## Updated at UTC 2026-10-11T19:13:51.532679

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-19935 7.5 0.00% 2 0 2026-10-11T18:16:59.410000 The Bluetooth LE host queues received L2CAP connection-oriented channel (CoC) da
CVE-2026-19736 7.8 0.00% 2 0 2026-10-11T18:16:58.810000 The NXP MCUX TRNG entropy driver in drivers/entropy/entropy_mcux_trng.c passed t
CVE-2026-19669 7.8 0.00% 2 0 2026-10-11T18:16:58.563000 The user-mode syscall verifiers z_vrfy_fuel_gauge_get_props() and z_vrfy_fuel_ga
CVE-2026-91136 7.5 0.56% 1 0 2026-10-11T17:17:07.010000 The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versi
CVE-2026-33367 8.1 0.29% 1 0 2026-10-11T17:17:04.760000 SNMP can be used to perform administrative actions such as retrieving configurat
CVE-2026-28745 7.5 0.22% 1 0 2026-10-11T17:17:04.303000 Usernames and passwords, including the default credentials, are stored in the co
CVE-2026-105281 7.5 0.31% 1 0 2026-10-11T17:17:01.723000 The internal data publisher on openPDC accepts network connections without authe
CVE-2026-104759 8.1 0.52% 1 0 2026-10-11T17:17:00.237000 The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin
CVE-2026-96341 8.2 0.28% 1 0 2026-10-11T13:17:29.907000 Incorrect Privilege Assignment vulnerability in WPMU DEV Forminator forminator a
CVE-2026-93944 9.8 0.31% 2 0 2026-10-11T13:17:28.283000 Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia cameli
CVE-2026-93943 9.8 0.31% 1 0 2026-10-11T13:17:28.180000 Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex
CVE-2026-93940 9.8 0.33% 1 0 2026-10-11T13:17:27.850000 Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny
CVE-2026-93937 9.8 0.33% 1 0 2026-10-11T13:17:27.643000 Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia al
CVE-2026-93934 9.8 0.31% 1 0 2026-10-11T13:17:27.323000 Deserialization of Untrusted Data vulnerability in ThemeREX Group Partiso partis
CVE-2026-93932 9.8 0.31% 1 0 2026-10-11T13:17:27.100000 Deserialization of Untrusted Data vulnerability in ThemeREX Group Smart Casa sma
CVE-2026-93931 9.8 0.31% 1 0 2026-10-11T13:17:26.997000 Deserialization of Untrusted Data vulnerability in ThemeREX Group Smash smash al
CVE-2026-62045 9.8 0.32% 2 0 2026-10-11T13:17:24.780000 Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers boo
CVE-2026-108753 9.4 0.00% 2 0 2026-10-11T13:17:20.237000 Agnaistic agnai through 1.0.555 contains a hard-coded credentials vulnerability
CVE-2026-106610 9.8 0.48% 2 1 2026-10-11T13:17:12.430000 Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verifi
CVE-2026-105892 9.8 0.42% 1 0 2026-10-11T13:17:11.910000 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v
CVE-2026-104398 9.8 0.34% 2 0 2026-10-11T13:17:11.270000 Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate M
CVE-2026-103071 7.5 0.25% 1 0 2026-10-11T13:17:10.180000 Improper Control of Generation of Code ('Code Injection') vulnerability in Villa
CVE-2026-93550 4.3 0.14% 2 0 2026-10-11T12:32:13 The Veeqo for WooCommerce WordPress plugin through 2.2.8 does not restrict who c
CVE-2026-96227 8.8 0.17% 2 0 2026-10-11T12:32:13 The Piotnet Forms WordPress plugin through 1.0.30 does not authenticate or valid
CVE-2026-86717 9.1 0.15% 2 0 2026-10-11T12:17:24.653000 The Insurify WordPress plugin through 1.0 does not have authorisation and nonce
CVE-2026-81797 9.8 0.32% 1 0 2026-10-11T12:17:22.500000 Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordP
CVE-2026-78535 9.8 0.34% 1 0 2026-10-11T12:17:21.310000 Unauthenticated PHP Object Injection in Photolia <= 1.0.3 versions.
CVE-2026-78533 9.8 0.34% 1 0 2026-10-11T12:17:21.103000 Unauthenticated PHP Object Injection in Qwery <= 3.6.1 versions.
CVE-2026-66569 9.8 0.31% 1 0 2026-10-11T12:17:20.693000 Unauthenticated PHP Object Injection in Kicker <= 2.2.1 versions.
CVE-2026-66568 9.8 0.31% 1 0 2026-10-11T12:17:20.590000 Unauthenticated PHP Object Injection in Original <= 1.9.0 versions.
CVE-2026-108540 9.9 1.70% 2 0 2026-10-11T09:30:32 A flaw has been found in OpenSpug Spug up to 3.4.0/4.0.1. This impacts an unknow
CVE-2026-108707 9.8 0.55% 2 0 2026-10-11T03:30:24 Wukong_HRM through commit 186115e contains an authentication bypass vulnerabilit
CVE-2026-78530 7.7 0.40% 1 0 2026-10-10T21:31:28 Subscriber Arbitrary File Deletion in FoodBakery <= 4.6 versions.
CVE-2026-78529 9.8 0.31% 1 0 2026-10-10T21:31:28 Unauthenticated PHP Object Injection in Alliance <= 3.11 versions.
CVE-2026-66566 8.1 0.28% 1 0 2026-10-10T21:31:28 Unauthenticated Local File Inclusion in Ambient <= 1.7 versions.
CVE-2026-66567 9.8 0.33% 1 0 2026-10-10T21:31:27 Unauthenticated PHP Object Injection in Anesta <= 1.5.3 versions.
CVE-2026-108598 9.8 0.73% 1 0 2026-10-10T21:31:20 Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateE
CVE-2026-106609 7.5 0.22% 1 0 2026-10-10T18:31:27 Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcas
CVE-2026-105889 9.3 0.26% 1 0 2026-10-10T18:31:27 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-108546 7.5 0.80% 1 0 2026-10-10T15:30:30 Spotweb through 1.5.8 contains an OS command injection vulnerability in the runc
CVE-2026-105885 8.8 0.29% 1 0 2026-10-10T15:30:29 Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider-
CVE-2026-108550 8.8 0.30% 1 0 2026-10-10T15:30:24 SkillHub before 0.2.22 contains an incorrect authorization vulnerability in Acco
CVE-2026-108161 7.5 1.10% 1 0 2026-10-10T15:30:22 FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_r
CVE-2026-108553 7.5 0.18% 1 0 2026-10-10T15:16:58.410000 OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in
CVE-2026-108551 9.8 0.41% 1 0 2026-10-10T15:16:58.273000 openapi-typescript-codegen through 0.31.0 contains a code injection vulnerabilit
CVE-2026-108549 8.1 0.45% 1 0 2026-10-10T15:16:58.087000 cc-connect through 1.5.0 contains a missing authentication vulnerability in the
CVE-2026-19494 8.1 0.29% 1 0 2026-10-10T13:17:32.163000 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-96662 7.5 0.39% 1 0 2026-10-10T09:30:41 The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
CVE-2026-93936 9.8 0.33% 2 0 2026-10-10T09:30:37 Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm
CVE-2026-93945 9.8 0.33% 3 0 2026-10-10T09:30:37 Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance a
CVE-2026-93935 9.8 0.31% 2 0 2026-10-10T09:30:37 Deserialization of Untrusted Data vulnerability in ThemeREX Group Let's Play pla
CVE-2026-62046 9.8 0.32% 2 0 2026-10-10T09:30:37 Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gute
CVE-2026-104803 9.8 0.45% 2 0 2026-10-10T09:30:37 The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in
CVE-2026-93933 9.8 0.31% 1 0 2026-10-10T09:30:37 Deserialization of Untrusted Data vulnerability in ThemeREX Group Rosalinda rosa
CVE-2026-93929 9.8 0.32% 1 0 2026-10-10T09:30:37 Deserialization of Untrusted Data vulnerability in ThemeREX Group Travesia trave
CVE-2026-93942 9.8 0.31% 1 0 2026-10-10T09:30:37 Deserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell al
CVE-2026-93941 9.8 0.33% 1 0 2026-10-10T09:30:37 Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema al
CVE-2026-93938 9.8 0.33% 1 0 2026-10-10T09:30:37 Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwo
CVE-2026-93950 7.5 0.20% 1 0 2026-10-10T09:30:37 Missing Authorization vulnerability in StylemixThemes Motors motors allows Explo
CVE-2026-94538 8.1 0.25% 1 0 2026-10-10T09:30:36 The WP File Download plugin for WordPress is vulnerable to authorization bypass
CVE-2026-93746 7.5 0.53% 1 0 2026-10-10T09:30:36 The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping
CVE-2026-93930 9.8 0.31% 1 0 2026-10-10T09:30:36 Deserialization of Untrusted Data vulnerability in ThemeREX Group Tantra tantra
CVE-2026-93927 9.8 0.32% 1 0 2026-10-10T09:30:36 Deserialization of Untrusted Data vulnerability in Axiomthemes Veto veto allows
CVE-2026-97670 9.1 0.37% 1 0 2026-10-10T06:31:08 The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization b
CVE-2026-94589 9.8 0.66% 1 0 2026-10-10T06:31:06 The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirect
CVE-2026-88131 9.8 0.84% 2 0 2026-10-10T04:18:19.240000 Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized
CVE-2026-84875 7.5 0.42% 1 0 2026-10-10T04:18:19.087000 IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker
CVE-2026-84035 8.1 0.37% 1 0 2026-10-10T04:18:17.220000 IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker
CVE-2026-77900 9.8 0.49% 2 0 2026-10-10T04:18:14.030000 Missing authentication for critical function in Azure App Service allows an unau
CVE-2026-69435 9.6 0.39% 2 0 2026-10-10T04:18:13.347000 Missing authorization in Azure SRE Agent allows an authorized attacker to elevat
CVE-2026-107406 0 0.47% 10 4 2026-10-10T04:18:09.503000 Memory overflow vulnerability leading to Remote Code Execution or Denial of Serv
CVE-2026-108474 9.8 0.32% 1 0 2026-10-10T00:17:03.673000 In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped strin
CVE-2026-108268 0 0.13% 1 0 2026-10-09T22:16:59.643000 Enclave OS Virtual runs container workloads inside confidential virtual machines
CVE-2026-75351 7.5 0.40% 1 0 2026-10-09T21:31:18 OpENer v2.3/commit 76b95cf, contains an out-of-bounds read in the server-side Et
CVE-2026-75346 7.5 0.54% 1 0 2026-10-09T21:17:05.800000 An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and mast
CVE-2026-62376 8.1 0.21% 1 0 2026-10-09T21:17:05.627000 Vikunja is an open-source self-hosted task management platform. Versions prior t
CVE-2026-57458 8.1 0.27% 1 0 2026-10-09T21:17:05.190000 Vikunja is an open-source self-hosted task management platform. In version 2.3.0
CVE-2026-108264 9.1 0.38% 1 0 2026-10-09T21:17:04.703000 Wizarr is an advanced user invitation and management system for Jellyfin, Plex,
CVE-2026-108263 9.9 0.43% 1 0 2026-10-09T21:17:04.527000 Astron Agent is an agentic workflow platform for building and running AI agents.
CVE-2026-108259 8.2 0.25% 1 0 2026-10-09T20:56:53 ### Summary `@tinacms/cli` inserts the raw Git branch value into the generated
CVE-2026-108261 9.3 0.16% 1 0 2026-10-09T20:56:50 ### Summary The TinaCMS admin builds its preview `<iframe src>` from the `/~/*`
CVE-2026-108260 7.6 0.21% 1 0 2026-10-09T20:56:46 ### Summary `<tina-markdown>` renders a rich-text AST into the DOM and, for `a`
CVE-2026-107845 9.3 0.27% 1 0 2026-10-09T20:53:52 An unauthenticated front end visitor can post a comment containing a XSS injecti
CVE-2026-107806 None 0.33% 1 1 2026-10-09T20:45:03 ## Summary An authenticated nginx-ui user can call `POST /api/restore`, upload
CVE-2026-107840 7.5 0.44% 1 0 2026-10-09T20:17:09.900000 yopass is a service for securely sharing secrets, passwords, and files. Prior to
CVE-2026-104084 8.8 0.25% 1 0 2026-10-09T20:17:09.050000 SmarterMail before build 9777 contains a privilege escalation vulnerability wher
CVE-2026-103412 8.8 0.52% 1 0 2026-10-09T18:32:43 Improper limitation of a pathname to a restricted directory ('path traversal') v
CVE-2026-75350 7.5 0.48% 1 0 2026-10-09T18:31:52 EIPStackGroup OpENer v2.3 / master commit 76b95cf contains a buffer overflow in
CVE-2026-108113 8.8 0.64% 1 0 2026-10-09T18:31:48 ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerab
CVE-2026-108160 7.5 0.15% 1 0 2026-10-09T18:31:48 AstronRPA through 1.1.6 contains a download of code without integrity check vuln
CVE-2026-108159 7.5 0.33% 1 0 2026-10-09T18:31:48 AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the des
CVE-2026-75345 7.5 0.45% 1 0 2026-10-09T18:31:47 OpENer v2.3.0 / commit 76b95cf contains an out-of-bounds read in the unconnected
CVE-2026-90983 8.2 0.26% 1 0 2026-10-09T18:31:47 Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc.
CVE-2026-78795 7.5 0.45% 1 0 2026-10-09T18:31:42 An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless route
CVE-2026-75348 7.5 0.51% 1 0 2026-10-09T18:17:13.893000 An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and mast
CVE-2026-108157 8.1 0.53% 1 0 2026-10-09T18:17:07.240000 Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vu
CVE-2026-107839 7.5 0.34% 1 0 2026-10-09T18:17:05.797000 ageLANServer provides a cross-platform web server and launcher for offline multi
CVE-2026-107818 8.4 0.34% 1 0 2026-10-09T18:17:03.373000 MariaDB server is a community developed fork of MySQL server. From 10.6.1 until
CVE-2026-107808 8.1 0.41% 1 0 2026-10-09T18:17:02.773000 Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.
CVE-2026-107807 8.8 0.31% 1 0 2026-10-09T18:17:02.610000 Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.
CVE-2026-75347 7.5 0.42% 1 0 2026-10-09T17:41:47.060000 EIPStackGroup OpENer v2.3 and master up to commit 76b95cf contain an expired poi
CVE-2026-107815 8.5 0.57% 1 0 2026-10-09T17:41:29.727000 MariaDB server is a community developed fork of MySQL server. From 10.6.1 until
CVE-2026-107826 7.5 0.46% 1 0 2026-10-09T17:33:55 ### Summary The JSON body processor (`internal/bodyprocessors/json.go`) can be
CVE-2026-107814 8.4 0.28% 1 0 2026-10-09T17:16:45.853000 MariaDB server is a community developed fork of MySQL server. From 10.6.1 until
CVE-2026-107812 7.5 0.17% 1 0 2026-10-09T17:08:21 ## Summary The self-upgrade downloads the release binary and its checksum (`*.ta
CVE-2026-107809 8.8 0.18% 1 0 2026-10-09T17:08:11 ## Summary Nginx-UI v2.4.3 stores the API JWT in a browser cookie named `token`
CVE-2026-107813 8.8 0.30% 1 0 2026-10-09T17:08:07 ## Summary Incomplete fix of GHSA-5v7c-xpfp-p65m: the secure-session (OTP step-
CVE-2026-107810 8.1 0.36% 1 0 2026-10-09T17:07:06 ### Summary An authenticated user who can create and restore a backup can craft
CVE-2026-108106 7.5 0.37% 1 0 2026-10-09T17:06:17.770000 Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulne
CVE-2026-75349 7.5 0.45% 1 0 2026-10-09T16:40:29.800000 EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bound
CVE-2026-107805 7.5 0.44% 1 0 2026-10-09T16:38:57.820000 Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.
CVE-2026-107811 8.8 0.36% 1 0 2026-10-09T16:38:57.820000 Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.
CVE-2026-55797 8.8 1.55% 1 0 2026-10-09T16:37:27 ### Impact Argo CD runs a shell command in the repo-server when it clones or fe
CVE-2026-103413 8.8 0.39% 1 0 2026-10-09T16:33:39.007000 Improper input validation vulnerability in Apache Camel Karavan. When a deplo
CVE-2026-93947 9.3 0.24% 1 0 2026-10-09T16:17:32.090000 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti
CVE-2026-79842 9.1 0.33% 2 0 2026-10-09T15:32:29 An authentication bypass vulnerability exists in HPE Intelligent Management Cent
CVE-2026-39460 8.1 0.29% 1 0 2026-10-09T15:31:42 Usernames and passwords, including the default factory credentials, are stored i
CVE-2026-108101 7.5 0.39% 1 0 2026-10-09T15:31:38 HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulne
CVE-2026-100730 9.8 0.62% 1 0 2026-10-09T15:31:37 A service console interface on openPDC and openHistorian deserializes a client-s
CVE-2026-15340 9.8 0.60% 1 0 2026-10-09T15:31:35 lwIP SMTP client does not check the size of inputs, potentially allowing a buffe
CVE-2026-39453 8.3 0.29% 1 0 2026-10-09T15:31:35 Navigating to a certain URL on the switch’s web server causes the switch to rebo
CVE-2026-108107 9.8 0.41% 1 0 2026-10-09T15:31:34 PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerabi
CVE-2026-108109 9.1 0.39% 1 0 2026-10-09T15:31:34 PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the c
CVE-2026-83943 8.7 0.38% 1 0 2026-10-09T15:31:32 Exposure of sensitive information to an unauthorized actor in Azure API Center a
CVE-2016-3081 8.1 96.05% 2 0 2026-10-09T14:43:05.703000 Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when
CVE-2026-11318 7.8 0.19% 1 1 2026-10-09T14:17:20.393000 Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.
CVE-2026-17189 8.2 0.15% 1 0 2026-10-09T14:15:54.050000 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-19493 7.5 0.36% 1 0 2026-10-09T14:15:19.050000 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-86405 9.8 0.20% 1 0 2026-10-09T13:21:13.267000 Improper verification of cryptographic signature vulnerability in Sipay Electron
CVE-2026-94503 10.0 0.28% 1 1 2026-10-09T12:31:48 Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify
CVE-2026-96207 10.0 0.48% 2 0 2026-10-09T00:31:56 Improper certificate validation in Microsoft Partner Center allows an unauthoriz
CVE-2026-94510 9.9 0.40% 2 0 2026-10-09T00:31:56 Authorization bypass through user-controlled key in Microsoft Bookings allows an
CVE-2026-83947 7.7 0.37% 1 0 2026-10-09T00:31:56 Missing authorization in Azure Event Grid allows an authorized attacker to perfo
CVE-2026-84058 8.1 0.36% 1 0 2026-10-09T00:31:56 IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer over
CVE-2026-84057 8.1 0.36% 1 0 2026-10-09T00:31:56 IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to e
CVE-2026-84249 9.8 0.41% 1 0 2026-10-09T00:31:56 IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to e
CVE-2026-89091 8.8 0.48% 1 0 2026-10-09T00:31:56 A flaw was found in ansible-core. When installing a collection with `ansible-gal
CVE-2026-107782 7.8 0.11% 1 0 2026-10-08T21:34:48.800000 System Informer before 4.0.26241.138 contains an incorrect authorization vulnera
CVE-2026-19482 8.8 0.42% 1 0 2026-10-08T21:33:42 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-16823 9.1 0.33% 1 0 2026-10-08T21:33:42 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-19491 9.1 0.33% 1 0 2026-10-08T21:33:42 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-78406 9.8 0.50% 1 0 2026-10-08T21:33:42 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-78401 9.8 0.57% 1 0 2026-10-08T21:33:42 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-18740 8.8 0.35% 1 0 2026-10-08T21:33:41 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-16916 9.1 0.42% 1 0 2026-10-08T21:33:41 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access
CVE-2026-107779 9.8 0.54% 1 0 2026-10-08T21:27:15.010000 Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains
CVE-2026-20362 7.2 0.47% 1 0 2026-10-08T20:08:45.857000 A vulnerability in the web-based management interface of Cisco Finesse could all
CVE-2026-103663 None 0.71% 2 0 2026-10-08T15:33:06 Ollama is vulnerable to path traversal in the `/api/pull` endpoint due to insuff
CVE-2025-64393 0 0.36% 2 0 2026-10-08T04:16:55.397000 This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execu
CVE-2026-102255 10.0 0.48% 3 0 2026-10-07T18:33:12 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla
CVE-2026-107181 8.1 0.34% 4 1 2026-10-07T17:16:53.520000 Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnera
CVE-2026-21589 0 1.77% 3 12 2026-10-07T13:17:22.273000 This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira S
CVE-2026-105192 9.8 0.48% 1 1 2026-10-07T12:31:58 LMCache multiprocess mode, also called distributed mode, opens an unauthenticate
CVE-2026-59346 9.3 0.26% 1 1 2026-10-07T06:33:08 VMware Workstation and Fusion contain an integer-overflow vulnerability. A malic
CVE-2026-105141 6.3 0.34% 2 0 2026-10-06T15:04:52.637000 A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affec
CVE-2026-79820 9.0 0.27% 1 0 2026-10-05T18:34:22 A remote user validation failure vulnerability exists in HPE Integrated Lights-O
CVE-2026-105133 7.3 0.38% 5 0 2026-10-04T09:30:21 A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the fu
CVE-2026-105134 10.0 1.84% 5 1 2026-10-04T09:30:21 A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects
CVE-2026-88772 8.1 1.30% 1 8 2026-09-28T12:32:09 Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue
CVE-2026-88771 9.8 1.08% 2 14 2026-09-28T12:32:08 Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc
CVE-2026-25264 8.8 0.07% 1 0 2026-09-25T13:37:47.870000 Privilege escalation due to weak configuration during package extraction process
CVE-2026-25254 9.8 0.32% 1 0 2026-09-25T13:37:41.860000 Improper authorization leads to Remote Code Execution via SocketIO interface.
CVE-2026-62866 6.2 0.19% 1 0 2026-09-24T21:25:27.050000 Dasel is a command-line tool and library for querying, modifying, and transformi
CVE-2026-82077 None 0.74% 2 0 2026-09-24T09:32:00 An improper limitation of a pathname to a restricted directory (path traversal)
CVE-2026-93952 10.0 1.06% 1 0 2026-09-23T14:32:12.417000 VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may a
CVE-2026-85219 3.7 0.41% 1 0 2026-09-22T19:41:38.447000 Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an
CVE-2026-19658 9.8 0.53% 1 1 2026-09-22T06:30:35 The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in
CVE-2026-13355 9.8 0.44% 1 1 2026-09-22T06:30:35 The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to A
CVE-2026-93485 7.1 0.38% 1 4 2026-09-18T06:32:17 Improper neutralization of input during web page generation ('cross-site scripti
CVE-2026-82078 9.1 63.53% 2 2 2026-09-14T00:16:56.777000 An unsafe dynamic class loading vulnerability exists in the database connection
CVE-2026-0310 None 0.37% 1 0 2026-09-10T06:31:55 A buffer overflow vulnerability in the XML processing functionality of Palo Alto
CVE-2026-80093 7.0 0.32% 1 0 2026-09-09T00:31:34 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized at
CVE-2025-30156 8.9 0.09% 2 0 2026-09-08T21:11:56.250000 Ceph is an open-source distributed storage platform providing object, block, and
CVE-2026-6726 7.9 0.19% 1 0 2026-09-08T14:09:00.860000 An information leakage vulnerability was reported in the TCG TPM 2.0 reference c
CVE-2026-6727 5.9 0.15% 1 4 2026-09-08T14:09:00.860000 A timing side-channel vulnerability exists in the RSA OAEP decryption implementa
CVE-2026-31431 7.8 3.44% 1 100 template 2026-09-08T09:36:36 In the Linux kernel, the following vulnerability has been resolved: crypto: alg
CVE-2026-81578 9.8 85.58% 2 2 2026-08-31T21:31:56 An improper access control vulnerability exists in the web management interface
CVE-2026-48710 6.5 7.06% 1 5 2026-08-28T18:31:00 ### Summary In affected versions, the HTTP `Host` request header was not validat
CVE-2026-73570 8.9 71.66% 1 10 2026-08-24T13:19:17.577000 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor
CVE-2026-72898 10.0 19.05% 1 10 2026-08-12T15:18:30.347000 Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via t
CVE-2026-47483 8.2 0.34% 1 0 2026-07-28T18:33:11 NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pp
CVE-2025-47818 2.2 0.24% 1 0 2026-06-17T09:28:43.993000 Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for
CVE-2025-31200 9.8 20.90% 1 4 2026-06-17T09:10:00.550000 A memory corruption issue was addressed with improved bounds checking. This issu
CVE-2025-24201 10.0 3.85% 1 3 2026-06-17T08:58:17.950000 An out-of-bounds write issue was addressed with improved checks to prevent unaut
CVE-2026-0257 9.1 96.89% 2 8 2026-06-09T12:32:02 Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of
CVE-2024-3094 10.0 85.97% 1 90 2024-03-29T18:30:50 Malicious code was discovered in the upstream tarballs of xz, starting with vers
CVE-2026-87902 0 39.98% 1 27 N/A
CVE-2026-108269 0 0.13% 1 0 N/A
CVE-2026-92705 0 0.13% 1 0 N/A
CVE-2026-107821 0 0.48% 1 0 N/A
CVE-2026-107838 0 0.34% 1 0 N/A
CVE-2026-107837 0 0.38% 1 0 N/A
CVE-2026-61746 0 0.40% 1 0 N/A

