##
Updated at UTC 2026-08-01T17:45:21.046997
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-67352 | 7.6 | 0.00% | 2 | 0 | 2026-08-01T13:17:05.860000 | luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in | |
| CVE-2026-67343 | 8.8 | 0.00% | 2 | 0 | 2026-08-01T13:17:05.563000 | ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the | |
| CVE-2026-67342 | 9.8 | 0.00% | 2 | 0 | 2026-08-01T13:17:05.417000 | ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in | |
| CVE-2026-67341 | 9.8 | 0.00% | 2 | 0 | 2026-08-01T13:17:05.273000 | ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks o | |
| CVE-2026-67340 | 9.8 | 0.00% | 4 | 0 | 2026-08-01T13:17:05.127000 | ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host | |
| CVE-2026-67336 | 8.7 | 0.00% | 2 | 0 | 2026-08-01T13:17:04.557000 | better-auth versions before 1.6.11 contain insecure cryptographic defaults in th | |
| CVE-2026-16635 | 8.8 | 0.31% | 2 | 0 | 2026-08-01T09:30:37 | The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in a | |
| CVE-2026-15964 | 9.8 | 0.49% | 4 | 0 | 2026-08-01T09:30:37 | The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication | |
| CVE-2026-15368 | None | 0.14% | 2 | 0 | 2026-08-01T09:30:36 | The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind | |
| CVE-2026-15262 | None | 0.15% | 1 | 0 | 2026-08-01T09:30:36 | The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape | |
| CVE-2026-14561 | None | 0.14% | 2 | 0 | 2026-08-01T09:30:36 | The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does n | |
| CVE-2026-64531 | 7.8 | 0.13% | 1 | 2 | 2026-08-01T09:30:23 | In the Linux kernel, the following vulnerability has been resolved: net: openvs | |
| CVE-2026-16144 | 8.1 | 0.69% | 2 | 0 | 2026-08-01T09:17:00.690000 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vu | |
| CVE-2026-15450 | 8.1 | 0.38% | 2 | 0 | 2026-08-01T09:16:59.023000 | The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable | |
| CVE-2026-66066 | 0 | 1.70% | 15 | 5 | 2026-08-01T08:16:30.147000 | Action Pack is a framework for handling and responding to web requests. In versi | |
| CVE-2026-15988 | 8.8 | 0.22% | 2 | 0 | 2026-08-01T08:16:29.610000 | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPre | |
| CVE-2026-3141 | 9.1 | 0.47% | 4 | 1 | 2026-08-01T06:16:26.030000 | The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file d | |
| CVE-2026-20316 | 5.3 | 0.79% | 14 | 0 | 2026-08-01T05:16:55.973000 | A vulnerability in the web interface of Cisco Secure Firewall Management Center | |
| CVE-2026-17566 | 9.9 | 0.43% | 2 | 0 | 2026-08-01T05:16:55.827000 | pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by in | |
| CVE-2026-15006 | 7.5 | 0.83% | 4 | 0 | 2026-08-01T03:16:25.460000 | The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email | |
| CVE-2026-62246 | 8.5 | 0.27% | 1 | 0 | 2026-08-01T00:17:17.480000 | Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, | |
| CVE-2026-61536 | 7.5 | 0.30% | 1 | 0 | 2026-07-31T23:17:25.930000 | Banks generates meaningful LLM prompts using a simple template language. In vers | |
| CVE-2026-44106 | 7.8 | 0.23% | 2 | 0 | 2026-07-31T23:17:24.103000 | A privilege escalation vulnerability in the init-script for user-applications al | |
| CVE-2026-44101 | 9.8 | 0.40% | 1 | 0 | 2026-07-31T23:17:23.970000 | Due to missing authentication the CHARX OCPP Agent service allows an unauthentic | |
| CVE-2026-44091 | 9.1 | 0.33% | 1 | 0 | 2026-07-31T23:17:23.707000 | An unauthenticated remote attacker can post a malicious ID to the MQTT Broker re | |
| CVE-2026-68771 | 9.8 | 0.62% | 3 | 0 | 2026-07-31T22:17:03.630000 | ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrai | |
| CVE-2026-53599 | 7.5 | 0.31% | 1 | 0 | 2026-07-31T22:17:03.213000 | REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_m | |
| CVE-2026-68770 | 9.8 | 0.52% | 3 | 0 | 2026-07-31T21:17:32.440000 | sentence-transformers contains a security control bypass vulnerability that allo | |
| CVE-2026-67207 | 8.8 | 0.30% | 1 | 0 | 2026-07-31T20:16:54.253000 | Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in Backu | |
| CVE-2026-52855 | 9.9 | 0.27% | 1 | 0 | 2026-07-31T20:16:51.173000 | Wings is the server control plane for Pterodactyl, a free, open-source game serv | |
| CVE-2026-18358 | 7.5 | 0.43% | 2 | 0 | 2026-07-31T20:16:49.663000 | A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. | |
| CVE-2026-52887 | 10.0 | 0.59% | 2 | 0 | 2026-07-31T19:45:02 | ## Summary `GET /api/myInAppChannels:list` accepts a structured `filter` query | |
| CVE-2026-53510 | 8.1 | 0.40% | 1 | 0 | 2026-07-31T19:38:26 | ### Impact `Savon::Model` generated SOAP operation methods by interpolating ope | |
| CVE-2026-53505 | 7.5 | 0.34% | 2 | 0 | 2026-07-31T19:17:10.123000 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, | |
| CVE-2026-18141 | 8.2 | 0.25% | 1 | 0 | 2026-07-31T19:17:08.053000 | A flaw was found in aap-gateway, a component of Ansible Automation Platform's Ev | |
| CVE-2026-53500 | 8.2 | 0.29% | 1 | 0 | 2026-07-31T18:36:05 | ## Summary The `ALLOWED_SOURCES` configuration is meant to restrict which hosts | |
| CVE-2026-17347 | 7.5 | 0.27% | 1 | 0 | 2026-07-31T18:32:24 | The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administr | |
| CVE-2026-10685 | 7.6 | 0.18% | 1 | 0 | 2026-07-31T18:17:09.510000 | The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() | |
| CVE-2026-54725 | 9.6 | 0.32% | 1 | 0 | 2026-07-31T17:45:04 | ## Summary The vault-secrets-webhook reads the `vault.security.banzaicloud.io/v | |
| CVE-2026-68500 | 7.5 | 0.38% | 1 | 0 | 2026-07-31T16:52:41 | ### Impact The shop payment webhook `POST /{_locale}/update-payment` (route | |
| CVE-2026-6267 | 8.5 | 0.34% | 2 | 0 | 2026-07-31T16:17:12.290000 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1. | |
| CVE-2026-68503 | 9.8 | 0.40% | 1 | 0 | 2026-07-31T16:17:12.183000 | LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framew | |
| CVE-2026-66360 | 7.5 | 0.28% | 1 | 0 | 2026-07-31T16:17:10.493000 | The ISO Presentation layer contains a flaw in the handling of specific paramete | |
| CVE-2026-63559 | 7.5 | 0.43% | 1 | 0 | 2026-07-31T16:17:09.290000 | An integer overflow in the UA_Variant arrayDimensions product computation in op | |
| CVE-2026-18157 | 7.8 | 0.24% | 1 | 0 | 2026-07-31T16:17:05.520000 | A flaw was found in yggdrasil-worker-package-manager. A local attacker with exis | |
| CVE-2026-15435 | 9.8 | 0.73% | 3 | 0 | 2026-07-31T16:16:58.413000 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0. | |
| CVE-2026-10079 | 8.5 | 0.17% | 1 | 0 | 2026-07-31T16:16:57.167000 | A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Wh | |
| CVE-2026-17561 | 9.8 | 0.31% | 4 | 0 | 2026-07-31T15:32:58 | Improper Control of Generation of Code ('Code Injection') vulnerability in Innot | |
| CVE-2026-63221 | 9.4 | 0.38% | 1 | 0 | 2026-07-31T14:16:50.873000 | CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query B | |
| CVE-2026-63220 | 4.8 | 0.14% | 1 | 0 | 2026-07-31T14:16:50.750000 | CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, Incom | |
| CVE-2026-11770 | 7.5 | 0.51% | 1 | 0 | 2026-07-31T12:30:30 | A flaw was found in 389 Directory Server. An unauthenticated remote attacker can | |
| CVE-2026-15722 | 7.5 | 0.51% | 1 | 0 | 2026-07-31T11:17:04.833000 | A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). Th | |
| CVE-2026-16236 | 8.8 | 0.63% | 1 | 0 | 2026-07-31T09:31:30 | The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Up | |
| CVE-2026-65313 | 8.1 | 0.18% | 1 | 0 | 2026-07-31T09:31:19 | A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engin | |
| CVE-2026-6102 | 7.8 | 0.09% | 1 | 0 | 2026-07-31T04:17:24.730000 | MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulner | |
| CVE-2026-66803 | 10.0 | 0.49% | 1 | 0 | 2026-07-31T04:17:24.520000 | Improper access control in Azure Cosmos DB allows an unauthorized attacker to ex | |
| CVE-2026-5490 | 8.8 | 0.48% | 1 | 1 | 2026-07-31T04:17:24.013000 | DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability a | |
| CVE-2026-58066 | 9.8 | 0.21% | 1 | 0 | 2026-07-31T04:17:23.877000 | Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, | |
| CVE-2026-58043 | 7.5 | 0.14% | 4 | 0 | 2026-07-31T04:17:23.737000 | A flaw in Node.js Permission Model enforcement can over-grant filesystem access | |
| CVE-2026-17543 | 0 | 0.39% | 1 | 0 | 2026-07-31T04:16:48.350000 | Improper escaping of backslashes in attacker-provided parameters would allow for | |
| CVE-2026-12940 | 9.8 | 0.48% | 1 | 0 | 2026-07-31T04:16:45.870000 | IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote | |
| CVE-2026-65423 | 8.8 | 0.60% | 1 | 0 | 2026-07-31T00:30:29 | An integer overflow in the UA_Variant arrayDimensions product computation in op | |
| CVE-2026-66421 | 9.3 | 0.36% | 1 | 0 | 2026-07-31T00:30:29 | OpenClaw Dashboard contains a stored cross-site scripting vulnerability that all | |
| CVE-2026-66420 | 8.8 | 0.17% | 1 | 0 | 2026-07-31T00:30:29 | MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass v | |
| CVE-2026-18064 | 7.5 | 0.34% | 1 | 0 | 2026-07-31T00:30:29 | An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Healt | |
| CVE-2026-63035 | 8.1 | 0.57% | 1 | 0 | 2026-07-31T00:30:22 | A heap use-after-free vulnerability in the TransferSubscriptions service in ope | |
| CVE-2026-67206 | 8.8 | 0.44% | 1 | 0 | 2026-07-30T21:31:57 | Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileM | |
| CVE-2026-67594 | 9.8 | 0.46% | 1 | 0 | 2026-07-30T21:31:57 | Spikster through commit e1cdf8c contains a missing authentication vulnerability | |
| CVE-2026-66416 | 8.8 | 0.16% | 1 | 0 | 2026-07-30T21:31:57 | Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows u | |
| CVE-2026-66415 | 8.5 | 0.28% | 1 | 0 | 2026-07-30T21:31:57 | Leantime 3.6.2 contains a server-side request forgery and local file inclusion v | |
| CVE-2026-13435 | 9.9 | 0.29% | 1 | 0 | 2026-07-30T21:31:56 | IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vuln | |
| CVE-2026-17657 | 8.3 | 0.36% | 1 | 0 | 2026-07-30T21:31:32 | Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a r | |
| CVE-2026-18245 | 9.0 | 0.52% | 1 | 0 | 2026-07-30T20:17:03.733000 | Improper control of code generation in Amazon @aws-amplify/codegen-ui-react befo | |
| CVE-2026-18140 | 7.5 | 0.44% | 1 | 0 | 2026-07-30T20:17:03.400000 | Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runti | |
| CVE-2026-67432 | 7.5 | 0.44% | 1 | 0 | 2026-07-30T19:30:33.710000 | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and cli | |
| CVE-2026-62663 | 7.5 | 0.34% | 1 | 0 | 2026-07-30T19:26:51.190000 | Banks generates meaningful LLM prompts using a simple template language. In vers | |
| CVE-2026-67437 | 7.5 | 0.35% | 1 | 0 | 2026-07-30T19:21:23.297000 | OliveTin gives access to predefined shell commands from a web interface. From 30 | |
| CVE-2026-16771 | 8.8 | 0.25% | 1 | 0 | 2026-07-30T19:10:06.847000 | In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to en | |
| CVE-2026-28323 | 9.8 | 0.64% | 3 | 0 | 2026-07-30T18:31:47 | SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass | |
| CVE-2026-9322 | 7.5 | 0.30% | 1 | 0 | 2026-07-30T18:31:47 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv | |
| CVE-2026-67595 | 8.1 | 0.42% | 3 | 0 | 2026-07-30T16:45:00.353000 | VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript p | |
| CVE-2026-67428 | 8.5 | 0.34% | 1 | 0 | 2026-07-30T16:41:25.650000 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior | |
| CVE-2026-56850 | 4.1 | 0.08% | 1 | 0 | 2026-07-30T16:33:59.580000 | A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key co | |
| CVE-2026-44102 | 5.3 | 0.21% | 1 | 0 | 2026-07-30T16:17:11.877000 | An unauthenticated remote attacker can trigger a firmware update download via th | |
| CVE-2026-47876 | 9.3 | 0.28% | 3 | 0 | 2026-07-30T15:31:54 | VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual | |
| CVE-2026-59309 | 9.8 | 0.74% | 2 | 0 | 2026-07-30T15:31:54 | VMware vCenter contains an authentication bypass vulnerability in the VMware Dir | |
| CVE-2026-59310 | 9.8 | 1.14% | 2 | 0 | 2026-07-30T15:31:51 | VMware vCenter contains a directory traversal vulnerability in the Syslog server | |
| CVE-2026-1360 | 7.5 | 0.57% | 1 | 0 | 2026-07-30T15:16:31.530000 | The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untruste | |
| CVE-2026-67429 | 10.0 | 0.49% | 1 | 0 | 2026-07-30T14:46:44 | ## Summary `image.download` fetches a URL and writes the response to disk. It d | |
| CVE-2026-44108 | 9.8 | 0.46% | 2 | 0 | 2026-07-30T14:31:21.447000 | Due to a flaw in the execution order of scripts during shutdown, the firewall is | |
| CVE-2026-44105 | 6.6 | 0.09% | 1 | 0 | 2026-07-30T14:31:21.447000 | The credentials for the local user "user-app" may be exposed in log files, poten | |
| CVE-2026-44098 | 8.6 | 1.37% | 1 | 0 | 2026-07-30T14:31:21.447000 | This vulnerability allows an unauthenticated remote attacker with control over t | |
