to stay protected.

#SolarWinds #WebHelpDesk #CVE202628323 #SAML #InfoSec

securityonline.info/solarwinds

##

CVE-2026-12940
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-07-30T18:31:47

1 posts

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables.

thehackerwire@mastodon.social at 2026-07-30T18:00:48.000Z ##

🔴 CVE-2026-12940 - Critical (9.8)

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py whe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56850
(4.1 MEDIUM)

EPSS: 0.08%

updated 2026-07-30T16:33:59.580000

1 posts

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:01.000Z ##

2026-07-29, Version 26.5.1 (Current), @RafaelGSS

This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...

github.com/nodejs/node/release

#nodejs #javascript

##

CVE-2026-59310
(9.8 CRITICAL)

EPSS: 1.14%

updated 2026-07-30T16:17:15.183000

2 posts

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

DailyCyberSecurity@infosec.exchange at 2026-07-29T12:48:35.000Z ##

Broadcom patched a critical VMware vCenter vulnerability. CVE-2026-59309 and CVE-2026-59310 both score 9.8 CVSS and allow auth bypass or code execution.

#VMware #vCenter #CVE202659309 #CVE202659310 #ESXi #InfoSec

meterpreter.org/vmware-vcenter

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T10:28:35.000Z ##

Broadcom released updates to fix a critical VMware authentication bypass (CVE-2026-59309). A directory traversal flaw (CVE-2026-59310) was also patched.

#VMware #CyberSecurity #CVE202659309 #InfoSec

securityonline.info/vmware-aut

##

CVE-2026-44107
(7.5 HIGH)

EPSS: 0.31%

updated 2026-07-30T16:17:12.010000

2 posts

A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.

thehackerwire@mastodon.social at 2026-07-30T10:00:21.000Z ##

🟠 CVE-2026-44107 - High (7.5)

A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Deni...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-16610
(9.8 CRITICAL)

EPSS: 0.58%

updated 2026-07-30T16:16:57.050000

2 posts

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no authentication check, CAPTCHA validation is bypassable by omitting an attacker-supplied key, and repeater row keys from cfgroup[input

thehackerwire@mastodon.social at 2026-07-30T06:00:07.000Z ##

🔴 CVE-2026-16610 - Critical (9.8)

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly em...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-07-30T04:30:24.000Z ##

CVE-2026-16610: ASE Pro plugin (≤8.9.0) for WordPress suffers CRITICAL RCE via recursive_html. Unauth attackers can execute code if [post_cf_form] is public. Update/disable plugin ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2026_16610 #Security

##

CVE-2026-15435
(9.8 CRITICAL)

EPSS: 0.73%

updated 2026-07-30T15:31:59

1 posts

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.

phillip@social.lol at 2026-07-30T20:04:23.000Z ##

@nuintari I was curious how the results differed between Kagi and Startpage (and by proxy, Google) on this. Holy shit, @da_667 is right to be so upset.

Nothing on Startpage or Google’s first page is at all related. Ctrl + F for the CVE returns only the query in the search bar, and Google’s AI overview, which somehow has the right CVE and description, despite the fact that only one of its cited websites even mentions the actual CVE?

For their part, at least @kagihq has CVE Feed’s actual listing for CVE-2026-15435 as their second result, with Tenable and Feedly further down, but still on the first page of results. It’s still crazy that those aren’t the top three results and this should be better, but given how atrocious the competition is, at least it even found the right CVE at all

##

CVE-2026-47876
(9.3 CRITICAL)

EPSS: 0.28%

updated 2026-07-30T15:31:54

3 posts

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

offseq@infosec.exchange at 2026-07-30T13:30:31.000Z ##

CRITICAL vuln: CVE-2026-47876 in VMware Cloud Foundation (9.1.x.x/9.0.x.x/5.x) allows VM admin to execute code on host via VMXNET3 adapter. Restrict admin access, use other adapters if possible. Patch not yet available. radar.offseq.com/threat/cve-20 #OffSeq #VMware #InfoSec #CVE202647876

##

jbhall56@infosec.exchange at 2026-07-29T12:17:18.000Z ##

Three of the vulnerabilities have been assigned a ‘critical’ severity rating. One of them is CVE-2026-47876, an out-of-bounds write issue in ESXi’s VMXNET3 virtual network adapter. securityweek.com/critical-vm-e

##

offseq@infosec.exchange at 2026-07-29T12:00:27.000Z ##

VMware ESXi, vCenter, Workstation, and Fusion patched for CRITICAL flaws: CVE-2026-47876 enables VM escape and host code execution; CVE-2026-59309/59310 impact vCenter auth & RCE. Patch ASAP — no exploitation reported. radar.offseq.com/threat/critic #OffSeq #VMware #Vuln #PatchNow

##

CVE-2026-59309
(9.8 CRITICAL)

EPSS: 0.74%

updated 2026-07-30T15:31:54

3 posts

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

DailyCyberSecurity@infosec.exchange at 2026-07-29T12:48:35.000Z ##

Broadcom patched a critical VMware vCenter vulnerability. CVE-2026-59309 and CVE-2026-59310 both score 9.8 CVSS and allow auth bypass or code execution.

#VMware #vCenter #CVE202659309 #CVE202659310 #ESXi #InfoSec

meterpreter.org/vmware-vcenter

##

offseq@infosec.exchange at 2026-07-29T12:00:27.000Z ##

VMware ESXi, vCenter, Workstation, and Fusion patched for CRITICAL flaws: CVE-2026-47876 enables VM escape and host code execution; CVE-2026-59309/59310 impact vCenter auth & RCE. Patch ASAP — no exploitation reported. radar.offseq.com/threat/critic #OffSeq #VMware #Vuln #PatchNow

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T10:28:35.000Z ##

Broadcom released updates to fix a critical VMware authentication bypass (CVE-2026-59309). A directory traversal flaw (CVE-2026-59310) was also patched.

#VMware #CyberSecurity #CVE202659309 #InfoSec

securityonline.info/vmware-aut

##

CVE-2026-44099
(7.8 HIGH)

EPSS: 0.23%

updated 2026-07-30T15:16:33.177000

1 posts

A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44094
(8.6 HIGH)

EPSS: 0.26%

updated 2026-07-30T15:16:33.033000

1 posts

An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-48449
(10.0 CRITICAL)

EPSS: 0.54%

updated 2026-07-30T14:54:03.443000

2 posts

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

DailyCyberSecurity@infosec.exchange at 2026-07-31T02:41:48.000Z ##

Adobe Campaign Classic flaw CVE-2026-48449 scores a perfect CVSS 10.0 and allows arbitrary code execution. Update to build 9398 now.

#AdobeCampaignClassic #CVE202648449 #RCE #Adobe #InfoSec

securityonline.info/adobe-camp

##

thehackerwire@mastodon.social at 2026-07-30T04:00:14.000Z ##

🔴 CVE-2026-48449 - Critical (10)

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67428
(8.5 HIGH)

EPSS: 0.34%

updated 2026-07-30T14:48:09

1 posts

## Summary Numerous HTTP-emitting modules (`core.api.http_get`, `core.api.http_post`, `graphql.query`/`graphql.mutation`, `monitor.http_check`, `communication.slack_send`, `notification.{discord,slack,teams}.send_message`, `ai.vision_analyze` [anthropic path], `verify.visual_diff`, `browser.proxy_rotate`, and the `agent`/`llm` inline base_url branch) perform outbound requests to a fully client-con

thehackerwire@mastodon.social at 2026-07-29T20:00:14.000Z ##

🟠 CVE-2026-67428 - High (8.5)

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_party/developer/http/requests.py, core.api.http_get, core.api.http_post, graphql.query, graphql.mutat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67429
(10.0 CRITICAL)

EPSS: 0.49%

updated 2026-07-30T14:46:44

1 posts

## Summary `image.download` fetches a URL and writes the response to disk. It does not use the central path guard (`validate_path_with_env_config`, which confines writes to `FLYTO_SANDBOX_DIR`); instead it confines the output to `output_dir`, but `output_dir` is itself a caller parameter. Since the attacker sets both the target and the base it is checked against, the check is meaningless, and att

thehackerwire@mastodon.social at 2026-07-29T20:00:25.000Z ##

🔴 CVE-2026-67429 - Critical (10)

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR confinem...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44101
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-07-30T14:31:21.447000

1 posts

Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44090
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-07-30T14:31:21.447000

1 posts

Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44091
(9.1 CRITICAL)

EPSS: 0.33%

updated 2026-07-30T14:31:21.447000

1 posts

An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44100
(9.4 CRITICAL)

EPSS: 0.28%

updated 2026-07-30T14:31:21.447000

1 posts

The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44095
(7.8 HIGH)

EPSS: 0.23%

updated 2026-07-30T14:31:21.447000

1 posts

A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-35226
(6.5 MEDIUM)

EPSS: 0.17%

updated 2026-07-30T14:31:21.447000

1 posts

An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in a controlled stop of the PLC application.

certvde@infosec.exchange at 2026-07-29T07:12:14.000Z ##

#OT #Advisory VDE-2026-041
CODESYS PROFINET Controller - Out-of-bounds Write

CODESYS PROFINET is an add‑on for the CODESYS Development System that provides a fully integrated PROFINET protocol stack along with diagnostic capabilities. When a PROFINET Controller is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.
#CVE CVE-2026-35226

certvde.com/en/advisories/vde-

#CSAF codesys.csaf-tp.certvde.com/.w

##

CVE-2026-67437
(7.5 HIGH)

EPSS: 0.35%

updated 2026-07-30T14:24:55

1 posts

## Summary OliveTin's OAuth2 login handler stores per-login state in an in-memory map (`registeredStates`) that grows unboundedly. States are added on every `/oauth/login` request but are **never deleted or expired**. An unauthenticated attacker can send millions of requests to `/oauth/login` to fill the map with state entries, exhausting server memory and causing a denial of service. This is **

thehackerwire@mastodon.social at 2026-07-29T21:59:48.000Z ##

🟠 CVE-2026-67437 - High (7.5)

OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registeredStates map on every /oau...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5487
(7.5 HIGH)

EPSS: 1.54%

updated 2026-07-30T14:18:46.477000

1 posts

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4568 by default. The issue results from the lack of proper validation of a us

thehackerwire@mastodon.social at 2026-07-30T05:00:28.000Z ##

🟠 CVE-2026-5487 - High (7.5)

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability.
...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14356
(8.8 HIGH)

EPSS: 0.27%

updated 2026-07-30T14:16:46.943000

1 posts

The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the email address and password of any WordPress user, including administrat

thehackerwire@mastodon.social at 2026-07-30T06:00:27.000Z ##

🟠 CVE-2026-14356 - High (8.8)

The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18220
(7.8 HIGH)

EPSS: 0.19%

updated 2026-07-30T14:15:31.167000

1 posts

An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation

1 repos

https://github.com/4D4J/objdump-Out-Of-Bounds-write

thehackerwire@mastodon.social at 2026-07-29T15:00:44.000Z ##

🟠 CVE-2026-18220 - High (7.8)

An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds ch...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-21655
(0 None)

EPSS: 0.17%

updated 2026-07-30T14:15:31.167000

1 posts

Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0.