CVE-2026-19935
(7.5 HIGH)

EPSS: 0.00%

updated 2026-10-11T18:16:59.410000

2 posts

The Bluetooth LE host queues received L2CAP connection-oriented channel (CoC) data for deferred processing through a struct k_work embedded in the channel object (le_chan->rx_work, handler l2cap_rx_process()) whenever the channel uses a dynamic PSM (0x0080-0x00FF). Channel teardown in l2cap_chan_destroy() in subsys/bluetooth/host/l2cap.c cancels the retransmission-timeout work and drains the RX FI

thehackerwire@mastodon.social at 2026-10-11T18:45:26.000Z ##

🟠 CVE-2026-19935 - High (7.5)

The Bluetooth LE host queues received L2CAP connection-oriented channel (CoC) data for deferred processing through a struct k_work embedded in the channel object (le_chan->rx_work, handler l2cap_rx_process()) whenever the channel uses a dynamic PS...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-11T18:45:26.000Z ##

🟠 CVE-2026-19935 - High (7.5)

The Bluetooth LE host queues received L2CAP connection-oriented channel (CoC) data for deferred processing through a struct k_work embedded in the channel object (le_chan->rx_work, handler l2cap_rx_process()) whenever the channel uses a dynamic PS...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19736
(7.8 HIGH)

EPSS: 0.00%

updated 2026-10-11T18:16:58.810000

2 posts

The NXP MCUX TRNG entropy driver in drivers/entropy/entropy_mcux_trng.c passed the caller's byte count straight to the vendor SDK routine TRNG_GetRandomData(). On i.MX RT5xx and RT6xx parts the SDK compiles its TRNG_SW_HEALTH_TESTS variant, which always copies whole 32-bit words and draws entropy rounded up to a multiple of 128 bytes. Its "caller buffer is full" guard tests dataSize == 0, so a req

thehackerwire@mastodon.social at 2026-10-11T18:45:45.000Z ##

🟠 CVE-2026-19736 - High (7.8)

The NXP MCUX TRNG entropy driver in drivers/entropy/entropy_mcux_trng.c passed the caller's byte count straight to the vendor SDK routine TRNG_GetRandomData(). On i.MX RT5xx and RT6xx parts the SDK compiles its TRNG_SW_HEALTH_TESTS variant, which ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-11T18:45:45.000Z ##

🟠 CVE-2026-19736 - High (7.8)

The NXP MCUX TRNG entropy driver in drivers/entropy/entropy_mcux_trng.c passed the caller's byte count straight to the vendor SDK routine TRNG_GetRandomData(). On i.MX RT5xx and RT6xx parts the SDK compiles its TRNG_SW_HEALTH_TESTS variant, which ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19669
(7.8 HIGH)

EPSS: 0.00%

updated 2026-10-11T18:16:58.563000

2 posts

The user-mode syscall verifiers z_vrfy_fuel_gauge_get_props() and z_vrfy_fuel_gauge_set_props() in drivers/fuel_gauge/fuel_gauge_syscall_handlers.c declared two variable-length arrays, union fuel_gauge_prop_val k_vals[len] and fuel_gauge_prop_t k_props[len], sized directly by the caller-supplied len argument. len is an unvalidated size_t taken straight from the syscall ABI, and the VLAs were alloc

thehackerwire@mastodon.social at 2026-10-11T18:45:36.000Z ##

🟠 CVE-2026-19669 - High (7.8)

The user-mode syscall verifiers z_vrfy_fuel_gauge_get_props() and z_vrfy_fuel_gauge_set_props() in drivers/fuel_gauge/fuel_gauge_syscall_handlers.c declared two variable-length arrays, union fuel_gauge_prop_val k_vals[len] and fuel_gauge_prop_t k_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-10-11T18:45:36.000Z ##

🟠 CVE-2026-19669 - High (7.8)

The user-mode syscall verifiers z_vrfy_fuel_gauge_get_props() and z_vrfy_fuel_gauge_set_props() in drivers/fuel_gauge/fuel_gauge_syscall_handlers.c declared two variable-length arrays, union fuel_gauge_prop_val k_vals[len] and fuel_gauge_prop_t k_...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-91136
(7.5 HIGH)

EPSS: 0.56%

updated 2026-10-11T17:17:07.010000

1 posts

The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.4.0 via the 'svg_image' parameter of the /wp-json/elicus/v1/dipl-modules/svg-animator REST endpoint. This is due to the endpoint's permission callback (SVGAnimatorController::index_permission) returning true unconditionally combined with insufficient validation of the 'svg_image' input — san

thehackerwire@mastodon.social at 2026-10-10T18:00:35.000Z ##

🟠 CVE-2026-91136 - High (7.5)

The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.4.0 via the 'svg_image' parameter of the /wp-json/elicus/v1/dipl-modules/svg-animator REST endpoint. This is due to the endpoint's permissi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-33367
(8.1 HIGH)

EPSS: 0.29%

updated 2026-10-11T17:17:04.760000

1 posts

SNMP can be used to perform administrative actions such as retrieving configuration files, modifying user accounts or device settings, and initiating firmware or bootloader upgrades or downgrades—all without any authentication.

thehackerwire@mastodon.social at 2026-10-09T21:01:01.000Z ##

🟠 CVE-2026-33367 - High (8.1)

SNMP can be used to perform administrative actions such as retrieving configuration files, modifying user accounts or device settings, and initiating firmware or bootloader upgrades or downgrades—all without any authentication.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-28745
(7.5 HIGH)

EPSS: 0.22%

updated 2026-10-11T17:17:04.303000

1 posts

Usernames and passwords, including the default credentials, are stored in the configuration file using weak encryption. If the default credentials are known by a malicious user, they could obtain other credentials on the system.

thehackerwire@mastodon.social at 2026-10-09T22:01:33.000Z ##

🟠 CVE-2026-28745 - High (7.5)

Usernames and passwords, including the default credentials, are stored in the configuration file using weak encryption. If the default credentials are known by a malicious user, they could obtain other credentials on the system.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105281
(7.5 HIGH)

EPSS: 0.31%

updated 2026-10-11T17:17:01.723000

1 posts

The internal data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and retrieve the complete device and measurement topology of the system.

DailyCyberSecurity@infosec.exchange at 2026-10-09T16:05:45.000Z ##

Fix critical openPDC openHistorian vulnerabilities like CVE-2026-100730 and CVE-2026-105281. CISA urges patching these severe RCE flaws immediately.

#openPDC #openHistorian #CyberSecurity #Vulnerability #CISA

securityonline.info/openpdc-op

##

CVE-2026-104759
(8.1 HIGH)

EPSS: 0.52%

updated 2026-10-11T17:17:00.237000

1 posts

The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Authentication Bypass via OIDC Nonce Replay in all versions up to, and including, 44.1 This is due to `Id_Token_Service_Deprecated::process_openidconnect_token()` using the incompatible WordPress core `wp_verify_nonce()` function to validate a nonce produced by `Nonce_Service::create_nonc

thehackerwire@mastodon.social at 2026-10-10T20:00:38.000Z ##

🟠 CVE-2026-104759 - High (8.1)

The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Authentication Bypass via OIDC Nonce Replay in all versions up to, and including, 44.1 This is due to `Id_Token_Service_Deprecated::proc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96341
(8.2 HIGH)

EPSS: 0.28%

updated 2026-10-11T13:17:29.907000

1 posts

Incorrect Privilege Assignment vulnerability in WPMU DEV Forminator forminator allows Privilege Escalation.This issue affects Forminator: from n/a through 1.57.3.

thehackerwire@mastodon.social at 2026-10-10T19:30:56.000Z ##

🟠 CVE-2026-96341 - High (8.2)

Incorrect Privilege Assignment vulnerability in WPMU DEV Forminator forminator allows Privilege Escalation.This issue affects Forminator: from n/a through 1.57.3.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93944
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-10-11T13:17:28.283000

2 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia camelia allows Object Injection.This issue affects Camelia: from n/a through 1.2.15.

thehackerwire@mastodon.social at 2026-10-10T18:46:00.000Z ##

🔴 CVE-2026-93944 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia camelia allows Object Injection.This issue affects Camelia: from n/a through 1.2.15.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-10T13:30:24.000Z ##

CVE-2026-93944: CRITICAL deserialization vuln in ThemeREX Camelia (<=1.2.15). Allows remote object injection & full system compromise. No patch yet — limit exposure, monitor vendor. 🔎 radar.offseq.com/threat/cve-20 #OffSeq #Infosec #Vulnerability

##

CVE-2026-93943
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-10-11T13:17:28.180000

1 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0.

thehackerwire@mastodon.social at 2026-10-10T18:45:50.000Z ##

🔴 CVE-2026-93943 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93940
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-11T13:17:27.850000

1 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.

thehackerwire@mastodon.social at 2026-10-10T18:30:36.000Z ##

🔴 CVE-2026-93940 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93937
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-11T13:17:27.643000

1 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0.

thehackerwire@mastodon.social at 2026-10-10T18:15:43.000Z ##

🔴 CVE-2026-93937 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93934
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-10-11T13:17:27.323000

1 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Partiso partiso allows Object Injection.This issue affects Partiso: from n/a through 1.1.13.

thehackerwire@mastodon.social at 2026-10-10T19:46:01.000Z ##

🔴 CVE-2026-93934 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Partiso partiso allows Object Injection.This issue affects Partiso: from n/a through 1.1.13.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93932
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-10-11T13:17:27.100000

1 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Smart Casa smart-casa allows Object Injection.This issue affects Smart Casa: from n/a through 1.0.12.

thehackerwire@mastodon.social at 2026-10-10T19:32:38.000Z ##

🔴 CVE-2026-93932 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Smart Casa smart-casa allows Object Injection.This issue affects Smart Casa: from n/a through 1.0.12.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93931
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-10-11T13:17:26.997000

1 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Smash smash allows Object Injection.This issue affects Smash: from n/a through 1.12.0.

thehackerwire@mastodon.social at 2026-10-10T19:32:30.000Z ##

🔴 CVE-2026-93931 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Smash smash allows Object Injection.This issue affects Smash: from n/a through 1.12.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62045
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-10-11T13:17:24.780000

2 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0.

thehackerwire@mastodon.social at 2026-10-10T20:00:56.000Z ##

🔴 CVE-2026-62045 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-10T07:30:23.000Z ##

Deserialization of untrusted data in ThemeREX Booklovers (<=2.13.0) — CVE-2026-62045 (CRITICAL, CVSS 9.8) enables object injection. No patch yet, so restrict access & monitor. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202662045 #WordPress #Vuln #infosec

##

CVE-2026-108753
(9.4 CRITICAL)

EPSS: 0.00%

updated 2026-10-11T13:17:20.237000

2 posts

Agnaistic agnai through 1.0.555 contains a hard-coded credentials vulnerability in self-host.docker-compose.yml, which sets a fixed admin password and public JWT secret. Unauthenticated attackers can log in as admin or sign their own JWT with admin: true to impersonate users, reset passwords, and change server configuration.

offseq at 2026-10-11T13:30:25.518Z ##

CVE-2026-108753 | agnaistic agnai ≤1.0.555: CRITICAL hard-coded admin creds in docker-compose enable full admin compromise. Restrict config file access & monitor for abuse. Patch status unconfirmed. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-11T13:30:25.000Z ##

CVE-2026-108753 | agnaistic agnai ≤1.0.555: CRITICAL hard-coded admin creds in docker-compose enable full admin compromise. Restrict config file access & monitor for abuse. Patch status unconfirmed. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026108753 #infosec #vuln

##

CVE-2026-106610
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-10-11T13:17:12.430000

2 posts

Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through 5.5.7.

1 repos

https://github.com/KevineCharles/CVE-2026-106610-miniorange-otp-ato

Matchbook3469@mastodon.social at 2026-10-11T13:23:12.000Z ##

🔴 New security advisory:

CVE-2026-106610 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
yazoul.net/advisory/cve/cve-20

by Yazoul AI

#InfoSec #SecurityPatching #HackerNews

##

thehackerwire@mastodon.social at 2026-10-10T19:31:16.000Z ##

🔴 CVE-2026-106610 - Critical (9.8)

Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through 5.5.7.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105892
(9.8 CRITICAL)

EPSS: 0.42%

updated 2026-10-11T13:17:11.910000

1 posts

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rtCamp Inc. rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Path Traversal.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through 4.7.13.

thehackerwire@mastodon.social at 2026-10-10T19:32:20.000Z ##

🔴 CVE-2026-105892 - Critical (9.8)

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rtCamp Inc. rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Path Traversal.This issue affects rtMedia for WordPress, BuddyPress a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104398
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-10-11T13:17:11.270000

2 posts

Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Object Injection.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.10.

offseq@infosec.exchange at 2026-10-11T00:00:38.000Z ##

Deserialization of untrusted data in VillaTheme AFFI for WooCommerce (<=1.0.10) — CVE-2026-104398 (CRITICAL, CVSS 9.8) enables remote code execution with no auth/user input. Restrict or remove plugin until patched. radar.offseq.com/threat/deseri #OffSeq #CVE2026104398 #WordPress #Infosec

##

thehackerwire@mastodon.social at 2026-10-10T17:31:32.000Z ##

🔴 CVE-2026-104398 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Object Injection.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103071
(7.5 HIGH)

EPSS: 0.25%

updated 2026-10-11T13:17:10.180000

1 posts

Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Code Injection.This issue affects Thank You Page Customizer for WooCommerce: from n/a through 1.2.3.

thehackerwire@mastodon.social at 2026-10-10T17:30:51.000Z ##

🟠 CVE-2026-103071 - High (7.5)

Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Code Injection.This issue affects Thank You Page Customizer for WooCommerce: from ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93550
(4.3 MEDIUM)

EPSS: 0.14%

updated 2026-10-11T12:32:13

2 posts

The Veeqo for WooCommerce WordPress plugin through 2.2.8 does not restrict who can trigger its remote bridge-installation process or validate the URL it is given before downloading and extracting it, allowing users with Subscriber-level access and above to make the Veeqo for WooCommerce WordPress plugin through 2.2.8 download and extract an attacker-controlled archive containing arbitrary PHP file

offseq at 2026-10-11T10:30:26.835Z ##

CVE-2026-93550 (HIGH): Veeqo for WooCommerce ≤2.2.8 lets Subscriber+ users upload arbitrary PHP files via insufficient URL validation, risking full site compromise. Restrict access & monitor plugin activity. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-11T10:30:26.000Z ##

CVE-2026-93550 (HIGH): Veeqo for WooCommerce ≤2.2.8 lets Subscriber+ users upload arbitrary PHP files via insufficient URL validation, risking full site compromise. Restrict access & monitor plugin activity. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #BlueTeam

##

CVE-2026-96227
(8.8 HIGH)

EPSS: 0.17%

updated 2026-10-11T12:32:13

2 posts

The Piotnet Forms WordPress plugin through 1.0.30 does not authenticate or validate a form-submission file-upload request and permits browser-renderable file types to be stored, allowing unauthenticated attackers to store a file that executes arbitrary JavaScript in the site's origin when it is opened (Stored XSS).

offseq at 2026-10-11T09:00:34.844Z ##

Piotnet Forms <=1.0.30 impacted by HIGH severity stored XSS (CVE-2026-96227). Unauthenticated file uploads allow arbitrary JS execution. Restrict uploads & validate files. Await vendor patch. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-11T09:00:34.000Z ##

Piotnet Forms <=1.0.30 impacted by HIGH severity stored XSS (CVE-2026-96227). Unauthenticated file uploads allow arbitrary JS execution. Restrict uploads & validate files. Await vendor patch. Details: radar.offseq.com/threat/cve-20 #OffSeq #XSS #WordPress #Infosec

##

CVE-2026-86717
(9.1 CRITICAL)

EPSS: 0.15%

updated 2026-10-11T12:17:24.653000

2 posts

The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to delete arbitrary WordPress options, which can take the site offline and strip every user of their role.

offseq at 2026-10-11T12:00:25.288Z ##

CVE-2026-86717 (CRITICAL) targets Insurify WP plugin ≤1.0. Missing auth & nonce checks in AJAX lets unauth users delete WordPress options — site can be taken offline, user roles wiped. Disable or restrict plugin. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-11T12:00:25.000Z ##

