## Updated at UTC 2026-10-04T21:42:14.192943

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-88779 0 0.28% 17 2 2026-10-04T21:16:35.903000 Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: b
CVE-2026-105219 7.5 0.00% 2 0 2026-10-04T18:16:34.777000 Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service v
CVE-2026-105089 8.7 0.00% 2 0 2026-10-04T16:16:30.330000 WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability
CVE-2026-105086 8.7 0.00% 2 0 2026-10-04T16:16:30.183000 WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerabi
CVE-2026-105212 7.5 0.00% 2 0 2026-10-04T15:30:30 ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypas
CVE-2026-105215 9.1 0.00% 2 0 2026-10-04T15:30:29 ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in
CVE-2026-105213 8.2 0.00% 2 0 2026-10-04T15:30:29 ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during
CVE-2026-105210 8.2 0.00% 2 0 2026-10-04T15:30:29 ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authenticatio
CVE-2026-105207 9.8 0.00% 2 0 2026-10-04T15:30:24 ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user
CVE-2026-105208 7.7 0.00% 2 0 2026-10-04T15:30:23 ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with
CVE-2026-105209 9.6 0.00% 2 0 2026-10-04T15:30:23 ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorizati
CVE-2026-105211 8.1 0.00% 2 0 2026-10-04T15:16:32.467000 ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V
CVE-2026-97307 7.5 0.00% 4 0 2026-10-04T12:32:45 Insertion of Sensitive Information Into Sent Data vulnerability in StylemixTheme
CVE-2026-105135 10.0 0.77% 4 0 2026-10-04T09:30:28 A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects
CVE-2026-103355 9.3 0.25% 4 1 2026-10-04T09:30:28 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-105134 10.0 1.84% 4 0 2026-10-04T09:30:21 A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects
CVE-2026-105129 6.5 0.31% 2 0 2026-10-04T00:31:06 LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability tha
CVE-2026-105123 8.8 0.52% 4 0 2026-10-04T00:31:06 W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnera
CVE-2026-89236 8.6 0.27% 2 0 2026-10-03T18:32:06 The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and es
CVE-2026-88783 8.8 0.28% 2 0 2026-10-03T18:32:06 The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widen
CVE-2026-103626 9.6 0.29% 2 0 2026-10-03T18:32:05 Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 15
CVE-2026-103624 8.3 0.28% 2 0 2026-10-03T18:32:04 Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0
CVE-2026-101160 7.5 0.34% 2 0 2026-10-03T18:31:03 The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a su
CVE-2026-103514 7.5 0.30% 2 0 2026-10-03T18:31:03 The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-t
CVE-2026-101159 7.5 0.25% 2 0 2026-10-03T18:31:02 The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise
CVE-2026-96451 8.8 0.30% 2 1 2026-10-03T16:16:46.920000 Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Membe
CVE-2026-94593 7.8 0.11% 2 0 2026-10-03T16:16:45.843000 Armatura One's backup and restore routine records the full database connection c
CVE-2026-91078 8.2 0.19% 2 0 2026-10-03T16:16:41.237000 The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publi
CVE-2026-75028 7.5 0.70% 2 0 2026-10-03T16:16:38.153000 The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin
CVE-2026-105105 9.8 0.78% 3 0 2026-10-03T16:16:35.200000 CWE-306: Missing Authentication for Critical Function in the ait.core.server tel
CVE-2026-103648 9.1 0.41% 1 1 2026-10-03T16:16:34.007000 Path traversal in image-downloader 4.3.0 allows an attacker who can control the
CVE-2026-101161 7.5 0.34% 2 0 2026-10-03T16:16:31.713000 The WP Ultimate Review WordPress plugin before 2.4.4 does not prevent unauthenti
CVE-2026-105115 8.6 0.46% 2 0 2026-10-03T15:30:32 OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation v
CVE-2026-103065 8.2 0.21% 2 0 2026-10-03T15:30:32 Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirk
CVE-2026-71886 None 0.17% 2 0 2026-10-03T09:31:26 In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API ac
CVE-2026-71885 None 0.19% 3 0 2026-10-03T09:31:26 In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 94
CVE-2026-94505 8.1 0.29% 2 0 2026-10-03T09:31:26 The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for Wo
CVE-2026-92084 9.1 0.53% 2 1 2026-10-03T09:31:26 The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for W
CVE-2026-71887 None 0.09% 1 0 2026-10-03T09:31:26 In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a dat
CVE-2026-18443 8.8 0.37% 2 0 2026-10-03T09:31:25 The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin
CVE-2026-87115 9.1 0.88% 3 0 2026-10-03T09:31:25 The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable
CVE-2026-96267 7.5 0.33% 2 0 2026-10-03T09:31:25 The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable
CVE-2026-103913 7.5 0.38% 2 0 2026-10-03T06:31:25 The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the sto
CVE-2026-97337 7.5 0.37% 2 0 2026-10-03T06:31:25 The Simple Membership plugin for WordPress is vulnerable to unauthorized modific
CVE-2026-101923 8.1 0.34% 2 0 2026-10-03T06:31:24 The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrar
CVE-2026-97644 8.8 0.50% 2 0 2026-10-03T06:31:19 The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress
CVE-2026-92536 8.8 0.63% 2 0 2026-10-03T06:31:12 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User
CVE-2026-103625 8.8 0.29% 2 0 2026-10-03T04:18:00.957000 Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote at
CVE-2026-93428 7.5 0.40% 2 0 2026-10-03T03:31:44 The Ultimate Member – User Profile, Registration, Login, Member Directory, Conte
CVE-2026-105080 9.9 0.33% 3 0 2026-10-03T03:31:39 In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, an
CVE-2026-84411 9.8 0.95% 4 0 2026-10-03T00:31:21 The web management service in affected RouterOS versions contains an integer und
CVE-2026-94592 8.4 0.13% 2 0 2026-10-03T00:31:17 Armatura One's database initialization routine assigns a fixed, vendor-defined p
CVE-2026-97363 7.5 0.32% 2 0 2026-10-03T00:31:16 The WebSocket Application Programming Interface lacks restrictions on the number
CVE-2026-95102 9.4 0.34% 3 0 2026-10-03T00:31:16 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to
CVE-2026-94591 8.4 0.09% 2 0 2026-10-03T00:31:16 Armatura One stores database and message-broker credentials in an install config
CVE-2026-59265 None 0.22% 1 0 2026-10-03T00:31:13 A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and
CVE-2026-104433 7.5 0.37% 2 0 2026-10-03T00:16:35.253000 Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerabil
CVE-2026-103622 8.8 0.27% 2 0 2026-10-02T21:33:05 Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote a
CVE-2026-82044 7.7 0.26% 2 0 2026-10-02T21:32:19 UTMStack before 11.2.16 contains a server-side request forgery vulnerability tha
CVE-2026-82042 9.8 0.55% 2 0 2026-10-02T21:32:19 UTMStack before 11.2.16 contains an authentication bypass vulnerability that all
CVE-2026-82041 9.9 0.44% 2 0 2026-10-02T21:32:19 UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMInc
CVE-2026-104988 8.1 0.20% 2 0 2026-10-02T21:32:18 A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plug
CVE-2026-39718 8.8 0.14% 2 0 2026-10-02T21:32:18 Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet
CVE-2026-96940 8.8 0.50% 5 0 2026-10-02T21:32:13 Weak authorization in Microsoft Exchange Server allows an authenticated attacker
CVE-2026-75937 None 0.53% 2 0 2026-10-02T21:32:07 A specially crafted HTTP POST request to the web administration interface allows
CVE-2026-51916 7.5 0.43% 2 0 2026-10-02T21:32:04 TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnera
CVE-2026-51907 8.1 0.39% 2 0 2026-10-02T21:32:04 In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function,
CVE-2026-103628 9.6 0.33% 4 0 2026-10-02T21:32:03 Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a r
CVE-2026-104019 9.0 1.42% 4 0 2026-10-02T21:16:54.477000 OS command injection in the Studio Space startup validation script in Amazon Sag
CVE-2026-82039 8.8 0.34% 2 0 2026-10-02T20:17:04.430000 UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupS
CVE-2026-67989 7.5 0.34% 2 0 2026-10-02T20:17:03.933000 crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a pol
CVE-2026-18397 0 0.34% 1 0 2026-10-02T20:17:02.060000 This vulnerability enables unauthenticated remote code execution (RCE) on a vict
CVE-2026-104861 7.5 0.43% 1 0 2026-10-02T19:16:41.137000 probe-image-size gets image dimensions without downloading the entire file. Prio
CVE-2026-86326 0 0.19% 2 0 2026-10-02T19:10:09.143000 An improper verification of cryptographic signature vulnerability exists in prot
CVE-2026-54049 8.7 0.26% 1 0 2026-10-02T18:47:49.947000 Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to b
CVE-2026-104851 8.8 0.32% 1 0 2026-10-02T18:47:49.947000 fsspec is a specification and Python implementation framework for filesystem int
CVE-2026-90970 9.9 0.94% 14 1 2026-10-02T18:44:11.270000 GitLab has remediated a vulnerability in the GitLab AI Gateway component affecti
CVE-2026-103922 9.3 0.21% 2 1 2026-10-02T18:44:11.270000 Capacitor is a cross-platform native runtime for web applications. From 6.0.0 un
CVE-2026-94422 8.8 0.69% 1 0 2026-10-02T18:44:11.270000 An incorrect implementation of message filtering in xdg-dbus-proxy versions befo
CVE-2026-102489 9.8 1.40% 11 0 2026-10-02T18:32:21 Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability tha
CVE-2026-102490 9.8 0.63% 5 0 2026-10-02T18:32:21 All versions of Zammad including the latest alpha enable the local zammad user t
CVE-2026-102795 9.3 0.28% 1 0 2026-10-02T18:31:37 Improper Access Control vulnerability in Apache Traffic Server. This issue af
CVE-2026-101104 7.7 0.27% 1 0 2026-10-02T18:31:25 The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization f
CVE-2026-104431 7.5 0.34% 1 0 2026-10-02T17:59:09.430000 Zebra before 6.0.0 contains a denial of service vulnerability that allows unauth
CVE-2026-102667 8.3 0.19% 1 0 2026-10-02T17:17:01.083000 Joyland AI app allows an attacker with shared network access to inject JavaScrip
CVE-2026-104026 7.8 0.13% 1 0 2026-10-02T15:31:37 In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to
CVE-2026-19652 9.8 0.33% 1 0 2026-10-02T15:31:32 The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation i
CVE-2026-104610 10.0 0.64% 2 0 2026-10-02T15:31:31 A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_
CVE-2026-104462 7.5 0.31% 1 0 2026-10-02T15:17:08.050000 YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuaget
CVE-2026-104448 8.1 0.16% 1 0 2026-10-02T15:17:07.150000 YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the
CVE-2026-104611 9.1 0.49% 1 0 2026-10-02T14:17:09.660000 A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown fu
CVE-2026-104286 9.8 2.20% 11 2 2026-10-02T12:35:33.990000 An improper limitation of a pathname to a restricted directory ('path traversal'
CVE-2026-91828 7.5 0.31% 1 0 2026-10-02T12:32:16 The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin bef
CVE-2026-104456 7.6 0.30% 1 0 2026-10-02T12:31:26 YesWiki before 4.6.7 contains a second-order SQL injection vulnerability in AclS
CVE-2026-104467 8.1 0.37% 1 0 2026-10-02T12:31:26 YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiServic
CVE-2026-104472 7.5 0.34% 1 0 2026-10-02T12:31:26 YesWiki before 4.6.7 contains a missing authorization vulnerability in the attac
CVE-2026-104457 8.6 0.28% 1 0 2026-10-02T12:31:25 YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filter
CVE-2026-104464 8.6 0.29% 1 0 2026-10-02T12:31:25 YesWiki before 4.6.7 contains a server-side request forgery vulnerability that a
CVE-2026-104460 7.5 0.39% 1 0 2026-10-02T12:31:25 YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newte
CVE-2026-104416 7.5 0.31% 1 0 2026-10-02T12:31:20 Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability
CVE-2026-104423 7.5 0.34% 1 0 2026-10-02T12:31:20 Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerab
CVE-2026-104422 7.5 0.18% 1 0 2026-10-02T12:31:20 The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's heig
CVE-2026-104430 7.5 0.41% 1 0 2026-10-02T12:31:20 Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature ope
CVE-2026-104445 8.2 0.40% 1 0 2026-10-02T12:31:20 YesWiki before 4.6.7 contains an authentication bypass vulnerability in the Acti
CVE-2026-104443 8.1 0.36% 1 0 2026-10-02T12:31:20 YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete
CVE-2026-104410 7.5 0.38% 1 0 2026-10-02T12:31:19 SiYuan before 3.8.5 contains an information disclosure vulnerability that allows
CVE-2026-104414 8.1 0.28% 1 0 2026-10-02T12:31:19 Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerabil
CVE-2026-86325 None 0.34% 2 0 2026-10-02T12:31:19 A stack-based buffer overflow vulnerability exists in protocol gateways' account
CVE-2026-80298 8.8 0.29% 1 0 2026-10-02T12:31:18 Improper neutralization of special elements used in an SQL command ('SQL injecti
CVE-2026-93698 9.9 0.46% 1 0 2026-10-02T09:31:25 Insufficient validation allows arbitrary commands to be executed via the Multila
CVE-2026-48005 7.5 0.61% 1 0 2026-10-01T21:33:58 Missing authentication checks in mod_auth_digest in Apache Software Foundation A
CVE-2026-57941 9.8 0.44% 1 0 2026-10-01T21:33:58 Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared sessio
CVE-2026-63292 7.5 0.58% 1 1 2026-10-01T21:33:58 Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apa
CVE-2026-63045 7.5 0.33% 1 0 2026-10-01T21:33:58 Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Softwar
CVE-2026-59685 7.5 0.34% 1 0 2026-10-01T21:33:58 Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while process
CVE-2026-63718 7.5 0.32% 1 0 2026-10-01T21:33:58 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVE-2026-93546 8.8 0.34% 1 0 2026-10-01T21:33:58 Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an au
CVE-2026-56449 7.5 0.42% 1 0 2026-10-01T21:33:57 Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with cr
CVE-2026-56153 7.5 0.50% 1 0 2026-10-01T21:33:57 Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. T
CVE-2026-59797 9.8 0.39% 1 0 2026-10-01T21:33:57 Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via
CVE-2026-103484 8.8 0.42% 1 0 2026-10-01T21:33:02 IVFFlat index build in pgvector before 0.8.7 allows a database user to write dat
CVE-2026-102628 9.3 0.28% 1 0 2026-10-01T21:32:51 The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode en
CVE-2026-73636 8.1 0.37% 1 0 2026-10-01T21:17:24.300000 Authentication bypass by capture-replay in mod_auth_digest in Apache Software Fo
CVE-2026-63686 7.5 0.33% 1 0 2026-10-01T21:17:23.790000 A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache H
CVE-2026-56154 9.8 0.42% 1 0 2026-10-01T21:17:22.267000 Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using look
CVE-2026-12627 9.8 0.44% 1 0 2026-10-01T20:34:26.287000 Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer ove
CVE-2026-79898 9.1 0.98% 1 0 2026-10-01T20:34:26.287000 Fortra BoKS Manager contains a command injection vulnerability in crlserver. An
CVE-2026-102369 None 0.24% 1 0 2026-10-01T18:32:57 Tapo C120 v1 and C200 V5 do not adequately protect login challenge data or sanit
CVE-2026-79901 9.9 0.27% 2 0 2026-10-01T15:17:32.163000 In deployments using BoKS keytab management, affected versions of boks_keytabmd
CVE-2026-96760 9.8 0.28% 1 1 2026-10-01T14:17:32.147000 Authlib (v1.7.2 and below) contains a signature verification bypass vulnerabilit
CVE-2026-93355 8.1 0.27% 2 0 2026-09-30T17:23:08.953000 LiteLLM contains a weak authentication vulnerability that allows an attacker hol
CVE-2026-71972 5.9 0.22% 1 0 2026-09-30T16:40:50.560000 U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the
CVE-2026-102437 7.8 0.99% 1 0 2026-09-29T21:36:39.547000 OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation
CVE-2026-92370 8.8 0.38% 1 0 2026-09-29T18:31:49 An improper access control vulnerability in TeamViewer Full Client, Host, and re
CVE-2026-86950 8.8 1.24% 2 3 2026-09-29T15:32:17 An out-of-bounds write issue was addressed with improved bounds checking. This i
CVE-2026-88771 9.8 1.06% 9 12 2026-09-29T04:18:01.603000 Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc
CVE-2026-88772 8.1 1.30% 4 8 2026-09-28T12:32:09 Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue
CVE-2026-100520 8.8 0.94% 2 1 2026-09-26T03:30:23 Laranode versions before 1.2.1 contain a path traversal vulnerability in the POS
CVE-2026-25265 8.8 0.07% 1 0 2026-09-25T13:37:33.170000 Privilege escalation due to weak configuration while temporary file handling.
CVE-2026-75791 8.6 1.71% 1 0 2026-09-22T19:32:25.730000 Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerab
CVE-2026-63272 0 0.17% 2 0 2026-09-22T19:09:32.273000 LibreOffice can import WMF graphics, which may be embedded in documents. A heap
CVE-2026-63274 0 0.17% 1 0 2026-09-22T19:09:32.273000 LibreOffice Draw can import PDF documents. A heap buffer overflow existed when i
CVE-2026-63275 0 0.17% 1 0 2026-09-22T19:09:32.273000 LibreOffice can read CFF fonts, which may be embedded in documents. A stack buff
CVE-2026-63278 0 0.15% 1 0 2026-09-22T19:09:32.273000 URLs could be constructed which expanded environment variable or INI file values
CVE-2026-63276 0 0.19% 1 0 2026-09-22T19:09:32.273000 LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens w
CVE-2026-95273 4.3 0.52% 1 0 2026-09-22T19:04:55.677000 A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This
CVE-2026-87078 9.1 0.65% 1 0 2026-09-22T18:33:29 Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buf
CVE-2026-95659 None 0.39% 1 0 2026-09-22T15:32:43 MISP contains a reflected cross-site scripting (XSS) vulnerability in the Analys
CVE-2026-95661 None 0.44% 1 0 2026-09-22T15:32:43 MISP contains a reflected cross-site scripting (XSS) vulnerability in the attrib
CVE-2026-95675 9.8 2.06% 1 1 2026-09-22T15:32:43 D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated re
CVE-2026-95499 7.3 0.47% 1 0 2026-09-22T15:32:43 A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0
CVE-2026-12718 9.8 0.32% 1 0 2026-09-22T15:32:43 Improper neutralization of special elements used in an SQL command ('SQL injecti
CVE-2026-95658 None 0.27% 1 0 2026-09-22T15:32:36 MISP's WorkflowsController exposed the moduleStatelessExecution action in the Se
CVE-2026-95272 3.7 0.67% 1 0 2026-09-22T15:32:35 A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. This affe
CVE-2026-63273 None 0.11% 1 0 2026-09-22T12:30:32 LibreOffice Draw can import PDF documents. A heap buffer overflow existed when i
CVE-2026-9004 4.3 0.37% 1 0 2026-09-22T09:31:17 The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerab
CVE-2026-10536 9.8 0.60% 2 0 2026-09-15T07:16:25.137000 A use-after-free vulnerability exists in libcurl when an application configures
CVE-2026-85706 10.0 92.96% 1 14 2026-09-12T12:30:50 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7
CVE-2026-73916 9.1 0.43% 1 0 2026-08-28T05:16:44.893000 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imp
CVE-2026-73570 8.9 11.74% 1 10 2026-08-21T18:34:48 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor
CVE-2026-16584 7.0 0.23% 1 0 2026-07-23T19:16:53.537000 Improper handling of an initialization failure in AWS API MCP Server from 0.2.13
CVE-2026-61500 9.8 0.99% 3 1 2026-07-13T18:31:00 Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the
CVE-2025-6543 9.8 10.56% 2 4 2026-06-17T10:02:07.007000 Memory overflow vulnerability leading to unintended control flow and Denial of S
CVE-2026-48842 8.1 0.89% 2 3 2026-06-04T00:31:26 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authenticat
CVE-2026-8695 7.5 1.07% 1 2 2026-05-15T18:30:46 radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list()
CVE-2026-40281 10.0 2.09% 2 4 2026-05-08T19:26:58 ## Vulnerability Details **CWE**: CWE-20 - Improper Input Validation The metad
CVE-2024-12426 6.5 0.55% 1 0 2025-12-08T21:30:18 Exposure of Environmental Variables and arbitrary INI file values to an Unauthor
CVE-2026-103956 0 0.47% 3 1 N/A
CVE-2026-103958 0 0.33% 2 0 N/A
CVE-2026-10426 0 0.00% 1 0 N/A
CVE-2026-104846 0 0.34% 1 0 N/A
CVE-2026-104845 0 0.43% 1 0 N/A

CVE-2026-88779
(0 None)

EPSS: 0.28%

updated 2026-10-04T21:16:35.903000

17 posts

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

2 repos

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

https://github.com/orjanj/netscaler_threat_hunt_helper

secdb at 2026-10-04T21:00:19.941Z ##

🚨 [CISA-2026:1004] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-88779 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: support.citrix.com/support-hom ; community.citrix.com/techzone- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

##

cisakevtracker@mastodon.social at 2026-10-04T20:00:50.000Z ##

CVE ID: CVE-2026-88779
Vendor: Citrix
Product: NetScaler
Date Added: 2026-10-04
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

otcyber at 2026-10-04T14:43:30.927Z ##

Einordnung: NetScaler-Zero-Day trifft Fernwartung

Citrix NetScaler: Zero-Day CVE-2026-88779 wird ausgenutzt. Wer SAML nutzt, sollte sofort auf 14.1-73.41 bzw. 13.1-64.28 patchen – auch die Fernwartung.


ot-cyber.de/blog/einordnung-ne

##

GossiTheDog@cyberplace.social at 2026-10-04T14:29:54.000Z ##

@bontchev @jsmall ah. You were replying to posts about CVE-2026-88779.