DailyCyberSecurity@infosec.exchange at 2026-07-29T14:30:41.000Z ##

A C-CURE 9000 vulnerability chain hits CVSS 9.6. CVE-2026-21655 allows remote code execution on Johnson Controls victor application servers.

#CCURE9000 #CVE202621655 #JohnsonControls #ICSSecurity

securityonline.info/c-cure-900

##

CVE-2026-18363
(0 None)

EPSS: 0.30%

updated 2026-07-30T14:12:18.697000

1 posts

A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the timestamp associated with the provided token and checks whether the configured validity period has expired. Consequently, the expiry check is only performed if the timestamp lookup fails, allowing tok

offseq@infosec.exchange at 2026-07-30T12:00:27.000Z ##

CVE-2026-18363: osTicket <1.17.8 & <1.18.4 has a CRITICAL flaw (CVSS 9.1) in password reset logic — tokens can be reused, risking account takeover. Upgrade when patch is available, monitor resets, and restrict token access. radar.offseq.com/threat/cve-20 #OffSeq #osTicket #CVE202618363

##

CVE-2026-14529
(9.4 CRITICAL)

EPSS: 0.33%

updated 2026-07-30T14:08:40.373000

2 posts

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.

DailyCyberSecurity@infosec.exchange at 2026-07-31T01:02:48.000Z ##

Four IBM WebSphere vulnerabilities are fixed, including a 9.8 pre-auth RCE (CVE-2026-14512) and a 9.4 SSRF (CVE-2026-14529). Patch now.

#IBMWebSphere #CVE202614512 #SSRF #RCE #Vulnerability #InfoSec

securityonline.info/ibm-websph

##

offseq@infosec.exchange at 2026-07-30T06:00:24.000Z ##

CRITICAL SSRF vuln (CVE-2026-14529) in IBM WebSphere App Server 9.0, 8.5, and Liberty 17.0.0.3 – 26.0.0.8 if SIP (sipServlet-1.1) is enabled. Review SIP use, disable if possible. Details: radar.offseq.com/threat/ibm-we #OffSeq #IBM #WebSphere #SSRF #CVE202614529

##

CVE-2026-14512
(9.8 CRITICAL)

EPSS: 0.54%

updated 2026-07-30T14:08:40.373000

1 posts

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.

CVE-2026-65883
(0 None)

EPSS: 0.50%

updated 2026-07-30T14:06:56.363000

2 posts

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.

1 repos

https://github.com/shinthink/CVE-2026-65883

AAKL@infosec.exchange at 2026-07-30T16:44:07.000Z ##

New. This is in reference to CVE-2026-65883.

VulnCheck: Aimy Captcha-Less Form Guard: The Anti-Bot Plugin That Hands Bots the Keys vulncheck.com/blog/aimy-captch @vulncheck #infosec #vulnerability

##

offseq@infosec.exchange at 2026-07-29T10:30:27.000Z ##

CVE-2026-65883 (CRITICAL, CVSS 10): Aimy Captcha-Less Form Guard for Joomla (v18.0-20.0) is vulnerable to PHP object injection via clfgd field — enabling RCE. Patch or disable plugin urgently. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #Exploit #RCE

##

CVE-2026-64560
(7.8 HIGH)

EPSS: 0.12%

updated 2026-07-30T12:32:18

1 posts

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sys_timer_delete() exec() posix_cpu_timer_del() // Observes old leader p = pid_task(pid, pid_type); de_thread() switch_leader(); release

CVE-2026-44106
(7.8 HIGH)

EPSS: 0.23%

updated 2026-07-30T09:31:25

2 posts

A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

thehackerwire@mastodon.social at 2026-07-30T10:00:11.000Z ##

🟠 CVE-2026-44106 - High (7.8)

A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44105
(6.6 MEDIUM)

EPSS: 0.09%

updated 2026-07-30T09:31:25

1 posts

The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44108
(9.8 CRITICAL)

EPSS: 0.46%

updated 2026-07-30T09:31:24

2 posts

Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise.

thehackerwire@mastodon.social at 2026-07-30T10:00:30.000Z ##

🔴 CVE-2026-44108 - Critical (9.8)

Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an un...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-7849
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-07-30T09:31:24

2 posts

Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.

offseq@infosec.exchange at 2026-07-30T07:30:24.000Z ##

Phoenix Contact CHARX SEC-3150 v1.0.0 hit by CRITICAL (CVSS 9.3) command injection (CVE-2026-7849): unauthenticated remote attackers can execute root commands. No mitigation yet — restrict access! radar.offseq.com/threat/cve-20 #OffSeq #ICS #Vuln #CVE2026_7849

##

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44103
(5.3 MEDIUM)

EPSS: 0.24%

updated 2026-07-30T09:31:24

1 posts

An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44093
(7.8 HIGH)

EPSS: 0.23%

updated 2026-07-30T09:31:24

1 posts

A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44102
(5.3 MEDIUM)

EPSS: 0.21%

updated 2026-07-30T09:31:24

1 posts

An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44092
(9.1 CRITICAL)

EPSS: 0.38%

updated 2026-07-30T09:31:24

1 posts

An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44104
(9.8 CRITICAL)

EPSS: 0.24%

updated 2026-07-30T09:31:24

1 posts

The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44098
(8.6 HIGH)

EPSS: 1.37%

updated 2026-07-30T09:31:18

1 posts

This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44097
(7.1 HIGH)

EPSS: 0.24%

updated 2026-07-30T09:31:18

1 posts

A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-44096
(7.8 HIGH)

EPSS: 0.23%

updated 2026-07-30T09:31:18

1 posts

A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.

certvde@infosec.exchange at 2026-07-30T06:55:05.000Z ##

#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102

certvde.com/en/advisories/vde-

#CSAF phoenixcontact.csaf-tp.certvde

##

CVE-2026-64531
(7.8 HIGH)

EPSS: 0.12%

updated 2026-07-30T06:33:35

2 posts

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guar

1 repos

https://github.com/mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool

tugatech@masto.pt at 2026-07-31T09:36:37.000Z ##

Falha OVSwrap ameaça servidores Linux com acesso root e já tem exploit público. Uma vulnerabilidade crítica no kernel do Linux, batizada de OVSwrap (CVE-2026-64531), permite que utilizadores locais sem privilégios obtenham acesso total de root. 🚨

🔗 tugatech.com.pt/t88334-falha-o

#exploit #falha #linux #root 

##

tugatech@masto.pt at 2026-07-31T09:36:37.000Z ##

Falha OVSwrap ameaça servidores Linux com acesso root e já tem exploit público. Uma vulnerabilidade crítica no kernel do Linux, batizada de OVSwrap (CVE-2026-64531), permite que utilizadores locais sem privilégios obtenham acesso total de root. 🚨

🔗 tugatech.com.pt/t88334-falha-o

#exploit #falha #linux #root 

##

CVE-2026-58066
(9.8 CRITICAL)

EPSS: 0.21%

updated 2026-07-30T06:32:44

1 posts

Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped document carrying forged identity attributes alongside any valid signature made by the trusted IdP certificate, and log in as an arbitrary user.

thehackerwire@mastodon.social at 2026-07-30T07:00:31.000Z ##

🔴 CVE-2026-58066 - Critical (9.8)

Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped docu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58046
(9.9 CRITICAL)

EPSS: 0.31%

updated 2026-07-30T06:32:44

1 posts

Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.

thehackerwire@mastodon.social at 2026-07-30T07:00:21.000Z ##

🔴 CVE-2026-58046 - Critical (9.9)

Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-1360
(7.5 HIGH)

EPSS: 0.57%

updated 2026-07-30T06:32:43

1 posts

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject ar

thehackerwire@mastodon.social at 2026-07-30T06:00:17.000Z ##

🟠 CVE-2026-1360 - High (7.5)

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48448
(8.6 HIGH)

EPSS: 0.37%

updated 2026-07-30T03:31:28

1 posts

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require user interaction. Scope is changed.

thehackerwire@mastodon.social at 2026-07-30T04:00:03.000Z ##

🟠 CVE-2026-48448 - High (8.6)

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to g...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67595
(8.1 HIGH)

EPSS: 0.42%

updated 2026-07-30T00:31:19

3 posts

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, install

DarkWebInformer@infosec.exchange at 2026-07-30T19:58:19.000Z ##

🚨 CVE-2026-67595: VaahCMS 2.0.0-2.3.4 contains malicious obfuscated JavaScript in an OTP email template that can connect to a C2 server, log passwords, scrape WhatsApp Web, and remotely alter pages.