CVE-2026-86717 (CRITICAL) targets Insurify WP plugin ≤1.0. Missing auth & nonce checks in AJAX lets unauth users delete WordPress options — site can be taken offline, user roles wiped. Disable or restrict plugin. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202686717 #infosec

##

CVE-2026-81797
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-10-11T12:17:22.500000

1 posts

Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordPress Theme <= 1.0.2 versions.

thehackerwire@mastodon.social at 2026-10-10T20:31:18.000Z ##

🔴 CVE-2026-81797 - Critical (9.8)

Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordPress Theme &lt;= 1.0.2 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78535
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-10-11T12:17:21.310000

1 posts

Unauthenticated PHP Object Injection in Photolia <= 1.0.3 versions.

thehackerwire@mastodon.social at 2026-10-10T20:31:09.000Z ##

🔴 CVE-2026-78535 - Critical (9.8)

Unauthenticated PHP Object Injection in Photolia &lt;= 1.0.3 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78533
(9.8 CRITICAL)

EPSS: 0.34%

updated 2026-10-11T12:17:21.103000

1 posts

Unauthenticated PHP Object Injection in Qwery <= 3.6.1 versions.

thehackerwire@mastodon.social at 2026-10-10T20:31:00.000Z ##

🔴 CVE-2026-78533 - Critical (9.8)

Unauthenticated PHP Object Injection in Qwery &lt;= 3.6.1 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66569
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-10-11T12:17:20.693000

1 posts

Unauthenticated PHP Object Injection in Kicker <= 2.2.1 versions.

thehackerwire@mastodon.social at 2026-10-10T20:45:51.000Z ##

🔴 CVE-2026-66569 - Critical (9.8)

Unauthenticated PHP Object Injection in Kicker &lt;= 2.2.1 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66568
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-10-11T12:17:20.590000

1 posts

Unauthenticated PHP Object Injection in Original <= 1.9.0 versions.

thehackerwire@mastodon.social at 2026-10-10T20:32:25.000Z ##

🔴 CVE-2026-66568 - Critical (9.8)

Unauthenticated PHP Object Injection in Original &lt;= 1.9.0 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108540
(9.9 CRITICAL)

EPSS: 1.70%

updated 2026-10-11T09:30:32

2 posts

A flaw has been found in OpenSpug Spug up to 3.4.0/4.0.1. This impacts an unknown function of the file /exec/transfer of the component File Transfer. Executing a manipulation can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

offseq at 2026-10-11T07:30:25.163Z ##

CVE-2026-108540: CRITICAL OS command injection in OpenSpug Spug 3.0 – 4.0.1. Remote attackers can execute arbitrary OS commands. Exploit code is public. Restrict access/disable vulnerable features until a patch arrives. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-10-11T07:30:25.000Z ##

CVE-2026-108540: CRITICAL OS command injection in OpenSpug Spug 3.0 – 4.0.1. Remote attackers can execute arbitrary OS commands. Exploit code is public. Restrict access/disable vulnerable features until a patch arrives. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Exploit #Infosec

##

CVE-2026-108707
(9.8 CRITICAL)

EPSS: 0.55%

updated 2026-10-11T03:30:24

2 posts

Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every HRM API endpoint by omitting the AUTH-TOKEN header. Attackers gain HR administrator access to read payslips, salary history and employee personal data, download attachments, and modify or delete company-wide HR records.

hugovalters@mastodon.social at 2026-10-11T11:04:28.000Z ##

CVE-2026-108707 - Critical Auth Bypass in Wukong_HRM allows full API takeover & sensitive HR data theft. CVSS 9.8. Restrict API access immediately. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-108

##

offseq@infosec.exchange at 2026-10-11T03:00:27.000Z ##

CRITICAL: CVE-2026-108707 in WuKong_HRM (≤ commit 186115e) enables auth bypass — attackers can access all HRM APIs, gaining admin rights and exposing sensitive HR data. Restrict endpoints & monitor for unauthorized access. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026108707 #infosec #vulnerability

##

CVE-2026-78530
(7.7 HIGH)

EPSS: 0.40%

updated 2026-10-10T21:31:28

1 posts

Subscriber Arbitrary File Deletion in FoodBakery <= 4.6 versions.

thehackerwire@mastodon.social at 2026-10-10T20:46:10.000Z ##

🟠 CVE-2026-78530 - High (7.7)

Subscriber Arbitrary File Deletion in FoodBakery &lt;= 4.6 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78529
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-10-10T21:31:28

1 posts

Unauthenticated PHP Object Injection in Alliance <= 3.11 versions.

thehackerwire@mastodon.social at 2026-10-10T20:46:00.000Z ##

🔴 CVE-2026-78529 - Critical (9.8)

Unauthenticated PHP Object Injection in Alliance &lt;= 3.11 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66566
(8.1 HIGH)

EPSS: 0.28%

updated 2026-10-10T21:31:28

1 posts

Unauthenticated Local File Inclusion in Ambient <= 1.7 versions.

CVE-2026-66567
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-10T21:31:27

1 posts

Unauthenticated PHP Object Injection in Anesta <= 1.5.3 versions.

thehackerwire@mastodon.social at 2026-10-10T20:32:16.000Z ##

🔴 CVE-2026-66567 - Critical (9.8)

Unauthenticated PHP Object Injection in Anesta &lt;= 1.5.3 versions.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108598
(9.8 CRITICAL)

EPSS: 0.73%

updated 2026-10-10T21:31:20

1 posts

Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util reflection to reach Runtime or ProcessBuilder, executing OS commands in the Floci JVM.

thehackerwire@mastodon.social at 2026-10-10T19:31:05.000Z ##

🔴 CVE-2026-108598 - Critical (9.8)

Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration wh...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-106609
(7.5 HIGH)

EPSS: 0.22%

updated 2026-10-10T18:31:27

1 posts

Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcash-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bayarcash WooCommerce: from n/a through 4.4.2.

thehackerwire@mastodon.social at 2026-10-10T17:30:42.000Z ##

🟠 CVE-2026-106609 - High (7.5)

Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcash-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bayarcash WooCommerce: from n/a through 4.4.2.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105889
(9.3 CRITICAL)

EPSS: 0.26%

updated 2026-10-10T18:31:27

1 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6.

thehackerwire@mastodon.social at 2026-10-10T17:30:33.000Z ##

🔴 CVE-2026-105889 - Critical (9.3)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108546
(7.5 HIGH)

EPSS: 0.80%

updated 2026-10-10T15:30:30

1 posts

Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with shell metacharacters in the title, which are substituted unescaped for $SPOTTITLE and passed to exec() when a user downloads the spot, running commands as

thehackerwire@mastodon.social at 2026-10-10T17:45:49.000Z ##

🟠 CVE-2026-108546 - High (7.5)

Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with sh...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-105885
(8.8 HIGH)

EPSS: 0.29%

updated 2026-10-10T15:30:29

1 posts

Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider-wd allows Object Injection.This issue affects Slider by 10Web: from n/a through 1.2.62.

thehackerwire@mastodon.social at 2026-10-10T17:46:26.000Z ##

🟠 CVE-2026-105885 - High (8.8)

Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider-wd allows Object Injection.This issue affects Slider by 10Web: from n/a through 1.2.62.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108550
(8.8 HIGH)

EPSS: 0.30%

updated 2026-10-10T15:30:24

1 posts

SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeController that allows authenticated attackers to take over other accounts by abusing the merge flow. Attackers can call the merge initiate endpoint with a target username or OAuth identity, receive the verification token directly, and confirm the merge to inherit the victim's API tokens

thehackerwire@mastodon.social at 2026-10-10T17:31:41.000Z ##

🟠 CVE-2026-108550 - High (8.8)

SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeController that allows authenticated attackers to take over other accounts by abusing the merge flow. Attackers can call the merge init...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108161
(7.5 HIGH)

EPSS: 1.10%

updated 2026-10-10T15:30:22

1 posts

FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. When the record_name filename template is enabled, attackers can embed shell metacharacters like $(...) in the Caller-ID name or number, executing commands as the web server user once a priv

thehackerwire@mastodon.social at 2026-10-10T17:46:35.000Z ##

🟠 CVE-2026-108161 - High (7.5)

FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. When the record_name filename templat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108553
(7.5 HIGH)

EPSS: 0.18%

updated 2026-10-10T15:16:58.410000

1 posts

OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET with a crafted engine parameter, executing operating system commands as the OpenRefine user.

thehackerwire@mastodon.social at 2026-10-10T17:45:40.000Z ##

🟠 CVE-2026-108553 - High (7.5)

OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET with a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108551
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-10-10T15:16:58.273000

1 posts

openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript by supplying unescaped values interpolated into single-quoted string literals. Attackers can embed a single quote in path keys, parameter names, servers[0].url, or info.version to execute arbitrary JavaScript when generated clients are importe

thehackerwire@mastodon.social at 2026-10-10T17:31:50.000Z ##

🔴 CVE-2026-108551 - Critical (9.8)

openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript by supplying unescaped values interpolated into single-quoted string literals. Attackers c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108549
(8.1 HIGH)

EPSS: 0.45%

updated 2026-10-10T15:16:58.087000

1 posts

cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webhook listener on port 8080 can forge updates with an allowed or admin user_id to run privileged commands like /shell on the host.

thehackerwire@mastodon.social at 2026-10-10T17:46:17.000Z ##

🟠 CVE-2026-108549 - High (8.1)

cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webho...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19494
(8.1 HIGH)

EPSS: 0.29%

updated 2026-10-10T13:17:32.163000

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication.

thehackerwire@mastodon.social at 2026-10-08T21:46:18.000Z ##

🟠 CVE-2026-19494 - High (8.1)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-96662
(7.5 HIGH)

EPSS: 0.39%

updated 2026-10-10T09:30:41

1 posts

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to generic SQL Injection via 'booking[service_id]' Parameter in all versions up to, and including, 5.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to a

thehackerwire@mastodon.social at 2026-10-10T18:00:45.000Z ##

🟠 CVE-2026-96662 - High (7.5)

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to generic SQL Injection via 'booking[service_id]' Parameter in all versions up to, and including, 5.7.2 due to insufficient esca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93936
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-10T09:30:37

2 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4.

offseq@infosec.exchange at 2026-10-11T06:00:25.000Z ##

ThemeREX IPharm ipharm ≤1.2.4 hit by CRITICAL deserialization vuln (CVE-2026-93936, CVSS 9.8) 🛡️ Allows object injection & potential system compromise. No patch yet — restrict access, increase monitoring. radar.offseq.com/threat/deseri #OffSeq #vuln #CVE202693936 #infosec

##

thehackerwire@mastodon.social at 2026-10-10T18:15:33.000Z ##

🔴 CVE-2026-93936 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93945
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-10T09:30:37

3 posts

Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.

offseq@infosec.exchange at 2026-10-11T04:30:24.000Z ##

CVE-2026-93945: CRITICAL object injection via deserialization in Axiomthemes Balance (<=1.12.0). Full compromise risk — no patch yet. Check vendor guidance & mitigate if possible. radar.offseq.com/threat/deseri #OffSeq #CVE202693945 #WordPress #Vuln #Infosec

##

thehackerwire@mastodon.social at 2026-10-10T18:00:54.000Z ##

🔴 CVE-2026-93945 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-10T12:00:24.000Z ##

CRITICAL: CVE-2026-93945 in Axiomthemes Balance (<=1.12.0) allows remote object injection via deserialization of untrusted data. No auth or user action needed — full system compromise possible. Restrict access & monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Vuln

##

CVE-2026-93935
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-10-10T09:30:37

2 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Let's Play playhockey allows Object Injection.This issue affects Let's Play: from n/a through 1.1.15.

offseq@infosec.exchange at 2026-10-11T01:30:25.000Z ##

CVE-2026-93935: ThemeREX Let's Play playhockey ≤1.1.15 affected by CRITICAL deserialization flaw (CWE-502). Enables remote object injection and full compromise. Patch pending — monitor vendor updates & restrict plugin use. radar.offseq.com/threat/deseri #OffSeq #CVE202693935 #WordPress #Infosec

##

thehackerwire@mastodon.social at 2026-10-10T19:46:09.000Z ##

🔴 CVE-2026-93935 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Let's Play playhockey allows Object Injection.This issue affects Let's Play: from n/a through 1.1.15.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62046
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-10-10T09:30:37

2 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12.

thehackerwire@mastodon.social at 2026-10-10T20:15:37.000Z ##

🔴 CVE-2026-62046 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-10T10:30:24.000Z ##

CVE-2026-62046: CRITICAL deserialization flaw in ThemeREX Gutentype (≤2.1.12) allows object injection — full system compromise possible. Patch status unknown, monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vulnerability #Infosec

##

CVE-2026-104803
(9.8 CRITICAL)

EPSS: 0.45%

updated 2026-10-10T09:30:37

2 posts

The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.27 via the `uuid` and `code` parameters of the social-login callback handler registered on the `init` hook. The vulnerability exists because the `login` function's social-login flow performs no nonce validation, no OAuth state verification, and no per-visitor namespace isolation i

thehackerwire@mastodon.social at 2026-10-10T20:00:47.000Z ##

🔴 CVE-2026-104803 - Critical (9.8)

The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.27 via the `uuid` and `code` parameters of the social-login callback handler registered on the `init` hook. The vulnerability ex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-10-10T09:00:24.000Z ##

WPCOM Member plugin (≤1.7.27) suffers CRITICAL auth bypass (CVE-2026-104803, CVSS 9.8) 🛡️. Attackers can impersonate any WordPress user via social-login flaw. Disable social login & check vendor for fixes. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #CVE2026104803

##

CVE-2026-93933
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-10-10T09:30:37

1 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Rosalinda rosalinda allows Object Injection.This issue affects Rosalinda: from n/a through 1.2.4.

thehackerwire@mastodon.social at 2026-10-10T19:45:53.000Z ##

🔴 CVE-2026-93933 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Rosalinda rosalinda allows Object Injection.This issue affects Rosalinda: from n/a through 1.2.4.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93929
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-10-10T09:30:37

1 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Travesia travesia allows Object Injection.This issue affects Travesia: from n/a through 1.1.16.

thehackerwire@mastodon.social at 2026-10-10T19:00:41.000Z ##

🔴 CVE-2026-93929 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Travesia travesia allows Object Injection.This issue affects Travesia: from n/a through 1.1.16.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93942
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-10-10T09:30:37

1 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell allows Object Injection.This issue affects Dwell: from n/a through 1.16.0.

thehackerwire@mastodon.social at 2026-10-10T18:45:42.000Z ##

🔴 CVE-2026-93942 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell allows Object Injection.This issue affects Dwell: from n/a through 1.16.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93941
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-10T09:30:37

1 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.

thehackerwire@mastodon.social at 2026-10-10T18:30:45.000Z ##

🔴 CVE-2026-93941 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93938
(9.8 CRITICAL)

EPSS: 0.33%

updated 2026-10-10T09:30:37

1 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7.

thehackerwire@mastodon.social at 2026-10-10T18:30:26.000Z ##

🔴 CVE-2026-93938 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93950
(7.5 HIGH)

EPSS: 0.20%

updated 2026-10-10T09:30:37

1 posts

Missing Authorization vulnerability in StylemixThemes Motors motors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through 1.4.108.

thehackerwire@mastodon.social at 2026-10-10T18:15:24.000Z ##

🟠 CVE-2026-93950 - High (7.5)

Missing Authorization vulnerability in StylemixThemes Motors motors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through 1.4.108.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-94538
(8.1 HIGH)

EPSS: 0.25%

updated 2026-10-10T09:30:36

1 posts

The WP File Download plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.3.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to permanently delete any file managed by WP File Download, empty the entire trash, mo

thehackerwire@mastodon.social at 2026-10-10T20:15:56.000Z ##

🟠 CVE-2026-94538 - High (8.1)

The WP File Download plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.3.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible fo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93746
(7.5 HIGH)

EPSS: 0.53%

updated 2026-10-10T09:30:36

1 posts

The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.2 via the 'email' parameter of the guest print_document_from_the_mail_link handler dispatched from print_window() on init. This is due to the handler authorizing access to an order's printable documents

thehackerwire@mastodon.social at 2026-10-10T20:15:47.000Z ##

🟠 CVE-2026-93746 - High (7.5)

The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.2 via the 'email' parameter of the guest print_doc...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93930
(9.8 CRITICAL)

EPSS: 0.31%

updated 2026-10-10T09:30:36

1 posts

Deserialization of Untrusted Data vulnerability in ThemeREX Group Tantra tantra allows Object Injection.This issue affects Tantra: from n/a through 2.9.0.

thehackerwire@mastodon.social at 2026-10-10T19:00:49.000Z ##

🔴 CVE-2026-93930 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeREX Group Tantra tantra allows Object Injection.This issue affects Tantra: from n/a through 2.9.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-93927
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-10-10T09:30:36

1 posts

Deserialization of Untrusted Data vulnerability in Axiomthemes Veto veto allows Object Injection.This issue affects Veto: from n/a through 1.6.0.

thehackerwire@mastodon.social at 2026-10-10T19:00:32.000Z ##

🔴 CVE-2026-93927 - Critical (9.8)

Deserialization of Untrusted Data vulnerability in Axiomthemes Veto veto allows Object Injection.This issue affects Veto: from n/a through 1.6.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-97670
(9.1 CRITICAL)

EPSS: 0.37%

updated 2026-10-10T06:31:08

1 posts

The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16.1. This is due to the plugin not properly verifying authorization before dispatching a WordPress action hook whose name is taken from an attacker-supplied form-field value (via the notification email_message [field] placeholder and the {action_hook,...} dynamic-data toke

offseq@infosec.exchange at 2026-10-10T06:00:25.000Z ##

CVE-2026-97670: Avada (Fusion) Builder ≤7.16.1 has a CRITICAL code injection flaw. Unauthenticated attackers can invoke arbitrary WP action hooks — risks include content deletion & DoS. Disable vulnerable forms, await patch. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #CVE202697670

##

CVE-2026-94589
(9.8 CRITICAL)

EPSS: 0.66%

updated 2026-10-10T06:31:06

1 posts

The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.4.5 via the extcf7_submit function. This is due to missing file extension, MIME type, and size validation in the signature field's validation_filter(), combined with the absence of PHP-execution guards in the upload

offseq@infosec.exchange at 2026-10-10T04:30:25.000Z ##

CVE-2026-94589: CRITICAL RCE in Extensions For CF7 (<=3.4.5) for WordPress. Unauth attackers can upload and run malicious files — full compromise possible. Restrict uploads, monitor activity, and check for fixes. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202694589 #infosec

##

CVE-2026-88131
(9.8 CRITICAL)

EPSS: 0.84%

updated 2026-10-10T04:18:19.240000

2 posts

Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code over a network.

ssvc@infosec.exchange at 2026-10-09T14:45:52.000Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

#microsoft #CVE

##

offseq@infosec.exchange at 2026-10-09T03:00:24.000Z ##

Microsoft Dataverse is affected by CVE-2026-88131 (CRITICAL, CVSS 9.8): deserialization of untrusted data allows unauthenticated RCE. Patch available — apply ASAP! radar.offseq.com/threat/cve-20 #OffSeq #CVE202688131 #Microsoft #RCE #Infosec

##

CVE-2026-84875
(7.5 HIGH)

EPSS: 0.42%

updated 2026-10-10T04:18:19.087000

1 posts

IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

thehackerwire@mastodon.social at 2026-10-08T22:31:07.000Z ##

🟠 CVE-2026-84875 - High (7.5)

IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84035
(8.1 HIGH)

EPSS: 0.37%

updated 2026-10-10T04:18:17.220000

1 posts

IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

thehackerwire@mastodon.social at 2026-10-08T22:32:04.000Z ##

🟠 CVE-2026-84035 - High (8.1)

IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-77900
(9.8 CRITICAL)

EPSS: 0.49%

updated 2026-10-10T04:18:14.030000

2 posts

Missing authentication for critical function in Azure App Service allows an unauthorized attacker to execute code over a network.

ssvc@infosec.exchange at 2026-10-09T14:45:52.000Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

#microsoft #CVE

##

offseq@infosec.exchange at 2026-10-09T04:30:25.000Z ##

Microsoft Azure App Service for Linux hit by CVE-2026-77900 (CRITICAL, CVSS 9.8): missing authentication enables unauthenticated remote code execution. Patch released — update now. radar.offseq.com/threat/cve-20 #OffSeq #Azure #CVE202677900 #Infosec #CloudSecurity

##

CVE-2026-69435
(9.6 CRITICAL)

EPSS: 0.39%

updated 2026-10-10T04:18:13.347000

2 posts

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

ssvc@infosec.exchange at 2026-10-09T14:45:52.000Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

#microsoft #CVE

##

offseq@infosec.exchange at 2026-10-09T07:30:24.000Z ##

CVE-2026-69435: CRITICAL SSRF (CVSS 9.6) in Microsoft Azure SRE Agent. Missing authorization controls let authorized attackers escalate privileges, risking confidentiality & integrity. Microsoft has issued a fix. radar.offseq.com/threat/cve-20 #OffSeq #Azure #SSRF #Infosec

##

CVE-2026-107406
(0 None)

EPSS: 0.47%

updated 2026-10-10T04:18:09.503000

10 posts

Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC. NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:   * For the following versions: Applicable only when configured as a SAML IdP: * NetScaler ADC and NetScaler Gateway between 14.1-73.37

4 repos

https://github.com/techupdate24/citrix-netscaler-rce-cve-2026-107406

https://github.com/ctroy999/CVE-2026-107406

https://github.com/ApexBreach/CVE-2026-107406-Poc

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

secpoint@mastodon.social at 2026-10-11T11:41:21.000Z ##

🚨 Critical Citrix NetScaler Vulnerability Disclosed

Citrix has disclosed CVE-2026-107406, a critical vulnerability affecting NetScaler ADC and NetScaler Gateway, with a CVSS 4.0 score of 9.5.