| CVE-2026-44100 | 9.4 | 0.28% | 1 | 0 | 2026-07-30T14:31:21.447000 | The CHARX JupiCore service allows an unauthenticated remote attacker to reconfig | |
| CVE-2026-44093 | 7.8 | 0.23% | 1 | 0 | 2026-07-30T14:31:21.447000 | A local privilege escalation vulnerability in the init-script for user-applicati | |
| CVE-2026-5057 | 7.5 | 0.48% | 1 | 0 | 2026-07-30T14:19:24.857000 | ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. | |
| CVE-2026-5491 | 7.5 | 1.54% | 1 | 0 | 2026-07-30T14:18:46.477000 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera | |
| CVE-2026-15975 | 7.5 | 0.39% | 1 | 0 | 2026-07-30T14:15:31.167000 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 | |
| CVE-2026-14529 | 9.4 | 0.33% | 2 | 0 | 2026-07-30T14:08:40.373000 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv | |
| CVE-2026-14270 | 8.8 | 0.55% | 1 | 0 | 2026-07-30T14:01:30.413000 | The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCom | |
| CVE-2026-18363 | None | 0.30% | 1 | 0 | 2026-07-30T12:32:26 | A logic vulnerability in the password reset token validation routine implemented | |
| CVE-2026-64560 | 7.8 | 0.12% | 1 | 0 | 2026-07-30T12:19:03.630000 | In the Linux kernel, the following vulnerability has been resolved: posix-cpu-t | |
| CVE-2026-44107 | 7.5 | 0.31% | 2 | 0 | 2026-07-30T09:31:24 | A reboot of the charging controller can be triggered via Modbus TCP without auth | |
| CVE-2026-7849 | 9.8 | 0.42% | 2 | 0 | 2026-07-30T09:31:24 | Due to improper neutralization of special elements, an unauthenticated remote at | |
| CVE-2026-44094 | 8.6 | 0.26% | 1 | 0 | 2026-07-30T09:31:24 | An unauthenticated remote attacker can enforce the system to fall back to a firm | |
| CVE-2026-44090 | 9.8 | 0.40% | 1 | 0 | 2026-07-30T09:31:24 | Due to missing authentication, an unauthenticated remote attacker may access the | |
| CVE-2026-44104 | 9.8 | 0.24% | 1 | 0 | 2026-07-30T09:31:24 | The firmware update process for the basemodule of the charging controller only v | |
| CVE-2026-44095 | 7.8 | 0.23% | 1 | 0 | 2026-07-30T09:31:24 | A privilege escalation vulnerability in a script used for network configuration | |
| CVE-2026-44103 | 5.3 | 0.24% | 1 | 0 | 2026-07-30T09:31:24 | An unauthenticated remote attacker can inject malicious firmware into the intern | |
| CVE-2026-44092 | 9.1 | 0.38% | 1 | 0 | 2026-07-30T09:31:24 | An unauthenticated remote attacker can inject malicious input into the ModbusSer | |
| CVE-2026-44096 | 7.8 | 0.23% | 1 | 0 | 2026-07-30T09:31:18 | A privilege escalation vulnerability in udhcpc allows a local user "charx-web" t | |
| CVE-2026-44099 | 7.8 | 0.23% | 1 | 0 | 2026-07-30T09:31:18 | A privilege escalation vulnerability in the system configuration allows a low-pr | |
| CVE-2026-44097 | 7.1 | 0.24% | 1 | 0 | 2026-07-30T09:31:18 | A low-privileged remote attacker with "operator" access can upload arbitrary fil | |
| CVE-2026-58046 | 9.9 | 0.31% | 1 | 0 | 2026-07-30T06:32:44 | Improper neutralization in the Plesk XML-RPC API allows a remote authenticated l | |
| CVE-2026-16610 | 9.8 | 0.58% | 2 | 0 | 2026-07-30T06:32:44 | The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to | |
| CVE-2026-14356 | 8.8 | 0.27% | 1 | 0 | 2026-07-30T06:32:43 | The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in a | |
| CVE-2026-48449 | 10.0 | 0.54% | 3 | 0 | 2026-07-30T03:31:28 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi | |
| CVE-2026-48448 | 8.6 | 0.37% | 1 | 0 | 2026-07-30T03:31:28 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia | |
| CVE-2026-16727 | None | 0.09% | 1 | 0 | 2026-07-30T03:31:28 | Concurrent Execution using Shared Resource with Improper Synchronization (“Race | |
| CVE-2026-5056 | 7.8 | 0.43% | 1 | 0 | 2026-07-29T21:31:08 | GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerabilit | |
| CVE-2026-13308 | 8.1 | 0.57% | 1 | 0 | 2026-07-29T21:31:08 | Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Executi | |
| CVE-2026-5487 | 7.5 | 1.54% | 1 | 0 | 2026-07-29T21:31:07 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera | |
| CVE-2026-67201 | 8.6 | 0.39% | 1 | 0 | 2026-07-29T21:31:07 | V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery | |
| CVE-2026-61511 | 9.8 | 1.27% | 2 | 6 | 2026-07-29T20:17:10.347000 | vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vul | |
| CVE-2026-67215 | 7.5 | 0.35% | 1 | 0 | 2026-07-29T15:31:12 | cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack ex | |
| CVE-2026-65883 | None | 0.50% | 1 | 1 | 2026-07-29T12:31:30 | Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Ca | |
| CVE-2026-18220 | 7.8 | 0.19% | 1 | 1 | 2026-07-29T12:31:23 | An out-of-bounds write vulnerability was found in the BFD library's DLX ELF back | |
| CVE-2026-18197 | None | 0.27% | 1 | 0 | 2026-07-29T09:31:36 | Improper neutralization of input during web page generation ('cross-site scripti | |
| CVE-2026-14512 | 9.8 | 0.54% | 1 | 0 | 2026-07-28T21:31:44 | IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-a | |
| CVE-2026-16347 | 8.8 | 0.23% | 2 | 0 | 2026-07-28T21:31:39 | MikroTik RouterOS contains a weakness in its API authentication handling that la | |
| CVE-2026-55390 | 7.5 | 0.36% | 1 | 0 | 2026-07-28T21:26:42 | ### Summary When generating models from an XML Schema (`--input-file-type xmlsc | |
| CVE-2026-5674 | 8.8 | 0.12% | 1 | 0 | 2026-07-28T18:33:47 | A flaw was found in PipeWire, a multimedia server. This vulnerability allows an | |
| CVE-2026-16812 | 10.0 | 0.88% | 1 | 0 | 2026-07-27T21:31:22 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may a | |
| CVE-2026-63077 | 9.8 | 0.65% | 4 | 1 | 2026-07-27T18:31:56 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe | |
| CVE-2026-66013 | None | 0.39% | 1 | 0 | 2026-07-25T12:31:47 | OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the | |
| CVE-2026-66373 | 7.5 | 0.47% | 1 | 0 | 2026-07-25T03:30:55 | Redis before 8.8.0, in the unusual case where an authenticated attacker can exec | |
| CVE-2026-59952 | None | 0.52% | 1 | 0 | 2026-07-24T16:14:33 | ## Summary `valibot` 1.4.1 can throw a `TypeError` inside its `flatten()` helpe | |
| CVE-2026-43499 | 7.8 | 0.73% | 1 | 57 | 2026-07-24T15:33:29 | In the Linux kernel, the following vulnerability has been resolved: rtmutex: Us | |
| CVE-2026-21655 | None | 0.17% | 1 | 0 | 2026-07-23T21:31:03 | Deserialization of untrusted data vulnerability in Johnson Control victor on Win | |
| CVE-2026-43503 | 8.8 | 0.34% | 1 | 9 | 2026-07-23T11:10:00.120000 | In the Linux kernel, the following vulnerability has been resolved: net: skbuff | |
| CVE-2026-16232 | 9.1 | 69.97% | 5 | 2 | template | 2026-07-22T21:32:05 | An authentication bypass vulnerability in the Check Point SmartConsole login pro |
| CVE-2026-50522 | 9.8 | 75.76% | 2 | 5 | 2026-07-22T21:31:51 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut | |
| CVE-2026-49176 | 7.8 | 0.47% | 1 | 2 | 2026-07-22T16:17:28.753000 | Improper privilege management in Windows WalletService allows an authorized atta | |
| CVE-2026-20896 | 9.8 | 31.81% | 2 | 6 | 2026-07-21T20:28:59 | # Summary The Gitea Docker images ship an `app.ini` template that hard-codes: | |
| CVE-2026-27771 | 8.2 | 43.07% | 2 | 2 | template | 2026-07-17T19:04:38 | ### CVE Description Gitea versions up to and including 1.26.1 have insufficient |
| CVE-2026-15352 | 7.5 | 0.43% | 1 | 0 | 2026-07-16T21:30:45 | A vulnerability exists in the Health & Safety (HS) application of NASA's Core Fl | |
| CVE-2026-42530 | 8.1 | 3.68% | 1 | 3 | 2026-07-16T12:17:51.630000 | NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGI | |
| CVE-2026-15409 | 10.0 | 78.44% | 2 | 5 | template | 2026-07-16T05:16:18.293000 | A Server-side request forgery (SSRF) vulnerability has been identified in the SM |
| CVE-2026-48319 | 9.1 | 32.29% | 2 | 0 | 2026-07-14T21:32:32 | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted D | |
| CVE-2026-15410 | 7.2 | 76.35% | 2 | 3 | 2026-07-14T21:32:21 | Post-authentication improper control of generation of code ('Code Injection') vu | |
| CVE-2026-59726 | 10.0 | 0.48% | 3 | 1 | 2026-07-10T19:15:15.780000 | Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo | |
| CVE-2026-56291 | 9.8 | 76.07% | 2 | 4 | template | 2026-07-10T18:33:13 | The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary |
| CVE-2026-58025 | 9.8 | 0.33% | 1 | 1 | 2026-07-09T21:31:14 | Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWik | |
| CVE-2026-10702 | 4.3 | 0.72% | 3 | 2 | 2026-06-30T03:36:54 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w | |
| CVE-2026-42897 | 8.1 | 5.64% | 6 | 1 | 2026-06-17T10:48:34.893000 | Improper neutralization of input during web page generation ('cross-site scripti | |
| CVE-2014-0160 | 7.5 | 100.00% | 1 | 75 | template | 2026-06-17T00:02:24.467000 | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not p |
| CVE-2013-4786 | 7.5 | 78.57% | 2 | 1 | 2026-06-16T23:57:53.617000 | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (R | |
| CVE-2026-20079 | 10.0 | 37.67% | 4 | 1 | template | 2026-03-04T18:32:03 | A vulnerability in the web interface of Cisco Secure Firewall Management Center |
| CVE-2025-15435 | 7.3 | 0.36% | 1 | 0 | 2026-01-02T09:30:27 | A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an u | |
| CVE-2023-37327 | 7.6 | 1.71% | 2 | 0 | 2025-11-04T21:32:34 | GStreamer FLAC File Parsing Integer Overflow Remote Code Execution Vulnerability | |
| CVE-2026-63030 | 0 | 98.42% | 2 | 72 | template | N/A | |
| CVE-2026-60137 | 0 | 79.03% | 2 | 46 | N/A | ||
| CVE-2026-18420 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-62999 | 0 | 0.29% | 1 | 0 | N/A | ||
| CVE-2026-62261 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-62379 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-46648 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-46647 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-63223 | 0 | 0.49% | 2 | 0 | N/A | ||
| CVE-2026-63222 | 0 | 0.45% | 1 | 0 | N/A | ||
| CVE-2026-68502 | 0 | 0.53% | 1 | 0 | N/A | ||
| CVE-2026-58086 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-56846 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-56848 | 0 | 0.00% | 4 | 0 | N/A | ||
| CVE-2026-53921 | 0 | 0.00% | 1 | 2 | N/A |
updated 2026-08-01T13:17:05.860000
2 posts
🟠 CVE-2026-67352 - High (7.6)
luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is ren...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67352/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67352 - High (7.6)
luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is ren...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67352/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T13:17:05.563000
2 posts
🟠 CVE-2026-67343 - High (8.8)
ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-Arcad...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67343/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67343 - High (8.8)
ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-Arcad...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67343/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T13:17:05.417000
2 posts
🔴 CVE-2026-67342 - Critical (9.8)
ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67342/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-67342 - Critical (9.8)
ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67342/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T13:17:05.273000
2 posts
🔴 CVE-2026-67341 - Critical (9.8)
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, by...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67341/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-67341 - Critical (9.8)
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, by...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67341/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T13:17:05.127000
4 posts
🔴 CVE-2026-67340 - Critical (9.8)
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67340/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-67340: CRITICAL RCE in ArcadeDB <26.7.2. Users w/ UPDATE_SCHEMA can exploit JavaScript triggers to run OS commands. Patch status pending — restrict permissions & audit triggers. Details: https://radar.offseq.com/threat/cve-2026-67340-improper-control-of-generation-of-code-code-injection-in-arcadedata-arcadedb-7ff6de59519457ac #OffSeq #ArcadeDB #RCE #infosec
##🔴 CVE-2026-67340 - Critical (9.8)
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67340/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-67340: CRITICAL RCE in ArcadeDB <26.7.2. Users w/ UPDATE_SCHEMA can exploit JavaScript triggers to run OS commands. Patch status pending — restrict permissions & audit triggers. Details: https://radar.offseq.com/threat/cve-2026-67340-improper-control-of-generation-of-code-code-injection-in-arcadedata-arcadedb-7ff6de59519457ac #OffSeq #ArcadeDB #RCE #infosec