Published: 2026-07-29

CVSS 4.0: 9.2
CVSS 3.1: 8.1
Exploitability Score: 2.2

Commit: github.com/webreinvent/vaahcms

##

offseq@infosec.exchange at 2026-07-30T00:00:36.000Z ##

CVE-2026-67595 (CRITICAL): VaahCMS 2.0.0 – 2.3.4 ships with malicious JS in OTP email templates. Enables C2, keylogging, WhatsApp scraping, and remote page control. Avoid JS-enabled viewing until patched. radar.offseq.com/threat/cve-20 #OffSeq #Infosec #CVE202667595 #VaahCMS

##

thehackerwire@mastodon.social at 2026-07-29T23:59:49.000Z ##

🟠 CVE-2026-67595 - High (8.1)

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-6267
(8.5 HIGH)

EPSS: 0.34%

updated 2026-07-29T21:31:08

2 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling.

DailyCyberSecurity@infosec.exchange at 2026-07-30T03:11:14.000Z ##

The latest GitLab patch release fixes 13 vulnerabilities, including CVE-2026-6267, a high-severity data exposure flaw. Update self-managed GitLab now.

#GitLab #CVE20266267 #DevSecOps #Vulnerability #PatchNow #InfoSec

securityonline.info/gitlab-pat

##

thehackerwire@mastodon.social at 2026-07-29T20:59:50.000Z ##

🟠 CVE-2026-6267 - High (8.5)

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5056
(7.8 HIGH)

EPSS: 0.43%

updated 2026-07-29T21:31:08

1 posts

GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of UncompressedFrameConfigBox

thehackerwire@mastodon.social at 2026-07-30T02:00:30.000Z ##

🟠 CVE-2026-5056 - High (7.8)

GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit th...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-13308
(8.1 HIGH)

EPSS: 0.57%

updated 2026-07-29T21:31:08

1 posts

Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of WebSocket messages related to the OCPP service.

thehackerwire@mastodon.social at 2026-07-29T21:59:57.000Z ##

🟠 CVE-2026-13308 - High (8.1)

Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15975
(7.5 HIGH)

EPSS: 0.39%

updated 2026-07-29T21:31:07

1 posts

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling when processing merge request discussions.

thehackerwire@mastodon.social at 2026-07-30T05:00:49.000Z ##

🟠 CVE-2026-15975 - High (7.5)

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5057
(7.5 HIGH)

EPSS: 0.48%

updated 2026-07-29T21:31:07

1 posts

ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ATEN Unizon. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RpcProvider class. The issue results from the lack of authentication prior to allowing access to

thehackerwire@mastodon.social at 2026-07-30T02:00:44.000Z ##

🟠 CVE-2026-5057 - High (7.5)

ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ATEN Unizon. Authentication is not required to exploit ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5491
(7.5 HIGH)

EPSS: 1.54%

updated 2026-07-29T21:31:07

1 posts

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 6067 by default. The issue results from the lack of proper validation of a us

thehackerwire@mastodon.social at 2026-07-30T02:00:18.000Z ##

🟠 CVE-2026-5491 - High (7.5)

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability.
...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61511
(9.8 CRITICAL)

EPSS: 1.27%

updated 2026-07-29T20:17:10.347000

3 posts

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style

6 repos

https://github.com/codeb0ssx/Ultimate-CVE-2026-61511

https://github.com/tc4dy/CVE-2026-61511-PoC-Exploit

https://github.com/shootcannon/CVE-2026-61511

https://github.com/webshellseo8/CVE-2026-61511-POC

https://github.com/puj790201-lab/cve-2026-61511

https://github.com/HORKimhab/CVE-2026-61511

cyberveille@mastobot.ping.moi at 2026-07-29T17:00:18.000Z ##

📢 RCE non authentifiée dans vBulletin ≤ 6.2.1 via la méthode runMaths() (CVE-2026-61511)
📝 ## 🔍 Contexte

Publié le 27 juillet 2026 sur le blog de recherche Karma(In)Security (karmainsecurity.com), cet article détaille une vulnérabilité critique d'exécut...
📖 cyberveille : cyberveille.ch/posts/2026-07-2
🌐 source : karmainsecurity.com/KIS-2026-13
#CVE_2026_61511 #IOC #Cyberveille

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T15:03:42.000Z ##

A critical vBulletin pre-auth RCE vulnerability, CVE-2026-61511, threatens unpatched forums. Learn how attackers exploit template math evaluation.

#vBulletin #CVE202661511 #RCE #Cybersecurity #Infosec

meterpreter.org/vbulletin-pre-

##

beyondmachines1@infosec.exchange at 2026-07-29T12:01:49.000Z ##

vBulletin Fixes Critical Pre-Auth Remote Code Execution Flaw

vBulletin released patches for a critical remote code execution vulnerability, tracked as CVE-2026-61511 (CVSS score 9.8), that allows unauthenticated attackers to execute arbitrary PHP code on affected forum servers. The flaw affects vBulletin 5.x and 6.x installations, and a public proof-of-concept exploit is available.

**If you run a self-hosted vBulletin forum, upgrade to version 6.2.2 or apply the available security patch immediately. A public exploit allows unauthenticated attackers to target vulnerable servers. Users running the unsupported 5.x branch should migrate to a patched 6.x release.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-20079
(10.0 CRITICAL)

EPSS: 37.67%

updated 2026-07-29T17:16:51.683000

5 posts

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.&nbsp; This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this v

Nuclei template

1 repos

https://github.com/0xBlackash/CVE-2026-20079

AAKL at 2026-07-31T16:19:58.449Z ##

There are two new advisories from Cisco, one addressing a critical vulnerability that was first published on March 4:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

The second is a high-severity vulnerability that was first published yesterday:

CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity

##

AAKL@infosec.exchange at 2026-07-31T16:19:58.000Z ##

There are two new advisories from Cisco, one addressing a critical vulnerability that was first published on March 4:

CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

The second is a high-severity vulnerability that was first published yesterday:

CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #vulnerability #Cisco

##

Bied@digitalhub.social at 2026-07-30T19:33:28.000Z ##

#Cisco - "We Never Learn". 🔥

Warum ein Konzern es noch immer notwendig findet eine #Backdoor in seine Produkte einzubauen ist mir völlig schleierhaft. 🙈

"Da CVE-2026-20316 bereits aktiv ausgenutzt wird, rät Cisco Administratoren, ihre FMC-Instanzen dringend zu aktualisieren."

"Gibt es Abhilfe?

"Die genannten Hotfix-Updates bessern auch bezüglich einer seit März bekannten kritischen Lücke (CVSS: 10) nach, mit der sich die Authentifizierung im Web-Interface von FMC umgehen lässt. Diese Lücke ist als CVE-2026-20079 registriert und verleiht Angreifern sogar einen direkten Root-Zugriff auf das zugrundeliegende Betriebssystem. "

Klar, eine Firewall ist ja nur zum Schutz der Kunden vorhanden, da kann man schon mal auch Kriminelle einladen, oder? 🤢

So eine persönliche Haftung des CEO und eine Strafe ab 5 % vom Konzernumsatz könnte möglicherweise zu einer Änderungen führen:

So stelle ich mir die Anweisung des CEO vor: 👍

"Ab sofort ist die Nutzung (auch während der Entwicklung) von Backdoors untersagt. Wer sich nicht daran hält wird fristlos entlassen und haftet für Schäden."

Und, natürlich sollte die Qualitätssicherung vorab prüfen ob die Entwickler sich auch daran halten. 😁

Es gibt erfahrene Spezialisten die gerne bei der Auswahl der Geräte helfen und für mehr Sicherheit sorgen. Einfach anfragen, dann weiß man mehr. 🙂

golem.de/news/kodierte-zugangs

#Backdoor

##

security_crawler_carl@infosec.exchange at 2026-07-30T11:45:32.000Z ##

🏆 New Achievement! Static Credentials, Static Fate!

RAID ALERT. RAID ALERT. Cisco Secure Firewall Management Center has a hardcoded low-privilege account baked right into the software — CVE-2026-20316 — and unauthenticated remote attackers are already using it to log in and harvest sensitive data. That's Phase One. Phase Two is the wipe: threat actors are chaining it with CVE-2026-20079, which hands them root access via arbitrary script execution. (1/2)

##

AAKL@infosec.exchange at 2026-07-29T17:36:00.000Z ##

New Cisco updates:

CRITICAL vulnerability, first released on March 4: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi

High severity: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability sec.cloudapps.cisco.com/securi

New informational advisory: Cisco Advance Notification for Publication of August 5, 2026, Security Advisories sec.cloudapps.cisco.com/securi @TalosSecurity #infosec #vulnerability #Cisco

##

CVE-2026-67215
(7.5 HIGH)

EPSS: 0.35%

updated 2026-07-29T15:31:12

1 posts

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON

thehackerwire@mastodon.social at 2026-07-29T15:00:21.000Z ##

🟠 CVE-2026-67215 - High (7.5)

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy oper...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-0667(CVSS UNKNOWN)

EPSS: 0.37%

updated 2026-07-29T15:31:11

1 posts

CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when communicating over the Modbus TCP protocol.

offseq@infosec.exchange at 2026-07-29T13:30:28.000Z ##

CVE-2026-0667 (CRITICAL, CVSS 9.3): Schneider Electric SCADAPack 47x is vulnerable to improper Modbus TCP checks — risk of code execution, DoS, data loss. Review exposure & monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #ICS #Vulnerability #SCADA

##

CVE-2026-45293
(8.6 HIGH)

EPSS: 0.18%

updated 2026-07-29T14:16:30.737000

1 posts

WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rulesets) reconstructed the $ver argument passed to functions such as wp_enqueue_script() and ran it through eval() inside its is_falsy() method, so a maliciously craf

CVE-2026-14270
(8.8 HIGH)

EPSS: 0.55%

updated 2026-07-29T12:31:30

1 posts

The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validation in the eco_save_settings() function, which allows low-privileged authenticated users to modify the tc_eco_custom_file_types upload allowlist setting,

thehackerwire@mastodon.social at 2026-07-29T15:00:33.000Z ##

🟠 CVE-2026-14270 - High (8.8)

The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18072
(9.8 CRITICAL)

EPSS: 0.59%

updated 2026-07-29T06:32:11

2 posts

The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs before any authentication checks on every request — reads an attacker-supplied t

thehackerwire@mastodon.social at 2026-07-29T06:59:52.000Z ##

🔴 CVE-2026-18072 - Critical (9.8)

The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` func...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T02:48:53.000Z ##

Active exploitation of CVE-2026-18072, a CVSS 9.8 video embedder backdoor, grants attackers full administrative control over 20,000 WordPress sites.