The vulnerability could potentially allow remote code execution or denial of service on affected systems.

Exploitation requires specific SAML Service Provider or Identity Provider configurations, depending on the installed version.

#SecPoint #Citrix #NetScaler #CyberSecurity #VulnerabilityManagement

##

jbhall56@infosec.exchange at 2026-10-09T14:40:50.000Z ##

CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution (RCE) or denial of service (DoS). It carries a CVSS v4.0 score of 9.5. theregister.com/security/2026/

##

guru@thecybersecguru.com at 2026-10-09T09:41:43.000Z ##

Citrix Patches Critical NetScaler Memory Overflow Flaw (CVSS 9.5) That Enables Remote Code Execution in SAML Deployments

Citrix patches CVE-2026-107406, a critical NetScaler memory overflow flaw rated CVSS 9.5 that can enable remote code execution or denial of service

thecybersecguru.com/uncategori

##

tugatech@masto.pt at 2026-10-09T09:33:45.000Z ##

Citrix emitiu um aviso urgente para corrigir uma vulnerabilidade crítica nas soluções de rede NetScaler ADC e plataformas de acesso remoto NetScaler Gateway. A falha, identificada como CVE-2026-107406, permite a execução remota de código arbitrário ou negação de serviço. 🚨

🔗 tugatech.com.pt/t92412-citrix-

#alerta #falha 

##

cyberworldops@infosec.exchange at 2026-10-09T09:20:27.000Z ##

Citrix NetScaler instances with SAML enabled are affected by CVE-2026-107406, which can cause remote code execution and crash. Exposed ADC and Gateway systems risk takeover or service disruption, so patching and log review for malicious SAML requests is critical. #NetScaler #Citrix #PatchManagement

cyberworldops.eu/en/netscaler-

##

DailyCyberSecurity@infosec.exchange at 2026-10-09T01:39:17.000Z ##

Critical Citrix NetScaler vulnerability CVE-2026-107406 (CVSS 9.5) can lead to RCE on SAML-configured ADC and Gateway. Upgrade now.

#Citrix #NetScaler #NetScalerGateway #CVE2026107406 #SAML #RCE #PatchNow #Vulnerability

securityonline.info/citrix-net

##

ssvc@infosec.exchange at 2026-10-08T23:55:22.000Z ##

I thought it was a Sunday because Citrix posted another yet another NetScaler security advisory:

CVE-2026-107406 (9.5 critical) pre-auth memory overflow > RCE or DoS

As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability.

support.citrix.com/external/ar
community.citrix.com/techzone-

#citrix #netscaler #cve

##

GossiTheDog@cyberplace.social at 2026-10-08T22:07:42.000Z ##

There’s yet another Citrix Netscaler vuln (new patch today) which allows unauth RCE - CVE-2026-107406

Same attack surface (SAML) as two of the other vulns exploited in the wild during the past month.

##

Creek__@cyberplace.social at 2026-10-08T21:09:21.000Z ##

@GossiTheDog community.citrix.com/techzone-

They did it again :D

##

ifin@infosec.exchange at 2026-10-08T21:09:58.000Z ##

I'm tired, boss.

A new #Citrix CVE affecting SAML IdP/SP-configured devices is out.

ifin.network/t/cve-2026-107406

#ThreatIntel #ThreatIntelligence #IFIN

##

CVE-2026-108474
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-10-10T00:17:03.673000

1 posts

In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped string arguments of several SQL functions

offseq@infosec.exchange at 2026-10-10T00:00:36.000Z ##

CVE-2026-108474: JetBrains Exposed (<1.5.1) faces CRITICAL SQL injection (CWE-89). Exploitation can fully compromise DBs — upgrade to 1.5.1+ now! CVSS 9.8. radar.offseq.com/threat/cve-20 #OffSeq #SQLi #JetBrains #AppSec

##

CVE-2026-108268
(0 None)

EPSS: 0.13%

updated 2026-10-09T22:16:59.643000

1 posts

Enclave OS Virtual runs container workloads inside confidential virtual machines with end-to-end attestation. Prior to tdx-v0.2.43 and tdx-gpu-v0.6.27, the TDX/GPU RA-TLS certificate issuer placed the certificate public-key hash and client nonce in quote ReportData but omitted a value bound to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote o

offseq@infosec.exchange at 2026-10-10T03:00:23.000Z ##

CVE-2026-108268 (CRITICAL, CVSS 9.1): Privasys enclave-os-virtual <0.2.43/<0.6.27 origin validation error lets attackers relay attestation quotes if they have the enclave TLS private key. Upgrade to patched versions ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026108268 #Vuln

##

CVE-2026-75351
(7.5 HIGH)

EPSS: 0.40%

updated 2026-10-09T21:31:18

1 posts

OpENer v2.3/commit 76b95cf, contains an out-of-bounds read in the server-side EtherNet/IP ForwardOpen connection-path parser. This allows a remote attacker to cause a denial of service.

thehackerwire@mastodon.social at 2026-10-09T21:47:06.000Z ##

🟠 CVE-2026-75351 - High (7.5)

OpENer v2.3/commit 76b95cf, contains an out-of-bounds read in the server-side EtherNet/IP ForwardOpen connection-path parser. This allows a remote attacker to cause a denial of service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75346
(7.5 HIGH)

EPSS: 0.54%

updated 2026-10-09T21:17:05.800000

1 posts

An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master through commit 76b95cf in the server-side CIP SetAttributeList service. This allows a remote attacker to cause a denial of service

thehackerwire@mastodon.social at 2026-10-09T22:01:13.000Z ##

🟠 CVE-2026-75346 - High (7.5)

An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master through commit 76b95cf in the server-side CIP SetAttributeList service. This allows a remote attacker to cause a denial of service

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62376
(8.1 HIGH)

EPSS: 0.21%

updated 2026-10-09T21:17:05.627000

1 posts

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.4.0 store password-reset, email-confirmation, and account-deletion tokens in the `user_tokens` table in plaintext. If an attacker gains read access to the database through a backup leak, misconfigured storage, or SQL-level exposure, they can immediately use pending tokens to take over user accounts without knowing

thehackerwire@mastodon.social at 2026-10-09T21:32:45.000Z ##

🟠 CVE-2026-62376 - High (8.1)

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.4.0 store password-reset, email-confirmation, and account-deletion tokens in the `user_tokens` table in plaintext. If an attacker gains read access to the database...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57458
(8.1 HIGH)

EPSS: 0.27%

updated 2026-10-09T21:17:05.190000

1 posts

Vikunja is an open-source self-hosted task management platform. In version 2.3.0, a scoped API token limited to the `oauth.authorize` permission can call `POST /api/v1/oauth/authorize`, obtain an OAuth authorization code, and exchange the code at `POST /api/v1/oauth/token` for a normal bearer JSON Web Token (JWT) and refresh token. The resulting credentials are not restricted by the original API t

thehackerwire@mastodon.social at 2026-10-09T21:32:35.000Z ##

🟠 CVE-2026-57458 - High (8.1)

Vikunja is an open-source self-hosted task management platform. In version 2.3.0, a scoped API token limited to the `oauth.authorize` permission can call `POST /api/v1/oauth/authorize`, obtain an OAuth authorization code, and exchange the code at ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108264
(9.1 CRITICAL)

EPSS: 0.38%

updated 2026-10-09T21:17:04.703000

1 posts

Wizarr is an advanced user invitation and management system for Jellyfin, Plex, Emby, and other media servers. Prior to 2026.9.1, wizard step Markdown supplied through the editor or imported bundles was evaluated by app/blueprints/wizard/routes.py in the application's non-sandboxed Jinja2 environment with application globals exposed. An authenticated user able to create steps, or an administrator

thehackerwire@mastodon.social at 2026-10-09T21:46:57.000Z ##

🔴 CVE-2026-108264 - Critical (9.1)

Wizarr is an advanced user invitation and management system for Jellyfin, Plex, Emby, and other media servers. Prior to 2026.9.1, wizard step Markdown supplied through the editor or imported bundles was evaluated by app/blueprints/wizard/routes.py...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108263
(9.9 CRITICAL)

EPSS: 0.43%

updated 2026-10-09T21:17:04.527000

1 posts

Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/code/code_node.py when CODE_EXEC_TYPE is not explicitly changed. LocalExecutor supplies complete Python builtins to dynamic code execution without the docu

thehackerwire@mastodon.social at 2026-10-09T21:46:48.000Z ##

🔴 CVE-2026-108263 - Critical (9.9)

Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108259
(8.2 HIGH)

EPSS: 0.25%

updated 2026-10-09T20:56:53

1 posts

### Summary `@tinacms/cli` inserts the raw Git branch value into the generated `client.ts` source without escaping or encoding. A Git-valid branch name can close the string literal and inject an arbitrary JavaScript expression that executes when the consumer build imports the generated client module. ### Affected component - **Source (branch read):** `packages/@tinacms/cli/src/cmds/init/templat

thehackerwire@mastodon.social at 2026-10-09T21:45:58.000Z ##

🟠 CVE-2026-108259 - High (8.2)

Tina is a headless content management system. Prior to 3.0.0, @tinacms/cli reads Git branch values from VERCEL_GIT_COMMIT_REF, GITHUB_BRANCH, or HEAD, incorporates the raw value into the API URL, and interpolates that URL into JavaScript string li...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108261
(9.3 CRITICAL)

EPSS: 0.16%

updated 2026-10-09T20:56:50

1 posts

### Summary The TinaCMS admin builds its preview `<iframe src>` from the `/~/*` hash-router splat without checking that the value stays same-origin. A fragment with a doubled slash (`#/~//attacker.example/p`) becomes the protocol-relative URL `//attacker.example/p`, so the admin frames an external site. That same unvalidated string derives `expectedOrigin`, the only trust anchor for the admin↔pre

thehackerwire@mastodon.social at 2026-10-09T21:46:15.000Z ##

🔴 CVE-2026-108261 - Critical (9.3)

Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router splat into an off-origin iframe URL thr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108260
(7.6 HIGH)

EPSS: 0.21%

updated 2026-10-09T20:56:46

1 posts

### Summary `<tina-markdown>` renders a rich-text AST into the DOM and, for `a` nodes, assigns the node's URL straight to the anchor's `href` with no scheme check. A link authored in the CMS as `javascript:…` renders as a live `javascript:` anchor, so a visitor who clicks it executes attacker-supplied script in the site's origin. Every sibling renderer in the repository already sanitizes these UR

thehackerwire@mastodon.social at 2026-10-09T21:46:07.000Z ##

🟠 CVE-2026-108260 - High (7.6)

Tina is a headless content management system. Prior to 0.2.1, the tina-markdown element in packages/@tinacms/web-components/src/tina-markdown.js assigns a rich-text node.url value directly to an anchor href without validating the URL scheme. A con...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107845
(9.3 CRITICAL)

EPSS: 0.27%

updated 2026-10-09T20:53:52

1 posts

An unauthenticated front end visitor can post a comment containing a XSS injection. The victim is any back end user who opens the Comments module, and moderation makes exposure certain rather than preventing it. No `Content-Security-Policy` header is sent on the Contao back end, so nothing mitigates the inline handler. ### Impact Anyone on the internet can inject script that executes in the Cont

thehackerwire@mastodon.social at 2026-10-09T20:31:16.000Z ##

🔴 CVE-2026-107845 - Critical (9.3)

Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundl...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107806(CVSS UNKNOWN)

EPSS: 0.33%

updated 2026-10-09T20:45:03

1 posts

## Summary An authenticated nginx-ui user can call `POST /api/restore`, upload a forged encrypted backup, restore `app.ini`, set nginx command settings such as `TestConfigCmd`, and then trigger command execution with `POST /api/nginx/test`. This was validated on nginx-ui `2.3.11 2(523) 6c86e5a5` in the local Docker container `uozi/nginx-ui:latest`. ## Impact An authenticated user can overwr

1 repos

https://github.com/murrez/CVE-2026-107806

DailyCyberSecurity@infosec.exchange at 2026-10-09T16:23:53.000Z ##

A critical Nginx UI RCE vulnerability (CVE-2026-107806) is publicly disclosed with PoC exploit code. Admins must patch now to prevent system takeover.

#NginxUI #RCE #Vulnerability #CVE2026107806 #CyberSecurity

securityonline.info/nginx-ui-r

##

CVE-2026-107840
(7.5 HIGH)

EPSS: 0.44%

updated 2026-10-09T20:17:09.900000

1 posts

yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the Prometheus metrics middleware in pkg/server/server.go uses the attacker-controlled r.Method value directly as the method label for yopass_http_requests_total and yopass_http_request_duration_seconds. Because the catch-all route accepts arbitrary HTTP method tokens, an unauthenticated remote attacke

thehackerwire@mastodon.social at 2026-10-09T18:45:43.000Z ##

🟠 CVE-2026-107840 - High (7.5)

yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the Prometheus metrics middleware in pkg/server/server.go uses the attacker-controlled r.Method value directly as the method label for yopass_http_req...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-104084
(8.8 HIGH)

EPSS: 0.25%

updated 2026-10-09T20:17:09.050000

1 posts

SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and refresh tokens embed a role claim at issuance that is not revalidated against the account's current role when redeemed through POST /api/v1/auth/refresh-token. Attackers who capture a refresh token issued before an administrator demotion, or a demoted user whose session was not actively polling at the

thehackerwire@mastodon.social at 2026-10-09T20:45:58.000Z ##

🟠 CVE-2026-104084 - High (8.8)

SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and refresh tokens embed a role claim at issuance that is not revalidated against the account's current role when redeemed through POST /api/v1/auth/refre...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103412
(8.8 HIGH)

EPSS: 0.52%

updated 2026-10-09T18:32:43

1 posts

Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Apache Camel Karavan. A project file name supplied through the project file API was used verbatim as a path segment when the project was written to the working copy for a Git commit, so a name containing `../` sequences caused the file content to be written outside the project directory, to any locat

DailyCyberSecurity@infosec.exchange at 2026-10-09T16:13:23.000Z ##

Discover how critical Apache Camel Karavan vulnerabilities (CVE-2026-103413 and CVE-2026-103412) allow code execution. Update to version 4.22.1 now.

#ApacheCamel #CyberSecurity #Vulnerability #CVE2026103413 #CVE2026103412

securityonline.info/apache-cam

##

CVE-2026-75350
(7.5 HIGH)

EPSS: 0.48%

updated 2026-10-09T18:31:52

1 posts

EIPStackGroup OpENer v2.3 / master commit 76b95cf contains a buffer overflow in the GetAttributeList() implementation for the EtherNet/IP Get_Attribute_List service. This allows a remote attacker to cause a denial of service

thehackerwire@mastodon.social at 2026-10-09T18:30:51.000Z ##

🟠 CVE-2026-75350 - High (7.5)

EIPStackGroup OpENer v2.3 / master commit 76b95cf contains a buffer overflow in the GetAttributeList() implementation for the EtherNet/IP Get_Attribute_List service. This allows a remote attacker to cause a denial of service

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108113
(8.8 HIGH)

EPSS: 0.64%

updated 2026-10-09T18:31:48

1 posts

ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import rights can import a crafted archive writing a .htaccess and PHP file to the web-served image directory, achieving remote code execution as the web server u

thehackerwire@mastodon.social at 2026-10-09T20:01:18.000Z ##

🟠 CVE-2026-108113 - High (8.8)

ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import ri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108160
(7.5 HIGH)

EPSS: 0.15%

updated 2026-10-09T18:31:48

1 posts

AstronRPA through 1.1.6 contains a download of code without integrity check vulnerability that allows network attackers to deliver malicious updates by abusing the desktop client's auto-update mechanism. Attackers positioned between the client and server can serve a malicious update manifest and NSIS installer, which electron-updater installs without signature verification, executing code as the d

thehackerwire@mastodon.social at 2026-10-09T17:30:45.000Z ##

🟠 CVE-2026-108160 - High (7.5)

AstronRPA through 1.1.6 contains a download of code without integrity check vulnerability that allows network attackers to deliver malicious updates by abusing the desktop client's auto-update mechanism. Attackers positioned between the client and...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108159
(7.5 HIGH)

EPSS: 0.33%

updated 2026-10-09T18:31:48

1 posts

AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the desktop client's smart-component chat that allows remote attackers to execute OS commands by abusing unsanitized LLM output rendered via v-html. Attackers can embed prompt-injection content in a web page so the model emits HTML event handlers invoking the unrestricted open-path IPC handler with shell metacharacters, execu

thehackerwire@mastodon.social at 2026-10-09T17:30:36.000Z ##

🟠 CVE-2026-108159 - High (7.5)

AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the desktop client's smart-component chat that allows remote attackers to execute OS commands by abusing unsanitized LLM output rendered via v-html. Attackers can embed promp...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75345
(7.5 HIGH)

EPSS: 0.45%

updated 2026-10-09T18:31:47

1 posts

OpENer v2.3.0 / commit 76b95cf contains an out-of-bounds read in the unconnected explicit messaging path. This allows a remote attacker to cause a denial of service.

thehackerwire@mastodon.social at 2026-10-09T19:30:48.000Z ##

🟠 CVE-2026-75345 - High (7.5)

OpENer v2.3.0 / commit 76b95cf contains an out-of-bounds read in the unconnected explicit messaging path. This allows a remote attacker to cause a denial of service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-90983
(8.2 HIGH)

EPSS: 0.26%

updated 2026-10-09T18:31:47

1 posts

Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc. (Hayat Hospital) Hayat Mobile allows Authentication Bypass. This issue affects Hayat Mobile: from 3.3.0 before 3.4.0.

thehackerwire@mastodon.social at 2026-10-09T18:46:45.000Z ##

🟠 CVE-2026-90983 - High (8.2)

Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc. (Hayat Hospital) Hayat Mobile allows Authentication Bypass.