##

darses@mastodon.nl at 2026-10-04T11:06:19.000Z ##

@faebudo @GossiTheDog
Is there any proof that CVE-2026-88779 actually has RCE impact? As far as I can tell this is all just conjecture based on the attempted command injection payloads from the same actor that introduced the crashes that lead to this fix.

##

GossiTheDog@cyberplace.social at 2026-10-04T09:55:03.000Z ##

The new Citrix Netscaler vuln from Friday is CVE-2026-88779, patch is out now and they recommend patching as soon as possible: support.citrix.com/support-hom

Although the vuln is labeled “Memory overflow vulnerability leading to Denial of Service”, that’s the same as CVE-2025–6543. You may remember that lead to RCE in the wild. Prior blog on that: doublepulsar.com/citrix-forgot

##

DailyCyberSecurity at 2026-10-04T08:21:54.136Z ##

Citrix NetScaler CVE-2026-88779 is exploited in the wild against NetScaler SAML authentication setups. Upgrade to 14.1-73.41 now.

securityonline.info/citrix-net

##

ifin at 2026-10-04T04:37:20.602Z ##

This is the patch that never ends
It goes on and on my friends
Some people
Started applying it
Not knowing what it was
And they will keep applying it
Forever just because

(CVE-2026-88779 advisory and patch included now)

ifin.network/t/multiple-citrix

##

offseq at 2026-10-04T04:30:26.990Z ##

CVE-2026-88779 (HIGH, CVSS 8.7) impacts NetScaler ADC & Gateway <14.1-73.41, <13.1-64.28, <13.1-37.282. Remote, unauthenticated attackers can disrupt availability. Patch required; no active exploits. radar.offseq.com/threat/cve-20

##

secdb@infosec.exchange at 2026-10-04T21:00:19.000Z ##

🚨 [CISA-2026:1004] CISA Adds One Known Exploited Vulnerability to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-88779 (secdb.nttzen.cloud/cve/detail/)
- Name: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Citrix
- Product: NetScaler
- Notes: support.citrix.com/support-hom ; community.citrix.com/techzone- ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261004 #cisa20261004 #cve_2026_88779 #cve202688779

##

cisakevtracker@mastodon.social at 2026-10-04T20:00:50.000Z ##

CVE ID: CVE-2026-88779
Vendor: Citrix
Product: NetScaler
Date Added: 2026-10-04
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

GossiTheDog@cyberplace.social at 2026-10-04T14:29:54.000Z ##

@bontchev @jsmall ah. You were replying to posts about CVE-2026-88779.

##

darses@mastodon.nl at 2026-10-04T11:06:19.000Z ##

@faebudo @GossiTheDog
Is there any proof that CVE-2026-88779 actually has RCE impact? As far as I can tell this is all just conjecture based on the attempted command injection payloads from the same actor that introduced the crashes that lead to this fix.

##

GossiTheDog@cyberplace.social at 2026-10-04T09:55:03.000Z ##

The new Citrix Netscaler vuln from Friday is CVE-2026-88779, patch is out now and they recommend patching as soon as possible: support.citrix.com/support-hom

Although the vuln is labeled “Memory overflow vulnerability leading to Denial of Service”, that’s the same as CVE-2025–6543. You may remember that lead to RCE in the wild. Prior blog on that: doublepulsar.com/citrix-forgot

##

DailyCyberSecurity@infosec.exchange at 2026-10-04T08:21:54.000Z ##

Citrix NetScaler CVE-2026-88779 is exploited in the wild against NetScaler SAML authentication setups. Upgrade to 14.1-73.41 now.

#Citrix #NetScaler #CVE202688779 #SAML #ActivelyExploited #DoS #Vulnerability

securityonline.info/citrix-net

##

ifin@infosec.exchange at 2026-10-04T04:37:20.000Z ##

This is the patch that never ends
It goes on and on my friends
Some people
Started applying it
Not knowing what it was
And they will keep applying it
Forever just because

(CVE-2026-88779 advisory and patch included now)

ifin.network/t/multiple-citrix

#Citrix #Netscaler #ThreatIntel #ThreatIntelligence

##

offseq@infosec.exchange at 2026-10-04T04:30:26.000Z ##

CVE-2026-88779 (HIGH, CVSS 8.7) impacts NetScaler ADC & Gateway <14.1-73.41, <13.1-64.28, <13.1-37.282. Remote, unauthenticated attackers can disrupt availability. Patch required; no active exploits. radar.offseq.com/threat/cve-20 #OffSeq #NetScaler #Vulnerability #InfoSec

##

CVE-2026-105219
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-04T18:16:34.777000

2 posts

Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an unterminated quoted string of repeated backslash escapes in mammoth/style-map to block the Node.js event loop.

thehackerwire@mastodon.social at 2026-10-04T18:30:20.000Z ##

🟠 CVE-2026-105219 - High (7.5)

Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an untermina...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-04T18:30:20.000Z ##

🟠 CVE-2026-105219 - High (7.5)

Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an untermina...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105089
(8.7 HIGH)

EPSS: 0.00%

updated 2026-10-04T16:16:30.330000

2 posts

WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlists, letting attackers break out of onclick strings or iframe src attributes to execute JavaScript in victims' browsers.

thehackerwire@mastodon.social at 2026-10-04T16:19:15.000Z ##

🟠 CVE-2026-105089 - High (8.7)

WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and chann...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-04T16:19:15.000Z ##

🟠 CVE-2026-105089 - High (8.7)

WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and chann...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105086
(8.7 HIGH)

EPSS: 0.00%

updated 2026-10-04T16:16:30.183000

2 posts

WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages.

thehackerwire@mastodon.social at 2026-10-04T16:19:06.000Z ##

🟠 CVE-2026-105086 - High (8.7)

WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entitie...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-04T16:19:06.000Z ##

🟠 CVE-2026-105086 - High (8.7)

WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entitie...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105212
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-04T15:30:30

2 posts

ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified. Unauthenticated attackers knowing only a victim's login name can register an attacker-controlled authenticator and log in as that user, bypassing exist

thehackerwire@mastodon.social at 2026-10-04T15:32:50.000Z ##

🟠 CVE-2026-105212 - High (7.5)

ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-04T15:32:50.000Z ##

🟠 CVE-2026-105212 - High (7.5)

ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105215
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-10-04T15:30:29

2 posts

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, w

thehackerwire@mastodon.social at 2026-10-04T15:33:08.000Z ##

🔴 CVE-2026-105215 - Critical (9.1)

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-04T15:33:08.000Z ##

🔴 CVE-2026-105215 - Critical (9.1)

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105213
(8.2 HIGH)

EPSS: 0.00%

updated 2026-10-04T15:30:29

2 posts

ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refresh token can still sign in, create sessions, and obtain or refresh tokens.

thehackerwire@mastodon.social at 2026-10-04T15:32:59.000Z ##

🟠 CVE-2026-105213 - High (8.2)

ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refres...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-04T15:32:59.000Z ##

🟠 CVE-2026-105213 - High (8.2)

ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refres...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105210
(8.2 HIGH)

EPSS: 0.00%

updated 2026-10-04T15:30:29

2 posts

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verified. Attackers knowing only a victim's login name can enroll attacker-controlled TOTP, OTP-SMS, OTP-Email, or U2F factors, overwrite the verified phone number, a

thehackerwire@mastodon.social at 2026-10-04T15:17:57.000Z ##

🟠 CVE-2026-105210 - High (8.2)

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verified. Att...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-04T15:17:57.000Z ##

🟠 CVE-2026-105210 - High (8.2)

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verified. Att...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105207
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-10-04T15:30:24

2 posts

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account

thehackerwire@mastodon.social at 2026-10-04T15:33:46.000Z ##

🔴 CVE-2026-105207 - Critical (9.8)

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User S...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-04T15:33:46.000Z ##

🔴 CVE-2026-105207 - Critical (9.8)

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User S...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105208
(7.7 HIGH)

EPSS: 0.00%

updated 2026-10-04T15:30:23

2 posts

ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent. An attacker who predicts a victim's in-flight intent identifier and wins a timing race can call /v2/idp_intents or /v2/sessions to steal the victim's IdP tokens

thehackerwire@mastodon.social at 2026-10-04T15:33:56.000Z ##

🟠 CVE-2026-105208 - High (7.7)

ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent. An atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-04T15:33:56.000Z ##

🟠 CVE-2026-105208 - High (7.7)

ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent. An atta...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105209
(9.6 CRITICAL)

EPSS: 0.00%

updated 2026-10-04T15:30:23

2 posts

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and r

thehackerwire@mastodon.social at 2026-10-04T15:17:47.000Z ##

🔴 CVE-2026-105209 - Critical (9.6)

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organizat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-04T15:17:47.000Z ##

🔴 CVE-2026-105209 - Critical (9.6)

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organizat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105211
(8.1 HIGH)

EPSS: 0.00%

updated 2026-10-04T15:16:32.467000

2 posts

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.

thehackerwire@mastodon.social at 2026-10-04T15:18:06.000Z ##

🟠 CVE-2026-105211 - High (8.1)

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-04T15:18:06.000Z ##

🟠 CVE-2026-105211 - High (8.1)

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97307
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-04T12:32:45

4 posts

Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17.

thehackerwire@mastodon.social at 2026-10-04T15:34:05.000Z ##

🟠 CVE-2026-97307 - High (7.5)

Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-10-04T12:00:25.337Z ##

StylemixThemes Cost Calculator Builder (<4.0.18) hit by HIGH severity vuln (CVE-2026-97307): sensitive info may be leaked via sent data. Patch not confirmed — track vendor updates and secure affected sites. 🛡️ radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-10-04T15:34:05.000Z ##

🟠 CVE-2026-97307 - High (7.5)

Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-04T12:00:25.000Z ##

StylemixThemes Cost Calculator Builder (<4.0.18) hit by HIGH severity vuln (CVE-2026-97307): sensitive info may be leaked via sent data. Patch not confirmed — track vendor updates and secure affected sites. 🛡️ radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

CVE-2026-105135
(10.0 CRITICAL)

EPSS: 0.77%

updated 2026-10-04T09:30:28

4 posts

A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure

thehackerwire@mastodon.social at 2026-10-04T15:51:05.000Z ##

🔴 CVE-2026-105135 - Critical (10)

A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-10-04T07:30:24.662Z ##

InternLM MindSearch 0.1.0 hit by CRITICAL code injection (CVE-2026-105135) in ExecutionAction.run — remote attackers can execute arbitrary code via manipulated inputs. No patch; restrict access & monitor for updates. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-10-04T15:51:05.000Z ##

🔴 CVE-2026-105135 - Critical (10)

A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-04T07:30:24.000Z ##

InternLM MindSearch 0.1.0 hit by CRITICAL code injection (CVE-2026-105135) in ExecutionAction.run — remote attackers can execute arbitrary code via manipulated inputs. No patch; restrict access & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026105135 #infosec #zeroday

##

CVE-2026-103355
(9.3 CRITICAL)

EPSS: 0.25%

updated 2026-10-04T09:30:28

4 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.

1 repos

https://github.com/Hassham1/CVE-2026-103355-unlimited-elements-sqli-poc

thehackerwire@mastodon.social at 2026-10-04T15:50:44.000Z ##

🔴 CVE-2026-103355 - Critical (9.3)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-10-04T09:00:25.785Z ##

CVE-2026-103355: CRITICAL blind SQL Injection in Unlimited Elements For Elementor (<2.0.21). Risk of data compromise — patch ASAP when available! radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-10-04T15:50:44.000Z ##

🔴 CVE-2026-103355 - Critical (9.3)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-04T09:00:25.000Z ##

CVE-2026-103355: CRITICAL blind SQL Injection in Unlimited Elements For Elementor (<2.0.21). Risk of data compromise — patch ASAP when available! radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #SQLInjection

##

CVE-2026-105134
(10.0 CRITICAL)

EPSS: 1.84%

updated 2026-10-04T09:30:21

4 posts

A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve

thehackerwire@mastodon.social at 2026-10-04T15:50:56.000Z ##

🔴 CVE-2026-105134 - Critical (10)

A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os comman...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq at 2026-10-04T10:30:26.116Z ##

CVE-2026-105134 (CRITICAL): Ahsay AhsayCBS ≤10.3.2 suffers OS command injection in Replication Receiver (/rps/api/json/UpdateReceivers.do). Remote RCE possible — public exploit out. Patch to 10.3.4+ now. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-10-04T15:50:56.000Z ##

🔴 CVE-2026-105134 - Critical (10)

A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os comman...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-04T10:30:26.000Z ##

CVE-2026-105134 (CRITICAL): Ahsay AhsayCBS ≤10.3.2 suffers OS command injection in Replication Receiver (/rps/api/json/UpdateReceivers.do). Remote RCE possible — public exploit out. Patch to 10.3.4+ now. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CVE #PatchNow

##

CVE-2026-105129
(6.5 MEDIUM)

EPSS: 0.31%

updated 2026-10-04T00:31:06

2 posts

LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.

offseq at 2026-10-04T13:30:25.123Z ##

CVE-2026-105129 | LaraDashboard <1.4.8 HIGH severity: settings.view users can access plaintext secrets (API keys, mail creds, tokens) via API. Patch to 1.4.8+ recommended. radar.offseq.com/threat/larada

##

offseq@infosec.exchange at 2026-10-04T13:30:25.000Z ##

CVE-2026-105129 | LaraDashboard <1.4.8 HIGH severity: settings.view users can access plaintext secrets (API keys, mail creds, tokens) via API. Patch to 1.4.8+ recommended. radar.offseq.com/threat/larada #OffSeq #Vulnerability #LaraDashboard #AppSec

##

CVE-2026-105123
(8.8 HIGH)

EPSS: 0.52%

updated 2026-10-04T00:31:06

4 posts

W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path

offseq at 2026-10-04T01:30:24.706Z ##

vincent-peugnet wcms ≤3.18.0 is vulnerable (CVE-2026-105123, HIGH, CVSS 8.7): Authenticated editors can upload malicious files via /api/v0/media/upload/ and delete arbitrary files. Restrict privileges, monitor uploads. radar.offseq.com/threat/cve-20

##

thehackerwire@mastodon.social at 2026-10-04T00:30:56.000Z ##

🟠 CVE-2026-105123 - High (8.8)

W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php file...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-04T01:30:24.000Z ##

vincent-peugnet wcms ≤3.18.0 is vulnerable (CVE-2026-105123, HIGH, CVSS 8.7): Authenticated editors can upload malicious files via /api/v0/media/upload/ and delete arbitrary files. Restrict privileges, monitor uploads. radar.offseq.com/threat/cve-20 #OffSeq #RCE #WebSecurity #Vuln

##

thehackerwire@mastodon.social at 2026-10-04T00:30:56.000Z ##

🟠 CVE-2026-105123 - High (8.8)

W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php file...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89236
(8.6 HIGH)

EPSS: 0.27%

updated 2026-10-03T18:32:06

2 posts

The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.

thehackerwire@mastodon.social at 2026-10-03T16:33:40.000Z ##

🟠 CVE-2026-89236 - High (8.6)

The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive info...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:33:40.000Z ##

🟠 CVE-2026-89236 - High (8.6)

The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive info...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-88783
(8.8 HIGH)

EPSS: 0.28%

updated 2026-10-03T18:32:06

2 posts

The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to store markup which the Kubio AI Page Builder WordPress plugin before 2.9.3's own script later executes in the browser of any visitor, or of an administr

thehackerwire@mastodon.social at 2026-10-03T16:33:31.000Z ##

🟠 CVE-2026-88783 - High (8.8)

The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:33:31.000Z ##

🟠 CVE-2026-88783 - High (8.8)

The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103626
(9.6 CRITICAL)

EPSS: 0.29%

updated 2026-10-03T18:32:05

2 posts

Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-10-03T19:15:59.000Z ##

🔴 CVE-2026-103626 - Critical (9.6)

Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium securi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T19:15:59.000Z ##

🔴 CVE-2026-103626 - Critical (9.6)

Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium securi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103624
(8.3 HIGH)

EPSS: 0.28%

updated 2026-10-03T18:32:04

2 posts

Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-10-03T19:00:57.000Z ##

🟠 CVE-2026-103624 - High (8.3)

Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromiu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T19:00:57.000Z ##

🟠 CVE-2026-103624 - High (8.3)

Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromiu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101160
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-03T18:31:03

2 posts

The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a submitted review rating is numeric before storing it and later using it in numeric operations when rendering reviews, allowing unauthenticated users to make the reviewed content fail with a fatal error for all visitors until the review is removed (a persistent denial of service), when user reviews are enabled.

thehackerwire@mastodon.social at 2026-10-03T16:47:54.000Z ##

🟠 CVE-2026-101160 - High (7.5)

The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a submitted review rating is numeric before storing it and later using it in numeric operations when rendering reviews, allowing unauthenticated users to make the reviewed...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:47:54.000Z ##

🟠 CVE-2026-101160 - High (7.5)

The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a submitted review rating is numeric before storing it and later using it in numeric operations when rendering reviews, allowing unauthenticated users to make the reviewed...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103514
(7.5 HIGH)

EPSS: 0.30%

updated 2026-10-03T18:31:03

2 posts

The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts.

thehackerwire@mastodon.social at 2026-10-03T16:47:36.000Z ##

🟠 CVE-2026-103514 - High (7.5)

The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:47:36.000Z ##

🟠 CVE-2026-103514 - High (7.5)

The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypa...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101159
(7.5 HIGH)

EPSS: 0.25%

updated 2026-10-03T18:31:02

2 posts

The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews submitted through its public review form, which is available to unauthenticated visitors, allowing them to perform Stored Cross-Site Scripting attacks against any user, including administrators, viewing a page displaying the review, when user reviews are enabled.

thehackerwire@mastodon.social at 2026-10-03T16:47:45.000Z ##

🟠 CVE-2026-101159 - High (7.5)

The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews submitted through its public review form, which is available to unauthenticated visitors, allowing them to perform Stored Cross-Site Scripting attac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:47:45.000Z ##

🟠 CVE-2026-101159 - High (7.5)

The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews submitted through its public review form, which is available to unauthenticated visitors, allowing them to perform Stored Cross-Site Scripting attac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96451
(8.8 HIGH)

EPSS: 0.30%

updated 2026-10-03T16:16:46.920000

2 posts

Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.