#CVE202618072 #WordPress #CyberSecurity #Backdoor

securityonline.info/cve-2026-1

##

CVE-2026-12144
(8.8 HIGH)

EPSS: 0.37%

updated 2026-07-29T03:30:21

1 posts

The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it directly to `WP_User::add_role()`, with no allowlist validation against permitted wholesale roles and no capability check

thehackerwire@mastodon.social at 2026-07-29T07:00:02.000Z ##

🟠 CVE-2026-12144 - High (8.8)

The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` P...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54650
(8.6 HIGH)

EPSS: 0.36%

updated 2026-07-28T22:20:54

1 posts

## Summary openhole-server forwarded the URL-decoded request path (`r.URL.Path`) to tunnel clients instead of the original request-target. Percent-encoded dot-segments (`%2e`) and separators (`%2f`) were decoded to `../` and `/` before reaching the local service. Go's ServeMux rejects literal `../` paths, but percent-encoded traversal sequences bypassed this and were delivered to backends as wor

thehackerwire@mastodon.social at 2026-07-29T02:00:25.000Z ##

🟠 CVE-2026-54650 - High (8.6)

openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.EscapedPath(), allowing percent e...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54658
(9.8 CRITICAL)

EPSS: 0.40%

updated 2026-07-28T22:19:24

1 posts

### Impact A SQL injection vulnerability exists in the `escapeValue()` function used for parameter substitution. Attackers who can control parameter values can inject arbitrary SQL by using a trailing backslash to escape the closing quote. Who is impacted: All users of @hypequery/clickhouse versions prior to 2.0.2 who pass user-controlled input as query parameters. ### Patches The vulnerability

thehackerwire@mastodon.social at 2026-07-29T02:00:36.000Z ##

🔴 CVE-2026-54658 - Critical (9.8)

Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing attacker controlled query param...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54638
(7.5 HIGH)

EPSS: 0.35%

updated 2026-07-28T22:15:29

1 posts

### Impact A remote, unauthenticated attacker can cause excessive memory allocation (and resulting CPU / GC pressure, potentially OOM termination) by sending a crafted unencrypted MTProto packet. `(*proto.UnencryptedMessage).Decode` read an attacker-controlled 32-bit `dataLen` field and immediately allocated a buffer of that size via `make([]byte, dataLen)` **before** validating that the underly

thehackerwire@mastodon.social at 2026-07-29T02:00:15.000Z ##

🟠 CVE-2026-54638 - High (7.5)

gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]byte, data...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54719
(7.5 HIGH)

EPSS: 0.28%

updated 2026-07-28T21:59:49

1 posts

GHSA-wvhv-qcqf-f3cx fixed the per-folder .goshs ACL bypass on the state-changing routes (PUT/POST upload/?mkdir/?delete) and added recursive ACL resolution, and its description states the read/list path correctly enforces .goshs. That premise does not hold for the ?bulk zip-download route. bulkDownload (httpserver/updown.go) takes one or more ?file= parameters, runs each through sanitizePath(fs.We

thehackerwire@mastodon.social at 2026-07-29T00:00:31.000Z ##

🟠 CVE-2026-54719 - High (7.5)

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauthenticate...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62325
(9.1 CRITICAL)

EPSS: 0.34%

updated 2026-07-28T21:57:19

1 posts

## Summary Start goshs v2.1.3 with `-b 'admin:' -sftp`. No `-fkf`. SFTP accepts connections without password. CVE-2026-40884 blocks the empty-username variant (`-b ':pass'`). The empty-password variant bypasses that fix. ## CVE-2026-40884 **CVE-2026-40884** (GHSA-c29w-qq4m-2gcv, Apr 13 2026) reported the empty-username case: `-b ':pass'` with `-sftp`. `sftpserver.go:85` uses `&&`: ```go if s.U

thehackerwire@mastodon.social at 2026-07-29T00:00:11.000Z ##

🔴 CVE-2026-62325 - Critical (9.1)

goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -fkf left...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15057
(7.5 HIGH)

EPSS: 0.26%

updated 2026-07-28T21:31:45

1 posts

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.

thehackerwire@mastodon.social at 2026-07-28T22:00:18.000Z ##

🟠 CVE-2026-15057 - High (7.5)

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14996
(8.2 HIGH)

EPSS: 0.22%

updated 2026-07-28T21:31:45

1 posts

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.

thehackerwire@mastodon.social at 2026-07-28T22:00:08.000Z ##

🟠 CVE-2026-14996 - High (8.2)

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-14981
(7.5 HIGH)

EPSS: 0.26%

updated 2026-07-28T21:31:45

1 posts

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.

thehackerwire@mastodon.social at 2026-07-28T21:59:58.000Z ##

🟠 CVE-2026-14981 - High (7.5)

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55390
(7.5 HIGH)

EPSS: 0.36%

updated 2026-07-28T21:26:42

2 posts

### Summary When generating models from an XML Schema (`--input-file-type xmlschema`), `datamodel-code-generator` resolves `<xs:include>`, `<xs:import>`, `<xs:redefine>`, and `<xs:override>` `schemaLocation` attributes against the source directory and reads the target with no restriction to the input/base directory. An attacker who controls the input XSD can read arbitrary files via `../` travers

hugovalters@mastodon.social at 2026-07-29T17:02:27.000Z ##

CVE-2026-55390 - High severity path traversal in datamodel-code-generator 0.59.0-0.62.0. Arbitrary local file read via XML schema imports. CVSS 7.5. Update to 0.62.0 immediately. #CVE #Python #infosec

valtersit.com/cve/CVE-2026-553

##

thehackerwire@mastodon.social at 2026-07-28T23:00:37.000Z ##

🟠 CVE-2026-55390 - High (7.5)

datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for --input-file-type xmlschema resolves xs:include, xs:import, xs:rede...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5674
(8.8 HIGH)

EPSS: 0.12%

updated 2026-07-28T17:16:52.923000

1 posts

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.

CVE-2026-16812
(10.0 CRITICAL)

EPSS: 0.88%

updated 2026-07-28T14:50:33.960000

1 posts

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intende

DailyCyberSecurity@infosec.exchange at 2026-07-30T02:16:35.000Z ##

Arista addresses CVE-2026-16812, a critical vulnerability in VeloCloud Orchestrator actively exploited to gain unauthenticated remote code execution.

#Arista #VeloCloud #Cybersecurity #CVE202616812 #RCE

meterpreter.org/arista-veloclo

##

CVE-2025-15467
(8.8 HIGH)

EPSS: 47.62%

updated 2026-07-28T13:17:14.747000

1 posts

Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encode

6 repos

https://github.com/mr-r3b00t/CVE-2025-15467

https://github.com/guiimoraes/CVE-2025-15467

https://github.com/materaj2/cve-2025-15467

https://github.com/WostGit/cve-2025-15467-crash

https://github.com/x-stp/cves-2025-11187_15467_69418

https://github.com/balgan/CVE-2025-15467

beyondmachines1@infosec.exchange at 2026-07-29T09:01:49.000Z ##

Siemens Patches Critical OpenSSL Flaw in Desigo CC Building Management Systems

Siemens released security updates for Desigo CC to address a critical OpenSSL vulnerability (CVE-2025-15467) that allows unauthenticated remote code execution or denial of service through malformed cryptographic messages.

**First, make sure all Desigo CC building management systems are isolated from the internet and reachable only from trusted networks. Then, if you run V9 update to V9.0 QU1 (or later) and if you run V8 apply patch V8.0 QU2.0021; for V7 there is no patch yet.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-66373
(7.5 HIGH)

EPSS: 0.47%

updated 2026-07-28T05:17:17.507000

1 posts

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.

CVE-2026-63077
(9.8 CRITICAL)

EPSS: 0.65%

updated 2026-07-27T18:31:56

7 posts

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

1 repos

https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation

undercodenews@mastodon.social at 2026-07-31T09:55:51.000Z ##

JetBrains TeamCity Hit by Critical CVE-2026-63077: Unauthenticated Attackers Could Take Control of On-Premises Servers + Video

A New TeamCity Security Crisis Puts CI/CD Infrastructure Under Pressure A critical security vulnerability in JetBrains TeamCity On-Premises has emerged as one of the most serious developer-infrastructure security issues reported this week. Tracked as CVE-2026-63077, the flaw can allow an unauthenticated remote attacker with HTTP(S) access to a…

undercodenews.com/jetbrains-te

##

tugatech@masto.pt at 2026-07-31T09:45:10.000Z ##

JetBrains emitiu um aviso urgente sobre uma vulnerabilidade crítica no TeamCity que permite execução remota de código. A falha, classificada como CVE-2026-63077, pode ser explorada por atacantes para alcançar a execução remota de código nos sistemas vulneráveis.

🔗 tugatech.com.pt/t88336-jetbrai

#alerta #falha #teamcity 

##

tugatech@masto.pt at 2026-07-31T09:45:10.000Z ##

JetBrains emitiu um aviso urgente sobre uma vulnerabilidade crítica no TeamCity que permite execução remota de código. A falha, classificada como CVE-2026-63077, pode ser explorada por atacantes para alcançar a execução remota de código nos sistemas vulneráveis.