This issue affects Hayat Mobile: from 3.3.0 before 3.4.0.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78795
(7.5 HIGH)

EPSS: 0.45%

updated 2026-10-09T18:31:42

1 posts

An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless router v1.3.241114.024540 and before allows a remote attacker to obtain sensitive information

thehackerwire@mastodon.social at 2026-10-09T20:46:08.000Z ##

🟠 CVE-2026-78795 - High (7.5)

An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless router v1.3.241114.024540 and before allows a remote attacker to obtain sensitive information

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75348
(7.5 HIGH)

EPSS: 0.51%

updated 2026-10-09T18:17:13.893000

1 posts

An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master up to commit 76b95cf in the EtherNet/IP TCP SendRRData Common Packet Format parser. The issue occurs in CreateCommonPacketFormatStructure() when it parses recognized optional socket address information items of type 0x8000 or 0x8001 without first validating that the remaining CPF buffer contains the complete fixed s

thehackerwire@mastodon.social at 2026-10-09T19:30:57.000Z ##

🟠 CVE-2026-75348 - High (7.5)

An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master up to commit 76b95cf in the EtherNet/IP TCP SendRRData Common Packet Format parser. The issue occurs in CreateCommonPacketFormatStructure() when it parses recognize...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108157
(8.1 HIGH)

EPSS: 0.53%

updated 2026-10-09T18:17:07.240000

1 posts

Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking in OAuthService.signUp(). Attackers can register a victim's unverified email on an enabled OAuth/OIDC provider, exploiting the missing email_verified check in GenericOidcProvider, to sign in as the vi

thehackerwire@mastodon.social at 2026-10-09T17:31:47.000Z ##

🟠 CVE-2026-108157 - High (8.1)

Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking in OAuthService.signUp(). Attackers can registe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107839
(7.5 HIGH)

EPSS: 0.34%

updated 2026-10-09T18:17:05.797000

1 posts

ageLANServer provides a cross-platform web server and launcher for offline multiplayer in several Age of Empires and Age of Mythology games. Prior to version 1.15.2, the AoE3 POST /game/cloud/getFileURL handler in the bundled game server has no request body size limit or cap on the attacker-controlled JSON names array and allocates response storage directly from the unbounded array length. A remot

thehackerwire@mastodon.social at 2026-10-09T18:45:33.000Z ##

🟠 CVE-2026-107839 - High (7.5)

ageLANServer provides a cross-platform web server and launcher for offline multiplayer in several Age of Empires and Age of Mythology games. Prior to version 1.15.2, the AoE3 POST /game/cloud/getFileURL handler in the bundled game server has no re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107818
(8.4 HIGH)

EPSS: 0.34%

updated 2026-10-09T18:17:03.373000

1 posts

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the mariadb.service unit used /run/mysqld/wsrep-new-cluster during the next service restart. A database user with FILE privilege and a secure-file-priv configuration permitting writes to /run/mysqld could create that file and inject attacker-controlled environment

thehackerwire@mastodon.social at 2026-10-09T18:46:27.000Z ##

🟠 CVE-2026-107818 - High (8.4)

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the mariadb.service unit used /run/mysqld/wsrep-new-cluster during the next service restart. A database user wi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107808
(8.1 HIGH)

EPSS: 0.41%

updated 2026-10-09T18:17:02.773000

1 posts

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is therefore issued a session after password verification, despite Enabled2FA reporting that the account has a second factor. An attacker who obtains the pa

thehackerwire@mastodon.social at 2026-10-09T20:16:06.000Z ##

🟠 CVE-2026-107808 - High (8.1)

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107807
(8.8 HIGH)

EPSS: 0.31%

updated 2026-10-09T18:17:02.610000

1 posts

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts the Node.Secret master credential through the node_secret query parameter in HTTP and WebSocket authentication paths instead of requiring the X-Node-Secret header. The credential can consequently appear in access logs, proxy logs, browser history, Referer headers, configuration URLs, and deployment

thehackerwire@mastodon.social at 2026-10-09T20:15:56.000Z ##

🟠 CVE-2026-107807 - High (8.8)

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts the Node.Secret master credential through the node_secret query parameter in HTTP and WebSocket authentication paths instead of requiring the X-Nod...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75347
(7.5 HIGH)

EPSS: 0.42%

updated 2026-10-09T17:41:47.060000

1 posts

EIPStackGroup OpENer v2.3 and master up to commit 76b95cf contain an expired pointer dereference vulnerability in the EtherNet/IP Common Packet Format (CPF) handling logic. This allows a remote attacker to cause a denial of service.

thehackerwire@mastodon.social at 2026-10-09T17:30:27.000Z ##

🟠 CVE-2026-75347 - High (7.5)

EIPStackGroup OpENer v2.3 and master up to commit 76b95cf contain an expired pointer dereference vulnerability in the EtherNet/IP Common Packet Format (CPF) handling logic. This allows a remote attacker to cause a denial of service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107815
(8.5 HIGH)

EPSS: 0.57%

updated 2026-10-09T17:41:29.727000

1 posts

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the CONNECT engine's DOS table type used an incorrect boundary check that permitted a one-byte null write beyond a stack buffer at an attacker-controlled offset. An authenticated user able to use the CONNECT engine could cause a crash and potentially remote code e

thehackerwire@mastodon.social at 2026-10-09T17:31:56.000Z ##

🟠 CVE-2026-107815 - High (8.5)

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the CONNECT engine's DOS table type used an incorrect boundary check that permitted a one-byte null write beyon...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107826
(7.5 HIGH)

EPSS: 0.46%

updated 2026-10-09T17:33:55

1 posts

### Summary The JSON body processor (`internal/bodyprocessors/json.go`) can be made to crash the whole process with an unrecoverable `fatal error: stack overflow`, using a request body that is well under the recommended `SecRequestBodyLimit` and the default `SecArgumentsLimit`. ### Root cause `readJSON` (json.go:113-143) runs a bounded, best-effort flattening walk (`readItems`) and *afterwards*

thehackerwire@mastodon.social at 2026-10-09T18:45:52.000Z ##

🟠 CVE-2026-107826 - High (7.5)

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after reaching SecArgumentsLimit or the byte budget and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107814
(8.4 HIGH)

EPSS: 0.28%

updated 2026-10-09T17:16:45.853000

1 posts

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB RPM packages created the dedicated mysql service account with the database data directory as its home directory. A database user with the FILE privilege could write startup dot-files such as .bash_profile into $HOME, and those files could execute when an a

thehackerwire@mastodon.social at 2026-10-09T20:01:10.000Z ##

🟠 CVE-2026-107814 - High (8.4)

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB RPM packages created the dedicated mysql service account with the database data directory as its home d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107812
(7.5 HIGH)

EPSS: 0.17%

updated 2026-10-09T17:08:21

1 posts

## Summary The self-upgrade downloads the release binary and its checksum (`*.tar.gz` and `*.tar.gz.digest`) through the SAME endpoint (`version.GetUrl()`, which is `github_proxy` or, by default, the project's `cloud.nginxui.com` mirror), and verifies the binary ONLY by comparing it to that digest: `digestFileContent == DigestSHA512(tarName)`. Both the binary and the digest come from the same orig

thehackerwire@mastodon.social at 2026-10-09T20:45:50.000Z ##

🟠 CVE-2026-107812 - High (7.5)

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the self-upgrade mechanism validates a downloaded binary only with a same-origin digest obtained from the same upgrade mirror. A compromised mirror or network attac...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107809
(8.8 HIGH)

EPSS: 0.18%

updated 2026-10-09T17:08:11

1 posts

## Summary Nginx-UI v2.4.3 stores the API JWT in a browser cookie named `token` and the `AuthRequired` middleware accepts that cookie as an authentication source. Because management endpoints are protected by `AuthRequired` and do not enforce a universal CSRF token or Origin/Referer check, a remote attacker can induce a logged-in administrator to submit cross-site state-changing requests. The atta

thehackerwire@mastodon.social at 2026-10-09T20:16:14.000Z ##

🟠 CVE-2026-107809 - High (8.8)

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, AuthRequired accepts a browser-managed token cookie as an API credential after the front end stores the JWT in that cookie. Because management endpoints do not univ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107813
(8.8 HIGH)

EPSS: 0.30%

updated 2026-10-09T17:08:07

1 posts

## Summary Incomplete fix of GHSA-5v7c-xpfp-p65m: the secure-session (OTP step-up) requirement added to the nginx, cert, dns, backup, site, and stream mutation routers was not applied to the parallel api/cluster router, so cluster node management and cluster-wide nginx reload/restart run with only a JWT and no step-up. An authenticated user whose JWT is stolen or persisted, but who does not hold

thehackerwire@mastodon.social at 2026-10-09T20:01:00.000Z ##

🟠 CVE-2026-107813 - High (8.8)

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster router exposes node and namespace mutation operations and cluster-wide Nginx reload or restart operations with AuthRequired but without RequireSecur...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107810
(8.1 HIGH)

EPSS: 0.36%

updated 2026-10-09T17:07:06

1 posts

### Summary An authenticated user who can create and restore a backup can craft a valid backup archive that causes the restore staging process to write attacker-controlled files into the live Nginx configuration path even when both `restore_nginx` and `restore_nginx_ui` are set to `false`. ### Details The restore flow always extracts the outer archive, verifies the manifest, decrypts `nginx-ui.zi

thehackerwire@mastodon.social at 2026-10-09T20:31:25.000Z ##

🟠 CVE-2026-107810 - High (8.1)

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, internal/backup/restore.go extracts inner archives before applying the restore_nginx and restore_nginx_ui flags and permits symlinks targeting the live Nginx config...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108106
(7.5 HIGH)

EPSS: 0.37%

updated 2026-10-09T17:06:17.770000

1 posts

Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to exhaust JVM memory by declaring a large uncompressed length in compressed input. Attackers can supply a few crafted bytes to Snappy.uncompress, uncompressString, SnappyInputStream or SnappyFramedInputStream to force allocations up to 2 GB, causing OutOfMemoryError and denial of service

thehackerwire@mastodon.social at 2026-10-09T22:17:09.000Z ##

🟠 CVE-2026-108106 - High (7.5)

Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to exhaust JVM memory by declaring a large uncompressed length in compressed input. Attackers can supply a few crafted bytes to Snappy.u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-75349
(7.5 HIGH)

EPSS: 0.45%

updated 2026-10-09T16:40:29.800000

1 posts

EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bounds read vulnerability in Connection Manager request parsing. This allows a remote attacker to cause a denial of service.

thehackerwire@mastodon.social at 2026-10-09T19:31:06.000Z ##

🟠 CVE-2026-75349 - High (7.5)

EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bounds read vulnerability in Connection Manager request parsing. This allows a remote attacker to cause a denial of service.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107805
(7.5 HIGH)

EPSS: 0.44%

updated 2026-10-09T16:38:57.820000

1 posts

Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it before validating the body digest and cryptographic signature. An unauthenticated remote client that can reach the API and provide syntactically valid signature metadata can consume tempo

thehackerwire@mastodon.social at 2026-10-09T22:46:26.000Z ##

🟠 CVE-2026-107805 - High (7.5)

Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it before validating the body digest ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107811
(8.8 HIGH)

EPSS: 0.36%

updated 2026-10-09T16:38:57.820000

1 posts

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenticated users can access /api/nodes and /api/nodes/:id, whose responses serialize the node token field. The same token is accepted as X-Node-Secret by AuthRequired and maps the request to initUser, allowing the user to impersonate a trusted node against a reachable cluster member. This cross-node auth

thehackerwire@mastodon.social at 2026-10-09T20:31:34.000Z ##

🟠 CVE-2026-107811 - High (8.8)

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenticated users can access /api/nodes and /api/nodes/:id, whose responses serialize the node token field. The same token is accepted as X-Node-Secret b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-55797
(8.8 HIGH)

EPSS: 1.55%

updated 2026-10-09T16:37:27

1 posts

### Impact Argo CD runs a shell command in the repo-server when it clones or fetches an SSH Git repository that has a proxy URL. The proxy host and port are copied into an SSH `ProxyCommand`. A host that contains shell metacharacters breaks out of that command and runs in the repo-server. All versions from v2.11.0 onward are affected, including every currently supported release. v2.10.20 and ear

thehackerwire@mastodon.social at 2026-10-09T17:31:38.000Z ##

🟠 CVE-2026-55797 - High (8.8)

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2, the Argo CD repo-server is vulnerable to command injection when it clones, tests, or fetches an SSH Git repository co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-103413
(8.8 HIGH)

EPSS: 0.39%

updated 2026-10-09T16:33:39.007000

1 posts

Improper input validation vulnerability in Apache Camel Karavan. When a deployment was started, Karavan unmarshalled a project's `kubernetes.yaml` and applied every resource it contained to the cluster without restricting the resource kinds, without rejecting security-sensitive pod options, and without pinning the target namespace. An authenticated user of any role could therefore have Karavan

DailyCyberSecurity@infosec.exchange at 2026-10-09T16:13:23.000Z ##

Discover how critical Apache Camel Karavan vulnerabilities (CVE-2026-103413 and CVE-2026-103412) allow code execution. Update to version 4.22.1 now.

#ApacheCamel #CyberSecurity #Vulnerability #CVE2026103413 #CVE2026103412

securityonline.info/apache-cam

##

CVE-2026-93947
(9.3 CRITICAL)

EPSS: 0.24%

updated 2026-10-09T16:17:32.090000

1 posts

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through 3.2.9.

offseq@infosec.exchange at 2026-10-09T10:30:25.000Z ##

CVE-2026-93947: CRITICAL SQL Injection in Shinetheme Traveler (0 – 3.2.9). Blind SQLi risk — attackers may access sensitive DB data. Patch when available & monitor your systems. radar.offseq.com/threat/cve-20 #OffSeq #CVE202693947 #SQLInjection #InfoSec

##

CVE-2026-79842
(9.1 CRITICAL)

EPSS: 0.33%

updated 2026-10-09T15:32:29

2 posts

An authentication bypass vulnerability exists in HPE Intelligent Management Center (iMC) prior to v7.3 E0713

DailyCyberSecurity@infosec.exchange at 2026-10-09T01:53:05.000Z ##

HPE fixes a critical HPE iLO 7 vulnerability, CVE-2026-79820, and iMC authentication bypass CVE-2026-79842. Update iLO to 1.25.01 now.

#HPE #iLO #iMC #CVE202679820 #CVE202679842 #AuthBypass #ServerSecurity #Vulnerability

securityonline.info/hpe-ilo-7-

##

thehackerwire@mastodon.social at 2026-10-08T21:31:21.000Z ##

🔴 CVE-2026-79842 - Critical (9.1)

An authentication bypass vulnerability exists in HPE Intelligent Management Center (iMC) prior to v7.3 E0713

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39460
(8.1 HIGH)

EPSS: 0.29%

updated 2026-10-09T15:31:42

1 posts

Usernames and passwords, including the default factory credentials, are stored in plaintext within the configuration file. With administrator rights, the configuration file can be viewed through the CLI or they can be exported from the device through a TFTP transfer from the web interface. A TFTP transfer can be initiated through SNMP which does not require authentication.

thehackerwire@mastodon.social at 2026-10-09T21:01:19.000Z ##

🟠 CVE-2026-39460 - High (8.1)

Usernames and passwords, including the default factory credentials, are stored in plaintext within the configuration file. With administrator rights, the configuration file can be viewed through the CLI or they can be exported from the device thro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108101
(7.5 HIGH)

EPSS: 0.39%

updated 2026-10-09T15:31:38

1 posts

HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under public/attachments/. Attackers can upload HTML or SVG files via /plants/attachments/add for stored cross-site scripting, or PHP files where .htaccess is unenforced to execute code.

thehackerwire@mastodon.social at 2026-10-09T22:46:17.000Z ##

🟠 CVE-2026-108101 - High (7.5)

HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under public/attachments/. Attackers can upload HTML or...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-100730
(9.8 CRITICAL)

EPSS: 0.62%

updated 2026-10-09T15:31:37

1 posts

A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which c

DailyCyberSecurity@infosec.exchange at 2026-10-09T16:05:45.000Z ##

Fix critical openPDC openHistorian vulnerabilities like CVE-2026-100730 and CVE-2026-105281. CISA urges patching these severe RCE flaws immediately.

#openPDC #openHistorian #CyberSecurity #Vulnerability #CISA

securityonline.info/openpdc-op

##

CVE-2026-15340
(9.8 CRITICAL)

EPSS: 0.60%

updated 2026-10-09T15:31:35

1 posts

lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.

thehackerwire@mastodon.social at 2026-10-09T22:01:22.000Z ##

🔴 CVE-2026-15340 - Critical (9.8)

lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39453
(8.3 HIGH)

EPSS: 0.29%

updated 2026-10-09T15:31:35

1 posts

Navigating to a certain URL on the switch’s web server causes the switch to reboot. This can be automated using a tool like curl to create DoS conditions where the switch constantly reboots.

thehackerwire@mastodon.social at 2026-10-09T21:01:10.000Z ##

🟠 CVE-2026-39453 - High (8.3)

Navigating to a certain URL on the switch’s web server causes the switch to reboot. This can be automated using a tool like curl to create DoS conditions where the switch constantly reboots.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108107
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-10-09T15:31:34

1 posts

PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to extract customer records and credentials via time-based blind SQL injection.

thehackerwire@mastodon.social at 2026-10-09T22:17:18.000Z ##

🔴 CVE-2026-108107 - Critical (9.8)

PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid par...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-108109
(9.1 CRITICAL)

EPSS: 0.39%

updated 2026-10-09T15:31:34

1 posts

PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account.

thehackerwire@mastodon.social at 2026-10-09T22:16:59.000Z ##

🔴 CVE-2026-108109 - Critical (9.1)

PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer us...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-83943
(8.7 HIGH)

EPSS: 0.38%

updated 2026-10-09T15:31:32

1 posts

Exposure of sensitive information to an unauthorized actor in Azure API Center allows an unauthorized attacker to disclose information over a network.

CVE-2016-3081
(8.1 HIGH)

EPSS: 96.05%

updated 2026-10-09T14:43:05.703000

2 posts

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.

thecybermind@infosec.exchange at 2026-10-10T12:49:06.000Z ##

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2016-3081 – Apache Struts Command Injection Vulnerability

A strategic C-Suite threat brief covering CVE-2016-3081 Apache Struts command injection vulnerability, featuring active mitigation, asset inventory management, and endpoint hardening....

thecybermind.co/2p4b

##

thecybermind@infosec.exchange at 2026-10-10T12:47:26.000Z ##

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2016-3081 – Apache Struts Command Injection Vulnerability

Unpack CVE-2016-3081 with our technical TSUITE brief. Get advanced detection rules, Splunk SPL, KQL, and forensic triage priorities for active CISA KEV threats....

thecybermind.co/bw95

##

CVE-2026-11318
(7.8 HIGH)

EPSS: 0.19%

updated 2026-10-09T14:17:20.393000

1 posts

Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service without authentication. Attackers can invoke the privileged installer method to run an attacker-supplied installer, achieving full root compromise of the

1 repos

https://github.com/Cr0wld3r/CVE-2026-11318

thehackerwire@mastodon.social at 2026-10-08T22:01:39.000Z ##

🟠 CVE-2026-11318 - High (7.8)

Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service w...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-17189
(8.2 HIGH)

EPSS: 0.15%

updated 2026-10-09T14:15:54.050000

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session

thehackerwire@mastodon.social at 2026-10-08T21:47:28.000Z ##

🟠 CVE-2026-17189 - High (8.2)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus alt...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19493
(7.5 HIGH)

EPSS: 0.36%

updated 2026-10-09T14:15:19.050000

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to perform an arbitrary file write due to path traversal.

thehackerwire@mastodon.social at 2026-10-08T21:46:09.000Z ##

🟠 CVE-2026-19493 - High (7.5)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to perform an arbitrary file write due to path traversal.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-86405
(9.8 CRITICAL)

EPSS: 0.20%

updated 2026-10-09T13:21:13.267000

1 posts

Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. PrestaShop Virtual POS Module allows Signature Spoofing by Improper Validation. This issue affects PrestaShop Virtual POS Module: from 26.8.1 before 26.9.1.

offseq@infosec.exchange at 2026-10-09T13:30:29.000Z ##

CVE-2026-86405 (CRITICAL, CVSS 9.8) in Sipay PrestaShop Virtual POS Module (26.8.1 – 26.9.1): Improper cryptographic signature checks allow spoofing & data tampering. Patch not confirmed — monitor vendor. radar.offseq.com/threat/cve-20 #OffSeq #CVE #vuln #cybersecurity

##

CVE-2026-94503
(10.0 CRITICAL)

EPSS: 0.28%

updated 2026-10-09T12:31:48

1 posts

Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify zombify allows Upload a Web Shell to a Web Server.This issue affects Zombify: from n/a through 1.7.7.

1 repos

https://github.com/Wayang1337/CVE-2026-94503

offseq@infosec.exchange at 2026-10-09T12:00:32.000Z ##

PX-lab Zombify ≤1.7.7 is affected by CVE-2026-94503 (CRITICAL, CVSS 10): unrestricted upload of dangerous files enables remote code execution. No patch yet — restrict uploads & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #CVE202694503 #WebSecurity #Infosec

##

CVE-2026-96207
(10.0 CRITICAL)

EPSS: 0.48%

updated 2026-10-09T00:31:56

2 posts

Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

ssvc@infosec.exchange at 2026-10-09T14:45:52.000Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

#microsoft #CVE

##

offseq@infosec.exchange at 2026-10-09T00:00:41.000Z ##

CVE-2026-96207 (CRITICAL, CVSS 10) affects Microsoft Partner Center: improper certificate validation (CWE-295) allows remote privilege escalation. Patch available — apply ASAP. No public exploits seen. radar.offseq.com/threat/cve-20 #OffSeq #Microsoft #CVE202696207 #Infosec

##

CVE-2026-94510
(9.9 CRITICAL)

EPSS: 0.40%

updated 2026-10-09T00:31:56

2 posts

Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.

ssvc@infosec.exchange at 2026-10-09T14:45:52.000Z ##

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

#microsoft #CVE

##

offseq@infosec.exchange at 2026-10-09T01:30:26.000Z ##

CVE-2026-94510 (CRITICAL, CVSS 9.9) in Microsoft Bookings enables remote privilege escalation via authorization bypass (CWE-639). Apply the official Microsoft patch now: radar.offseq.com/threat/cve-20 #OffSeq #Microsoft #Vuln #CVE #Infosec

##

CVE-2026-83947
(7.7 HIGH)

EPSS: 0.37%

updated 2026-10-09T00:31:56

1 posts

Missing authorization in Azure Event Grid allows an authorized attacker to perform spoofing over a network.