1 repos

https://github.com/Nxploited/CVE-2026-96451

thehackerwire@mastodon.social at 2026-10-03T16:17:34.000Z ##

🟠 CVE-2026-96451 - High (8.8)

Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:17:34.000Z ##

🟠 CVE-2026-96451 - High (8.8)

Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94593
(7.8 HIGH)

EPSS: 0.11%

updated 2026-10-03T16:16:45.843000

2 posts

Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available.

thehackerwire@mastodon.social at 2026-10-03T17:45:24.000Z ##

🟠 CVE-2026-94593 - High (7.8)

Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:45:24.000Z ##

🟠 CVE-2026-94593 - High (7.8)

Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91078
(8.2 HIGH)

EPSS: 0.19%

updated 2026-10-03T16:16:41.237000

2 posts

The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone with no identity or capability check, allowing unauthenticated attackers to obtain a privileged POS session and thereby read customer and site-user personal

thehackerwire@mastodon.social at 2026-10-03T16:33:49.000Z ##

🟠 CVE-2026-91078 - High (8.2)

The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone wit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:33:49.000Z ##

🟠 CVE-2026-91078 - High (8.2)

The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone wit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75028
(7.5 HIGH)

EPSS: 0.70%

updated 2026-10-03T16:16:38.153000

2 posts

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.18 via the (template scope) function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP c

thehackerwire@mastodon.social at 2026-10-03T15:33:01.000Z ##

🟠 CVE-2026-75028 - High (7.5)

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.18 via the (template scope) function. This makes it possible for authe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T15:33:01.000Z ##

🟠 CVE-2026-75028 - High (7.5)

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.18 via the (template scope) function. This makes it possible for authe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105105
(9.8 CRITICAL)

EPSS: 0.78%

updated 2026-10-03T16:16:35.200000

3 posts

CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus. The ait-serv

thehackerwire@mastodon.social at 2026-10-03T15:17:44.000Z ##

🔴 CVE-2026-105105 - Critical (9.8)

CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T15:17:44.000Z ##

🔴 CVE-2026-105105 - Critical (9.8)

CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-03T13:30:23.000Z ##

NASA-AMMOS AIT-Core ≤3.1.1 has a CRITICAL vuln (CVE-2026-105105): ZeroMQ bus lacks auth, exposing command & telemetry to remote attackers. Upgrade to 3.1.2 restricts access to loopback. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #SpaceSec #Infosec

##

CVE-2026-103648
(9.1 CRITICAL)

EPSS: 0.41%

updated 2026-10-03T16:16:34.007000

1 posts

Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory.

1 repos

https://github.com/EterNullSec/CVE-2026-103648

thehackerwire@mastodon.social at 2026-10-02T16:19:06.000Z ##

🔴 CVE-2026-103648 - Critical (9.1)

Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101161
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-03T16:16:31.713000

2 posts

The WP Ultimate Review WordPress plugin before 2.4.4 does not prevent unauthenticated users from storing crafted review content that makes the reviewed page fail with a fatal error on every subsequent visit, resulting in a persistent denial of service when the WP Ultimate Review WordPress plugin before 2.4.4's review display settings have never been saved.

thehackerwire@mastodon.social at 2026-10-03T17:02:38.000Z ##

🟠 CVE-2026-101161 - High (7.5)

The WP Ultimate Review WordPress plugin before 2.4.4 does not prevent unauthenticated users from storing crafted review content that makes the reviewed page fail with a fatal error on every subsequent visit, resulting in a persistent denial of ser...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:02:38.000Z ##

🟠 CVE-2026-101161 - High (7.5)

The WP Ultimate Review WordPress plugin before 2.4.4 does not prevent unauthenticated users from storing crafted review content that makes the reviewed page fail with a fatal error on every subsequent visit, resulting in a persistent denial of ser...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105115
(8.6 HIGH)

EPSS: 0.46%

updated 2026-10-03T15:30:32

2 posts

OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadge

thehackerwire@mastodon.social at 2026-10-03T15:17:36.000Z ##

🟠 CVE-2026-105115 - High (8.6)

OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* wi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T15:17:36.000Z ##

🟠 CVE-2026-105115 - High (8.6)

OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* wi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103065
(8.2 HIGH)

EPSS: 0.21%

updated 2026-10-03T15:30:32

2 posts

Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1.

thehackerwire@mastodon.social at 2026-10-03T15:17:27.000Z ##

🟠 CVE-2026-103065 - High (8.2)

Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T15:17:27.000Z ##

🟠 CVE-2026-103065 - High (8.2)

Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71886(CVSS UNKNOWN)

EPSS: 0.17%

updated 2026-10-03T09:31:26

2 posts

In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation from any component key of the issuing certificate, without requiring that component to have been granted the authority to certify. OpenPGPCertificate.getCertificationBy() and getDelegationBy() resolve a third-party signature by matching its issuer key identifier ag

offseq at 2026-10-04T06:00:24.214Z ##

CVE-2026-71886: Bouncy Castle for Java <1.86 HIGH severity vuln lets restricted OpenPGP subkeys improperly certify or delegate trust. No patch yet — validate key flags before accepting certifications. radar.offseq.com/threat/in-bou

##

offseq@infosec.exchange at 2026-10-04T06:00:24.000Z ##

CVE-2026-71886: Bouncy Castle for Java <1.86 HIGH severity vuln lets restricted OpenPGP subkeys improperly certify or delegate trust. No patch yet — validate key flags before accepting certifications. radar.offseq.com/threat/in-bou #OffSeq #JavaSecurity #PKI #BouncyCastle

##

CVE-2026-71885(CVSS UNKNOWN)

EPSS: 0.19%

updated 2026-10-03T09:31:26

3 posts

In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against the signature_key carried in the leaf itself, while the credential's X.509 certificate chain was stored but never parsed or validated, so the end-entity certificate's public key was ne

offseq at 2026-10-04T00:00:36.437Z ##

CVE-2026-71885 (CRITICAL): Bouncy Castle for Java <1.86 suffers from X.509 credential binding flaw in MLS. Attackers can impersonate users & decrypt group messages. Upgrade to v1.86+ now. radar.offseq.com/threat/in-bou

##

offseq@infosec.exchange at 2026-10-04T00:00:36.000Z ##

CVE-2026-71885 (CRITICAL): Bouncy Castle for Java <1.86 suffers from X.509 credential binding flaw in MLS. Attackers can impersonate users & decrypt group messages. Upgrade to v1.86+ now. radar.offseq.com/threat/in-bou #OffSeq #BouncyCastle #Java #Infosec

##

offseq@infosec.exchange at 2026-10-03T10:30:24.000Z ##

CRITICAL CVE-2026-71885 in Bouncy Castle BC-JAVA (<1.86): Improper X.509 cert validation in MLS lets attackers impersonate users & compromise group comms. Upgrade to 1.86+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202671885 #JavaSecurity #Infosec

##

CVE-2026-94505
(8.1 HIGH)

EPSS: 0.29%

updated 2026-10-03T09:31:26

2 posts

The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to permanently delete any reusable socia

thehackerwire@mastodon.social at 2026-10-03T15:18:33.000Z ##

🟠 CVE-2026-94505 - High (8.1)

The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0 This is due to the plugin not properly verifying that a user is authorized ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T15:18:33.000Z ##

🟠 CVE-2026-94505 - High (8.1)

The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0 This is due to the plugin not properly verifying that a user is authorized ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92084
(9.1 CRITICAL)

EPSS: 0.53%

updated 2026-10-03T09:31:26

2 posts

The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcode

1 repos

https://github.com/Hassham1/CVE-2026-92084-beaver-builder-shortcode-poc

thehackerwire@mastodon.social at 2026-10-03T15:18:23.000Z ##

🔴 CVE-2026-92084 - Critical (9.1)

The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an acti...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T15:18:23.000Z ##

🔴 CVE-2026-92084 - Critical (9.1)

The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an acti...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-71887(CVSS UNKNOWN)

EPSS: 0.09%

updated 2026-10-03T09:31:26

1 posts

In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature carried no embedded Primary Key Binding (cross-certification) signature, in the case where that binding omits a Key Flags subpacket. RFC 9580 sec. 5.2.1.8 and sec. 10.1.3 require the embedded Primary Key Binding signature on any subkey that can issue s

offseq@infosec.exchange at 2026-10-03T09:00:25.000Z ##

CVE-2026-71887 | Legion of the Bouncy Castle BC-JAVA <1.86 has a HIGH severity flaw: improper signature verification can enable signature misattribution via public signing subkeys. Patch to 1.86+ now. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Java #Infosec

##

CVE-2026-18443
(8.8 HIGH)

EPSS: 0.37%

updated 2026-10-03T09:31:25

2 posts

The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and including, 8.97.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subs

thehackerwire@mastodon.social at 2026-10-03T15:33:19.000Z ##

🟠 CVE-2026-18443 - High (8.8)

The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and including, 8.97.0 due to insufficient escaping...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T15:33:19.000Z ##

🟠 CVE-2026-18443 - High (8.8)

The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and including, 8.97.0 due to insufficient escaping...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-87115
(9.1 CRITICAL)

EPSS: 0.88%

updated 2026-10-03T09:31:25

3 posts

The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as

thehackerwire@mastodon.social at 2026-10-03T15:33:11.000Z ##

🔴 CVE-2026-87115 - Critical (9.1)

The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T15:33:11.000Z ##

🔴 CVE-2026-87115 - Critical (9.1)

The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-03T07:30:22.000Z ##

VikAppointments Booking Calendar plugin (<=1.2.21) for WordPress is vulnerable to CRITICAL path traversal (CVE-2026-87115). Unauth attackers can delete files, risking RCE. Check for File-type fields & secure your site! radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202687115

##

CVE-2026-96267
(7.5 HIGH)

EPSS: 0.33%

updated 2026-10-03T09:31:25

2 posts

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, and including, 8.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already exi

thehackerwire@mastodon.social at 2026-10-03T15:18:42.000Z ##

🟠 CVE-2026-96267 - High (7.5)

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, and including, 8.7 due to insufficient escaping on the user supplied parameter and lack of...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T15:18:42.000Z ##

🟠 CVE-2026-96267 - High (7.5)

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, and including, 8.7 due to insufficient escaping on the user supplied parameter and lack of...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103913
(7.5 HIGH)

EPSS: 0.38%

updated 2026-10-03T06:31:25

2 posts

The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. This is due to insufficient escaping and the absence of numeric validation on coordinate values when a listing is saved, combined with the direct string interpolation of those values into a distance sub-expression in geodir_gps_q

thehackerwire@mastodon.social at 2026-10-03T16:02:51.000Z ##

🟠 CVE-2026-103913 - High (7.5)

The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. This is due to insufficient escaping and the absence of numeric validation o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:02:51.000Z ##

🟠 CVE-2026-103913 - High (7.5)

The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. This is due to insufficient escaping and the absence of numeric validation o...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97337
(7.5 HIGH)

EPSS: 0.37%

updated 2026-10-03T06:31:25

2 posts

The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are dispatched from SwpmInitTimeTasks::check_and_do_email_activation() on frontend init with no authentication, nonce, capability, or ownership check, and th

thehackerwire@mastodon.social at 2026-10-03T16:02:42.000Z ##

🟠 CVE-2026-97337 - High (7.5)

The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:02:42.000Z ##

🟠 CVE-2026-97337 - High (7.5)

The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101923
(8.1 HIGH)

EPSS: 0.34%

updated 2026-10-03T06:31:24

2 posts

The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of a public review submission into the review's reviews-images comment meta without verifying that the IDs correspond to attachments owned by the submitter,

thehackerwire@mastodon.social at 2026-10-03T16:03:00.000Z ##

🟠 CVE-2026-101923 - High (8.1)

The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T16:03:00.000Z ##

🟠 CVE-2026-101923 - High (8.1)

The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97644
(8.8 HIGH)

EPSS: 0.50%

updated 2026-10-03T06:31:19

2 posts

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the `create_contact` function in the v3 REST endpoint (`POST /gh/v3/contacts`) is gated solely by the `add_contacts` capability and forwards the full request payload — includi

thehackerwire@mastodon.social at 2026-10-03T17:02:48.000Z ##

🟠 CVE-2026-97644 - High (8.8)

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the `create_contact`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:02:48.000Z ##

🟠 CVE-2026-97644 - High (8.8)

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the `create_contact`...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-92536
(8.8 HIGH)

EPSS: 0.63%

updated 2026-10-03T06:31:12

2 posts

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the get_user_profile_structure. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract other users' email addres

thehackerwire@mastodon.social at 2026-10-03T17:02:56.000Z ##

🟠 CVE-2026-92536 - High (8.8)

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the g...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:02:56.000Z ##

🟠 CVE-2026-92536 - High (8.8)

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the g...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103625
(8.8 HIGH)

EPSS: 0.29%

updated 2026-10-03T04:18:00.957000

2 posts

Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-10-03T19:15:51.000Z ##

🟠 CVE-2026-103625 - High (8.8)

Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T19:15:51.000Z ##

🟠 CVE-2026-103625 - High (8.8)

Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93428
(7.5 HIGH)

EPSS: 0.40%

updated 2026-10-03T03:31:44

2 posts

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.1 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view privacy-restricted memb

thehackerwire@mastodon.social at 2026-10-03T17:18:31.000Z ##

🟠 CVE-2026-93428 - High (7.5)

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.1 This is due to the plugin ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:18:31.000Z ##

🟠 CVE-2026-93428 - High (7.5)

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.1 This is due to the plugin ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105080
(9.9 CRITICAL)

EPSS: 0.33%

updated 2026-10-03T03:31:39

3 posts

In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.

thehackerwire@mastodon.social at 2026-10-03T17:18:39.000Z ##

🔴 CVE-2026-105080 - Critical (9.9)

In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:18:39.000Z ##

🔴 CVE-2026-105080 - Critical (9.9)

In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-03T01:30:23.000Z ##

CVE-2026-105080 (CRITICAL, CVSS 9.4) in C4illin ConvertX <0.19.0: Untrusted .recipe files can execute code via Calibre's ebook-convert. Update to 0.19.0+ recommended. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CVE2026105080 #ConvertX #Calibre

##

CVE-2026-84411
(9.8 CRITICAL)

EPSS: 0.95%

updated 2026-10-03T00:31:21

4 posts

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.

thehackerwire@mastodon.social at 2026-10-03T17:30:26.000Z ##

🔴 CVE-2026-84411 - Critical (9.8)

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary cod...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:30:26.000Z ##

🔴 CVE-2026-84411 - Critical (9.8)

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary cod...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

nyanbinary@infosec.exchange at 2026-10-03T06:32:36.000Z ##

Saturday morning RouterOS 9.8 :apartyblobcat:

db.gcve.eu/vuln/cve-2026-84411

##

offseq@infosec.exchange at 2026-10-03T00:00:37.000Z ##

CVE-2026-84411 (CRITICAL, CVSS 9.8) affects MikroTik RouterOS <7.24. Integer underflow in web mgmt lets unauth'd attackers exec root code or DoS via crafted HTTP. Restrict access & monitor now. radar.offseq.com/threat/cve-20 #OffSeq #CVE #MikroTik #InfoSec

##

CVE-2026-94592
(8.4 HIGH)

EPSS: 0.13%

updated 2026-10-03T00:31:17

2 posts

Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed.

thehackerwire@mastodon.social at 2026-10-03T17:30:45.000Z ##

🟠 CVE-2026-94592 - High (8.4)

Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operatin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:30:45.000Z ##

🟠 CVE-2026-94592 - High (8.4)

Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operatin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97363
(7.5 HIGH)

EPSS: 0.32%

updated 2026-10-03T00:31:16

2 posts

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.

thehackerwire@mastodon.social at 2026-10-03T17:45:45.000Z ##

🟠 CVE-2026-97363 - High (7.5)

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:45:45.000Z ##

🟠 CVE-2026-97363 - High (7.5)

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-95102
(9.4 CRITICAL)

EPSS: 0.34%

updated 2026-10-03T00:31:16

3 posts

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.

thehackerwire@mastodon.social at 2026-10-03T17:45:34.000Z ##

🔴 CVE-2026-95102 - Critical (9.4)

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:45:34.000Z ##

🔴 CVE-2026-95102 - Critical (9.4)

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-03T03:00:24.000Z ##

Monta monta.app faces a CRITICAL risk (CVE-2026-95102, CVSS 9.4): missing auth on WebSocket endpoints allows attackers to impersonate charging stations & access sensitive data. Restrict access, monitor traffic. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202695102 #InfoSec ⚡️

##

CVE-2026-94591
(8.4 HIGH)

EPSS: 0.09%

updated 2026-10-03T00:31:16

2 posts

Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package can recover this key and initialization vector, a

thehackerwire@mastodon.social at 2026-10-03T17:30:36.000Z ##

🟠 CVE-2026-94591 - High (8.4)

Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:30:36.000Z ##

🟠 CVE-2026-94591 - High (8.4)

Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59265(CVSS UNKNOWN)

EPSS: 0.22%

updated 2026-10-03T00:31:13

1 posts

A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user. This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase. Until then, users can mitigate this issue by disabling Java runtime integration in the Preferences d

CVE-2026-104433
(7.5 HIGH)

EPSS: 0.37%

updated 2026-10-03T00:16:35.253000

2 posts

Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the hosting process, such as an SGLang inference serve

thehackerwire@mastodon.social at 2026-10-03T17:18:50.000Z ##

🟠 CVE-2026-104433 - High (7.5)

Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T17:18:50.000Z ##

🟠 CVE-2026-104433 - High (7.5)

Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103622
(8.8 HIGH)

EPSS: 0.27%

updated 2026-10-02T21:33:05

2 posts

Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

thehackerwire@mastodon.social at 2026-10-03T19:00:46.000Z ##

🟠 CVE-2026-103622 - High (8.8)

Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T19:00:46.000Z ##

🟠 CVE-2026-103622 - High (8.8)

Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82044
(7.7 HIGH)