🔗 tugatech.com.pt/t88336-jetbrai

#alerta #falha #teamcity 

##

offseq@infosec.exchange at 2026-07-31T00:00:37.000Z ##

CRITICAL: JetBrains TeamCity On-Premises (all versions) vulnerable to CVE-2026-63077 — auth bypass enables remote code execution via HTTPS. Patch to 2025.11.7/2026.1.3 or apply plugin for 2017.1+. TeamCity Cloud unaffected. radar.offseq.com/threat/jetbra
#OffSeq #Vuln #TeamCity #CVE202663077

##

oversecurity@mastodon.social at 2026-07-30T12:31:32.000Z ##

CVE-2026-63077 Exposes TeamCity Servers to Unauthenticated RCE

A critical security flaw affecting TeamCity On-Premises has prompted administrators to update their servers immediately after researchers disclosed...

🔗️ [Thecyberexpress] link.is.it/Uo0klI

##

DailyCyberSecurity@infosec.exchange at 2026-07-30T06:17:33.000Z ##

JetBrains patches critical TeamCity On-Premises vulnerability CVE-2026-63077 (CVSS 9.8), preventing unauthenticated remote code execution.

#TeamCity #JetBrains #CVE202663077 #Cybersecurity #CICD

meterpreter.org/teamcity-vulne

##

security_crawler_carl@infosec.exchange at 2026-07-28T21:57:19.000Z ##

🏆 New Achievement! Exhibit A: Your CI Server Did It!

The record will reflect that on or about July 28, 2026, JetBrains disclosed CVE-2026-63077, a CVSS 9.8 vulnerability in TeamCity On-Premises. The record will further reflect that any unauthenticated attacker with mere HTTP(S) access could bypass authentication and execute arbitrary operating system commands. (1/3)

##

CVE-2026-66013(CVSS UNKNOWN)

EPSS: 0.39%

updated 2026-07-25T12:31:47

1 posts

OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consol

DailyCyberSecurity@infosec.exchange at 2026-07-31T01:39:37.000Z ##

An OpenRemote vulnerability, CVE-2026-66013 (CVSS 9.3), enables unauthenticated asset takeover. Full advisory details are now public. Patch to 1.26.2.

#OpenRemote #CVE202666013 #IoTSecurity #AssetTakeover

securityonline.info/openremote

##

CVE-2026-43499
(7.8 HIGH)

EPSS: 0.73%

updated 2026-07-24T15:17:20.787000

1 posts

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue oper

55 repos

https://github.com/x-spy/CVE-2026-43499-popsicle

https://github.com/CakesTwix/Android-CVE-2026-43499

https://github.com/pubglite55/oppo-ghostlock

https://github.com/ayyy7128/CVE-2026-43499-jinghu

https://github.com/No-22-Github/UnPlus

https://github.com/2932796375github/CVE-2026-43499_OPPO-MT6835

https://github.com/BuSung-dev/Root-My-Galaxy

https://github.com/BuSung-dev/CVE-2026-43499-S25U

https://github.com/joehquak/Mi8E5-Unlocker-by-CVE-2026-43499

https://github.com/sorrow404Null/CVE-2026-43499-RMX5200

https://github.com/ctn-Qvo/auto_extract_offsets

https://github.com/woshimaniubi8/CVE-2026-43499-root-KernelSU

https://github.com/soralis0912/CVE-2026-43499-pmg110-root

https://github.com/LuZe0y/pd2425-cve-2026-43499-config

https://github.com/cuteaplane/GhostLock-for-OnePlus15T

https://github.com/MobiusM/CVE-2026-43499

https://github.com/dmcdtc/openvz-cve-patch-2026

https://github.com/HYCQAQ/Logitech-G-Cloud-GhostLock-CVE-2026-43499

https://github.com/Wtrwx/smt878u-ionstack-poc

https://github.com/fusiondrive/CVE-2026-43499-S24U

https://github.com/soralis0912/CVE-2026-43499-aristotle

https://github.com/WitAqua-tools/Root-My-Device

https://github.com/Petalrain224/CVE-2026-43499-Redmi-Turbo5

https://github.com/gagaltotal/CVE-2026-43499-PoC-Scanner

https://github.com/soralis0912/CVE-2026-43499-warhol-root

https://github.com/0xBlackash/CVE-2026-43499

https://github.com/dnlid/CVE-2026-43499

https://github.com/onesmiledx/CVE-2026-43499

https://github.com/Kananosa/CVE-2026-43499-For-Xiaomi-17T-chagall

https://github.com/PeronGH/ghostlock-selinux-disabler

https://github.com/MiaPatsune/cve-2026-43499

https://github.com/HORKimhab/CVE-2026-43499

https://github.com/mumaosong/cve-2026-43499-CyberMeowfia

https://github.com/soralis0912/CVE-2026-43499-aristotle-apk

https://github.com/tc3650/CVE-2026-43499-armv7

https://github.com/caspy123/CVE-2026-43499

https://github.com/xianwan1314/CVE-2026-43499-Poc-Analysis

https://github.com/Bailan766/rmx3888-cve-2026-43499-config

https://github.com/Cxyofficial/x200-cve-2026-43499

https://github.com/p2p3p/GhostLock-for-OnePlus

https://github.com/Thiasap/oppo-pgem10-ghostlock

https://github.com/datfooldive/ghostlock-emerald

https://github.com/geecjdj/CVE-2026-43499

https://github.com/JoinChang/ghostlock-oneplus

https://github.com/Linuxoid-cn/CVE-2026-43499-Poc-Analysis

https://github.com/justsoman/CyberMeowfia-ace3

https://github.com/qsvggff-spec/oppo-A5-PRO-5G-CVE-2026-43499

https://github.com/Yakayna/SpringPeace

https://github.com/Linuxoid-cn/Mi8E5-Unlocker-by-CVE-2026-43499

https://github.com/Colorful-glassblock/duchamp-root

https://github.com/fancyzll/CVE-2026-43499_OPPO-MT6835

https://github.com/ctn-Qvo/CVE-2026-43499-so-build

https://github.com/Bartixxx32/CVE-2026-43499-OnePlus15

https://github.com/inforcqb/CVE-2026-43499-pja110

https://github.com/233laoliu/mt6985-CVE-2026-43499

JulianOliver@mastodon.social at 2026-07-31T01:30:52.000Z ##

Update Firefox, the Tor browser, and other derivatives if you are still running FF versions 147 through to 151.0.2.

Some interesting attacks exploiting CVE-2026-10702 are shoring up:

thehackernews.com/2026/07/rese

Note that thanks to Android's lazy sandbox,
this attack can be used as the entry point of a complete browser-to-kernel chain, giving the attacker root (CVE-2026-43499).

(Unclear if/how Firefox-ESR is affected)

#infosec

##

CVE-2026-16232
(9.1 CRITICAL)

EPSS: 69.97%

updated 2026-07-23T15:44:54.743000

6 posts

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server I

Nuclei template

2 repos

https://github.com/sfewer-r7/CVE-2026-16232

https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

daniel1820815@infosec.exchange at 2026-07-30T07:47:53.000Z ##

From our Check Point Research Team:

July 2026 Security Update

Check Point has addressed CVE-2026-16232, an authentication bypass vulnerability in SmartConsole that is under active exploitation, affecting a handful of customers. The flaw allows remote attackers to bypass authentication and gain administrative access to Check Point management servers. Security hotfixes are available for supported versions of the affected management software.

blog.checkpoint.com/security/s

#CheckPoint #CheckPointSoftwareTechnologies #CVE202616232

##

obivan@infosec.exchange at 2026-07-29T17:57:51.000Z ##

Authentication bypass for Check Point Security Management Server and Multi-Domain Security Management Server github.com/sfewer-r7/CVE-2026-

##

AAKL@infosec.exchange at 2026-07-29T17:49:40.000Z ##

Rapid7, from yesterday: Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232) rapid7.com/blog/post/ra-check- @Rapid7Official #infosec #vulnerability #threatresearch

##

threatcodex@infosec.exchange at 2026-07-29T13:18:07.000Z ##

Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
#CVE_2026_16232
rapid7.com/blog/post/ra-check-

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T02:27:22.000Z ##

CVE-2026-16232 is a SmartConsole authentication bypass in Check Point Security Management. Exploited in the wild, with a public PoC now available.

#CheckPoint #SmartConsole #CVE202616232 #AuthenticationBypass #ZeroDay #CyberSecurity

securityonline.info/check-poin

##

hackmag@infosec.exchange at 2026-07-28T21:30:05.000Z ##

⚪️ Hackers Exploit a Zero-Day in Check Point SmartConsole

🗨️ Check Point has warned customers about a critical vulnerability, CVE-2026-16232, affecting its Security Management and Multi-Domain Management products. The flaw allows attackers to bypass authentication, gain administrator privileges, and modify security policies. The vulnerability is already be…

🔗 hackmag.com/news/cve-2026-1623

#news

##

CVE-2026-16723
(9.0 None)

EPSS: 0.41%

updated 2026-07-23T09:32:08

2 posts

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

6 repos

https://github.com/why-success/fastjson-rce-lab

https://github.com/dinosn/fastjson-jsontype-rce-lab

https://github.com/fazilbaig1/CVE-2026-16723

https://github.com/HORKimhab/CVE-2026-16723

https://github.com/1xPwn/CVE-2026-16723

https://github.com/EQSTLab/CVE-2026-16723

DailyCyberSecurity@infosec.exchange at 2026-07-29T12:34:32.000Z ##

Discover the critical Fastjson RCE CVE-2026-16723 vulnerability. Learn how attackers exploit Spring Boot applications and find mitigation strategies.