##updated 2026-08-01T13:17:04.557000
2 posts
🟠 CVE-2026-67336 - High (8.7)
better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned token...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67336/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67336 - High (8.7)
better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned token...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67336/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T09:30:37
2 posts
🟠 CVE-2026-16635 - High (8.8)
The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed-...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16635/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-16635 - High (8.8)
The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed-...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16635/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T09:30:37
4 posts
🔴 CVE-2026-15964 - Critical (9.8)
The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15964/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL: CVE-2026-15964 in britcoder Single Sign On For TNG <=2.0.0 lets unauthenticated attackers reset any WP user password via exposed AJAX. Full site takeover possible. Disable or restrict access now. https://radar.offseq.com/threat/cve-2026-15964-cwe-620-unverified-password-change-in-britcoder-single-sign-on-for-tng-6425266a865be131 #OffSeq #WordPress #CVE #Vuln
##🔴 CVE-2026-15964 - Critical (9.8)
The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15964/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL: CVE-2026-15964 in britcoder Single Sign On For TNG <=2.0.0 lets unauthenticated attackers reset any WP user password via exposed AJAX. Full site takeover possible. Disable or restrict access now. https://radar.offseq.com/threat/cve-2026-15964-cwe-620-unverified-password-change-in-britcoder-single-sign-on-for-tng-6425266a865be131 #OffSeq #WordPress #CVE #Vuln
##updated 2026-08-01T09:30:36
2 posts
CVE-2026-15368: User Profile Builder WP plugin (CRITICAL) allows session hijack as any user — including admins — if using specific non-default configs. Review settings, restrict auto-login, and monitor for fixes. https://radar.offseq.com/threat/cve-2026-15368-cwe-269-improper-privilege-management-in-user-profile-builder-7cbf3fdcef75f1fb #OffSeq #WordPress #Infosec #CVE202615368 🔒
##CVE-2026-15368: User Profile Builder WP plugin (CRITICAL) allows session hijack as any user — including admins — if using specific non-default configs. Review settings, restrict auto-login, and monitor for fixes. https://radar.offseq.com/threat/cve-2026-15368-cwe-269-improper-privilege-management-in-user-profile-builder-7cbf3fdcef75f1fb #OffSeq #WordPress #Infosec #CVE202615368 🔒
##updated 2026-08-01T09:30:36
1 posts
Linux Kernel Vulnerability Enables Privilege Escalation via Local Exploits
📰 Original title: CVE-2026-15262
🤖 IA: It's not clickbait ✅
👥 Users: It's not clickbait ✅
View full AI summary https://en.killbait.com/linux-kernel-vulnerability-enables-privilege-escalation-via-local-exploits.html?utm_source=mastodon_world&utm_medium=social&utm_campaign=killbait.mastodon_world
##updated 2026-08-01T09:30:36
2 posts
CVE-2026-14561 | CRITICAL | Authora: Easy login with mobile number (WordPress <1.7.7) suffers from improper authentication — attackers can log in as any user if they know a mobile number. Restrict plugin endpoints & monitor logins. https://radar.offseq.com/threat/cve-2026-14561-cwe-287-improper-authentication-in-authora-easy-login-with-mobile-number-9e459a9493ea0d5c #OffSeq #WordPress #Vuln
##CVE-2026-14561 | CRITICAL | Authora: Easy login with mobile number (WordPress <1.7.7) suffers from improper authentication — attackers can log in as any user if they know a mobile number. Restrict plugin endpoints & monitor logins. https://radar.offseq.com/threat/cve-2026-14561-cwe-287-improper-authentication-in-authora-easy-login-with-mobile-number-9e459a9493ea0d5c #OffSeq #WordPress #Vuln
##updated 2026-08-01T09:30:23
1 posts
2 repos
https://github.com/0xBlackash/CVE-2026-64531
https://github.com/mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool
Falha OVSwrap ameaça servidores Linux com acesso root e já tem exploit público. Uma vulnerabilidade crítica no kernel do Linux, batizada de OVSwrap (CVE-2026-64531), permite que utilizadores locais sem privilégios obtenham acesso total de root. 🚨
##updated 2026-08-01T09:17:00.690000
2 posts
🟠 CVE-2026-16144 - High (8.1)
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16144/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-16144 - High (8.1)
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16144/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T09:16:59.023000
2 posts
🟠 CVE-2026-15450 - High (8.1)
The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15450/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-15450 - High (8.1)
The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15450/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T08:16:30.147000
15 posts
5 repos
https://github.com/paveg/rails-activestorage-vips-audit
https://github.com/0xsha/KindaRails2Shell
https://github.com/Zer0SumGam3/CVE-2026-66066-POC
Critical Ruby on Rails Flaw CVE-2026-66066 Exposes Sensitive Files, Secret Keys, and the Hidden Risks Inside Modern Web Frameworks + Video
Introduction: A New Warning Sign for Web Application Security Modern web frameworks have transformed software development by making it faster and easier to build powerful applications. However, every additional feature, plugin, and integrated component also creates new security challenges. The discovery of CVE-2026-66066, a critical…
##Rails patches Active Storage flaw with RCE potential
A critical vulnerability in Rails' Active Storage, known as CVE-2026-66066, can allow an unauthenticated attacker to read sensitive files and potentially execute remote code, putting your application at risk. This flaw can be exploited under specific conditions, making it crucial to patch immediately.
#Rails #ActiveStorage #Cve202666066 #RemoteCodeExecution #FileUploadVulnerability
##CVE-2026-66066 (CVSS 9.5) enables Rails Active Storage RCE via libvips. A Metasploit module is now public. Upgrade Rails and rotate secrets.
#RubyOnRails #CVE202666066 #RCE #ActiveStorage #CyberSecurity #Metasploit
##CVE-2026-66066 (CVSS 9.5) enables Rails Active Storage RCE via libvips. A Metasploit module is now public. Upgrade Rails and rotate secrets.
#RubyOnRails #CVE202666066 #RCE #ActiveStorage #CyberSecurity #Metasploit
##RE: https://ruby.social/@flavorjones/117003927959522056
The Rails security team published attack details and -- more importantly -- tools and agent skills to run a forensic investigation to help you determine if you were exploited. Be careful out there.
##KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
#CVE_2026_66066
https://www.rapid7.com/blog/post/etr-kindarails2shell-cve-2026-66066-critical-arbitrary-file-read-and-possible-remote-code-execution-in-ruby-on-rails/
New.
Rapaid7: KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails https://www.rapid7.com/blog/post/etr-kindarails2shell-cve-2026-66066-critical-arbitrary-file-read-and-possible-remote-code-execution-in-ruby-on-rails/ @Rapid7Official
The related Ruby on Rails advisory was published yesterday: Possible arbitrary file read and remote code execution in Active Storage variant processing https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm #infosec #vulnerability #Ruby
##KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) https://lobste.rs/s/kkobew #ruby #security
https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066
KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066) https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066
##Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials, and API tokens. https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html?_m=3n%2e009a%2e4043%2ebk0aof3yrl%2e33lb
##🚨 Manyfold v0.147.1 is out, with a security fix for #Rails CVE-2026-66066. Update your instances! 🚨
##CVE-2026-66066: un atacant pot llegir fitxers del servidor Rails gràcies a Active Storage + libvips. secret_key_base, master.key, credencials de cloud — tot a l'abast. I després fer RCE amb les claus robades. 🎯
Parcheja a: activestorage 7.2.3.2 / 8.0.5.1 / 8.1.3.1 o libvips ≥ 8.13.0
Si encara uses libvips vell, posa VIPS_BLOCK_UNTRUSTED i resa.
##Critical Rails Active Storage Flaw Allows Unauthenticated Arbitrary File Read
Ruby on Rails patched a critical vulnerability (CVE-2026-66066) in Active Storage that allows unauthenticated attackers to read arbitrary server files and steal sensitive secrets.
**Update Rails immediately to a patched version (7.2.3.2, 8.0.5.1, or 8.1.3.1) and make sure libvips is upgraded to 8.13 or later. A public exploit is already available and attacks are expected soon. Because attackers may have already stolen your secrets, rotate every credential the app could access, including secret_key_base, the master key, database passwords, and all API tokens after patching.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-rails-active-storage-flaw-allows-unauthenticated-arbitrary-file-read-k-h-8-7-3/gD2P6Ple2L
A Rails Active Storage flaw, CVE-2026-66066 (CVSS 9.5), enables arbitrary file read and remote code execution. Patch Rails and rotate secrets now.
#RubyOnRails #ActiveStorage #CVE202666066 #RCE #libvips #InfoSec
https://securityonline.info/rails-cve-2026-66066/?utm_source=mastodon&utm_medium=jetpack_social
##RE: https://christine-seeman.com/cve-2026-66066-active-storage/
Patch your #rails there's a new CVE out there specifically about active storage and if your app accepts image uploads.
##updated 2026-08-01T08:16:29.610000
2 posts
🟠 CVE-2026-15988 - High (8.8)
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_aut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15988/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-15988 - High (8.8)
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_aut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15988/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T06:16:26.030000
4 posts
1 repos
https://github.com/Rat5ak/CVE-2026-31413-BPF-Container-Escape
🔴 CVE-2026-3141 - Critical (9.1)
The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-3141/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-3141 (CRITICAL, CVSS 9.1): wpwax FormGent for WordPress lets unauthenticated users delete arbitrary files via REST API. Linux servers risk full takeover if wp-config.php is deleted. Patch or restrict access now. https://radar.offseq.com/threat/cve-2026-3141-cwe-862-missing-authorization-in-wpwax-formgent-next-gen-ai-form-builder-for-wordpress-19f88cc02a19c7e3 #OffSeq #WordPress #CVE20263141
##🔴 CVE-2026-3141 - Critical (9.1)
The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-3141/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-3141 (CRITICAL, CVSS 9.1): wpwax FormGent for WordPress lets unauthenticated users delete arbitrary files via REST API. Linux servers risk full takeover if wp-config.php is deleted. Patch or restrict access now. https://radar.offseq.com/threat/cve-2026-3141-cwe-862-missing-authorization-in-wpwax-formgent-next-gen-ai-form-builder-for-wordpress-19f88cc02a19c7e3 #OffSeq #WordPress #CVE20263141
##updated 2026-08-01T05:16:55.973000
14 posts
What year is it?:
##What year is it?:
##There are two new advisories from Cisco, one addressing a critical vulnerability that was first published on March 4:
CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
The second is a high-severity vulnerability that was first published yesterday:
CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh @TalosSecurity #infosec #vulnerability #Cisco
##Executive alert: CVE-2026-20316 exposes Cisco Secure Firewall Management Center to active exploitation via hard-coded credentials. Review enterprise exposure metrics, zero-trust segmentation, and board-level risk mitigation strategies today. https://thecybermind.co/jily
##CVE-2026-20316 Zero-Day Actively Exploited, Cisco Releases Fix
Cisco has released security updates for an actively exploited zero-day vulnerability, CVE-2026-20316, affecting Cisco Secure FMC (Secure Firewall...
🔗️ [Thecyberexpress] https://link.is.it/FLOu9T
##Critical advisory: CVE-2026-20316 exposes Cisco Secure Firewall Management Center to hard-coded credential abuse. Review active threat vectors, network access lockdowns, and system hardening playbooks to protect your perimeter. https://thecybermind.co/bkur
###Cisco - "We Never Learn". 🔥
Warum ein Konzern es noch immer notwendig findet eine #Backdoor in seine Produkte einzubauen ist mir völlig schleierhaft. 🙈
"Da CVE-2026-20316 bereits aktiv ausgenutzt wird, rät Cisco Administratoren, ihre FMC-Instanzen dringend zu aktualisieren."
"Gibt es Abhilfe?