CVE-2026-84058
(8.1 HIGH)

EPSS: 0.36%

updated 2026-10-09T00:31:56

1 posts

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Microsoft SQL Server) PRELOGIN packet decoder. A remote attacker who can send a specially crafted TDS PRELOGIN packet to a network monitored by an IBM Guardium Collector may cause a denial of service or potentially execute arbitrary code on the Collector appliance.

thehackerwire@mastodon.social at 2026-10-08T22:32:22.000Z ##

🟠 CVE-2026-84058 - High (8.1)

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Microsoft SQL Server) PRELOGIN packet decoder. A remote attacker who can send a specially crafted TDS PRELOGIN packet to a network monitored by an IBM...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84057
(8.1 HIGH)

EPSS: 0.36%

updated 2026-10-09T00:31:56

1 posts

IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

thehackerwire@mastodon.social at 2026-10-08T22:32:13.000Z ##

🟠 CVE-2026-84057 - High (8.1)

IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-84249
(9.8 CRITICAL)

EPSS: 0.41%

updated 2026-10-09T00:31:56

1 posts

IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to execute arbitrary management operations due to missing authentication for critical function.

thehackerwire@mastodon.social at 2026-10-08T22:30:58.000Z ##

🔴 CVE-2026-84249 - Critical (9.8)

IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to execute arbitrary management operations due to missing authentication for critical function.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-89091
(8.8 HIGH)

EPSS: 0.48%

updated 2026-10-09T00:31:56

1 posts

A flaw was found in ansible-core. When installing a collection with `ansible-galaxy collection install`, the archive extractor validates member paths using lexical path normalisation (os.path.abspath) instead of resolving symbolic links (os.path.realpath), and it performs no containment check on symlink-typed directory members before creating them. A crafted collection tarball can chain symlink di

thehackerwire@mastodon.social at 2026-10-08T22:30:49.000Z ##

🟠 CVE-2026-89091 - High (8.8)

A flaw was found in ansible-core. When installing a collection with
`ansible-galaxy collection install`, the archive extractor validates member
paths using lexical path normalisation (os.path.abspath) instead of resolving
symbolic links (os.path.r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107782
(7.8 HIGH)

EPSS: 0.11%

updated 2026-10-08T21:34:48.800000

1 posts

System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. Attackers can load code into a Microsoft-signed host like rundll32.exe, connect to SiSvcApiPort, and call PhSvcApiCreateService to execute code as SYSTEM.

thehackerwire@mastodon.social at 2026-10-08T22:01:27.000Z ##

🟠 CVE-2026-107782 - High (7.8)

System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. Attackers can load code into a Micr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19482
(8.8 HIGH)

EPSS: 0.42%

updated 2026-10-08T21:33:42

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of command arguments.

thehackerwire@mastodon.social at 2026-10-08T22:00:59.000Z ##

🟠 CVE-2026-19482 - High (8.8)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of command arguments.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16823
(9.1 CRITICAL)

EPSS: 0.33%

updated 2026-10-08T21:33:42

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass security restrictions due to improper authentication.

thehackerwire@mastodon.social at 2026-10-08T21:47:11.000Z ##

🔴 CVE-2026-16823 - Critical (9.1)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass security restrictions due to improper authentication.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-19491
(9.1 CRITICAL)

EPSS: 0.33%

updated 2026-10-08T21:33:42

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass authentication due to improper authentication.

thehackerwire@mastodon.social at 2026-10-08T21:46:00.000Z ##

🔴 CVE-2026-19491 - Critical (9.1)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass authentication due to improper authentication.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78406
(9.8 CRITICAL)

EPSS: 0.50%

updated 2026-10-08T21:33:42

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

thehackerwire@mastodon.social at 2026-10-08T21:31:12.000Z ##

🔴 CVE-2026-78406 - Critical (9.8)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-78401
(9.8 CRITICAL)

EPSS: 0.57%

updated 2026-10-08T21:33:42

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

thehackerwire@mastodon.social at 2026-10-08T21:31:03.000Z ##

🔴 CVE-2026-78401 - Critical (9.8)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-18740
(8.8 HIGH)

EPSS: 0.35%

updated 2026-10-08T21:33:41

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to perform unauthorized actions due to argument injection.

thehackerwire@mastodon.social at 2026-10-08T22:00:48.000Z ##

🟠 CVE-2026-18740 - High (8.8)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to perform unauthorized actions due to argument injection.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-16916
(9.1 CRITICAL)

EPSS: 0.42%

updated 2026-10-08T21:33:41

1 posts

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary code due to a protection mechanism failure.

thehackerwire@mastodon.social at 2026-10-08T21:47:19.000Z ##

🔴 CVE-2026-16916 - Critical (9.1)

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary code due to a protection mechanism failure.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107779
(9.8 CRITICAL)

EPSS: 0.54%

updated 2026-10-08T21:27:15.010000

1 posts

Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers can POST GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL jobs with attacker-supplied glueSource to /jobinfo/addAndStart, executing commands on the executor ho

thehackerwire@mastodon.social at 2026-10-08T22:01:47.000Z ##

🔴 CVE-2026-107779 - Critical (9.8)

Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20362
(7.2 HIGH)

EPSS: 0.47%

updated 2026-10-08T20:08:45.857000

1 posts

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successfu

sans_isc@infosec.exchange at 2026-10-09T07:55:30.000Z ##

SANS Stormcast Friday, October 9th, 2026: AI Agent Forensics; AI-Assisted Attack on South Korean Banks; IDN Typosquatting; Cisco Finesse SSRF (CVE-2026-20362)
isc.sans.edu/podcastdetail/101

##

CVE-2026-103663(CVSS UNKNOWN)

EPSS: 0.71%

updated 2026-10-08T15:33:06

2 posts

Ollama is vulnerable to path traversal in the `/api/pull` endpoint due to insufficient validation of layer digests by the `digestToPath` function. An unauthenticated remote attacker can specify a path traversal sequence as a layer digest, causing a malicious binary to be written outside the model store.  Critically if the server process has write access to `/usr/lib/ollama` (the default in most O

secpoint@mastodon.social at 2026-10-11T10:10:04.000Z ##

🚨 Critical Ollama Vulnerability: CVE-2026-103663

A critical security vulnerability has been disclosed in Ollama, the popular platform for running AI models locally and on private infrastructure.

The vulnerability allows unauthenticated attackers to exploit a path traversal weakness in the model-pull functionality, potentially writing malicious files outside the intended model directory.

#SecPoint #Ollama #AISecurity #CyberSecurity #VulnerabilityManagement

##

secpoint@mastodon.social at 2026-10-11T10:10:04.000Z ##

🚨 Critical Ollama Vulnerability: CVE-2026-103663

A critical security vulnerability has been disclosed in Ollama, the popular platform for running AI models locally and on private infrastructure.

The vulnerability allows unauthenticated attackers to exploit a path traversal weakness in the model-pull functionality, potentially writing malicious files outside the intended model directory.

#SecPoint #Ollama #AISecurity #CyberSecurity #VulnerabilityManagement

##

CVE-2025-64393
(0 None)

EPSS: 0.36%

updated 2026-10-08T04:16:55.397000

2 posts

This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server.

security_crawler_carl@infosec.exchange at 2026-10-09T09:22:31.000Z ##

🏆 New Achievement! The Keys to the Vault Were Under the Mat!

Magnificent. Truly, someone looked at a backup server — the one room that holds the skeleton keys to your entire infrastructure — and said, let's let low-privileged users knock it over. CVE-2025-64393 is a critical remote code execution flaw in Veeam Backup & Replication version 12, and it hands full control of the backup server to anyone with the Backup Viewer role. (1/3)

##

beyondmachines1@infosec.exchange at 2026-10-09T09:01:49.000Z ##

Veeam Patches Critical Remote Code Execution Flaw in Backup & Replication Software

Veeam patched four vulnerabilities in Backup & Replication version 12, including a critical RCE flaw (CVE-2025-64393) that allows low-privileged users to take control of the backup server.

**If you use Veeam Backup & Replication version 12, update ASAP to 12.3.2 P4 (build 12.3.2.4934). Review and remove the Backup Viewer role from anyone who doesn't really need it, and keep your backup servers isolated from the rest of the network.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-102255
(10.0 CRITICAL)

EPSS: 0.48%

updated 2026-10-07T18:33:12

3 posts

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.

oversecurity@mastodon.social at 2026-10-09T13:51:04.000Z ##

Max severity SonicWall SMA1000 flaw now exploited in attacks

Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days...

🔗️ [Bleepingcomputer] link.is.it/pvDc7j

##

jbhall56@infosec.exchange at 2026-10-09T13:41:19.000Z ##

Tracked as CVE-2026-102255, the flaw affects the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v models, but does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls. bleepingcomputer.com/news/secu

##

DailyCyberSecurity@infosec.exchange at 2026-10-09T10:55:44.000Z ##

Attackers target a critical SonicWall SMA1000 vulnerability in the wild. Apply vendor hotfixes to secure remote access gateways against CVE-2026-102255.

#SonicWall #CVE2026102255 #CyberSecurity #InfoSec #SSRF

securityonline.info/sonicwall-

##

CVE-2026-107181
(8.1 HIGH)

EPSS: 0.34%

updated 2026-10-07T17:16:53.520000

4 posts

Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.

1 repos

https://github.com/SeanDishman/telegram-cve-2026-107181

raul@mastodon.in4matics.cat at 2026-10-10T07:33:37.000Z ##

⚠️ Un clic en un enllaç extern podia acabar amb el segrest de Telegram Desktop: una fallada IPC permetia llegir i exfiltrar fitxers locals. CVE-2026-107181; corregida a 7.2.9. Actualitza. #Telegram #Ciberseguretat beaksec.github.io/posts/telegr

##

guru@thecybersecguru.com at 2026-10-10T06:08:29.000Z ##

Critical Telegram Desktop Vulnerability (CVE-2026-107181): A Technical Analysis of One-Click Account Takeover via IPC Injection

Telegram Desktop CVE-2026-107181 enables one-click account takeover through IPC injection and local session file theft. Learn how it works and how to protect your account

thecybersecguru.com/exploits/t

##

DarkWebInformer@infosec.exchange at 2026-10-09T21:10:20.000Z ##

🚨 PoC released for Telegram Desktop account takeover vulnerability; CVE-2026-107181

beaksec.github.io/posts/telegr

A vulnerability in Telegram Desktop allows attackers to steal local files, including session keys, by tricking users into opening a specially crafted tg:// link.

Stolen session data could allow attackers to hijack Telegram accounts without knowing the victim's password.

CVSS: 8.1 (High, v3.1) / 8.6 (High, v4.0)
Affected: Telegram Desktop before 7.2.9
Fixed: Version 7.2.9

The published PoC demonstrates how a malicious link can trigger file exfiltration through Telegram's IPC handler.

##

DailyCyberSecurity@infosec.exchange at 2026-10-09T02:09:46.000Z ##

A critical Telegram Desktop account takeover vulnerability (CVE-2026-107181) exposes users to session hijacking. Exploit details and PoC are now public.

#Telegram #Cybersecurity #CVE2026107181 #AccountTakeover #PoC

securityonline.info/telegram-d

##

CVE-2026-21589
(0 None)

EPSS: 1.77%

updated 2026-10-07T13:17:22.273000

3 posts

This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledg

12 repos

https://github.com/BimBoxH4/CVE-2026-21589

https://github.com/rxsklife/CVE-2026-21589

https://github.com/aduli198/CVE-2026-21589

https://github.com/watchtowrlabs/watchTowr-vs-Atlassian-CVE-2026-21589

https://github.com/tc4dy/CVE-2026-21589-PoC-Exploit

https://github.com/murrez/CVE-2026-21589

https://github.com/MarcusProgram/CVE-2026-21589

https://github.com/renzi25031469/CVE-2026-21589

https://github.com/gotr00t0day/CVE-2026-21589

https://github.com/webserverdude/f5_CVE-2026-21589_mitigation

https://github.com/ynsmroztas/AtlasSniper

https://github.com/0xBlackash/CVE-2026-21589

tierrasapiens@mastodon.social at 2026-10-11T11:05:12.000Z ##

🖲️ #Noticia de #CiberSeguridad #CiberGuerra #CiberAtaque #CiberNoticia
⚫ Exploit para falla crítica de Atlassian que permite acceso admin a Jira
🔗 blog.segu-info.com.ar/2026/10/

Se ha publicado un exploit de prueba de concepto para la vulnerabilidad
CVE-2026-21589, un fallo crítico de lectura arbitraria de archivos que afecta a varios
productos autogestionados de Atlassian. Esta vulnerabilidad puede exponer
archivos sensibles y, en

##

DailyCyberSecurity@infosec.exchange at 2026-10-09T12:56:36.000Z ##

Hackers rapidly exploit the Atlassian vulnerability CVE-2026-21589. Learn how this critical flaw compromises Jira, Confluence, and Bitbucket security.

#Atlassian #CVE202621589 #CyberSecurity #Jira #TechNews

meterpreter.org/atlassian-cve-

##

patrickcmiller@infosec.exchange at 2026-10-09T03:12:00.000Z ##

You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) labs.watchtowr.com/you-wont-he

##

CVE-2026-105192
(9.8 CRITICAL)

EPSS: 0.48%

updated 2026-10-07T12:31:58

1 posts

LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls pickle.loads, while the server is still decoding request arguments and before the handler runs. A single unauthenticated ZMQ DEALER mes

1 repos

https://github.com/rxsklife/CVE-2026-105192

DailyCyberSecurity@infosec.exchange at 2026-10-09T11:54:44.000Z ##

Explore the critical LMCache vulnerability CVE-2026-105192. Learn how insecure ZeroMQ configurations and Python pickle deserialization lead to RCE attacks.

#LMCache #CVE2026105192 #CyberSecurity #TechNews #ZeroMQ

meterpreter.org/critical-lmcac

##

CVE-2026-59346
(9.3 CRITICAL)

EPSS: 0.26%

updated 2026-10-07T06:33:08

1 posts

VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)

1 repos

https://github.com/0xCyberstan/CVE-2026-59346-POC

threatcodex@infosec.exchange at 2026-10-09T17:21:50.000Z ##

CVE-2026-59346: Critical VMware Workstation and Fusion Flaw Enables Guest-to-Host Code Execution
#CVE_2026_59346
socprime.com/blog/cve-2026-593

##

CVE-2026-105141
(6.3 MEDIUM)

EPSS: 0.34%

updated 2026-10-06T15:04:52.637000

2 posts

A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler. The manipulation of the argument FASTAPI_USERS_JWT_SECRET results in hard-coded credentials. The attack may be launched remotely. Upgrading to version 1.6.0

nyanbinary at 2026-10-11T16:39:33.495Z ##

@wdormann ikr? Seems like VulDB has a template of sorts (its not exact, see e.g. the different phrasing in cve.org/CVERecord?id=CVE-2026- ) that expects a function name which.. just doesn't make sense most of the time? And the followup part of the template

The manipulation of the argument $argname results in $cwe-friendly-name.

just never makes sense for hardcoded credentials? I have said it before, I should become a CNA of my own, doesn't seem to be THAT hard...

##

nyanbinary@infosec.exchange at 2026-10-11T16:39:33.000Z ##

@wdormann ikr? Seems like VulDB has a template of sorts (its not exact, see e.g. the different phrasing in cve.org/CVERecord?id=CVE-2026- ) that expects a function name which.. just doesn't make sense most of the time? And the followup part of the template

The manipulation of the argument $argname results in $cwe-friendly-name.

just never makes sense for hardcoded credentials? I have said it before, I should become a CNA of my own, doesn't seem to be THAT hard...

##

CVE-2026-79820
(9.0 None)

EPSS: 0.27%

updated 2026-10-05T18:34:22

1 posts

A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.

CVE-2026-105133
(7.3 HIGH)

EPSS: 0.38%

updated 2026-10-04T09:30:21

5 posts

A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 10.3.4 is able to mitigate thi

security_crawler_carl@infosec.exchange at 2026-10-10T20:00:23.000Z ##

🏆 New Achievement! Stand in the Fire, Lose the Server!

EVERYONE STOP WHAT YOU ARE DOING. No — too late, they already got in. Huntress is calling it out in raid chat: threat actors are actively chaining CVE-2026-105133 and CVE-2026-105134 in AhsayCBS backup software to bypass authentication, inject OS commands, and land unauthenticated remote code execution with SYSTEM privileges. Webshells deployed. The party wiped.

The latest version, 10.3.4, is still affected. There is no patch. (1/2)

##

threatnoir@infosec.exchange at 2026-10-10T09:06:30.000Z ##

⚠️ CRITICAL: Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

Attackers are actively exploiting two unpatched remote code execution flaws in AhsayCBS backup software versions up to 10.3.4. CVE-2026-105133 and CVE-2026-105134 allow authentication bypass and OS command injection, leading to webshell deployment, cryptominer installation, and Windows service pers…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

cyberworldops@infosec.exchange at 2026-10-09T18:40:07.000Z ##

Huntress reports active exploitation of AhsayCBS CVE-2026-105133 and CVE-2026-105134 chained for auth bypass and OS command execution. Attackers deploy web shells and XMRig miners, gaining persistence on backup servers. Patch and hunt for indicators. #AhsayCBS #ThreatIntel #InfoSec

cyberworldops.eu/en/huntress-a

##

ssvc@infosec.exchange at 2026-10-09T14:55:27.000Z ##

Huntress is reporting AhsayCBS CVE-2026-105133 and CVE-2026-105134 exploitation to drop web shells and XMRig cryptominer:

Huntress is seeing these two vulnerabilities being chained together in order to gain access to targeted systems.

huntress.com/blog/ahsaycbs-fla

#threatintel #ahsayCBS #CVE #eitw #IOC

##

beyondmachines1@infosec.exchange at 2026-10-09T11:01:49.000Z ##

Threat Actors Chain AhsayCBS Vulnerabilities to Deploy Webshells and Cryptominers

Threat actors are chaining two vulnerabilities in AhsayCBS (CVE-2026-105133 and CVE-2026-105134) to bypass authentication and gain remote code execution on backup servers.

**If you run AhsayCBS (any version up to and including 10.3.4), be aware it's actively exploited with no patch available. Immediately make sure that the management console is off the internet and allow access only from trusted IPs or over VPN. Then check for signs of compromise, such as unusual processes started by cbssvcX64.exe. If you find any, fully re-image the server from a clean backup.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-105134
(10.0 CRITICAL)

EPSS: 1.84%

updated 2026-10-04T09:30:21

5 posts

A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve

1 repos

https://github.com/RayanAlmulhim/CVE-2026-105134-lab

security_crawler_carl@infosec.exchange at 2026-10-10T20:00:23.000Z ##

🏆 New Achievement! Stand in the Fire, Lose the Server!

EVERYONE STOP WHAT YOU ARE DOING. No — too late, they already got in. Huntress is calling it out in raid chat: threat actors are actively chaining CVE-2026-105133 and CVE-2026-105134 in AhsayCBS backup software to bypass authentication, inject OS commands, and land unauthenticated remote code execution with SYSTEM privileges. Webshells deployed. The party wiped.

The latest version, 10.3.4, is still affected. There is no patch. (1/2)

##

threatnoir@infosec.exchange at 2026-10-10T09:06:30.000Z ##

⚠️ CRITICAL: Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

Attackers are actively exploiting two unpatched remote code execution flaws in AhsayCBS backup software versions up to 10.3.4. CVE-2026-105133 and CVE-2026-105134 allow authentication bypass and OS command injection, leading to webshell deployment, cryptominer installation, and Windows service pers…

threatnoir.com/focus

#infosec #cybersecurity

🤖 AI generated summary

##

cyberworldops@infosec.exchange at 2026-10-09T18:40:07.000Z ##

Huntress reports active exploitation of AhsayCBS CVE-2026-105133 and CVE-2026-105134 chained for auth bypass and OS command execution. Attackers deploy web shells and XMRig miners, gaining persistence on backup servers. Patch and hunt for indicators. #AhsayCBS #ThreatIntel #InfoSec

cyberworldops.eu/en/huntress-a

##

ssvc@infosec.exchange at 2026-10-09T14:55:27.000Z ##

Huntress is reporting AhsayCBS CVE-2026-105133 and CVE-2026-105134 exploitation to drop web shells and XMRig cryptominer:

Huntress is seeing these two vulnerabilities being chained together in order to gain access to targeted systems.

huntress.com/blog/ahsaycbs-fla

#threatintel #ahsayCBS #CVE #eitw #IOC

##

beyondmachines1@infosec.exchange at 2026-10-09T11:01:49.000Z ##

Threat Actors Chain AhsayCBS Vulnerabilities to Deploy Webshells and Cryptominers

Threat actors are chaining two vulnerabilities in AhsayCBS (CVE-2026-105133 and CVE-2026-105134) to bypass authentication and gain remote code execution on backup servers.