#Fastjson #CVE202616723 #Cybersecurity #SpringBoot #Malware

meterpreter.org/fastjson-rce-c

##

threatnoir@infosec.exchange at 2026-07-29T07:07:47.000Z ##

⚠️ CRITICAL: Hackers target US firms in FastJson RCE zero-day attacks

A critical RCE zero-day (CVE-2026-16723) in FastJson Java library versions 1.2.68-1.2.83 is actively exploited against U.S. firms across multiple sectors. Attackers can execute arbitrary code without user interaction. FastJson 1.x is unmaintained, leaving affected systems without patches.

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-50502
(8.0 HIGH)

EPSS: 0.60%

updated 2026-07-22T16:18:05.400000

1 posts

Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.

DailyCyberSecurity@infosec.exchange at 2026-07-29T13:04:49.000Z ##

A public PoC exploit now targets CVE-2026-50502, an RCE in the Windows Event Log service. Microsoft patched the flaw on July 14, 2026. Details below.

#CVE202650502 #WindowsEventLog #RCE #PatchTuesday #InfoSec #Microsoft

securityonline.info/cve-2026-5

##

CVE-2026-49176
(7.8 HIGH)

EPSS: 0.40%

updated 2026-07-22T16:17:28.753000

2 posts

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

2 repos

https://github.com/777erp/CVE-2026-49176_BOF

https://github.com/DavidCarliez/CVE-2026-49176_LPE_POC

DarkWebInformer at 2026-07-31T17:33:23.212Z ##

🚨 A Cobalt Strike BOF targeting CVE-2026-49176 adds another exploitation method for the CVSS 7.8 Windows WalletService local privilege escalation vulnerability.

GitHub: github.com/777erp/CVE-2026-491

The flaw can allow a standard user to execute commands with SYSTEM privileges on unpatched Windows systems.

##

DarkWebInformer@infosec.exchange at 2026-07-31T17:33:23.000Z ##

🚨 A Cobalt Strike BOF targeting CVE-2026-49176 adds another exploitation method for the CVSS 7.8 Windows WalletService local privilege escalation vulnerability.

GitHub: github.com/777erp/CVE-2026-491

The flaw can allow a standard user to execute commands with SYSTEM privileges on unpatched Windows systems.

##

CVE-2026-15352
(7.5 HIGH)

EPSS: 0.43%

updated 2026-07-17T18:31:44.140000

1 posts

A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service.

thehackerwire@mastodon.social at 2026-07-30T23:00:23.000Z ##

🟠 CVE-2026-18064 - High (7.5)

An incomplete fix for CVE-2026-15352 in the NASA core Flight System
(cFS) Health and Safety (HS) application leaves a separate NULL pointer
dereference reachable in versions through 7.0.1. An attacker who can
trigger the affected command under ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-42530
(8.1 HIGH)

EPSS: 3.68%

updated 2026-07-16T12:33:31

1 posts

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers

3 repos

https://github.com/0xBlackash/CVE-2026-42530

https://github.com/HORKimhab/CVE-2026-42530

https://github.com/v4ltonn/CVE-2026-42530

DailyCyberSecurity@infosec.exchange at 2026-07-29T13:30:38.000Z ##

Certighost AD CS vulnerability details and PoC code for CVE-2026-54121 are public. The flaw let a low-privileged user impersonate a Domain Controller.

#Certighost #CVE202654121 #ADCS #ActiveDirectory

securityonline.info/certighost

##

CVE-2026-50469
(7.8 HIGH)

EPSS: 0.27%

updated 2026-07-14T18:32:32

1 posts

Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.

CVE-2026-58025
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-07-09T21:31:14

1 posts

Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/Import/WikiRevision.Php, includes/Logging/LogEntryBase.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

1 repos

https://github.com/shinthink/CVE-2026-58025

DarkWebInformer@infosec.exchange at 2026-07-30T19:21:53.000Z ##

🚨 PoC for CVE-2026-58025, a CVSS 9.8 MediaWiki deserialization flaw that could enable RCE through malicious log entry imports.

Exploitation requires import permissions. Upgrade to 1.43.9, 1.44.6, 1.45.4, or 1.46.0.

GitHub: github.com/shinthink/CVE-2026-

##

CVE-2026-43503
(8.8 HIGH)

EPSS: 0.34%

updated 2026-07-02T12:31:55

1 posts

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when moving frags from source to destination. __pskb_copy_fclone() defers the rest of the shinfo metadata to skb_copy_header(

9 repos

https://github.com/lieehrdiansyah12/CVE-2026-43503

https://github.com/mooder1/dirtyclone-CVE-2026-43503

https://github.com/0xBlackash/CVE-2026-43503

https://github.com/SecureWithUmer/CVE-2026-43503

https://github.com/sec0x/CVE-2026-43503

https://github.com/entra1337/DirtyClone

https://github.com/rjt-gupta/page-cache-corruption-lpes

https://github.com/gl1tch0x1/DirtyClone

https://github.com/douglasmun/pagecache-lpe-containment-kit

DarkWebInformer@infosec.exchange at 2026-07-29T18:58:30.000Z ##

‼️ CVE-2026-43503: DirtyClone is a Linux kernel local privilege escalation (LPE) vulnerability caused by page-cache corruption.

PoC: github.com/entra1337/DirtyClone

##

CVE-2026-12045
(9.0 CRITICAL)

EPSS: 0.48%

updated 2026-07-01T19:26:30.593000

1 posts

Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin user's database role. The AI Assistant's execute_sql_query tool runs LLM-generated SQL inside a BEGIN TRANSACTION READ ONLY wrapper to prevent data modification. The LLM-supplied query was forwarded to

EUVD_Bot@mastodon.social at 2026-07-31T17:00:27.000Z ##

🚨 EUVD-2026-51564

📊 Score: 9.4/10 (CVSS v3.1)
📦 Product: pgAdmin 4
🏢 Vendor: pgadmin.org
📅 Updated: 2026-07-31

📝 The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-12044
(8.8 HIGH)

EPSS: 0.71%

updated 2026-07-01T19:23:39.010000

1 posts

SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-supplied description field. The Jinja templates for Domains (and their constraints), Foreign Tables, Languages, and Event Triggers, plus the Views OID-lookup query, interpolated the description directly inside a single-quoted SQL literal -- ``'{{ data.description }}'`` -- instead o

EUVD_Bot@mastodon.social at 2026-07-31T17:00:33.000Z ##

🚨 EUVD-2026-51559

📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: pgAdmin 4, pgAdmin 4
🏢 Vendor: pgadmin.org
📅 Updated: 2026-07-31

📝 The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the ...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2026-10702
(4.3 MEDIUM)

EPSS: 0.72%

updated 2026-06-30T03:36:54

4 posts

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.

1 repos

https://github.com/HORKimhab/CVE-2026-10702

DailyCyberSecurity at 2026-07-31T12:09:47.566Z ##

Firefox CVE-2026-10702 Exploit: Android Flaw Exposed

meterpreter.org/firefox-cve-20

##

DailyCyberSecurity@infosec.exchange at 2026-07-31T12:09:47.000Z ##

Firefox CVE-2026-10702 Exploit: Android Flaw Exposed

meterpreter.org/firefox-cve-20

##

JulianOliver@mastodon.social at 2026-07-31T01:30:52.000Z ##

Update Firefox, the Tor browser, and other derivatives if you are still running FF versions 147 through to 151.0.2.

Some interesting attacks exploiting CVE-2026-10702 are shoring up:

thehackernews.com/2026/07/rese

Note that thanks to Android's lazy sandbox,
this attack can be used as the entry point of a complete browser-to-kernel chain, giving the attacker root (CVE-2026-43499).

(Unclear if/how Firefox-ESR is affected)

#infosec

##

jbhall56@infosec.exchange at 2026-07-30T12:34:28.000Z ##

Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. thehackernews.com/2026/07/rese

##

CVE-2026-42897
(8.1 HIGH)

EPSS: 5.64%

updated 2026-06-17T10:48:34.893000

9 posts

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

1 repos

https://github.com/atiilla/CVE-2026-42897

sayzard@mastodon.sayzard.org at 2026-07-31T14:41:19.000Z ##

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

러시아 연계 위협 그룹 TA488(Laundry Bear/Void Blizzard)이 Microsoft Exchange Server의 최대 심각도 XSS 취약점 CVE-2026-42897을 실제 공격에 악용하고 있습니다. 공격자는 Outlook Web Access(OWA)에서 사용자가 악성 이메일을 열기만 해도 실행되는 'half-click' 체인을 통해 OWAReaper라는 브라우저 기반 지속성 임플란트를 설치합니다. OWARea...

arstechnica.com/security/2026/

##

threatnoir at 2026-07-31T08:06:41.273Z ##

⚠️ CRITICAL: Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

Russian state-sponsored group Laundry Bear is actively exploiting a zero-day XSS vulnerability (CVE-2026-42897) in Exchange OWA to deploy OWAReaper backdoor. Targets include U.S. and European government entities and private sector organizations. Successful exploitation grants persistent mailbox acc…

threatnoir.com/focus

##

threatnoir@infosec.exchange at 2026-07-31T08:06:41.000Z ##

⚠️ CRITICAL: Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

Russian state-sponsored group Laundry Bear is actively exploiting a zero-day XSS vulnerability (CVE-2026-42897) in Exchange OWA to deploy OWAReaper backdoor. Targets include U.S. and European government entities and private sector organizations. Successful exploitation grants persistent mailbox acc…

threatnoir.com/focus

#infosec #cybersecurity

##

security_crawler_carl@infosec.exchange at 2026-07-30T20:06:31.000Z ##

🏆 New Achievement! Inbox: One New Backdoor (Unread)!