"Die genannten Hotfix-Updates bessern auch bezüglich einer seit März bekannten kritischen Lücke (CVSS: 10) nach, mit der sich die Authentifizierung im Web-Interface von FMC umgehen lässt. Diese Lücke ist als CVE-2026-20079 registriert und verleiht Angreifern sogar einen direkten Root-Zugriff auf das zugrundeliegende Betriebssystem. "
Klar, eine Firewall ist ja nur zum Schutz der Kunden vorhanden, da kann man schon mal auch Kriminelle einladen, oder? 🤢
So eine persönliche Haftung des CEO und eine Strafe ab 5 % vom Konzernumsatz könnte möglicherweise zu einer Änderungen führen:
So stelle ich mir die Anweisung des CEO vor: 👍
"Ab sofort ist die Nutzung (auch während der Entwicklung) von Backdoors untersagt. Wer sich nicht daran hält wird fristlos entlassen und haftet für Schäden."
Und, natürlich sollte die Qualitätssicherung vorab prüfen ob die Entwickler sich auch daran halten. 😁
Es gibt erfahrene Spezialisten die gerne bei der Auswahl der Geräte helfen und für mehr Sicherheit sorgen. Einfach anfragen, dann weiß man mehr. 🙂
##🏆 New Achievement! Static Credentials, Static Fate!
RAID ALERT. RAID ALERT. Cisco Secure Firewall Management Center has a hardcoded low-privilege account baked right into the software — CVE-2026-20316 — and unauthenticated remote attackers are already using it to log in and harvest sensitive data. That's Phase One. Phase Two is the wipe: threat actors are chaining it with CVE-2026-20079, which hands them root access via arbitrary script execution. (1/2)
##Cisco Patches Actively Exploited Hard-Coded Password in Secure Firewall Management Center
Cisco fixed a high-severity vulnerability (CVE-2026-20316) in Secure Firewall Management Center that allows unauthenticated remote attackers to log in using hard-coded credentials. CISA added the flaw to its KEV catalog following reports of zero-day exploitation targeting network security infrastructure.
**Make sure your Cisco Secure Firewall Management Center (FMC) is isolated from the internet and only reachable from trusted internal networks. Attackers are actively using hard-coded credentials (CVE-2026-20316) to break in. Apply Cisco's hotfix immediately (CISA requires it by August 1, 2026), and check your management logs for suspicious entries mentioning /var/tmp/license.tmp to spot any break-in.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisco-patches-actively-exploited-hard-coded-password-in-secure-firewall-management-center-p-x-i-l-e/gD2P6Ple2L
Cisco warns of FMC static credential flaw exploited in zero-day attacks
Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was...
🔗️ [Bleepingcomputer] https://link.is.it/AKCr32
##A Cisco FMC vulnerability, CVE-2026-20316, is exploited in the wild. Static credentials let attackers log in. CISA added it to KEV — patch now.
#Cisco #CVE202620316 #FMC #KEV #Vulnerability #InfoSec
https://securityonline.info/cisco-fmc-cve-2026-20316/?utm_source=mastodon&utm_medium=jetpack_social
##🚨 [CISA-2026:0729] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-20316 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20316)
- Name: Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Cisco
- Product: Secure Firewall Management Center (FMC)
- Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20316
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260729 #cisa20260729 #cve_2026_20316 #cve202620316
##CVE ID: CVE-2026-20316
Vendor: Cisco
Product: Secure Firewall Management Center (FMC)
Date Added: 2026-07-29
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-20316
New Cisco updates:
CRITICAL vulnerability, first released on March 4: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
High severity: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
New informational advisory: Cisco Advance Notification for Publication of August 5, 2026, Security Advisories https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-L4XfJg8S @TalosSecurity #infosec #vulnerability #Cisco
##updated 2026-08-01T05:16:55.827000
2 posts
CVE-2026-17566 - Critical RCE in pgAdmin 4. Import/Export Data tool allows command injection via crafted SQL. CVSS 9.9. Unpatched - restrict access immediately. #CVE #pgAdmin #infosec
##🔴 CVE-2026-17566 - Critical (9.9)
pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17566/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T03:16:25.460000
4 posts
🟠 CVE-2026-15006 - High (7.5)
The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15006/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-15006: Bit integrations plugin ≤2.9.0 for WordPress has a HIGH severity path traversal flaw (CVSS 7.5). Unauthenticated attackers can read arbitrary server files. No patch yet — disable or restrict plugin. https://radar.offseq.com/threat/cve-2026-15006-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-ee5b332d75a54eb5 #OffSeq #WordPress #Vuln
##🟠 CVE-2026-15006 - High (7.5)
The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15006/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-15006: Bit integrations plugin ≤2.9.0 for WordPress has a HIGH severity path traversal flaw (CVSS 7.5). Unauthenticated attackers can read arbitrary server files. No patch yet — disable or restrict plugin. https://radar.offseq.com/threat/cve-2026-15006-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-ee5b332d75a54eb5 #OffSeq #WordPress #Vuln
##updated 2026-08-01T00:17:17.480000
1 posts
🟠 CVE-2026-62246 - High (8.5)
Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62246/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T23:17:25.930000
1 posts
🟠 CVE-2026-61536 - High (7.5)
Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resolves their import_path field through importlib.impo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61536/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T23:17:24.103000
2 posts
🟠 CVE-2026-44106 - High (7.8)
A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44106/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
###OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-31T23:17:23.970000
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-31T23:17:23.707000
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-31T22:17:03.630000
3 posts
CVE-2026-68771 - Critical RCE in ComfyUI. Unsafe deserialization in LoadTrainingDataset. CVSS 9.8. No patch; stop using /upload/image and /prompt. #CVE #ComfyUI #infosec
##🔴 CVE-2026-68771 - Critical (9.8)
ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68771/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-68771: CRITICAL RCE in ComfyUI v0.23.0. Unauthenticated remote attackers can exploit unsafe pickle deserialization via /upload/image, leading to code execution as the process user. Restrict access & monitor endpoints. https://radar.offseq.com/threat/cve-2026-68771-deserialization-of-untrusted-data-in-comfy-org-comfyui-029fe0d26fda144c #OffSeq #CVE202668771 #infosec
##updated 2026-07-31T22:17:03.213000
1 posts
🟠 CVE-2026-53599 - High (7.5)
REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/PHP polygl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53599/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:17:32.440000
3 posts
CVE-2026-68770: Hugging Face sentence-transformers (all versions) impacted by CRITICAL code injection vuln. Local model dirs with malicious files can bypass trust_remote_code=False — arbitrary Python execution possible. Awaiting patch. https://radar.offseq.com/threat/cve-2026-68770-improper-control-of-generation-of-code-code-injection-in-hugging-face-sentence-e94c4111969724ef #OffSeq #CVE #AIsecurity
##CVE-2026-68770: Hugging Face sentence-transformers (all versions) impacted by CRITICAL code injection vuln. Local model dirs with malicious files can bypass trust_remote_code=False — arbitrary Python execution possible. Awaiting patch. https://radar.offseq.com/threat/cve-2026-68770-improper-control-of-generation-of-code-code-injection-in-hugging-face-sentence-e94c4111969724ef #OffSeq #CVE #AIsecurity
##🔴 CVE-2026-68770 - Critical (9.8)
sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68770/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T20:16:54.253000
1 posts
🟠 CVE-2026-67207 - High (8.8)
Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67207/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T20:16:51.173000
1 posts
CVE-2026-52855 - Critical SSTI in Wings (Pterodactyl). Low-priv user can read daemon config tokens via {{config.}} in egg templates. CVSS 9.9. Update to 1.12.3 immediately. #CVE #infosec #Pterodactyl
##updated 2026-07-31T20:16:49.663000
2 posts
CVE-2026-18358 - DoS in Gnome-Remote-Desktop on RHEL. Unauthenticated RDP flood exhausts resources, blocking legit sessions. CVSS 7.5. No patch yet; restrict RDP access. #CVE #infosec #Linux
##🟠 CVE-2026-18358 - High (7.5)
A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote atta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18358/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:45:02
2 posts
CVE-2026-52887: @nocobase/plugin-notification-in-app-message <2.0.61 suffers CRITICAL SQL injection in /api/myInAppChannels:list, enabling RCE as PG superuser 🛡️. Patch to 2.0.61+, disable anonymous signup, restrict DB roles. https://radar.offseq.com/threat/plugin-notification-in-app-message-nocobase-sql-injection-in-apimyinappchannelslist-filter-to-pg-b1d463a23d7d458b #OffSeq #CVE202652887 #AppSec
##CVE-2026-52887: @nocobase/plugin-notification-in-app-message <2.0.61 suffers CRITICAL SQL injection in /api/myInAppChannels:list, enabling RCE as PG superuser 🛡️. Patch to 2.0.61+, disable anonymous signup, restrict DB roles. https://radar.offseq.com/threat/plugin-notification-in-app-message-nocobase-sql-injection-in-apimyinappchannelslist-filter-to-pg-b1d463a23d7d458b #OffSeq #CVE202652887 #AppSec
##updated 2026-07-31T19:38:26
1 posts
🟠 CVE-2026-53510 - High (8.1)
Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53510/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:17:10.123000
2 posts
CVE-2026-53505 - DoS in Thumbor. Unbounded proportion filter causes CPU/memory exhaustion. CVSS 7.5. Update to 7.8.0 immediately. #CVE #Thumbor #infosec
##🟠 CVE-2026-53505 - High (7.5)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion() filter does not enforce an upper bound on and runs in the post-transform phase. An attacker can trigger extremely large resizes (CPU/me...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53505/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:17:08.053000
1 posts
🟠 CVE-2026-18141 - High (8.2)
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by ma...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18141/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:36:05
1 posts
🟠 CVE-2026-53500 - High (8.2)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. This issu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53500/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:32:24
1 posts
🟠 CVE-2026-17347 - High (7.5)
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implement...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17347/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:17:09.510000
1 posts
Zephyr Bluetooth GATT client (versions 2.4.0 to <4.5.0) faces a HIGH severity use-after-free (CVE-2026-10685) in gatt_write_ccc_rsp(). Risk: memory corruption, crash, or attacker-driven flow. Patch pending — apply mitigations. https://radar.offseq.com/threat/cve-2026-10685-use-after-free-in-zephyrproject-zephyr-33ca6b79fde1e5b1 #OffSeq #Zephyr #Bluetooth #CVE
##updated 2026-07-31T17:45:04
1 posts
bank-vaults vault-secrets-webhook is impacted by CVE-2026-54725 (CRITICAL, CVSS 9.6). SSRF flaw lets attackers exfiltrate ServiceAccount JWTs via attacker-controlled Vault addresses. Update to 1.23.1 ASAP. https://radar.offseq.com/threat/cve-2026-54725-cwe-918-server-side-request-forgery-ssrf-in-bank-vaults-vault-secrets-webhook-ec0efb4a3e2ca6ff #OffSeq #Kubernetes #SSRF #CloudSecurity
##updated 2026-07-31T16:52:41
1 posts
🟠 CVE-2026-68500 - High (7.5)
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but doe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68500/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T16:17:12.290000
2 posts
The latest GitLab patch release fixes 13 vulnerabilities, including CVE-2026-6267, a high-severity data exposure flaw. Update self-managed GitLab now.
#GitLab #CVE20266267 #DevSecOps #Vulnerability #PatchNow #InfoSec
##🟠 CVE-2026-6267 - High (8.5)
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauth...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-6267/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T16:17:12.183000
1 posts
🔴 CVE-2026-68503 - Critical (9.8)
LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.py HTTP ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68503/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T16:17:10.493000
1 posts
🟠 CVE-2026-66360 - High (7.5)
The ISO Presentation layer contains a flaw in the handling of specific
parameters during normal mode negotiation. A missing length check in the
processing of the encoded presentation data allows an attacker
controlled field with a zero length v...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66360/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T16:17:09.290000
1 posts
🟠 CVE-2026-63559 - High (7.5)
An integer overflow in the UA_Variant arrayDimensions product
computation in open62541 may allow a remote attacker to read
out-of-bounds heap memory, potentially disclosing sensitive information.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63559/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T16:17:05.520000
1 posts
🟠 CVE-2026-18157 - High (7.8)
A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen,...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18157/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T16:16:58.413000
3 posts
IBM Patches Critical File Write and Command Injection Flaws in App Connect Enterprise
IBM fixed three vulnerabilities in App Connect Enterprise, including a critical path traversal flaw (CVE-2026-15435) that allows remote attackers to write arbitrary files and compromise systems. The updates also address OS command injection and unauthorized file read risks.
**If you run IBM App Connect Enterprise (versions 12.0.1.0–12.0.12.27 or 13.0.1.0–13.0.7.2), first make sure the system is isolated from the internet and reachable only from trusted networks. Then upgrade ASAP to v13 Fix Pack 13.0.8.0 or v12 Fix Pack 12.0.12.28.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/ibm-patches-critical-file-write-and-command-injection-flaws-in-app-connect-enterprise-5-e-y-1-w/gD2P6Ple2L
IBM Patches Critical File Write and Command Injection Flaws in App Connect Enterprise
IBM fixed three vulnerabilities in App Connect Enterprise, including a critical path traversal flaw (CVE-2026-15435) that allows remote attackers to write arbitrary files and compromise systems. The updates also address OS command injection and unauthorized file read risks.
**If you run IBM App Connect Enterprise (versions 12.0.1.0–12.0.12.27 or 13.0.1.0–13.0.7.2), first make sure the system is isolated from the internet and reachable only from trusted networks. Then upgrade ASAP to v13 Fix Pack 13.0.8.0 or v12 Fix Pack 12.0.12.28.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/ibm-patches-critical-file-write-and-command-injection-flaws-in-app-connect-enterprise-5-e-y-1-w/gD2P6Ple2L
@nuintari I was curious how the results differed between Kagi and Startpage (and by proxy, Google) on this. Holy shit, @da_667 is right to be so upset.