EPSS: 0.26%

updated 2026-10-02T21:32:19

2 posts

UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated url parameter to the PdfService.downloadPdf() method exposed via GET /api/generate-pdf-report. Attackers can leverage this to force the web-pdf microservice to fetch internal backend endpoints, the OpenS

thehackerwire@mastodon.social at 2026-10-03T18:00:57.000Z ##

🟠 CVE-2026-82044 - High (7.7)

UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated url parameter to the PdfService.downloadPdf() meth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:00:57.000Z ##

🟠 CVE-2026-82044 - High (7.7)

UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated url parameter to the PdfService.downloadPdf() meth...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82042
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-10-02T21:32:19

2 posts

UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint without path restriction, constant-time comparison, rate limiting, or audit logging. Attackers who obtai

thehackerwire@mastodon.social at 2026-10-03T18:00:47.000Z ##

🔴 CVE-2026-82042 - Critical (9.8)

UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:00:47.000Z ##

🔴 CVE-2026-82042 - Critical (9.8)

UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-82041
(9.9 CRITICAL)

EPSS: 0.44%

updated 2026-10-02T21:32:19

2 posts

UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before forwarding supplied commands. Any authenticated user, regardless of role, can send arbitrary operating-system commands over gRPC to any connected agent, res

thehackerwire@mastodon.social at 2026-10-03T18:00:37.000Z ##

🔴 CVE-2026-82041 - Critical (9.9)

UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before for...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:00:37.000Z ##

🔴 CVE-2026-82041 - Critical (9.9)

UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before for...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104988
(8.1 HIGH)

EPSS: 0.20%

updated 2026-10-02T21:32:18

2 posts

A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem's agent certificate, which causes downstream authorization checks to treat the request as agent-privileged. An authenticated EST use

thehackerwire@mastodon.social at 2026-10-03T18:15:42.000Z ##

🟠 CVE-2026-104988 - High (8.1)

A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retai...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:15:42.000Z ##

🟠 CVE-2026-104988 - High (8.1)

A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retai...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39718
(8.8 HIGH)

EPSS: 0.14%

updated 2026-10-02T21:32:18

2 posts

Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross Site Request Forgery.This issue affects Wallstreet: from n/a through 2.8.6.

thehackerwire@mastodon.social at 2026-10-03T18:15:32.000Z ##

🟠 CVE-2026-39718 - High (8.8)

Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross Site Request Forgery.This issue affects Wallstreet: from n/a through 2.8.6.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:15:32.000Z ##

🟠 CVE-2026-39718 - High (8.8)

Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross Site Request Forgery.This issue affects Wallstreet: from n/a through 2.8.6.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96940
(8.8 HIGH)

EPSS: 0.50%

updated 2026-10-02T21:32:13

5 posts

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-10-03T18:30:40.000Z ##

🟠 CVE-2026-96940 - High (8.8)

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:30:40.000Z ##

🟠 CVE-2026-96940 - High (8.8)

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

tugatech@masto.pt at 2026-10-03T14:51:34.000Z ##

Microsoft lança atualizações urgentes para corrigir falha crítica no Exchange Server, que permite a elevação de privilégios e acesso não autorizado a caixas de correio de outros utilizadores. A falha, CVE-2026-96940, afeta várias versões do Exchange Server local. 🚨

🔗 tugatech.com.pt/t92180-microso

#exchange #falha #lan #microsoft #server 

##

DailyCyberSecurity@infosec.exchange at 2026-10-03T01:00:29.000Z ##

Microsoft's September 2026 V2 Exchange Server security updates add CVE-2026-96940 for Exchange SE, 2019 and 2016. Install them now.

#Microsoft #ExchangeServer #ExchangeSE #CVE202696940 #SecurityUpdate #PatchManagement #ESU

securityonline.info/exchange-s

##

mderooij@mastodon.social at 2026-10-02T23:53:52.000Z ##

PSA: Exchange Server V2 Security Updates for September were published, additionally addressing CVE-2026-96940 eightwone.com/2026/10/03/v2-se #MSExchange

##

CVE-2026-75937(CVSS UNKNOWN)

EPSS: 0.53%

updated 2026-10-02T21:32:07

2 posts

A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device.

offseq@infosec.exchange at 2026-10-03T04:30:23.000Z ##

Digi IX Family devices hit by CRITICAL OS command injection (CVE-2026-75937, CVSS 9.4). Unauthenticated remote attackers can execute root commands via HTTP POST. Disable web admin interface to reduce risk. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoT #Infosec

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T22:00:22.000Z ##

Digi DAL OS vulnerability CVE-2026-75937 (CVSS 9.4) lets attackers run root commands on Digi Accelerated Linux devices. Patch now.

#Digi #DALOS #CVE202675937 #CommandInjection #IoTSecurity #OTSecurity #Vulnerability

securityonline.info/digi-dal-o

##

CVE-2026-51916
(7.5 HIGH)

EPSS: 0.43%

updated 2026-10-02T21:32:04

2 posts

TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowledge object without requiring authentication in the route and without verifying organization ownership of the supplied knowledge_id.

thehackerwire@mastodon.social at 2026-10-03T19:00:38.000Z ##

🟠 CVE-2026-51916 - High (7.5)

TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowle...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T19:00:38.000Z ##

🟠 CVE-2026-51916 - High (7.5)

TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowle...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-51907
(8.1 HIGH)

EPSS: 0.39%

updated 2026-10-02T21:32:04

2 posts

In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter.

thehackerwire@mastodon.social at 2026-10-03T18:45:51.000Z ##

🟠 CVE-2026-51907 - High (8.1)

In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:45:51.000Z ##

🟠 CVE-2026-51907 - High (8.1)

In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103628
(9.6 CRITICAL)

EPSS: 0.33%

updated 2026-10-02T21:32:03

4 posts

Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

thehackerwire@mastodon.social at 2026-10-03T19:16:09.000Z ##

🔴 CVE-2026-103628 - Critical (9.6)

Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T19:16:09.000Z ##

🔴 CVE-2026-103628 - Critical (9.6)

Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

ssvc@infosec.exchange at 2026-10-03T03:17:16.000Z ##

Google Chrome published an empty blog post as a security advisory on Thursday afternoon. They filled it out in the past day, but don't make it easy to grasp the severity of their bugs.

For example, "Critical CVE-2026-103628: Out of bounds write in WebGL." is actually a CVSSv3.1: 9.6 critical because it allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. You'd have to chase down those details yourself on cve.org or elsewhere.

chromereleases.googleblog.com/

#google #chrome #CVE

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T21:49:21.000Z ##

Chrome security update: Chrome 154 fixes 11 flaws, including critical WebGL sandbox escape CVE-2026-103628. Update your browser now.

#Chrome #GoogleChrome #Chrome154 #CVE2026103628 #CVE2026103631 #BrowserSecurity #Vulnerability

securityonline.info/chrome-sec

##

CVE-2026-104019
(9.0 CRITICAL)

EPSS: 1.42%

updated 2026-10-02T21:16:54.477000

4 posts

OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as used by Amazon SageMaker Unified Studio, might allow an authenticated remote user with project contributor permissions to execute arbitrary commands in

thehackerwire@mastodon.social at 2026-10-03T18:30:30.000Z ##

🔴 CVE-2026-104019 - Critical (9)

OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:30:30.000Z ##

🔴 CVE-2026-104019 - Critical (9)

OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-03T06:00:26.000Z ##

CVE-2026-104019: CRITICAL OS command injection in AWS SageMaker Distribution (CVSS 9.0) can let project contributors run arbitrary code & steal credentials. Upgrade to fixed versions or restart supported Spaces for auto-patch. radar.offseq.com/threat/cve-20 #OffSeq #AWS #CVE #CloudSec

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T22:09:53.000Z ##

AWS fixes Loom for AWS admin takeover CVE-2026-103956 and a SageMaker Unified Studio code execution bug, CVE-2026-104019. Patch now.

#AWS #LoomForAWS #SageMaker #CVE2026103956 #CVE2026104019 #AISecurity #CloudSecurity #Vulnerability

securityonline.info/loom-for-a

##

CVE-2026-82039
(8.8 HIGH)

EPSS: 0.34%

updated 2026-10-02T20:17:04.430000

2 posts

UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are inserted unsanitized into a native PostgreSQL query via String.format(). Attackers can exploit the GET /api/utm-asset-groups/searchGroupsByFilter endpoint to execute arb

thehackerwire@mastodon.social at 2026-10-03T18:15:23.000Z ##

🟠 CVE-2026-82039 - High (8.8)

UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are inserted unsanit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:15:23.000Z ##

🟠 CVE-2026-82039 - High (8.8)

UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are inserted unsanit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-67989
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-02T20:17:03.933000

2 posts

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x

thehackerwire@mastodon.social at 2026-10-03T18:45:42.000Z ##

🟠 CVE-2026-67989 - High (7.5)

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:45:42.000Z ##

🟠 CVE-2026-67989 - High (7.5)

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18397
(0 None)

EPSS: 0.34%

updated 2026-10-02T20:17:02.060000

1 posts

This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component. The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.

cyberworldops@infosec.exchange at 2026-10-03T06:40:00.000Z ##

Thales SConnect is affected by CVE-2026-18397 (CVSS 4.0 9.4), which allows a malicious website to reach the native host and achieve remote code execution. This matters because it fronts hardware-token authentication for SWIFT, Qatar Tawtheeq and Sweden Skatteverket. #Thales #SConnect #CriticalVulnerability

cyberworldops.eu/en/sconnect-f

##

CVE-2026-104861
(7.5 HIGH)

EPSS: 0.43%

updated 2026-10-02T19:16:41.137000

1 posts

probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg.js and lib/parse_stream/svg.js use the searching regular expression /<[-_.:a-zA-Z0-9][^>]*>/, which repeatedly scans to the end of input when attacker-controlled data contains many less-than characters without a closing greater-than character. The synchronous parser converts and scans the

thehackerwire@mastodon.social at 2026-10-02T18:31:09.000Z ##

🟠 CVE-2026-104861 - High (7.5)

probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg.js and lib/parse_stream/svg.js use the searching regular expression /]*>/, which repeatedly scans to the end of input when attacker-cont...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86326
(0 None)

EPSS: 0.19%

updated 2026-10-02T19:10:09.143000

2 posts

An improper verification of cryptographic signature vulnerability exists in protocol gateways because the device does not properly verify the cryptographic authenticity of firmware images before installation. An attacker with high privileges and access to the firmware update interface could provide a specially crafted or modified firmware image, causing it to be installed on the device. Successful

DailyCyberSecurity@infosec.exchange at 2026-10-02T14:43:13.000Z ##

Moxa MGate vulnerabilities CVE-2026-86325 (CVSS 9.4) and CVE-2026-86326 hit MGate protocol gateway firmware. See affected versions and fixes.

#Moxa #MGate #CVE202686325 #CVE202686326 #ICSSecurity #OTSecurity #Vulnerability

securityonline.info/moxa-mgate

##

cR0w@infosec.exchange at 2026-10-02T13:28:30.000Z ##

moxa.com/en/support/product-su

CVE-2026-86325

A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the account_name parameter when processing account management requests. An attacker authenticated as a read-only user to the web management interface could supply a specially crafted account name that exceeds the size of the internal stack buffer, resulting in corruption of program execution flow. Successful exploitation could allow an attacker to read sensitive information from device memory, including credentials, modify arbitrary memory contents, and disrupt device availability.

CVE-2026-86326

An improper verification of cryptographic signature vulnerability exists in protocol gateways because the device does not properly verify the cryptographic authenticity of firmware images before installation. An attacker with high privileges and access to the firmware update interface could provide a specially crafted or modified firmware image, causing it to be installed on the device. Successful exploitation could allow the attacker to execute unauthorized code, compromise the integrity and availability of the device, and persist malicious modifications across subsequent firmware updates.

Given the high severity of these issues, users should apply the solutions immediately to reduce security risks.

##

CVE-2026-54049
(8.7 HIGH)

EPSS: 0.26%

updated 2026-10-02T18:47:49.947000

1 posts

Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's unsafeHTML() directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversa

thehackerwire@mastodon.social at 2026-10-02T17:20:29.000Z ##

🟠 CVE-2026-54049 - High (8.7)

Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them usin...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104851
(8.8 HIGH)

EPSS: 0.32%

updated 2026-10-02T18:47:49.947000

1 posts

fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.implementations.reference.ReferenceFileSystem evaluates fields from Kerchunk reference JSON documents through unrestricted jinja2.Template(...).render(...) calls in _process_references1._render_jinja, _process_templates, and _process_gen in fsspec/implementations/reference.py.

thehackerwire@mastodon.social at 2026-10-02T17:19:22.000Z ##

🟠 CVE-2026-104851 - High (8.8)

fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.implementations.reference.ReferenceFileSystem evaluates fields from Kerchunk reference JSON documents through unrestricted j...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90970
(9.9 CRITICAL)

EPSS: 0.94%

updated 2026-10-02T18:44:11.270000

14 posts

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command

1 repos

https://github.com/techupdate24/gitlab-ai-gateway-cve-2026-90970

security_crawler_carl at 2026-10-04T12:31:23.016Z ##

🏆 New Achievement! Duo-pocalypse Now!

Thank you for contacting GitLab Support. I see you're running a self-hosted AI Gateway. Great choice! Have you tried letting authenticated users execute arbitrary commands on it? Because CVE-2026-90970, CVSS 9.9, has gone ahead and enabled that feature for you. You're welcome. We've escalated your ticket to "catastrophic." (1/3)

##

threatnoir at 2026-10-04T10:05:57.027Z ##

⚠️ CRITICAL: GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab disclosed CVE-2026-90970, a critical RCE in AI Gateway that lets authenticated users with Duo Agent Platform access break out of prompt sandbox and run arbitrary commands. Self-hosted deployments are vulnerable; cloud instances are already patched. This is the second critical GitLab vuln in…

threatnoir.com/focus

🤖 AI generated summary

##

mohith808@mastodon.social at 2026-10-04T09:45:15.000Z ##

POV: you shipped an AI gateway

the prompt template: "hi {{name}}"

a logged in user with a crafted flow config: "what if i was a shell"

gitlab patched a CVSS 9.9 prompt template sandbox escape in its self-hosted AI gateway (CVE-2026-90970). affected: 18.1.6 to 19.2.3, 19.3.0 to 19.3.1, 19.4.0. fixed in 19.2.4, 19.3.2, 19.4.1. gitlab.com and dedicated already patched

#InfoSec #GitLab #AI #DevSecOps

##

security_crawler_carl@infosec.exchange at 2026-10-04T12:31:23.000Z ##

🏆 New Achievement! Duo-pocalypse Now!

Thank you for contacting GitLab Support. I see you're running a self-hosted AI Gateway. Great choice! Have you tried letting authenticated users execute arbitrary commands on it? Because CVE-2026-90970, CVSS 9.9, has gone ahead and enabled that feature for you. You're welcome. We've escalated your ticket to "catastrophic." (1/3)

##

threatnoir@infosec.exchange at 2026-10-04T10:05:57.000Z ##

⚠️ CRITICAL: GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab disclosed CVE-2026-90970, a critical RCE in AI Gateway that lets authenticated users with Duo Agent Platform access break out of prompt sandbox and run arbitrary commands. Self-hosted deployments are vulnerable; cloud instances are already patched. This is the second critical GitLab vuln in…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

mohith808@mastodon.social at 2026-10-04T09:45:15.000Z ##

POV: you shipped an AI gateway

the prompt template: "hi {{name}}"

a logged in user with a crafted flow config: "what if i was a shell"

gitlab patched a CVSS 9.9 prompt template sandbox escape in its self-hosted AI gateway (CVE-2026-90970). affected: 18.1.6 to 19.2.3, 19.3.0 to 19.3.1, 19.4.0. fixed in 19.2.4, 19.3.2, 19.4.1. gitlab.com and dedicated already patched

#InfoSec #GitLab #AI #DevSecOps

##

guru@thecybersecguru.com at 2026-10-03T13:31:19.000Z ##

Critical GitLab AI Gateway vulnerability (CVE-2026-90970) enables remote code execution on self-hosted servers

GitLab CVE-2026-90970 is a critical 9.9 AI Gateway sandbox escape affecting self-hosted deployments. Check affected versions and patches

thecybersecguru.com/exploits/g

##

beyondmachines1@infosec.exchange at 2026-10-03T10:01:13.000Z ##

GitLab Issues Emergency Patches for Actively Exploited Critical AI Gateway and Path Traversal Flaws

GitLab released emergency security updates to fix a critical remote code execution vulnerability in its AI Gateway (CVE-2026-90970) and a maximum-severity path traversal flaw (CVE-2026-85706) that allows unauthenticated attackers to steal sensitive server data.

**If you run self-hosted GitLab (Community or Enterprise Edition) or a self-hosted GitLab AI Gateway for Duo, patch now: upgrade the AI Gateway to 19.2.4, 19.3.2 or 19.4.1 and apply GitLab's latest security release. One of the flaws is already actively exploited. After patching, check your logs for strange flow configurations or file access, and rotate all AI provider API keys and other secrets on those servers.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

cyberworldops@infosec.exchange at 2026-10-03T03:00:01.000Z ##

GitLab patched CVE-2026-90970, a sandbox escape in self-hosted AI Gateway allowing authenticated Duo Agent users to execute arbitrary commands via crafted flow configs. Self-hosted deployments should patch and audit for abuse, as gateway compromise can expose AI workflows and downstream systems. #GitLab #AiSecurity #SandboxEscape

cyberworldops.eu/en/gitlab-fix

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T21:42:58.000Z ##

GitLab AI Gateway vulnerability CVE-2026-90970 (CVSS 9.9) lets Duo Agent Platform users run commands. Upgrade self-hosted gateways now.

#GitLab #AIGateway #GitLabDuo #CVE202690970 #RCE #DevSecOps #Vulnerability

securityonline.info/gitlab-ai-

##

news@fawkes.rocks at 2026-10-02T17:18:15.000Z ##

GitLab AI Gateway flaw CVE-2026-90970 enables RCE

fawkes.rocks/2026/10/02/gitlab

##

cR0w@infosec.exchange at 2026-10-02T16:23:33.000Z ##

Go hack more AI shit.

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.9 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.

##

nyanbinary@infosec.exchange at 2026-10-02T15:43:07.000Z ##

Go hack more AI shit.
Go hack more Gitlab.

But most importantly, hack more Gitlab AI shit: db.gcve.eu/vuln/cve-2026-90970

##

thehackerwire@mastodon.social at 2026-10-02T15:18:39.000Z ##

🔴 CVE-2026-90970 - Critical (9.9)

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authentic...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103922
(9.3 CRITICAL)

EPSS: 0.21%

updated 2026-10-02T18:44:11.270000

2 posts

Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host and scheme but not its path, allowing a victim who activates an untrusted link to navigate a frame to /_capacitor_http_interceptor_. The native proxy can fetch an attacker-selected URL and return the re

1 repos

https://github.com/techupdate24/capacitor-flaw-cve-2026-103922

beyondmachines1 at 2026-10-04T08:01:14.127Z ##

Critical Capacitor Flaw Allows Malicious Links to Hijack Mobile App Data and Native Features

Capacitor patched a critical vulnerability (CVE-2026-103922) that allows malicious links to load attacker-controlled content within a mobile app's trusted origin. This flaw enables unauthorized access to sensitive user data, authentication tokens, and native device features through Capacitor plugins.