Conducting inventory audit of your Microsoft Exchange installation. Status: CVE-2026-42897, one cross-site scripting flaw in Outlook Web Access — present, unpatched, actively exploited. OWAReaper backdoor — installed, compliments of Laundry Bear (also filed under: Void Blizzard). Long-term mailbox access — granted, unauthorized, ongoing. Affected sectors listed: government, telecom, financial, hospitality, aerospace. (1/2)

##

security_crawler_carl@infosec.exchange at 2026-07-30T20:06:31.000Z ##

HTML sanitization — missing. Proofpoint's report — filed July 29, one week after the activity was detected.

Summary column: your email server is carrying significant negative-value assets. Patch CVE-2026-42897 immediately and audit OWA logs for suspicious JavaScript execution and unauthorized mailbox access.

Reward: A cursed Rusty Audit Clipboard. It changes nothing. The backdoor is still there.

#CyberSecurity #ZeroDay #Exchange #Ransomware #APT #AchievementUnlocked (2/2)

##

jbhall56@infosec.exchange at 2026-07-30T12:09:26.000Z ##

The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026. thehackernews.com/2026/07/russ

##

VirusBulletin@infosec.exchange at 2026-07-30T09:01:00.000Z ##

Proofpoint analyses a campaign from Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) exploiting Outlook CVE-2026-42897 and targeting US & European government entities, as well as the telecommunications, financial, hospitality & aerospace sectors. proofpoint.com/us/blog/threat-

##

AAKL@infosec.exchange at 2026-07-29T18:03:12.000Z ##

New.

"On 22 July 2026, one day prior to Proofpoint’s recent joint release with the NSA on Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear), the actor began a campaign abusing CVE-2026-42897, a cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA)."

Proofpoint: Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit proofpoint.com/us/blog/threat-

More:

The Record: Laundry Bear’s webmail hackers had more in store after February, report says therecord.media/russia-hackers @therecord_media @jwarminsky #infosec #threatresearch #Outlook #Microsoft

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T12:41:20.000Z ##

A TA488 half-click exploit abuses CVE-2026-42897 in Outlook Web Access to drop OWAReaper, a stealthy implant that survives device reimaging.

#TA488 #OWAReaper #HalfClickExploit #CVE202642897 #OutlookWebAccess #InfoSec

securityonline.info/ta488-owar

##

CVE-2026-1623
(6.3 MEDIUM)

EPSS: 2.18%

updated 2026-06-17T10:16:12.407000

1 posts

A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument FileName causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

1 repos

https://github.com/sfewer-r7/CVE-2026-16232

hackmag@infosec.exchange at 2026-07-28T21:30:05.000Z ##

⚪️ Hackers Exploit a Zero-Day in Check Point SmartConsole

🗨️ Check Point has warned customers about a critical vulnerability, CVE-2026-16232, affecting its Security Management and Multi-Domain Management products. The flaw allows attackers to bypass authentication, gain administrator privileges, and modify security policies. The vulnerability is already be…

🔗 hackmag.com/news/cve-2026-1623

#news

##

CVE-2025-15435
(7.3 HIGH)

EPSS: 0.35%

updated 2026-06-17T08:37:46.203000

1 posts

A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_update.jsp. This manipulation of the argument Report causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

jyasskin@hachyderm.io at 2026-07-30T18:14:29.000Z ##

@fugueish Was going to shill Kagi, but their first result is CVE-2025-15435 (i.e. wrong year). The second result is correct. Quotes don't uprank that second result for some reason. It's still the first day, so maybe their crawls aren't as aggressive?

##

CVE-2025-66518(CVSS UNKNOWN)

EPSS: 0.89%

updated 2026-01-29T03:42:38

1 posts

Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2. Users are recommended to upgrade to version 1.10.3 or upper, which fixes the issue.

EUVD_Bot@mastodon.social at 2026-07-31T11:01:19.000Z ##

🚨 EUVD-2026-51518

📊 Score: n/a
📦 Product: Apache Kyuubi
🏢 Vendor: Apache Software Foundation
📅 Updated: 2026-07-31

📝 The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.

This issue aff...

🔗 euvd.enisa.europa.eu/vulnerabi

#cybersecurity #infosec #euvd #cve #vulnerability

##

CVE-2023-37327
(7.6 HIGH)

EPSS: 1.71%

updated 2025-11-04T21:32:34

2 posts

GStreamer FLAC File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of FLAC audio files. The issue

hugovalters@mastodon.social at 2026-07-30T05:55:09.000Z ##

@slomo No need for the hostility. The text summary might pull context from reference links mentioning 1.22.5, but our 'Patch Status' flag operates strictly on machine-readable data from the NVD API.
If you look at the official NVD record for CVE-2023-37327, the CPE configurations only map up to 1.22.4 and do not explicitly record the patched status. We explicitly do not accept vendor GitHub releases as evidence until they are validated by NVD.

##

slomo@toot.cat at 2026-07-29T19:32:02.000Z ##

@hugovalters Bullshit. Get your data updated and fix your website instead of spreading fud.

It's very funny that e.g. valtersit.com/cve/CVE-2023-373 claims to be "unpatched" and at the top says that it's fixed in 1.22.5, contains completely wrong information (just follow your own NVD link and compare: it's describing completely different issues), and a wrong patch for code that does not even exist in this shape in 1.22.5 or any other version.

Not enough that we have to deal with a flood of new issues reported thanks to LLMs, on top of that we also have to deal with clowns like you.

##

CVE-2014-0160
(7.5 HIGH)

EPSS: 100.00%

updated 2025-10-22T03:31:11

1 posts

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

Nuclei template

75 repos

https://github.com/anthophilee/A2SV--SSL-VUL-Scan

https://github.com/DisK0nn3cT/MaltegoHeartbleed

https://github.com/timsonner/cve-2014-0160-heartbleed

https://github.com/rouze-d/heartbleed

https://github.com/jdauphant/patch-openssl-CVE-2014-0160

https://github.com/PinkP4nther/Heartbleed_PoC

https://github.com/mpgn/heartbleed-PoC

https://github.com/GeeksXtreme/ssl-heartbleed.nse

https://github.com/indiw0rm/-Heartbleed-

https://github.com/undacmic/heartbleed-proof-of-concept

https://github.com/roganartu/heartbleedchecker-chrome

https://github.com/xanas/heartbleed.py

https://github.com/hmlio/vaas-cve-2014-0160

https://github.com/indrajeetmp11/Heartbleed-PoC-Exploit-Script

https://github.com/zouguangxian/heartbleed

https://github.com/caiqiqi/OpenSSL-HeartBleed-CVE-2014-0160-PoC

https://github.com/DominikTo/bleed

https://github.com/ingochris/heartpatch.us

https://github.com/marstornado/cve-2014-0160-Yunfeng-Jiang

https://github.com/isgroup/openmagic

https://github.com/iSCInc/heartbleed

https://github.com/waqasjamal-zz/HeartBleed-Vulnerability-Checker

https://github.com/Lekensteyn/pacemaker

https://github.com/tomdevman/heartbleed-bug

https://github.com/OffensivePython/HeartLeak

https://github.com/musalbas/heartbleed-masstest

https://github.com/22imer/CVE-2014-0160

https://github.com/obayesshelton/CVE-2014-0160-Scanner

https://github.com/GuillermoEscobero/heartbleed

https://github.com/idkqh7/heatbleeding

https://github.com/ArtemCyberLab/Project-Field-Analysis-and-Memory-Leak-Demonstration

https://github.com/takeshixx/ssl-heartbleed.nse

https://github.com/a0726h77/heartbleed-test

https://github.com/fb1h2s/CVE-2014-0160

https://github.com/hreese/heartbleed-dtls

https://github.com/proactiveRISK/heartbleed-extention

https://github.com/ice-security88/CVE-2014-0160

https://github.com/vortextube/ssl_scanner

https://github.com/iwaffles/heartbleed-test.crx

https://github.com/pblittle/aws-suture

https://github.com/WildfootW/CVE-2014-0160_OpenSSL_1.0.1f_Heartbleed

https://github.com/xlucas/heartbleed

https://github.com/einaros/heartbleed-tools

https://github.com/cved-sources/cve-2014-0160

https://github.com/belmind/heartbleed

https://github.com/sensepost/heartbleed-poc

https://github.com/Ryo-Soikutsu/Heartbleed

https://github.com/froyo75/Heartbleed_Dockerfile_with_Nginx

https://github.com/mozilla-services/Heartbleed

https://github.com/Saymeis/HeartBleed

https://github.com/GardeniaWhite/fuzzing

https://github.com/titanous/heartbleeder

https://github.com/sammyfung/openssl-heartbleed-fix

https://github.com/yashfren/CVE-2014-0160-HeartBleed

https://github.com/Xyl2k/CVE-2014-0160-Chrome-Plugin

https://github.com/hybridus/heartbleedscanner

https://github.com/amerine/coronary

https://github.com/FiloSottile/Heartbleed

https://github.com/0x90/CVE-2014-0160

https://github.com/h3x0v3rl0rd/CVE-2014-0160_Heartbleed

https://github.com/0xBlackash/CVE-2014-0160

https://github.com/0xinf0/bleeding_onions

https://github.com/artofscripting-zz/cmty-ssl-heartbleed-CVE-2014-0160-HTTP-HTTPS

https://github.com/MrE-Fog/CVE-2014-0160-Chrome-Plugin

https://github.com/ThanHuuTuan/Heartexploit

https://github.com/pierceoneill/bleeding-heart

https://github.com/cheese-hub/heartbleed

https://github.com/cbk914/heartbleed-checker

https://github.com/siddolo/knockbleed

https://github.com/cyphar/heartthreader

https://github.com/SimoesCTT/CTT-HEARTBLEED-Temporal-Resonance-Memory-Leak-Exploit-Heartbleed-CVE-2014-0160

https://github.com/victoriacfigueiredo/heartbleed-lab

https://github.com/yryz/heartbleed.js

https://github.com/Shayhha/HeartbleedAttack

https://github.com/tungduongNT/CVE-2014-0160.

g0rb@infosec.exchange at 2026-07-29T17:09:54.000Z ##

Shodan-Query of the day:

asn:"AS59399" vuln:"cve-2014-0160"

#ThruntersAnonymous #shodansafari #yeet

##

CVE-2026-62379
(0 None)

EPSS: 0.00%

2 posts

N/A

DailyCyberSecurity at 2026-07-31T13:41:47.544Z ##

Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9.

securityonline.info/openam-cve

##

DailyCyberSecurity@infosec.exchange at 2026-07-31T13:41:47.000Z ##

Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9.