**If you run AhsayCBS (any version up to and including 10.3.4), be aware it's actively exploited with no patch available. Immediately make sure that the management console is off the internet and allow access only from trusted IPs or over VPN. Then check for signs of compromise, such as unusual processes started by cbssvcX64.exe. If you find any, fully re-image the server from a clean backup.**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

CVE-2026-88772
(8.1 HIGH)

EPSS: 1.30%

updated 2026-09-28T12:32:09

1 posts

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

8 repos

https://github.com/FollowerSeize/CVE-2026-88772-POC

https://github.com/orjanj/netscaler_threat_hunt_helper

https://github.com/technion/netscaler_scanner

https://github.com/murrez/CVE-2026-88772

https://github.com/emilstahl/pitscaler

https://github.com/securekomodo/citrixInspector

https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker

https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772

linuxmint_hun@mastodon.social at 2026-10-10T17:32:06.000Z ##

Riasztás: kritikus, aktívan kihasznált CVE-2026-88771 és CVE-2026-88772 sebezhetőségek érintik a NetScaler ADC/Gateway eszközöket. Telepítetted már az ajánlott javításokat, és gondoltál rá, hogy korábbi kompromittálódás miatt vizsgálatot indíts? A cikkben megtalálod a frissített kiadásokat és a javasolt teendőket.

linuxmint.hu/hir/2026/10/riasz

#NetScaler #NetScalerADC #NetScalerGateway #CVE2026-88771 #CVE2026-88772 #Citrix #kiberbiztonság #patch #frissítés #CISA #VPN

##

linuxmint_hun@mastodon.social at 2026-10-10T17:32:06.000Z ##

Riasztás: kritikus, aktívan kihasznált CVE-2026-88771 és CVE-2026-88772 sebezhetőségek érintik a NetScaler ADC/Gateway eszközöket. Telepítetted már az ajánlott javításokat, és gondoltál rá, hogy korábbi kompromittálódás miatt vizsgálatot indíts? A cikkben megtalálod a frissített kiadásokat és a javasolt teendőket.

linuxmint.hu/hir/2026/10/riasz

#NetScaler #NetScalerADC #NetScalerGateway #CVE2026-88771 #CVE2026-88772 #Citrix #kiberbiztonság #patch #frissítés #CISA #VPN

##

bontchev@infosec.exchange at 2026-10-09T05:37:07.000Z ##

@GossiTheDog Meanwhile I've updated my Citrix honeypot to handle CVE-2026-88771 - but so far have seen absolutely no attacks. I'll run some tests later today to check if it doesn't miss them due to some kind of bug.

Visualization (empty so far):

pandora.nlcv.bas.bg/grafana/d/

##

CVE-2026-25264
(8.8 HIGH)

EPSS: 0.07%

updated 2026-09-25T13:37:47.870000

1 posts

Privilege escalation due to weak configuration during package extraction process.

hugovalters@mastodon.social at 2026-10-11T10:30:02.000Z ##

CVE-2026-25264 Qualcomm DLL hijacking, privilege escalation via weak package extraction config. CVSS 8.8. No patch yet. Audit your systems now. valtersit.com/cve/CVE-2026-252 #CVE #infosec #Qualcomm

##

CVE-2026-25254
(9.8 CRITICAL)

EPSS: 0.32%

updated 2026-09-25T13:37:41.860000

1 posts

Improper authorization leads to Remote Code Execution via SocketIO interface.

hugovalters@mastodon.social at 2026-10-11T12:00:24.000Z ##

CVE-2026-25254 Qualcomm improper auth leads to RCE via SocketIO. CVSS 9.8, patch status unknown. Treat as unpatched and restrict exposure now. valtersit.com/cve/CVE-2026-252 #CVE #infosec #Qualcomm

##

CVE-2026-62866
(6.2 MEDIUM)

EPSS: 0.19%

updated 2026-09-24T21:25:27.050000

1 posts

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.2, selector/lexer/tokenize.go parseCurRune advances the input index across trailing whitespace and then reads the source at the exhausted index without an end-of-input check. A selector ending in whitespace, including input passed through lexer.NewTokenizer(...).Tokenize() or d

hugovalters@mastodon.social at 2026-10-11T15:10:04.000Z ##

CVE-2026-62866 Dasel 3.0.0-3.11.2 (CVSS 6.2): a selector ending in whitespace passes an unchecked index in parseCurRune, causing an out-of-range panic that kills the process. Denial of service. Patched in 3.11.2, update now. valtersit.com/cve/CVE-2026-628 #CVE #infosec #Dasel

##

CVE-2026-82077(CVSS UNKNOWN)

EPSS: 0.74%

updated 2026-09-24T09:32:00

2 posts

An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings.

CVE-2026-93952
(10.0 CRITICAL)

EPSS: 1.06%

updated 2026-09-23T14:32:12.417000

1 posts

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been

hugovalters@mastodon.social at 2026-10-11T13:40:02.000Z ##

CVE-2026-93952 Arista VeloCloud Orchestrator on-prem: remote attacker can reach privileged internal functionality, full CIA impact. CVSS 10. Patch under review; hosted already fixed. Patch now: valtersit.com/cve/CVE-2026-939 #CVE #infosec #Arista

##

CVE-2026-85219
(3.7 LOW)

EPSS: 0.41%

updated 2026-09-22T19:41:38.447000

1 posts

Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause unconstrained memory usage.

hugovalters@mastodon.social at 2026-10-10T06:20:19.000Z ##

CVE-2026-85219: DoS in Thinkst Canary OpenCanary 0.9.9 Redis module. Unauthenticated remote attacker can exhaust memory. CVSS 3.7. Patch under review, watch for updates. valtersit.com/cve/CVE-2026-852 #CVE #infosec #cybersecurity

##

CVE-2026-19658
(9.8 CRITICAL)

EPSS: 0.53%

updated 2026-09-22T06:30:35

1 posts

The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1 via deserialization of untrusted input . This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is i

1 repos

https://github.com/murrez/CVE-2026-19658

hugovalters@mastodon.social at 2026-10-11T08:50:02.000Z ##

CVE-2026-19658: PHP Object Injection in GiveWP Give Tributes plugin, all versions up to 2.3.1. CVSS 9.8, unauthenticated. No patch yet - remove the plugin or update immediately.
valtersit.com/cve/CVE-2026-196
#CVE #WordPress #infosec

##

CVE-2026-13355
(9.8 CRITICAL)

EPSS: 0.44%

updated 2026-09-22T06:30:35

1 posts

The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-frontend-submission component unconditionally overrides the form's target object_id from the GET parameter 'rwmb_frontend_field_object_id' without any authorization check, and Form::p

1 repos

https://github.com/murrez/CVE-2026-13355

hugovalters@mastodon.social at 2026-10-11T07:20:16.000Z ##

CVE-2026-13355 Meta Box AIO for WordPress privilege escalation to admin, CVSS 9.8, unpatched. No fix available yet - restrict plugin access now. valtersit.com/cve/CVE-2026-133 #CVE #WordPress #infosec

##

CVE-2026-93485
(7.1 HIGH)

EPSS: 0.38%

updated 2026-09-18T06:32:17

1 posts

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.1

4 repos

https://github.com/HORKimhab/CVE-2026-93485

https://github.com/DeathShotXD/Comment2Shell

https://github.com/686f6c61/POC-WP-CORE-CVE-2026-93485

https://github.com/0xBlackash/CVE-2026-93485

sekurakbot@mastodon.com.pl at 2026-10-09T07:35:00.000Z ##

Ataki na strony WordPress chwilę po wydaniu poprawki

17 września 2026 r. WordPress wydał wersję 7.1.1, w której załatano dwie podatności – kojarzone jako Click2Shell i Comment2Shell (CVE-2026-93485). To jednak dopiero początek historii. Kilka dni później – 22 września – wydano wersję 7.1.2 łatającą kolejną podatność. Atakujący nie czekali jednak na publikację jej szczegółów – wszystko wskazuje na...

#WBiegu #Podatność #Rce #Wordpress

sekurak.pl/ataki-na-strony-wor

##

CVE-2026-82078
(9.1 CRITICAL)

EPSS: 63.53%

updated 2026-09-14T00:16:56.777000

2 posts

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on

2 repos

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

https://github.com/virologi-info/papercut-toolkit

CVE-2026-0310(CVSS UNKNOWN)

EPSS: 0.37%

updated 2026-09-10T06:31:55

1 posts

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimiz

AAKL@infosec.exchange at 2026-10-09T16:15:10.000Z ##

Palo Alto has a a long list of advisories, addressing at least two critical vulnerabilities, among others: security.paloaltonetworks.com/

CRITICAL: CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing security.paloaltonetworks.com/

CRITICAL: PAN-SA-2026-0012 Chromium: Monthly Vulnerability Update (September 2026) security.paloaltonetworks.com/

- Tenable Research Advisories:

HIGH: Hermes Agent - PKCE Session Takeover via Redirect-URI Parser Confusion tenable.com/security/research/

There are also two WordPress vulnerabilities and a few others here tenable.com/security/research #WorPress

- Microsoft:

In case you missed this, Microsoft posted quite a few patches yesterday msrc.microsoft.com/update-guide #infosec #vulnerability #Microsofot #Azure #Linux

##

CVE-2026-80093
(7.0 None)

EPSS: 0.32%

updated 2026-09-09T00:31:34

1 posts

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

DailyCyberSecurity@infosec.exchange at 2026-10-09T13:15:49.000Z ##

Discover the details of the Windows Cloud Files Driver vulnerability, CVE-2026-80093. Learn how this flaw in cldflt.sys affects kernel privileges.

#WindowsSecurity #CVE202680093 #CyberSecurity #Microsoft #TechNews

meterpreter.org/windows-cloud-

##

CVE-2025-30156
(8.9 HIGH)

EPSS: 0.09%

updated 2026-09-08T21:11:56.250000

2 posts

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol encrypts tickets with AES-128-CBC in an unauthenticated mode that uses a hard-coded initialization vector and no message authentication, allowing an attacker to forge credentials and gain cluster-wide access. Because the ciphertext

mmeier@social.mei-home.net at 2026-10-11T18:01:47.000Z ##

The issue now is: Ceph 20 is still on an older NFS Ganesha version which hasn't got the fix yet. Ceph 21 does have the fix, but it also has the fix for this CVE: medium.com/rook-io/rook-adviso

And this CVE fix, in turn, only works with kernels > 7.0. Which means I'm currently in a bit of a deadlock. I can't really update my hosts to the newer Ubuntu, because of the Ganesha bug. But I also can't update Ceph/Ganesha because I need a newer kernel.

#HomeLab

##

mmeier@social.mei-home.net at 2026-10-11T18:01:47.000Z ##

The issue now is: Ceph 20 is still on an older NFS Ganesha version which hasn't got the fix yet. Ceph 21 does have the fix, but it also has the fix for this CVE: medium.com/rook-io/rook-adviso

And this CVE fix, in turn, only works with kernels > 7.0. Which means I'm currently in a bit of a deadlock. I can't really update my hosts to the newer Ubuntu, because of the Ganesha bug. But I also can't update Ceph/Ganesha because I need a newer kernel.

#HomeLab

##

CVE-2026-6726
(7.9 HIGH)

EPSS: 0.19%

updated 2026-09-08T14:09:00.860000

1 posts

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.

chaekyung@ieji.de at 2026-10-11T10:43:09.000Z ##

🚨🚨🚨 Did AMD and/or Gigabyte intentionally or unintentionally just make local "AI" models available to a lot more people?

I have an old AM4 Gigabyte GA-AX370-Gaming 5 motherboard with a 6 core 5600G processor in it. Gigabyte released a new BIOS for that motherboard on September 3rd 2026. Changelog story is that version F54d is a "Fix AMD TPM Reference Code Errata (CVE-2026-6726, CVE-2026-6727)"

gigabyte.com/Motherboard/GA-AX

I updated the motherboard to the shiny new F54d BIOS and it re-set the BIOS settings. This is annoying but not unusual when upgrading a BIOS. Thus, I had to poke around in the BIOS in order to restore my previous preferences and that's when I noticed something new that's not indicated in the changelog:

The area of the BIOS where you can choose how much RAM should be assigned to the integrated graphics part of the CPU (if you have one with integrated graphics) goes all the way up to 16 GB in BIOS F54d. The max used to be 2 GB, I've never seen any BIOS where you could assign more than 2 GB to the iGPU/APU.

I tried assigning 8GB to the 5600G in the BIOS and then I tried running the Q3_K_M version of the Kreamagine Krea 2 Turbo checkpoint on it. Krea 2 is a image generation model, so horsepower matters more than it does if you run some LLM. I didn't expect it to run very fast, but I was curious if it would run at all since that was previously not possible when the max assigned GPU RAM was limited to 2 GB.

Kreamagine Q3_K_M did run and I got a awfully slow 29.35 seconds per iteration. For context, the RX 6600 runs that model at around 4.93s/it. Half a minute times 10 iterations (what you ideally want for Krea 2 Turbo models) works out to 5 minutes compared to 50 seconds using the RX 6600. That's quite the execution time just to get an image resembling "1girl, confused, using computer running ai app, glasses, blond hair, tight shirt". You're not going to get lightning fast execution if you assign more RAM to GPU integrated in a CPU, but the more important detail is that it actually works.

WHY I THINK THIS IS SO COOL: If you have a now nearly 10 year old computer with an AMD CPU with integrated graphics and 16 or 32 GB DDR4 bought back when it was less than half of today's price then you're now able to assign 8 or 16 GB RAM to the graphics part of the CPU and use that to do a whole range of useful things like as offloading an image models text encoder if you have some older graphics card like a RX 6600 with only 8 GB VRAM.

It's not like I bought anything new or expected to get this new feature. I just updated the BIOS and unexpectedly got the ability to assign up to 16 GB VRAM to the integrated graphics chip. If you have some old AM4 board with a G series CPU and you play around with local models then you should see if there is a new BIOS for your board that may or may not give you the ability to bump the iGPUs memory from 2 to 16 GB.

#ai #localai #amd #apu

##

CVE-2026-6727
(5.9 MEDIUM)

EPSS: 0.15%

updated 2026-09-08T14:09:00.860000

1 posts

A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. U

4 repos

https://github.com/HORKimhab/CVE-2026-67276

https://github.com/shmaki4/CVE-2026-67279-Mikrotik-6.42-POC

https://github.com/tc4dy/CVE-2026-67279-86060-Toolkit

https://github.com/HackSpeak/CVE-2026-67279

chaekyung@ieji.de at 2026-10-11T10:43:09.000Z ##

🚨🚨🚨 Did AMD and/or Gigabyte intentionally or unintentionally just make local "AI" models available to a lot more people?

I have an old AM4 Gigabyte GA-AX370-Gaming 5 motherboard with a 6 core 5600G processor in it. Gigabyte released a new BIOS for that motherboard on September 3rd 2026. Changelog story is that version F54d is a "Fix AMD TPM Reference Code Errata (CVE-2026-6726, CVE-2026-6727)"

gigabyte.com/Motherboard/GA-AX

I updated the motherboard to the shiny new F54d BIOS and it re-set the BIOS settings. This is annoying but not unusual when upgrading a BIOS. Thus, I had to poke around in the BIOS in order to restore my previous preferences and that's when I noticed something new that's not indicated in the changelog:

The area of the BIOS where you can choose how much RAM should be assigned to the integrated graphics part of the CPU (if you have one with integrated graphics) goes all the way up to 16 GB in BIOS F54d. The max used to be 2 GB, I've never seen any BIOS where you could assign more than 2 GB to the iGPU/APU.

I tried assigning 8GB to the 5600G in the BIOS and then I tried running the Q3_K_M version of the Kreamagine Krea 2 Turbo checkpoint on it. Krea 2 is a image generation model, so horsepower matters more than it does if you run some LLM. I didn't expect it to run very fast, but I was curious if it would run at all since that was previously not possible when the max assigned GPU RAM was limited to 2 GB.

Kreamagine Q3_K_M did run and I got a awfully slow 29.35 seconds per iteration. For context, the RX 6600 runs that model at around 4.93s/it. Half a minute times 10 iterations (what you ideally want for Krea 2 Turbo models) works out to 5 minutes compared to 50 seconds using the RX 6600. That's quite the execution time just to get an image resembling "1girl, confused, using computer running ai app, glasses, blond hair, tight shirt". You're not going to get lightning fast execution if you assign more RAM to GPU integrated in a CPU, but the more important detail is that it actually works.

WHY I THINK THIS IS SO COOL: If you have a now nearly 10 year old computer with an AMD CPU with integrated graphics and 16 or 32 GB DDR4 bought back when it was less than half of today's price then you're now able to assign 8 or 16 GB RAM to the graphics part of the CPU and use that to do a whole range of useful things like as offloading an image models text encoder if you have some older graphics card like a RX 6600 with only 8 GB VRAM.

It's not like I bought anything new or expected to get this new feature. I just updated the BIOS and unexpectedly got the ability to assign up to 16 GB VRAM to the integrated graphics chip. If you have some old AM4 board with a G series CPU and you play around with local models then you should see if there is a new BIOS for your board that may or may not give you the ability to bump the iGPUs memory from 2 to 16 GB.

#ai #localai #amd #apu

##

CVE-2026-31431
(7.8 HIGH)

EPSS: 3.44%

updated 2026-09-08T09:36:36

1 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just

Nuclei template

100 repos

https://github.com/gagaltotal/cve-2026-31431-copy-fail

https://github.com/Qengineering/RK35xx-CopyFail-Hotfix

https://github.com/haydenjames/CVE-2026-31431-check

https://github.com/mrunalp/block-copyfail

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script

https://github.com/ben-slates/CVE-2026-31431-Exploit

https://github.com/Sl4cK0TH/CVE-2026-31431-PoC

https://github.com/ErdemOzgen/copy-fail-cve-2026-31431

https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit

https://github.com/pedromizz/copy-fail

https://github.com/MrAriaNet/cPanel-Fix

https://github.com/MartinPham/copy-fail-CVE-2026-31431-php

https://github.com/jbnetwork-git/copy-fail-check

https://github.com/diemoeve/copyfail-rs

https://github.com/rvzsec/CVE-2026-31431

https://github.com/Boos4721/copyfail-rs

https://github.com/Xerxes-2/CVE-2026-31431-rs

https://github.com/bootsareme/copyfail-deconstructed

https://github.com/bigwario/copy-fail-CVE-2026-31431-C

https://github.com/XsanFlip/CVE-2026-31431-Patch

https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail

https://github.com/sgkdev/page_inject

https://github.com/cs8425/copy-fail-go

https://github.com/TheMalwareGuardian/CVE-2026-31431

https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE

https://github.com/SeanRickerd/cve-2026-31431

https://github.com/xeloxa/copyfail-exploit

https://github.com/desultory/CVE-2026-31431

https://github.com/rootsecdev/cve_2026_31431

https://github.com/st4rburn/public-passwd

https://github.com/wgnet/wg.copyfail.patch

https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell

https://github.com/aestechno/cve-2026-31431-ansible

https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail

https://github.com/b5null/CVE-2026-31431-C

https://github.com/ZephrFish/CopyFail-CVE-2026-31431

https://github.com/atgreen/block-copyfail

https://github.com/tgies/copy-fail-c

https://github.com/sammwyy/copyfail-rs

https://github.com/cozystack/copy-fail-blocker

https://github.com/philfry/cve-2026-31431-ftrace

https://github.com/yuspring/cve-2026-31431-poc

https://github.com/ExploitEoom/CVE-2026-31431

https://github.com/samanzamani/copy-fail-checker

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC

https://github.com/sudoytang/copyfail-arm64

https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431

https://github.com/Iamliuxiaozhen/copy_fail

https://github.com/Huchangzhi/autorootlinux

https://github.com/cyber-joker/copy-fail-python

https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized

https://github.com/guiimoraes/CVE-2026-31431

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/Smarttfoxx/copyfail

https://github.com/abdullaabdullazade/CVE-2026-31431

https://github.com/malwarekid/CVE-2026-31431

https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit

https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation

https://github.com/st4rburn/RootRemover

https://github.com/TrevoCastles/CVE-2026-31431-copy-fail

https://github.com/badsectorlabs/copyfail-go

https://github.com/JuanBindez/CVE-2026-31431

https://github.com/kadir/copy-fail-CVE-2026-31431-IOC

https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/lonelyor/CVE-2026-31431-exp

https://github.com/Alfredooe/CVE-2026-31431

https://github.com/erlangparasu/mitigate_cve_2026_31431-sh

https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431

https://github.com/luotian2/CVE-2026-31431

https://github.com/pascal-gujer/CVE-2026-31431

https://github.com/ZeroDayEvil/CVE-2026-31431

https://github.com/AliHzSec/CVE-2026-31431

https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431

https://github.com/novysodope/copy-fail-CVE-2026-31431-C

https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH

https://github.com/nisec-eric/cve-2026-31431

https://github.com/kinryulabs/rootpacket-cve-2026-31431

https://github.com/0xBlackash/CVE-2026-31431

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/Juguitos/copy-fail

https://github.com/Dabbleam/CVE-2026-31431-mitigation

https://github.com/pyroceper/copy-fail-CVE-2026-31431

https://github.com/sgkdev/ptrace_may_dream

https://github.com/theori-io/copy-fail-CVE-2026-31431

https://github.com/AdityaBhatt3010/CVE-2026-31431

https://github.com/povzayd/CVE-2026-31431

https://github.com/qi4L/CVE-2026-31431-Container-Escape

https://github.com/wesmar/CVE-2026-31431

https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431

https://github.com/wuwu001/CVE-2026-31431-exploit

https://github.com/sec17br/CVE-2026-31431-Copy-Fail

https://github.com/0xShe/CVE-2026-31431

https://github.com/JnamerZ/CopyFail-CVE-2026-31431

https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite

https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

https://github.com/4xura/CVE-2026-31431-Copy-Fail

https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape

https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit

kubesploit@learnk8s.news at 2026-10-09T18:46:02.000Z ##

This article examines why Copy Fail (CVE-2026-31431) breaks container assumptions and provides a small, safe Python check to determine whether your nodes can reach the vulnerable kernel path