**If you build mobile apps with Capacitor, update to a patched version (6.2.2, 7.6.9, 8.3.5, 8.4.3 or 8.5.1), then rebuild your Android and iOS apps and push the new versions to users. Updating the package alone doesn't protect anyone. If you can't update, block navigation to the internal interceptor path with a custom plugin, and rebuild the apps. Prioritize apps that show chat messages, feeds or other user content first.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-10-04T08:01:14.000Z ##

Critical Capacitor Flaw Allows Malicious Links to Hijack Mobile App Data and Native Features

Capacitor patched a critical vulnerability (CVE-2026-103922) that allows malicious links to load attacker-controlled content within a mobile app's trusted origin. This flaw enables unauthorized access to sensitive user data, authentication tokens, and native device features through Capacitor plugins.

**If you build mobile apps with Capacitor, update to a patched version (6.2.2, 7.6.9, 8.3.5, 8.4.3 or 8.5.1), then rebuild your Android and iOS apps and push the new versions to users. Updating the package alone doesn't protect anyone. If you can't update, block navigation to the internal interceptor path with a custom plugin, and rebuild the apps. Prioritize apps that show chat messages, feeds or other user content first.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-94422
(8.8 HIGH)

EPSS: 0.69%

updated 2026-10-02T18:44:11.270000

1 posts

An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox bound

thehackerwire@mastodon.social at 2026-10-02T15:17:32.000Z ##

🟠 CVE-2026-94422 - High (8.8)

An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102489
(9.8 CRITICAL)

EPSS: 1.40%

updated 2026-10-02T18:32:21

11 posts

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

thecybermind at 2026-10-04T15:05:08.707Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-102489 – Zammad GmbH Zammad Session Fixation Vulnerability

Immediate CISA KEV threat advisory for CVE-2026-102489 affecting Zammad. Includes session fixation RCE analysis, CISO compliance steps, and comprehensive asset hardening runbooks....

thecybermind.co/qfru

##

thecybermind at 2026-10-04T15:02:52.224Z ##

(CISA TwS) The Cyber Mind TSUITE Brief: CVE-2026-102489 – Zammad GmbH Zammad Session Fixation Vulnerability

Immediate CISA KEV threat advisory for CVE-2026-102489 affecting Zammad. Includes session fixation RCE analysis, BOD 26-04 compliance guidance, and multi-vendor SOC detection queries....

thecybermind.co/l7ux

##

secpoint@mastodon.social at 2026-10-04T12:26:03.000Z ##

Zammad security alert: session hijacking and remote code execution

CVE-2026-102489 concerns session hijacking that can lead to code execution as the Zammad service account on affected older installations. DIVD reports exploitation in a real incident.

Zammad states that version 7.0 and later are not exploitable through this issue and recommends upgrading to 7.2.0.

#Zammad #CyberSecurity #VulnerabilityManagement #SecPoint #Penetrator

##

thecybermind@infosec.exchange at 2026-10-04T15:05:08.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-102489 – Zammad GmbH Zammad Session Fixation Vulnerability

Immediate CISA KEV threat advisory for CVE-2026-102489 affecting Zammad. Includes session fixation RCE analysis, CISO compliance steps, and comprehensive asset hardening runbooks....

thecybermind.co/qfru

##

thecybermind@infosec.exchange at 2026-10-04T15:02:52.000Z ##

(CISA TwS) The Cyber Mind TSUITE Brief: CVE-2026-102489 – Zammad GmbH Zammad Session Fixation Vulnerability

Immediate CISA KEV threat advisory for CVE-2026-102489 affecting Zammad. Includes session fixation RCE analysis, BOD 26-04 compliance guidance, and multi-vendor SOC detection queries....

thecybermind.co/l7ux

##

secpoint@mastodon.social at 2026-10-04T12:26:03.000Z ##

Zammad security alert: session hijacking and remote code execution

CVE-2026-102489 concerns session hijacking that can lead to code execution as the Zammad service account on affected older installations. DIVD reports exploitation in a real incident.

Zammad states that version 7.0 and later are not exploitable through this issue and recommends upgrading to 7.2.0.

#Zammad #CyberSecurity #VulnerabilityManagement #SecPoint #Penetrator

##

security_crawler_carl@infosec.exchange at 2026-10-02T22:35:39.000Z ##

The Dutch Institute for Vulnerability Disclosure, whose entire ledger is OTHER people's vulnerabilities, has recorded a significant loss in column B.

Agentic AI in the threat actor slot: filed under Equipment Used Against Us. Session tokens: stolen. Root access: granted to strangers. Irony reserves: critically depleted.

Patch Zammad immediately to address CVE-2026-102489 and the second zero-day, and review DIVD's published findings for full remediation guidance. (2/3)

##

security_crawler_carl@infosec.exchange at 2026-10-02T22:35:38.000Z ##

🏆 New Achievement! Auditing the Auditors, Zero Days Found, Zero Days Remaining!

Conducting inventory review of DIVD assets. Status: two zero-day vulnerabilities in Zammad (CVE-2026-102489, CVSS 9.4, and a companion flaw) — unpatched, unaccounted for, now exploited. An AI-powered automated attack chained both flaws to hijack sessions, execute remote code, and escalate privileges to root. In seconds. (1/3)

##

AAKL@infosec.exchange at 2026-10-02T17:11:31.000Z ##

CISA has updated the catalogue. GMBH is looking like Swiss cheese these days.

- CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability cve.org/CVERecord?id=CVE-2026-

Yesterday's funny headline:

CISA Launches Cybersecurity Awareness Month: Securing the Next 250 cisa.gov/news-events/news/cisa #CISA #infosec #vulnerability

##

cisakevtracker@mastodon.social at 2026-10-02T17:01:17.000Z ##

CVE ID: CVE-2026-102489
Vendor: Zammad GmbH
Product: Zammad
Date Added: 2026-10-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-10-02T17:00:11.000Z ##

🚨 [CISA-2026:1002] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-102489 (secdb.nttzen.cloud/cve/detail/)
- Name: Zammad GmbH Zammad Session Fixation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Zammad GmbH
- Product: Zammad
- Notes: zammad.com/en/product/releases/ ; community.zammad.org/t/take-ca ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-102490 (secdb.nttzen.cloud/cve/detail/)
- Name: Zammad GmbH Zammad Improper Privilege Management Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Zammad GmbH
- Product: Zammad
- Notes: zammad.com/en/product/releases/ ; community.zammad.org/t/take-ca ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261002 #cisa20261002 #cve_2026_102489 #cve_2026_102490 #cve2026102489 #cve2026102490

##

CVE-2026-102490
(9.8 CRITICAL)

EPSS: 0.63%

updated 2026-10-02T18:32:21

5 posts

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

thecybermind at 2026-10-04T09:28:59.584Z ##

The Cyber Mind Cybersecurity Weekly Brief October 4, 2026

Immediate CISA KEV threat advisory for CVE-2026-102490 affecting Zammad. Includes privilege escalation workflow analysis, BOD 26-04 compliance steps, and production-ready SOC detection queries....

thecybermind.co/9km9

##

thecybermind@infosec.exchange at 2026-10-04T09:28:59.000Z ##

The Cyber Mind Cybersecurity Weekly Brief October 4, 2026

Immediate CISA KEV threat advisory for CVE-2026-102490 affecting Zammad. Includes privilege escalation workflow analysis, BOD 26-04 compliance steps, and production-ready SOC detection queries....

thecybermind.co/9km9

##

AAKL@infosec.exchange at 2026-10-02T17:11:31.000Z ##

CISA has updated the catalogue. GMBH is looking like Swiss cheese these days.

- CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability cve.org/CVERecord?id=CVE-2026-

- CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability cve.org/CVERecord?id=CVE-2026-

Yesterday's funny headline:

CISA Launches Cybersecurity Awareness Month: Securing the Next 250 cisa.gov/news-events/news/cisa #CISA #infosec #vulnerability

##

cisakevtracker@mastodon.social at 2026-10-02T17:01:02.000Z ##

CVE ID: CVE-2026-102490
Vendor: Zammad GmbH
Product: Zammad
Date Added: 2026-10-02
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-10-02T17:00:11.000Z ##

🚨 [CISA-2026:1002] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-102489 (secdb.nttzen.cloud/cve/detail/)
- Name: Zammad GmbH Zammad Session Fixation Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Zammad GmbH
- Product: Zammad
- Notes: zammad.com/en/product/releases/ ; community.zammad.org/t/take-ca ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-102490 (secdb.nttzen.cloud/cve/detail/)
- Name: Zammad GmbH Zammad Improper Privilege Management Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset&#39;s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Zammad GmbH
- Product: Zammad
- Notes: zammad.com/en/product/releases/ ; community.zammad.org/t/take-ca ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261002 #cisa20261002 #cve_2026_102489 #cve_2026_102490 #cve2026102489 #cve2026102490

##

CVE-2026-102795
(9.3 CRITICAL)

EPSS: 0.28%

updated 2026-10-02T18:31:37

1 posts

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. This CVE supersedes CVE-2026-41920, whose record listed the affected 9.x versions as 9.0.0 through 9.1.14 and the fixed version as 9.1.15. All 9.

thehackerwire@mastodon.social at 2026-10-02T18:31:18.000Z ##

🔴 CVE-2026-102795 - Critical (9.3)

Improper Access Control vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the is...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-101104
(7.7 HIGH)

EPSS: 0.27%

updated 2026-10-02T18:31:25

1 posts

The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions.

thehackerwire@mastodon.social at 2026-10-02T16:20:11.000Z ##

🟠 CVE-2026-101104 - High (7.7)

The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104431
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-02T17:59:09.430000

1 posts

Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sigop P2SH transactions that reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresp

thehackerwire@mastodon.social at 2026-10-02T16:48:07.000Z ##

🟠 CVE-2026-104431 - High (7.5)

Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sig...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102667
(8.3 HIGH)

EPSS: 0.19%

updated 2026-10-02T17:17:01.083000

1 posts

Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream' module, or access app-internal storage. If the installed app has been granted permissions previously, the attacker can access the entire file system, camera, mi

thehackerwire@mastodon.social at 2026-10-02T17:45:33.000Z ##

🟠 CVE-2026-102667 - High (8.3)

Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream' module, ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104026
(7.8 HIGH)

EPSS: 0.13%

updated 2026-10-02T15:31:37

1 posts

In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl log/blame/annotate.

thehackerwire@mastodon.social at 2026-10-02T15:17:23.000Z ##

🟠 CVE-2026-104026 - High (7.8)

In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19652
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-02T15:31:32

1 posts

The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowe

thehackerwire@mastodon.social at 2026-10-02T15:17:40.000Z ##

🔴 CVE-2026-19652 - Critical (9.8)

The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104610
(10.0 CRITICAL)

EPSS: 0.64%

updated 2026-10-02T15:31:31

2 posts

A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

thehackerwire@mastodon.social at 2026-10-02T15:18:48.000Z ##

🔴 CVE-2026-104610 - Critical (10)

A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads to stac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

cR0w@infosec.exchange at 2026-10-02T13:18:54.000Z ##

cve.org/CVERecord?id=CVE-2026-

cc: @da_667

##

CVE-2026-104462
(7.5 HIGH)

EPSS: 0.31%

updated 2026-10-02T15:17:08.050000

1 posts

YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute into a raw SQL IN clause. Attackers with page-write access (unauthenticated on default installs) can embed a nuagetag tag ending in a backslash to break quote parity and inject a UNION subquery, exfiltrating password hashes and arbitrary table data.

thehackerwire@mastodon.social at 2026-10-02T15:47:22.000Z ##

🟠 CVE-2026-104462 - High (7.5)

YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute into a raw SQL IN clause. Attackers with page-write access (unauthenticated on default installs) can embed a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104448
(8.1 HIGH)

EPSS: 0.16%

updated 2026-10-02T15:17:07.150000

1 posts

YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the ajaxdeletepage handler, which permanently deletes a page on any GET request carrying a jsonp_callback parameter without checking a CSRF token. Attackers can lure a logged-in administrator or page owner to a crafted link to delete arbitrary pages along with their ACLs, links, triples, comments and referrers.

thehackerwire@mastodon.social at 2026-10-02T16:20:31.000Z ##

🟠 CVE-2026-104448 - High (8.1)

YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the ajaxdeletepage handler, which permanently deletes a page on any GET request carrying a jsonp_callback parameter without checking a CSRF token. Attackers can lure a log...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104611
(9.1 CRITICAL)

EPSS: 0.49%

updated 2026-10-02T14:17:09.660000

1 posts

A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fast_setting_internet_set of the component POST Request Handler. Performing a manipulation of the argument netWanType results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.

thehackerwire@mastodon.social at 2026-10-02T15:18:56.000Z ##

🔴 CVE-2026-104611 - Critical (9.1)

A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fast_setting_internet_set of the component POST Request Handler. Performing a manipulation of the argument netWanType results in stack-based...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104286
(9.8 CRITICAL)

EPSS: 2.20%

updated 2026-10-02T12:35:33.990000

11 posts

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

2 repos

https://github.com/techupdate24/fortimail-zero-day-cve-2026-104286

https://github.com/ShadowForge-Cyber/CVE-2026-104286-POC

youranonnewsirc@nerdculture.de at 2026-10-04T16:26:20.000Z ##

Geopolitical tensions are escalating with intensified fighting in Yemen, as Iran reiterates that there is "no military solution" to the ongoing conflict. In technology, OpenAI has halted the release of its GPT-6.1 Astra model citing safety concerns, highlighting the growing scrutiny of advanced AI. On the cybersecurity front, a suspected ShinyHunters hacker has been detained in Jordan, assisting the FBI. Urgent action is also advised for an exploited critical FortiMail zero-day vulnerability (CVE-2026-104286).

#AnonNews_irc #Cybersecurity #News

##

cyberveille@mastobot.ping.moi at 2026-10-04T09:00:37.000Z ##

📢 ⚠️ [VULN] Utilisateurs de FortiMail, attention à une nouvelle vulnérabilité critique - CVE-2026-104286

Fortinet vient d’avertir d’une vulnérabilité critique de traversée de chemin dans FortiMail. Référencée CVE-2026-104286, elle est déjà exploitée par des acteurs malveillants.

🔗 lemagit.fr/actualites/36665157
💬 discussion : infosec.pub/post/53131369
#Vulnérabilité #CVE #Cyberveille

##

threatnoir at 2026-10-04T05:15:04.320Z ##

2026-W40 — Weekly Threat Roundup

🔥 A zero-day in Fortinet FortiMail (CVE-2026-104286) is actively exploited with no patch available yet, demanding immediate workarounds.
🏴‍☠️ Operation KillSwitch dismantled the KillSec ransomware gang, allegedly run by a 16-year-old, seizing 110TB of stolen victim data.
🇨🇳 China-linked Warlock…

threatnoir.com/weekly/2026-w40

🤖 AI generated summary

##

netsecio@mastodon.social at 2026-10-03T19:05:11.000Z ##

📰 Critical Fortinet FortiMail Zero-Day Exploited for RCE

Fortinet warns of critical zero-day (CVE-2026-104286) in FortiMail, actively exploited for RCE. CVSS 9.8. CISA added to KEV. Patches are pending, but urgent workarounds are available. #Fortinet #ZeroDay #CVE2026104286 #CyberSecurity

🔗 cyber.netsecops.io/articles/cr

##

youranonnewsirc@nerdculture.de at 2026-10-04T16:26:20.000Z ##

Geopolitical tensions are escalating with intensified fighting in Yemen, as Iran reiterates that there is "no military solution" to the ongoing conflict. In technology, OpenAI has halted the release of its GPT-6.1 Astra model citing safety concerns, highlighting the growing scrutiny of advanced AI. On the cybersecurity front, a suspected ShinyHunters hacker has been detained in Jordan, assisting the FBI. Urgent action is also advised for an exploited critical FortiMail zero-day vulnerability (CVE-2026-104286).

#AnonNews_irc #Cybersecurity #News

##

threatnoir@infosec.exchange at 2026-10-04T05:15:04.000Z ##

2026-W40 — Weekly Threat Roundup

🔥 A zero-day in Fortinet FortiMail (CVE-2026-104286) is actively exploited with no patch available yet, demanding immediate workarounds.
🏴‍☠️ Operation KillSwitch dismantled the KillSec ransomware gang, allegedly run by a 16-year-old, seizing 110TB of stolen victim data.
🇨🇳 China-linked Warlock…

threatnoir.com/weekly/2026-w40

#infosec #cybersecurity #threatintel

🤖 AI generated summary

##

netsecio@mastodon.social at 2026-10-03T19:05:11.000Z ##

📰 Critical Fortinet FortiMail Zero-Day Exploited for RCE

Fortinet warns of critical zero-day (CVE-2026-104286) in FortiMail, actively exploited for RCE. CVSS 9.8. CISA added to KEV. Patches are pending, but urgent workarounds are available. #Fortinet #ZeroDay #CVE2026104286 #CyberSecurity

🔗 cyber.netsecops.io/articles/cr

##

censys@infosec.exchange at 2026-10-02T21:42:21.000Z ##

🚨 Fortinet reports active exploitation of CVE-2026-104286, a critical path traversal vulnerability affecting FortiMail.

Censys observes roughly 2,800 Internet-exposed FortiMail hosts after excluding honeypots. This is an exposure count, not a confirmed-vulnerable count.

No fixed builds have been released as of October 2. Censys ARC covers affected versions, Fortinet’s current workarounds, indicators, and remediation guidance: censys.com/advisory/cve-2026-1

#CensysARC #Fortinet #FortiMail #Cybersecurity #Vulnerability

##

jbz@indieweb.social at 2026-10-02T19:00:11.000Z ##

🚨 Fortinet sounds the alarm over actively exploited FortiMail zero-day

「 The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security platform 」

theregister.com/security/2026/

#fortinet #fortimail #cybersecurity

##

thehackerwire@mastodon.social at 2026-10-02T17:30:29.000Z ##

🔴 CVE-2026-104286 - Critical (9.8)

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an una...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

AAKL@infosec.exchange at 2026-10-02T16:11:11.000Z ##

Fortinet has a couple of advisories today, one pertaining to a critical vulnerability.