#OpenAM #RCE #IAM #CVE202662379

securityonline.info/openam-cve

##

CVE-2026-62261
(0 None)

EPSS: 0.00%

2 posts

N/A

DailyCyberSecurity at 2026-07-31T13:41:47.544Z ##

Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9.

securityonline.info/openam-cve

##

DailyCyberSecurity@infosec.exchange at 2026-07-31T13:41:47.000Z ##

Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9.

#OpenAM #RCE #IAM #CVE202662379

securityonline.info/openam-cve

##

CVE-2026-46647
(0 None)

EPSS: 0.00%

2 posts

N/A

moltenbit at 2026-07-31T12:33:17.430Z ##

two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.

CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.

CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.

github.com/globaleaks/globalea and github.com/globaleaks/globalea

##

moltenbit@infosec.exchange at 2026-07-31T12:33:17.000Z ##

two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.

CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.

CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.

github.com/globaleaks/globalea and github.com/globaleaks/globalea

#GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security

##

CVE-2026-46648
(0 None)

EPSS: 0.00%

2 posts

N/A

moltenbit at 2026-07-31T12:33:17.430Z ##

two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.

CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.

CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.

github.com/globaleaks/globalea and github.com/globaleaks/globalea

##

moltenbit@infosec.exchange at 2026-07-31T12:33:17.000Z ##

two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.

CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.

CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.

github.com/globaleaks/globalea and github.com/globaleaks/globalea

#GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security

##

CVE-2026-63222
(0 None)

EPSS: 0.45%

3 posts

N/A

hugovalters@mastodon.social at 2026-07-31T11:00:17.000Z ##

CVE-2026-63222 - Path traversal in CodeIgniter. UploadedFile::move() unsanitized filename lets attackers write outside intended directory. CVSS 7.5. Update to 4.7.4 immediately. #CVE #CodeIgniter #infosec

valtersit.com/cve/CVE-2026-632

##

AmmarSpaces at 2026-07-31T10:51:10.006Z ##

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

##

AmmarSpaces@infosec.exchange at 2026-07-31T10:51:10.000Z ##

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

#cybersecurity #infosec #codeigniter #vulnerability

##

CVE-2026-63220
(0 None)

EPSS: 0.14%

2 posts

N/A

AmmarSpaces at 2026-07-31T10:51:10.006Z ##

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

##

AmmarSpaces@infosec.exchange at 2026-07-31T10:51:10.000Z ##

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

#cybersecurity #infosec #codeigniter #vulnerability

##

CVE-2026-63221
(0 None)

EPSS: 0.38%

2 posts

N/A

AmmarSpaces at 2026-07-31T10:51:10.006Z ##

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

##

AmmarSpaces@infosec.exchange at 2026-07-31T10:51:10.000Z ##

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

#cybersecurity #infosec #codeigniter #vulnerability

##

CVE-2026-59726
(0 None)

EPSS: 0.48%

5 posts

N/A

1 repos

https://github.com/HORKimhab/CVE-2026-59726

threatnoir at 2026-07-31T09:06:06.268Z ##

⚠️ CRITICAL: Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

CVE-2026-59726 in Ruflo AI orchestration platform allows unauthenticated remote code execution via an exposed Model Context Protocol bridge. Attackers can steal API keys, access user conversations, and corrupt AI memory without any credentials. Any organization running Ruflo is immediately exploita…

threatnoir.com/focus

##

beyondmachines1 at 2026-07-31T09:01:05.736Z ##

Critical RufRoot Flaw Allows Full Takeover of Ruflo AI Agent Environments

Ruflo patched a CVSS 10.0 vulnerability (CVE-2026-59726) that allowed unauthenticated attackers to execute code and steal API keys via an exposed MCP bridge. The flaw, named RufRoot, also enabled AI memory poisoning that persists even after software updates.

**If you run Ruflo (formerly Claude Flow), first make sure your instances are isolated from the internet and reachable only from trusted networks, then update to version 3.16.3 immediately to fix the RufRoot flaw (CVE-2026-59726) and firewall ports 3001 and 27017 to block outside access from the local network. Because a simple update won't undo damage already done, rotate all your LLM provider API keys (OpenAI, Anthropic, etc.) and audit the AgentDB memory store for any malicious entries left behind by attackers.**

beyondmachines.net/event_detai

##

threatnoir@infosec.exchange at 2026-07-31T09:06:06.000Z ##

⚠️ CRITICAL: Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

CVE-2026-59726 in Ruflo AI orchestration platform allows unauthenticated remote code execution via an exposed Model Context Protocol bridge. Attackers can steal API keys, access user conversations, and corrupt AI memory without any credentials. Any organization running Ruflo is immediately exploita…

threatnoir.com/focus

#infosec #cybersecurity

##

beyondmachines1@infosec.exchange at 2026-07-31T09:01:05.000Z ##

Critical RufRoot Flaw Allows Full Takeover of Ruflo AI Agent Environments

Ruflo patched a CVSS 10.0 vulnerability (CVE-2026-59726) that allowed unauthenticated attackers to execute code and steal API keys via an exposed MCP bridge. The flaw, named RufRoot, also enabled AI memory poisoning that persists even after software updates.

**If you run Ruflo (formerly Claude Flow), first make sure your instances are isolated from the internet and reachable only from trusted networks, then update to version 3.16.3 immediately to fix the RufRoot flaw (CVE-2026-59726) and firewall ports 3001 and 27017 to block outside access from the local network. Because a simple update won't undo damage already done, rotate all your LLM provider API keys (OpenAI, Anthropic, etc.) and audit the AgentDB memory store for any malicious entries left behind by attackers.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

offseq@infosec.exchange at 2026-07-30T10:30:29.000Z ##

Ruflo <3.16.3 has a CRITICAL flaw (CVE-2026-59726): exposed /mcp endpoint allows unauth RCE in MCP bridge container. Attackers can spawn rogue AI swarms & steal API keys. Upgrade to 3.16.3 asap. radar.offseq.com/threat/critic #OffSeq #AIsecurity #infosec #CVE202659726

##

CVE-2026-17543
(0 None)

EPSS: 0.39%

1 posts

N/A

CVE-2026-62246
(0 None)

EPSS: 0.27%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-30T23:00:02.000Z ##

🟠 CVE-2026-62246 - High (8.5)

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-68503
(0 None)

EPSS: 0.40%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-30T22:00:38.000Z ##

🔴 CVE-2026-68503 - Critical (9.8)

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.py HTTP ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18245
(0 None)

EPSS: 0.52%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-30T20:01:24.000Z ##

🔴 CVE-2026-18245 - Critical (9)

Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18140
(0 None)

EPSS: 0.44%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-30T20:01:11.000Z ##

🟠 CVE-2026-18140 - High (7.5)

Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62663
(0 None)

EPSS: 0.34%

1 posts

N/A

thehackerwire@mastodon.social at 2026-07-30T18:00:38.000Z ##

🟠 CVE-2026-62663 - High (7.5)

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks accept untrusted user input as file paths via Path(value) and pass them directly t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-58086
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-56848
(0 None)

EPSS: 0.00%

4 posts

N/A

nodejs_release_watcher@kodesumber.com at 2026-07-29T17:29:15.000Z ##

2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T15:30:05.000Z ##

Node.js patched 11 vulnerabilities in its July 2026 release. The high-severity bugs include a HTTP/2 use-after-free (CVE-2026-56848). Update now.

#NodeJS #CVE202656848 #HTTP2 #UseAfterFree #Vulnerability #InfoSec

securityonline.info/nodejs-jul

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:01.000Z ##

2026-07-29, Version 26.5.1 (Current), @RafaelGSS

This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:00.000Z ##

2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolito

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

CVE-2026-56846
(0 None)

EPSS: 0.00%

2 posts

N/A

nodejs_release_watcher@kodesumber.com at 2026-07-29T17:29:15.000Z ##

2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

nodejs_release_watcher@kodesumber.com at 2026-07-29T14:10:00.000Z ##

2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolito

This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...

github.com/nodejs/node/release

#nodejs #javascript

##

DailyCyberSecurity@infosec.exchange at 2026-07-29T14:01:16.000Z ##

OpenWrt Vulnerability CVE-2026-53921 Demands Immediate Action

securityexpress.info/openwrt-v

##

threatnoir@infosec.exchange at 2026-07-29T08:06:52.000Z ##

⚠️ CRITICAL: Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

OpenWrt released a critical patch (v24.10.8) for CVE-2026-53921, a stack overflow in the DHCPv6 service (odhcpd) that allows unauthenticated remote code execution as root. Any unpatched OpenWrt device is exploitable by sending crafted DHCPv6 packets. This affects routers and edge devices across ent…

threatnoir.com/focus

#infosec #cybersecurity

##

CVE-2026-65094
(0 None)

EPSS: 0.00%

1 posts

N/A

DailyCyberSecurity@infosec.exchange at 2026-07-29T02:15:59.000Z ##

NVIDIA BlueField has a critical VIRTIO-Net flaw, CVE-2026-65094, rated CVSS 9.0. A VM user could trigger code execution. Update to the fixed DOCA build.

#NVIDIA #BlueField #VIRTIONet #CVE202665094 #CodeExecution #CyberSecurity

securityonline.info/nvidia-blu

##

Visit counter For Websites