Nothing on Startpage or Google’s first page is at all related. Ctrl + F for the CVE returns only the query in the search bar, and Google’s AI overview, which somehow has the right CVE and description, despite the fact that only one of its cited websites even mentions the actual CVE?
For their part, at least @kagihq has CVE Feed’s actual listing for CVE-2026-15435 as their second result, with Tenable and Feedly further down, but still on the first page of results. It’s still crazy that those aren’t the top three results and this should be better, but given how atrocious the competition is, at least it even found the right CVE at all
##updated 2026-07-31T16:16:57.167000
1 posts
🟠 CVE-2026-10079 - High (8.5)
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to cr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10079/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T15:32:58
4 posts
CVE-2026-17561: CRITICAL code injection vuln in Logsign SIEM <6.4.108 (CVSS 9.8). Allows unauthenticated RCE — full compromise possible. No patch confirmed. Restrict mgmt access pending fix. https://radar.offseq.com/threat/improper-control-of-generation-of-code-code-injection-vulnerability-in-innotim-software-1c25c2f49555d07d #OffSeq #infosec #SIEM #vuln
##CVE-2026-17561: CRITICAL code injection vuln in Logsign SIEM <6.4.108 (CVSS 9.8). Allows unauthenticated RCE — full compromise possible. No patch confirmed. Restrict mgmt access pending fix. https://radar.offseq.com/threat/improper-control-of-generation-of-code-code-injection-vulnerability-in-innotim-software-1c25c2f49555d07d #OffSeq #infosec #SIEM #vuln
##🔴 CVE-2026-17561 - Critical (9.8)
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection.
This issue affects Logsign SIEM: before 6.4.108.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17561/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-17561: Logsign SIEM <6.4.108 faces CRITICAL code injection (CWE-94, CVSS 9.8). Exploitable remotely, no patch yet. Full system compromise possible. Monitor for updates. https://radar.offseq.com/threat/cve-2026-17561-cwe-94-improper-control-of-generation-of-code-code-injection-in-innotim-software-30d176d2929ded6e #OffSeq #CVE202617561 #SIEM #Vuln #BlueTeam
##updated 2026-07-31T14:16:50.873000
1 posts
So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.
Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)
Did people still use CodeIgniter?
Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.
##updated 2026-07-31T14:16:50.750000
1 posts
So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.
Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)
Did people still use CodeIgniter?
Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.
##updated 2026-07-31T12:30:30
1 posts
🟠 CVE-2026-11770 - High (7.5)
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11770/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T11:17:04.833000
1 posts
🟠 CVE-2026-15722 - High (7.5)
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds chec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15722/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T09:31:30
1 posts
CVE-2026-16236 - Critical RCE in Realtyna Organic IDX WP plugin. Arbitrary file upload from subscriber-level. CVSS 8.8. No patch. Disable plugin now. #CVE #WordPress #infosec
##updated 2026-07-31T09:31:19
1 posts
🟠 CVE-2026-65313 - High (8.1)
A provisioning script used when installing HIPASE-250 (formerly 250
SCALA) engineering workstations sets a fixed, hard-coded x11vnc
password. Because the same credential is applied to every workstation
provisioned this way, an attacker with adjace...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65313/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T04:17:24.730000
1 posts
🟠 CVE-2026-6102 - High (7.8)
MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An attacker must first obtain the ability to execute...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-6102/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T04:17:24.520000
1 posts
Azure Cosmos DB suffers a CRITICAL improper access control vulnerability (CVE-2026-66803) allowing unauthorized remote code execution. No patch yet — restrict network access & monitor Microsoft advisories. https://radar.offseq.com/threat/improper-access-control-in-azure-cosmos-db-allows-an-unauthorized-attacker-to-execute-code-over-a-db3b78e9f6a886eb #OffSeq #Azure #Vuln #CyberSecurity
##updated 2026-07-31T04:17:24.013000
1 posts
1 repos
🟠 CVE-2026-5490 - High (8.8)
DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of DriveLock. Authentication is required to exploit this vulnerability.
The specific flaw exis...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5490/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T04:17:23.877000
1 posts
🔴 CVE-2026-58066 - Critical (9.8)
Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped docu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58066/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T04:17:23.737000
4 posts
🟠 CVE-2026-58043 - High (7.5)
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.
Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58043/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
####This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
##This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...
##This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
updated 2026-07-31T04:16:48.350000
1 posts
A PHP SQL injection flaw, CVE-2026-17543, was patched alongside two memory bugs. Update to PHP 8.2.33, 8.3.33, 8.4.24, or 8.5.9 now.
#PHP #SQLInjection #CVE202617543 #PostgreSQL #Vulnerability #InfoSec
##updated 2026-07-31T04:16:45.870000
1 posts
🔴 CVE-2026-12940 - Critical (9.8)
IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py whe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12940/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T00:30:29
1 posts
🟠 CVE-2026-65423 - High (8.8)
An integer overflow in the UA_Variant arrayDimensions product
computation in open62541 may allow a remote attacker to trigger an
out-of-bounds write.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65423/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T00:30:29
1 posts
🔴 CVE-2026-66421 - Critical (9.3)
OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages pro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66421/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T00:30:29
1 posts
🟠 CVE-2026-66420 - High (8.8)
MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebSer...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66420/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T00:30:29
1 posts
🟠 CVE-2026-18064 - High (7.5)
An incomplete fix for CVE-2026-15352 in the NASA core Flight System
(cFS) Health and Safety (HS) application leaves a separate NULL pointer
dereference reachable in versions through 7.0.1. An attacker who can
trigger the affected command under ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18064/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T00:30:22
1 posts
🟠 CVE-2026-63035 - High (8.1)
A heap use-after-free vulnerability in the TransferSubscriptions service
in open62541 may allow an authenticated attacker to cause a denial of
service or potentially execute arbitrary code.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63035/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T21:31:57
1 posts
🟠 CVE-2026-67206 - High (8.8)
Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() func...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67206/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T21:31:57
1 posts
🔴 CVE-2026-67594 - Critical (9.8)
Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any ro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67594/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T21:31:57
1 posts
🟠 CVE-2026-66416 - High (8.8)
Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel VerifyCsrfToken middleware from the global middlew...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66416/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T21:31:57
1 posts
🟠 CVE-2026-66415 - High (8.5)
Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::im...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66415/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T21:31:56
1 posts
🔴 CVE-2026-13435 - Critical (9.9)
IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13435/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T21:31:32
1 posts
Chrome CVE Report for the 2026-07-29 Stable channel: https://tbljrmp60k.joplinusercontent.com/shares/mIyA83WXtKANql5AEUYqwx
Top vulnerability types: Inappropriate Implementation (34.5%), Insufficient Input Validation (19%), Use After Free (13.4%)
Most affected components: XR (36), Chrome for iOS (35), Input Handling (33), ANGLE Graphics (30)
Largest bounty: $36,000 — CVE-2026-17657 (Use after free in Navigation)
##updated 2026-07-30T20:17:03.733000
1 posts
🔴 CVE-2026-18245 - Critical (9)
Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18245/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T20:17:03.400000
1 posts
🟠 CVE-2026-18140 - High (7.5)
Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18140/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T19:30:33.710000
1 posts
🟠 CVE-2026-67432 - High (7.5)
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem reads and parses an entire JSON-RPC POST body without a size limit, allowing an ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67432/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T19:26:51.190000
1 posts
🟠 CVE-2026-62663 - High (7.5)
Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks accept untrusted user input as file paths via Path(value) and pass them directly t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62663/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T19:21:23.297000
1 posts
🟠 CVE-2026-67437 - High (7.5)
OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registeredStates map on every /oau...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67437/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T19:10:06.847000
1 posts
The Arris BGW210-700 vulnerability, CVE-2026-16771, is an authentication bypass in AT&T's gateway. A LAN user can read the WiFi password.
#Arris #BGW210700 #ATT #CVE202616771 #AuthenticationBypass #CyberSecurity
##updated 2026-07-30T18:31:47
3 posts
SolarWinds Patches Critical SAML Bypass and pgAdmin4 RCE in Web Help Desk
SolarWinds released Web Help Desk 2026.2.1 to address eight vulnerabilities, including a critical SAML authentication bypass (CVE-2026-28323) and multiple remote code execution flaws in pgAdmin4.
**Update SolarWinds Web Help Desk to version 2026.2.1 ASAP to fix a critical authentication bypass and multiple remote code execution flaws that could give attackers full control of your help desk and connected databases. Before upgrading, switch from Servlet authentication to SAML 2.0 or HTTP Header authentication. If possible for your process, keep the platform isolated on trusted internal networks.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/solarwinds-patches-critical-saml-bypass-and-pgadmin4-rce-in-web-help-desk-f-z-i-u-l/gD2P6Ple2L
SolarWinds Patches Critical SAML Bypass and pgAdmin4 RCE in Web Help Desk
SolarWinds released Web Help Desk 2026.2.1 to address eight vulnerabilities, including a critical SAML authentication bypass (CVE-2026-28323) and multiple remote code execution flaws in pgAdmin4.
**Update SolarWinds Web Help Desk to version 2026.2.1 ASAP to fix a critical authentication bypass and multiple remote code execution flaws that could give attackers full control of your help desk and connected databases. Before upgrading, switch from Servlet authentication to SAML 2.0 or HTTP Header authentication. If possible for your process, keep the platform isolated on trusted internal networks.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/solarwinds-patches-critical-saml-bypass-and-pgadmin4-rce-in-web-help-desk-f-z-i-u-l/gD2P6Ple2L
A SolarWinds Web Help Desk SAML authentication bypass, CVE-2026-28323, scores a critical CVSS 9.8. Update to 2026.2.1 to stay protected.
##updated 2026-07-30T18:31:47
1 posts
🟠 CVE-2026-9322 - High (7.5)
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9322/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T16:45:00.353000
3 posts
🚨 CVE-2026-67595: VaahCMS 2.0.0-2.3.4 contains malicious obfuscated JavaScript in an OTP email template that can connect to a C2 server, log passwords, scrape WhatsApp Web, and remotely alter pages.
Published: 2026-07-29
CVSS 4.0: 9.2
CVSS 3.1: 8.1
Exploitability Score: 2.2
Commit: https://github.com/webreinvent/vaahcms/commit/8d7898f7a385a5fade1180a9b664ff158d873129
##CVE-2026-67595 (CRITICAL): VaahCMS 2.0.0 – 2.3.4 ships with malicious JS in OTP email templates. Enables C2, keylogging, WhatsApp scraping, and remote page control. Avoid JS-enabled viewing until patched. https://radar.offseq.com/threat/cve-2026-67595-embedded-malicious-code-in-webreinvent-vaahcms-94fc0638a0fe22eb #OffSeq #Infosec #CVE202667595 #VaahCMS
##🟠 CVE-2026-67595 - High (8.1)
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67595/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T16:41:25.650000
1 posts
🟠 CVE-2026-67428 - High (8.5)
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_party/developer/http/requests.py, core.api.http_get, core.api.http_post, graphql.query, graphql.mutat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67428/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T16:33:59.580000
1 posts
##This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...
updated 2026-07-30T16:17:11.877000
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T15:31:54
3 posts
🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!
Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)
##🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!
Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)
##CRITICAL vuln: CVE-2026-47876 in VMware Cloud Foundation (9.1.x.x/9.0.x.x/5.x) allows VM admin to execute code on host via VMXNET3 adapter. Restrict admin access, use other adapters if possible. Patch not yet available. https://radar.offseq.com/threat/cve-2026-47876-cwe-787-out-of-bounds-write-in-vmware-cloud-foundation-111066eb743eb8c6 #OffSeq #VMware #InfoSec #CVE202647876
##updated 2026-07-30T15:31:54
2 posts
🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!
Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)
##🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!
Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)
##updated 2026-07-30T15:31:51
2 posts
🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!
Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)
##🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!
Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)
##updated 2026-07-30T15:16:31.530000
1 posts
🟠 CVE-2026-1360 - High (7.5)
The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-1360/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T14:46:44
1 posts
🔴 CVE-2026-67429 - Critical (10)
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR confinem...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67429/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T14:31:21.447000
2 posts
🔴 CVE-2026-44108 - Critical (9.8)
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an un...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44108/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
###OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T14:31:21.447000
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T14:31:21.447000
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T14:31:21.447000
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T14:31:21.447000
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T14:19:24.857000
1 posts
🟠 CVE-2026-5057 - High (7.5)
ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ATEN Unizon. Authentication is not required to exploit ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5057/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T14:18:46.477000
1 posts
🟠 CVE-2026-5491 - High (7.5)
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability.
...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5491/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T14:15:31.167000
1 posts
🟠 CVE-2026-15975 - High (7.5)
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15975/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T14:08:40.373000
2 posts
Four IBM WebSphere vulnerabilities are fixed, including a 9.8 pre-auth RCE (CVE-2026-14512) and a 9.4 SSRF (CVE-2026-14529). Patch now.