CRITICAL: CVE-2026-104286 - Improper Pathname Restriction Allows Unauthenticated Arbitrary File Write in Fortinet FortiMail app.opencve.io/cve/CVE-2026-10

More:

The Register: Fortinet sounds the alarm over actively exploited FortiMail zero-day theregister.com/security/2026/ @theregister @carlypage #infosec #Fortinet #zeroday #vulnerability

##

CVE-2026-91828
(7.5 HIGH)

EPSS: 0.31%

updated 2026-10-02T12:32:16

1 posts

The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust the site's PHP worker pool and make the entire site unavailable.

thehackerwire@mastodon.social at 2026-10-02T17:20:19.000Z ##

🟠 CVE-2026-91828 - High (7.5)

The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104456
(7.6 HIGH)

EPSS: 0.30%

updated 2026-10-02T12:31:26

1 posts

YesWiki before 4.6.7 contains a second-order SQL injection vulnerability in AclService::updateRequestWithACL, where a stored username is concatenated unescaped into a read-ACL LIKE clause. Attackers can self-register an account name containing a double-quote payload, then load non-admin ACL-filtered listings to read database contents and bypass read ACLs.

thehackerwire@mastodon.social at 2026-10-02T15:47:40.000Z ##

🟠 CVE-2026-104456 - High (7.6)

YesWiki before 4.6.7 contains a second-order SQL injection vulnerability in AclService::updateRequestWithACL, where a stored username is concatenated unescaped into a read-ACL LIKE clause. Attackers can self-register an account name containing a d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104467
(8.1 HIGH)

EPSS: 0.37%

updated 2026-10-02T12:31:26

1 posts

YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. Attackers can send requests to endpoints like api/ci/update_config and api/archives to overwrite configuration and list, download, or delete backup archives.

thehackerwire@mastodon.social at 2026-10-02T15:32:50.000Z ##

🟠 CVE-2026-104467 - High (8.1)

YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. Attackers can send requests to endpoints like ap...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104472
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-02T12:31:26

1 posts

YesWiki before 4.6.7 contains a missing authorization vulnerability in the attachment download handler that allows unauthenticated attackers to bypass page read ACLs. Attackers can request the download handler with a known page tag and file parameter to retrieve confidential attachments from read-restricted pages.

thehackerwire@mastodon.social at 2026-10-02T15:32:40.000Z ##

🟠 CVE-2026-104472 - High (7.5)

YesWiki before 4.6.7 contains a missing authorization vulnerability in the attachment download handler that allows unauthenticated attackers to bypass page read ACLs. Attackers can request the download handler with a known page tag and file parame...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104457
(8.6 HIGH)

EPSS: 0.28%

updated 2026-10-02T12:31:25

1 posts

YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filtertags action, which wraps unescaped filterN attribute tokens in quotes and concatenates them into a raw tags.value IN (...) clause. Unauthenticated attackers on default installs can save filtertags markup in a page with a trailing-backslash token that breaks quote parity under MySQL backslash escaping. This lets them in

thehackerwire@mastodon.social at 2026-10-02T16:20:21.000Z ##

🟠 CVE-2026-104457 - High (8.6)

YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filtertags action, which wraps unescaped filterN attribute tokens in quotes and concatenates them into a raw tags.value IN (...) clause. Unauthenticated attackers on default...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104464
(8.6 HIGH)

EPSS: 0.29%

updated 2026-10-02T12:31:25

1 posts

YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET requests by supplying an unvalidated actor URL to the Bazar abonnements sync action. Attackers can target internal hosts or cloud metadata endpoints and chain attacker-controlled outbox first/next links, with fetched responses stored as readable Bazar entries.

thehackerwire@mastodon.social at 2026-10-02T15:47:31.000Z ##

🟠 CVE-2026-104464 - High (8.6)

YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET requests by supplying an unvalidated actor URL to the Bazar abonnements sync action. Attackers can target inter...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104460
(7.5 HIGH)

EPSS: 0.39%

updated 2026-10-02T12:31:25

1 posts

YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}} action because Bazar list option ids are concatenated into SQL REGEXP/LIKE clauses in actions/newtextsearch.php without escaping. Anonymous attackers can plant a malicious option id in an anonymously editable Bazar list and use search requests as a boolean oracle to read arbitrary database data, including ad

thehackerwire@mastodon.social at 2026-10-02T15:32:59.000Z ##

🟠 CVE-2026-104460 - High (7.5)

YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}} action because Bazar list option ids are concatenated into SQL REGEXP/LIKE clauses in actions/newtextsearch.php without escaping. Anonymous attackers can pl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104416
(7.5 HIGH)

EPSS: 0.31%

updated 2026-10-02T12:31:20

1 posts

Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges.

thehackerwire@mastodon.social at 2026-10-02T17:04:11.000Z ##

🟠 CVE-2026-104416 - High (7.5)

Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for hig...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104423
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-02T12:31:20

1 posts

Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared unprioritized Halo2 verification queue with zero-fee transactions carrying zero-filled Orchard and Ironwood proofs, causing nodes to fall behind the chain tip.

thehackerwire@mastodon.social at 2026-10-02T16:48:27.000Z ##

🟠 CVE-2026-104423 - High (7.5)

Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared unprio...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104422
(7.5 HIGH)

EPSS: 0.18%

updated 2026-10-02T12:31:20

1 posts

The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too far behind the tip before consensus validation, without penalizing the supplying peer. Because V5 transaction IDs exclude the scriptSig, a malicious peer can repeatedly serve a canonical block whose coinbase claims height 1 while keeping the re

thehackerwire@mastodon.social at 2026-10-02T16:48:18.000Z ##

🟠 CVE-2026-104422 - High (7.5)

The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too far behind the tip before consensus validation, without penalizing the supplying peer. Beca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104430
(7.5 HIGH)

EPSS: 0.41%

updated 2026-10-02T12:31:20

1 posts

Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold multisig redeem scripts so that a block zcashd accepts exceeds Zebra's inflated MAX_BL

thehackerwire@mastodon.social at 2026-10-02T16:34:37.000Z ##

🟠 CVE-2026-104430 - High (7.5)

Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104445
(8.2 HIGH)

EPSS: 0.40%

updated 2026-10-02T12:31:20

1 posts

YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. Unauthenticated attackers with any ActivityPub keypair can send signed Delete or Update activities referencing a mirrored entry's sourceUrl to delete or overwrite other actors' federated entries.

thehackerwire@mastodon.social at 2026-10-02T16:34:28.000Z ##

🟠 CVE-2026-104445 - High (8.2)

YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. Unauthenticated attackers with any ActivityPub keypair can send signed Delet...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104443
(8.1 HIGH)

EPSS: 0.36%

updated 2026-10-02T12:31:20

1 posts

YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic triples regardless of ownership. Attackers can send an empty filter to the triples delete endpoint to remove the admins-group membership triple, emptying the admin group and causing a site-wide authorization lockout.

thehackerwire@mastodon.social at 2026-10-02T16:34:19.000Z ##

🟠 CVE-2026-104443 - High (8.1)

YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic triples regardless of ownership. Attackers can send an empty filter to the triples delete...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104410
(7.5 HIGH)

EPSS: 0.38%

updated 2026-10-02T12:31:19

1 posts

SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled database rows via the /api/export/preview endpoint. Attackers can request an export preview of a public document embedding a database view to obtain protected rows' primary-key text and cell values.

thehackerwire@mastodon.social at 2026-10-02T17:04:21.000Z ##

🟠 CVE-2026-104410 - High (7.5)

SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled database rows via the /api/export/preview endpoint. Attackers can request an export preview of a publi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104414
(8.1 HIGH)

EPSS: 0.28%

updated 2026-10-02T12:31:19

1 posts

Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post content via oEmbed photo responses. Attackers can host malicious oEmbed photo responses so that embedding their URL stores scripts that run in the Ghost editor, published site, and newsletter emails, compromising staff admin sessions.

thehackerwire@mastodon.social at 2026-10-02T17:04:02.000Z ##

🟠 CVE-2026-104414 - High (8.1)

Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post content via oEmbed photo responses. Attackers can host malicious oEmbed photo responses so that embeddi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86325(CVSS UNKNOWN)

EPSS: 0.34%

updated 2026-10-02T12:31:19

2 posts

A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the `account_name` parameter when processing account management requests. An attacker authenticated as a read-only user to the web management interface could supply a specially crafted account name that exceeds the size of the inter

DailyCyberSecurity@infosec.exchange at 2026-10-02T14:43:13.000Z ##

Moxa MGate vulnerabilities CVE-2026-86325 (CVSS 9.4) and CVE-2026-86326 hit MGate protocol gateway firmware. See affected versions and fixes.

#Moxa #MGate #CVE202686325 #CVE202686326 #ICSSecurity #OTSecurity #Vulnerability

securityonline.info/moxa-mgate

##

cR0w@infosec.exchange at 2026-10-02T13:28:30.000Z ##

moxa.com/en/support/product-su

CVE-2026-86325

A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the account_name parameter when processing account management requests. An attacker authenticated as a read-only user to the web management interface could supply a specially crafted account name that exceeds the size of the internal stack buffer, resulting in corruption of program execution flow. Successful exploitation could allow an attacker to read sensitive information from device memory, including credentials, modify arbitrary memory contents, and disrupt device availability.

CVE-2026-86326

An improper verification of cryptographic signature vulnerability exists in protocol gateways because the device does not properly verify the cryptographic authenticity of firmware images before installation. An attacker with high privileges and access to the firmware update interface could provide a specially crafted or modified firmware image, causing it to be installed on the device. Successful exploitation could allow the attacker to execute unauthorized code, compromise the integrity and availability of the device, and persist malicious modifications across subsequent firmware updates.

Given the high severity of these issues, users should apply the solutions immediately to reduce security risks.

##

CVE-2026-80298
(8.8 HIGH)

EPSS: 0.29%

updated 2026-10-02T12:31:18

1 posts

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows SQL Injection. This issue affects Sef - AI Chatbot Platform: before 2.1.

thehackerwire@mastodon.social at 2026-10-02T17:20:08.000Z ##

🟠 CVE-2026-80298 - High (8.8)

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows SQL Injection.

This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93698
(9.9 CRITICAL)

EPSS: 0.46%

updated 2026-10-02T09:31:25

1 posts

Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.

cR0w@infosec.exchange at 2026-10-02T13:31:31.000Z ##

cPanel vulns are fun, right? IDK what Adminbin is but I'm sure some of you do. Have fun.

support.cpanel.net/hc/en-us/ar

sev:CRIT 9.9 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.

nvd.nist.gov/vuln/detail/cve-2

##

CVE-2026-48005
(7.5 HIGH)

EPSS: 0.61%

updated 2026-10-01T21:33:58

1 posts

Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck . Users are recommended to upgrade to version 2.4.69, which fixes this issue.

thehackerwire@mastodon.social at 2026-10-02T19:15:41.000Z ##

🟠 CVE-2026-48005 - High (7.5)

Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorizati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57941
(9.8 CRITICAL)

EPSS: 0.44%

updated 2026-10-01T21:33:58

1 posts

Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

thehackerwire@mastodon.social at 2026-10-02T19:00:39.000Z ##

🔴 CVE-2026-57941 - Critical (9.8)

Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63292
(7.5 HIGH)

EPSS: 0.58%

updated 2026-10-01T21:33:58

1 posts

Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default. Users ar

1 repos

https://github.com/0xBlackash/CVE-2026-63292

thehackerwire@mastodon.social at 2026-10-02T18:32:08.000Z ##

🟠 CVE-2026-63292 - High (7.5)

Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Ho...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63045
(7.5 HIGH)

EPSS: 0.33%

updated 2026-10-01T21:33:58

1 posts

Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

thehackerwire@mastodon.social at 2026-10-02T18:31:59.000Z ##

🟠 CVE-2026-63045 - High (7.5)

Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data conn...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59685
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-01T21:33:58

1 posts

Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

thehackerwire@mastodon.social at 2026-10-02T18:01:04.000Z ##

🟠 CVE-2026-59685 - High (7.5)

Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded.

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63718
(7.5 HIGH)

EPSS: 0.32%

updated 2026-10-01T21:33:58

1 posts

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68.

thehackerwire@mastodon.social at 2026-10-02T17:45:54.000Z ##

🟠 CVE-2026-63718 - High (7.5)

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding.

This issue affects Apache HTTP Serv...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93546
(8.8 HIGH)

EPSS: 0.34%

updated 2026-10-01T21:33:58

1 posts

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.

thehackerwire@mastodon.social at 2026-10-02T17:45:44.000Z ##

🟠 CVE-2026-93546 - High (8.8)

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XM...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56449
(7.5 HIGH)

EPSS: 0.42%

updated 2026-10-01T21:33:57

1 posts

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

thehackerwire@mastodon.social at 2026-10-02T19:15:32.000Z ##

🟠 CVE-2026-56449 - High (7.5)

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies.

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56153
(7.5 HIGH)

EPSS: 0.50%

updated 2026-10-01T21:33:57

1 posts

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

thehackerwire@mastodon.social at 2026-10-02T19:00:48.000Z ##

🟠 CVE-2026-56153 - High (7.5)

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite.

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-59797
(9.8 CRITICAL)

EPSS: 0.39%

updated 2026-10-01T21:33:57

1 posts

Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

thehackerwire@mastodon.social at 2026-10-02T18:01:13.000Z ##

🔴 CVE-2026-59797 - Critical (9.8)

Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103484
(8.8 HIGH)

EPSS: 0.42%

updated 2026-10-01T21:33:02

1 posts

IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.

thehackerwire@mastodon.social at 2026-10-02T17:30:39.000Z ##

🟠 CVE-2026-103484 - High (8.8)

IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-102628
(9.3 CRITICAL)

EPSS: 0.28%

updated 2026-10-01T21:32:51

1 posts

The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, causing Laravel to expose the entire server environment, including all .env configuration variables, in plaintext. Fixed on or before 2026-09-02.

thehackerwire@mastodon.social at 2026-10-02T17:30:48.000Z ##

🔴 CVE-2026-102628 - Critical (9.3)

The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-73636
(8.1 HIGH)

EPSS: 0.37%

updated 2026-10-01T21:17:24.300000

1 posts

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to versi

thehackerwire@mastodon.social at 2026-10-02T18:00:55.000Z ##

🟠 CVE-2026-73636 - High (8.1)

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-63686
(7.5 HIGH)

EPSS: 0.33%

updated 2026-10-01T21:17:23.790000

1 posts

A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

thehackerwire@mastodon.social at 2026-10-02T18:32:17.000Z ##

🟠 CVE-2026-63686 - High (7.5)

A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partia...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-56154
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-10-01T21:17:22.267000

1 posts

Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

thehackerwire@mastodon.social at 2026-10-02T19:00:57.000Z ##

🔴 CVE-2026-56154 - Critical (9.8)

Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-12627
(9.8 CRITICAL)

EPSS: 0.44%

updated 2026-10-01T20:34:26.287000

1 posts

Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.

netsecio@mastodon.social at 2026-10-04T18:08:12.000Z ##

📰 Fortra Patches Critical Flaws in BoKS Privileged Access Manager

Fortra patches 3 critical vulnerabilities in its BoKS Privileged Access Manager. Flaws include auth bypass (CVE-2026-79901, 9.9), RCE (CVE-2026-79898, 9.1), and buffer overflow (CVE-2026-12627, 9.8). #CVE #PatchNow #Linux

🔗 cyber.netsecops.io/articles/fo

##

CVE-2026-79898
(9.1 CRITICAL)

EPSS: 0.98%

updated 2026-10-01T20:34:26.287000

1 posts

Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide network-accessible administration paths and do not require a local sudo or suexec r

netsecio@mastodon.social at 2026-10-04T18:08:12.000Z ##

📰 Fortra Patches Critical Flaws in BoKS Privileged Access Manager

Fortra patches 3 critical vulnerabilities in its BoKS Privileged Access Manager. Flaws include auth bypass (CVE-2026-79901, 9.9), RCE (CVE-2026-79898, 9.1), and buffer overflow (CVE-2026-12627, 9.8). #CVE #PatchNow #Linux

🔗 cyber.netsecops.io/articles/fo

##

CVE-2026-102369(CVSS UNKNOWN)

EPSS: 0.24%

updated 2026-10-01T18:32:57

1 posts

Tapo C120 v1 and C200 V5 do not adequately protect login challenge data or sanitize attacker-controlled input processed by the MacTool handler. An unauthenticated attacker on the same local network can replay login challenge data to obtain an administrative session, enable a privileged service that becomes accessible after a reboot, and submit crafted input to execute arbitrary commands within the

CVE-2026-79901
(9.9 CRITICAL)

EPSS: 0.27%

updated 2026-10-01T15:17:32.163000

2 posts

In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.

netsecio@mastodon.social at 2026-10-04T18:08:12.000Z ##

📰 Fortra Patches Critical Flaws in BoKS Privileged Access Manager

Fortra patches 3 critical vulnerabilities in its BoKS Privileged Access Manager. Flaws include auth bypass (CVE-2026-79901, 9.9), RCE (CVE-2026-79898, 9.1), and buffer overflow (CVE-2026-12627, 9.8). #CVE #PatchNow #Linux

🔗 cyber.netsecops.io/articles/fo

##

offseq@infosec.exchange at 2026-10-03T12:00:25.000Z ##

Fortra BoKS faces 3 CRITICAL vulns (CVE-2026-79901, - 79898, - 12627): auth bypass, command injection as root, and remote memory corruption. No active exploits seen. Patch now to secure privileged environments! radar.offseq.com/threat/fortra #OffSeq #Fortra #BoKS #Vulnerability

##

CVE-2026-96760
(9.8 CRITICAL)

EPSS: 0.28%

updated 2026-10-01T14:17:32.147000

1 posts

Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.

1 repos

https://github.com/uziii2208/CVE-2026-96760

DailyCyberSecurity@infosec.exchange at 2026-10-02T13:21:28.000Z ##

Explore Authlib CVE-2026-96760, an authentication bypass vulnerability involving empty JSON Web Signature arrays in Python. Learn how to secure your apps.

#Authlib #Cybersecurity #CVE202696760 #AuthenticationBypass #PythonSecurity

meterpreter.org/authlib-cve-20

##

CVE-2026-93355
(8.1 HIGH)

EPSS: 0.27%

updated 2026-09-30T17:23:08.953000

2 posts

LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting an email-based fallback lookup in the JWT authentication flow without verifying the email_verified claim. Attackers can present a token with an unverified email address matching a victim's account to inherit the vi

hasamba at 2026-10-03T17:46:42.993Z ##

----------------

🎯 AI
===================

Unpatched account takeover in LiteLLM (CVE-2026-93355) allows authentication as any user, including proxy_admin, via a single JWT request with an unverified email claim.

Technical Details
• Vulnerability: JWT authentication fallback bypass (CWE-290).
• CVSS: 8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
• Affected Versions: LiteLLM up to 1.100.1 (PyPI).
• Mechanism: LiteLLM proxies authenticate JWTs by matching user_id or sso_user_id. When this fails, it falls back to the email claim. It trusts this claim without checking email_verified. If a match is found, it returns the matched account as the authenticated caller and overwrites the victim's sso_user_id with the attacker's token subject in a background write.

Impact
The attacker does not need the victim's credentials or any interaction. A validly signed JWT from a trusted IdP carrying the victim's email is sufficient. Many IdP and self-service signup flows populate the email claim before or without verifying it. Since LiteLLM is an AI gateway holding upstream API keys and spend history, compromising a proxy_admin account grants access to all organizational LLM credentials.

Status
OX Research reported the issue on May 18, 2026. After a follow-up on July 27 with no response, the issue remains unpatched in the latest release (1.100.1).

🔹 LiteLLM

🔗 Source: ox.security/blog/litellm-an-or

##

hasamba@infosec.exchange at 2026-10-03T17:46:42.000Z ##

----------------

🎯 AI
===================

Unpatched account takeover in LiteLLM (CVE-2026-93355) allows authentication as any user, including proxy_admin, via a single JWT request with an unverified email claim.

Technical Details
• Vulnerability: JWT authentication fallback bypass (CWE-290).
• CVSS: 8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
• Affected Versions: LiteLLM up to 1.100.1 (PyPI).
• Mechanism: LiteLLM proxies authenticate JWTs by matching user_id or sso_user_id. When this fails, it falls back to the email claim. It trusts this claim without checking email_verified. If a match is found, it returns the matched account as the authenticated caller and overwrites the victim's sso_user_id with the attacker's token subject in a background write.

Impact
The attacker does not need the victim's credentials or any interaction. A validly signed JWT from a trusted IdP carrying the victim's email is sufficient. Many IdP and self-service signup flows populate the email claim before or without verifying it. Since LiteLLM is an AI gateway holding upstream API keys and spend history, compromising a proxy_admin account grants access to all organizational LLM credentials.