➤ ku.bz/CTv-Yf60c

##

CVE-2026-81578
(9.8 CRITICAL)

EPSS: 85.58%

updated 2026-08-31T21:31:56

2 posts

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

2 repos

https://github.com/yora1928/PaperCut-CVE-2026-81578-82078

https://github.com/virologi-info/papercut-toolkit

CVE-2026-48710
(6.5 MEDIUM)

EPSS: 7.06%

updated 2026-08-28T18:31:00

1 posts

### Summary In affected versions, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions

5 repos

https://github.com/Bhanunamikaze/BadHost-CVE-2026-48710-Exploit

https://github.com/sb-ox/repro-OXDEV-77637-uv-workspace

https://github.com/CuteeCat/CVE-2026-48710

https://github.com/xtremebeing/starlette-host-header-lab

https://github.com/eris-ths/supply-chain-guard

x41sec@infosec.exchange at 2026-10-09T14:05:54.000Z ##

We have published our writeup about the discovery and details of the #BadHost vulnerability (CVE-2026-48710) at x41-dsec.de/lab/research/2026/

##

CVE-2026-73570
(8.9 HIGH)

EPSS: 71.66%

updated 2026-08-24T13:19:17.577000

1 posts

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands a

10 repos

https://github.com/dahnutz/zimbra-cve-2026-73570-ir

https://github.com/hainhc/CVE-2026-73570

https://github.com/alsyundawy/eradicate-zimbra-malware

https://github.com/0xBlackash/CVE-2026-73570

https://github.com/juanpoch/CVE-2026-73570

https://github.com/HORKimhab/CVE-2026-73570

https://github.com/BiuTrap/CVE-2026-73570

https://github.com/jishino567/CVE-2026-73570

https://github.com/gabrielunknown/CVE-2026-73570

https://github.com/INFOKOM-KI/Zimbra-CVE-2026-73570-Rules

hasamba@infosec.exchange at 2026-10-09T17:49:51.000Z ##

----------------

🎯 Threat Intelligence
===================

Microsoft Threat Intelligence tracks CVE-2026-73570: unauthenticated command injection on internet-facing Zimbra mail servers

Microsoft Threat Intelligence published an analysis of CVE-2026-73570, described as an unauthenticated command injection vulnerability exploited in Zimbra on internet-facing mail servers. The post documents observed attack paths, detection opportunities, and mitigation guidance. The digest available here is thin, so this write-up keeps what the source states separate from general class context and flags everything the digest does not state.

🔹 Executive Summary
• CVE-2026-73570 is an unauthenticated command injection vulnerability in Zimbra.
• Exploitation observed in the wild, per Microsoft Threat Intelligence.
• Exposure model: internet-facing mail servers, no authentication required.
• The same post carries detection opportunities and mitigation guidance.

🔹 Technical Details

What the source states:
• Vulnerability class: command injection
• Authentication: none (pre-auth)
• Exposure: internet-facing mail servers
• Affected product: Zimbra
• Publisher and date: Microsoft Threat Intelligence, September 30, roughly a 20-minute read

Not stated in the digest: affected versions, CVSS score, CWE mapping, specific IOCs, named actor, ATT&CK mappings. Treat all of that as unconfirmed until the full post is read.

🔹 Analysis

Class context, not a source claim: pre-auth command injection on an internet-facing mail server is close to the worst property combination a CVE can carry. No credential barrier, no user interaction, and the target sits on the public edge. Mail hosts also concentrate mailbox contents, credentials in authentication flows, and internal trust relationships, which makes a pre-auth path on the edge a practical pivot for follow-on activity. Zimbra has a history as a target of mass exploitation campaigns on earlier CVEs; that is general background relevant to prioritization, not a claim from the current post.

🔹 Attack Chain Analysis

Only the entry step is confirmed by the digest:

1. Initial Access: unauthenticated exploitation of CVE-2026-73570 against an internet-facing Zimbra instance.
2. Post-exploitation: the original post describes observed attack paths, but the digest does not enumerate stages beyond initial access. Do not assume a specific chain from this summary.

🔹 Detection

The source says the post includes detection opportunities, but the digest does not contain the actual queries. Reasonable starting hypotheses for a command injection scenario on a mail host: unexpected process spawns from mail service modules, unusual outbound connections originating from the mail server itself, and anomalous request patterns in web access logs aimed at service and admin endpoints. Treat these as hypotheses to validate against the full post, not verified signatures.

🔹 Mitigation
• The post publishes specific mitigation guidance, so apply it from the source directly.
• Interim hygiene: confirm patch status on every internet-facing Zimbra instance, trim unnecessary internet exposure, and test the detection hypotheses above against existing logs.

🔹 Source Note

The feed item also carried the headline "3 lessons from frontier AI vulnerability research" with no body content, so it is not covered here.

🔹 References
• Microsoft Threat Intelligence post: "Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570", September 30
• CVE-2026-73570

🔹 CVE202673570 #Zimbra #ThreatIntelligence #CommandInjection #MailServers

🔗 Source: microsoft.com/en-us/security/b

##

kaito834@infosec.exchange at 2026-10-08T23:15:40.000Z ##

直近で相次いでいる国内組織における不正アクセスに関する注意喚起 jpcert.or.jp/m/at/2026/at26003 2026-10-08
JPCERT/CCに寄せられた情報などでは:
ケースA:...既知の脆弱性を探索し攻撃試行するもの
ケースB:API経由での不正な操作
ケースC:MetabaseのSQLインジェクションの脆弱性(CVE-2026-72898)

ケースBの場合:
(a)一般公開しているスマートフォンアプリを解析しAPIのエンドポイントやキーを特定する
(b)本来画面操作では実行できない内部APIに対する攻撃
(c)他のシステムの侵害で窃取したAPIキーを使用する

##

CVE-2026-47483
(8.2 HIGH)

EPSS: 0.34%

updated 2026-07-28T18:33:11

1 posts

NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. A successful exploit of this vulnerability might lead to denial of service and information disclosure.

_r_netsec@infosec.exchange at 2026-10-08T22:03:21.000Z ##

How We Found Thousands of Exposed NVIDIA GPUs and a Way to Disrupt Them (CVE-2026-47483) lava.security/research/cve-202

##

CVE-2025-47818
(2.2 LOW)

EPSS: 0.24%

updated 2026-06-17T09:28:43.993000

1 posts

Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection.

olearysec@infosec.exchange at 2026-10-09T14:11:02.000Z ##

@briankrebs Every Flock CVE in existence (CVE-2025-47818 through -47824) came through MITRE off Jon Gaines' 2025 research, before Flock had any say in the numbering. The "outside parties requesting CVE IDs before a fix is ready" line reads like a reference to that.

As for who decides what's a bug, they've answered in writing. The new VDP gives Flock 120 days to publish, with an exception for anything it deems a "material safety risk to law enforcement or the public." Their advisories page lists nothing, two weeks after a pentest write-up with 2 criticals and 7 highs that Flock says needed no customer action, which is exactly the kind of finding a vendor CNA can decline to number. So yes, Flock decides now. The criteria just live on a legal page instead of a press release.

##

CVE-2025-31200
(9.8 CRITICAL)

EPSS: 20.90%

updated 2026-06-17T09:10:00.550000

1 posts

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specif

4 repos

https://github.com/hunters-sec/CVE-2025-31200

https://github.com/JGoyd/iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201

https://github.com/zhuowei/apple-positional-audio-codec-invalid-header

https://github.com/serundengsapi/CVE-2025-31200-iOS-AudioConverter-RCE

cyberworldops@infosec.exchange at 2026-10-09T17:20:57.000Z ##

iVerify reports a P7 DarkSword iOS variant combining crypto-wallet theft with remote command execution. It chains CVE-2025-24201 and CVE-2025-31200, both CISA KEV-listed, enabling persistent device control. Patching and wallet-device isolation are critical. #IosSecurity #CryptoTheft #DarkSword

cyberworldops.eu/en/p7-darkswo

##

CVE-2025-24201
(10.0 CRITICAL)

EPSS: 3.85%

updated 2026-06-17T08:58:17.950000

1 posts

An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 18.3.2, iPadOS 17.7.6, macOS Sequoia 15.3.2, visionOS 2.3.2, watchOS 11.4. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary f

3 repos

https://github.com/JGoyd/Glass-Cage-iOS18-CVE-2025-24085-CVE-2025-24201

https://github.com/The-Maxu/CVE-2025-24201-WebKit-Vulnerability-Detector-PoC-

https://github.com/5ky9uy/glass-cage-i18-2025-24085-and-cve-2025-24201

cyberworldops@infosec.exchange at 2026-10-09T17:20:57.000Z ##

iVerify reports a P7 DarkSword iOS variant combining crypto-wallet theft with remote command execution. It chains CVE-2025-24201 and CVE-2025-31200, both CISA KEV-listed, enabling persistent device control. Patching and wallet-device isolation are critical. #IosSecurity #CryptoTheft #DarkSword

cyberworldops.eu/en/p7-darkswo

##

CVE-2026-0257
(9.1 CRITICAL)

EPSS: 96.89%

updated 2026-06-09T12:32:02

2 posts

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

8 repos

https://github.com/tushargurav28/CVE-2026-0257

https://github.com/akashsingh0454/CVE-2026-0257-PoC

https://github.com/sfewer-r7/CVE-2026-0257

https://github.com/grayxploit/CVE-2026-0257

https://github.com/Mr-Robot-LP/CVE-2026-0257

https://github.com/HORKimhab/CVE-2026-0257

https://github.com/0xBlackash/CVE-2026-0257

https://github.com/Ez4rd1x1/CVE-2026-0257

thecybersecguru@mastox.eu at 2026-10-11T07:17:09.000Z ##

🚨 Ransomware gangs are exploiting a flaw in Palo Alto Networks GlobalProtect VPN to bypass authentication and gain unauthorized network access.

⚠️ CVE-2026-0257
🔴 Qilin & Settra named in reports
🛡️ Patch, audit VPN logs, hunt for suspicious access.

Your VPN could be the way in.

Full breakdown 👇
thecybersecguru.com/news/cve-2

#CyberSecurity #Ransomware #InfoSec

##

guru@thecybersecguru.com at 2026-10-11T07:14:01.000Z ##

Ransomware Actors Weaponize Palo Alto GlobalProtect Authentication Bypass for Stealthy VPN Access

Palo Alto GlobalProtect CVE-2026-0257 is being exploited by Qilin and Settra ransomware actors. Check affected PAN-OS versions, IOCs, and fixes

thecybersecguru.com/news/cve-2

##

CVE-2024-3094
(10.0 CRITICAL)

EPSS: 85.97%

updated 2024-03-29T18:30:50

1 posts

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. The tarballs included extra .m4 files, which contained instructions for building with automake that did not exist in the repository. These instructions, through a series of complex obfuscations, extract a prebuilt object file from one of the test archives, which is then used to modify specific functions in t

90 repos

https://github.com/stevehenderson/lab_xz_backdoor

https://github.com/HackerHermanos/CVE-2024-3094_xz_check

https://github.com/zpxlz/CVE-2024-3094

https://github.com/amlweems/xzbot

https://github.com/hariskhalil555000-sketch/What-utility-does-CVE-2024-3094-refer-to-

https://github.com/ThomRgn/xzutils_backdoor_obfuscation

https://github.com/been22426/CVE-2024-3094

https://github.com/ScrimForever/CVE-2024-3094

https://github.com/robertdfrench/ifuncd-up

https://github.com/harekrishnarai/xz-utils-vuln-checker

https://github.com/Horizon-Software-Development/CVE-2024-3094

https://github.com/0xBlackash/CVE-2024-3094

https://github.com/Titus-soc/-CVE-2024-3094-Vulnerability-Checker-Fixer-Public

https://github.com/x-cmd-build/xz

https://github.com/vesjolyjd/Kaspersky_CVE-2024-3094

https://github.com/brinhosa/CVE-2024-3094-One-Liner

https://github.com/ykhurshudyan-blip/CVE-2024-3094

https://github.com/neuralinhibitor/xzwhy

https://github.com/mightysai1997/CVE-2024-3094-info

https://github.com/namegabevictoire01-sys/cs50-cybersecurity-final-project

https://github.com/weltregie/liblzma-scan

https://github.com/0xlane/xz-cve-2024-3094

https://github.com/bioless/xz_cve-2024-3094_detection

https://github.com/mightysai1997/CVE-2024-3094

https://github.com/encikayelwhitehat-glitch/CVE-2024-3094

https://github.com/Michel-DV/xz-utils-backdoor-case-study

https://github.com/michalAshurov/writeup-CVE-2024-3094

https://github.com/emirkmo/xz-backdoor-github

https://github.com/fevar54/Detectar-Backdoor-en-liblzma-de-XZ-utils-CVE-2024-3094-

https://github.com/OpensourceICTSolutions/xz_utils-CVE-2024-3094

https://github.com/lypd0/CVE-2024-3094-Vulnerabity-Checker

https://github.com/BOSE122/CVE-2024-3094

https://github.com/ElinaNotElina/cve-2024-3094-analysis

https://github.com/h3raklez/CVE-2024-3094

https://github.com/TheTorjanCaptain/CVE-2024-3094-Checker

https://github.com/AndreaCicca/Sicurezza-Informatica-Presentazione

https://github.com/pentestfunctions/CVE-2024-3094

https://github.com/badsectorlabs/ludus_xz_backdoor

https://github.com/hackingetico21/revisaxzutils

https://github.com/devjanger/CVE-2024-3094-XZ-Backdoor-Detector

https://github.com/Preacher98/Report-XZ-Utils-CVE-2024-3094

https://github.com/bsekercioglu/cve2024-3094-Checker

https://github.com/Ikram124/CVE-2024-3094-analysis

https://github.com/jfrog/cve-2024-3094-tools

https://github.com/przemoc/xz-backdoor-links

https://github.com/gensecaihq/CVE-2024-3094-Vulnerability-Checker-Fixer

https://github.com/laxmikumari615/Linux---Security---Detect-and-Mitigate-CVE-2024-3094

https://github.com/mhicairo-hue/cs50-cybersecurity-final-project

https://github.com/mesutgungor/xz-backdoor-vulnerability

https://github.com/FabioBaroni/CVE-2024-3094-checker

https://github.com/hackura/xz-cve-2024-3094

https://github.com/24Owais/threat-intel-cve-2024-3094

https://github.com/hazemkya/CVE-2024-3094-checker

https://github.com/teyhouse/CVE-2024-3094

https://github.com/mrk336/CVE-2024-3094

https://github.com/MrBUGLF/XZ-Utils_CVE-2024-3094

https://github.com/lockness-Ko/xz-vulnerable-honeypot

https://github.com/wgetnz/CVE-2024-3094-check

https://github.com/byinarie/CVE-2024-3094-info

https://github.com/ashwani95/CVE-2024-3094

https://github.com/Yuma-Tsushima07/CVE-2024-3094

https://github.com/Simplifi-ED/CVE-2024-3094-patcher

https://github.com/buluma/ansible-role-cve_2024_3094

https://github.com/iheb2b/CVE-2024-3094-Checker

https://github.com/ackemed/detectar_cve-2024-3094

https://github.com/Juul/xz-backdoor-scan

https://github.com/Fractal-Tess/CVE-2024-3094

https://github.com/valeriot30/cve-2024-3094

https://github.com/extracoding-dozen/CVE-2024-3094

https://github.com/spidygal/CVE-2024-3094-Nmap-NSE-script

https://github.com/MagpieRYL/CVE-2024-3094-backdoor-env-container

https://github.com/M1lo25/CS50FinalProject

https://github.com/Security-Phoenix-demo/CVE-2024-3094-fix-exploits

https://github.com/robertdebock/ansible-playbook-cve-2024-3094

https://github.com/vnchk1/sec_review_cve-2024-3094

https://github.com/felipecosta09/cve-2024-3094

https://github.com/gustavorobertux/CVE-2024-3094

https://github.com/Dermot-lab/TryHack

https://github.com/dah4k/CVE-2024-3094

https://github.com/robertdebock/ansible-role-cve_2024_3094

https://github.com/shefirot/CVE-2024-3094

https://github.com/Bella-Bc/xz-backdoor-CVE-2024-3094-Check

https://github.com/Ava-Vispilio/CVE-2024-3094

https://github.com/isuruwa/CVE-2024-3094

https://github.com/r0binak/xzk8s

https://github.com/Mustafa1986/CVE-2024-3094

https://github.com/nnatsopoulos/xz-backdoor-research

https://github.com/KaminaDuck/ansible-CVE-2024-3094

https://github.com/galacticquest/cve-2024-3094-detect

https://github.com/jbnetwork-git/CVE-2024-3094-XZ-Utils-Check

technotenshi@infosec.exchange at 2026-10-10T01:41:36.000Z ##

An analysis by a Redditor, published on sheets.works, counted regular contributors on 23 core open source projects and found 11 had only one or two in the past year. xz, which shipped a backdoor in 2024 (CVE-2024-3094), again has one: Lasse Collin wrote 97 percent of its 2025 changes, and the analysis found no new funding. Eight projects, including SQLite, zlib and bash, show no grant from four named funders.

linuxstans.com/11-of-23-core-o

#OpenSource #InfoSec #SupplyChain #Linux

##

linuxmint_hun@mastodon.social at 2026-10-10T06:08:29.000Z ##

Figyelem: egy magas súlyosságú WordPress Core hiba (CVE-2026-87902) LFI-ből RCE-vé alakulhat — érint sok ágat és régi témát. Van aktív page- előtagú témád és régi PHP-d? Ellenőrizd a naplókat, és frissíts minél előbb.

linuxmint.hu/hir/2026/10/riasz

#WordPress #CVE2026-87902 #RCE #LFI #NKI #CISA #websecurity #PHP #themes #kiberbiztonság

##

CVE-2026-108269
(0 None)

EPSS: 0.13%

1 posts

N/A

offseq@infosec.exchange at 2026-10-10T01:30:27.000Z ##

CVE-2026-108269 (CRITICAL, CVSS 9.1): Privasys ra-tls-clients <0.5.0 origin validation error lets attackers relay attestation quotes, compromising TLS trust. Upgrade to 0.5.0+ now. radar.offseq.com/threat/cve-20 #OffSeq #CVE2026108269 #Rust #Go #TLS

##

CVE-2026-92705
(0 None)

EPSS: 0.13%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-09T21:32:26.000Z ##

🟠 CVE-2026-92705 - High (7.8)

Aegisub is a cross-platform advanced subtitle editor. From 3.2.0 to 3.4.2, Aegisub automatically loads Automation scripts referenced by `Automation Scripts` metadata in `ASS` subtitle projects without asking whether the user trusts the scripts or ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107821
(0 None)

EPSS: 0.48%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-09T18:46:36.000Z ##

🟠 CVE-2026-107821 - High (8)

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB insufficiently validated counts, offsets, lengths, and field boundaries in FRM metadata while opening b...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107838
(0 None)

EPSS: 0.34%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-09T18:31:09.000Z ##

🟠 CVE-2026-107838 - High (7.5)

RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. From version 2023.07 through version 2026.07, nanocoap_fileserver callers in sys/net/application_layer/nanocoap/fileserver....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-107837
(0 None)

EPSS: 0.38%

1 posts

N/A

thehackerwire@mastodon.social at 2026-10-09T18:31:00.000Z ##

🟠 CVE-2026-107837 - High (8.2)

RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, _receive() in sys/net/gnrc/network_layer/sixlowpan/gnrc_sixlowpan.c can route an undersized packet ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-61746
(0 None)

EPSS: 0.40%

1 posts

N/A

hugovalters@mastodon.social at 2026-10-09T17:40:03.000Z ##

CVE-2026-61746 InvenTree: unauthenticated info disclosure via plugin settings API before 1.4.0. CVSS 5.3. Patch under review - restrict API access now. valtersit.com/cve/CVE-2026-617 #CVE #infosec

##

Visit counter For Websites