#IBMWebSphere #CVE202614512 #SSRF #RCE #Vulnerability #InfoSec
##CRITICAL SSRF vuln (CVE-2026-14529) in IBM WebSphere App Server 9.0, 8.5, and Liberty 17.0.0.3 – 26.0.0.8 if SIP (sipServlet-1.1) is enabled. Review SIP use, disable if possible. Details: https://radar.offseq.com/threat/ibm-websphere-application-server-90-and-85-and-ibm-websphere-application-server-liberty-17003-through-99257a570e2e63d4 #OffSeq #IBM #WebSphere #SSRF #CVE202614529
##updated 2026-07-30T14:01:30.413000
1 posts
🟠 CVE-2026-14270 - High (8.8)
The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validati...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14270/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T12:32:26
1 posts
CVE-2026-18363: osTicket <1.17.8 & <1.18.4 has a CRITICAL flaw (CVSS 9.1) in password reset logic — tokens can be reused, risking account takeover. Upgrade when patch is available, monitor resets, and restrict token access. https://radar.offseq.com/threat/cve-2026-18363-cwe-640-weak-password-recovery-mechanism-for-forgotten-password-in-enhancesoft-llc-eea2d9a253a6859e #OffSeq #osTicket #CVE202618363
##updated 2026-07-30T12:19:03.630000
1 posts
CVE-2026-64560: Linux UAF https://nvd.nist.gov/vuln/detail/CVE-2026-64560
##updated 2026-07-30T09:31:24
2 posts
🟠 CVE-2026-44107 - High (7.5)
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Deni...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44107/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
###OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:24
2 posts
Phoenix Contact CHARX SEC-3150 v1.0.0 hit by CRITICAL (CVSS 9.3) command injection (CVE-2026-7849): unauthenticated remote attackers can execute root commands. No mitigation yet — restrict access! https://radar.offseq.com/threat/cve-2026-7849-cwe-77-improper-neutralization-of-special-elements-used-in-a-command-command-injection-8b9703c63834cb6a #OffSeq #ICS #Vuln #CVE2026_7849
###OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:24
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:24
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:24
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:24
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:24
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:24
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:18
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:18
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T09:31:18
1 posts
#OT #Advisory VDE-2026-008
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
#CVE CVE-2026-7849, CVE-2026-44108, CVE-2026-44104, CVE-2026-44101, CVE-2026-44090, CVE-2026-44100, CVE-2026-44092, CVE-2026-44091, CVE-2026-44098, CVE-2026-44094, CVE-2026-44106, CVE-2026-44099, CVE-2026-44096, CVE-2026-44095, CVE-2026-44093, CVE-2026-44107, CVE-2026-44097, CVE-2026-44105, CVE-2026-44103, CVE-2026-44102
https://certvde.com/en/advisories/vde-2026-008/
#CSAF https://phoenixcontact.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-008.json
##updated 2026-07-30T06:32:44
1 posts
🔴 CVE-2026-58046 - Critical (9.9)
Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58046/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T06:32:44
2 posts
🔴 CVE-2026-16610 - Critical (9.8)
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly em...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16610/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-16610: ASE Pro plugin (≤8.9.0) for WordPress suffers CRITICAL RCE via recursive_html. Unauth attackers can execute code if [post_cf_form] is public. Update/disable plugin ASAP. https://radar.offseq.com/threat/cve-2026-16610-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-ase-admin-and-site-9666b4d559bc4aea #OffSeq #WordPress #CVE2026_16610 #Security
##updated 2026-07-30T06:32:43
1 posts
🟠 CVE-2026-14356 - High (8.8)
The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14356/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T03:31:28
3 posts
Adobe Patches CVSS 10.0 Flaw in Campaign Classic
Adobe has patched a critical flaw in Campaign Classic, a vulnerability rated 10.0 on the CVSS scale that could allow attackers to run malicious code without user interaction. This maximum-severity issue, tracked as CVE-2026-48449, enables arbitrary code execution with the privileges of the current user.
#AdobeCampaignClassic #Cve202648449 #ArbitraryCodeExecution #IncorrectauthorizationFlaw #Cvss100
##Adobe Campaign Classic flaw CVE-2026-48449 scores a perfect CVSS 10.0 and allows arbitrary code execution. Update to build 9398 now.
##🔴 CVE-2026-48449 - Critical (10)
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48449/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T03:31:28
1 posts
🟠 CVE-2026-48448 - High (8.6)
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to g...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48448/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T03:31:28
1 posts
CVE-2026-16727 (HIGH): Race condition in ASUS Armoury Crate 5.4.1 lets local users escalate privileges via improper synchronization. No patch available. Limit local access & monitor systems. https://radar.offseq.com/threat/cve-2026-16727-cwe-362-concurrent-execution-using-shared-resource-with-improper-synchronization-race-75a81e87495a29e2 #OffSeq #CVE202616727 #ASUS #Vuln
##updated 2026-07-29T21:31:08
1 posts
🟠 CVE-2026-5056 - High (7.8)
GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5056/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T21:31:08
1 posts
🟠 CVE-2026-13308 - High (8.1)
Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13308/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T21:31:07
1 posts
🟠 CVE-2026-5487 - High (7.5)
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability.
...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5487/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T21:31:07
1 posts
🟠 CVE-2026-67201 - High (8.6)
V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploiting a parser differential between net.urllib and net.http. Attackers c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67201/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T20:17:10.347000
2 posts
6 repos
https://github.com/codeb0ssx/Ultimate-CVE-2026-61511
https://github.com/HORKimhab/CVE-2026-61511
https://github.com/tc4dy/CVE-2026-61511-PoC-Exploit
https://github.com/shootcannon/CVE-2026-61511
📢 RCE non authentifiée dans vBulletin ≤ 6.2.1 via la méthode runMaths() (CVE-2026-61511)
📝 ## 🔍 Contexte
Publié le 27 juillet 2026 sur le blog de recherche Karma(In)Security (karmainsecurity.com), cet article détaille une vulnérabilité critique d'exécut...
📖 cyberveille : https://cyberveille.ch/posts/2026-07-29-rce-non-authentifiee-dans-vbulletin-6-2-1-via-la-methode-runmaths-cve-2026-61511/
🌐 source : https://karmainsecurity.com/KIS-2026-13
#CVE_2026_61511 #IOC #Cyberveille
A critical vBulletin pre-auth RCE vulnerability, CVE-2026-61511, threatens unpatched forums. Learn how attackers exploit template math evaluation.
##updated 2026-07-29T15:31:12
1 posts
🟠 CVE-2026-67215 - High (7.5)
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy oper...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67215/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T12:31:30
1 posts
1 repos
New. This is in reference to CVE-2026-65883.
VulnCheck: Aimy Captcha-Less Form Guard: The Anti-Bot Plugin That Hands Bots the Keys https://www.vulncheck.com/blog/aimy-captcha-less-form-guard-object-injection @vulncheck #infosec #vulnerability
##updated 2026-07-29T12:31:23
1 posts
1 repos
🟠 CVE-2026-18220 - High (7.8)
An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds ch...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18220/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T09:31:36
1 posts
New.
Tenable Research Advisories: CVE-2026-18197: Link Library - Reflected Cross-Site Scripting https://www.tenable.com/security/research/tra-2026-52
From yesterday:
Coordinated “cyberattack” on Minnesota water utilities: What you need to know https://www.tenable.com/blog/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know @tenable #infosec #cyberattack #Minnesota #threatresearch
##updated 2026-07-28T21:31:44
1 posts
Four IBM WebSphere vulnerabilities are fixed, including a 9.8 pre-auth RCE (CVE-2026-14512) and a 9.4 SSRF (CVE-2026-14529). Patch now.
#IBMWebSphere #CVE202614512 #SSRF #RCE #Vulnerability #InfoSec
##updated 2026-07-28T21:31:39
2 posts
MikroTik RouterOS Flaw CVE-2026-16347 Helps Attackers Gain Unauthorized System Access
CVE-2026-16347 lets attackers brute-force MikroTik RouterOS logins for unauthorized system access. Rated CVSS 8.8, with no fix yet. Apply mitigations. #MikroTik #RouterOS #CVE202616347 #BruteForce #CISA #CyberSecurity TL;DR CISA warned of a brute-force weakness in MikroTik RouterOS and Cloud Hosted Router. Tracked as CVE-2026-16347, it scores a CVSS of 8.8. The flaw helps attackers guess passwords and gain unauthorized system access to admin services.
##MikroTik RouterOS Flaw CVE-2026-16347 Helps Attackers Gain Unauthorized System Access
CVE-2026-16347 lets attackers brute-force MikroTik RouterOS logins for unauthorized system access. Rated CVSS 8.8, with no fix yet. Apply mitigations. #MikroTik #RouterOS #CVE202616347 #BruteForce #CISA #CyberSecurity TL;DR CISA warned of a brute-force weakness in MikroTik RouterOS and Cloud Hosted Router. Tracked as CVE-2026-16347, it scores a CVSS of 8.8. The flaw helps attackers guess passwords and gain unauthorized system access to admin services.
##updated 2026-07-28T21:26:42
1 posts
CVE-2026-55390 - High severity path traversal in datamodel-code-generator 0.59.0-0.62.0. Arbitrary local file read via XML schema imports. CVSS 7.5. Update to 0.62.0 immediately. #CVE #Python #infosec
##updated 2026-07-28T18:33:47
1 posts
Escaping Linux Sandboxes via PipeWire (CVE-2026-5674) https://embracethered.com/blog/posts/2026/pipewire-flatpak-linux-sandbox-escape-cve-2026-5674/
##updated 2026-07-27T21:31:22
1 posts
Arista addresses CVE-2026-16812, a critical vulnerability in VeloCloud Orchestrator actively exploited to gain unauthenticated remote code execution.
##updated 2026-07-27T18:31:56
4 posts
1 repos
https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation
JetBrains emitiu um aviso urgente sobre uma vulnerabilidade crítica no TeamCity que permite execução remota de código. A falha, classificada como CVE-2026-63077, pode ser explorada por atacantes para alcançar a execução remota de código nos sistemas vulneráveis.
##CRITICAL: JetBrains TeamCity On-Premises (all versions) vulnerable to CVE-2026-63077 — auth bypass enables remote code execution via HTTPS. Patch to 2025.11.7/2026.1.3 or apply plugin for 2017.1+. TeamCity Cloud unaffected. https://radar.offseq.com/threat/jetbrains-warns-of-critical-teamcity-remote-code-execution-flaw-b5d2b338dff8d1eb
#OffSeq #Vuln #TeamCity #CVE202663077
CVE-2026-63077 Exposes TeamCity Servers to Unauthenticated RCE
A critical security flaw affecting TeamCity On-Premises has prompted administrators to update their servers immediately after researchers disclosed...
🔗️ [Thecyberexpress] https://link.is.it/Uo0klI
##JetBrains patches critical TeamCity On-Premises vulnerability CVE-2026-63077 (CVSS 9.8), preventing unauthenticated remote code execution.
##updated 2026-07-25T12:31:47
1 posts
An OpenRemote vulnerability, CVE-2026-66013 (CVSS 9.3), enables unauthenticated asset takeover. Full advisory details are now public. Patch to 1.26.2.
#OpenRemote #CVE202666013 #IoTSecurity #AssetTakeover
https://securityonline.info/openremote-cve-2026-66013/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-07-25T03:30:55
1 posts
A public PoC now targets CVE-2026-66373, a Redis RCE double-free via RESTORE. See affected versions and upgrade to Redis 8.8.0 now.
#Redis #RedisRCE #CVE202666373 #RCE #DoubleFree #PoC #RESTORE #Cybersecurity
https://securityonline.info/redis-rce-cve-2026-66373/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-07-24T16:14:33
1 posts
CVE-2026-59952 | open-circle valibot <1.4.2 suffers from improper exception handling in flatten(), causing TypeErrors & potential DoS if attacker-controlled keys collide w/ Object.prototype methods. Severity: MEDIUM. Upgrade to 1.4.2+ https://radar.offseq.com/threat/cve-2026-59952-cwe-755-improper-handling-of-exceptional-conditions-in-open-circle-valibot-c7fe163cf2db3032 #OffSeq #Valibot #AppSec
##updated 2026-07-24T15:33:29
1 posts
57 repos
https://github.com/Wtrwx/smt878u-ionstack-poc
https://github.com/woshimaniubi8/CVE-2026-43499-root-KernelSU
https://github.com/Colorful-glassblock/duchamp-root
https://github.com/justsoman/CyberMeowfia-ace3
https://github.com/fusiondrive/CVE-2026-43499-S24U
https://github.com/MobiusM/CVE-2026-43499
https://github.com/ctn-Qvo/auto_extract_offsets
https://github.com/pubglite55/oppo-ghostlock
https://github.com/x-spy/CVE-2026-43499-popsicle
https://github.com/p2p3p/GhostLock-for-OnePlus
https://github.com/ayyy7128/CVE-2026-43499-jinghu
https://github.com/BuSung-dev/CVE-2026-43499-S25U
https://github.com/WitAqua-tools/Root-My-Device
https://github.com/datfooldive/ghostlock-emerald
https://github.com/0xBlackash/CVE-2026-43499
https://github.com/LuZe0y/pd2425-cve-2026-43499-config
https://github.com/PeronGH/ghostlock-selinux-disabler
https://github.com/Cxyofficial/x200-cve-2026-43499
https://github.com/joehquak/Mi8E5-Unlocker-by-CVE-2026-43499
https://github.com/sorrow404Null/CVE-2026-43499-RMX5200
https://github.com/Linuxoid-cn/Mi8E5-Unlocker-by-CVE-2026-43499
https://github.com/No-22-Github/UnPlus
https://github.com/qsvggff-spec/oppo-A5-PRO-5G-CVE-2026-43499
https://github.com/xianwan1314/CVE-2026-43499-Poc-Analysis
https://github.com/BuSung-dev/Root-My-Galaxy
https://github.com/dmcdtc/openvz-cve-patch-2026
https://github.com/dnlid/CVE-2026-43499
https://github.com/HYCQAQ/Logitech-G-Cloud-GhostLock-CVE-2026-43499
https://github.com/2932796375github/CVE-2026-43499_OPPO-MT6835
https://github.com/fancyzll/CVE-2026-43499_OPPO-MT6835
https://github.com/geecjdj/CVE-2026-43499
https://github.com/Petalrain224/CVE-2026-43499-Redmi-Turbo5
https://github.com/soralis0912/CVE-2026-43499-aristotle-apk
https://github.com/CatXiaoShi/cve-2026-43499
https://github.com/cuteaplane/GhostLock-for-OnePlus15T
https://github.com/soralis0912/CVE-2026-43499-pmg110-root
https://github.com/mumaosong/cve-2026-43499-CyberMeowfia
https://github.com/soralis0912/CVE-2026-43499-aristotle
https://github.com/Bailan766/rmx3888-cve-2026-43499-config
https://github.com/Bartixxx32/CVE-2026-43499-OnePlus15
https://github.com/inforcqb/CVE-2026-43499-pja110
https://github.com/soralis0912/CVE-2026-43499-warhol-root
https://github.com/HORKimhab/CVE-2026-43499
https://github.com/tc3650/CVE-2026-43499-armv7
https://github.com/Yakayna/SpringPeace
https://github.com/Thiasap/oppo-pgem10-ghostlock
https://github.com/onesmiledx/CVE-2026-43499
https://github.com/ctn-Qvo/CVE-2026-43499-so-build
https://github.com/Linuxoid-cn/CVE-2026-43499-Poc-Analysis
https://github.com/gagaltotal/CVE-2026-43499-PoC-Scanner
https://github.com/JoinChang/ghostlock-oneplus
https://github.com/Kananosa/CVE-2026-43499-For-Xiaomi-17T-chagall
https://github.com/NothingFumo/ghostlock-aresin
https://github.com/MiaPatsune/cve-2026-43499
https://github.com/caspy123/CVE-2026-43499
Update Firefox, the Tor browser, and other derivatives if you are still running FF versions 147 through to 151.0.2.