Status
OX Research reported the issue on May 18, 2026. After a follow-up on July 27 with no response, the issue remains unpatched in the latest release (1.100.1).

🔹 LiteLLM #CVE_2026_93355 #AppSec #JWT #AI

🔗 Source: ox.security/blog/litellm-an-or

##

CVE-2026-71972
(5.9 MEDIUM)

EPSS: 0.22%

updated 2026-09-30T16:40:50.560000

1 posts

U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the video_display_rle8_bitmap function in drivers/video/video_bmp.c. Attackers can supply a crafted RLE8-compressed BMP image to corrupt memory adjacent to the framebuffer and crash the bootloader.

_r_netsec@infosec.exchange at 2026-10-02T17:03:21.000Z ##

Bypassing Secure Boot via Unbounded RLE8 Splash Images in U-Boot (CVE-2026-71972) pop.byteray.co.uk/advisory/BYT

##

CVE-2026-102437
(7.8 HIGH)

EPSS: 0.99%

updated 2026-09-29T21:36:39.547000

1 posts

OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer.

beyondmachines1@infosec.exchange at 2026-10-03T11:01:13.000Z ##

DeepSeek-Reasonix Patches ConfigPoisoning Command Injection Flaw

DeepSeek-Reasonix fixed a vulnerability (CVE-2026-102437) that allowed attackers to execute arbitrary commands via poisoned git configuration files when a user viewed file diffs. The flaw is caused by an inadequate neutralization of git filter mechanisms in the tool's internal git wrapper.

**If you use DeepSeek-Reasonix Studio or the Reasonix npm package, update ASAP to Studio 2.21.0 or npm 1.39.3. Until you've updated, don't open or view changes in code projects you got from archives, shared folders, or other people; only work with projects you downloaded yourself from a trusted source.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-92370
(8.8 HIGH)

EPSS: 0.38%

updated 2026-09-29T18:31:49

1 posts

An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuratio

cyberveille@mastobot.ping.moi at 2026-10-04T11:30:37.000Z ##

📢 [VULN] TeamViewer a corrigé 5 failles de sécurité, dont une exploitable à distance - CVE-2026-92370

i vous utilisez TeamViewer comme outil de téléassistance pour dépanner vos utilisateurs, je vous invite à lire ce qui suit : une nouvelle version corrige 5 vulnérabilités dans les clients TeamViewer pour Windows, Linux et macOS. L'une d'elles est une faille exploitable à distance. Voici ce qu'il…

🔗 it-connect.fr/teamviewer-5-fai
💬 discussion : infosec.pub/post/53133414
#Vulnérabilité #CVE #Cyberveille

##

CVE-2026-86950
(8.8 HIGH)

EPSS: 1.24%

updated 2026-09-29T15:32:17

2 posts

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions o

3 repos

https://github.com/msuiche/hotcell

https://github.com/DeAurity/CVE-2026-86950-POC

https://github.com/decalage2/detect_CVE-2026-86950

decalage@mastodon.social at 2026-10-02T21:12:38.000Z ##

How to detect the Apple iOS/macOS recent 0-day CVE-2026-86950 in PDF files?
I developed a python tool for that, based on the PoC published two days ago:
decalage.info/CVE-2026-86950/

##

hackmag@infosec.exchange at 2026-10-02T16:07:55.000Z ##

⚪️ Apple fixes CoreGraphics zero-day vulnerability exploited in attacks

🗨️ Apple developers have released updates for iOS, iPadOS, and macOS that fix the zero-day vulnerability CVE-2026-86950. The CoreGraphics bug may already have been exploited in “extremely sophisticated” targeted attacks against specific iPhone users. The issue was reportedly discovered by researchers…

🔗 hackmag.com/news/cve-2026-8695

#news

##

todb at 2026-10-04T18:47:59.436Z ##

I didn’t realize the EU CERT was so witty!

cert.europa.eu/blog/taking-exe

(analysis of the NetScaler thing from last week.)

##

bontchev at 2026-10-04T14:02:03.384Z ##

@GossiTheDog @jsmall I was talking about one of the previous ones (CVE-2026-88771, since it's easier to emulate than CVE-2026-88772). The Watchtowr article I was referring to is this one:

labs.watchtowr.com/oh-look-the

##

netsecio@mastodon.social at 2026-10-03T19:05:03.000Z ##

📰 Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack

Critical Alert: Two Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are under active global attack. Flaws allow unauthenticated RCE. CISA KEV listed. Patch and hunt for compromise now! #Citrix #NetScaler #CyberSecurity #CVE

🔗 cyber.netsecops.io/articles/ci

##

ssvc at 2026-10-03T15:15:53.539Z ##

Looking for additional Citrix NetScaler IOC? Sygnia has novel and credible indicators from CVE-2026-88771 exploitation (published 9/30):

sygnia.co/threat-reports-and-a

##

todb@infosec.exchange at 2026-10-04T18:47:59.000Z ##

I didn’t realize the EU CERT was so witty!

cert.europa.eu/blog/taking-exe

(analysis of the NetScaler thing from last week.)

##

bontchev@infosec.exchange at 2026-10-04T14:02:03.000Z ##

@GossiTheDog @jsmall I was talking about one of the previous ones (CVE-2026-88771, since it's easier to emulate than CVE-2026-88772). The Watchtowr article I was referring to is this one:

labs.watchtowr.com/oh-look-the

##

ssvc@infosec.exchange at 2026-10-03T15:15:53.000Z ##

Looking for additional Citrix NetScaler IOC? Sygnia has novel and credible indicators from CVE-2026-88771 exploitation (published 9/30):

sygnia.co/threat-reports-and-a

#threatintel #citrix #netscaler

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T21:32:40.000Z ##

Citrix flags a NetScaler SAML authentication issue as patched NetScaler appliances reboot after CVE-2026-88771 attacks. Check your config.

#Citrix #NetScaler #SAML #CVE202688771 #CVE202688772 #ZeroDay #Vulnerability

securityonline.info/netscaler-

##

DarkWebInformer@infosec.exchange at 2026-10-02T16:51:46.000Z ##

🚨 Reports of NetScaler Incidents After Latest Patch Raise Concerns Over Continued Exploitation

Multiple Citrix administrators are reporting suspicious activity affecting NetScaler appliances even after updating to version 14.1-73.37.

The reports surfaced on Reddit, where one administrator said multiple customers experienced incidents that caused externally accessible NetScaler appliances to repeatedly reboot.

Other administrators reported similar behavior on newly rebuilt appliances, including systems where Enhanced ISN Generation had already been enabled. Several affected organizations said they collected forensic data and opened cases with Citrix.

It is currently unclear whether the activity represents successful exploitation of a new or existing vulnerability, residual compromise, vulnerability scanning, or an issue with the updated firmware.

The reports come days after Citrix disclosed active exploitation of CVE-2026-88771 and CVE-2026-88772, two critical vulnerabilities affecting NetScaler ADC and NetScaler Gateway.

The latest post-patch activity has not yet been confirmed by Citrix as exploitation.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

Source: reddit.com/r/Citrix/comments/1

##

CVE-2026-88772
(8.1 HIGH)

EPSS: 1.30%

updated 2026-09-28T12:32:09

4 posts

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

8 repos

https://github.com/FollowerSeize/CVE-2026-88772-POC

https://github.com/emilstahl/pitscaler

https://github.com/orjanj/netscaler_threat_hunt_helper

https://github.com/technion/netscaler_scanner

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772

https://github.com/murrez/CVE-2026-88772

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

https://github.com/securekomodo/citrixInspector

bontchev at 2026-10-04T14:02:03.384Z ##

@GossiTheDog @jsmall I was talking about one of the previous ones (CVE-2026-88771, since it's easier to emulate than CVE-2026-88772). The Watchtowr article I was referring to is this one:

labs.watchtowr.com/oh-look-the

##

netsecio@mastodon.social at 2026-10-03T19:05:03.000Z ##

📰 Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack

Critical Alert: Two Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are under active global attack. Flaws allow unauthenticated RCE. CISA KEV listed. Patch and hunt for compromise now! #Citrix #NetScaler #CyberSecurity #CVE

🔗 cyber.netsecops.io/articles/ci

##

bontchev@infosec.exchange at 2026-10-04T14:02:03.000Z ##

@GossiTheDog @jsmall I was talking about one of the previous ones (CVE-2026-88771, since it's easier to emulate than CVE-2026-88772). The Watchtowr article I was referring to is this one:

labs.watchtowr.com/oh-look-the

##

DarkWebInformer@infosec.exchange at 2026-10-02T16:51:46.000Z ##

🚨 Reports of NetScaler Incidents After Latest Patch Raise Concerns Over Continued Exploitation

Multiple Citrix administrators are reporting suspicious activity affecting NetScaler appliances even after updating to version 14.1-73.37.

The reports surfaced on Reddit, where one administrator said multiple customers experienced incidents that caused externally accessible NetScaler appliances to repeatedly reboot.

Other administrators reported similar behavior on newly rebuilt appliances, including systems where Enhanced ISN Generation had already been enabled. Several affected organizations said they collected forensic data and opened cases with Citrix.

It is currently unclear whether the activity represents successful exploitation of a new or existing vulnerability, residual compromise, vulnerability scanning, or an issue with the updated firmware.

The reports come days after Citrix disclosed active exploitation of CVE-2026-88771 and CVE-2026-88772, two critical vulnerabilities affecting NetScaler ADC and NetScaler Gateway.

The latest post-patch activity has not yet been confirmed by Citrix as exploitation.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

Source: reddit.com/r/Citrix/comments/1

##

CVE-2026-100520
(8.8 HIGH)

EPSS: 0.94%

updated 2026-09-26T03:30:23

2 posts

Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal sequences in the path parameter to write PHP files into other tenants' web roots and execute code as those tenants.

1 repos

https://github.com/wvllxe/CVE-2026-100520-laranode-path-traversal

DarkWebInformer at 2026-10-03T21:40:01.539Z ##

🚨 Public PoC released for CVE-2026-100520 affecting Laranode

github.com/wvllxe/CVE-2026-100

CVE-2026-100520 is a high-severity path traversal flaw in the Laranode multi-tenant hosting control panel that can let a low-privileged authenticated user write files outside their own home directory.

A newly published proof of concept demonstrates how the issue can be chained into remote code execution by placing a PHP file inside another tenant’s web root.

Key details:
⠀
• CVE-2026-100520
• CVSS 3.1: 8.8 HIGH
• CVSS 4.0: 8.7 HIGH
• CWE-22 Path Traversal
• Authenticated exploitation required
• Arbitrary file write
• Cross-tenant impact
• Remote code execution possible
• Laranode versions before 1.2.1 affected
• Fixed in version 1.2.1
⠀
The vulnerability stems from attacker-controlled path values being used when constructing upload destinations without sufficient traversal protections.

The published PoC uses a valid low-privileged account and demonstrates writing a file into a sibling tenant’s web root.

The issue was publicly disclosed on September 21, 2026, and the CVE was published on September 26. The vendor fix was released before the PoC became public.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

##

DarkWebInformer@infosec.exchange at 2026-10-03T21:40:01.000Z ##

🚨 Public PoC released for CVE-2026-100520 affecting Laranode

github.com/wvllxe/CVE-2026-100

CVE-2026-100520 is a high-severity path traversal flaw in the Laranode multi-tenant hosting control panel that can let a low-privileged authenticated user write files outside their own home directory.

A newly published proof of concept demonstrates how the issue can be chained into remote code execution by placing a PHP file inside another tenant’s web root.

Key details:
⠀
• CVE-2026-100520
• CVSS 3.1: 8.8 HIGH
• CVSS 4.0: 8.7 HIGH
• CWE-22 Path Traversal
• Authenticated exploitation required
• Arbitrary file write
• Cross-tenant impact
• Remote code execution possible
• Laranode versions before 1.2.1 affected
• Fixed in version 1.2.1
⠀
The vulnerability stems from attacker-controlled path values being used when constructing upload destinations without sufficient traversal protections.

The published PoC uses a valid low-privileged account and demonstrates writing a file into a sibling tenant’s web root.

The issue was publicly disclosed on September 21, 2026, and the CVE was published on September 26. The vendor fix was released before the PoC became public.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

##

CVE-2026-25265
(8.8 HIGH)

EPSS: 0.07%

updated 2026-09-25T13:37:33.170000

1 posts

Privilege escalation due to weak configuration while temporary file handling.

hugovalters@mastodon.social at 2026-10-04T15:10:02.000Z ##

CVE-2026-25265 Qualcomm privilege escalation via insecure temp file handling, CVSS 8.8. No patch yet. Apply mitigations and watch for vendor update. valtersit.com/cve/CVE-2026-252 #CVE #infosec #Qualcomm

##

CVE-2026-75791
(8.6 HIGH)

EPSS: 1.71%

updated 2026-09-22T19:32:25.730000

1 posts

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.

hugovalters@mastodon.social at 2026-10-03T15:40:20.000Z ##

CVE-2026-75791 ManageEngine ADSelfService Plus auth bypass in REST API. CVSS 8.6, unpatched. Restrict API access and update to build 7001 now. valtersit.com/cve/CVE-2026-757 #CVE #infosec #ManageEngine

##

CVE-2026-63272
(0 None)

EPSS: 0.17%

updated 2026-09-22T19:09:32.273000

2 posts

LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text were read separately from the file and were not required to agree, so drawing the text walked the advance array by character position and ran past its end when the a

hugovalters@mastodon.social at 2026-10-04T01:40:01.000Z ##

CVE-2026-63272 LibreOffice heap buffer overflow when importing WMF graphics in documents. CVSS 5.3. No patch yet. Avoid untrusted files and update as soon as a fix ships. valtersit.com/cve/CVE-2026-632 #CVE #infosec #LibreOffice

##

hugovalters@mastodon.social at 2026-10-04T01:40:01.000Z ##

CVE-2026-63272 LibreOffice heap buffer overflow when importing WMF graphics in documents. CVSS 5.3. No patch yet. Avoid untrusted files and update as soon as a fix ships. valtersit.com/cve/CVE-2026-632 #CVE #infosec #LibreOffice

##

CVE-2026-63274
(0 None)

EPSS: 0.17%

updated 2026-09-22T19:09:32.273000

1 posts

LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object's own dictionary and was not checked against the number of bytes actually present, so copying the stream read and wrote past the end of the buffer holding it. In fixed versions the declared length is clamped to the bytes actually read.

hugovalters@mastodon.social at 2026-10-03T22:00:19.000Z ##

CVE-2026-63274 LibreOffice Draw heap buffer overflow on PDF import, no CVSS, patch status unknown. Opening a crafted PDF can corrupt memory. Treat untrusted PDFs with caution and update as soon as a fix lands. valtersit.com/cve/CVE-2026-632 #CVE #infosec #LibreOffice

##

CVE-2026-63275
(0 None)

EPSS: 0.17%

updated 2026-09-22T19:09:32.273000

1 posts

LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than the array can hold wrote past its end. In fixed versions the hint count is checked against the capacity the array really has.

hugovalters@mastodon.social at 2026-10-03T20:20:10.000Z ##

CVE-2026-63275 stack buffer overflow in LibreOffice CFF font glyph hint parsing. Open a malicious document, get code execution. No CVSS or patch yet. Treat untrusted docs with care. valtersit.com/cve/CVE-2026-632 #CVE #LibreOffice #infosec

##

CVE-2026-63278
(0 None)

EPSS: 0.15%

updated 2026-09-22T19:09:32.273000

1 posts

URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-12426 did not recognise every way of naming the package content provider, so a URL that named it differently still reached the expansion. In fixed versions the package

hugovalters@mastodon.social at 2026-10-03T18:50:23.000Z ##

CVE-2026-63278: info disclosure via crafted URLs that expand env or INI values, leaking secrets to remote servers. Incomplete fix for CVE-2024-12426. CVSS 7.4, no patch yet. Restrict document links and monitor outbound valtersit.com/cve/CVE-2026-632 #CVE #infosec #cybersecurity

##

CVE-2026-63276
(0 None)

EPSS: 0.19%

updated 2026-09-22T19:09:32.273000

1 posts

LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The converted operators were written into a fixed size buffer with no check that they still fit, so a glyph emitting many operators wrote past the end of the buffer. In fixed versions the r

hugovalters@mastodon.social at 2026-10-03T17:10:04.000Z ##

CVE-2026-63276 LibreOffice stack buffer overflow, CVSS 7.8, triggered by exporting a malicious document to PDF. No patch yet. Avoid untrusted files until fixed. valtersit.com/cve/CVE-2026-632 #CVE #infosec #LibreOffice

##

CVE-2026-95273
(4.3 MEDIUM)

EPSS: 0.52%

updated 2026-09-22T19:04:55.677000

1 posts

A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of the file changedetectionio/flask_app.py of the component visual_selector_data. Executing a manipulation of the argument filename can lead to path traversal. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Distinct from CV

hugovalters@mastodon.social at 2026-10-04T04:30:26.000Z ##

CVE-2026-95273: path traversal in dgtlmoon changedetection.io up to 0.60.7 via static_content filename, CVSS 4.3, exploit public, no patch. Update or restrict access now. valtersit.com/cve/CVE-2026-952 #CVE #infosec #cybersecurity

##

CVE-2026-87078
(9.1 CRITICAL)

EPSS: 0.65%

updated 2026-09-22T18:33:29

1 posts

Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode. The XS backend allocates the scalar it returns before it validates the input, sizing the buffer at twice the input length. The scalar is released only on the success path, so each of the three croaks that reject a label leaves the scalar and its buffer allocated. Nothing

hugovalters@mastodon.social at 2026-10-03T09:20:02.000Z ##

CVE-2026-87078 Net::IDN::Punycode for Perl leaks its output buffer on every rejected label in decode_punycode. Unbounded labels mean memory exhaustion and DoS. CVSS 9.1. Patch still under review, so pin versions or limit input now. valtersit.com/cve/CVE-2026-870 #CVE #infosec #Perl

##

CVE-2026-95659(CVSS UNKNOWN)

EPSS: 0.39%

updated 2026-09-22T15:32:43

1 posts

MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action. The method accepted a parent object type parameter from the URL without validation and passed it to the Overmind-themed AnalystData thread view element, where it was interpolated into two translated strings and rendered into the HTML response without output encoding. An authentica

hugovalters@mastodon.social at 2026-10-04T12:00:19.000Z ##

CVE-2026-95659 MISP reflected XSS (CVSS 6.1) in AnalystDataController. Patch under review - until then, validate input and be wary of crafted URLs. Details: valtersit.com/cve/CVE-2026-956 #CVE #infosec #MISP

##

CVE-2026-95661(CVSS UNKNOWN)

EPSS: 0.44%

updated 2026-09-22T15:32:43

1 posts

MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL path segment , was interpolated directly into a JavaScript array literal inside an onClick HTML attribute without any encoding or escaping. An attacker who can cause an authenticated MISP user to visit a crafted URL containing a malicious ty

hugovalters@mastodon.social at 2026-10-04T08:50:02.000Z ##

CVE-2026-95661 MISP reflected XSS in attribute histogram view, CVSS 6.1. Crafted URL runs JS in an authenticated user's browser. Patch still under review, so limit exposure and watch for the fix. valtersit.com/cve/CVE-2026-956 #CVE #infosec #MISP