Some interesting attacks exploiting CVE-2026-10702 are shoring up:
https://thehackernews.com/2026/07/researchers-show-single-malicious.html?m=1
Note that thanks to Android's lazy sandbox,
this attack can be used as the entry point of a complete browser-to-kernel chain, giving the attacker root (CVE-2026-43499).
(Unclear if/how Firefox-ESR is affected)
##updated 2026-07-23T21:31:03
1 posts
A C-CURE 9000 vulnerability chain hits CVSS 9.6. CVE-2026-21655 allows remote code execution on Johnson Controls victor application servers.
##updated 2026-07-23T11:10:00.120000
1 posts
9 repos
https://github.com/SecureWithUmer/CVE-2026-43503
https://github.com/lieehrdiansyah12/CVE-2026-43503
https://github.com/rjt-gupta/page-cache-corruption-lpes
https://github.com/mooder1/dirtyclone-CVE-2026-43503
https://github.com/entra1337/DirtyClone
https://github.com/douglasmun/pagecache-lpe-containment-kit
https://github.com/gl1tch0x1/DirtyClone
‼️ CVE-2026-43503: DirtyClone is a Linux kernel local privilege escalation (LPE) vulnerability caused by page-cache corruption.
##updated 2026-07-22T21:32:05
5 posts
2 repos
https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
From our Check Point Research Team:
July 2026 Security Update
Check Point has addressed CVE-2026-16232, an authentication bypass vulnerability in SmartConsole that is under active exploitation, affecting a handful of customers. The flaw allows remote attackers to bypass authentication and gain administrative access to Check Point management servers. Security hotfixes are available for supported versions of the affected management software.
##Authentication bypass for Check Point Security Management Server and Multi-Domain Security Management Server https://github.com/sfewer-r7/CVE-2026-16232
##Rapid7, from yesterday: Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232) https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232/ @Rapid7Official #infosec #vulnerability #threatresearch
##updated 2026-07-22T21:31:51
2 posts
5 repos
https://github.com/HORKimhab/CVE-2026-50522
https://github.com/ChPratik/CVE-2026-50522
https://github.com/4minx/CVE-2026-50522
https://github.com/webshellseo8/CVE-2026-50522-Proof-of-Concept
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-22T16:17:28.753000
1 posts
2 repos
🚨 A Cobalt Strike BOF targeting CVE-2026-49176 adds another exploitation method for the CVSS 7.8 Windows WalletService local privilege escalation vulnerability.
GitHub: https://github.com/777erp/CVE-2026-49176_BOF
The flaw can allow a standard user to execute commands with SYSTEM privileges on unpatched Windows systems.
##updated 2026-07-21T20:28:59
2 posts
6 repos
https://github.com/XaocZenon/CVE-2026-20896
https://github.com/szybnev/cve-2026-20896-gitea-poc
https://github.com/Lite-os15/Lab-001-Gitea-CVE-2026-20896-
https://github.com/EQSTLab/CVE-2026-20896
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-17T19:04:38
2 posts
2 repos
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-16T21:30:45
1 posts
🟠 CVE-2026-18064 - High (7.5)
An incomplete fix for CVE-2026-15352 in the NASA core Flight System
(cFS) Health and Safety (HS) application leaves a separate NULL pointer
dereference reachable in versions through 7.0.1. An attacker who can
trigger the affected command under ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18064/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-16T12:17:51.630000
1 posts
3 repos
https://github.com/HORKimhab/CVE-2026-42530
A public PoC now details CVE-2026-42530, an NGINX HTTP/3 RCE from a QPACK use-after-free. Upgrade to NGINX 1.31.2 to close the flaw now.
#NGINX #HTTP3 #CVE202642530 #RCE #UseAfterFree #QUIC #QPACK #PoC #Cybersecurity
##updated 2026-07-16T05:16:18.293000
2 posts
5 repos
https://github.com/tc4dy/CVE-2026-15409-15410-Framework
https://github.com/HORKimhab/CVE-2026-15409
https://github.com/0xBlackash/CVE-2026-15409
https://github.com/remmons-r7/rapid7-CVE-2026-15409
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-14T21:32:32
2 posts
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-14T21:32:21
2 posts
3 repos
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-10T19:15:15.780000
3 posts
1 repos
⚠️ CRITICAL: Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
CVE-2026-59726 in Ruflo AI orchestration platform allows unauthenticated remote code execution via an exposed Model Context Protocol bridge. Attackers can steal API keys, access user conversations, and corrupt AI memory without any credentials. Any organization running Ruflo is immediately exploita…
##Critical RufRoot Flaw Allows Full Takeover of Ruflo AI Agent Environments
Ruflo patched a CVSS 10.0 vulnerability (CVE-2026-59726) that allowed unauthenticated attackers to execute code and steal API keys via an exposed MCP bridge. The flaw, named RufRoot, also enabled AI memory poisoning that persists even after software updates.
**If you run Ruflo (formerly Claude Flow), first make sure your instances are isolated from the internet and reachable only from trusted networks, then update to version 3.16.3 immediately to fix the RufRoot flaw (CVE-2026-59726) and firewall ports 3001 and 27017 to block outside access from the local network. Because a simple update won't undo damage already done, rotate all your LLM provider API keys (OpenAI, Anthropic, etc.) and audit the AgentDB memory store for any malicious entries left behind by attackers.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-rufroot-flaw-allows-full-takeover-of-ruflo-ai-agent-environments-m-z-i-s-1/gD2P6Ple2L
Ruflo <3.16.3 has a CRITICAL flaw (CVE-2026-59726): exposed /mcp endpoint allows unauth RCE in MCP bridge container. Attackers can spawn rogue AI swarms & steal API keys. Upgrade to 3.16.3 asap. https://radar.offseq.com/threat/critical-ruflo-flaw-lets-attackers-spawn-rogue-ai-swarms-96a3ca25e5fa59f3 #OffSeq #AIsecurity #infosec #CVE202659726
##updated 2026-07-10T18:33:13
2 posts
4 repos
https://github.com/ChiefYoru/CVE-2026-56291_PoC
https://github.com/0xdenis77/CVE-2026-56291
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-09T21:31:14
1 posts
1 repos
🚨 PoC for CVE-2026-58025, a CVSS 9.8 MediaWiki deserialization flaw that could enable RCE through malicious log entry imports.
Exploitation requires import permissions. Upgrade to 1.43.9, 1.44.6, 1.45.4, or 1.46.0.
##updated 2026-06-30T03:36:54
3 posts
2 repos
Firefox CVE-2026-10702 Exploit: Android Flaw Exposed
##Update Firefox, the Tor browser, and other derivatives if you are still running FF versions 147 through to 151.0.2.
Some interesting attacks exploiting CVE-2026-10702 are shoring up:
https://thehackernews.com/2026/07/researchers-show-single-malicious.html?m=1
Note that thanks to Android's lazy sandbox,
this attack can be used as the entry point of a complete browser-to-kernel chain, giving the attacker root (CVE-2026-43499).
(Unclear if/how Firefox-ESR is affected)
##Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. https://thehackernews.com/2026/07/researchers-show-single-malicious.html
##updated 2026-06-17T10:48:34.893000
6 posts
1 repos
⚠️ CRITICAL: Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
Russian state-sponsored group Laundry Bear is actively exploiting a zero-day XSS vulnerability (CVE-2026-42897) in Exchange OWA to deploy OWAReaper backdoor. Targets include U.S. and European government entities and private sector organizations. Successful exploitation grants persistent mailbox acc…
##🏆 New Achievement! Inbox: One New Backdoor (Unread)!
Conducting inventory audit of your Microsoft Exchange installation. Status: CVE-2026-42897, one cross-site scripting flaw in Outlook Web Access — present, unpatched, actively exploited. OWAReaper backdoor — installed, compliments of Laundry Bear (also filed under: Void Blizzard). Long-term mailbox access — granted, unauthorized, ongoing. Affected sectors listed: government, telecom, financial, hospitality, aerospace. (1/2)
##HTML sanitization — missing. Proofpoint's report — filed July 29, one week after the activity was detected.
Summary column: your email server is carrying significant negative-value assets. Patch CVE-2026-42897 immediately and audit OWA logs for suspicious JavaScript execution and unauthorized mailbox access.
Reward: A cursed Rusty Audit Clipboard. It changes nothing. The backdoor is still there.
#CyberSecurity #ZeroDay #Exchange #Ransomware #APT #AchievementUnlocked (2/2)
##The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026. https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html?_m=3n%2e009a%2e4043%2ebk0aof3yrl%2e33l5
##Proofpoint analyses a campaign from Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) exploiting Outlook CVE-2026-42897 and targeting US & European government entities, as well as the telecommunications, financial, hospitality & aerospace sectors. https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit
##New.
"On 22 July 2026, one day prior to Proofpoint’s recent joint release with the NSA on Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear), the actor began a campaign abusing CVE-2026-42897, a cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA)."
Proofpoint: Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit
More:
The Record: Laundry Bear’s webmail hackers had more in store after February, report says https://therecord.media/russia-hackers-outlook-webmail-malware @therecord_media @jwarminsky #infosec #threatresearch #Outlook #Microsoft
##updated 2026-06-17T00:02:24.467000
1 posts
75 repos
https://github.com/OffensivePython/HeartLeak
https://github.com/rouze-d/heartbleed
https://github.com/iSCInc/heartbleed
https://github.com/DisK0nn3cT/MaltegoHeartbleed
https://github.com/jdauphant/patch-openssl-CVE-2014-0160
https://github.com/GeeksXtreme/ssl-heartbleed.nse
https://github.com/proactiveRISK/heartbleed-extention
https://github.com/idkqh7/heatbleeding
https://github.com/marstornado/cve-2014-0160-Yunfeng-Jiang
https://github.com/0xBlackash/CVE-2014-0160
https://github.com/h3x0v3rl0rd/CVE-2014-0160_Heartbleed
https://github.com/waqasjamal-zz/HeartBleed-Vulnerability-Checker
https://github.com/0xinf0/bleeding_onions
https://github.com/GardeniaWhite/fuzzing
https://github.com/anthophilee/A2SV--SSL-VUL-Scan
https://github.com/roganartu/heartbleedchecker-chrome
https://github.com/takeshixx/ssl-heartbleed.nse
https://github.com/artofscripting-zz/cmty-ssl-heartbleed-CVE-2014-0160-HTTP-HTTPS
https://github.com/tungduongNT/CVE-2014-0160.
https://github.com/yashfren/CVE-2014-0160-HeartBleed
https://github.com/PinkP4nther/Heartbleed_PoC
https://github.com/timsonner/cve-2014-0160-heartbleed
https://github.com/titanous/heartbleeder
https://github.com/FiloSottile/Heartbleed
https://github.com/WildfootW/CVE-2014-0160_OpenSSL_1.0.1f_Heartbleed
https://github.com/iwaffles/heartbleed-test.crx
https://github.com/sensepost/heartbleed-poc
https://github.com/Saymeis/HeartBleed
https://github.com/yryz/heartbleed.js
https://github.com/vortextube/ssl_scanner
https://github.com/tomdevman/heartbleed-bug
https://github.com/cheese-hub/heartbleed
https://github.com/cved-sources/cve-2014-0160
https://github.com/mozilla-services/Heartbleed
https://github.com/ingochris/heartpatch.us
https://github.com/Xyl2k/CVE-2014-0160-Chrome-Plugin
https://github.com/cbk914/heartbleed-checker
https://github.com/xlucas/heartbleed
https://github.com/belmind/heartbleed
https://github.com/musalbas/heartbleed-masstest
https://github.com/froyo75/Heartbleed_Dockerfile_with_Nginx
https://github.com/MrE-Fog/CVE-2014-0160-Chrome-Plugin
https://github.com/caiqiqi/OpenSSL-HeartBleed-CVE-2014-0160-PoC
https://github.com/hybridus/heartbleedscanner
https://github.com/DominikTo/bleed
https://github.com/undacmic/heartbleed-proof-of-concept
https://github.com/mpgn/heartbleed-PoC
https://github.com/a0726h77/heartbleed-test
https://github.com/22imer/CVE-2014-0160
https://github.com/indiw0rm/-Heartbleed-
https://github.com/hmlio/vaas-cve-2014-0160
https://github.com/cyphar/heartthreader
https://github.com/hreese/heartbleed-dtls
https://github.com/isgroup/openmagic
https://github.com/siddolo/knockbleed
https://github.com/obayesshelton/CVE-2014-0160-Scanner
https://github.com/zouguangxian/heartbleed
https://github.com/Lekensteyn/pacemaker
https://github.com/indrajeetmp11/Heartbleed-PoC-Exploit-Script
https://github.com/0x90/CVE-2014-0160
https://github.com/sammyfung/openssl-heartbleed-fix
https://github.com/einaros/heartbleed-tools
https://github.com/GuillermoEscobero/heartbleed
https://github.com/Shayhha/HeartbleedAttack
https://github.com/ArtemCyberLab/Project-Field-Analysis-and-Memory-Leak-Demonstration
https://github.com/amerine/coronary
https://github.com/Ryo-Soikutsu/Heartbleed
https://github.com/pierceoneill/bleeding-heart
https://github.com/fb1h2s/CVE-2014-0160
https://github.com/xanas/heartbleed.py
https://github.com/ThanHuuTuan/Heartexploit
https://github.com/victoriacfigueiredo/heartbleed-lab
Shodan-Query of the day:
asn:"AS59399" vuln:"cve-2014-0160"
##updated 2026-06-16T23:57:53.617000
2 posts
1 repos
Also wirklich, niemand, wirklich niemand sollte ein #BMC ohne ein VPN/SSL frei ins Internet stellen! Das war schon 2004 fahrlässig.
@gborn : "Mehr als 24.000 Server mit BMC per #Schwachstelle CVE-2013-4786 gefährdet. .... Diese besteht wohl seit 2004 und kann den Password-Hash zur Authentifizierung leaken. Die Server wären dann per Internet öffentlich angreifbar, und die Passwort-Hashes sind in vielen Fällen knackbar"
##Also wirklich, niemand, wirklich niemand sollte ein #BMC ohne ein VPN/SSL frei ins Internet stellen! Das war schon 2004 fahrlässig.
@gborn : "Mehr als 24.000 Server mit BMC per #Schwachstelle CVE-2013-4786 gefährdet. .... Diese besteht wohl seit 2004 und kann den Password-Hash zur Authentifizierung leaken. Die Server wären dann per Internet öffentlich angreifbar, und die Passwort-Hashes sind in vielen Fällen knackbar"
##updated 2026-03-04T18:32:03
4 posts
1 repos
There are two new advisories from Cisco, one addressing a critical vulnerability that was first published on March 4:
CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
The second is a high-severity vulnerability that was first published yesterday:
CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh @TalosSecurity #infosec #vulnerability #Cisco
###Cisco - "We Never Learn". 🔥
Warum ein Konzern es noch immer notwendig findet eine #Backdoor in seine Produkte einzubauen ist mir völlig schleierhaft. 🙈
"Da CVE-2026-20316 bereits aktiv ausgenutzt wird, rät Cisco Administratoren, ihre FMC-Instanzen dringend zu aktualisieren."
"Gibt es Abhilfe?
"Die genannten Hotfix-Updates bessern auch bezüglich einer seit März bekannten kritischen Lücke (CVSS: 10) nach, mit der sich die Authentifizierung im Web-Interface von FMC umgehen lässt. Diese Lücke ist als CVE-2026-20079 registriert und verleiht Angreifern sogar einen direkten Root-Zugriff auf das zugrundeliegende Betriebssystem. "
Klar, eine Firewall ist ja nur zum Schutz der Kunden vorhanden, da kann man schon mal auch Kriminelle einladen, oder? 🤢
So eine persönliche Haftung des CEO und eine Strafe ab 5 % vom Konzernumsatz könnte möglicherweise zu einer Änderungen führen:
So stelle ich mir die Anweisung des CEO vor: 👍
"Ab sofort ist die Nutzung (auch während der Entwicklung) von Backdoors untersagt. Wer sich nicht daran hält wird fristlos entlassen und haftet für Schäden."
Und, natürlich sollte die Qualitätssicherung vorab prüfen ob die Entwickler sich auch daran halten. 😁
Es gibt erfahrene Spezialisten die gerne bei der Auswahl der Geräte helfen und für mehr Sicherheit sorgen. Einfach anfragen, dann weiß man mehr. 🙂
##🏆 New Achievement! Static Credentials, Static Fate!
RAID ALERT. RAID ALERT. Cisco Secure Firewall Management Center has a hardcoded low-privilege account baked right into the software — CVE-2026-20316 — and unauthenticated remote attackers are already using it to log in and harvest sensitive data. That's Phase One. Phase Two is the wipe: threat actors are chaining it with CVE-2026-20079, which hands them root access via arbitrary script execution. (1/2)
##New Cisco updates:
CRITICAL vulnerability, first released on March 4: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
High severity: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
New informational advisory: Cisco Advance Notification for Publication of August 5, 2026, Security Advisories https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-L4XfJg8S @TalosSecurity #infosec #vulnerability #Cisco
##updated 2026-01-02T09:30:27
1 posts
@fugueish Was going to shill Kagi, but their first result is CVE-2025-15435 (i.e. wrong year). The second result is correct. Quotes don't uprank that second result for some reason. It's still the first day, so maybe their crawls aren't as aggressive?
##updated 2025-11-04T21:32:34
2 posts
@slomo No need for the hostility. The text summary might pull context from reference links mentioning 1.22.5, but our 'Patch Status' flag operates strictly on machine-readable data from the NVD API.
If you look at the official NVD record for CVE-2023-37327, the CPE configurations only map up to 1.22.4 and do not explicitly record the patched status. We explicitly do not accept vendor GitHub releases as evidence until they are validated by NVD.
@hugovalters Bullshit. Get your data updated and fix your website instead of spreading fud.
It's very funny that e.g. https://www.valtersit.com/cve/CVE-2023-37327/ claims to be "unpatched" and at the top says that it's fixed in 1.22.5, contains completely wrong information (just follow your own NVD link and compare: it's describing completely different issues), and a wrong patch for code that does not even exist in this shape in 1.22.5 or any other version.
Not enough that we have to deal with a flood of new issues reported thanks to LLMs, on top of that we also have to deal with clowns like you.
##2 posts
72 repos
https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell
https://github.com/imXur/WordPress-CVE-2026-63030-Analysis
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/ekomsSavior/wp2shell
https://github.com/raphy76/wp2shell-poc-fulljs
https://github.com/michael-kanda/Wp2shell-ioc-scanner
https://github.com/0xWhoknows/wp2shell
https://github.com/yuag/wp2shell
https://github.com/0xh7ml/CVE-2026-63030
https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2026-63030-WP2Shell
https://github.com/4minx/CVE-2026-63030
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/TomorrowX6/CVE-2026-63030-poc
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/0xjessie21/wp2shell-checker
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner
https://github.com/mhtsec/CVE-2026-63030
https://github.com/zeroc00I/CVE-2026-63030
https://github.com/administrator-01001/CVE-2026-63030
https://github.com/zi3lak/wp2shell_scanner
https://github.com/kulichr/wp2shell
https://github.com/0xsha/wp2shell
https://github.com/ChiefYoru/CVE-2026-63030_PoC
https://github.com/shinthink/CVE-2026-63030
https://github.com/JohenLastGen-JLG/wp2shell
https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030
https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t
https://github.com/0xBlackash/CVE-2026-63030
https://github.com/vulnquest58/PressVector
https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause
https://github.com/h4cd0c/wp2shell
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/ZenithGenius/wordpress-batch-rce-lab
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/Colere-Sys/wp2shell-poc
https://github.com/ananay/wp2shell-lab
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/Icex0/wp2shell-poc
https://github.com/4B3R4M4-607D/CVE-2026-63030-POC
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/mrx-arafat/CVE-2026-63030-POC
https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030
https://github.com/fullhunt/wp2shell-scan
https://github.com/bahartanir/wp2shell-scanner
https://github.com/HackingLZ/wp2shell_stock_chain
https://github.com/ikow/wp2shell
https://github.com/Crypto-Cat/wp2shell
https://github.com/47Cid/wp2shell-lab
https://github.com/Iqbalx7/wp2shell
https://github.com/Senanfurkan/wordpress-cve-2026-63030
https://github.com/NULL200OK/WP2Shell
https://github.com/ebrasha/abdal-cve-2026-63030
https://github.com/InstaWP/wp2shell-scan
https://github.com/dinosn/wp2shell-lab
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/attackercan/wp2shell-poc2
https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction
https://github.com/AkbarWiraN/holy-wp2shell
https://github.com/Lutfifakee-Project/wp2shell
https://github.com/Ch4120N/CVE-2026-63030
https://github.com/mverschu/CVE-2026-63030
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/c0gnit00/Wp2Shell
https://github.com/mcipekci/wp2shell
https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030
https://github.com/CybersecSpirit/CVE-2026-63030
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
https://github.com/gbrsh/CVE-2026-63030
https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
2 posts
46 repos
https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell
https://github.com/ebrasha/abdal-cve-2026-60137
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/ekomsSavior/wp2shell
https://github.com/michael-kanda/Wp2shell-ioc-scanner
https://github.com/0xWhoknows/wp2shell
https://github.com/yuag/wp2shell
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/0xjessie21/wp2shell-checker
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner
https://github.com/zi3lak/wp2shell_scanner
https://github.com/kulichr/wp2shell
https://github.com/0xsha/wp2shell
https://github.com/shinthink/CVE-2026-63030
https://github.com/JohenLastGen-JLG/wp2shell
https://github.com/vulnquest58/PressVector
https://github.com/h4cd0c/wp2shell
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/Colere-Sys/wp2shell-poc
https://github.com/ananay/wp2shell-lab
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/Icex0/wp2shell-poc
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/bahartanir/wp2shell-scanner
https://github.com/HackingLZ/wp2shell_stock_chain
https://github.com/ikow/wp2shell
https://github.com/Crypto-Cat/wp2shell
https://github.com/47Cid/wp2shell-lab
https://github.com/Iqbalx7/wp2shell
https://github.com/Senanfurkan/wordpress-cve-2026-63030
https://github.com/NULL200OK/WP2Shell
https://github.com/northsia/CVE-2026-60137-With-Skip-SSL
https://github.com/dinosn/wp2shell-lab
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction
https://github.com/AkbarWiraN/holy-wp2shell
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
https://github.com/mcipekci/wp2shell
https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030
https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
CVE-2026-18420: CRITICAL RCE via prototype pollution in OpenSearch Dashboards TSVB plugin. Full system compromise possible. No patch yet — check AWS Security Bulletin, limit plugin access, monitor updates. https://radar.offseq.com/threat/cve-2026-18420-remote-code-execution-via-prototype-pollution-in-opensearch-dashboards-tsvb-plugin-7ca97f6da2a61633 #OffSeq #OpenSearch #Infosec #RCE
##🟠 CVE-2026-62999 - High (7.5)
Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an HTTP serv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62999/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9.
#OpenAM #RCE #IAM #CVE202662379
https://securityonline.info/openam-cve-2026-62379/?utm_source=mastodon&utm_medium=jetpack_social
##Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9.
#OpenAM #RCE #IAM #CVE202662379
https://securityonline.info/openam-cve-2026-62379/?utm_source=mastodon&utm_medium=jetpack_social
##two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.
CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.
CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.
https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-w88m-4vmc-pq9g and https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-m5xx-3qv7-37hj
#GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security
##two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.
CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.
CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.
https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-w88m-4vmc-pq9g and https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-m5xx-3qv7-37hj
#GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security
##So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.
Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)
Did people still use CodeIgniter?
Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.
##CVE-2026-63223: CodeIgniter4 RCE Vulnerability Rated CVSS 9.8
##So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.
Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)
Did people still use CodeIgniter?
Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.
##🔴 CVE-2026-68502 - Critical (9.8)
LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches data.get('value') to LazyOwnShell.one_cmd, reachi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68502/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Using AI to understand kernel crashes | Alexander Leidinger
<https://www.leidinger.net/blog/2026/07/19/using-ai-to-understand-kernel-crashes/>
– via <https://www.reddit.com/r/freebsd/comments/1val3np/using_ai_to_understand_kernel_crashes_alexander/>.
Alexander is credited for this month's CVE-2026-58086 (FreeBSD-SA-26:53.ktrace): <https://www.reddit.com/r/freebsd/comments/1vakgpe/freebsd_errata_notices_and_security_advisories/p0m8ods/>
####This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
##This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
##This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
Node.js patched 11 vulnerabilities in its July 2026 release. The high-severity bugs include a HTTP/2 use-after-free (CVE-2026-56848). Update now.
#NodeJS #CVE202656848 #HTTP2 #UseAfterFree #Vulnerability #InfoSec
####This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...
##This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
OpenWrt Vulnerability CVE-2026-53921 Demands Immediate Action
##