##

CVE-2026-95675
(9.8 CRITICAL)

EPSS: 2.06%

updated 2026-09-22T15:32:43

1 posts

D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device to persistently modify its configuration and use it as a pivot point into the loc

1 repos

https://github.com/d6fault/CVE-2026-95675

hugovalters@mastodon.social at 2026-10-04T07:20:19.000Z ##

CVE-2026-95675: unauthenticated RCE as root in D-Link DAP-1360 firmware 6.14 and earlier via the web management interface. CVSS 9.8. No patch available - if you expose this device, assume full compromise. Segment it or retire it now. valtersit.com/cve/CVE-2026-956 #CVE #infosec #DLink

##

CVE-2026-95499
(7.3 HIGH)

EPSS: 0.47%

updated 2026-09-22T15:32:43

1 posts

A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of the argument files can lead to unrestricted upload. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.

hugovalters@mastodon.social at 2026-10-04T05:50:01.000Z ##

CVE-2026-95499: Unrestricted file upload in JosephChuks php-file-manager-with-code-editor up to 3.0, CVSS 7.3. Remote attackers can upload arbitrary files via filemanager.php. Vendor unresponsive, no patch. Restrict access now.
valtersit.com/cve/CVE-2026-954
#CVE #infosec

##

CVE-2026-12718
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-09-22T15:32:43

1 posts

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic Industry and Trade Inc. KarelIPS allows Blind SQL Injection. This issue affects KarelIPS: through 22092026. NOTE: The vendor was contacted and it was learned that the product is not supported.

hugovalters@mastodon.social at 2026-10-04T04:10:18.000Z ##

CVE-2026-12718: SQL injection in Karel KarelIPS, CVSS 9.8. Vendor says product unsupported, so no patch is coming. Anyone still running it is exposed. Migrate off or isolate now. valtersit.com/cve/CVE-2026-127 #CVE #infosec #cybersecurity

##

CVE-2026-95658(CVSS UNKNOWN)

EPSS: 0.27%

updated 2026-09-22T15:32:36

1 posts

MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list. In CakePHP, listing an action in unlockedActions disables both the CSRF token check and the field hash validation for that action. Because moduleStatelessExecution executes a workflow module's exec() method with caller-supplied input and parameters, the absence of CSRF protectio

hugovalters@mastodon.social at 2026-10-04T13:40:22.000Z ##

CVE-2026-95658 MISP CSRF (CVSS 6.5): unlockedActions disabled CSRF checks on moduleStatelessExecution, letting crafted cross-origin posts run workflow modules. Patch still under review, so restrict access and monitor advisories now. valtersit.com/cve/CVE-2026-956 #CVE #infosec #MISP

##

CVE-2026-95272
(3.7 LOW)

EPSS: 0.67%

updated 2026-09-22T15:32:35

1 posts

A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. This affects the function static_content of the file changedetectionio/flask_app.py of the component Screenshot Handler. Performing a manipulation of the argument filename results in path traversal. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is reported a

hugovalters@mastodon.social at 2026-10-04T10:30:03.000Z ##

CVE-2026-95272: path traversal in changedetection.io up to 0.60.7, Screenshot Handler. CVSS 3.7, public exploit, no patch yet. Restrict access and watch for updates. valtersit.com/cve/CVE-2026-952 #CVE #infosec #cybersecurity

##

CVE-2026-63273(CVSS UNKNOWN)

EPSS: 0.11%

updated 2026-09-22T12:30:32

1 posts

LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from the document's own encryption dictionary and was used to fill a fixed size key buffer without being checked against it, so a length larger than that buffer wrote past its end. In fixed versions a declared key length larger than the buffer i

hugovalters@mastodon.social at 2026-10-04T04:20:28.000Z ##

CVE-2026-63273 LibreOffice Draw heap buffer overflow via encrypted PDF key length, CVSS 7.8. No patch yet, so treat untrusted PDFs with care. Details: valtersit.com/cve/CVE-2026-632 #CVE #infosec #LibreOffice

##

CVE-2026-9004
(4.3 MEDIUM)

EPSS: 0.37%

updated 2026-09-22T09:31:17

1 posts

The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.6 via the 'contact_id' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to extract full names, email addresses, phone numbers, mobile numbers, fax numbers, and physical address informati

hugovalters@mastodon.social at 2026-10-02T17:40:02.000Z ##

CVE-2026-9004: WP-CRM System plugin for WordPress leaks CRM contact names, emails, phones and addresses via the contact_id parameter. CVSS 4.3, no patch yet. Restrict contributor access or remove the plugin. valtersit.com/cve/CVE-2026-900 #CVE #WordPress #infosec

##

CVE-2026-10536
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-09-15T07:16:25.137000

2 posts

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during

beyondmachines1@infosec.exchange at 2026-10-03T10:01:13.000Z ##

GitLab Issues Emergency Patches for Actively Exploited Critical AI Gateway and Path Traversal Flaws

GitLab released emergency security updates to fix a critical remote code execution vulnerability in its AI Gateway (CVE-2026-90970) and a maximum-severity path traversal flaw (CVE-2026-85706) that allows unauthenticated attackers to steal sensitive server data.

**If you run self-hosted GitLab (Community or Enterprise Edition) or a self-hosted GitLab AI Gateway for Duo, patch now: upgrade the AI Gateway to 19.2.4, 19.3.2 or 19.4.1 and apply GitLab's latest security release. One of the flaws is already actively exploited. After patching, check your logs for strange flow configurations or file access, and rotate all AI provider API keys and other secrets on those servers.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-73916
(9.1 CRITICAL)

EPSS: 0.43%

updated 2026-08-28T05:16:44.893000

1 posts

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical da

beyondmachines1@infosec.exchange at 2026-10-02T16:01:13.000Z ##

Critical Oracle Helidon Flaw Allows Unauthenticated Data Access and Modification

Oracle disclosed CVE-2026-73916, a critical vulnerability in Helidon’s Imperative Web Server that can be exploited remotely over HTTP without authentication. Successful exploitation can allow attackers to access, create, modify, or delete data available to the affected application.

**Check your Helidon version and apply Oracle’s latest security update as soon as possible. Until remediation is complete, restrict network access to affected Helidon web services and avoid exposing them directly to untrusted networks.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-73570
(8.9 HIGH)

EPSS: 11.74%

updated 2026-08-21T18:34:48

1 posts

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands a

10 repos

https://github.com/dahnutz/zimbra-cve-2026-73570-ir

https://github.com/gabrielunknown/CVE-2026-73570

https://github.com/hainhc/CVE-2026-73570

https://github.com/juanpoch/CVE-2026-73570

https://github.com/INFOKOM-KI/Zimbra-CVE-2026-73570-Rules

https://github.com/BiuTrap/CVE-2026-73570

https://github.com/alsyundawy/eradicate-zimbra-malware

https://github.com/HORKimhab/CVE-2026-73570

https://github.com/jishino567/CVE-2026-73570

https://github.com/0xBlackash/CVE-2026-73570

CVE-2026-16584
(7.0 HIGH)

EPSS: 0.23%

updated 2026-07-23T19:16:53.537000

1 posts

Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that the policy was set to deny or gate. When initialization of the security policy enforcement data fails at server startup, the policy check is skipped for the lifetime of the process. IAM permissions on

DevOpsPink@mastodon.social at 2026-10-04T16:18:04.000Z ##

In July, AWS fixed two guardrails for AI agents in the same week: a deny list in the AWS API MCP Server skipped after a failed startup load (CVE-2026-16584), and a read-only mode in the MCP proxy that hid write tools without blocking them. IAM held both times.

What to set up before an agent gets an AWS role, and why even ViewOnlyAccess returns Lambda environment variables:
builder.aws.com/content/3KD10s

Poll (AWS Builder ID): builder.aws.com/poll/3KD0tMXab

#AWSCommunityBuilder #AIAgents #CloudSecurity #MCP

##

CVE-2026-61500
(9.8 CRITICAL)

EPSS: 0.99%

updated 2026-07-13T18:31:00

3 posts

Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full admi

1 repos

https://github.com/aramosf/CVE-2026-61500

undercodenews@mastodon.social at 2026-10-03T21:46:57.000Z ##

CVE-2026-61500: Anthropic’s Mythos AI Discovers Critical Rejetto HFS Vulnerability as Exploitation Begins Within 24 Hours + Video

Introduction: From AI-Powered Vulnerability Discovery to Real-World Exploitation The growing capabilities of artificial intelligence in cybersecurity are raising new questions about how quickly vulnerabilities can move from discovery to active exploitation. The disclosure of CVE-2026-61500, a critical unauthenticated remote code execution…

undercodenews.com/cve-2026-615

##

sayzard@mastodon.sayzard.org at 2026-10-03T18:39:26.000Z ##

Anthropic's super bug-hunting model Mythos is hardcore good at math

Anthropic의 취약점 탐색 모델 Mythos가 Rejetto HTTP File Server(HFS)의 인증 우회 및 원격 코드 실행(RCE) 취약점 CVE-2026-61500을 찾아냈고, 공개 다음 날 실제 공격 시도가 관측됐다. 취약점은 V8의 비암호학적 `Math.random()` 출력이 애플리케이션에서 노출되는 경로와 결합돼, 공격자가 xorshift128+ 내부 상태를...

theregister.com/security/2026/

##

Analyst207@mastodon.social at 2026-10-03T15:51:09.000Z ##

Mythos Exposes New Vulnerability in Rejetto HTTP File Server

A critical vulnerability, CVE-2026-61500, has been uncovered in Rejetto HTTP File Server (HFS), allowing for full administrator access and remote code execution. This flaw was discovered using Anthropic's bug-hunting model Mythos and can be exploited with alarming ease.

osintsights.com/mythos-exposes

#RejettoHttpFileServer #Cve202661500 #AuthenticationBypass #RemoteCodeExecution #Vulnerability

##

CVE-2025-6543
(9.8 CRITICAL)

EPSS: 10.56%

updated 2026-06-17T10:02:07.007000

2 posts

Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

4 repos

https://github.com/lex1010/CVE-2025-6543

https://github.com/grupooruss/Citrix-cve-2025-6543

https://github.com/abrewer251/CVE-2025-6543_CitrixNetScaler_PoC

https://github.com/fox-it/citrix-netscaler-triage

GossiTheDog@cyberplace.social at 2026-10-04T09:55:03.000Z ##

The new Citrix Netscaler vuln from Friday is CVE-2026-88779, patch is out now and they recommend patching as soon as possible: support.citrix.com/support-hom

Although the vuln is labeled “Memory overflow vulnerability leading to Denial of Service”, that’s the same as CVE-2025–6543. You may remember that lead to RCE in the wild. Prior blog on that: doublepulsar.com/citrix-forgot

##

GossiTheDog@cyberplace.social at 2026-10-04T09:55:03.000Z ##

The new Citrix Netscaler vuln from Friday is CVE-2026-88779, patch is out now and they recommend patching as soon as possible: support.citrix.com/support-hom

Although the vuln is labeled “Memory overflow vulnerability leading to Denial of Service”, that’s the same as CVE-2025–6543. You may remember that lead to RCE in the wild. Prior blog on that: doublepulsar.com/citrix-forgot

##

CVE-2026-48842
(8.1 HIGH)

EPSS: 0.89%

updated 2026-06-04T00:31:26

2 posts

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

3 repos

https://github.com/4minx/CVE-2026-48842

https://github.com/murrez/CVE-2026-48842

https://github.com/XsanFlip/POC-CVE-2026-48842

beyondmachines1 at 2026-10-04T14:01:13.087Z ##

Roundcube Webmail SQL Injection Vulnerability CVE-2026-48842 Under Active Exploitation

Roundcube Webmail high-severity SQL injection vulnerability (CVE-2026-48842) in its virtuser_query plugin is being actively exploited, allowing unauthenticated attackers to compromise databases and steal sensitive email data.

**If you run Roundcube Webmail (common in cPanel and other web hosting), update immediately to version 1.6.16 or 1.7.1. The flaw is actively exploited to steal mail, passwords and accounts. If you can't update right away, disable the `virtuser_query` plugin, and check your database logs for anything unusual, since you may already have been breached.**

beyondmachines.net/event_detai

##

beyondmachines1@infosec.exchange at 2026-10-04T14:01:13.000Z ##

Roundcube Webmail SQL Injection Vulnerability CVE-2026-48842 Under Active Exploitation

Roundcube Webmail high-severity SQL injection vulnerability (CVE-2026-48842) in its virtuser_query plugin is being actively exploited, allowing unauthenticated attackers to compromise databases and steal sensitive email data.

**If you run Roundcube Webmail (common in cPanel and other web hosting), update immediately to version 1.6.16 or 1.7.1. The flaw is actively exploited to steal mail, passwords and accounts. If you can't update right away, disable the `virtuser_query` plugin, and check your database logs for anything unusual, since you may already have been breached.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-8695
(7.5 HIGH)

EPSS: 1.07%

updated 2026-05-15T18:30:46

1 posts

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo response. Attackers can exploit this vulnerability through GDB remote debugging to cause a denial of service or potentially achieve code execution by manipulating thread list

2 repos

https://github.com/DeAurity/CVE-2026-86950-POC

https://github.com/decalage2/detect_CVE-2026-86950

hackmag@infosec.exchange at 2026-10-02T16:07:55.000Z ##

⚪️ Apple fixes CoreGraphics zero-day vulnerability exploited in attacks

🗨️ Apple developers have released updates for iOS, iPadOS, and macOS that fix the zero-day vulnerability CVE-2026-86950. The CoreGraphics bug may already have been exploited in “extremely sophisticated” targeted attacks against specific iPhone users. The issue was reportedly discovered by researchers…

🔗 hackmag.com/news/cve-2026-8695

#news

##

CVE-2026-40281
(10.0 CRITICAL)

EPSS: 2.09%

updated 2026-05-08T19:26:58

2 posts

## Vulnerability Details **CWE**: CWE-20 - Improper Input Validation The metadata value sanitization introduced in v8.30.1 (commit 405f106) only validates metadata KEYS via safeKeyPattern regex. Metadata VALUES are passed unsanitized to go-exiftool SetString(), which writes them as fmt.Fprintln(e.stdin, "-"+k+"="+str). A newline (\n) in a value splits the ExifTool stdin line into two separate ar

4 repos

https://github.com/HackfutSecRoot/-GOTENBERG-RCE-CHAIN

https://github.com/0xgh057r3c0n/CVE-2026-40281

https://github.com/codeb0ssx/CVE-2026-42589xCVE-2026-40281-PoC

https://github.com/MRdark-ops/CVE-2026-40281-exploit

DarkWebInformer at 2026-10-03T21:23:59.214Z ##

🚨 Public exploit released for CVE-2026-40281 affecting Gotenberg

github.com/MRdark-ops/CVE-2026

A proof-of-concept exploit has been published for CVE-2026-40281, a critical unauthenticated remote code execution vulnerability affecting Gotenberg versions prior to 8.31.0.

The flaw affects Gotenberg’s PDF metadata handling and can allow a remote attacker to inject commands through crafted metadata values sent to the /forms/pdfengines/metadata/write endpoint. No authentication or user interaction is required.

Key details:
⠀
• CVE-2026-40281
• CVSS: 9.1 Critical
• Gotenberg < 8.31.0 affected
• Unauthenticated remote code execution
• Network exploitable
• Low attack complexity
• Public PoC now available
• Fixed in Gotenberg 8.31.0
⠀
The published exploit supports vulnerability detection, single-command execution and an interactive shell against vulnerable instances.

Organizations running affected Gotenberg deployments should upgrade to version 8.31.0 or later.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

##

DarkWebInformer@infosec.exchange at 2026-10-03T21:23:59.000Z ##

🚨 Public exploit released for CVE-2026-40281 affecting Gotenberg

github.com/MRdark-ops/CVE-2026

A proof-of-concept exploit has been published for CVE-2026-40281, a critical unauthenticated remote code execution vulnerability affecting Gotenberg versions prior to 8.31.0.

The flaw affects Gotenberg’s PDF metadata handling and can allow a remote attacker to inject commands through crafted metadata values sent to the /forms/pdfengines/metadata/write endpoint. No authentication or user interaction is required.

Key details:
⠀
• CVE-2026-40281
• CVSS: 9.1 Critical
• Gotenberg < 8.31.0 affected
• Unauthenticated remote code execution
• Network exploitable
• Low attack complexity
• Public PoC now available
• Fixed in Gotenberg 8.31.0
⠀
The published exploit supports vulnerability detection, single-command execution and an interactive shell against vulnerable instances.

Organizations running affected Gotenberg deployments should upgrade to version 8.31.0 or later.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

##

CVE-2024-12426
(6.5 MEDIUM)

EPSS: 0.55%

updated 2025-12-08T21:30:18

1 posts

Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice. URLs could be constructed which expanded environmental variables or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. This issue affects LibreOffice: from 24.8

hugovalters@mastodon.social at 2026-10-03T18:50:23.000Z ##

CVE-2026-63278: info disclosure via crafted URLs that expand env or INI values, leaking secrets to remote servers. Incomplete fix for CVE-2024-12426. CVSS 7.4, no patch yet. Restrict document links and monitor outbound valtersit.com/cve/CVE-2026-632 #CVE #infosec #cybersecurity

##

thehackerwire@mastodon.social at 2026-10-03T18:45:31.000Z ##

🔴 CVE-2026-103956 - Critical (10)

Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:45:31.000Z ##

🔴 CVE-2026-103956 - Critical (10)

Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DailyCyberSecurity@infosec.exchange at 2026-10-02T22:09:53.000Z ##

AWS fixes Loom for AWS admin takeover CVE-2026-103956 and a SageMaker Unified Studio code execution bug, CVE-2026-104019. Patch now.

#AWS #LoomForAWS #SageMaker #CVE2026103956 #CVE2026104019 #AISecurity #CloudSecurity #Vulnerability

securityonline.info/loom-for-a

##

CVE-2026-103958
(0 None)

EPSS: 0.33%

2 posts

N/A

thehackerwire@mastodon.social at 2026-10-03T18:30:49.000Z ##

🟠 CVE-2026-103958 - High (7.6)

Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the credentials of the application's own container role and to read responses from ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-03T18:30:49.000Z ##

🟠 CVE-2026-103958 - High (7.6)

Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the credentials of the application's own container role and to read responses from ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10426
(0 None)

EPSS: 0.00%

1 posts

N/A

censys@infosec.exchange at 2026-10-02T21:42:21.000Z ##

🚨 Fortinet reports active exploitation of CVE-2026-104286, a critical path traversal vulnerability affecting FortiMail.

Censys observes roughly 2,800 Internet-exposed FortiMail hosts after excluding honeypots. This is an exposure count, not a confirmed-vulnerable count.

No fixed builds have been released as of October 2. Censys ARC covers affected versions, Fortinet’s current workarounds, indicators, and remediation guidance: censys.com/advisory/cve-2026-1

#CensysARC #Fortinet #FortiMail #Cybersecurity #Vulnerability

##

CVE-2026-104846
(0 None)

EPSS: 0.34%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-02T16:18:58.000Z ##

🔴 CVE-2026-104846 - Critical (9.8)

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass a plugin-produced callable-bearing thenab...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104845
(0 None)

EPSS: 0.43%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-02T16:18:48.000Z ##

🟠 CVE-2026-104845 - High (7.5)

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.6.3, deserializeTypedArray in fromJSON and fromCrossJSON trusts a deserialized source value as an ArrayBuffer and does not bo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites